Skip to content

Commit 087fb45

Browse files
committed
Revert fix: keep Secret data out of the manager's informer cache
1 parent b5ba35a commit 087fb45

2 files changed

Lines changed: 0 additions & 136 deletions

File tree

‎cmd/manager/main.go‎

Lines changed: 0 additions & 46 deletions
Original file line numberDiff line numberDiff line change
@@ -25,14 +25,11 @@ import (
2525
// to ensure that exec-entrypoint and run can make use of them.
2626
_ "k8s.io/client-go/plugin/pkg/client/auth"
2727

28-
corev1 "k8s.io/api/core/v1"
2928
"k8s.io/apimachinery/pkg/runtime"
3029
utilruntime "k8s.io/apimachinery/pkg/util/runtime"
3130
clientgoscheme "k8s.io/client-go/kubernetes/scheme"
3231
clusterv1 "sigs.k8s.io/cluster-api/api/core/v1beta2"
3332
ctrl "sigs.k8s.io/controller-runtime"
34-
"sigs.k8s.io/controller-runtime/pkg/cache"
35-
"sigs.k8s.io/controller-runtime/pkg/client"
3633
"sigs.k8s.io/controller-runtime/pkg/healthz"
3734
"sigs.k8s.io/controller-runtime/pkg/log/zap"
3835
"sigs.k8s.io/controller-runtime/pkg/metrics/filters"
@@ -59,47 +56,6 @@ func init() {
5956
// +kubebuilder:scaffold:scheme
6057
}
6158

62-
// managerCacheOptions keeps Secret data out of the shared informer cache. Both
63-
// controllers watch Secrets — credentials, bootstrap data and the bastion
64-
// cloud-init — and a watch only needs an object's identity to enqueue a
65-
// reconcile, never its contents, so caching credential bytes in memory buys
66-
// nothing and exposes them to anything that can read the process. Managed
67-
// fields go with them: nothing here reads them, and they are usually the
68-
// largest part of what is left once the data is gone.
69-
//
70-
// Deliberately no label selector on the entry, unlike Cluster API's own
71-
// equivalent in internal/setup. Cluster API only watches Secrets it stamps
72-
// itself, whereas the credentials and bastion cloud-init Secrets here are
73-
// created by the user and carry no labels, so a selector would silently stop
74-
// those watches from firing rather than only hardening the cache.
75-
func managerCacheOptions() cache.Options {
76-
return cache.Options{
77-
ByObject: map[client.Object]cache.ByObject{
78-
&corev1.Secret{}: {
79-
Transform: func(in any) (any, error) {
80-
if secret, ok := in.(*corev1.Secret); ok {
81-
secret.Data = nil
82-
secret.SetManagedFields(nil)
83-
}
84-
return in, nil
85-
},
86-
},
87-
},
88-
}
89-
}
90-
91-
// managerClientOptions turns every Secret read into a live lookup. The cache no
92-
// longer holds Secret data (see managerCacheOptions), so the reads that need
93-
// the real bytes — util.BuildCloudClient and the bootstrap-data fetch — have to
94-
// bypass it.
95-
func managerClientOptions() client.Options {
96-
return client.Options{
97-
Cache: &client.CacheOptions{
98-
DisableFor: []client.Object{&corev1.Secret{}},
99-
},
100-
}
101-
}
102-
10359
// nolint:gocyclo
10460
func main() {
10561
var metricsAddr string
@@ -204,8 +160,6 @@ func main() {
204160

205161
mgr, err := ctrl.NewManager(ctrl.GetConfigOrDie(), ctrl.Options{
206162
Scheme: scheme,
207-
Cache: managerCacheOptions(),
208-
Client: managerClientOptions(),
209163
Metrics: metricsServerOptions,
210164
WebhookServer: webhookServer,
211165
HealthProbeBindAddress: probeAddr,

‎cmd/manager/main_test.go‎

Lines changed: 0 additions & 90 deletions
This file was deleted.

0 commit comments

Comments
 (0)