Checklist
Bug Description
I created a simple containercluster resource with workload identity enabled.
╰─ kubectl get containercluster paas-jonny1-dev-us-west1 -o jsonpath={.spec.workloadIdentityConfig}
{"identityNamespace":"my-project.svc.id.goog"}
This all works and on GCP, I see that it's enabled for my cluster:

But now it doesn't work to disable it on an existing cluster.
I'm trying to disable by running
╰─ kubectl patch containercluster/paas-jonny1-dev-us-west1 -p '{"spec":{"workloadIdentityConfig":null}}' --type=merge
containercluster.container.cnrm.cloud.google.com/paas-jonny1-dev-us-west1 patched
By watching the containercluster in a separate window via
watch kubectl get containercluster paas-jonny1-dev-us-west1 -o jsonpath={.spec.workloadIdentityConfig}
I see that my patch command actually removes the .spec.workloadIdentityConfig as expected, but right after the cnrm-controller-manager adds it back in (probably because it takes what's on GCP as source of truth).
If I explicitly set spec.workloadIdentityConfig to null, I would expect that the feature gets disabled on GCP. I have also tried setting it to {} instead of null, but that doesn't work either.
Additional Diagnostic Information
Kubernetes Cluster Version
Client Version: v1.20.4
Server Version: v1.16.15-gke.7800
Config Connector Version
Config Connector Mode
Log Output
{"severity":"info","logger":"containercluster-controller","msg":"starting reconcile","resource":{"namespace":"clusters","name":"paas-jonny1-dev-us-west1"}}
{"severity":"info","logger":"containercluster-controller","msg":"creating/updating underlying resource","resource":{"namespace":"clusters","name":"paas-jonny1-dev-us-west1"}}
{"severity":"info","logger":"containercluster-controller","msg":"successfully finished reconcile","resource":{"namespace":"clusters","name":"paas-jonny1-dev-us-west1"}}
{"severity":"info","logger":"containercluster-controller","msg":"starting reconcile","resource":{"namespace":"clusters","name":"paas-jonny1-dev-us-west1"}}
{"severity":"info","logger":"containercluster-controller","msg":"underlying resource already up to date","resource":{"namespace":"clusters","name":"paas-jonny1-dev-us-west1"}}
{"severity":"info","logger":"containercluster-controller","msg":"successfully finished reconcile","resource":{"namespace":"clusters","name":"paas-jonny1-dev-us-west1"}}
{"severity":"info","logger":"containercluster-controller","msg":"starting reconcile","resource":{"namespace":"clusters","name":"paas-jonny1-dev-us-west1"}}
{"severity":"info","logger":"containercluster-controller","msg":"underlying resource already up to date","resource":{"namespace":"clusters","name":"paas-jonny1-dev-us-west1"}}
{"severity":"info","logger":"containercluster-controller","msg":"successfully finished reconcile","resource":{"namespace":"clusters","name":"paas-jonny1-dev-us-west1"}}
Steps to Reproduce
Steps to reproduce the issue
- create a containercluster with workload identity enabled
- disable workload identity via the containercluster resource
Checklist
Bug Description
I created a simple
containerclusterresource with workload identity enabled.╰─ kubectl get containercluster paas-jonny1-dev-us-west1 -o jsonpath={.spec.workloadIdentityConfig} {"identityNamespace":"my-project.svc.id.goog"}This all works and on GCP, I see that it's enabled for my cluster:

But now it doesn't work to disable it on an existing cluster.
I'm trying to disable by running
╰─ kubectl patch containercluster/paas-jonny1-dev-us-west1 -p '{"spec":{"workloadIdentityConfig":null}}' --type=merge containercluster.container.cnrm.cloud.google.com/paas-jonny1-dev-us-west1 patchedBy watching the
containerclusterin a separate window viawatch kubectl get containercluster paas-jonny1-dev-us-west1 -o jsonpath={.spec.workloadIdentityConfig}I see that my patch command actually removes the
.spec.workloadIdentityConfigas expected, but right after thecnrm-controller-manageradds it back in (probably because it takes what's on GCP as source of truth).If I explicitly set
spec.workloadIdentityConfigtonull, I would expect that the feature gets disabled on GCP. I have also tried setting it to{}instead ofnull, but that doesn't work either.Additional Diagnostic Information
Kubernetes Cluster Version
Config Connector Version
Config Connector Mode
Log Output
Steps to Reproduce
Steps to reproduce the issue