fix(vault-injector): run two replicas so restarts cannot skip injection
The webhook is failurePolicy: Ignore, so with one replica any pod created during an injector restart is admitted without its Vault agent sidecar and then crash-loops forever on a missing /vault/secrets file, with nothing to indicate injection was skipped. Hit twice while rolling ariadne. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
parent
7cb266b5f1
commit
d19feb1659
@ -33,7 +33,12 @@ spec:
|
|||||||
enabled: false
|
enabled: false
|
||||||
injector:
|
injector:
|
||||||
enabled: true
|
enabled: true
|
||||||
replicas: 1
|
# Two replicas because the webhook is failurePolicy: Ignore. With a
|
||||||
|
# single replica, any pod created while the injector restarts is
|
||||||
|
# admitted unmutated: it comes up without its Vault agent sidecar,
|
||||||
|
# never finds /vault/secrets, and crash-loops indefinitely with no
|
||||||
|
# indication that injection was skipped. Observed twice on ariadne.
|
||||||
|
replicas: 2
|
||||||
agentImage:
|
agentImage:
|
||||||
repository: hashicorp/vault
|
repository: hashicorp/vault
|
||||||
tag: "1.17.6"
|
tag: "1.17.6"
|
||||||
|
|||||||
Loading…
x
Reference in New Issue
Block a user