Skip to content

containercluster: can't disable workloadIdentityConfig once enabled #437

Description

@jonnylangefeld

Checklist

Bug Description

I created a simple containercluster resource with workload identity enabled.

╰─ kubectl get containercluster paas-jonny1-dev-us-west1 -o jsonpath={.spec.workloadIdentityConfig}
{"identityNamespace":"my-project.svc.id.goog"}

This all works and on GCP, I see that it's enabled for my cluster:
Screen Shot 2021-03-25 at 12 17 06 AM

But now it doesn't work to disable it on an existing cluster.

I'm trying to disable by running

╰─ kubectl patch containercluster/paas-jonny1-dev-us-west1 -p '{"spec":{"workloadIdentityConfig":null}}' --type=merge
containercluster.container.cnrm.cloud.google.com/paas-jonny1-dev-us-west1 patched

By watching the containercluster in a separate window via

watch kubectl get containercluster paas-jonny1-dev-us-west1 -o jsonpath={.spec.workloadIdentityConfig}

I see that my patch command actually removes the .spec.workloadIdentityConfig as expected, but right after the cnrm-controller-manager adds it back in (probably because it takes what's on GCP as source of truth).

If I explicitly set spec.workloadIdentityConfig to null, I would expect that the feature gets disabled on GCP. I have also tried setting it to {} instead of null, but that doesn't work either.

Additional Diagnostic Information

Kubernetes Cluster Version

Client Version: v1.20.4
Server Version: v1.16.15-gke.7800

Config Connector Version

1.32.0

Config Connector Mode

cluster

Log Output

{"severity":"info","logger":"containercluster-controller","msg":"starting reconcile","resource":{"namespace":"clusters","name":"paas-jonny1-dev-us-west1"}}
{"severity":"info","logger":"containercluster-controller","msg":"creating/updating underlying resource","resource":{"namespace":"clusters","name":"paas-jonny1-dev-us-west1"}}
{"severity":"info","logger":"containercluster-controller","msg":"successfully finished reconcile","resource":{"namespace":"clusters","name":"paas-jonny1-dev-us-west1"}}
{"severity":"info","logger":"containercluster-controller","msg":"starting reconcile","resource":{"namespace":"clusters","name":"paas-jonny1-dev-us-west1"}}
{"severity":"info","logger":"containercluster-controller","msg":"underlying resource already up to date","resource":{"namespace":"clusters","name":"paas-jonny1-dev-us-west1"}}
{"severity":"info","logger":"containercluster-controller","msg":"successfully finished reconcile","resource":{"namespace":"clusters","name":"paas-jonny1-dev-us-west1"}}
{"severity":"info","logger":"containercluster-controller","msg":"starting reconcile","resource":{"namespace":"clusters","name":"paas-jonny1-dev-us-west1"}}
{"severity":"info","logger":"containercluster-controller","msg":"underlying resource already up to date","resource":{"namespace":"clusters","name":"paas-jonny1-dev-us-west1"}}
{"severity":"info","logger":"containercluster-controller","msg":"successfully finished reconcile","resource":{"namespace":"clusters","name":"paas-jonny1-dev-us-west1"}}

Steps to Reproduce

Steps to reproduce the issue

  1. create a containercluster with workload identity enabled
  2. disable workload identity via the containercluster resource

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions