Uploaded image for project: 'OpenShift Pod Autoscaling'
  1. OpenShift Pod Autoscaling
  2. PODAUTO-241

Reload VPA admission server if admission webhook CA bundle changed

XMLWordPrintable

    • Icon: Story Story
    • Resolution: Unresolved
    • Icon: Normal Normal
    • None
    • None
    • None
    • 5
    • False
    • Hide

      None

      Show
      None
    • False
    • PODAUTO - Sprint 264

      As a cluster admin, I want my server to still be handling my admission requests, if my webhook CA cert happens to rotate or get changed.

      As of now, we don't have any implementation of this in the code, however VPA 1.2.0 seems to include this change here to automatically rotate the TLS cert and key, but not the CA cert if need be. Our 4.17 VPA uses upstream VPA 1.1.2, so once we upstream rebase 4.18, at least that part should be good to go (we still need to test this since the PR doesn't seem to actually restart the server to handle new certs). But the CA cert still needs to be watched.

              rh-ee-macao Max Cao
              rh-ee-macao Max Cao
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated: