-
Story
-
Resolution: Done
-
Undefined
-
None
-
None
-
Product / Portfolio Work
-
False
-
-
False
-
None
-
None
-
None
The pod `gcp-pd-csi-driver-controller` mounts the secret:
$ oc get po -n openshift-cluster-csi-drivers gcp-pd-csi-driver-controller-5787b9c477-q78qx -o yaml
...
name: provisioner-kube-rbac-proxy
...
volumeMounts:
- mountPath: /etc/tls/private
name: metrics-serving-cert
volumes:
- name: metrics-serving-cert
secret:
secretName: gcp-pd-csi-driver-controller-metrics-serving-cert
Hence, if the secret is updated (e.g. as a result of CA cert update), the Pod must be restarted