This message was deleted.
# general
s
This message was deleted.
a
@Zixuan Liu I’m following the apache docs and your blogpost, any ideas?
z
could you try bin/pulsar standalone -nfw
a
That works (I can connect and authenticate with a Java client)
z
Could you try Pulsar 3.0.1?
a
I just tried it with Pulsar 3.1.0 and I get the same error as before
Maybe related to this, when I run
./bin/pulsar-admin clusters get standalone
, the information returned contains an empty
serviceUrlTls
and also the authentication related properties are null
z
See this log:
Copy code
2023-08-15T15:23:26,736+0200 [main] INFO  org.apache.pulsar.functions.worker.WorkerUtils - Create Pulsar Admin to service url <http://localhost:8080>: authPlugin = org.apache.pulsar.client.impl.auth.AuthenticationTls, authParams = {"tlsCertFile":"/Users/alex/Desktop/pulsar/apache-pulsar-3.0.0-tls/conf/tls-certs/client.cert.pem","tlsKeyFile":"/Users/alex/Desktop/pulsar/apache-pulsar-3.0.0-tls/conf/tls-certs/client.key-pk8.pem"}, tlsTrustCerts = /Users/alex/Desktop/pulsar/apache-pulsar-3.0.0-tls/conf/tls-certs/ca.cert.pem, allowTlsInsecureConnection = false, enableTlsHostnameVerification = false
service url is incorrect, it should be http://localhost:8081. Could you add
tlsEnabled=true
to
conf/standalone.conf
? And then I think the Pulsar works fine.
a
Yes, I saw it too. I’m wondering why the function worker tries to connect to a different serviceurl, I think that’s a bug
Setting
tlsEnabled=true
(which is also deprecated) gives the same error
I think I solved it
It works now, it is not enough to configure
conf/standalone.conf
but the url and tls settings also have to be set in
conf/functions_woker.yaml
A bit confusing, I was thinking that the settings of the standalone would override this already
✅ 1
z
I check the Pulsar codebase, I think
tlsEnabled=true
should be works fine. I will fix this bug.
a
Thank you 🙂
❤️ 1
z
I made a PR to fix this issue: https://github.com/apache/pulsar/pull/21013, could you review and verify this PR?
🙌 1
a
I had a look and to me the code is looking good but I’m not a committer, so someone else will have to give it a final check
👍 1
a
I'm also having tls issues with cert-manager. Not sure if we can troubleshoot my issues 🙂
z
Same issue? If so, I think my PR can fix your issue! But my PR breaks some tests, I need time to fix that.
a
Not same issue. I'm trying to configure tls using cert-manager and they aren't generated as .pem files but like so in pulsar-tls secret. ca.crt: 1168 bytes tls.crt: 1549 bytes tls.key: 1675 bytes
z
Could you create a issue in the Pulsar repo?