Skip to content

Commit 336ffd5

Browse files
Merge pull request #1416 from ingvagabund/sync-library-go-4.12
OCPBUGS-4478: guard controller: set an explicit hostname to avoid name collisions
2 parents cefbfbf + 57bbb53 commit 336ffd5

16 files changed

+128
-59
lines changed

bindata/bootkube/bootstrap-manifests/kube-apiserver-pod.yaml

Lines changed: 10 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@ spec:
1818
initContainers:
1919
- name: setup
2020
terminationMessagePolicy: FallbackToLogsOnError
21-
image: {{ .Image }}
21+
image: '{{ .Image }}'
2222
imagePullPolicy: IfNotPresent
2323
volumeMounts:
2424
- mountPath: /var/log/kube-apiserver
@@ -36,8 +36,8 @@ spec:
3636
cpu: 5m
3737
containers:
3838
- name: kube-apiserver
39-
image: {{ .Image }}
40-
imagePullPolicy: {{ .ImagePullPolicy }}
39+
image: '{{ .Image }}'
40+
imagePullPolicy: '{{ .ImagePullPolicy }}'
4141
terminationMessagePolicy: FallbackToLogsOnError
4242
command: [ "/bin/bash", "-ec" ]
4343
args:
@@ -88,10 +88,9 @@ spec:
8888
- name: HOST_IP
8989
valueFrom:
9090
fieldRef:
91-
fieldPath: status.hostIP
92-
{{if .OperatorImage}}
91+
fieldPath: status.hostIP{{if .OperatorImage}}
9392
- name: kube-apiserver-insecure-readyz
94-
image: {{.OperatorImage}}
93+
image: '{{.OperatorImage}}'
9594
imagePullPolicy: IfNotPresent
9695
terminationMessagePolicy: FallbackToLogsOnError
9796
command: ["cluster-kube-apiserver-operator", "insecure-readyz"]
@@ -103,18 +102,17 @@ spec:
103102
resources:
104103
requests:
105104
memory: 50Mi
106-
cpu: 5m
107-
{{end}}
108-
terminationGracePeriodSeconds: {{ .TerminationGracePeriodSeconds }}
105+
cpu: 5m{{end}}
106+
terminationGracePeriodSeconds: +{{ .TerminationGracePeriodSeconds }}
109107
volumes:
110108
- hostPath:
111-
path: {{ .SecretsHostPath }}
109+
path: '{{ .SecretsHostPath }}'
112110
name: secrets
113111
- hostPath:
114-
path: {{ .CloudProviderHostPath }}
112+
path: '{{ .CloudProviderHostPath }}'
115113
name: etc-kubernetes-cloud
116114
- hostPath:
117-
path: {{ .ConfigHostPath }}
115+
path: '{{ .ConfigHostPath }}'
118116
name: config
119117
- hostPath:
120118
path: /etc/ssl/certs

bindata/bootkube/manifests/secret-aggregator-client-signer.yaml

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -4,10 +4,10 @@ metadata:
44
name: aggregator-client-signer
55
namespace: openshift-kube-apiserver-operator
66
annotations:
7-
"auth.openshift.io/certificate-not-before": {{ .Assets | load "aggregator-signer.crt" | notBefore }}
8-
"auth.openshift.io/certificate-not-after": {{ .Assets | load "aggregator-signer.crt" | notAfter }}
9-
"auth.openshift.io/certificate-issuer": {{ .Assets | load "aggregator-signer.crt" | issuer }}
7+
"auth.openshift.io/certificate-not-before": '{{ .Assets | load "aggregator-signer.crt" | notBefore }}'
8+
"auth.openshift.io/certificate-not-after": '{{ .Assets | load "aggregator-signer.crt" | notAfter }}'
9+
"auth.openshift.io/certificate-issuer": '{{ .Assets | load "aggregator-signer.crt" | issuer }}'
1010
type: kubernetes.io/tls
1111
data:
12-
tls.crt: {{ .Assets | load "aggregator-signer.crt" | base64 }}
13-
tls.key: {{ .Assets | load "aggregator-signer.key" | base64 }}
12+
tls.crt: '{{ .Assets | load "aggregator-signer.crt" | base64 }}'
13+
tls.key: '{{ .Assets | load "aggregator-signer.key" | base64 }}'

bindata/bootkube/manifests/secret-bound-sa-token-signing-key.yaml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,6 @@ kind: Secret
33
metadata:
44
name: next-bound-service-account-signing-key
55
namespace: openshift-kube-apiserver-operator
6-
data:
7-
service-account.key: {{ .Assets | load "bound-service-account-signing-key.key" | base64 }}
8-
service-account.pub: {{ .Assets | load "bound-service-account-signing-key.pub" | base64 }}
6+
data:
7+
service-account.key: '{{ .Assets | load "bound-service-account-signing-key.key" | base64 }}'
8+
service-account.pub: '{{ .Assets | load "bound-service-account-signing-key.pub" | base64 }}'

bindata/bootkube/manifests/secret-control-plane-client-signer.yaml

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -4,10 +4,10 @@ metadata:
44
name: kube-control-plane-signer
55
namespace: openshift-kube-apiserver-operator
66
annotations:
7-
"auth.openshift.io/certificate-not-before": {{ .Assets | load "kube-control-plane-signer.crt" | notBefore }}
8-
"auth.openshift.io/certificate-not-after": {{ .Assets | load "kube-control-plane-signer.crt" | notAfter }}
9-
"auth.openshift.io/certificate-issuer": {{ .Assets | load "kube-control-plane-signer.crt" | issuer }}
7+
"auth.openshift.io/certificate-not-before": '{{ .Assets | load "kube-control-plane-signer.crt" | notBefore }}'
8+
"auth.openshift.io/certificate-not-after": '{{ .Assets | load "kube-control-plane-signer.crt" | notAfter }}'
9+
"auth.openshift.io/certificate-issuer": '{{ .Assets | load "kube-control-plane-signer.crt" | issuer }}'
1010
type: kubernetes.io/tls
1111
data:
12-
tls.crt: {{ .Assets | load "kube-control-plane-signer.crt" | base64 }}
13-
tls.key: {{ .Assets | load "kube-control-plane-signer.key" | base64 }}
12+
tls.crt: '{{ .Assets | load "kube-control-plane-signer.crt" | base64 }}'
13+
tls.key: '{{ .Assets | load "kube-control-plane-signer.key" | base64 }}'

bindata/bootkube/manifests/secret-kube-apiserver-to-kubelet-signer.yaml

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -4,10 +4,10 @@ metadata:
44
name: kube-apiserver-to-kubelet-signer
55
namespace: openshift-kube-apiserver-operator
66
annotations:
7-
"auth.openshift.io/certificate-not-before": {{ .Assets | load "kube-apiserver-to-kubelet-signer.crt" | notBefore }}
8-
"auth.openshift.io/certificate-not-after": {{ .Assets | load "kube-apiserver-to-kubelet-signer.crt" | notAfter }}
9-
"auth.openshift.io/certificate-issuer": {{ .Assets | load "kube-apiserver-to-kubelet-signer.crt" | issuer }}
7+
"auth.openshift.io/certificate-not-before": '{{ .Assets | load "kube-apiserver-to-kubelet-signer.crt" | notBefore }}'
8+
"auth.openshift.io/certificate-not-after": '{{ .Assets | load "kube-apiserver-to-kubelet-signer.crt" | notAfter }}'
9+
"auth.openshift.io/certificate-issuer": '{{ .Assets | load "kube-apiserver-to-kubelet-signer.crt" | issuer }}'
1010
type: kubernetes.io/tls
1111
data:
12-
tls.crt: {{ .Assets | load "kube-apiserver-to-kubelet-signer.crt" | base64 }}
13-
tls.key: {{ .Assets | load "kube-apiserver-to-kubelet-signer.key" | base64 }}
12+
tls.crt: '{{ .Assets | load "kube-apiserver-to-kubelet-signer.crt" | base64 }}'
13+
tls.key: '{{ .Assets | load "kube-apiserver-to-kubelet-signer.key" | base64 }}'

bindata/bootkube/manifests/secret-loadbalancer-serving-signer.yaml

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -4,10 +4,10 @@ metadata:
44
name: loadbalancer-serving-signer
55
namespace: openshift-kube-apiserver-operator
66
annotations:
7-
"auth.openshift.io/certificate-not-before": {{ .Assets | load "kube-apiserver-lb-signer.crt" | notBefore }}
8-
"auth.openshift.io/certificate-not-after": {{ .Assets | load "kube-apiserver-lb-signer.crt" | notAfter }}
9-
"auth.openshift.io/certificate-issuer": {{ .Assets | load "kube-apiserver-lb-signer.crt" | issuer }}
7+
"auth.openshift.io/certificate-not-before": '{{ .Assets | load "kube-apiserver-lb-signer.crt" | notBefore }}'
8+
"auth.openshift.io/certificate-not-after": '{{ .Assets | load "kube-apiserver-lb-signer.crt" | notAfter }}'
9+
"auth.openshift.io/certificate-issuer": '{{ .Assets | load "kube-apiserver-lb-signer.crt" | issuer }}'
1010
type: kubernetes.io/tls
1111
data:
12-
tls.crt: {{ .Assets | load "kube-apiserver-lb-signer.crt" | base64 }}
13-
tls.key: {{ .Assets | load "kube-apiserver-lb-signer.key" | base64 }}
12+
tls.crt: '{{ .Assets | load "kube-apiserver-lb-signer.crt" | base64 }}'
13+
tls.key: '{{ .Assets | load "kube-apiserver-lb-signer.key" | base64 }}'

bindata/bootkube/manifests/secret-localhost-serving-signer.yaml

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -4,10 +4,10 @@ metadata:
44
name: localhost-serving-signer
55
namespace: openshift-kube-apiserver-operator
66
annotations:
7-
"auth.openshift.io/certificate-not-before": {{ .Assets | load "kube-apiserver-localhost-signer.crt" | notBefore }}
8-
"auth.openshift.io/certificate-not-after": {{ .Assets | load "kube-apiserver-localhost-signer.crt" | notAfter }}
9-
"auth.openshift.io/certificate-issuer": {{ .Assets | load "kube-apiserver-localhost-signer.crt" | issuer }}
7+
"auth.openshift.io/certificate-not-before": '{{ .Assets | load "kube-apiserver-localhost-signer.crt" | notBefore }}'
8+
"auth.openshift.io/certificate-not-after": '{{ .Assets | load "kube-apiserver-localhost-signer.crt" | notAfter }}'
9+
"auth.openshift.io/certificate-issuer": '{{ .Assets | load "kube-apiserver-localhost-signer.crt" | issuer }}'
1010
type: kubernetes.io/tls
1111
data:
12-
tls.crt: {{ .Assets | load "kube-apiserver-localhost-signer.crt" | base64 }}
13-
tls.key: {{ .Assets | load "kube-apiserver-localhost-signer.key" | base64 }}
12+
tls.crt: '{{ .Assets | load "kube-apiserver-localhost-signer.crt" | base64 }}'
13+
tls.key: '{{ .Assets | load "kube-apiserver-localhost-signer.key" | base64 }}'

bindata/bootkube/manifests/secret-service-network-serving-signer.yaml

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -4,10 +4,10 @@ metadata:
44
name: service-network-serving-signer
55
namespace: openshift-kube-apiserver-operator
66
annotations:
7-
"auth.openshift.io/certificate-not-before": {{ .Assets | load "kube-apiserver-service-network-signer.crt" | notBefore }}
8-
"auth.openshift.io/certificate-not-after": {{ .Assets | load "kube-apiserver-service-network-signer.crt" | notAfter }}
9-
"auth.openshift.io/certificate-issuer": {{ .Assets | load "kube-apiserver-service-network-signer.crt" | issuer }}
7+
"auth.openshift.io/certificate-not-before": '{{ .Assets | load "kube-apiserver-service-network-signer.crt" | notBefore }}'
8+
"auth.openshift.io/certificate-not-after": '{{ .Assets | load "kube-apiserver-service-network-signer.crt" | notAfter }}'
9+
"auth.openshift.io/certificate-issuer": '{{ .Assets | load "kube-apiserver-service-network-signer.crt" | issuer }}'
1010
type: kubernetes.io/tls
1111
data:
12-
tls.crt: {{ .Assets | load "kube-apiserver-service-network-signer.crt" | base64 }}
13-
tls.key: {{ .Assets | load "kube-apiserver-service-network-signer.key" | base64 }}
12+
tls.crt: '{{ .Assets | load "kube-apiserver-service-network-signer.crt" | base64 }}'
13+
tls.key: '{{ .Assets | load "kube-apiserver-service-network-signer.key" | base64 }}'

go.mod

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,7 @@ require (
1515
github.com/openshift/api v0.0.0-20221013123531-622889ac07cf
1616
github.com/openshift/build-machinery-go v0.0.0-20220913142420-e25cf57ea46d
1717
github.com/openshift/client-go v0.0.0-20220831193253-4950ae70c8ea
18-
github.com/openshift/library-go v0.0.0-20221021005159-d93563844063
18+
github.com/openshift/library-go v0.0.0-20221212171543-669323ec9bca
1919
github.com/pkg/profile v1.5.0 // indirect
2020
github.com/prometheus-operator/prometheus-operator/pkg/client v0.45.0
2121
github.com/prometheus/client_golang v1.12.1

go.sum

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -423,8 +423,8 @@ github.com/openshift/build-machinery-go v0.0.0-20220913142420-e25cf57ea46d h1:RR
423423
github.com/openshift/build-machinery-go v0.0.0-20220913142420-e25cf57ea46d/go.mod h1:b1BuldmJlbA/xYtdZvKi+7j5YGB44qJUJDZ9zwiNCfE=
424424
github.com/openshift/client-go v0.0.0-20220831193253-4950ae70c8ea h1:7JbjIzWt3Q75ErY1PAZ+gCA+bErI6HSlpffHFmMMzqM=
425425
github.com/openshift/client-go v0.0.0-20220831193253-4950ae70c8ea/go.mod h1:+J8DqZC60acCdpYkwVy/KH4cudgWiFZRNOBeghCzdGA=
426-
github.com/openshift/library-go v0.0.0-20221021005159-d93563844063 h1:Mn2LKR04FBEiXk1g2r6cB98G7M3sCUp58qb89Uz5kcE=
427-
github.com/openshift/library-go v0.0.0-20221021005159-d93563844063/go.mod h1:KPBAXGaq7pPmA+1wUVtKr5Axg3R68IomWDkzaOxIhxM=
426+
github.com/openshift/library-go v0.0.0-20221212171543-669323ec9bca h1:zAugG9rbkcjEDsnIcyaxmOszs5G3xuIzqNZGw9kS20Y=
427+
github.com/openshift/library-go v0.0.0-20221212171543-669323ec9bca/go.mod h1:KPBAXGaq7pPmA+1wUVtKr5Axg3R68IomWDkzaOxIhxM=
428428
github.com/pborman/uuid v1.2.0/go.mod h1:X/NO0urCmaxf9VXbdlT7C2Yzkj2IKimNn4k+gtPdI/k=
429429
github.com/pelletier/go-toml v1.2.0/go.mod h1:5z9KED0ma1S8pY6P1sdut58dfprrGBbd/94hg7ilaic=
430430
github.com/peterbourgon/diskv v2.0.1+incompatible/go.mod h1:uqqh8zWWbv1HBMNONnaR/tNboyR3/BZd58JJSHlUSCU=

0 commit comments

Comments
 (0)