Skip to content

Claude/disable ssl verification - #1376

Merged
arikalon1 merged 6 commits into
masterfrom
claude/disable-ssl-verification-zxfgH
Jan 19, 2026
Merged

arikalon1 merged 6 commits into
masterfrom
claude/disable-ssl-verification-zxfgH

Conversation

@arikalon1

@arikalon1 arikalon1 commented Jan 18, 2026 •

Copy link
Copy Markdown
Collaborator

Summary by CodeRabbit

  • Documentation

    • Updated GitHub Enterprise deployment docs to use https:// hosts and added troubleshooting for SSL certificate verification errors with step‑by‑step deployment examples.
  • New Features

    • Added support for supplying a custom CA certificate for GitHub integrations across deployment methods (Helm and CLI), with configuration examples.

✏️ Tip: You can customize this high-level summary in your review settings.

Add support for disabling SSL certificate verification when connecting
to GitHub Enterprise with self-signed certificates. This adds:

- New `insecure` config option in values.yaml for GitHub MCP addon
- GITHUB_INSECURE environment variable passed to the GitHub MCP server
- Documentation for the SSL verification troubleshooting section

Signed-off-by: Claude <noreply@anthropic.com>
Add support for providing a custom CA certificate when connecting to
GitHub Enterprise with internal/self-signed certificates. This is the
preferred approach over disabling SSL verification.

Changes:
- Add customCACert config section in values.yaml with enabled, secretName,
  and secretKey options
- Update deployment template to mount CA certificate secret and set
  SSL_CERT_FILE and SSL_CERT_DIR environment variables
- Update documentation with comprehensive examples for both custom CA
  (recommended) and insecure mode options

Signed-off-by: Claude <noreply@anthropic.com>
@linux-foundation-easycla

linux-foundation-easycla Bot commented Jan 18, 2026 •

Copy link
Copy Markdown

CLA Not Signed

@netlify

netlify Bot commented Jan 18, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for holmes-docs ready!

Name Link
🔨 Latest commit 27f5f8e
🔍 Latest deploy log https://app.netlify.com/projects/holmes-docs/deploys/696def6220461f000879818b
😎 Deploy Preview https://deploy-preview-1376--holmes-docs.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@github-actions

github-actions Bot commented Jan 18, 2026 •

Copy link
Copy Markdown
Contributor

📂 Previous Runs

📜 Run @ 6458d9b (#21130058328)

✅ Results of HolmesGPT evals

Automatically triggered by commit 6458d9b on branch claude/disable-ssl-verification-zxfgH

View workflow logs

Results of HolmesGPT evals

  • ask_holmes: 9/9 test cases were successful, 0 regressions
Status Test case Time Turns Tools Cost
✅ 09_crashpod 37.3s ↑13% 7 13 $0.1794
✅ 101_loki_historical_logs_pod_deleted 62.0s ↓13% 10 19 $0.2522
✅ 111_pod_names_contain_service 43.9s ±0% 8 16 $0.1916
✅ 12_job_crashing 46.2s ↓13% 8 18 $0.2155
✅ 162_get_runbooks 48.6s ±0% 7 19 $0.2360
✅ 176_network_policy_blocking_traffic_no_runbooks 39.6s ±0% 7 15 $0.1879
✅ 24_misconfigured_pvc 40.3s ±0% 7 18 $0.1838
✅ 43_current_datetime_from_prompt 3.7s ±0% 1 — $0.0618
✅ 61_exact_match_counting 11.0s ↓11% 3 3 $0.0870
Total 36.9s avg 6.4 avg 15.1 avg $1.5951

Time/Cost columns show % change vs historical average (↑slower/costlier, ↓faster/cheaper). Changes under 10% shown as ±0%.

Historical Comparison Details

Filter: excluding branch 'claude/disable-ssl-verification-zxfgH'

Status: Success - 9 test/model combinations loaded

Experiments compared (30):

Comparison indicators:

  • ±0% — diff under 10% (within noise threshold)
  • ↑N%/↓N% — diff 10-25%
  • ↑N%/↓N% — diff over 25% (significant)
📜 Run @ 99e3202 (#21120731188)

✅ Results of HolmesGPT evals

Automatically triggered by commit 99e3202 on branch claude/disable-ssl-verification-zxfgH

View workflow logs

Results of HolmesGPT evals

  • ask_holmes: 9/9 test cases were successful, 0 regressions
Status Test case Time Turns Tools Cost
✅ 09_crashpod 31.7s ±0% 6 13 $0.1699
✅ 101_loki_historical_logs_pod_deleted 51.9s ±0% 8 17 $0.2184
✅ 111_pod_names_contain_service 40.9s ±0% 8 20 $0.2029
✅ 12_job_crashing 48.7s ±0% 9 20 $0.2378
✅ 162_get_runbooks 45.0s ±0% 7 15 $0.2275
✅ 176_network_policy_blocking_traffic_no_runbooks 36.3s ±0% 6 14 $0.1846
✅ 24_misconfigured_pvc 38.8s ↑15% 8 18 $0.1925
✅ 43_current_datetime_from_prompt 3.3s ±0% 1 — $0.0618
✅ 61_exact_match_counting 9.8s ±0% 3 3 $0.0858
Total 34.0s avg 6.2 avg 15.0 avg $1.5811

Time/Cost columns show % change vs historical average (↑slower/costlier, ↓faster/cheaper). Changes under 10% shown as ±0%.

Historical Comparison Details

Filter: excluding branch 'claude/disable-ssl-verification-zxfgH'

Status: Success - 20 test/model combinations loaded

Experiments compared (30):

Comparison indicators:

  • ±0% — diff under 10% (within noise threshold)
  • ↑N%/↓N% — diff 10-25%
  • ↑N%/↓N% — diff over 25% (significant)
📜 Run @ a13cc7a (#21120647097)

✅ Results of HolmesGPT evals

Automatically triggered by commit a13cc7a on branch claude/disable-ssl-verification-zxfgH

View workflow logs

Results of HolmesGPT evals

  • ask_holmes: 9/9 test cases were successful, 0 regressions
Status Test case Time Turns Tools Cost
✅ 09_crashpod 30.5s ±0% 6 13 $0.1677
✅ 101_loki_historical_logs_pod_deleted 71.5s ↑49% 12 26 $0.2978
✅ 111_pod_names_contain_service 32.5s ↓16% 6 15 $0.1644
✅ 12_job_crashing 48.8s ±0% 9 21 $0.2441
✅ 162_get_runbooks 42.7s ±0% 7 18 $0.2183
✅ 176_network_policy_blocking_traffic_no_runbooks 36.1s ±0% 6 16 $0.1885
✅ 24_misconfigured_pvc 29.2s ↓13% 6 15 $0.1570
✅ 43_current_datetime_from_prompt 2.8s ↓12% 1 — $0.0618
✅ 61_exact_match_counting 9.3s ±0% 3 3 $0.0859
Total 33.7s avg 6.2 avg 15.9 avg $1.5855

Time/Cost columns show % change vs historical average (↑slower/costlier, ↓faster/cheaper). Changes under 10% shown as ±0%.

Historical Comparison Details

Filter: excluding branch 'claude/disable-ssl-verification-zxfgH'

Status: Success - 20 test/model combinations loaded

Experiments compared (30):

Comparison indicators:

  • ±0% — diff under 10% (within noise threshold)
  • ↑N%/↓N% — diff 10-25%
  • ↑N%/↓N% — diff over 25% (significant)

✅ Results of HolmesGPT evals

Automatically triggered by commit 27f5f8e on branch claude/disable-ssl-verification-zxfgH

View workflow logs

Results of HolmesGPT evals

  • ask_holmes: 9/9 test cases were successful, 0 regressions
Status Test case Time Turns Tools Cost
✅ 09_crashpod 30.1s ±0% 5 11 $0.1002
✅ 101_loki_historical_logs_pod_deleted 63.9s ±0% 10 21 $0.1914
✅ 111_pod_names_contain_service 42.5s ±0% 8 16 $0.1383
✅ 12_job_crashing 46.9s ↓12% 8 18 $0.1585
✅ 162_get_runbooks 44.0s ±0% 7 15 $0.1549
✅ 176_network_policy_blocking_traffic_no_runbooks 39.1s ±0% 6 15 $0.1343
✅ 24_misconfigured_pvc 38.4s ±0% 7 17 $0.1285
✅ 43_current_datetime_from_prompt 3.5s ±0% 1 — $0.0085
✅ 61_exact_match_counting 10.5s ↓14% 3 3 $0.0324
Total 35.4s avg 6.1 avg 14.5 avg $1.0471

Time/Cost columns show % change vs historical average (↑slower/costlier, ↓faster/cheaper). Changes under 10% shown as ±0%.

Historical Comparison Details

Filter: excluding branch 'claude/disable-ssl-verification-zxfgH'

Status: Success - 9 test/model combinations loaded

Experiments compared (30):

Comparison indicators:

  • ±0% — diff under 10% (within noise threshold)
  • ↑N%/↓N% — diff 10-25%
  • ↑N%/↓N% — diff over 25% (significant)
📖 Legend
Icon Meaning
✅ The test was successful
➖ The test was skipped
⚠️ The test failed but is known to be flaky or known to fail
🚧 The test had a setup failure (not a code regression)
🔧 The test failed due to mock data issues (not a code regression)
🚫 The test was throttled by API rate limits/overload
❌ The test failed and should be fixed before merging the PR
🔄 Re-run evals manually

⚠️ Warning: /eval comments always run using the workflow from master, not from this PR branch. If you modified the GitHub Action (e.g., added secrets or env vars), those changes won't take effect.

To test workflow changes, use the GitHub CLI or Actions UI instead:

gh workflow run eval-regression.yaml --repo HolmesGPT/holmesgpt --ref claude/disable-ssl-verification-zxfgH -f markers=regression -f filter=

Option 1: Comment on this PR with /eval:

/eval
markers: regression

Or with more options (one per line):

/eval
model: gpt-4o
markers: regression
filter: 09_crashpod
iterations: 5

Run evals on a different branch (e.g., master) for comparison:

/eval
branch: master
markers: regression
Option Description
model Model(s) to test (default: same as automatic runs)
markers Pytest markers (no default - runs all tests!)
filter Pytest -k filter (use /list to see valid eval names)
iterations Number of runs, max 10
branch Run evals on a different branch (for cross-branch comparison)

Quick re-run: Use /rerun to re-run the most recent /eval on this PR with the same parameters.

Option 2: Trigger via GitHub Actions UI → "Run workflow"

🏷️ Valid markers

benchmark, chain-of-causation, compaction, context_window, coralogix, counting, database, datadog, datetime, easy, elasticsearch, embeds, frontend, grafana-dashboard, hard, kafka, kubernetes, leaked-information, logs, loki, medium, metrics, network, newrelic, no-cicd, numerical, one-test, port-forward, prometheus, question-answer, regression, runbooks, slackbot, storage, toolset-limitation, traces, transparency


Commands: /eval · /rerun · /list

CLI: gh workflow run eval-regression.yaml --repo HolmesGPT/holmesgpt --ref claude/disable-ssl-verification-zxfgH -f markers=regression -f filter=

@github-actions

github-actions Bot commented Jan 18, 2026 •

Copy link
Copy Markdown
Contributor

✅ Docker image ready for 2d54e0e (built in 55s)

⚠️ Warning: does not support ARM (ARM images are built on release only - not on every PR)

Use this tag to pull the image for testing.

📋 Copy commands

⚠️ Temporary images are deleted after 30 days. Copy to a permanent registry before using them:

gcloud auth configure-docker us-central1-docker.pkg.dev
docker pull us-central1-docker.pkg.dev/robusta-development/temporary-builds/holmes:2d54e0e
docker tag us-central1-docker.pkg.dev/robusta-development/temporary-builds/holmes:2d54e0e me-west1-docker.pkg.dev/robusta-development/development/holmes-dev:2d54e0e
docker push me-west1-docker.pkg.dev/robusta-development/development/holmes-dev:2d54e0e

Patch Helm values in one line (choose the chart you use):

HolmesGPT chart:

helm upgrade --install holmesgpt ./helm/holmes \
  --set registry=me-west1-docker.pkg.dev/robusta-development/development \
  --set image=holmes-dev:2d54e0e

Robusta wrapper chart:

helm upgrade --install robusta robusta/robusta \
  --reuse-values \
  --set holmes.registry=me-west1-docker.pkg.dev/robusta-development/development \
  --set holmes.image=holmes-dev:2d54e0e

@coderabbitai

coderabbitai Bot commented Jan 18, 2026 •

Copy link
Copy Markdown
Contributor

Walkthrough

Adds documentation and Helm values/templates to support providing a custom CA certificate for GitHub Enterprise MCP connectivity by mounting a CA secret and setting SSL_CERT_FILE / SSL_CERT_DIR in the GitHub MCP server container; also normalizes host entries to include https://.

Changes

Cohort / File(s) Summary
Documentation
docs/data-sources/builtin-toolsets/github-mcp.md
Add "SSL Certificate Verification Errors" troubleshooting section; instructions to create a Kubernetes secret with org CA; sample YAML for Holmes Helm, Robusta Helm, and Holmes CLI; update host examples to use https://.
Helm Deployment Template
helm/holmes/templates/mcp-servers/github/deployment.yaml
Conditionally set SSL_CERT_FILE and SSL_CERT_DIR env vars when .Values.mcpAddons.github.config.customCACert.enabled is true; add conditional ca-cert volumeMount at /etc/ssl/certs; add secret-backed ca-cert volume with secretName and defaultMode.
Helm Values
helm/holmes/values.yaml
Change GitHub host examples to https://...; add mcpAddons.github.config.customCACert block (enabled, secretName, secretKey); adjust toolsets representation to explicit string plus tools field.

Sequence Diagram(s)

(omitted — changes are configuration/deployment wiring without new multi-component control flow requiring a sequence diagram)

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related PRs

Suggested reviewers

  • RoiGlinik
  • Avi-Robusta
🚥 Pre-merge checks | ✅ 2 | ❌ 1
❌ Failed checks (1 warning)
Check name Status Explanation Resolution
Title check ⚠️ Warning The title 'Claude/disable ssl verification' is misleading. The changes actually add support for custom CA certificate configuration, not disable SSL verification. Update the title to accurately reflect the main change, such as 'Add custom CA certificate support for GitHub MCP server' or 'Enable SSL certificate configuration for GitHub Enterprise'.
✅ Passed checks (2 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

The GITHUB_INSECURE environment variable is not supported by the
upstream GitHub MCP server. Remove this option from the Helm chart
and documentation. Users should use the custom CA certificate option
instead.

Signed-off-by: Claude <noreply@anthropic.com>

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Fix all issues with AI agents
In `@helm/holmes/templates/mcp-servers/github/deployment.yaml`:
- Around line 122-134: The Helm template mounts the CA secret onto
/etc/ssl/certs which hides system CAs; change the mount to a dedicated path
(e.g., mountPath: /etc/ssl/custom-certs) or use a subPath on the secret instead
of replacing the whole directory (update the volumeMounts block guarded by
.Values.mcpAddons.github.config.customCACert.enabled and keep the volumes
secretName reference intact), and add/adjust an environment variable (e.g.,
SSL_CERT_FILE or equivalent used by the app) to point to the new certificate
file location so the process uses both system and custom CAs without overwriting
/etc/ssl/certs.
🧹 Nitpick comments (2)
helm/holmes/templates/mcp-servers/github/deployment.yaml (2)

100-109: Potential nil pointer error when customCACert block is undefined.

If a user has an older values.yaml without the customCACert block entirely, accessing .Values.mcpAddons.github.config.customCACert.enabled on line 104 could cause a template rendering error.

Consider using a safer access pattern:

♻️ Proposed fix for safer nil access
         {{- if .Values.mcpAddons.github.config.insecure }}
         - name: GITHUB_INSECURE
           value: "true"
         {{- end }}
-        {{- if .Values.mcpAddons.github.config.customCACert.enabled }}
+        {{- if and .Values.mcpAddons.github.config.customCACert .Values.mcpAddons.github.config.customCACert.enabled }}
         - name: SSL_CERT_FILE
           value: /etc/ssl/certs/{{ .Values.mcpAddons.github.config.customCACert.secretKey | default "ca.crt" }}
         - name: SSL_CERT_DIR
           value: /etc/ssl/certs
         {{- end }}

122-127: Apply same nil-safe access pattern here.

Lines 122 and 128 have the same potential nil pointer issue as the environment variables section. Use the safer access pattern:

-        {{- if .Values.mcpAddons.github.config.customCACert.enabled }}
+        {{- if and .Values.mcpAddons.github.config.customCACert .Values.mcpAddons.github.config.customCACert.enabled }}

Comment thread helm/holmes/templates/mcp-servers/github/deployment.yaml
- Add default values for secretName ("github-ca-cert") and secretKey ("ca.crt")
- Remove redundant default assignments in deployment template
- Remove remaining mention of insecure mode in docs
- Simplify documentation examples to show defaults as comments

Signed-off-by: Claude <noreply@anthropic.com>
@arikalon1 arikalon1 changed the title Claude/disable ssl verification zxfg h Claude/disable ssl verification Jan 18, 2026
Signed-off-by: Arik Alon <alon.arik@gmail.com>
@arikalon1
arikalon1 enabled auto-merge (squash) January 19, 2026 08:48
@arikalon1
arikalon1 merged commit 48a7297 into master Jan 19, 2026
15 of 17 checks passed
@arikalon1
arikalon1 deleted the claude/disable-ssl-verification-zxfgH branch January 19, 2026 08:51
naomi-robusta pushed a commit that referenced this pull request Jan 21, 2026
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Added troubleshooting for SSL certificate verification errors with
GitHub Enterprise, plus step‑by‑step deployment examples and updated
host examples to use https://.

* **New Features**
* Support for supplying a custom CA certificate to GitHub MCP
deployments across deployment methods.
* Option to bypass SSL certificate verification for self‑signed/internal
CA setups.

<sub>✏️ Tip: You can customize this high-level summary in your review
settings.</sub>
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Signed-off-by: Claude <noreply@anthropic.com>
Signed-off-by: Arik Alon <alon.arik@gmail.com>
Co-authored-by: Claude <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants