-
Notifications
You must be signed in to change notification settings - Fork 6.5k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
kube_encryption_resources must be output as yaml #6309
kube_encryption_resources must be output as yaml #6309
Conversation
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: mirwan The full list of commands accepted by this bot can be found here. The pull request process is described here
Needs approval from an approver in each of these files:
Approvers can indicate their approval by writing |
I'm not sure this is needed, here is an output of what I got as of now
Compared to your version
Am I missing something ? |
@floryut That is the output I get:
I don't know what is the root cause (py version on the remote host, control machine, ...). |
@floryut What do you think ? |
Can we add a test case for it? Like a file in |
Well as of now we kind of already have a test for it as it's default to |
Lets merge that, we can always add another PR if we want to further test things, as long as this fix a bug in some cases |
@floryut Thx for the approval. |
* 'master' of https://github.com/kubernetes-sigs/kubespray: (22 commits) Remove runtime-config from kubeadm if empty (kubernetes-sigs#6311) Update deprecated api (kubernetes-sigs#6245) Update kube-router to 1.0.0 (kubernetes-sigs#6211) Fix kubelet cgroup driver detection for crio (kubernetes-sigs#6331) Update hashes and set default version to 1.18.5 (kubernetes-sigs#6335) Change MetalLB to one of addons (kubernetes-sigs#6238) Update calico to 1.15.0 + minor update to kube-ovn/weave (kubernetes-sigs#6306) Add .editorconfig file (kubernetes-sigs#6307) Use NetworkManager to manage resolv.conf in FedoraCoreOS (kubernetes-sigs#6291) Add USE_REAL_HOSTNAME to inventory.py (kubernetes-sigs#6293) Cleanup OpenStack network things (kubernetes-sigs#6283) Add support for dns_etchosts (kubernetes-sigs#6236) kube_encryption_resources must be output as yaml (kubernetes-sigs#6309) Gather ansible_default_ipv4 for specific groups (kubernetes-sigs#6318) added azure_cloud parameter to Azure's cloud_config (kubernetes-sigs#6321) Fix some doc links (kubernetes-sigs#6328) Use `connection: local` when `delegate_to: localhost` (kubernetes-sigs#6322) Add /dev volume (kubernetes-sigs#6319) Update cilium to 1.8.0 (kubernetes-sigs#6314) fix use of ansible tags (kubernetes-sigs#6316) ...
@mirwan thanks for this. it was weird because new clusters were fine, but it was killing my upgrades. |
We need this cherrypicked to release-2.13 |
Please do, we could always do another tag with the 1.18.9 I guess |
What type of PR is this?
/kind bug
What this PR does / why we need it:
kube_encryption_resources
variable (list) is rendered as plain text from secrets_encryption.yaml.j2 template, elements of this list (strings) are prefixed with unicode "u" prefix in the rendered manifest.As a consequence, encryption at REST is simply ignored for these resources.
This variable must be serialized as yaml, that's what this PR does.
Which issue(s) this PR fixes:
None
Special notes for your reviewer:
N/A
Does this PR introduce a user-facing change?: