New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Use kubernetes.default for OIDC discovery in gossip clusters #11470
Conversation
/assign @johngmyers |
Does the |
It doesn't make sense to use a gossip hostname as the discovery url because it wont be resolveable. For gossip clusters that dont provide a public VFS store, we can at least use kubernetes.default for internal oidc usage.
Good point, I've updated this to only affect gossip clusters |
An integration test would not be amiss. |
/hold cancel |
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: johngmyers, olemarkus The full list of commands accepted by this bot can be found here. The pull request process is described here
Needs approval from an approver in each of these files:
Approvers can indicate their approval by writing |
It doesn't make sense to use a gossip hostname as the discovery url because it wont be resolveable.
For gossip clusters that dont provide a public VFS store, we can at least use kubernetes.default for internal oidc usage.
the goal of this is to fix the oidc tests for the e2e prow jobs that use gossip clusters:
https://testgrid.k8s.io/kops-gce#kops-gce-kubetest2&show-stale-tests=
https://testgrid.k8s.io/kops-misc#e2e-kops-do-calico&show-stale-tests=
slack thread: https://kubernetes.slack.com/archives/C8MKE2G5P/p1620837506354700
/hold for feedback