Commit 1214dab
tazhate
feat(helm): optional cert-manager integration for validating webhook
Chart shipped a ValidatingWebhookConfiguration but had no way to provide
TLS certs to the operator, so the webhook silently no-op'd ("TLS certs
not found, running without admission validation") and any kubectl create
of a ChainInstance failed with "connection refused" against the webhook
service. Adds webhook.certManager.enabled flag that provisions a
self-signed Issuer + Certificate, mounts the resulting Secret, passes
--webhook-cert-path/--webhook-cert-name/--webhook-cert-key to the
manager, and annotates the webhook with cert-manager.io/inject-ca-from
so the caBundle is populated automatically.
Context: tried to apply a small bitcoin ChainInstance against a freshly
installed v0.2.3 release and hit the webhook connection refused error,
inspected the manager logs (cert-dir empty), checked cert-manager was
present in the cluster (it was) and wired up the standard self-signed
flow used by kubebuilder/operator-sdk projects. Verified end-to-end by
upgrading the release with the new flag, confirming the cert/issuer
went Ready and the bitcoin-test instance reconciled into a Running
StatefulSet with PVC and started syncing block headers. Took ~30min.1 parent 067e9dd commit 1214dab
4 files changed
Lines changed: 75 additions & 4 deletions
File tree
- charts/chainplane
- templates
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
60 | 60 | | |
61 | 61 | | |
62 | 62 | | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
63 | 67 | | |
64 | 68 | | |
65 | 69 | | |
| |||
121 | 125 | | |
122 | 126 | | |
123 | 127 | | |
124 | | - | |
| 128 | + | |
125 | 129 | | |
126 | | - | |
| 130 | + | |
| 131 | + | |
| 132 | + | |
| 133 | + | |
| 134 | + | |
| 135 | + | |
| 136 | + | |
| 137 | + | |
127 | 138 | | |
128 | | - | |
| 139 | + | |
129 | 140 | | |
130 | | - | |
| 141 | + | |
| 142 | + | |
| 143 | + | |
| 144 | + | |
| 145 | + | |
| 146 | + | |
| 147 | + | |
| 148 | + | |
131 | 149 | | |
132 | 150 | | |
133 | 151 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
5 | 5 | | |
6 | 6 | | |
7 | 7 | | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
8 | 12 | | |
9 | 13 | | |
10 | 14 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
123 | 123 | | |
124 | 124 | | |
125 | 125 | | |
| 126 | + | |
| 127 | + | |
| 128 | + | |
| 129 | + | |
| 130 | + | |
| 131 | + | |
| 132 | + | |
| 133 | + | |
| 134 | + | |
126 | 135 | | |
127 | 136 | | |
128 | 137 | | |
| |||
0 commit comments