Skip to content

Commit

Permalink
Seed kubelet-client-ca certificate for kubeadm (#897)
Browse files Browse the repository at this point in the history
* Seed kubelet-client-ca certificate for kubeadm

* Concatenate kubelet CAs for kubeadm
  • Loading branch information
Nuckal777 authored Mar 25, 2024
1 parent cf8902c commit 152f6f4
Show file tree
Hide file tree
Showing 2 changed files with 2 additions and 4 deletions.
2 changes: 1 addition & 1 deletion charts/seed/templates/kubeadm.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -169,7 +169,7 @@ data:
apiVersion: v1
clusters:
- cluster:
certificate-authority-data: {{ .Values.tlsCaCert | b64enc }}
certificate-authority-data: {{ printf "%s%s" .Values.tlsCaCert .Values.kubeletClientsCaCert | b64enc }}
server: https://{{ .Values.api.apiserverHost }}
name: ""
contexts: null
Expand Down
4 changes: 1 addition & 3 deletions pkg/controller/ground/reconciler.go
Original file line number Diff line number Diff line change
Expand Up @@ -103,6 +103,7 @@ func (sr *SeedReconciler) EnrichHelmValuesForSeed(client project.ProjectClient,
values["shortName"] = kluster.Spec.Name[:idx]
}
values["tlsCaCert"] = secret.TLSCACertificate
values["kubeletClientsCaCert"] = secret.KubeletClientsCACertificate
return nil
}

Expand Down Expand Up @@ -417,9 +418,6 @@ func (sr *SeedReconciler) createOrUpdateObjects(client dynamic.Interface, mapper
} else if err != nil {
return err
}
if err != nil {
return err
}
if oneDiff.deployed == nil {
err = sr.createPlanned(client, mapping, &oneDiff.planned)
if err != nil {
Expand Down

0 comments on commit 152f6f4

Please sign in to comment.