Sitelet https://github.com/kubernetes/kops/pull/18384
Skip to content

Fix kops get assets when spec.dnsZone is a DNS name - #18384

Merged
k8s-ci-robot merged 1 commit into
kubernetes:masterfrom
hakman:fix-get-assets
May 21, 2026
Merged

k8s-ci-robot merged 1 commit into
kubernetes:masterfrom
hakman:fix-get-assets

Conversation

@hakman

@hakman hakman commented May 21, 2026

Copy link
Copy Markdown
Member

kops get assets runs with checkExisting disabled, so DNSZone.Find is skipped and ZoneID is never populated from a DNS-name dnsZone. IAMRolePolicy.ShouldCreate then aborts the run with "DNS ZoneID not set" before assets.Copy is reached.
Fall back to DNSName when ZoneID is empty. The rendered policy is discarded in dry-run modes; real applies always populate ZoneID before this path runs.

Fixes #17713
Fixes #17714

/cc @rifelpet @ameukam

@k8s-ci-robot
k8s-ci-robot requested review from ameukam and rifelpet May 21, 2026 03:10
@k8s-ci-robot k8s-ci-robot added cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. size/M Denotes a PR that changes 30-99 lines, ignoring generated files. labels May 21, 2026
@hakman
hakman force-pushed the fix-get-assets branch 2 times, most recently from fe5b3f8 to e9a3bbd Compare May 21, 2026 03:22
@hakman

hakman commented May 21, 2026

Copy link
Copy Markdown
Member Author

/test all

`kops get assets` runs with checkExisting disabled, so DNSZone.Find
is skipped and ZoneID is never populated from a DNS-name dnsZone.
IAMRolePolicy.ShouldCreate then aborts the run with "DNS ZoneID not
set" before assets.Copy is reached.
Fall back to DNSName when ZoneID is empty. The rendered policy is
discarded in dry-run modes; real applies always populate ZoneID
before this path runs.

Signed-off-by: Ciprian Hacman <ciprian@hakman.dev>
@hakman

hakman commented May 21, 2026

Copy link
Copy Markdown
Member Author

/test pull-kops-e2e-azure-cni-calico

@k8s-ci-robot k8s-ci-robot added the lgtm "Looks good to me", indicates that a PR is ready to be merged. label May 21, 2026
@k8s-ci-robot

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: rifelpet

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@k8s-ci-robot k8s-ci-robot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label May 21, 2026
@k8s-ci-robot
k8s-ci-robot merged commit ca32e63 into kubernetes:master May 21, 2026
39 checks passed
@hakman
hakman deleted the fix-get-assets branch May 21, 2026 10:34
k8s-ci-robot added a commit that referenced this pull request May 21, 2026
…-upstream-release-1.35

Automated cherry pick of #18384: Fix kops get assets when spec.dnsZone is a DNS name
k8s-ci-robot added a commit that referenced this pull request May 21, 2026
…-upstream-release-1.34

Automated cherry pick of #18384: Fix kops get assets when spec.dnsZone is a DNS name
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. lgtm "Looks good to me", indicates that a PR is ready to be merged. size/M Denotes a PR that changes 30-99 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

"kops get assets" fails when spec.dnsZone is not a Hosted Zone ID "kops get assets --copy" doesn't work from 1.34.0

3 participants