fix(adguard): sync job RBAC and idempotency
ci / lint-prettier (push) Successful in 3s
ci / lint-ruff (push) Successful in 0s
ci / lint-yaml (push) Successful in 2s
ci / lint-dockerfiles (push) Successful in 1s
ci / validate (push) Successful in 1s
ci / build (push) Skipped
ci / deploy-userbot-panel (push) Skipped

- grant list+watch on adguard-deployment (rollout status hung
  without it, job hit activeDeadline and failed)
- compare content digests only (old hash embedded filenames, so
  every run patched + restarted even when in sync)

Keeps explicit rollout restart alongside reloader annotation:
one extra restart per rotation (~60d) is accepted for
determinism if reloader is down.
This commit is contained in:
forust committed 2026-09-23 13:52:57 +02:00
1 parent c42bf14c9a
commit a8f7c79934
2 files changed
+8 -5

No files matched your search

+4 -3
View File
@@ -5,8 +5,9 @@
# and create pods/exec (read-only `cat` of /data/letsencrypt/acme.json). # and create pods/exec (read-only `cat` of /data/letsencrypt/acme.json).
# It never writes anything in namespace traefik. # It never writes anything in namespace traefik.
# * namespace adguard: get/update/patch Secret `adguard-certs` (the only # * namespace adguard: get/update/patch Secret `adguard-certs` (the only
# secret it may touch) and get/patch Deployment `adguard-deployment` # secret it may touch) and get/list/watch/patch Deployment
# (`kubectl rollout restart` issues a patch; `rollout status` reads). # `adguard-deployment` (`rollout restart` issues a patch,
# `rollout status` needs list+watch).
apiVersion: v1 apiVersion: v1
kind: ServiceAccount kind: ServiceAccount
metadata: metadata:
@@ -30,7 +31,7 @@ rules:
- apiGroups: ["apps"] - apiGroups: ["apps"]
resources: ["deployments"] resources: ["deployments"]
resourceNames: ["adguard-deployment"] resourceNames: ["adguard-deployment"]
verbs: ["get", "patch"] verbs: ["get", "list", "watch", "patch"]
--- ---
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding kind: RoleBinding
+4 -2
View File
@@ -114,8 +114,10 @@ spec:
| base64 -d > "$TMP/live.crt" | base64 -d > "$TMP/live.crt"
kubectl -n "$NS" get secret "$SECRET" -o jsonpath='{.data.tls\.key}' \ kubectl -n "$NS" get secret "$SECRET" -o jsonpath='{.data.tls\.key}' \
| base64 -d > "$TMP/live.key" | base64 -d > "$TMP/live.key"
NEW_HASH="$(sha256sum "$TMP/new.crt" "$TMP/new.key" | sha256sum | cut -d' ' -f1)" # Compare content digests only (never filenames: identical
LIVE_HASH="$(sha256sum "$TMP/live.crt" "$TMP/live.key" | sha256sum | cut -d' ' -f1)" # content under different paths must hash equal).
NEW_HASH="$(sha256sum "$TMP/new.crt" | cut -d' ' -f1)$(sha256sum "$TMP/new.key" | cut -d' ' -f1)"
LIVE_HASH="$(sha256sum "$TMP/live.crt" | cut -d' ' -f1)$(sha256sum "$TMP/live.key" | cut -d' ' -f1)"
if [ "$NEW_HASH" = "$LIVE_HASH" ]; then if [ "$NEW_HASH" = "$LIVE_HASH" ]; then
echo "secret ${SECRET} already holds the current ${DOMAIN} cert, nothing to do" echo "secret ${SECRET} already holds the current ${DOMAIN} cert, nothing to do"
exit 0 exit 0