Add warning to docs about enabling IRSA in existing cluster #13818
Labels
kind/feature
Categorizes issue or PR as related to a new feature.
lifecycle/stale
Denotes an issue or PR has remained open with no activity and has become stale.
/kind feature
The following operations are extremely likely to be highly disruptive during cluster upgrading (speaking specifically about using kops-managed IRSA here, I am unsure whether externally managed OIDC would be affected as well but I suspect it would be):
After the control plane have been upgraded during the upgrade process I've observed the following behaviors:
As such the recommended method for making an IRSA change should be to roll all the cluster nodes as quickly as possible once the control plane has been rolled in order to ensure that only "new" nodes are in the cluster. A warning to this effect should be added to the documentation around the IRSA feature.
For this reason also we should also ensure that IRSA is never enabled for pre-existing clusters that did not have IRSA enabled during the migration to new Kops versions.
The text was updated successfully, but these errors were encountered: