-
Notifications
You must be signed in to change notification settings - Fork 1.5k
tls: add kube-apiserver-complete-server-ca-bundle.crt #1298
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
8664199 to
439fa46
Compare
staebler
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Please regenerate the asset dependency graph in a separate commit.
pkg/asset/kubeconfig/kubelet.go
Outdated
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Will the kubelet-client-ca-bundle.crt still be used by anything once it is removed from the kubelet kubeconfig?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Will the
kubelet-client-ca-bundle.crtstill be used by anything once it is removed from the kubelet kubeconfig?
I think it was wired improperly here before (kube-ca for everyone!). It is logically distinct and is for verifying kubelet clients.
439fa46 to
4131408
Compare
4131408 to
f52512c
Compare
done |
pkg/asset/tls/adminkubeconfig.go
Outdated
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
nit:
KAS can use this file to trust the client certificate generated by admin-kubeconfig-signer. just drop kubeapiserver*signer
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I think I deleted these lines. We're trying to create a call bundle to verify the KAS serving cert, not one to verify clients.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Oh, I understand now. Sure, I'll make it client ca only. Lgty otherwise? An lgtm and hold so I can get it this weekend?
/approve |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: abhinavdahiya, deads2k The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
The KCM and the admin.kubeconfig both need the complete set of certs to use to trust the KAS.
f52512c to
4ae423d
Compare
|
made that client-ca and tagging per comment |
|
/retest |
1 similar comment
|
/retest |
|
/test e2e-aws |
|
/retest |
|
/retest Please review the full test history for this PR and help us cut down flakes. |
2 similar comments
|
/retest Please review the full test history for this PR and help us cut down flakes. |
|
/retest Please review the full test history for this PR and help us cut down flakes. |
|
aws, aws, aws /retest |
|
/retest Please review the full test history for this PR and help us cut down flakes. |
|
/retest Please review the full test history for this PR and help us cut down flakes. |
|
/test e2e-aws |
1 similar comment
|
/test e2e-aws |
|
cadvisor /retest |
|
This fixes sa ca.crt bundles. Green, with no overlap to the other AWS one I merged |
|
@deads2k: The following test failed for commit 4ae423d, say
Full PR test history. Your PR dashboard. Please help us cut down on flakes by linking to an open issue when you hit one in your PR. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. I understand the commands that are listed here. |
The KCM and the admin.kubeconfig both need the complete set of certs
to use to trust the KAS.
This is needed so the kube-apiserver can serve with it's shiny new certs. openshift/cluster-kube-apiserver-operator#282
/assign @abhinavdahiya