Skip to content
Closed
Show file tree
Hide file tree
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Prev Previous commit
Next Next commit
Support RefreshOnlyWhenExpired mode in ManageCSRCABundle
  • Loading branch information
vrutkovs committed Sep 24, 2025
commit f835f28b2d0b6888abde2a44a8f96ea7a6bf95bd
2 changes: 1 addition & 1 deletion pkg/cmd/recoverycontroller/csrcontroller.go
Original file line number Diff line number Diff line change
Expand Up @@ -172,7 +172,7 @@ func (c *CSRController) sync(ctx context.Context) error {
klog.Info("Refreshed CSRIntermediateCABundle.")
}

_, changed, err = targetconfigcontroller.ManageCSRCABundle(ctx, c.configMapLister, c.kubeClient.CoreV1(), c.eventRecorder)
_, changed, err = targetconfigcontroller.ManageCSRCABundle(ctx, c.configMapLister, c.kubeClient.CoreV1(), c.eventRecorder, true)
if err != nil {
return err
}
Expand Down
6 changes: 3 additions & 3 deletions pkg/operator/targetconfigcontroller/targetconfigcontroller.go
Original file line number Diff line number Diff line change
Expand Up @@ -222,7 +222,7 @@ func createTargetConfigController(ctx context.Context, syncCtx factory.SyncConte
if err != nil {
errors = append(errors, fmt.Errorf("%q: %v", "configmap/csr-intermediate-ca", err))
}
_, _, err = ManageCSRCABundle(ctx, c.configMapLister, c.kubeClient.CoreV1(), syncCtx.Recorder())
_, _, err = ManageCSRCABundle(ctx, c.configMapLister, c.kubeClient.CoreV1(), syncCtx.Recorder(), false)
if err != nil {
errors = append(errors, fmt.Errorf("%q: %v", "configmap/csr-controller-ca", err))
}
Expand Down Expand Up @@ -744,7 +744,7 @@ func manageServiceAccountCABundle(ctx context.Context, lister corev1listers.Conf
return caBundleConfigMap, false, nil
}

func ManageCSRCABundle(ctx context.Context, lister corev1listers.ConfigMapLister, client corev1client.ConfigMapsGetter, recorder events.Recorder) (*corev1.ConfigMap, bool, error) {
func ManageCSRCABundle(ctx context.Context, lister corev1listers.ConfigMapLister, client corev1client.ConfigMapsGetter, recorder events.Recorder, refreshOnlyWhenExpired bool) (*corev1.ConfigMap, bool, error) {
additionalAnnotations := certrotation.AdditionalAnnotations{
JiraComponent: "kube-controller-manager",
Description: "CA to recognize the CSRs (both serving and client) signed by the kube-controller-manager.",
Expand Down Expand Up @@ -788,7 +788,7 @@ func ManageCSRCABundle(ctx context.Context, lister corev1listers.ConfigMapLister
}
klog.V(2).Infof("Created CSR CA bundle configmap %s/%s", caBundleConfigMap.Namespace, caBundleConfigMap.Name)
return caBundleConfigMap, true, nil
} else if updateRequired {
} else if updateRequired && !refreshOnlyWhenExpired {
caBundleConfigMap, err = client.ConfigMaps(operatorclient.OperatorNamespace).Update(ctx, requiredConfigMap, metav1.UpdateOptions{})
resourcehelper.ReportUpdateEvent(recorder, caBundleConfigMap, err)
if err != nil {
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -1049,7 +1049,7 @@ func TestManageCSRCABundle(t *testing.T) {
recorder := events.NewInMemoryRecorder("test", clock.RealClock{})

// Call the function under test
resultConfigMap, changed, err := ManageCSRCABundle(context.Background(), lister, client.CoreV1(), recorder)
resultConfigMap, changed, err := ManageCSRCABundle(context.Background(), lister, client.CoreV1(), recorder, false)

// Assert error expectations
require.NoError(t, err)
Expand Down

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.