open-policy-agent / open-policy-agent/cert-controller

CA and Server certificate potentially get updated before ValidatingWebhookConfiguration

Open
#13 14 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Go
Stars
109
Forks
48
Avg merge
19h 20m
Merged PRs (30d)
6

Description

Is it not a problem that the ValidatingWebhookConfiguration and the Secret are updated independently from each other? I think this can lead to the condition where the CA is already renewed but the ValidatingWebhookConfiguration still have the old CA and thus calls to the webhook would fail?

I did not really had problems with this. I only looked into the code and thought that this might become a problem. Or do I miss something?

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No files or tests are named. Start by tracing where the Secret and ValidatingWebhookConfiguration are updated during certificate renewal, then verify whether an intermediate state can break webhook calls; done means confirming or ruling out the race and documenting the required change.

Written by the indexing model from the issue text.

Assessment

Tech stack
go, kubernetes
Domain
infrastructure, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.