Skip to content

apisix-ingress-controller: webhook configuration supports no annotations, blocking cert-manager cainjector #1006

Description

@ahmedgabers

The ValidatingWebhookConfiguration in the apisix-ingress-controller chart renders with no annotations and no way to add any. With webhook.certificate.provided=true, operators supplying the serving certificate from a cert-manager Certificate must hand-copy the CA into webhook.certificate.caBundle — and re-copy it whenever the CA rotates, or the API server silently stops trusting the webhook (with the default failurePolicy: Ignore, admission validation is skipped without any visible failure).

The ecosystem-standard fix is cert-manager's cainjector: annotate the webhook configuration with cert-manager.io/inject-ca-from: <namespace>/<certificate> and the caBundle is maintained automatically, rotation included. That needs only an annotations knob on the webhook template.

Proposed fix in #1004 — adds webhook.annotations (default {}); unset output is byte-identical to today.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions