jetstack-bot and GitHub
7c53f88f19
Merge pull request #3476 from maelvls/unit-test-backoff-one-hour
...
Move the 'back off for 1 hour' logic to a unit-tested func
2020-12-08 11:02:17 +01:00
Maël Valais
62f8db6e6a
refactor(issuing): PR review: use MustCreateCryptoBundle directly
...
Signed-off-by: Maël Valais <mael.valais@gmail.com >
2020-12-06 14:22:02 +01:00
Maël Valais
6484010f5c
fix(issuing): wait until req matches cert before setting failure
...
The issuing controller wasn't checking if the certificate request that
it picked up is up to date. That resulted in the certificate being set
to "Failing" and "Issuing = False" due to an old certificate request
that was created during a previous issuance. The certificate would then
become stale.
Signed-off-by: Maël Valais <mael.valais@gmail.com >
2020-12-06 14:22:02 +01:00
Maël Valais
17cd05ecab
test(issuing): new test: when req mismatches, cert can't be updated
...
This new unit test highlights an unexpected behavior of the issuing
controller: the issuing controller is updating the certificate's status
when the certificate request has a failure ("Reason = Failed"), but the
controller might have picked up an out-of-date certificate request.
The consequence is that the issuing controller would set the certificate
to "Issuing = False". That happens when a re-issuance is triggered with
an old failing certificate request.
Signed-off-by: Maël Valais <mael.valais@gmail.com >
2020-12-06 14:22:02 +01:00
Maël Valais
07fd8754f5
refactor(trigger): add test case when failure just happened
...
Signed-off-by: Maël Valais <mael.valais@gmail.com >
2020-12-06 13:51:12 +01:00
Maël Valais
769303c5f8
refactor(trigger): don't backoff when exactly 60min
...
As Maartje mentioned, it doesn't make sense to return backoff = true
while returning a delay of 0. Also, use time.UTC instead of time.Local.
Signed-off-by: Maël Valais <mael.valais@gmail.com >
2020-12-06 13:44:06 +01:00
Maël Valais
27d4924b5a
refactor(trigger): move backoff logic to a unit-tested func
...
The trigger_controller_test.go has many unrelated test cases and I
thought it would be good to have more tightly scoped functions that are
easy to review (and most importantly, the unit tests are easy to
review).
Signed-off-by: Maël Valais <mael.valais@gmail.com >
2020-12-06 13:40:01 +01:00
Richard Wall
1fc1fa88a0
Prevent instant renewal when the renewBefore value matches the duration
...
Signed-off-by: Richard Wall <richard.wall@jetstack.io >
2020-11-19 15:00:27 +00:00
Richard Wall
95a229cc6e
Unit tests for current behaviour
...
Signed-off-by: Richard Wall <richard.wall@jetstack.io >
2020-11-19 13:01:00 +00:00
Richard Wall
a33abd2060
Plumb through the flag provided defaultRenewBeforeExpiryDuration
...
Signed-off-by: Richard Wall <richard.wall@jetstack.io >
2020-11-19 12:44:18 +00:00
Mateusz Gozdek
27fa2f1ec4
Fix various typos found by codespell
...
Found by running this command:
codespell -S .git,*.png,go.sum -L keypair,iam,ans,unknwon,tage,ths,creater
Signed-off-by: Mateusz Gozdek <mgozdekof@gmail.com >
2020-11-07 14:55:13 +01:00
Maartje Eyskens
f1c6c93df5
Fix CR and make a general function
...
Signed-off-by: Maartje Eyskens <maartje@eyskens.me >
2020-08-28 15:06:54 +02:00
Richard Wall
9d0559cfda
Compare email addresses in RequestMatchesSpec
...
Signed-off-by: Richard Wall <richard.wall@jetstack.io >
2020-08-27 09:10:57 +01:00
Richard Wall
3107b380f2
Replace some references to URISANs and EmailSANs
...
Signed-off-by: Richard Wall <richard.wall@jetstack.io >
2020-08-26 16:52:08 +01:00
Richard Wall
e8185e73f1
Remove duplicate import
...
Signed-off-by: Richard Wall <richard.wall@jetstack.io >
2020-08-26 16:47:47 +01:00
Lars Lehtonen
aab6b479c5
pkg/controller/certificates/internal: fix dropped test errors
...
Signed-off-by: Lars Lehtonen <lars.lehtonen@gmail.com >
2020-08-21 21:39:29 -07:00
Richard Wall
01b5d0fa88
Fix tests in ./pkg/controller/certificates/...
...
Signed-off-by: Richard Wall <richard.wall@jetstack.io >
2020-08-20 14:28:06 +01:00
Richard Wall
81eb53f597
./hack/update-all.sh
...
Signed-off-by: Richard Wall <richard.wall@jetstack.io >
2020-08-20 14:28:06 +01:00
Richard Wall
a70298180a
Run a script to update v1alpha2 usage to v1
...
Script is available at https://github.com/jetstack/cert-manager/pull/3201
Signed-off-by: Richard Wall <richard.wall@jetstack.io >
2020-08-20 14:26:51 +01:00
Richard Wall
2b1e1d1d2b
Remove deprecated issuer related annotation key constants from the API
...
Signed-off-by: Richard Wall <richard.wall@jetstack.io >
2020-08-14 17:07:36 +01:00
jetstack-bot and GitHub
d9ad986823
Merge pull request #3173 from wallrj/p12-intermed-cert
...
Add intermediate cert to P12 chain if ca.crt is empty
2020-08-12 13:18:59 +01:00
Maartje Eyskens and Richard Wall
d2f86c410a
Add intermediate cert to P12 chain if ca.crt is empty
...
Signed-off-by: Maartje Eyskens <maartje@eyskens.me >
2020-08-12 12:39:27 +01:00
Richard Wall
5acb052194
A test for certificate chains
...
Signed-off-by: Richard Wall <richard.wall@jetstack.io >
2020-08-12 12:39:27 +01:00
Maartje Eyskens
3259fdfe9b
Implement feedback
...
Signed-off-by: Maartje Eyskens <maartje@eyskens.me >
2020-08-12 10:59:42 +02:00
Maartje Eyskens
827ce9c5ad
Revert log levels on errors
...
Signed-off-by: Maartje Eyskens <maartje@eyskens.me >
2020-08-12 10:59:42 +02:00
Maartje Eyskens
86dee5ed41
Set error log levels
...
Signed-off-by: Maartje Eyskens <maartje@eyskens.me >
2020-08-12 10:59:41 +02:00
Maartje Eyskens
fecd0b3518
Set all log levels for info
...
Signed-off-by: Maartje Eyskens <maartje@eyskens.me >
2020-08-12 10:59:41 +02:00
Richard Wall
46d4ea768b
Update test for pkcs12 encoded CA data
...
Signed-off-by: Richard Wall <richard.wall@jetstack.io >
2020-08-07 17:26:59 +01:00
JoshVanL
016b566689
Adds Issuer Group to Secret annotation
...
Signed-off-by: JoshVanL <vleeuwenjoshua@gmail.com >
2020-08-06 09:24:37 +01:00
James Munnelly
fdc0960d27
Schedule a 'resync' of Certificates that have been marked as failed and are to be retried later
...
Signed-off-by: James Munnelly <james@munnelly.eu >
2020-07-20 09:19:11 +01:00
Haoxiang Zhou
fe80b7d760
Moved predicate package to pkg/util
...
Signed-off-by: Haoxiang Zhou <haoxiang.zhou@jetstack.io >
2020-07-02 12:23:15 +01:00
James Munnelly
9e2d6a514b
Move expcertificates into certificates package
...
Signed-off-by: James Munnelly <james@munnelly.eu >
2020-07-01 12:16:25 +01:00
James Munnelly
2280480c02
Remove old certificates controller
...
Signed-off-by: James Munnelly <james@munnelly.eu >
2020-07-01 11:46:13 +01:00
James Munnelly
6caa4c451d
Rename CRPrivateKeyAnnotationKey -> CertificateRequestPrivateKeyAnnotationKey
...
Signed-off-by: James Munnelly <james@munnelly.eu >
2020-06-26 14:47:27 +01:00
James Munnelly
1adfe16690
Bulk fix of non-test staticcheck failures
...
Signed-off-by: James Munnelly <james@munnelly.eu >
2020-06-26 12:25:08 +01:00
James Munnelly
1d6424b8f2
Use 'clock' package in pkg/scheduler
...
Signed-off-by: James Munnelly <james@munnelly.eu >
2020-06-23 16:23:42 +01:00
jetstack-bot and GitHub
46eaf3d1a4
Merge pull request #2923 from JoshVanL/new-metrics
...
Updates the metrics package + new metrics controller
2020-06-04 12:59:38 +01:00
Haoxiang Zhou
609eedacec
Do not add ca.crt key to TLS secret if empty in expcertificates as well
...
Signed-off-by: Haoxiang Zhou <haoxiang.zhou@jetstack.io >
2020-05-26 14:37:40 +01:00
Haoxiang Zhou
3591de614d
Changed unit tests to expect no ca.crt instead of nil
...
Signed-off-by: Haoxiang Zhou <haoxiang.zhou@jetstack.io >
2020-05-26 12:16:55 +01:00
Haoxiang Zhou
dceae33364
Do not add ca.crt key to TLS secret if empty
...
Signed-off-by: Haoxiang Zhou <haoxiang.zhou@jetstack.io >
2020-05-26 12:16:20 +01:00
JoshVanL
9c9fe56f0b
Update new files to use 2020 copyright
...
Signed-off-by: JoshVanL <vleeuwenjoshua@gmail.com >
2020-05-21 10:52:56 +01:00
JoshVanL
5539bf3495
Moves metrics controller into sub-package of ./controller/certificates
...
and fix metrics listen address flag description
Signed-off-by: JoshVanL <vleeuwenjoshua@gmail.com >
2020-05-21 10:47:52 +01:00
JoshVanL
92eb8d0957
Refactor controllers to use new instrumented metrics that's baked into
...
all controllers
Signed-off-by: JoshVanL <vleeuwenjoshua@gmail.com >
2020-05-18 17:43:56 +01:00
James Munnelly
7978fbe081
Address review feedback and include truststore.jks with JKS mode enabled
...
Signed-off-by: James Munnelly <james@munnelly.eu >
2020-04-22 15:20:49 +01:00
James Munnelly
ba33c823a3
Add 'keystores' stanza to CertificateSpec to allow dynamic keystore configuration
...
Signed-off-by: James Munnelly <james@munnelly.eu >
2020-04-21 17:58:18 +01:00
James Munnelly
822b9e17a0
Remove AdditionalRunFuncs from base controller
...
Signed-off-by: James Munnelly <james@munnelly.eu >
2020-03-30 20:43:00 +01:00
James Munnelly
881b886049
Update Kubernetes API client call-sites
...
Signed-off-by: James Munnelly <james@munnelly.eu >
2020-03-26 12:58:50 +00:00
James Munnelly
acff2b12bb
Fix JKS keystore functionality and add additional tests
...
Signed-off-by: James Munnelly <james@munnelly.eu >
2020-03-23 10:02:42 +00:00
James Munnelly
98bc0d52f9
Add --experimental-issue-jks flag to enable JKS bundle generation
...
Signed-off-by: James Munnelly <james@munnelly.eu >
2020-03-04 15:33:22 +00:00
James Munnelly
e9374730c9
Add --experimental-issue-pkcs12 flag to enable PKCS12 bundle generation
...
Signed-off-by: James Munnelly <james@munnelly.eu >
2020-03-04 10:02:21 +00:00