关于Corda中Bridge向Float动态传输truststore及是否需手动复制的问询
Great question! Let’s unpack this discrepancy between the Corda documentation and the Kubernetes deployment configuration you found.
The Core Difference: Deployment Modes
The Corda documentation describes the default, secure deployment model for the Firewall components:
The Bridge dynamically transfers the truststore to the Float, and the Float only stores it in memory (never writing it to disk). This is a security-focused design to avoid sensitive certificate material being persisted locally.
However, the float.conf in the Corda Kubernetes deployment repo is tailored specifically for containerized, orchestrated environments like Kubernetes, which often use volume mounts to manage certificate assets consistently across pods.
Do You Need to Manually Copy the Truststore to Float?
Yes—if you’re using that Kubernetes deployment setup. Here’s why:
- The config explicitly sets
trustStoreFile: "certificates/trust.jks"andsslKeystore: "certificates/float.jks", which tells the Float to load these files from the local filesystem instead of relying on the Bridge’s dynamic transfer. - In this setup, you’ll need to ensure the truststore (and keystore) files are present in the specified directory inside the Float container. This is typically done via Kubernetes volume mounts (mounting a secret or config map that holds the certificates) or via automated CI/CD pipelines that copy the files into the container image or mounted volume.
Optional: Reverting to the Dynamic Truststore Model
If you want to follow the documentation’s secure, in-memory approach instead, you can:
- Remove the
trustStoreFileand related SSL keystore config entries fromfloat.conf. - Ensure the Bridge and Float have proper network connectivity to facilitate the dynamic truststore transfer.
- Adjust any Kubernetes security policies or network policies that might block the communication between Bridge and Float required for this transfer.
内容的提问来源于stack exchange,提问作者Jonathan

