-
Notifications
You must be signed in to change notification settings - Fork 317
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Support deploying and managing TLS encryption enabled TiDB cluster #529
Comments
Reminder: Please also support TiCDC TLS deployment. |
It seems |
also tidb binog |
@july2993 @overvenus Is there any doc about how to configure TLS for CDC and binlog? |
This issue has been placed in the security issue pingcap/tidb#18084 as a sub-item. It's duplicated in |
@lonng this is a sub-task of tidb#18084, do not adding it to longterm project. |
Actually this issue is about "support deploy cluster with security features enabled" instead of "support those security features among components". Please have title and description clear, or it is a waste of time for whom cares. @lucklove |
Feature Request
Description
At present, when deploying a cluster with tiup-cluster, the tidb cluster (tidb <-> pd <-> tikv and pd <-> tiup) use plain messages to communicate, this may lead to potential security leaks. We should support TLS encryption as an option in the cluster topology to enable TLS encryption among components.
Similar support is already implemented in tidb-ansible and tidb-operator.
Catagory
Security
Value
Increase security of TiDB cluster, and avoid potential security leaks like MITM attack.
TODO List
Schedule
GanttStart: 2020-08-01
GanttDue: 2020-08-31
GanttProgress: 95%
The text was updated successfully, but these errors were encountered: