File tree Expand file tree Collapse file tree 3 files changed +17
-11
lines changed
manifests/02-skipper-validation-webhook
node-pools/master-default Expand file tree Collapse file tree 3 files changed +17
-11
lines changed Original file line number Diff line number Diff line change @@ -342,6 +342,8 @@ routegroups_validation: "enabled"
342342# disabled|enabled ingress validation via skipper webhook
343343ingresses_validation : " enabled"
344344
345+ enable_advanced_validation : " false"
346+
345347# tokeninfo
346348{{if eq .Cluster.Environment "production"}}
347349# production|bridge|disabled
Original file line number Diff line number Diff line change 1- {{- if eq .Cluster.Provider "zalando-eks"}}
1+ # {{- if eq .Cluster.Provider "zalando-eks"}}
22apiVersion : apps/v1
33kind : Deployment
44metadata :
@@ -34,10 +34,12 @@ spec:
3434 - name : skipper-admission-webhook
3535 image : 926694233939.dkr.ecr.eu-central-1.amazonaws.com/production_namespace/teapot/skipper:v0.22.142
3636 args :
37- - webhook
38- - --address=:9085
39- - --tls-cert-file=/etc/tls-certs/skipper-validation-webhook.pem
40- - --tls-key-file=/etc/tls-certs/skipper-validation-webhook-key.pem
37+ - skipper
38+ - --validation-webhook-enabled=true
39+ - --validation-webhook-address=:9085
40+ - --validation-webhook-cert-file=/etc/tls-certs/skipper-validation-webhook.pem
41+ - --validation-webhook-key-file=/etc/tls-certs/skipper-validation-webhook-key.pem
42+ - " --enable-advanced-validation={{ .Cluster.ConfigItems.enable_advanced_validation }}"
4143 lifecycle :
4244 preStop :
4345 sleep :
6365 - name : tls-certs
6466 secret :
6567 secretName : skipper-validation-webhook-tls-certs
66- {{- end }}
68+ # {{- end }}
Original file line number Diff line number Diff line change @@ -260,12 +260,14 @@ write_files:
260260 name : admission-controller-kubeconfig
261261 readOnly : true
262262 - name : skipper-admission-webhook
263- image : 926694233939.dkr.ecr.eu-central-1.amazonaws.com/production_namespace/teapot/skipper:v0.22.127
263+ image : 926694233939.dkr.ecr.eu-central-1.amazonaws.com/production_namespace/teapot/skipper:v0.22.142
264264 args :
265- - webhook
266- - --address=:9085
267- - --tls-cert-file=/etc/kubernetes/ssl/admission-controller.pem
268- - --tls-key-file=/etc/kubernetes/ssl/admission-controller-key.pem
265+ - skipper
266+ - --validation-webhook-enabled=true
267+ - --validation-webhook-address=:9085
268+ - --validation-webhook-cert-file=/etc/kubernetes/ssl/admission-controller.pem
269+ - --validation-webhook-key-file=/etc/kubernetes/ssl/admission-controller-key.pem
270+ - " --enable-advanced-validation={{ .Cluster.ConfigItems.enable_advanced_validation }}"
269271 lifecycle :
270272 preStop :
271273 sleep :
You can’t perform that action at this time.
0 commit comments