Skip to content

sds: early update failure can stop secret updates #42438

@kyessenov

Description

@kyessenov

There are two problems in how SDS updates are published:

  1. When a cluster/listener is attached to a subscription, and the current cert is incompatible with it (e.g. wrong proto or private key method cannot bind), then no future SDS updates will be sent to that recipient.

  2. When an update fails to a cert, all other subsequent certs in the same recipient are not populated.

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions