Repository navigation
fix(k8s): give each bridge its own CA secret - #17
Merged
Merged
Conversation
InjectCA named the secret "bridge-ca", and Rename only appends the device ID, so every bridge from a device shared bdg-bridge-ca-<device>: - each create generated a new CA and replaced the one the device's other bridges had mounted; - two concurrent creates both found it missing and raced to create it, so the loser failed with AlreadyExists; - each create relabeled it with its own bridge's labels, so removing that bridge deleted the secret out from under the others, whose pods then can't restart. The secret is now named after the bridge (bdg-bridge-ca-<bridge>-<device>), so it carries only its own bridge's labels and is removed with it. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
InjectCAnamed the CA secretbridge-ca, andRenameonly appends the device ID, so every bridge from one machine sharedbdg-bridge-ca-<device>:InjectCAgenerates a new CA per create and upserts it over the shared secret.secrets "bdg-bridge-ca-<device>" already exists. That's what broke the managed-drives e2e when it brought two bridges up at once.vercel.sh/bridge-deployment, so removing whichever bridge created it last deletes it. The device's other bridges keep running, but their pods can't restart, because the secret volume is gone. I hit this in venus: removing a test bridge deletedbdg-bridge-ca-39twy3, which three live bridges still mount.Change
The secret is named after the bridge,
bdg-bridge-ca-<bridge>-<device>, so it carries only its own bridge's labels andremovedeletes only that one. Nothing else refers to the secret by name. The proxy reads the CA from its mount, and the devcontainer gets it from the proxy's metadata.Rollout
Testing
TestInjectCA_SecretPerBridgerunsInjectCA,Rename,InjectLabelsandRewriteRefsfor two bridges from one device. It checks that each gets its own secret, labeled with its own bridge's deployment and mounted by it. Without the fix, both bridges getbdg-bridge-ca-dev123.go vet, andgo test ./pkg/k8s/resources/ ./pkg/commands/pass.🤖 Generated with Claude Code