Sitelet https://github.com/kubernetes/kops/commit/0155a74d5f879ceeb643ff7176132b93b846eb30
Skip to content

Commit 0155a74

Browse files
committed
nodeup: don't mutate the cluster spec when clearing authenticator config
BuildNodeUpConfig assigned the shared Authentication pointer into the nodeup config and then replaced its AWS field with an empty struct, wiping spec.authentication.aws on the live cluster object. Since #18215 moved addon rendering to task run time, the aws-iam-authenticator manifest rendered after this mutation, losing backendMode, clusterID and identityMappings. Copy the struct before clearing the field, and extend the complex integration test to cover backendMode: CRD with identity mappings.
1 parent 83dc088 commit 0155a74

6 files changed

Lines changed: 49 additions & 13 deletions

‎pkg/apis/nodeup/config.go‎

Lines changed: 5 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -375,11 +375,13 @@ func NewConfig(cluster *kops.Cluster, instanceGroup *kops.InstanceGroup) (*Confi
375375
},
376376
}
377377
if cluster.Spec.Authentication != nil {
378-
config.APIServerConfig.Authentication = cluster.Spec.Authentication
379-
if cluster.Spec.Authentication.AWS != nil {
378+
// Copy before clearing fields, so that we don't mutate the shared cluster spec.
379+
authentication := *cluster.Spec.Authentication
380+
if authentication.AWS != nil {
380381
// The values go into the manifest and aren't needed by nodeup.
381-
config.APIServerConfig.Authentication.AWS = &kops.AWSAuthenticationSpec{}
382+
authentication.AWS = &kops.AWSAuthenticationSpec{}
382383
}
384+
config.APIServerConfig.Authentication = &authentication
383385
}
384386
if cluster.Spec.API.DNS != nil {
385387
config.APIServerConfig.API.DNS = &kops.DNSAccessSpec{}

‎tests/integration/update_cluster/complex/data/aws_s3_object_cluster-completed.spec_content‎

Lines changed: 8 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,14 @@ spec:
2323
name: us-test-1a
2424
type: Public
2525
authentication:
26-
aws: {}
26+
aws:
27+
backendMode: CRD
28+
clusterID: complex.example.com
29+
identityMappings:
30+
- arn: arn:aws:iam::000000000000:role/AWSReservedSSO_Developer_7de86b085b6056ae
31+
groups:
32+
- he:dev
33+
username: dev:{{SessionNameRaw}}
2734
authorization:
2835
rbac: {}
2936
channel: stable

‎tests/integration/update_cluster/complex/data/aws_s3_object_complex.example.com-addons-authentication.aws-k8s-1.12_content‎

Lines changed: 19 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -155,9 +155,10 @@ spec:
155155
containers:
156156
- args:
157157
- server
158-
- --config=/etc/aws-iam-authenticator/config.yaml
158+
- --cluster-id=complex.example.com
159159
- --state-dir=/var/aws-iam-authenticator
160160
- --kubeconfig-pregenerated=true
161+
- --backend-mode=CRD
161162
image: public.ecr.aws/eks-distro/kubernetes-sigs/aws-iam-authenticator:v0.6.20-eks-1-30-7
162163
livenessProbe:
163164
httpGet:
@@ -180,8 +181,6 @@ spec:
180181
runAsGroup: 10000
181182
runAsUser: 10000
182183
volumeMounts:
183-
- mountPath: /etc/aws-iam-authenticator/
184-
name: config
185184
- mountPath: /var/aws-iam-authenticator/
186185
name: state
187186
- mountPath: /etc/kubernetes/aws-iam-authenticator/
@@ -203,9 +202,6 @@ spec:
203202
- key: CriticalAddonsOnly
204203
operator: Exists
205204
volumes:
206-
- configMap:
207-
name: aws-iam-authenticator
208-
name: config
209205
- hostPath:
210206
path: /srv/kubernetes/aws-iam-authenticator/
211207
name: output
@@ -214,3 +210,20 @@ spec:
214210
name: state
215211
updateStrategy:
216212
type: RollingUpdate
213+
214+
---
215+
216+
apiVersion: iamauthenticator.k8s.aws/v1alpha1
217+
kind: IAMIdentityMapping
218+
metadata:
219+
labels:
220+
addon.kops.k8s.io/name: authentication.aws
221+
app.kubernetes.io/managed-by: kops
222+
k8s-app: aws-iam-authenticator
223+
role.kubernetes.io/authentication: "1"
224+
name: iam-identity-mapping-0
225+
spec:
226+
arn: arn:aws:iam::000000000000:role/AWSReservedSSO_Developer_7de86b085b6056ae
227+
groups:
228+
- he:dev
229+
username: dev:{{SessionNameRaw}}

‎tests/integration/update_cluster/complex/data/aws_s3_object_complex.example.com-addons-bootstrap_content‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -91,7 +91,7 @@ spec:
9191
k8s-addon: storage-aws.addons.k8s.io
9292
- id: k8s-1.12
9393
manifest: authentication.aws/k8s-1.12.yaml
94-
manifestHash: 7233a06582f37d422ad0fd908ff5c23965edff21d81e5888549c9ea9089a8309
94+
manifestHash: 0e9091db37b82a2c506d68ed1e628e62247b202db51d34edce140f35b9a3084e
9595
name: authentication.aws
9696
selector:
9797
role.kubernetes.io/authentication: "1"

‎tests/integration/update_cluster/complex/in-legacy-v1alpha2.yaml‎

Lines changed: 8 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,14 @@ spec:
2020
accessLog:
2121
bucket: access-log-example
2222
authentication:
23-
aws: {}
23+
aws:
24+
backendMode: CRD
25+
clusterID: complex.example.com
26+
identityMappings:
27+
- arn: arn:aws:iam::000000000000:role/AWSReservedSSO_Developer_7de86b085b6056ae
28+
groups:
29+
- he:dev
30+
username: dev:{{SessionNameRaw}}
2431
kubernetesApiAccess:
2532
- 1.1.1.0/24
2633
- pl-44444444

‎tests/integration/update_cluster/complex/in-v1alpha2.yaml‎

Lines changed: 8 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,14 @@ spec:
2020
accessLog:
2121
bucket: access-log-example
2222
authentication:
23-
aws: {}
23+
aws:
24+
backendMode: CRD
25+
clusterID: complex.example.com
26+
identityMappings:
27+
- arn: arn:aws:iam::000000000000:role/AWSReservedSSO_Developer_7de86b085b6056ae
28+
groups:
29+
- he:dev
30+
username: dev:{{SessionNameRaw}}
2431
kubernetesApiAccess:
2532
- 1.1.1.0/24
2633
- pl-44444444

0 commit comments

Comments
 (0)