GoogleCloudPlatform / GoogleCloudPlatform/cloud-sql-proxy-operator

Having two AuthProxyWorkload with same selector and same connection string makes the operator fail creation

Aperta
#789 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub
Lingua principale
Go
Stelle
120
Fork
18
Metriche di merge delle PR
Nessuna PR unita negli ultimi 30g

Descrizione

**Information**:
Having 2 `AuthProxyWorkload` with same selector and same connection string makes the operator fail. This should still work, as there is no conflicting information and allows a smooth rollover.

The question is, how would one handle 2 conflicting ones, but I think this one should not fail, if it's not conflicting information. But I guess this a design choice? Looking forward to your thoughts!

**Version where the error occured**:
1.7.8

**Reproduced on latest version**:
Yes

**Logs / Further Info**:
```
Name: open-webui-pgbouncer-78dd849f95.18c83568c85e5cc4
Namespace: open-webui
Labels:
Annotations:
API Version: events.k8s.io/v1
Deprecated Count: 8
Deprecated First Timestamp: 2026-08-03T05:46:16Z
Deprecated Last Timestamp: 2026-08-03T05:46:21Z
Deprecated Source:
Component: replicaset-controller
Event Time:
Kind: Event
Metadata:
Creation Timestamp: 2026-08-03T05:46:16Z
Resource Version: 1785735981523231007
UID: 68fb8469-a62e-43b2-b1b8-4b340decc481
Note: Error creating: admission webhook "pods.proxy.cloudsql.google.com" denied the request: there is an AuthProxyWorkloadConfiguration error reconciling this workload found 1 configuration errors on workload /v1, Kind=Pod open-webui/: [{PortConflict proxy port 5432 for instance REDACTED:europe-west3:shared-postgres is already in use open-webui-pgbouncer-double open-webui /v1, Kind=Pod open-webui}]
Reason: FailedCreate
Regarding:
API Version: apps/v1
Kind: ReplicaSet
Name: open-webui-pgbouncer-78dd849f95
Namespace: open-webui
Resource Version: 1785735959118047010
UID: 08199b78-c069-4b24-98c1-3c421656f9b5
Reporting Controller: replicaset-controller
Type: Warning
Events:

```

Guida per i contributori

Apri la guida per i contributori

Direzione di ricerca

Start at the admission webhook's AuthProxyWorkload configuration reconciliation and the PortConflict reported for proxy port 5432. Reproduce the case with two AuthProxyWorkload resources using the same selector and connection string, then determine the expected handling for identical versus conflicting configurations and add regression coverage for the agreed behavior.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Stack tecnologico
go, google-cloud, kubernetes
Ambito
cloud, infrastructure
Tipo di issue
Bug
Difficoltà
4/5
Tempo stimato
3-5 giorni
Stato di attività
Tranquilla
Chiarezza
Abbastanza chiara
Idoneità per principianti
48/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.