-
Notifications
You must be signed in to change notification settings - Fork 1.1k
Use configmap helm driver instead of secrets #3272
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Use configmap helm driver instead of secrets #3272
Conversation
|
Skipping CI for Draft Pull Request. |
Codecov Report
@@ Coverage Diff @@
## master #3272 +/- ##
=======================================
Coverage 65.51% 65.51%
=======================================
Files 399 399
Lines 23198 23198
=======================================
Hits 15198 15198
Misses 6215 6215
Partials 1785 1785 |
| resources: | ||
| - secrets | ||
| verbs: | ||
| - list |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Could you add logic for enabling HELM_DRIVER as secret.
Signed-off-by: trafalgarzzz <trafalgarz@outlook.com>
Signed-off-by: trafalgarzzz <trafalgarz@outlook.com>
Signed-off-by: trafalgarzzz <trafalgarz@outlook.com>
Signed-off-by: trafalgarzzz <trafalgarz@outlook.com>
Signed-off-by: trafalgarzzz <trafalgarz@outlook.com>
Signed-off-by: trafalgarzzz <trafalgarz@outlook.com>
Signed-off-by: trafalgarzzz <trafalgarz@outlook.com>
Signed-off-by: trafalgarzzz <trafalgarz@outlook.com>
Signed-off-by: trafalgarzzz <trafalgarz@outlook.com>
fede12c to
58038d8
Compare
|
Kudos, SonarCloud Quality Gate passed!
|
|
/test fluid-e2e |
cheyang
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
/lgtm
/approve
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: cheyang The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |








Ⅰ. Describe what this PR does
Fluid now use the default HELM_DRIVER(i.e. secret) to install/uninstall runtime charts which means Fluid controllers must have full permission to operate secret resources. This may incur potential security issue because secrets usually store sensitve user-applied data.
This PR makes the following changes to the code:
configmapinstead ofsecretIMPORTANT: BREAKING CHANGE NOTE
By migrating HELM_DRIVER from
secrettoconfigmap,it is possible that some resources may not be cleared after upgrade to the latest Fluid version. It is highly recommended to delete all the datasets and runtimes before upgrading to the version.Ⅱ. Does this pull request fix one issue?
NONE
Ⅲ. List the added test cases (unit test/integration test) if any, please explain if no tests are needed.
Ⅳ. Describe how to verify it
Ⅴ. Special notes for reviews