New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
make externalAdmissionHookConfigurationManager distinguish API disabled error #48576
make externalAdmissionHookConfigurationManager distinguish API disabled error #48576
Conversation
Thanks! Unit test? |
97f3fb4
to
6a1308d
Compare
Added unit tests. |
…ed error Also added unit tests
6a1308d
to
9eb065f
Compare
@lavalamp PTAL. Thanks. |
@wojtek-t this is a bug fix. Without this fix, apiserver enters crashloop if a user enables the GenericWebhook admission plugin but not the admissionregistration/v1alpha1 API. |
@caesarxuchao - can you please add a release note - with that I'm obviously fine with cherrypicking it. |
Release note added. |
@caesarxuchao - thanks! I will add "cherrypick-approved" label once this is lgtmed (and will create a cherrypick then - it's just easier for me to manage proposal this way). |
/lgtm |
@wojtek-t could you approve the cherrypick? Thanks. |
/test pull-kubernetes-kubemark-e2e-gce |
/approve no-issue |
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: caesarxuchao, lavalamp, wojtek-t Associated issue requirement bypassed by: wojtek-t The full list of commands accepted by this bot can be found here.
Needs approval from an approver in each of these OWNERS Files:
You can indicate your approval by writing |
Automatic merge from submit-queue (batch tested with PRs 48576, 49010) |
@caesarxuchao - cherrypicking it makes sense to me, but it's not possible to make automated cherrypick from it due to conflicts. Can you prepare a cherrypick if you want this in 1.7 branch? |
Thanks. Cherrypicked in #49155 |
…#48576-upstream-release-1.7 Automated cherry pick of #48576
Commit found in the "release-1.7" branch appears to be this PR. Removing the "cherrypick-candidate" label. If this is an error find help to get your PR picked. |
The externalAdmissionHookConfigurationManager does not return "DisabledErr" even if the API is disabled, so the GenericWebhook admission controller will not fail open.
The GenericWebhook admission controller is default to off, so the bug is hidden in most cases. To be safe, we should cherrypick it to 1.7.