Skip to content

Commit

Permalink
Merge pull request #361 from tnozicka/reload-client-certs
Browse files Browse the repository at this point in the history
Bug 1810008: Reload client certs
  • Loading branch information
openshift-merge-robot committed Mar 9, 2020
2 parents bef4f05 + b64ea08 commit de1d81d
Show file tree
Hide file tree
Showing 3 changed files with 5 additions and 5 deletions.
4 changes: 2 additions & 2 deletions bindata/v4.1.0/kube-controller-manager/kubeconfig-cm.yaml
Expand Up @@ -22,5 +22,5 @@ data:
users:
- name: kube-controller-manager
user:
client-certificate: /etc/kubernetes/static-pod-resources/secrets/kube-controller-manager-client-cert-key/tls.crt
client-key: /etc/kubernetes/static-pod-resources/secrets/kube-controller-manager-client-cert-key/tls.key
client-certificate: /etc/kubernetes/static-pod-certs/secrets/kube-controller-manager-client-cert-key/tls.crt
client-key: /etc/kubernetes/static-pod-certs/secrets/kube-controller-manager-client-cert-key/tls.key
2 changes: 1 addition & 1 deletion pkg/operator/starter.go
Expand Up @@ -186,7 +186,6 @@ var deploymentConfigMaps = []revision.RevisionResource{

// deploymentSecrets is a list of secrets that are directly copied for the current values. A different actor/controller modifies these.
var deploymentSecrets = []revision.RevisionResource{
{Name: "kube-controller-manager-client-cert-key"},
{Name: "service-account-private-key"},

// this cert is created by the service-ca controller, which doesn't come up until after we are available. this piece of config must be optional.
Expand All @@ -205,5 +204,6 @@ var CertConfigMaps = []revision.RevisionResource{
}

var CertSecrets = []revision.RevisionResource{
{Name: "kube-controller-manager-client-cert-key"},
{Name: "csr-signer"},
}
4 changes: 2 additions & 2 deletions pkg/operator/v411_00_assets/bindata.go

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

0 comments on commit de1d81d

Please sign in to comment.