Skip to content

Commit fca628c

Browse files
authored
Merge pull request #732 from vinayakankugoyal/byebye
Remove GKE specific kubelet readonly port signing loop.
2 parents 66e8901 + 98feb18 commit fca628c

File tree

7 files changed

+1
-1164
lines changed

7 files changed

+1
-1164
lines changed

cmd/gcp-controller-manager/BUILD

Lines changed: 0 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -26,7 +26,6 @@ go_library(
2626
"csr_signer.go",
2727
"gcp_config.go",
2828
"istiod_csr_approver.go",
29-
"kubelet_readonly_csr_approver.go",
3029
"loops.go",
3130
"main.go",
3231
"node_annotator.go",
@@ -70,7 +69,6 @@ go_library(
7069
"//vendor/k8s.io/apimachinery/pkg/util/runtime",
7170
"//vendor/k8s.io/apimachinery/pkg/util/validation/field",
7271
"//vendor/k8s.io/apimachinery/pkg/util/wait",
73-
"//vendor/k8s.io/apiserver/pkg/authentication/serviceaccount",
7472
"//vendor/k8s.io/apiserver/pkg/server/options",
7573
"//vendor/k8s.io/apiserver/pkg/util/feature",
7674
"//vendor/k8s.io/apiserver/pkg/util/webhook",
@@ -112,7 +110,6 @@ go_test(
112110
"csr_signer_test.go",
113111
"gcp_config_test.go",
114112
"istiod_csr_approver_test.go",
115-
"kubelet_readonly_csr_approver_test.go",
116113
"node_annotator_test.go",
117114
"node_csr_approver_test.go",
118115
"oidc_csr_approver_test.go",
@@ -134,7 +131,6 @@ go_test(
134131
"//vendor/k8s.io/apimachinery/pkg/apis/meta/v1:meta",
135132
"//vendor/k8s.io/apimachinery/pkg/runtime",
136133
"//vendor/k8s.io/apimachinery/pkg/runtime/schema",
137-
"//vendor/k8s.io/apimachinery/pkg/types",
138134
"//vendor/k8s.io/apimachinery/pkg/util/strategicpatch",
139135
"//vendor/k8s.io/client-go/kubernetes/fake",
140136
"//vendor/k8s.io/client-go/listers/core/v1:core",

cmd/gcp-controller-manager/csr_signer.go

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -91,8 +91,7 @@ func (s *gkeSigner) handleInternal(csr *capi.CertificateSigningRequest) (process
9191
csr.Spec.SignerName != certsv1.KubeletServingSignerName &&
9292
csr.Spec.SignerName != certsv1b1.LegacyUnknownSignerName &&
9393
csr.Spec.SignerName != istiodSignerName &&
94-
csr.Spec.SignerName != oidcSignerName &&
95-
csr.Spec.SignerName != kubeletReadonlyCSRSignerName {
94+
csr.Spec.SignerName != oidcSignerName {
9695
return false, nil, nil
9796
}
9897

cmd/gcp-controller-manager/csr_signer_test.go

Lines changed: 0 additions & 26 deletions
Original file line numberDiff line numberDiff line change
@@ -107,19 +107,6 @@ func TestGKESigner(t *testing.T) {
107107
wantProcessed: true,
108108
wantErr: false,
109109
},
110-
{
111-
name: "Signs approved certs with kubelet readonly signer name",
112-
csr: &certsv1.CertificateSigningRequest{
113-
Spec: capi.CertificateSigningRequestSpec{
114-
SignerName: kubeletReadonlyCSRSignerName,
115-
Request: generateCSR(),
116-
},
117-
Status: statusApproved,
118-
},
119-
mockResponse: goodResponse,
120-
expected: goodResponse.Status.Certificate,
121-
wantProcessed: true,
122-
},
123110
{
124111
name: "Signs Approved API client certificates",
125112
csr: &certsv1.CertificateSigningRequest{
@@ -218,19 +205,6 @@ func TestGKESigner(t *testing.T) {
218205
wantProcessed: true,
219206
wantErr: true,
220207
},
221-
{
222-
name: "Returns error after invalid response for readonly approver",
223-
csr: &certsv1.CertificateSigningRequest{
224-
Spec: capi.CertificateSigningRequestSpec{
225-
SignerName: kubeletReadonlyCSRSignerName,
226-
Request: generateCSR(),
227-
},
228-
Status: statusApproved,
229-
},
230-
mockResponse: invalidResponse,
231-
wantProcessed: true,
232-
wantErr: true,
233-
},
234208
}
235209

236210
for _, c := range cases {

0 commit comments

Comments
 (0)