Skip to content

switch controller manager to secure port#207

Merged
openshift-merge-robot merged 1 commit intoopenshift:masterfrom
mfojtik:switch-to-secure-port
Apr 4, 2019
Merged

switch controller manager to secure port#207
openshift-merge-robot merged 1 commit intoopenshift:masterfrom
mfojtik:switch-to-secure-port

Conversation

@mfojtik
Copy link
Copy Markdown
Contributor

@mfojtik mfojtik commented Apr 3, 2019

Rebase landed, we should switch the port to secure again. This updates controller manager default config and set the insecure port to 0 and also update the init container to check the secure port.

Also sets the cert-dir to /var/run/kubernetes.

@openshift-ci-robot openshift-ci-robot added approved Indicates a PR has been approved by an approver from all required OWNERS files. size/S Denotes a PR that changes 10-29 lines, ignoring generated files. labels Apr 3, 2019
@mfojtik mfojtik force-pushed the switch-to-secure-port branch from 662f92b to 4d54ada Compare April 3, 2019 09:18
@sttts
Copy link
Copy Markdown
Contributor

sttts commented Apr 3, 2019

/lgtm

@openshift-ci-robot openshift-ci-robot added the lgtm Indicates that a PR is ready to be merged. label Apr 3, 2019
@mfojtik mfojtik force-pushed the switch-to-secure-port branch from 4d54ada to 57a1bfa Compare April 3, 2019 10:30
@openshift-ci-robot
Copy link
Copy Markdown

New changes are detected. LGTM label has been removed.

@openshift-ci-robot openshift-ci-robot added size/M Denotes a PR that changes 30-99 lines, ignoring generated files. and removed lgtm Indicates that a PR is ready to be merged. size/S Denotes a PR that changes 10-29 lines, ignoring generated files. labels Apr 3, 2019
@mfojtik mfojtik added the lgtm Indicates that a PR is ready to be merged. label Apr 3, 2019
@mfojtik
Copy link
Copy Markdown
Contributor Author

mfojtik commented Apr 3, 2019

adding lgtm back, fixed the liveness probe port

@mfojtik
Copy link
Copy Markdown
Contributor Author

mfojtik commented Apr 3, 2019

/retest

@openshift-bot
Copy link
Copy Markdown
Contributor

/retest

Please review the full test history for this PR and help us cut down flakes.

1 similar comment
@openshift-bot
Copy link
Copy Markdown
Contributor

/retest

Please review the full test history for this PR and help us cut down flakes.

@soltysh
Copy link
Copy Markdown
Contributor

soltysh commented Apr 3, 2019

/retest

@openshift-ci-robot
Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: mfojtik, soltysh, sttts

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@mfojtik
Copy link
Copy Markdown
Contributor Author

mfojtik commented Apr 4, 2019

/retest

@soltysh
Copy link
Copy Markdown
Contributor

soltysh commented Apr 4, 2019

/hold
we need openshift/origin#22476 first and than we can land this.

@openshift-ci-robot openshift-ci-robot added the do-not-merge/hold Indicates that a PR should not merge because someone has issued a /hold command. label Apr 4, 2019
@soltysh
Copy link
Copy Markdown
Contributor

soltysh commented Apr 4, 2019

/hold cancel
/retest

@openshift-ci-robot openshift-ci-robot removed the do-not-merge/hold Indicates that a PR should not merge because someone has issued a /hold command. label Apr 4, 2019
@sttts
Copy link
Copy Markdown
Contributor

sttts commented Apr 4, 2019

/assign @s-urbaniak

This also needs a change on the monitoring side.

@s-urbaniak
Copy link
Copy Markdown
Contributor

/cc @s-urbaniak

@openshift-bot
Copy link
Copy Markdown
Contributor

/retest

Please review the full test history for this PR and help us cut down flakes.

1 similar comment
@openshift-bot
Copy link
Copy Markdown
Contributor

/retest

Please review the full test history for this PR and help us cut down flakes.

@openshift-merge-robot openshift-merge-robot merged commit b80336d into openshift:master Apr 4, 2019
s-urbaniak added a commit to s-urbaniak/cluster-monitoring-operator that referenced this pull request Apr 5, 2019
s-urbaniak added a commit to s-urbaniak/cluster-monitoring-operator that referenced this pull request Apr 5, 2019
@sttts
Copy link
Copy Markdown
Contributor

sttts commented Apr 5, 2019

/retest

s-urbaniak added a commit to s-urbaniak/cluster-monitoring-operator that referenced this pull request Apr 8, 2019
In accordance to
openshift/cluster-kube-controller-manager-operator#207
we can now enable TLS for the controller manager.
s-urbaniak added a commit to s-urbaniak/cluster-monitoring-operator that referenced this pull request Apr 10, 2019
s-urbaniak added a commit to s-urbaniak/installer that referenced this pull request Apr 10, 2019
Recently, the control plane switched to secure ports in [1] and [2].
This aligns them in the installer.

[1]
openshift/cluster-kube-scheduler-operator#88
[2]
openshift/cluster-kube-controller-manager-operator#207
s-urbaniak added a commit to s-urbaniak/cluster-monitoring-operator that referenced this pull request Apr 12, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. lgtm Indicates that a PR is ready to be merged. size/M Denotes a PR that changes 30-99 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants