-
Notifications
You must be signed in to change notification settings - Fork 451
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Only update network policy allow-to-runtime-apiserver
after resolver has been synced
#9644
Only update network policy allow-to-runtime-apiserver
after resolver has been synced
#9644
Conversation
Co-authored-by: Olivir Goetz <o.goetz@sap.com>
Co-authored-by: Rafael Franzke <rafael.franzke@sap.com>
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
/lgtm
LGTM label has been added. Git tree hash: d95248eefe9e0960502cd5bec10bfb85a5452334
|
/lgtm |
/approve |
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: rfranzke The full list of commands accepted by this bot can be found here. The pull request process is described here
Needs approval from an approver in each of these files:
Approvers can indicate their approval by writing |
How to categorize this PR?
/area control-plane
/kind bug
What this PR does / why we need it:
The lookup of the IP address of the kube-apiserver via DNS from its external domain name can take some several seconds in rare situations due to network issues. In these cases, the network policy
allow-to-runtime-apiserver
must not be updated until the resolver has resolved the domain name successfully. Especially on startup of the gardenlet, the first reconciliation of the network policy can occur too early.A check is added to skip the update of the network policy in such situations.
Which issue(s) this PR fixes:
Fixes #
Special notes for your reviewer:
Release note: