install: always re-apply CRDs and RBAC on --deploy-ate-system - #698
Open
NekoPunch (orangeCatDeveloper) wants to merge 1 commit into
Open
Conversation
ensure_crds skips the generated manifests once the CRDs exist, so an upgrade never refreshed CRD schemas or ClusterRoles; a controller needing a new permission deadlocked on informer start while the rollout reported success. Fixes agent-substrate#697.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #697
Summary
deploy_ate_systemgatedmanifests/ate-install/generated/behindensure_crds, whose existence check skips the directory on any upgrade — stranding CRD schemas and, sincerole.yamlhas no other apply path, all ClusterRoles at first-install state. A controller image needing a new permission then deadlocks on informer start while the rollout reports success.deploy_ate_systemnow callsdeploy_crdsunconditionally (kubectl applyis idempotent). The demo scripts and per-component deploy flags keepensure_crds, where "make sure they exist" is the intended semantic.Test plan
Reproduced on a 4-day-old kind cluster: upgrading the control plane deadlocked ate-controller on
cannot list networkpolicies; manually applyingrole.yamlunblocked it.With this fix, the same
install-ate-kind.sh --deploy-ate-systemrun prints thedeploy_crdsstep and re-applied the drifted manifests (actortemplates.ate.dev configured,workerpools.ate.dev configured, ClusterRoles applied); cluster reconciles normally.bash -n hack/install-ate.sh.Tests pass
Appropriate changes to documentation are included in the PR (none needed)