fix(adguard): sync job RBAC and idempotency
ci / lint-prettier (push) Successful in 3s
ci / lint-ruff (push) Successful in 0s
ci / lint-yaml (push) Successful in 2s
ci / lint-dockerfiles (push) Successful in 1s
ci / validate (push) Successful in 1s
ci / build (push) Skipped
ci / deploy-userbot-panel (push) Skipped
ci / lint-prettier (push) Successful in 3s
ci / lint-ruff (push) Successful in 0s
ci / lint-yaml (push) Successful in 2s
ci / lint-dockerfiles (push) Successful in 1s
ci / validate (push) Successful in 1s
ci / build (push) Skipped
ci / deploy-userbot-panel (push) Skipped
- grant list+watch on adguard-deployment (rollout status hung without it, job hit activeDeadline and failed) - compare content digests only (old hash embedded filenames, so every run patched + restarted even when in sync) Keeps explicit rollout restart alongside reloader annotation: one extra restart per rotation (~60d) is accepted for determinism if reloader is down.
This commit is contained in:
1 parent
c42bf14c9a
commit
a8f7c79934
2 files changed
+8
-5
No files matched your search
@@ -5,8 +5,9 @@
|
||||
# and create pods/exec (read-only `cat` of /data/letsencrypt/acme.json).
|
||||
# It never writes anything in namespace traefik.
|
||||
# * namespace adguard: get/update/patch Secret `adguard-certs` (the only
|
||||
# secret it may touch) and get/patch Deployment `adguard-deployment`
|
||||
# (`kubectl rollout restart` issues a patch; `rollout status` reads).
|
||||
# secret it may touch) and get/list/watch/patch Deployment
|
||||
# `adguard-deployment` (`rollout restart` issues a patch,
|
||||
# `rollout status` needs list+watch).
|
||||
apiVersion: v1
|
||||
kind: ServiceAccount
|
||||
metadata:
|
||||
@@ -30,7 +31,7 @@ rules:
|
||||
- apiGroups: ["apps"]
|
||||
resources: ["deployments"]
|
||||
resourceNames: ["adguard-deployment"]
|
||||
verbs: ["get", "patch"]
|
||||
verbs: ["get", "list", "watch", "patch"]
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: RoleBinding
|
||||
|
||||
@@ -114,8 +114,10 @@ spec:
|
||||
| base64 -d > "$TMP/live.crt"
|
||||
kubectl -n "$NS" get secret "$SECRET" -o jsonpath='{.data.tls\.key}' \
|
||||
| base64 -d > "$TMP/live.key"
|
||||
NEW_HASH="$(sha256sum "$TMP/new.crt" "$TMP/new.key" | sha256sum | cut -d' ' -f1)"
|
||||
LIVE_HASH="$(sha256sum "$TMP/live.crt" "$TMP/live.key" | sha256sum | cut -d' ' -f1)"
|
||||
# Compare content digests only (never filenames: identical
|
||||
# content under different paths must hash equal).
|
||||
NEW_HASH="$(sha256sum "$TMP/new.crt" | cut -d' ' -f1)$(sha256sum "$TMP/new.key" | cut -d' ' -f1)"
|
||||
LIVE_HASH="$(sha256sum "$TMP/live.crt" | cut -d' ' -f1)$(sha256sum "$TMP/live.key" | cut -d' ' -f1)"
|
||||
if [ "$NEW_HASH" = "$LIVE_HASH" ]; then
|
||||
echo "secret ${SECRET} already holds the current ${DOMAIN} cert, nothing to do"
|
||||
exit 0
|
||||
|
||||
Reference in new issue
Block a user