CNTRLPLANE-3237: kms preflight: don't degrade when encryption is disabled - #2397
Conversation
|
@p0lyn0mial: This pull request references CNTRLPLANE-3237 which is a valid jira issue. Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the story to target the "5.0.0" version, but no target version was set. DetailsIn response to this: Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: openshift/coderabbit/.coderabbit.yaml Review profile: CHILL Plan: Enterprise Run ID: 📒 Files selected for processing (2)
WalkthroughThe controller now checks the APIServer encryption type before KMS preflight processing. It skips preflight for identity encryption, even with a stale KMS hash. Tests verify pod cleanup and unchanged status conditions. ChangesKMS preflight handling
Estimated code review effort: 2 (Simple) | ~10 minutes Possibly related PRs
🚥 Pre-merge checks | ✅ 15✅ Passed checks (15 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
| // Encryption is not KMS — nothing to preflight. A stale ObservedConfigHash | ||
| // (written when KMS was active) is irrelevant; the key controller will | ||
| // overwrite it when/if KMS is re-enabled. | ||
| return "", nil, nil |
There was a problem hiding this comment.
ah, I found the caller. Ignore my comment
There was a problem hiding this comment.
the controller always clean up in this case -
does it make sense ?
|
/lgtm |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: ardaguclu, p0lyn0mial The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
|
@p0lyn0mial: all tests passed! Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
Summary by CodeRabbit