From 02babcb3a535adfa8cb5d37ba546a70e9725e90c Mon Sep 17 00:00:00 2001 From: Fang-Pen Lin Date: Wed, 3 Dec 2025 14:20:33 -0800 Subject: [PATCH] Fix ssl stuff --- .../kubernetes/kubernetes-resource-factory.ts | 20 +++++-------------- 1 file changed, 5 insertions(+), 15 deletions(-) diff --git a/backend/src/ee/services/pam-resource/kubernetes/kubernetes-resource-factory.ts b/backend/src/ee/services/pam-resource/kubernetes/kubernetes-resource-factory.ts index 3afad5ae2..26177acaa 100644 --- a/backend/src/ee/services/pam-resource/kubernetes/kubernetes-resource-factory.ts +++ b/backend/src/ee/services/pam-resource/kubernetes/kubernetes-resource-factory.ts @@ -26,7 +26,7 @@ export const executeWithGateway = async ( gatewayId: string; }, gatewayV2Service: Pick, - operation: (baseUrl: string, httpsAgent?: https.Agent) => Promise + operation: (baseUrl: string, httpsAgent: https.Agent) => Promise ): Promise => { const { connectionDetails, gatewayId } = config; const url = new URL(connectionDetails.url); @@ -46,23 +46,13 @@ export const executeWithGateway = async ( targetHost, targetPort }); - if (!platformConnectionDetails) { throw new BadRequestError({ message: "Unable to connect to gateway, no platform connection details found" }); } - - let httpsAgent: https.Agent | undefined; - if (connectionDetails.caCertificate) { - httpsAgent = new https.Agent({ - ca: connectionDetails.caCertificate, - rejectUnauthorized: !connectionDetails.skipTLSVerify - }); - } else if (!connectionDetails.skipTLSVerify) { - httpsAgent = new https.Agent({ - rejectUnauthorized: true - }); - } - + const httpsAgent = new https.Agent({ + ca: connectionDetails.sslCertificate, + rejectUnauthorized: connectionDetails.sslRejectUnauthorized + }); return withGatewayV2Proxy( async (proxyPort) => { const protocol = url.protocol === "https:" ? "https" : "http";