Skip to content

fix(webhook): add defensive check for spireEnabled vs identity.type=spiffe lockstep #453

Description

@akram

Summary

The ensurePerAgentConfigMap() function now injects/scrubs the spiffe: block based on spireEnabled, while synthesizePipeline() sets identity.type=spiffe based on ClientAuthType == "federated-jwt". These two decisions are currently kept in lockstep by the mTLS-baseline auto-enable (pod_mutator.go:290), but they could diverge during the kagenti-extensions → operator webhook migration.

If a workload's effective config carries identity.type: spiffe while spireEnabled=false, the spiffe: block will be stripped, producing a startup crash ("spiffe identity requires a SPIFFE provider to be injected").

Suggested fix

Add a defensive check: if the synthesized pipeline contains identity.type=spiffe, force spireEnabled=true for the spiffe: block injection, or log a warning about the mismatch.

Context

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    Status
    New/ToDo

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions