Uploaded image for project: 'OpenShift Service Mesh'
  1. OpenShift Service Mesh
  2. OSSM-8819

Istio Operator - Server cert is patched rather than CA in webhook bundle

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Blocker Blocker
    • OSSM 2.6.6
    • None
    • Maistra
    • None

      When using cert-manager, and either the `istiod-tls` or the `cacerts` secrets, the istio operator patches the server cert into the istiod's webhook caBundle rather than the CA cert. This affects 3.0 migrations because the 3.0 istiod also patches the same webhooks but it patches the CA instead. The two controllers each attempt to patch a different bundle and an endless reconcile loop occurs.

              nfox@redhat.com Nick Fox
              nfox@redhat.com Nick Fox
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated: