Skip to content

Commit 5de431c

Browse files
olix0rpull[bot]
authored andcommitted
Configure the identity's controller proxy to discovery policies (#6873)
Now that the proxy uses its default policy at startup and can discover its policies lazily, the identity controller no longer must be exempt from policy discovery. This enables the identity controller to enforce admin server policies, in particular. This change enables policy discovery on the identity controller.
1 parent a7eeaa8 commit 5de431c

17 files changed

+160
-4
lines changed

charts/partials/templates/_proxy.tpl

Lines changed: 0 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -33,7 +33,6 @@ env:
3333
value: {{ternary "localhost.:8086" (printf "linkerd-dst-headless.%s.svc.%s.:8086" .Values.namespace .Values.clusterDomain) (eq (toString .Values.proxy.component) "linkerd-destination")}}
3434
- name: LINKERD2_PROXY_DESTINATION_PROFILE_NETWORKS
3535
value: {{.Values.clusterNetworks | quote}}
36-
{{ if (ne (toString .Values.proxy.component) "linkerd-identity") -}}
3736
- name: LINKERD2_PROXY_POLICY_SVC_ADDR
3837
value: {{ternary "localhost.:8090" (printf "linkerd-policy.%s.svc.%s.:8090" .Values.namespace .Values.clusterDomain) (eq (toString .Values.proxy.component) "linkerd-destination")}}
3938
- name: LINKERD2_PROXY_POLICY_WORKLOAD
@@ -42,7 +41,6 @@ env:
4241
value: {{.Values.proxy.defaultInboundPolicy | default .Values.policyController.defaultAllowPolicy}}
4342
- name: LINKERD2_PROXY_POLICY_CLUSTER_NETWORKS
4443
value: {{.Values.clusterNetworks | quote}}
45-
{{ end -}}
4644
{{ if .Values.proxy.inboundConnectTimeout -}}
4745
- name: LINKERD2_PROXY_INBOUND_CONNECT_TIMEOUT
4846
value: {{.Values.proxy.inboundConnectTimeout | quote}}
@@ -128,11 +126,9 @@ be used in other contexts.
128126
value: linkerd-identity.{{.Values.namespace}}.serviceaccount.identity.{{.Values.namespace}}.{{$trustDomain}}
129127
- name: LINKERD2_PROXY_DESTINATION_SVC_NAME
130128
value: linkerd-destination.{{.Values.namespace}}.serviceaccount.identity.{{.Values.namespace}}.{{$trustDomain}}
131-
{{ if (ne (toString .Values.proxy.component) "linkerd-identity") -}}
132129
- name: LINKERD2_PROXY_POLICY_SVC_NAME
133130
value: linkerd-destination.{{.Values.namespace}}.serviceaccount.identity.{{.Values.namespace}}.{{$trustDomain}}
134131
{{ end -}}
135-
{{ end -}}
136132
image: {{.Values.proxy.image.name}}:{{.Values.proxy.image.version | default .Values.linkerdVersion}}
137133
imagePullPolicy: {{.Values.proxy.image.pullPolicy | default .Values.imagePullPolicy}}
138134
livenessProbe:

cli/cmd/testdata/install_controlplane_tracing_output.golden

Lines changed: 10 additions & 0 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

cli/cmd/testdata/install_custom_domain.golden

Lines changed: 10 additions & 0 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

cli/cmd/testdata/install_custom_registry.golden

Lines changed: 10 additions & 0 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

cli/cmd/testdata/install_default.golden

Lines changed: 10 additions & 0 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

cli/cmd/testdata/install_default_override_dst_get_nets.golden

Lines changed: 10 additions & 0 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

cli/cmd/testdata/install_ha_output.golden

Lines changed: 10 additions & 0 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

cli/cmd/testdata/install_ha_with_overrides_output.golden

Lines changed: 10 additions & 0 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

cli/cmd/testdata/install_heartbeat_disabled_output.golden

Lines changed: 10 additions & 0 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

cli/cmd/testdata/install_helm_output.golden

Lines changed: 10 additions & 0 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

0 commit comments

Comments
 (0)