@@ -22,7 +22,6 @@ import (
2222 metav1 "k8s.io/apimachinery/pkg/apis/meta/v1"
2323 "k8s.io/apimachinery/pkg/types"
2424 clusterv1 "sigs.k8s.io/cluster-api/api/core/v1beta2"
25- "sigs.k8s.io/controller-runtime/pkg/client"
2625 "sigs.k8s.io/controller-runtime/pkg/reconcile"
2726
2827 infrav1 "github.com/stackitcloud/cluster-api-provider-stackit/api/v1alpha1"
@@ -500,19 +499,34 @@ var _ = Describe("StackitCluster Controller", func() {
500499 expectCondition (got .Status .Conditions , infrav1 .ClusterReadyCondition , metav1 .ConditionFalse , "NetworkNotFound" )
501500 })
502501
503- It ("marks credentials invalid without requeueing on unauthorized credentials" , func () {
502+ // The requeue is what lets a corrected Secret take effect: nothing else
503+ // enqueues the cluster once the credentials are rejected.
504+ It ("requeues on unauthorized credentials and recovers once they are corrected" , func () {
504505 reconciler .CloudClientFactory = func (context.Context , cloud.Credentials ) (cloud.Client , error ) {
505506 return nil , fmt .Errorf ("authenticate: %w" , cloud .ErrUnauthorized )
506507 }
507508
508509 result , err := reconciler .Reconcile (ctx , request )
509510 Expect (err ).NotTo (HaveOccurred ())
510- Expect (result ).To (Equal (reconcile. Result {} ))
511+ Expect (result . RequeueAfter ).To (Equal (credentialsRetryRequeueAfter ))
511512
512513 got := & infrav1.StackitCluster {}
513514 Expect (k8sClient .Get (ctx , stackitKey , got )).To (Succeed ())
515+ Expect (got .Status .Ready ).To (BeFalse ())
514516 expectCondition (got .Status .Conditions , infrav1 .ClusterCredentialsReadyCondition , metav1 .ConditionFalse , "CredentialsInvalid" )
515517 expectCondition (got .Status .Conditions , infrav1 .ClusterReadyCondition , metav1 .ConditionFalse , "CredentialsInvalid" )
518+
519+ By ("correcting the credentials" )
520+ reconciler .CloudClientFactory = func (context.Context , cloud.Credentials ) (cloud.Client , error ) {
521+ return fakeCloud , nil
522+ }
523+
524+ _ , err = reconciler .Reconcile (ctx , request )
525+ Expect (err ).NotTo (HaveOccurred ())
526+
527+ Expect (k8sClient .Get (ctx , stackitKey , got )).To (Succeed ())
528+ Expect (got .Status .Ready ).To (BeTrue ())
529+ expectCondition (got .Status .Conditions , infrav1 .ClusterCredentialsReadyCondition , metav1 .ConditionTrue , "Available" )
516530 })
517531
518532 It ("does not call the cloud API when the owning Cluster is paused" , func () {
@@ -723,48 +737,6 @@ var _ = Describe("StackitCluster Controller", func() {
723737 Expect (requests ).To (Equal ([]reconcile.Request {request }))
724738 })
725739
726- It ("maps credentials Secret events to StackitCluster reconcile requests" , func () {
727- secret := & corev1.Secret {}
728- Expect (k8sClient .Get (ctx , types.NamespacedName {Name : credentials , Namespace : namespace }, secret )).To (Succeed ())
729-
730- requests := reconciler .stackitClusterRequestsForCredentialsSecret (ctx , secret )
731- Expect (requests ).To (Equal ([]reconcile.Request {request }))
732- })
733-
734- It ("maps credentials Secret events from a different namespace than the StackitCluster" , func () {
735- otherNamespace := "credentials-elsewhere"
736- Expect (client .IgnoreAlreadyExists (k8sClient .Create (ctx , & corev1.Namespace {
737- ObjectMeta : metav1.ObjectMeta {Name : otherNamespace },
738- }))).To (Succeed ())
739-
740- otherCredentials := credentials + "-elsewhere"
741- createCredentialsSecret (ctx , otherCredentials , otherNamespace , testProjectID )
742- DeferCleanup (func () {
743- deleteIfExists (ctx , & corev1.Secret {ObjectMeta : metav1.ObjectMeta {Name : otherCredentials , Namespace : otherNamespace }})
744- })
745-
746- got := & infrav1.StackitCluster {}
747- Expect (k8sClient .Get (ctx , stackitKey , got )).To (Succeed ())
748- got .Spec .CredentialsSecretRef = corev1.SecretReference {Name : otherCredentials , Namespace : otherNamespace }
749- Expect (k8sClient .Update (ctx , got )).To (Succeed ())
750-
751- secret := & corev1.Secret {}
752- Expect (k8sClient .Get (ctx , types.NamespacedName {Name : otherCredentials , Namespace : otherNamespace }, secret )).To (Succeed ())
753-
754- requests := reconciler .stackitClusterRequestsForCredentialsSecret (ctx , secret )
755- Expect (requests ).To (Equal ([]reconcile.Request {request }),
756- "credentialsSecretRef.namespace is optional, so the mapper must not be limited to the Secret's own namespace" )
757- })
758-
759- It ("ignores Secret events that no StackitCluster uses as credentials" , func () {
760- secret := & corev1.Secret {}
761- Expect (k8sClient .Get (ctx , types.NamespacedName {Name : credentials , Namespace : namespace }, secret )).To (Succeed ())
762- secret .Name = credentials + "-unused"
763-
764- requests := reconciler .stackitClusterRequestsForCredentialsSecret (ctx , secret )
765- Expect (requests ).To (BeEmpty ())
766- })
767-
768740 It ("ignores Cluster events for other infrastructure providers" , func () {
769741 cluster := & clusterv1.Cluster {
770742 ObjectMeta : metav1.ObjectMeta {Name : "other" , Namespace : namespace },
0 commit comments