Claude/disable ssl verification - #1376
Conversation
Add support for disabling SSL certificate verification when connecting to GitHub Enterprise with self-signed certificates. This adds: - New `insecure` config option in values.yaml for GitHub MCP addon - GITHUB_INSECURE environment variable passed to the GitHub MCP server - Documentation for the SSL verification troubleshooting section Signed-off-by: Claude <noreply@anthropic.com>
Add support for providing a custom CA certificate when connecting to GitHub Enterprise with internal/self-signed certificates. This is the preferred approach over disabling SSL verification. Changes: - Add customCACert config section in values.yaml with enabled, secretName, and secretKey options - Update deployment template to mount CA certificate secret and set SSL_CERT_FILE and SSL_CERT_DIR environment variables - Update documentation with comprehensive examples for both custom CA (recommended) and insecure mode options Signed-off-by: Claude <noreply@anthropic.com>
|
✅ Deploy Preview for holmes-docs ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
📂 Previous Runs📜 Run @ 6458d9b (#21130058328)✅ Results of HolmesGPT evalsAutomatically triggered by commit 6458d9b on branch Results of HolmesGPT evals
Time/Cost columns show % change vs historical average (↑slower/costlier, ↓faster/cheaper). Changes under 10% shown as ±0%. Historical Comparison DetailsFilter: excluding branch 'claude/disable-ssl-verification-zxfgH' Status: Success - 9 test/model combinations loaded Experiments compared (30):
Comparison indicators:
📜 Run @ 99e3202 (#21120731188)✅ Results of HolmesGPT evalsAutomatically triggered by commit 99e3202 on branch Results of HolmesGPT evals
Time/Cost columns show % change vs historical average (↑slower/costlier, ↓faster/cheaper). Changes under 10% shown as ±0%. Historical Comparison DetailsFilter: excluding branch 'claude/disable-ssl-verification-zxfgH' Status: Success - 20 test/model combinations loaded Experiments compared (30):
Comparison indicators:
📜 Run @ a13cc7a (#21120647097)✅ Results of HolmesGPT evalsAutomatically triggered by commit a13cc7a on branch Results of HolmesGPT evals
Time/Cost columns show % change vs historical average (↑slower/costlier, ↓faster/cheaper). Changes under 10% shown as ±0%. Historical Comparison DetailsFilter: excluding branch 'claude/disable-ssl-verification-zxfgH' Status: Success - 20 test/model combinations loaded Experiments compared (30):
Comparison indicators:
✅ Results of HolmesGPT evalsAutomatically triggered by commit 27f5f8e on branch Results of HolmesGPT evals
Time/Cost columns show % change vs historical average (↑slower/costlier, ↓faster/cheaper). Changes under 10% shown as ±0%. Historical Comparison DetailsFilter: excluding branch 'claude/disable-ssl-verification-zxfgH' Status: Success - 9 test/model combinations loaded Experiments compared (30):
Comparison indicators:
📖 Legend
🔄 Re-run evals manually
Option 1: Comment on this PR with Or with more options (one per line): Run evals on a different branch (e.g., master) for comparison:
Quick re-run: Use Option 2: Trigger via GitHub Actions UI → "Run workflow" 🏷️ Valid markers
Commands: CLI: |
|
✅ Docker image ready for
Use this tag to pull the image for testing. 📋 Copy commandsgcloud auth configure-docker us-central1-docker.pkg.dev
docker pull us-central1-docker.pkg.dev/robusta-development/temporary-builds/holmes:2d54e0e
docker tag us-central1-docker.pkg.dev/robusta-development/temporary-builds/holmes:2d54e0e me-west1-docker.pkg.dev/robusta-development/development/holmes-dev:2d54e0e
docker push me-west1-docker.pkg.dev/robusta-development/development/holmes-dev:2d54e0ePatch Helm values in one line (choose the chart you use): HolmesGPT chart: helm upgrade --install holmesgpt ./helm/holmes \
--set registry=me-west1-docker.pkg.dev/robusta-development/development \
--set image=holmes-dev:2d54e0eRobusta wrapper chart: helm upgrade --install robusta robusta/robusta \
--reuse-values \
--set holmes.registry=me-west1-docker.pkg.dev/robusta-development/development \
--set holmes.image=holmes-dev:2d54e0e |
WalkthroughAdds documentation and Helm values/templates to support providing a custom CA certificate for GitHub Enterprise MCP connectivity by mounting a CA secret and setting SSL_CERT_FILE / SSL_CERT_DIR in the GitHub MCP server container; also normalizes host entries to include https://. Changes
Sequence Diagram(s)(omitted — changes are configuration/deployment wiring without new multi-component control flow requiring a sequence diagram) Estimated code review effort🎯 3 (Moderate) | ⏱️ ~20 minutes Possibly related PRs
Suggested reviewers
🚥 Pre-merge checks | ✅ 2 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (2 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
The GITHUB_INSECURE environment variable is not supported by the upstream GitHub MCP server. Remove this option from the Helm chart and documentation. Users should use the custom CA certificate option instead. Signed-off-by: Claude <noreply@anthropic.com>
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Fix all issues with AI agents
In `@helm/holmes/templates/mcp-servers/github/deployment.yaml`:
- Around line 122-134: The Helm template mounts the CA secret onto
/etc/ssl/certs which hides system CAs; change the mount to a dedicated path
(e.g., mountPath: /etc/ssl/custom-certs) or use a subPath on the secret instead
of replacing the whole directory (update the volumeMounts block guarded by
.Values.mcpAddons.github.config.customCACert.enabled and keep the volumes
secretName reference intact), and add/adjust an environment variable (e.g.,
SSL_CERT_FILE or equivalent used by the app) to point to the new certificate
file location so the process uses both system and custom CAs without overwriting
/etc/ssl/certs.
🧹 Nitpick comments (2)
helm/holmes/templates/mcp-servers/github/deployment.yaml (2)
100-109: Potential nil pointer error whencustomCACertblock is undefined.If a user has an older
values.yamlwithout thecustomCACertblock entirely, accessing.Values.mcpAddons.github.config.customCACert.enabledon line 104 could cause a template rendering error.Consider using a safer access pattern:
♻️ Proposed fix for safer nil access
{{- if .Values.mcpAddons.github.config.insecure }} - name: GITHUB_INSECURE value: "true" {{- end }} - {{- if .Values.mcpAddons.github.config.customCACert.enabled }} + {{- if and .Values.mcpAddons.github.config.customCACert .Values.mcpAddons.github.config.customCACert.enabled }} - name: SSL_CERT_FILE value: /etc/ssl/certs/{{ .Values.mcpAddons.github.config.customCACert.secretKey | default "ca.crt" }} - name: SSL_CERT_DIR value: /etc/ssl/certs {{- end }}
122-127: Apply same nil-safe access pattern here.Lines 122 and 128 have the same potential nil pointer issue as the environment variables section. Use the safer access pattern:
- {{- if .Values.mcpAddons.github.config.customCACert.enabled }} + {{- if and .Values.mcpAddons.github.config.customCACert .Values.mcpAddons.github.config.customCACert.enabled }}
- Add default values for secretName ("github-ca-cert") and secretKey ("ca.crt")
- Remove redundant default assignments in deployment template
- Remove remaining mention of insecure mode in docs
- Simplify documentation examples to show defaults as comments
Signed-off-by: Claude <noreply@anthropic.com>
<!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added troubleshooting for SSL certificate verification errors with GitHub Enterprise, plus step‑by‑step deployment examples and updated host examples to use https://. * **New Features** * Support for supplying a custom CA certificate to GitHub MCP deployments across deployment methods. * Option to bypass SSL certificate verification for self‑signed/internal CA setups. <sub>✏️ Tip: You can customize this high-level summary in your review settings.</sub> <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Signed-off-by: Claude <noreply@anthropic.com> Signed-off-by: Arik Alon <alon.arik@gmail.com> Co-authored-by: Claude <noreply@anthropic.com>
Summary by CodeRabbit
Documentation
New Features
✏️ Tip: You can customize this high-level summary in your review settings.