From 489fbf49e3d4c587b7ff640969c0fa086863b29d Mon Sep 17 00:00:00 2001 From: Grace Cai Date: Fri, 5 Dec 2025 17:23:15 +0800 Subject: [PATCH 1/4] Add temp.md --- temp.md | 1 + 1 file changed, 1 insertion(+) create mode 100644 temp.md diff --git a/temp.md b/temp.md new file mode 100644 index 000000000000..af27ff4986a7 --- /dev/null +++ b/temp.md @@ -0,0 +1 @@ +This is a test file. \ No newline at end of file From e26e2495b88a2b6f6d9ebf5f03b93d199efcfdfa Mon Sep 17 00:00:00 2001 From: Grace Cai Date: Fri, 5 Dec 2025 17:23:20 +0800 Subject: [PATCH 2/4] Delete temp.md --- temp.md | 1 - 1 file changed, 1 deletion(-) delete mode 100644 temp.md diff --git a/temp.md b/temp.md deleted file mode 100644 index af27ff4986a7..000000000000 --- a/temp.md +++ /dev/null @@ -1 +0,0 @@ -This is a test file. \ No newline at end of file From 4b1ed8305831a8d49036e72211324f65a0c5f5e4 Mon Sep 17 00:00:00 2001 From: qiancai Date: Fri, 5 Dec 2025 17:29:31 +0800 Subject: [PATCH 3/4] add translation --- enable-tls-between-components.md | 3 +++ tiproxy/tiproxy-configuration.md | 4 ++++ 2 files changed, 7 insertions(+) diff --git a/enable-tls-between-components.md b/enable-tls-between-components.md index 45a5574e0091..9858236ab78b 100644 --- a/enable-tls-between-components.md +++ b/enable-tls-between-components.md @@ -246,6 +246,9 @@ aliases: ['/docs-cn/dev/enable-tls-between-components/','/docs-cn/dev/how-to/sec ## 证书重新加载 - 如果 TiDB 集群部署在本地的数据中心,TiDB、PD、TiKV、TiFlash、TiCDC、TiProxy 和各种 client 在每次新建相互通讯的连接时都会重新读取当前的证书和密钥文件内容,实现证书和密钥的重新加载,无需重启 TiDB 集群。 + +- TiProxy 每小时会从磁盘重新加载一次证书。 + - 如果 TiDB 集群部署在自己管理的 Cloud,TLS 证书的签发需要与云服务商的证书管理服务集成,TiDB、PD、TiKV、TiFlash、TiCDC、TiProxy 组件的 TLS 证书支持自动轮换,无需重启 TiDB 集群。 ## 证书有效期 diff --git a/tiproxy/tiproxy-configuration.md b/tiproxy/tiproxy-configuration.md index 43c046f0a5a1..93ccc7a73433 100644 --- a/tiproxy/tiproxy-configuration.md +++ b/tiproxy/tiproxy-configuration.md @@ -222,6 +222,10 @@ server_configs: ### security +> **注意:** +> +> TiProxy 每小时会从磁盘重新加载一次证书。因此,磁盘上证书文件的变更最多可能需要一小时才能生效。 + 在 `[security]` 部分有四个名称不同的 TLS 对象,它们共享相同的配置格式和字段,但是不同名称对象的字段解释可能不同。 ```toml From f3685a66ceab5d45ec0662cbf64fa48a59d6fe05 Mon Sep 17 00:00:00 2001 From: Grace Cai Date: Tue, 9 Dec 2025 16:59:27 +0800 Subject: [PATCH 4/4] Update enable-tls-between-components.md Co-authored-by: Aolin --- enable-tls-between-components.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/enable-tls-between-components.md b/enable-tls-between-components.md index 9858236ab78b..ec9f77a136f5 100644 --- a/enable-tls-between-components.md +++ b/enable-tls-between-components.md @@ -245,7 +245,7 @@ aliases: ['/docs-cn/dev/enable-tls-between-components/','/docs-cn/dev/how-to/sec ## 证书重新加载 -- 如果 TiDB 集群部署在本地的数据中心,TiDB、PD、TiKV、TiFlash、TiCDC、TiProxy 和各种 client 在每次新建相互通讯的连接时都会重新读取当前的证书和密钥文件内容,实现证书和密钥的重新加载,无需重启 TiDB 集群。 +- 如果 TiDB 集群部署在本地的数据中心,TiDB、PD、TiKV、TiFlash、TiCDC 和各种 client 在每次新建相互通讯的连接时都会重新读取当前的证书和密钥文件内容,实现证书和密钥的重新加载,无需重启 TiDB 集群。 - TiProxy 每小时会从磁盘重新加载一次证书。