Commit 12ea713
committed
fix: Correct sync wave ordering for certificate dependency chain
Move nginx-ingress-pxe-boots from wave 1200 → 1100 so it creates tls-boots
secret BEFORE infra-onboarding (wave 1150) needs boots-ca-cert.
Wave ordering:
- 1100: nginx-ingress-pxe-boots creates tls-boots Certificate resource
- 1140: copy-ca-cert-boots-to-infra copies tls-boots → boots-ca-cert (ExternalSecret)
- 1150: infra-onboarding deploys with boots-ca-cert available for dkam
This fixes dkam CrashLoopBackOff due to missing /etc/ssl/boots-ca-cert/ca.crt1 parent 0e1b544 commit 12ea713
1 file changed
+1
-1
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
4 | 4 | | |
5 | 5 | | |
6 | 6 | | |
7 | | - | |
| 7 | + | |
8 | 8 | | |
9 | 9 | | |
10 | 10 | | |
| |||
0 commit comments