Skip to content

Automatically update oidc-ca-* secrets when oidcCABundle changes #89

@dimityrmirchev

Description

@dimityrmirchev

What happened:
I changed the contents of oidcCABundle in the configuration of the oidc-apps-controller. The existing oidc-ca-* secrets were not updated automatically with the new content. As a workaround I deleted the secrets and then they were recreated by the controller. In addition to that some of the mutated pods needed restart because they were not able automatically refresh the new CA content from the already updated secret. A hash produced of the CA secret contents can be added as an annotation to the pod definition so that pods get recreated once the contents of the secret change.

What you expected to happen:
The oidc-ca-* secrets to be updated automatically and pods to restart.

Metadata

Metadata

Assignees

No one assigned

    Labels

    kind/bugBuglifecycle/staleDenotes an issue or PR has remained open with no activity and has become stale.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions