Skip to content

Sync hub gateway cert into monitoring via config-syncer - #1342

Merged
ArnobKumarSaha merged 1 commit into
masterfrom
arnob-cfg-syncer
Sep 23, 2026
Merged

ArnobKumarSaha merged 1 commit into
masterfrom
arnob-cfg-syncer

Conversation

@ArnobKumarSaha

@ArnobKumarSaha ArnobKumarSaha commented Sep 23, 2026 •

Copy link
Copy Markdown
Member

On the ACE hub, prom-label-proxy runs in monitoring but the gateway cert (ace-gw-cert) is issued in ace. config-syncer copies it into monitoring and keeps the copy in sync when cert-manager rotates the cert.

  • ace-installer / ace-installer-certified: new config-syncer HelmRelease (v0.15.5, mode: oss); the ace HelmRelease now depends on it when it's enabled.
  • opscenter-features: the config-syncer Feature defaults to mode: oss (the OSS build has no license check); version bumped to v0.15.5.
  • service-gateway: the Certificate's secretTemplate gets kubed.appscode.com/sync: kubernetes.io/metadata.name=monitoring only when the release is the default GatewayClass, its namespace isn't monitoring, and no monitoring GatewayClass exists. So nothing is synced on a monitoring cluster.

Companion: opnpulse/installer#23 (selects ace / ace-gw-cert on the hub).

Signed-off-by: Arnob kumar saha <arnob@appscode.com>
@ArnobKumarSaha
ArnobKumarSaha merged commit 0739617 into master Sep 23, 2026
8 checks passed
@ArnobKumarSaha
ArnobKumarSaha deleted the arnob-cfg-syncer branch September 23, 2026 12:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants