The ValidatingWebhookConfiguration in the apisix-ingress-controller chart renders with no annotations and no way to add any. With webhook.certificate.provided=true, operators supplying the serving certificate from a cert-manager Certificate must hand-copy the CA into webhook.certificate.caBundle — and re-copy it whenever the CA rotates, or the API server silently stops trusting the webhook (with the default failurePolicy: Ignore, admission validation is skipped without any visible failure).
The ecosystem-standard fix is cert-manager's cainjector: annotate the webhook configuration with cert-manager.io/inject-ca-from: <namespace>/<certificate> and the caBundle is maintained automatically, rotation included. That needs only an annotations knob on the webhook template.
Proposed fix in #1004 — adds webhook.annotations (default {}); unset output is byte-identical to today.
The
ValidatingWebhookConfigurationin the apisix-ingress-controller chart renders with no annotations and no way to add any. Withwebhook.certificate.provided=true, operators supplying the serving certificate from a cert-managerCertificatemust hand-copy the CA intowebhook.certificate.caBundle— and re-copy it whenever the CA rotates, or the API server silently stops trusting the webhook (with the defaultfailurePolicy: Ignore, admission validation is skipped without any visible failure).The ecosystem-standard fix is cert-manager's cainjector: annotate the webhook configuration with
cert-manager.io/inject-ca-from: <namespace>/<certificate>and the caBundle is maintained automatically, rotation included. That needs only an annotations knob on the webhook template.Proposed fix in #1004 — adds
webhook.annotations(default{}); unset output is byte-identical to today.