Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
fix: support extraVolumes/extraVolumeMounts, fix WH CA handling (OP-388) #2800
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: 09-10-docs_add_ainav_size_check_to_lint_trim_navigation_files_and_document_management_proxy
Are you sure you want to change the base?
fix: support extraVolumes/extraVolumeMounts, fix WH CA handling (OP-388) #2800
Changes from all commits
afac063File filter
Filter by extension
Conversations
Uh oh!
There was an error while loading. Please reload this page.
Jump to
Uh oh!
There was an error while loading. Please reload this page.
There are no files selected for viewing
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Two things here.
1. Concatenating every file in the secret dir will inline a private key if the user points
cacertSecretat akubernetes.io/tlssecret. That's a very natural mistake — a TLS secret is the obvious thing to reach for, and it hastls.crt+tls.key. TheBEGIN CERTIFICATEcheck passes (thanks totls.crt), sotls.keylands verbatim inside/opt/weka/k8s-runtime/vars/wh-cacert/cert.pem, which is then pointed at byweka_cloud_ca_cert_path. Worth filtering to certificate blocks, or at least skipping files containing a private key:That also removes the need for the post-hoc content test, since a dir with no PEM certs produces no file at all.
2.
chmod 400happens only after the loop, so the file exists with the default umask (typically0644) for the duration of the concatenation. Harmless for a public CA bundle, but combined with (1) it's a real window on a private key. Set the mode before writing:(then drop the trailing
chmod, keeping only therm -rfon the no-certs path).Nit on the comment: "the glob skips the
..data/..2025_*dotfiles" — true, but the reason is that shell globs don't match leading dots, not the date; the..2025_*naming will read as stale in a year.# the glob skips the secret's ..data/..timestamp dotfilesis enough.There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The
/tmpguard is exact-match only, somountPath: /tmp/foo(or/tmp/) sails through and shadows part of the operator's owntmpdiremptyDir. Same on-or-under rule the Go side uses (IsReservedMountPath) would be more consistent:Also nothing here catches duplicate names or duplicate mount paths within the user's own lists — Kubernetes will reject the Deployment, but with a much less obvious message than the two
fails above. Low priority given the failure is at least loud.Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.