Skip to content

Commit f78557c

Browse files
committed
ROSA: Generate unique username for BreakGlassCredential requests
1 parent b2fae56 commit f78557c

File tree

2 files changed

+3
-2
lines changed

2 files changed

+3
-2
lines changed

controlplane/rosa/controllers/rosacontrolplane_controller.go

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -39,6 +39,7 @@ import (
3939
metav1 "k8s.io/apimachinery/pkg/apis/meta/v1"
4040
"k8s.io/apimachinery/pkg/types"
4141
kerrors "k8s.io/apimachinery/pkg/util/errors"
42+
"k8s.io/apiserver/pkg/storage/names"
4243
restclient "k8s.io/client-go/rest"
4344
"k8s.io/client-go/tools/clientcmd"
4445
"k8s.io/client-go/tools/clientcmd/api"
@@ -609,7 +610,7 @@ func (r *ROSAControlPlaneReconciler) reconcileExternalAuthBootstrapKubeconfig(ct
609610

610611
// kubeconfig doesn't exist, generate a new one.
611612
breakGlassConfig, err := cmv1.NewBreakGlassCredential().
612-
Username("capi-admin").
613+
Username(names.SimpleNameGenerator.GenerateName("capi-admin-")). // OCM requires unique usernames
613614
ExpirationTimestamp(time.Now().Add(time.Hour * 24)).
614615
Build()
615616
if err != nil {

go.mod

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -47,6 +47,7 @@ require (
4747
k8s.io/api v0.29.3
4848
k8s.io/apiextensions-apiserver v0.29.3
4949
k8s.io/apimachinery v0.29.3
50+
k8s.io/apiserver v0.29.3
5051
k8s.io/cli-runtime v0.29.3
5152
k8s.io/client-go v0.29.3
5253
k8s.io/component-base v0.29.3
@@ -217,7 +218,6 @@ require (
217218
gopkg.in/inf.v0 v0.9.1 // indirect
218219
gopkg.in/ini.v1 v1.67.0 // indirect
219220
gopkg.in/yaml.v3 v3.0.1 // indirect
220-
k8s.io/apiserver v0.29.3 // indirect
221221
k8s.io/cluster-bootstrap v0.29.3 // indirect
222222
k8s.io/component-helpers v0.29.3 // indirect
223223
k8s.io/kube-openapi v0.0.0-20231010175941-2dd684a91f00 // indirect

0 commit comments

Comments
 (0)