์ž์ฒด ์„œ๋ช…๋œ TLS ์‚ฌ์šฉ์ž ์ธ์ฆ ์ •๋ณด ์ƒ์„ฑ

์ด ์ฃผ์ œ์—์„œ๋Š” ํ™˜๊ฒฝ ๊ตฌ์„ฑ์— ์‚ฌ์šฉํ•  ์ž์ฒด ์„œ๋ช…๋œ TLS ์ธ์ฆ์„œ๋ฅผ ๋งŒ๋“œ๋Š” ๋ฐฉ๋ฒ•์„ ์„ค๋ช…ํ•ฉ๋‹ˆ๋‹ค. ์ด ์ •๋ณด๋Š” ๋ฌด๋ฃŒ ์ฒดํ—˜ํŒ ๋˜๋Š” ํ…Œ์ŠคํŠธ ๋ชฉ์ ์œผ๋กœ๋งŒ ์‚ฌ์šฉ๋ฉ๋‹ˆ๋‹ค.

๋Ÿฐํƒ€์ž„ ์ธ๊ทธ๋ ˆ์Šค ๊ฒŒ์ดํŠธ์›จ์ด(API ํ”„๋ก์‹œ ํŠธ๋ž˜ํ”ฝ์„ ์ฒ˜๋ฆฌํ•˜๋Š” ๊ฒŒ์ดํŠธ์›จ์ด)์—๋Š” TLS ์ธ์ฆ์„œ/ํ‚ค ์Œ์ด ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค. ์ด ๋น ๋ฅธ ์‹œ์ž‘ ์„ค์น˜์—์„œ๋Š” ์ž์ฒด ์„œ๋ช… ์‚ฌ์šฉ์ž ์ธ์ฆ ์ •๋ณด๋ฅผ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๋‹ค์Œ ๋‹จ๊ณ„์—์„œ๋Š” ์‚ฌ์šฉ์ž ์ธ์ฆ ์ •๋ณด๋ฅผ ์ƒ์„ฑํ•˜๋Š” ๋ฐ openssl์ด ์‚ฌ์šฉ๋ฉ๋‹ˆ๋‹ค.

  1. HELM_CHARTS_HOME/apigee-virtualhost/ ์ฐจํŠธ ๋””๋ ‰ํ„ฐ๋ฆฌ๋กœ ์ด๋™ํ•˜๊ณ  ๋‹ค์Œ ๋ช…๋ น์–ด๋ฅผ ์‹คํ–‰ํ•˜์—ฌ ์ธ์ฆ์„œ ๋ฐ ํ‚ค ํŒŒ์ผ์„ ๋งŒ๋“ญ๋‹ˆ๋‹ค. ์ธ์ฆ์„œ ํŒŒ์ผ์€ ํ™•์žฅ์ž๊ฐ€ .crt ๋˜๋Š” .pem์ผ ๊ฐ€๋Šฅ์„ฑ์ด ๋†’์œผ๋ฉฐ ํ‚ค ํŒŒ์ผ์€ .key์ผ ๊ฐ€๋Šฅ์„ฑ์ด ๋†’์Šต๋‹ˆ๋‹ค.
    openssl req  -nodes -new -x509 -keyout ./certs/keystore.key -out \
        ./certs/keystore.pem -subj '/CN=mydomain.net' -days 3650

    ์ด ๋ช…๋ น์–ด๋Š” ๋น ๋ฅธ ์‹œ์ž‘ ์„ค์น˜์— ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋Š” ์ž์ฒด ์„œ๋ช… ์ธ์ฆ์„œ/ํ‚ค ์Œ์„ ๋งŒ๋“ญ๋‹ˆ๋‹ค. CN mydomain.net์€ ์ž์ฒด ์„œ๋ช… ์‚ฌ์šฉ์ž ์ธ์ฆ ์ •๋ณด๋กœ ์›ํ•˜๋Š” ๋ชจ๋“  ๊ฐ’์ด ๋  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

  2. ํŒŒ์ผ์ด ./certs ๋””๋ ‰ํ„ฐ๋ฆฌ์— ์žˆ๋Š”์ง€ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค.
    ls ./certs
      keystore.pem
      keystore.key

    ์—ฌ๊ธฐ์„œ keystore.pem์€ ์ž์ฒด ์„œ๋ช… TLS ์ธ์ฆ์„œ ํŒŒ์ผ์ด๊ณ  keystore.key๋Š” ํ‚ค ํŒŒ์ผ์ž…๋‹ˆ๋‹ค.