Checklist
Bug Description
Config Connector Version
> kubectl get ns cnrm-system -o jsonpath='{.metadata.annotations.cnrm\.cloud\.google\.com/version}'
1.99.0
Kubernetes Version
I have KCC set up in namespaced mode on GKE cluster. I also have other CRDs (non KCC) installed in the same cluster. When I try to delete the other CRDs (non KCC), the validation webhook configuration intercepts it.
This is not desirable to me for reasons described in the Log Output section.
I found this issue #202 which is somewhat related, but it focuses more on the KCC uninstallation process.
Additional Diagnostic Information
I see the config for abandon-on-uninstall.cnrm.cloud.google.com validation webhook is
rules:
- apiGroups:
- apiextensions.k8s.io
apiVersions:
- v1
operations:
- DELETE
resources:
- customresourcedefinitions
scope: '*'
Would it be better if it has selector so that it only intercepts kcc CRDs? e.g. adding this to the validation webhook
objectSelector:
matchLabels:
cnrm.cloud.google.com/managed-by-kcc: "true"
Or is there any way I can do this already?
Kubernetes Cluster Version
GKE v1.23.14-gke.1800
Config Connector Version
1.99.0
Config Connector Mode
namespaced mode (default)
Log Output
In my case, I have a number of CRDs (some are namespace scoped) in the cluster and the default netpols is deny all, so I end up with below, when I try to delete them
I get this error when I try to delete the CRD certificaterequests.cert-manager.io
CustomResourceDefinition/certificaterequests.cert-manager.io immutable field detected, failed to delete object, error: Internal error occurred: failed calling webhook "abandon-on-uninstall.cnrm.cloud.google.com": failed to call webhook: Post "[https://abandon-on-uninstall.cnrm-system.svc:443/abandon-on-uninstall?timeout=10s](https://abandon-on-uninstall.cnrm-system.svc/abandon-on-uninstall?timeout=10s)": context deadline exceeded
Steps to reproduce the issue
Pre-requisite:
-
Have other non KCC CRDs (namespace scoped) in the cluster
-
Have the default netpols as deny all
-
Set up config connector in k8s cluster in namespaced mode https://cloud.google.com/config-connector/docs/how-to/advanced-install#manual
-
Delete any non KCC CRD in the cluster
You will see that the webhook call times out.
YAML snippets
No response
Checklist
Bug Description
Config Connector Version
Kubernetes Version
I have KCC set up in namespaced mode on GKE cluster. I also have other CRDs (non KCC) installed in the same cluster. When I try to delete the other CRDs (non KCC), the validation webhook configuration intercepts it.
This is not desirable to me for reasons described in the Log Output section.
I found this issue #202 which is somewhat related, but it focuses more on the KCC uninstallation process.
Additional Diagnostic Information
I see the config for
abandon-on-uninstall.cnrm.cloud.google.comvalidation webhook isWould it be better if it has selector so that it only intercepts kcc CRDs? e.g. adding this to the validation webhook
Or is there any way I can do this already?
Kubernetes Cluster Version
GKE v1.23.14-gke.1800
Config Connector Version
1.99.0
Config Connector Mode
namespaced mode (default)
Log Output
In my case, I have a number of CRDs (some are namespace scoped) in the cluster and the default netpols is deny all, so I end up with below, when I try to delete them
I get this error when I try to delete the CRD
certificaterequests.cert-manager.ioSteps to reproduce the issue
Pre-requisite:
Have other non KCC CRDs (namespace scoped) in the cluster
Have the default netpols as deny all
Set up config connector in k8s cluster in namespaced mode https://cloud.google.com/config-connector/docs/how-to/advanced-install#manual
Delete any non KCC CRD in the cluster
You will see that the webhook call times out.
YAML snippets
No response