Skip to content

Commit 58a5323

Browse files
fix: requeue with a fixed delay on stale ServiceAccount cache
Addresses review feedback on the stale-cache handling: relying on the `Owns(ServiceAccount)` watch to requeue is not guaranteed, because a ServiceAccount with the deterministic name that is owned by another controller will never be mapped back to this Workspace. Requeue with a small fixed `RequeueAfter` instead: a stale cache is common and is not write contention, so no exponential backoff is needed. Assisted-by: Qwen3.8-27B Signed-off-by: Christian Heusel <christian@heusel.eu>
1 parent 99711c1 commit 58a5323

1 file changed

Lines changed: 11 additions & 5 deletions

File tree

‎workspaces/controller/internal/controller/workspace_controller.go‎

Lines changed: 11 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -63,6 +63,10 @@ const (
6363
// pod template constants
6464
workspacePodTemplateContainerName = "main"
6565

66+
// requeue delay when the local cache is known to be stale (fixed delay, since a stale cache
67+
// is not write contention, so no exponential backoff is needed)
68+
requeueAfterStaleCache = 2 * time.Second
69+
6670
// lengths for resource names
6771
generateNameSuffixLength = 6
6872
nameHashLength = 8
@@ -292,9 +296,10 @@ func (r *WorkspaceReconciler) Reconcile(ctx context.Context, req ctrl.Request) (
292296
existingServiceAccount := &corev1.ServiceAccount{}
293297
if getErr := r.Get(ctx, client.ObjectKeyFromObject(serviceAccount), existingServiceAccount); getErr != nil {
294298
if apierrors.IsNotFound(getErr) {
295-
// the cache is stale, the watch on owned ServiceAccounts will requeue us
296-
log.V(2).Info("ServiceAccount already exists but is not in the cache yet, relying on the owned-object watch to requeue")
297-
return ctrl.Result{}, nil
299+
// the cache is stale; requeue after a short delay instead of relying on the
300+
// owned-object watch, which will not fire if the ServiceAccount is owned by another controller
301+
log.V(2).Info("ServiceAccount already exists but is not in the cache yet, will requeue")
302+
return ctrl.Result{RequeueAfter: requeueAfterStaleCache}, nil
298303
}
299304
log.Error(getErr, "unable to get existing ServiceAccount")
300305
return ctrl.Result{}, getErr
@@ -306,8 +311,9 @@ func (r *WorkspaceReconciler) Reconcile(ctx context.Context, req ctrl.Request) (
306311
fmt.Sprintf(stateMsgErrorServiceAccountNotOwned, existingServiceAccount.Name),
307312
)
308313
}
309-
// the cache is stale, the watch on owned ServiceAccounts will requeue us
310-
return ctrl.Result{}, nil
314+
// the cache is stale (the owner index did not return the ServiceAccount), requeue after
315+
// a short delay so we pick it up once the cache catches up
316+
return ctrl.Result{RequeueAfter: requeueAfterStaleCache}, nil
311317
}
312318
log.Error(err, "unable to create ServiceAccount")
313319
return ctrl.Result{}, err

0 commit comments

Comments
 (0)