Add pod
cache to gardener-node-agent
only when nodeName
is present
#11964
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
How to categorize this PR?
/kind bug
What this PR does / why we need it:
This PR adapts
gardener-node-agent
to add a cache for pods only if thenodeName
is present. We use thenodeName
in thenode-agent-authorizer
webhook to ensure that podlist
requests for only the same node are allowed.During the startup, nodeName can be empty in some providers (eg: aws), and starting the cache with
hostName
can fail since the webhook doesn't know about this hostName.We restart
gardener-node-agent
as soon as it identifies it's node for the first time, ref, the cache will be added during that time.Which issue(s) this PR fixes:
Part of #10219
Special notes for your reviewer:
Introduced with #11718
/cc @acumino @oliver-goetz
Release note: