@@ -25,14 +25,11 @@ import (
2525 // to ensure that exec-entrypoint and run can make use of them.
2626 _ "k8s.io/client-go/plugin/pkg/client/auth"
2727
28- corev1 "k8s.io/api/core/v1"
2928 "k8s.io/apimachinery/pkg/runtime"
3029 utilruntime "k8s.io/apimachinery/pkg/util/runtime"
3130 clientgoscheme "k8s.io/client-go/kubernetes/scheme"
3231 clusterv1 "sigs.k8s.io/cluster-api/api/core/v1beta2"
3332 ctrl "sigs.k8s.io/controller-runtime"
34- "sigs.k8s.io/controller-runtime/pkg/cache"
35- "sigs.k8s.io/controller-runtime/pkg/client"
3633 "sigs.k8s.io/controller-runtime/pkg/healthz"
3734 "sigs.k8s.io/controller-runtime/pkg/log/zap"
3835 "sigs.k8s.io/controller-runtime/pkg/metrics/filters"
@@ -59,47 +56,6 @@ func init() {
5956 // +kubebuilder:scaffold:scheme
6057}
6158
62- // managerCacheOptions keeps Secret data out of the shared informer cache. Both
63- // controllers watch Secrets — credentials, bootstrap data and the bastion
64- // cloud-init — and a watch only needs an object's identity to enqueue a
65- // reconcile, never its contents, so caching credential bytes in memory buys
66- // nothing and exposes them to anything that can read the process. Managed
67- // fields go with them: nothing here reads them, and they are usually the
68- // largest part of what is left once the data is gone.
69- //
70- // Deliberately no label selector on the entry, unlike Cluster API's own
71- // equivalent in internal/setup. Cluster API only watches Secrets it stamps
72- // itself, whereas the credentials and bastion cloud-init Secrets here are
73- // created by the user and carry no labels, so a selector would silently stop
74- // those watches from firing rather than only hardening the cache.
75- func managerCacheOptions () cache.Options {
76- return cache.Options {
77- ByObject : map [client.Object ]cache.ByObject {
78- & corev1.Secret {}: {
79- Transform : func (in any ) (any , error ) {
80- if secret , ok := in .(* corev1.Secret ); ok {
81- secret .Data = nil
82- secret .SetManagedFields (nil )
83- }
84- return in , nil
85- },
86- },
87- },
88- }
89- }
90-
91- // managerClientOptions turns every Secret read into a live lookup. The cache no
92- // longer holds Secret data (see managerCacheOptions), so the reads that need
93- // the real bytes — util.BuildCloudClient and the bootstrap-data fetch — have to
94- // bypass it.
95- func managerClientOptions () client.Options {
96- return client.Options {
97- Cache : & client.CacheOptions {
98- DisableFor : []client.Object {& corev1.Secret {}},
99- },
100- }
101- }
102-
10359// nolint:gocyclo
10460func main () {
10561 var metricsAddr string
@@ -204,8 +160,6 @@ func main() {
204160
205161 mgr , err := ctrl .NewManager (ctrl .GetConfigOrDie (), ctrl.Options {
206162 Scheme : scheme ,
207- Cache : managerCacheOptions (),
208- Client : managerClientOptions (),
209163 Metrics : metricsServerOptions ,
210164 WebhookServer : webhookServer ,
211165 HealthProbeBindAddress : probeAddr ,
0 commit comments