Skip to content

fix: restore original loki write service account name#2599

Merged
joelmccoy merged 1 commit intomainfrom
joel/infra-109-fix-loki-write-service-account
Apr 20, 2026
Merged

fix: restore original loki write service account name#2599
joelmccoy merged 1 commit intomainfrom
joel/infra-109-fix-loki-write-service-account

Conversation

@joelmccoy
Copy link
Copy Markdown
Contributor

@joelmccoy joelmccoy commented Apr 20, 2026

Description

Restores the Loki service account name used by the write pods to loki. Upstream unexpectedly changed this and can fail deployments that reference this service account by name for object storage auth (i.e. IRSA). See upstream issue: grafana-community/helm-charts#390

Type of change

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Other (security config, docs update, etc)

Steps to Validate

  • uds run & check loki service account is used by write pods

Checklist before merging

@joelmccoy joelmccoy requested a review from a team as a code owner April 20, 2026 19:20
Copilot AI review requested due to automatic review settings April 20, 2026 19:20
Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Restores the Loki Helm chart configuration so the write component uses the shared loki ServiceAccount again (avoiding unexpected upstream per-component SA naming changes that can break IRSA/object-store auth integrations).

Changes:

  • Disable creation of the write-specific ServiceAccount so write pods use the shared ServiceAccount.
  • Update the file copyright year range to include 2026.

@joelmccoy joelmccoy merged commit a5386e2 into main Apr 20, 2026
44 of 45 checks passed
@joelmccoy joelmccoy deleted the joel/infra-109-fix-loki-write-service-account branch April 20, 2026 19:57
joelmccoy added a commit that referenced this pull request Apr 20, 2026
joelmccoy pushed a commit that referenced this pull request Apr 20, 2026
🤖 I have created a release *beep* *boop*
---


##
[1.2.1](v1.2.0...v1.2.1)
(2026-04-20)


### Bug Fixes

* restore original loki write service account name
([#2599](#2599))
(backport-1.2)
([#2600](#2600))
([3082971](3082971))

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
jasonwashburn pushed a commit that referenced this pull request Apr 28, 2026
🤖 I have created a release *beep* *boop*
---


##
[1.3.0](v1.2.0...v1.3.0)
(2026-04-28)


### Features

* **CORE-27:** allow opt-in public clients
([#2598](#2598))
([9af5ca7](9af5ca7))
* cycle gateways when istio gatewayTopology proxyProtocol changes
([#2595](#2595))
([5eceba7](5eceba7))


### Bug Fixes

* **ci:** run istio gen-crds in autogenerated-check
([#2605](#2605))
([40a1a97](40a1a97))
* handle apply properly for keycloak client secret
([#2627](#2627))
([c227289](c227289))
* re-add keycloak client registration authpol
([#2614](#2614))
([ebed871](ebed871))
* restore original loki write service account name
([#2599](#2599))
([a5386e2](a5386e2))
* updating prometheus to use endpointslice
([#2594](#2594))
([ba319c8](ba319c8))


### Miscellaneous

* add retry to multi-arch manifest check
([#2602](#2602))
([4e8ba23](4e8ba23))
* **deps-dev:** bump postcss from 8.5.8 to 8.5.12 in /scripts/renovate
([#2615](#2615))
([0922090](0922090))
* **deps:** update identity-config to 0.26.1
([#2616](#2616))
([fd105a2](fd105a2))
* **deps:** update istio to v1.29.2
([#2587](#2587))
([caddf35](caddf35))
* **deps:** update pepr to v1.1.6
([#2607](#2607))
([d9f2ae9](d9f2ae9))
* **deps:** update pepr to v1.1.7
([#2611](#2611))
([fd43cc3](fd43cc3))
* **deps:** update prometheus-stack
([#2546](#2546))
([6812697](6812697))
* **deps:** update velero chart to v12.0.1
([#2613](#2613))
([1048ae9](1048ae9))
* swap bundles google idp saml signing cert
([#2609](#2609))
([57795b9](57795b9))
* update istio CRDs to use v1 API
([#2606](#2606))
([079c361](079c361))


### Documentation

* add 1.3.0 release notes
([#2633](#2633))
([00468ab](00468ab))
* add keycloak admin handling doc
([#2597](#2597))
([328d19c](328d19c))
* add troubleshooting for too many open files
([#2612](#2612))
([0b64a05](0b64a05))
* update release notes for 1.2.1
([#2603](#2603))
([bfa8124](bfa8124))
* update release notes to include newest patches
([#2629](#2629))
([d59ca81](d59ca81))

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants