sync: rework find-by-name behavior - #1506
Draft
kenjenkins wants to merge 1 commit into
Draft
kenjenkins wants to merge 1 commit into
kenjenkins wants to merge 1 commit into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
The ingress-controller sync functionality has logic to find an entity by name if the
api.pomerium.ioID annotation is lost. It also has logic delete & recreate entities if the--sync-api-namespace-idargument changes.However, these two behaviors do not currently work together correctly. If an entity is found by name in a different namespace than expected, the sync logic will try to update it rather than deleting and recreating it. This can cause ingress-controller to get stuck for that entity.
Instead of trying to do both things at once, separate these into two separate passes: the first pass will just restore the missing ID annotation. This annotation change will cause the object to be queued for reconciliation again. The second pass can then delete & recreate if needed.
Also log (at debug level) when deleting an entity due to a namespace change.
Related issues
TBD
Checklist
improvement/bug/ etc)