Skip to content

Commit afd7814

Browse files
committed
ccm: disable unused secure-serving port and webhook
1 parent 614b98d commit afd7814

File tree

8 files changed

+18
-41
lines changed

8 files changed

+18
-41
lines changed

pkg/cloud/aws/assets/deployment.yaml

Lines changed: 1 addition & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -43,17 +43,14 @@ spec:
4343
--leader-elect-renew-deadline=107s \
4444
--leader-elect-retry-period=26s \
4545
--leader-elect-resource-namespace=openshift-cloud-controller-manager \
46+
--secure-port=0 \
4647
-v=2
4748
env:
4849
- name: CLOUD_CONFIG
4950
value: /etc/kubernetes-cloud-config/cloud.conf
5051
image: {{ .images.CloudControllerManager }}
5152
imagePullPolicy: IfNotPresent
5253
name: cloud-controller-manager
53-
ports:
54-
- containerPort: 10258
55-
name: https
56-
protocol: TCP
5754
resources:
5855
requests:
5956
cpu: 200m

pkg/cloud/azure/assets/cloud-controller-manager-deployment.yaml

Lines changed: 2 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -94,10 +94,6 @@ spec:
9494
requests:
9595
cpu: 200m
9696
memory: 50Mi
97-
ports:
98-
- containerPort: 10258
99-
name: https
100-
protocol: TCP
10197
command:
10298
- /bin/bash
10399
- -c
@@ -121,7 +117,8 @@ spec:
121117
--leader-elect-lease-duration=137s \
122118
--leader-elect-renew-deadline=107s \
123119
--leader-elect-retry-period=26s \
124-
--leader-elect-resource-namespace=openshift-cloud-controller-manager
120+
--leader-elect-resource-namespace=openshift-cloud-controller-manager \
121+
--secure-port=0
125122
terminationMessagePolicy: FallbackToLogsOnError
126123
volumeMounts:
127124
- name: host-etc-kube

pkg/cloud/azurestack/assets/cloud-controller-manager-deployment.yaml

Lines changed: 2 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -88,9 +88,6 @@ spec:
8888
cpu: 200m
8989
memory: 50Mi
9090
ports:
91-
- containerPort: 10258
92-
name: https
93-
protocol: TCP
9491
command:
9592
- /bin/bash
9693
- -c
@@ -113,7 +110,8 @@ spec:
113110
--leader-elect-lease-duration=137s \
114111
--leader-elect-renew-deadline=107s \
115112
--leader-elect-retry-period=26s \
116-
--leader-elect-resource-namespace=openshift-cloud-controller-manager
113+
--leader-elect-resource-namespace=openshift-cloud-controller-manager \
114+
--secure-port=0
117115
terminationMessagePolicy: FallbackToLogsOnError
118116
volumeMounts:
119117
- name: host-etc-kube

pkg/cloud/gcp/assets/cloud-controller-manager.yaml

Lines changed: 2 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -68,10 +68,6 @@ spec:
6868
requests:
6969
cpu: 200m
7070
memory: 128Mi
71-
ports:
72-
- containerPort: 10258
73-
name: https
74-
protocol: TCP
7571
command:
7672
- /bin/bash
7773
- -c
@@ -95,7 +91,8 @@ spec:
9591
--leader-elect-lease-duration=137s \
9692
--leader-elect-renew-deadline=107s \
9793
--leader-elect-retry-period=26s \
98-
--leader-elect-resource-namespace=openshift-cloud-controller-manager
94+
--leader-elect-resource-namespace=openshift-cloud-controller-manager \
95+
--secure-port=0
9996
terminationMessagePolicy: FallbackToLogsOnError
10097
volumeMounts:
10198
- name: host-etc-kube

pkg/cloud/nutanix/assets/cloud-controller-manager-deployment.yaml

Lines changed: 2 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -72,10 +72,6 @@ spec:
7272
requests:
7373
cpu: 200m
7474
memory: 128Mi
75-
ports:
76-
- containerPort: 10258
77-
name: https
78-
protocol: TCP
7975
command:
8076
- /bin/bash
8177
- -c
@@ -98,7 +94,8 @@ spec:
9894
--leader-elect-renew-deadline=107s \
9995
--leader-elect-retry-period=26s \
10096
--leader-elect-resource-namespace=openshift-cloud-controller-manager \
101-
--tls-cipher-suites=TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256
97+
--tls-cipher-suites=TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 \
98+
--secure-port=0
10299
terminationMessagePolicy: FallbackToLogsOnError
103100
volumeMounts:
104101
- name: nutanix-config

pkg/cloud/openstack/assets/deployment.yaml

Lines changed: 2 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -78,11 +78,8 @@ spec:
7878
--leader-elect-renew-deadline=107s \
7979
--leader-elect-retry-period=26s \
8080
--leader-elect-resource-namespace=openshift-cloud-controller-manager \
81-
--feature-gates={{ .featureGates }}
82-
ports:
83-
- containerPort: 10258
84-
name: https
85-
protocol: TCP
81+
--feature-gates={{ .featureGates }} \
82+
--secure-port=0
8683
resources:
8784
requests:
8885
cpu: 200m

pkg/cloud/vsphere/assets/cloud-controller-manager-deployment.yaml

Lines changed: 2 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -72,10 +72,6 @@ spec:
7272
requests:
7373
cpu: 200m
7474
memory: 128Mi
75-
ports:
76-
- containerPort: 10258
77-
name: https
78-
protocol: TCP
7975
command:
8076
- /bin/bash
8177
- -c
@@ -99,7 +95,8 @@ spec:
9995
--leader-elect-retry-period=26s \
10096
--leader-elect-resource-namespace=openshift-cloud-controller-manager \
10197
--feature-gates={{ .featureGates }} \
102-
--use-service-account-credentials=true
98+
--use-service-account-credentials=true \
99+
--secure-port=0
103100
terminationMessagePolicy: FallbackToLogsOnError
104101
volumeMounts:
105102
- name: host-etc-kube

pkg/controllers/clusteroperator_controller_test.go

Lines changed: 5 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -420,11 +420,10 @@ var _ = Describe("Apply resources should", func() {
420420

421421
// Checking that the port has been reverted back and there is only one item in the list
422422
Expect(cl.Get(context.Background(), client.ObjectKeyFromObject(dep), dep)).To(Succeed())
423-
Expect(len(dep.Spec.Template.Spec.Containers[0].Ports)).To(Equal(1))
424-
Expect(dep.Spec.Template.Spec.Containers[0].Ports[0].ContainerPort).To(Equal(int32(10258)))
423+
Expect(len(dep.Spec.Template.Spec.Containers[0].Ports)).To(Equal(0))
425424
})
426425

427-
It("Expect to have just one item in the port list after user added another one", func() {
426+
It("Expect to have no item in the port list after user added another one", func() {
428427
var dep *appsv1.Deployment
429428
operatorConfig := getConfigForPlatform(&configv1.PlatformStatus{Type: configv1.AWSPlatformType})
430429

@@ -457,9 +456,8 @@ var _ = Describe("Apply resources should", func() {
457456

458457
// Checking that the port has been added and there are two items in the list
459458
Expect(cl.Get(context.Background(), client.ObjectKeyFromObject(dep), dep)).To(Succeed())
460-
Expect(len(dep.Spec.Template.Spec.Containers[0].Ports)).To(Equal(2))
461-
Expect(dep.Spec.Template.Spec.Containers[0].Ports[0].ContainerPort).To(Equal(int32(10258)))
462-
Expect(dep.Spec.Template.Spec.Containers[0].Ports[1].ContainerPort).To(Equal(int32(11258)))
459+
Expect(len(dep.Spec.Template.Spec.Containers[0].Ports)).To(Equal(1))
460+
Expect(dep.Spec.Template.Spec.Containers[0].Ports[0].ContainerPort).To(Equal(int32(11258)))
463461

464462
// Apply resources again
465463
freshResources, err = cloud.GetResources(operatorConfig)
@@ -479,8 +477,7 @@ var _ = Describe("Apply resources should", func() {
479477

480478
// Checking that the port list has been reverted back and there is only one item in the list
481479
Expect(cl.Get(context.Background(), client.ObjectKeyFromObject(dep), dep)).To(Succeed())
482-
Expect(len(dep.Spec.Template.Spec.Containers[0].Ports)).To(Equal(1))
483-
Expect(dep.Spec.Template.Spec.Containers[0].Ports[0].ContainerPort).To(Equal(int32(10258)))
480+
Expect(len(dep.Spec.Template.Spec.Containers[0].Ports)).To(Equal(0))
484481
})
485482

486483
It("Expect to have deployment labels merged with user ones", func() {

0 commit comments

Comments
 (0)