service-ca-operator and cluster-network-operators compete in injecting CA bundles in OpenShift Container Platform 4 when wrongly configured
Issue
service-ca-operator
andcluster-network-operators
compete in injecting CA bundles in OpenShift Container Platform 4 when wrongly configured.- When annotating a
ConfigMap
withservice.beta.openshift.io/inject-cabundle=true
and adding the labelconfig.openshift.io/inject-trusted-cabundle=true
to the sameConfigMap
, theservice-ca-operator
and thecluster-network-operator
are racing each other to apply the desired state which will never be possible.
Environment
- Red Hat OpenShift Container Platform (OCP) 4
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.