Skip to content

Commit 6841675

Browse files
committed
certrotationcontroller: set RefreshOnlyWhenExpired for CA bundle
This prevents CA bundle from being updated by sidecar running in RefreshOnlyWhenExpired=true mode
1 parent 3dfbb67 commit 6841675

File tree

1 file changed

+5
-4
lines changed

1 file changed

+5
-4
lines changed

pkg/operator/certrotationcontroller/certrotationcontroller.go

Lines changed: 5 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -102,10 +102,11 @@ func newCertRotationController(
102102
AdditionalAnnotations: certrotation.AdditionalAnnotations{
103103
JiraComponent: "kube-controller-manager",
104104
},
105-
Informer: kubeInformersForNamespaces.InformersFor(operatorclient.OperatorNamespace).Core().V1().ConfigMaps(),
106-
Lister: kubeInformersForNamespaces.InformersFor(operatorclient.OperatorNamespace).Core().V1().ConfigMaps().Lister(),
107-
Client: configMapsGetter,
108-
EventRecorder: eventRecorder,
105+
RefreshOnlyWhenExpired: refreshOnlyWhenExpired,
106+
Informer: kubeInformersForNamespaces.InformersFor(operatorclient.OperatorNamespace).Core().V1().ConfigMaps(),
107+
Lister: kubeInformersForNamespaces.InformersFor(operatorclient.OperatorNamespace).Core().V1().ConfigMaps().Lister(),
108+
Client: configMapsGetter,
109+
EventRecorder: eventRecorder,
109110
},
110111
certrotation.RotatedSelfSignedCertKeySecret{
111112
Namespace: operatorclient.OperatorNamespace,

0 commit comments

Comments
 (0)