Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

cleanup orphan outdated certificate secrets #46

Merged
merged 1 commit into from
Nov 11, 2020
Merged

Conversation

MartinWeindel
Copy link
Member

What this PR does / why we need it:
The secret referenced by a certificate custom resource is not deleted if the certificate CR is deleted,
because it is unclear if the certificate will be recreated, e.g if the source object has been disappeared temporarily.
With this PR a garbage collection is added which deletes a certificate secret if it is not referenced by a certificate CR and it is outdated at least for 14 days. The garbage collection runs on startup and every 7 days.

Which issue(s) this PR fixes:
Fixes #

Special notes for your reviewer:

Release note:

cleanup orphan outdated certificate secrets

@MartinWeindel MartinWeindel requested a review from a team as a code owner November 10, 2020 14:18
@gardener-robot gardener-robot added needs/review Needs review size/S Denotes a PR that changes 10-29 lines, ignoring generated files. labels Nov 10, 2020
@gardener-robot-ci-3 gardener-robot-ci-3 added the reviewed/ok-to-test Has approval for testing (check PR in detail before setting this label because PR is run on CI/CD) label Nov 10, 2020
@gardener-robot-ci-2 gardener-robot-ci-2 added needs/ok-to-test Needs approval for testing (check PR in detail before setting this label because PR is run on CI/CD) and removed reviewed/ok-to-test Has approval for testing (check PR in detail before setting this label because PR is run on CI/CD) labels Nov 10, 2020
@gardener-robot-ci-3 gardener-robot-ci-3 added reviewed/ok-to-test Has approval for testing (check PR in detail before setting this label because PR is run on CI/CD) and removed reviewed/ok-to-test Has approval for testing (check PR in detail before setting this label because PR is run on CI/CD) labels Nov 10, 2020
@gardener-robot-ci-2 gardener-robot-ci-2 added the reviewed/ok-to-test Has approval for testing (check PR in detail before setting this label because PR is run on CI/CD) label Nov 10, 2020
@gardener-robot-ci-3 gardener-robot-ci-3 removed the reviewed/ok-to-test Has approval for testing (check PR in detail before setting this label because PR is run on CI/CD) label Nov 10, 2020
@gardener-robot gardener-robot removed the needs/review Needs review label Nov 11, 2020
@MartinWeindel MartinWeindel merged commit bf551ae into master Nov 11, 2020
@MartinWeindel MartinWeindel deleted the gc-cert-secrets branch November 11, 2020 12:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
needs/ok-to-test Needs approval for testing (check PR in detail before setting this label because PR is run on CI/CD) size/S Denotes a PR that changes 10-29 lines, ignoring generated files.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants