Skip to content

ConfigConnector Webhook uses deprecated 'CommonName' field for certificates and cannot be installed in k8s 1.19.x #335

Description

@Tonyqu123

Describe the bug
After install the k8s-config-connector on our k8s cluster[version: 1.19.3]. I try to install an sql instance by following the sample yaml. Use the command kubectl create -f /path/to/sample-sql.yaml

Error from server (InternalError): error when creating "/Users/i519593/Code/cnrm/tmp/samples/sql.yaml": Internal error occurred: failed calling webhook "annotation-defaulter.cnrm.cloud.google.com": Post "https://cnrm-validating-webhook.cnrm-system.svc:443/annotation-defaulter?timeout=30s": x509: certificate relies on legacy Common Name field, use SANs or temporarily enable Common Name matching with GODEBUG=x509ignoreCN=0

ConfigConnector Version
1.16.0

To Reproduce
Install a k8s 1.19.x cluster. kubectl create -f /path/to/sample-sql.yaml

YAML snippets:
apiVersion: sql.cnrm.cloud.google.com/v1beta1
kind: SQLInstance
metadata:
name: sqlinstance-sample-mysql
spec:
databaseVersion: MYSQL_5_7
region: us-central1
settings:
tier: db-f1-micro%

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions