From 8af787fa5a25835316781cfc11ff381b85170e4c Mon Sep 17 00:00:00 2001 From: Aditya Arora Date: Mon, 28 Sep 2026 11:11:19 -0400 Subject: [PATCH 1/2] chore: update go grpc and dependencies --- go.mod | 8 +- go.sum | 16 +-- third_party/cert-manager/01-cert-manager.yaml | 77 ++++++++++++ .../cert-manager/02-trust-manager.yaml | 90 ++++++++------ vendor/golang.org/x/net/http2/hpack/encode.go | 1 - vendor/golang.org/x/net/http2/hpack/hpack.go | 1 - vendor/golang.org/x/net/http2/hpack/tables.go | 51 +++++--- .../golang.org/x/net/http2/transport_wrap.go | 49 +++++--- vendor/google.golang.org/grpc/clientconn.go | 23 +--- .../clientconn_disconnect_reason_noplan9.go | 48 ++++++++ .../clientconn_disconnect_reason_plan9.go | 39 ++++++ .../grpc/internal/envconfig/envconfig.go | 12 +- .../grpc/internal/envconfig/xds.go | 7 +- .../internal/grpcsync/callback_serializer.go | 26 ++++ .../grpc/internal/mem/buffer_pool.go | 14 +++ .../grpc/internal/resolver/config_selector.go | 78 +----------- .../grpc/internal/transport/client_stream.go | 5 +- .../grpc/internal/transport/handler_server.go | 2 +- .../grpc/internal/transport/http2_client.go | 6 +- .../grpc/internal/transport/http2_server.go | 8 +- .../grpc/internal/transport/transport.go | 112 ++++++++++++++++-- .../google.golang.org/grpc/mem/buffer_pool.go | 4 - vendor/google.golang.org/grpc/mem/buffers.go | 6 +- vendor/google.golang.org/grpc/stream.go | 35 ++++-- vendor/google.golang.org/grpc/version.go | 2 +- vendor/modules.txt | 8 +- 26 files changed, 503 insertions(+), 225 deletions(-) create mode 100644 vendor/google.golang.org/grpc/clientconn_disconnect_reason_noplan9.go create mode 100644 vendor/google.golang.org/grpc/clientconn_disconnect_reason_plan9.go diff --git a/go.mod b/go.mod index f00ba6af2ac..a356fcf1890 100644 --- a/go.mod +++ b/go.mod @@ -44,7 +44,7 @@ require ( go.uber.org/atomic v1.10.0 go.uber.org/multierr v1.11.0 go.uber.org/zap v1.28.0 - golang.org/x/net v0.57.0 + golang.org/x/net v0.58.0 golang.org/x/sync v0.22.0 k8s.io/api v0.35.7 k8s.io/apiextensions-apiserver v0.35.7 @@ -131,18 +131,18 @@ require ( go.uber.org/automaxprocs v1.6.0 // indirect go.yaml.in/yaml/v2 v2.4.4 // indirect go.yaml.in/yaml/v3 v3.0.5 // indirect - golang.org/x/crypto v0.54.0 // indirect + golang.org/x/crypto v0.55.0 // indirect golang.org/x/mod v0.38.0 // indirect golang.org/x/oauth2 v0.36.0 // indirect golang.org/x/sys v0.47.0 // indirect golang.org/x/term v0.45.0 // indirect - golang.org/x/text v0.40.0 // indirect + golang.org/x/text v0.41.0 // indirect golang.org/x/time v0.12.0 // indirect golang.org/x/tools v0.48.0 // indirect gomodules.xyz/jsonpatch/v2 v2.5.0 // indirect google.golang.org/genproto/googleapis/api v0.0.0-20260526163538-3dc84a4a5aaa // indirect google.golang.org/genproto/googleapis/rpc v0.0.0-20260526163538-3dc84a4a5aaa // indirect - google.golang.org/grpc v1.82.1 // indirect + google.golang.org/grpc v1.83.2 // indirect google.golang.org/protobuf v1.36.12-0.20260120151049-f2248ac996af // indirect gopkg.in/evanphx/json-patch.v4 v4.13.0 // indirect gopkg.in/inf.v0 v0.9.1 // indirect diff --git a/go.sum b/go.sum index c3490144a5d..b7cfb63493c 100644 --- a/go.sum +++ b/go.sum @@ -628,8 +628,8 @@ golang.org/x/crypto v0.0.0-20200622213623-75b288015ac9/go.mod h1:LzIPMQfyMNhhGPh golang.org/x/crypto v0.0.0-20210817164053-32db794688a5/go.mod h1:GvvjBRRGRdwPK5ydBHafDWAxML/pGHZbMvKqRZ5+Abc= golang.org/x/crypto v0.0.0-20210921155107-089bfa567519/go.mod h1:GvvjBRRGRdwPK5ydBHafDWAxML/pGHZbMvKqRZ5+Abc= golang.org/x/crypto v0.19.0/go.mod h1:Iy9bg/ha4yyC70EfRS8jz+B6ybOBKMaSxLj6P6oBDfU= -golang.org/x/crypto v0.54.0 h1:YLIA59K4fiNzHzjnZt2tUJQjQtUWfWbeHBqKtk3eScw= -golang.org/x/crypto v0.54.0/go.mod h1:KWL8ny2AZdGR2cWmzeHrp2azQPGogOv+HeQaVEXC2dk= +golang.org/x/crypto v0.55.0 h1:+KWHjbgOaAQ66dh/YlkZKHlz9ZUlq61AFirAR9ntP8M= +golang.org/x/crypto v0.55.0/go.mod h1:uq0V9dE/fzQuJtbnL+2EhWOE63vo164FY8xqEnV9xis= golang.org/x/exp v0.0.0-20190121172915-509febef88a4/go.mod h1:CJ0aWSM057203Lf6IL+f9T1iT9GByDxfZKAQTCR3kQA= golang.org/x/exp v0.0.0-20190306152737-a1d7652674e8/go.mod h1:CJ0aWSM057203Lf6IL+f9T1iT9GByDxfZKAQTCR3kQA= golang.org/x/exp v0.0.0-20190510132918-efd6b22b2522/go.mod h1:ZjyILWgesfNpC6sMxTJOJm9Kp84zZh5NQWvqDGG3Qr8= @@ -716,8 +716,8 @@ golang.org/x/net v0.0.0-20210813160813-60bc85c4be6d/go.mod h1:9nx3DQGgdP8bBQD5qx golang.org/x/net v0.0.0-20220722155237-a158d28d115b/go.mod h1:XRhObCWvk6IyKnWLug+ECip1KBveYUHfp+8e9klMJ9c= golang.org/x/net v0.6.0/go.mod h1:2Tu9+aMcznHK/AK1HMvgo6xiTLG5rD5rZLDS+rp2Bjs= golang.org/x/net v0.10.0/go.mod h1:0qNGK6F8kojg2nk9dLZ2mShWaEBan6FAoqfSigmmuDg= -golang.org/x/net v0.57.0 h1:K5+3DljvIuDG9/Jv9rvyMywYNFCQ9RSUY6OOTTkT+tE= -golang.org/x/net v0.57.0/go.mod h1:KpXc8iv+r3XplLAG/f7Jsf9RPszJzdR0f58q9vGOuEU= +golang.org/x/net v0.58.0 h1:ynWG7rqYi4ccpTEuPZ2QGWHktVEM9DMCj9yzDE0Q7To= +golang.org/x/net v0.58.0/go.mod h1:YwCddHnFlT7eLQqVprV19OnhLGtc5xOKgE0RyqgfWAU= golang.org/x/oauth2 v0.0.0-20180821212333-d2e6202438be/go.mod h1:N/0e6XlmueqKjAGxoOufVs8QHGRruUQn6yWY3a++T0U= golang.org/x/oauth2 v0.0.0-20190226205417-e64efc72b421/go.mod h1:gOpvHmFTYa4IltrdGE7lF6nIHvwfUNPOp7c8zoXwtLw= golang.org/x/oauth2 v0.0.0-20190604053449-0f29369cfe45/go.mod h1:gOpvHmFTYa4IltrdGE7lF6nIHvwfUNPOp7c8zoXwtLw= @@ -846,8 +846,8 @@ golang.org/x/text v0.3.7/go.mod h1:u+2+/6zg+i71rQMx5EYifcz6MCKuco9NR6JIITiCfzQ= golang.org/x/text v0.7.0/go.mod h1:mrYo+phRRbMaCq/xk9113O4dZlRixOauAjOtrjsXDZ8= golang.org/x/text v0.9.0/go.mod h1:e1OnstbJyHTd6l/uOt8jFFHp6TRDWZR/bV3emEE/zU8= golang.org/x/text v0.14.0/go.mod h1:18ZOQIKpY8NJVqYksKHtTdi31H5itFRjB5/qKTNYzSU= -golang.org/x/text v0.40.0 h1:Ub2Z6/xjgF1WrYQz2nuITOEegKFtiIy+rieRJ5lHZKs= -golang.org/x/text v0.40.0/go.mod h1:hpnzDAfGV753zIKo+wk3u1bVKCGPbrnF7+7LBF/UHVY= +golang.org/x/text v0.41.0 h1:vz/seA0lnX87Othu2f/0L24RcgrXD9/YFTSuGjj3rH8= +golang.org/x/text v0.41.0/go.mod h1:jvf1O8ajNzZqhSrQBPbutR/EB83Cc0CFrezNQIwbb5M= golang.org/x/time v0.0.0-20181108054448-85acf8d2951c/go.mod h1:tRJNPiyCQ0inRvYxbN9jk5I+vvW/OXSQhTDSoE431IQ= golang.org/x/time v0.0.0-20190308202827-9d24e82272b4/go.mod h1:tRJNPiyCQ0inRvYxbN9jk5I+vvW/OXSQhTDSoE431IQ= golang.org/x/time v0.0.0-20191024005414-555d28b269f0/go.mod h1:tRJNPiyCQ0inRvYxbN9jk5I+vvW/OXSQhTDSoE431IQ= @@ -1058,8 +1058,8 @@ google.golang.org/grpc v1.39.1/go.mod h1:PImNr+rS9TWYb2O4/emRugxiyHZ5JyHW5F+RPnD google.golang.org/grpc v1.40.0/go.mod h1:ogyxbiOoUXAkP+4+xa6PZSE9DZgIHtSpzjDTB9KAK34= google.golang.org/grpc v1.40.1/go.mod h1:ogyxbiOoUXAkP+4+xa6PZSE9DZgIHtSpzjDTB9KAK34= google.golang.org/grpc v1.42.0/go.mod h1:k+4IHHFw41K8+bbowsex27ge2rCb65oeWqe4jJ590SU= -google.golang.org/grpc v1.82.1 h1:NnAxzGRA0677vCa4BUkOAnO5+FfQqVl9iUXeD0IqcGE= -google.golang.org/grpc v1.82.1/go.mod h1:yzTZ1TB1Z3SG+LIYaI+WiE8D5+PZ3ArnrSp8zF3+/ZA= +google.golang.org/grpc v1.83.2 h1:EManeRomTObA0BU7I8vXgg/78uE5MJ9M8B39EX2WscU= +google.golang.org/grpc v1.83.2/go.mod h1:YPI1hK3kDked6iHvgX3tR0y+nX/qpMFKhPgFsokw1S8= google.golang.org/grpc/cmd/protoc-gen-go-grpc v1.1.0/go.mod h1:6Kw0yEErY5E/yWrBtf03jp27GLLJujG4z/JK95pnjjw= google.golang.org/protobuf v0.0.0-20200109180630-ec00e32a8dfd/go.mod h1:DFci5gLYBciE7Vtevhsrf46CRTquxDuWsQurQQe4oz8= google.golang.org/protobuf v0.0.0-20200221191635-4d8936d0db64/go.mod h1:kwYJMbMJ01Woi6D6+Kah6886xMZcty6N08ah7+eCXa0= diff --git a/third_party/cert-manager/01-cert-manager.yaml b/third_party/cert-manager/01-cert-manager.yaml index c62f2273daf..32267cd7df2 100644 --- a/third_party/cert-manager/01-cert-manager.yaml +++ b/third_party/cert-manager/01-cert-manager.yaml @@ -14,6 +14,7 @@ metadata: app.kubernetes.io/version: "v1.16.3" app.kubernetes.io/managed-by: Helm helm.sh/chart: cert-manager-v1.16.3 + --- # Source: cert-manager/templates/serviceaccount.yaml apiVersion: v1 @@ -30,6 +31,7 @@ metadata: app.kubernetes.io/version: "v1.16.3" app.kubernetes.io/managed-by: Helm helm.sh/chart: cert-manager-v1.16.3 + --- # Source: cert-manager/templates/webhook-serviceaccount.yaml apiVersion: v1 @@ -46,6 +48,7 @@ metadata: app.kubernetes.io/version: "v1.16.3" app.kubernetes.io/managed-by: Helm helm.sh/chart: cert-manager-v1.16.3 + --- # Source: cert-manager/templates/crds.yaml # @@ -370,6 +373,8 @@ spec: storage: true # END crd + + --- # Source: cert-manager/templates/crds.yaml # START crd @@ -1141,6 +1146,8 @@ spec: storage: true # END crd + + --- # Source: cert-manager/templates/crds.yaml # START crd @@ -4350,6 +4357,8 @@ spec: status: {} # END crd + + --- # Source: cert-manager/templates/crds.yaml # START crd @@ -8079,6 +8088,8 @@ spec: storage: true # END crd + + --- # Source: cert-manager/templates/crds.yaml # START crd @@ -11808,6 +11819,8 @@ spec: storage: true # END crd + + --- # Source: cert-manager/templates/crds.yaml # START crd @@ -12079,6 +12092,7 @@ spec: storage: true # END crd + --- # Source: cert-manager/templates/cainjector-rbac.yaml apiVersion: rbac.authorization.k8s.io/v1 @@ -12112,6 +12126,7 @@ rules: - apiGroups: ["apiextensions.k8s.io"] resources: ["customresourcedefinitions"] verbs: ["get", "list", "watch", "update", "patch"] + --- # Source: cert-manager/templates/rbac.yaml # Issuer controller role @@ -12140,6 +12155,7 @@ rules: - apiGroups: [""] resources: ["events"] verbs: ["create", "patch"] + --- # Source: cert-manager/templates/rbac.yaml # ClusterIssuer controller role @@ -12168,6 +12184,8 @@ rules: - apiGroups: [""] resources: ["events"] verbs: ["create", "patch"] + + --- # Source: cert-manager/templates/rbac.yaml # Certificates controller role @@ -12205,6 +12223,8 @@ rules: - apiGroups: [""] resources: ["events"] verbs: ["create", "patch"] + + --- # Source: cert-manager/templates/rbac.yaml # Orders controller role @@ -12245,6 +12265,8 @@ rules: - apiGroups: [""] resources: ["events"] verbs: ["create", "patch"] + + --- # Source: cert-manager/templates/rbac.yaml # Challenges controller role @@ -12307,6 +12329,8 @@ rules: - apiGroups: [""] resources: ["secrets"] verbs: ["get", "list", "watch"] + + --- # Source: cert-manager/templates/rbac.yaml # ingress-shim controller role @@ -12347,6 +12371,8 @@ rules: - apiGroups: [""] resources: ["events"] verbs: ["create", "patch"] + + --- # Source: cert-manager/templates/rbac.yaml apiVersion: rbac.authorization.k8s.io/v1 @@ -12366,6 +12392,7 @@ rules: - apiGroups: ["cert-manager.io"] resources: ["clusterissuers"] verbs: ["get", "list", "watch"] + --- # Source: cert-manager/templates/rbac.yaml apiVersion: rbac.authorization.k8s.io/v1 @@ -12391,6 +12418,9 @@ rules: - apiGroups: ["acme.cert-manager.io"] resources: ["challenges", "orders"] verbs: ["get", "list", "watch"] + + + --- # Source: cert-manager/templates/rbac.yaml apiVersion: rbac.authorization.k8s.io/v1 @@ -12417,6 +12447,8 @@ rules: - apiGroups: ["acme.cert-manager.io"] resources: ["challenges", "orders"] verbs: ["create", "delete", "deletecollection", "patch", "update"] + + --- # Source: cert-manager/templates/rbac.yaml # Permission to approve CertificateRequests referencing cert-manager.io Issuers and ClusterIssuers @@ -12439,6 +12471,8 @@ rules: resourceNames: - "issuers.cert-manager.io/*" - "clusterissuers.cert-manager.io/*" + + --- # Source: cert-manager/templates/rbac.yaml # Permission to: @@ -12470,6 +12504,8 @@ rules: - apiGroups: ["authorization.k8s.io"] resources: ["subjectaccessreviews"] verbs: ["create"] + + --- # Source: cert-manager/templates/webhook-rbac.yaml apiVersion: rbac.authorization.k8s.io/v1 @@ -12488,6 +12524,7 @@ rules: - apiGroups: ["authorization.k8s.io"] resources: ["subjectaccessreviews"] verbs: ["create"] + --- # Source: cert-manager/templates/cainjector-rbac.yaml apiVersion: rbac.authorization.k8s.io/v1 @@ -12510,6 +12547,8 @@ subjects: - name: cert-manager-cainjector namespace: cert-manager kind: ServiceAccount + + --- # Source: cert-manager/templates/rbac.yaml apiVersion: rbac.authorization.k8s.io/v1 @@ -12532,6 +12571,8 @@ subjects: - name: cert-manager namespace: cert-manager kind: ServiceAccount + + --- # Source: cert-manager/templates/rbac.yaml apiVersion: rbac.authorization.k8s.io/v1 @@ -12554,6 +12595,8 @@ subjects: - name: cert-manager namespace: cert-manager kind: ServiceAccount + + --- # Source: cert-manager/templates/rbac.yaml apiVersion: rbac.authorization.k8s.io/v1 @@ -12576,6 +12619,8 @@ subjects: - name: cert-manager namespace: cert-manager kind: ServiceAccount + + --- # Source: cert-manager/templates/rbac.yaml apiVersion: rbac.authorization.k8s.io/v1 @@ -12598,6 +12643,8 @@ subjects: - name: cert-manager namespace: cert-manager kind: ServiceAccount + + --- # Source: cert-manager/templates/rbac.yaml apiVersion: rbac.authorization.k8s.io/v1 @@ -12620,6 +12667,8 @@ subjects: - name: cert-manager namespace: cert-manager kind: ServiceAccount + + --- # Source: cert-manager/templates/rbac.yaml apiVersion: rbac.authorization.k8s.io/v1 @@ -12642,6 +12691,7 @@ subjects: - name: cert-manager namespace: cert-manager kind: ServiceAccount + --- # Source: cert-manager/templates/rbac.yaml apiVersion: rbac.authorization.k8s.io/v1 @@ -12664,6 +12714,8 @@ subjects: - name: cert-manager namespace: cert-manager kind: ServiceAccount + + --- # Source: cert-manager/templates/rbac.yaml apiVersion: rbac.authorization.k8s.io/v1 @@ -12686,6 +12738,7 @@ subjects: - name: cert-manager namespace: cert-manager kind: ServiceAccount + --- # Source: cert-manager/templates/webhook-rbac.yaml apiVersion: rbac.authorization.k8s.io/v1 @@ -12708,6 +12761,7 @@ subjects: - kind: ServiceAccount name: cert-manager-webhook namespace: cert-manager + --- # Source: cert-manager/templates/cainjector-rbac.yaml # leader election rules @@ -12737,6 +12791,8 @@ rules: - apiGroups: ["coordination.k8s.io"] resources: ["leases"] verbs: ["create"] + + --- # Source: cert-manager/templates/rbac.yaml apiVersion: rbac.authorization.k8s.io/v1 @@ -12760,6 +12816,8 @@ rules: - apiGroups: ["coordination.k8s.io"] resources: ["leases"] verbs: ["create"] + + --- # Source: cert-manager/templates/rbac.yaml apiVersion: rbac.authorization.k8s.io/v1 @@ -12780,6 +12838,8 @@ rules: resources: ["serviceaccounts/token"] resourceNames: ["cert-manager"] verbs: ["create"] + + --- # Source: cert-manager/templates/webhook-rbac.yaml apiVersion: rbac.authorization.k8s.io/v1 @@ -12805,6 +12865,7 @@ rules: - apiGroups: [""] resources: ["secrets"] verbs: ["create"] + --- # Source: cert-manager/templates/cainjector-rbac.yaml # grant cert-manager permission to manage the leaderelection configmap in the @@ -12830,6 +12891,7 @@ subjects: - kind: ServiceAccount name: cert-manager-cainjector namespace: cert-manager + --- # Source: cert-manager/templates/rbac.yaml # grant cert-manager permission to manage the leaderelection configmap in the @@ -12855,6 +12917,8 @@ subjects: - kind: ServiceAccount name: cert-manager namespace: cert-manager + + --- # Source: cert-manager/templates/rbac.yaml # grant cert-manager permission to create tokens for the serviceaccount @@ -12879,6 +12943,8 @@ subjects: - kind: ServiceAccount name: cert-manager namespace: cert-manager + + --- # Source: cert-manager/templates/webhook-rbac.yaml apiVersion: rbac.authorization.k8s.io/v1 @@ -12902,6 +12968,8 @@ subjects: - kind: ServiceAccount name: cert-manager-webhook namespace: cert-manager + + --- # Source: cert-manager/templates/cainjector-service.yaml apiVersion: v1 @@ -12927,6 +12995,7 @@ spec: app.kubernetes.io/name: cainjector app.kubernetes.io/instance: cert-manager app.kubernetes.io/component: "cainjector" + --- # Source: cert-manager/templates/service.yaml apiVersion: v1 @@ -12953,6 +13022,7 @@ spec: app.kubernetes.io/name: cert-manager app.kubernetes.io/instance: cert-manager app.kubernetes.io/component: "controller" + --- # Source: cert-manager/templates/webhook-service.yaml apiVersion: v1 @@ -12983,6 +13053,7 @@ spec: app.kubernetes.io/name: webhook app.kubernetes.io/instance: cert-manager app.kubernetes.io/component: "webhook" + --- # Source: cert-manager/templates/cainjector-deployment.yaml apiVersion: apps/v1 @@ -13050,6 +13121,7 @@ spec: readOnlyRootFilesystem: true nodeSelector: kubernetes.io/os: linux + --- # Source: cert-manager/templates/deployment.yaml apiVersion: apps/v1 @@ -13235,6 +13307,7 @@ spec: fieldPath: metadata.namespace nodeSelector: kubernetes.io/os: linux + --- # Source: cert-manager/templates/webhook-mutating-webhook.yaml apiVersion: admissionregistration.k8s.io/v1 @@ -13344,6 +13417,7 @@ metadata: app.kubernetes.io/version: "v1.16.3" app.kubernetes.io/managed-by: Helm helm.sh/chart: cert-manager-v1.16.3 + --- # Source: cert-manager/templates/startupapicheck-rbac.yaml # create certificate role @@ -13368,6 +13442,7 @@ rules: - apiGroups: ["cert-manager.io"] resources: ["certificaterequests"] verbs: ["create"] + --- # Source: cert-manager/templates/startupapicheck-rbac.yaml apiVersion: rbac.authorization.k8s.io/v1 @@ -13395,6 +13470,7 @@ subjects: - kind: ServiceAccount name: cert-manager-startupapicheck namespace: cert-manager + --- # Source: cert-manager/templates/startupapicheck-job.yaml apiVersion: batch/v1 @@ -13456,3 +13532,4 @@ spec: fieldPath: metadata.namespace nodeSelector: kubernetes.io/os: linux + diff --git a/third_party/cert-manager/02-trust-manager.yaml b/third_party/cert-manager/02-trust-manager.yaml index 8cce328328c..d55f5b77f8a 100644 --- a/third_party/cert-manager/02-trust-manager.yaml +++ b/third_party/cert-manager/02-trust-manager.yaml @@ -11,6 +11,7 @@ metadata: app.kubernetes.io/instance: cert-manager app.kubernetes.io/version: "v0.12.0" app.kubernetes.io/managed-by: Helm + --- # Source: trust-manager/templates/crd-trust.cert-manager.io_bundles.yaml apiVersion: apiextensions.k8s.io/v1 @@ -457,6 +458,7 @@ subjects: - kind: ServiceAccount name: trust-manager namespace: cert-manager + --- # Source: trust-manager/templates/role.yaml kind: Role @@ -479,6 +481,7 @@ rules: - "get" - "list" - "watch" + --- # Source: trust-manager/templates/role.yaml kind: Role @@ -503,6 +506,7 @@ rules: - "update" - "watch" - "list" + --- # Source: trust-manager/templates/rolebinding.yaml kind: RoleBinding @@ -524,6 +528,7 @@ subjects: - kind: ServiceAccount name: trust-manager namespace: cert-manager + --- # Source: trust-manager/templates/rolebinding.yaml kind: RoleBinding @@ -545,6 +550,7 @@ subjects: - kind: ServiceAccount name: trust-manager namespace: cert-manager + --- # Source: trust-manager/templates/metrics-service.yaml apiVersion: v1 @@ -568,6 +574,7 @@ spec: name: metrics selector: app: trust-manager + --- # Source: trust-manager/templates/webhook.yaml apiVersion: v1 @@ -591,6 +598,8 @@ spec: name: webhook selector: app: trust-manager + + --- # Source: trust-manager/templates/deployment.yaml apiVersion: apps/v1 @@ -697,44 +706,8 @@ spec: secret: defaultMode: 420 secretName: trust-manager-tls ---- -# Source: trust-manager/templates/certificate.yaml -apiVersion: cert-manager.io/v1 -kind: Certificate -metadata: - name: trust-manager - namespace: cert-manager - labels: - app.kubernetes.io/name: trust-manager - helm.sh/chart: trust-manager-v0.12.0 - app.kubernetes.io/instance: cert-manager - app.kubernetes.io/version: "v0.12.0" - app.kubernetes.io/managed-by: Helm -spec: - commonName: "trust-manager.cert-manager.svc" - dnsNames: - - "trust-manager.cert-manager.svc" - secretName: trust-manager-tls - revisionHistoryLimit: 1 - issuerRef: - name: trust-manager - kind: Issuer - group: cert-manager.io ---- -# Source: trust-manager/templates/certificate.yaml -apiVersion: cert-manager.io/v1 -kind: Issuer -metadata: - name: trust-manager - namespace: cert-manager - labels: - app.kubernetes.io/name: trust-manager - helm.sh/chart: trust-manager-v0.12.0 - app.kubernetes.io/instance: cert-manager - app.kubernetes.io/version: "v0.12.0" - app.kubernetes.io/managed-by: Helm -spec: - selfSigned: {} + + --- # Source: trust-manager/templates/webhook.yaml apiVersion: admissionregistration.k8s.io/v1 @@ -775,3 +748,44 @@ webhooks: name: trust-manager namespace: cert-manager path: /validate-trust-cert-manager-io-v1alpha1-bundle + +--- +# Source: trust-manager/templates/certificate.yaml +apiVersion: cert-manager.io/v1 +kind: Certificate +metadata: + name: trust-manager + namespace: cert-manager + labels: + app.kubernetes.io/name: trust-manager + helm.sh/chart: trust-manager-v0.12.0 + app.kubernetes.io/instance: cert-manager + app.kubernetes.io/version: "v0.12.0" + app.kubernetes.io/managed-by: Helm +spec: + commonName: "trust-manager.cert-manager.svc" + dnsNames: + - "trust-manager.cert-manager.svc" + secretName: trust-manager-tls + revisionHistoryLimit: 1 + issuerRef: + name: trust-manager + kind: Issuer + group: cert-manager.io + + +--- +# Source: trust-manager/templates/certificate.yaml +apiVersion: cert-manager.io/v1 +kind: Issuer +metadata: + name: trust-manager + namespace: cert-manager + labels: + app.kubernetes.io/name: trust-manager + helm.sh/chart: trust-manager-v0.12.0 + app.kubernetes.io/instance: cert-manager + app.kubernetes.io/version: "v0.12.0" + app.kubernetes.io/managed-by: Helm +spec: + selfSigned: {} diff --git a/vendor/golang.org/x/net/http2/hpack/encode.go b/vendor/golang.org/x/net/http2/hpack/encode.go index 46219da2b01..e6d0c265acf 100644 --- a/vendor/golang.org/x/net/http2/hpack/encode.go +++ b/vendor/golang.org/x/net/http2/hpack/encode.go @@ -39,7 +39,6 @@ func NewEncoder(w io.Writer) *Encoder { tableSizeUpdate: false, w: w, } - e.dynTab.table.init() e.dynTab.setMaxSize(initialHeaderTableSize) return e } diff --git a/vendor/golang.org/x/net/http2/hpack/hpack.go b/vendor/golang.org/x/net/http2/hpack/hpack.go index 7a1d976696a..ecd3eeca99a 100644 --- a/vendor/golang.org/x/net/http2/hpack/hpack.go +++ b/vendor/golang.org/x/net/http2/hpack/hpack.go @@ -105,7 +105,6 @@ func NewDecoder(maxDynamicTableSize uint32, emitFunc func(f HeaderField)) *Decod emitEnabled: true, firstField: true, } - d.dynTab.table.init() d.dynTab.allowedMaxSize = maxDynamicTableSize d.dynTab.setMaxSize(maxDynamicTableSize) return d diff --git a/vendor/golang.org/x/net/http2/hpack/tables.go b/vendor/golang.org/x/net/http2/hpack/tables.go index 8cbdf3f019c..3bd7eb75332 100644 --- a/vendor/golang.org/x/net/http2/hpack/tables.go +++ b/vendor/golang.org/x/net/http2/hpack/tables.go @@ -31,10 +31,18 @@ type headerFieldTable struct { // byName maps a HeaderField name to the unique id of the newest entry with // the same name. See above for a definition of "unique id". + // + // byName and byNameValue are used only by search, which is only called + // for tables used by encoders. For tables used only by decoders, the + // maps are never built, as a memory optimization for servers with many + // mostly-idle connections, each pinning a dynamic table. The maps are + // built lazily by the first search call and are nil until then. The two + // maps are always both nil or both non-nil. byName map[string]uint64 // byNameValue maps a HeaderField name/value pair to the unique id of the newest // entry with the same name and value. See above for a definition of "unique id". + // See byName for when this map is non-nil. byNameValue map[pairNameValue]uint64 } @@ -42,9 +50,17 @@ type pairNameValue struct { name, value string } -func (t *headerFieldTable) init() { - t.byName = make(map[string]uint64) - t.byNameValue = make(map[pairNameValue]uint64) +// buildMaps initializes byName and byNameValue from ents. +func (t *headerFieldTable) buildMaps() { + t.byName = make(map[string]uint64, len(t.ents)) + t.byNameValue = make(map[pairNameValue]uint64, len(t.ents)) + for k, f := range t.ents { + // Map to the newest matching entry: later (newer) entries + // overwrite earlier ones, matching addEntry's behavior. + id := t.evictCount + uint64(k) + 1 + t.byName[f.Name] = id + t.byNameValue[pairNameValue{f.Name, f.Value}] = id + } } // len reports the number of entries in the table. @@ -54,9 +70,11 @@ func (t *headerFieldTable) len() int { // addEntry adds a new entry. func (t *headerFieldTable) addEntry(f HeaderField) { - id := uint64(t.len()) + t.evictCount + 1 - t.byName[f.Name] = id - t.byNameValue[pairNameValue{f.Name, f.Value}] = id + if t.byName != nil { + id := uint64(t.len()) + t.evictCount + 1 + t.byName[f.Name] = id + t.byNameValue[pairNameValue{f.Name, f.Value}] = id + } t.ents = append(t.ents, f) } @@ -65,14 +83,16 @@ func (t *headerFieldTable) evictOldest(n int) { if n > t.len() { panic(fmt.Sprintf("evictOldest(%v) on table with %v entries", n, t.len())) } - for k := 0; k < n; k++ { - f := t.ents[k] - id := t.evictCount + uint64(k) + 1 - if t.byName[f.Name] == id { - delete(t.byName, f.Name) - } - if p := (pairNameValue{f.Name, f.Value}); t.byNameValue[p] == id { - delete(t.byNameValue, p) + if t.byName != nil { + for k := 0; k < n; k++ { + f := t.ents[k] + id := t.evictCount + uint64(k) + 1 + if t.byName[f.Name] == id { + delete(t.byName, f.Name) + } + if p := (pairNameValue{f.Name, f.Value}); t.byNameValue[p] == id { + delete(t.byNameValue, p) + } } } copy(t.ents, t.ents[n:]) @@ -100,6 +120,9 @@ func (t *headerFieldTable) evictOldest(n int) { // // See Section 2.3.3. func (t *headerFieldTable) search(f HeaderField) (i uint64, nameValueMatch bool) { + if t.byName == nil { + t.buildMaps() + } if !f.Sensitive { if id := t.byNameValue[pairNameValue{f.Name, f.Value}]; id != 0 { return t.idToIndex(id), true diff --git a/vendor/golang.org/x/net/http2/transport_wrap.go b/vendor/golang.org/x/net/http2/transport_wrap.go index 534e77ab963..741fb97062e 100644 --- a/vendor/golang.org/x/net/http2/transport_wrap.go +++ b/vendor/golang.org/x/net/http2/transport_wrap.go @@ -237,32 +237,40 @@ type ClientConn struct { } func (cc *ClientConn) roundTrip(req *http.Request) (*http.Response, error) { - err := func() error { + haveReservation, err := func() (bool, error) { cc.mu.Lock() defer cc.mu.Unlock() if cc.doNotReuse { - return errClientConnUnusable - } - cc.roundTrips++ - if cc.reserved > 0 { - // We've already reserved a concurrency slot for this request. - cc.reserved-- - } else if cc.cc.Reserve() != nil { - // We don't seem to have an available concurrency slot, - // so bump the pending count (requests waiting for a slot). - cc.pending++ + return false, errClientConnUnusable } + // ClientConn.Shutdown will not shut down the conn while // cc.starting > 0 or cc.cc.InFlight() > 0. // // The starting state covers the gap between us deciding to // start sending the request, and actually sending it. cc.starting++ - return nil + + cc.roundTrips++ + if cc.reserved == 0 { + // We do not have a concurrency slot reserved for this request. + return false, nil + } + cc.reserved-- + return true, nil }() if err != nil { return nil, err } + // If we have no reservation, try to acquire one. + // (This must be done without cc.mu held, since Reserve may call back to the state hook.) + if !haveReservation && cc.cc.Reserve() != nil { + // We could not acquire a concurrency slot, so bump the pending count + // (requests waiting for a slot). + cc.mu.Lock() + cc.pending++ + cc.mu.Unlock() + } resp, err := cc.cc.RoundTrip(req) cc.mu.Lock() cc.starting-- @@ -293,16 +301,21 @@ func (cc *ClientConn) ping(ctx context.Context) error { } func (cc *ClientConn) reserveNewRequest() bool { + if err := cc.cc.Reserve(); err != nil { + return false + } + reserved := true cc.mu.Lock() - defer cc.mu.Unlock() if cc.doNotReuse { - return false + reserved = false + } else { + cc.reserved++ } - if err := cc.cc.Reserve(); err != nil { - return false + cc.mu.Unlock() + if !reserved { + cc.cc.Release() } - cc.reserved++ - return true + return reserved } func (cc *ClientConn) setDoNotReuse() { diff --git a/vendor/google.golang.org/grpc/clientconn.go b/vendor/google.golang.org/grpc/clientconn.go index c4bca5203eb..b27c7e84a3d 100644 --- a/vendor/google.golang.org/grpc/clientconn.go +++ b/vendor/google.golang.org/grpc/clientconn.go @@ -24,12 +24,10 @@ import ( "fmt" "math" "net/url" - "os" "slices" "strings" "sync" "sync/atomic" - "syscall" "time" "google.golang.org/grpc/balancer" @@ -1573,26 +1571,13 @@ func (ac *addrConn) createTransport(ctx context.Context, addr resolver.Address, // to the provided transport.GoAwayInfo, as specified by gRFC A94: // https://github.com/grpc/proposal/blob/master/A94-grpc-subchannel-disconnections-metrics.md func disconnectErrorString(info transport.GoAwayInfo) string { - err := info.Err - var sysErr syscall.Errno - switch { - case info.Reason != transport.GoAwayInvalid: + if info.Reason != transport.GoAwayInvalid { return fmt.Sprintf("GOAWAY %s", info.GoAwayCode.String()) - case err == nil: - return "unknown" - case errors.Is(err, context.Canceled): - return "subchannel shutdown" - case errors.Is(err, syscall.ECONNRESET): - return "connection reset" - case errors.Is(err, syscall.ETIMEDOUT), errors.Is(err, context.DeadlineExceeded), errors.Is(err, os.ErrDeadlineExceeded): - return "connection timed out" - case errors.Is(err, syscall.ECONNABORTED): - return "connection aborted" - case errors.As(err, &sysErr): - return "socket error" - default: + } + if info.Err == nil { return "unknown" } + return disconnectErrorLabel(info.Err) } // startHealthCheck starts the health checking stream (RPC) to watch the health diff --git a/vendor/google.golang.org/grpc/clientconn_disconnect_reason_noplan9.go b/vendor/google.golang.org/grpc/clientconn_disconnect_reason_noplan9.go new file mode 100644 index 00000000000..f0fcd884237 --- /dev/null +++ b/vendor/google.golang.org/grpc/clientconn_disconnect_reason_noplan9.go @@ -0,0 +1,48 @@ +//go:build !plan9 + +/* + * + * Copyright 2026 gRPC authors. + * + * Licensed under the Apache License, Version 2.0 (the "License"); + * you may not use this file except in compliance with the License. + * You may obtain a copy of the License at + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, software + * distributed under the License is distributed on an "AS IS" BASIS, + * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + * See the License for the specific language governing permissions and + * limitations under the License. + * + */ + +package grpc + +import ( + "context" + "errors" + "os" + "syscall" +) + +// disconnectErrorLabel returns the grpc.disconnect_error metric label for a +// transport error, as specified by gRFC A94. +func disconnectErrorLabel(err error) string { + var sysErr syscall.Errno + switch { + case errors.Is(err, context.Canceled): + return "subchannel shutdown" + case errors.Is(err, syscall.ECONNRESET): + return "connection reset" + case errors.Is(err, syscall.ETIMEDOUT), errors.Is(err, context.DeadlineExceeded), errors.Is(err, os.ErrDeadlineExceeded): + return "connection timed out" + case errors.Is(err, syscall.ECONNABORTED): + return "connection aborted" + case errors.As(err, &sysErr): + return "socket error" + default: + return "unknown" + } +} diff --git a/vendor/google.golang.org/grpc/clientconn_disconnect_reason_plan9.go b/vendor/google.golang.org/grpc/clientconn_disconnect_reason_plan9.go new file mode 100644 index 00000000000..930b12664cc --- /dev/null +++ b/vendor/google.golang.org/grpc/clientconn_disconnect_reason_plan9.go @@ -0,0 +1,39 @@ +/* + * + * Copyright 2026 gRPC authors. + * + * Licensed under the Apache License, Version 2.0 (the "License"); + * you may not use this file except in compliance with the License. + * You may obtain a copy of the License at + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, software + * distributed under the License is distributed on an "AS IS" BASIS, + * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + * See the License for the specific language governing permissions and + * limitations under the License. + * + */ + +package grpc + +import ( + "context" + "errors" + "os" +) + +// disconnectErrorLabel returns the grpc.disconnect_error metric label for a +// transport error, as specified by gRFC A94. syscall.Errno does not exist on +// plan9, so only the portable classifications are available. +func disconnectErrorLabel(err error) string { + switch { + case errors.Is(err, context.Canceled): + return "subchannel shutdown" + case errors.Is(err, context.DeadlineExceeded), errors.Is(err, os.ErrDeadlineExceeded): + return "connection timed out" + default: + return "unknown" + } +} diff --git a/vendor/google.golang.org/grpc/internal/envconfig/envconfig.go b/vendor/google.golang.org/grpc/internal/envconfig/envconfig.go index 29d332e7b67..33344812746 100644 --- a/vendor/google.golang.org/grpc/internal/envconfig/envconfig.go +++ b/vendor/google.golang.org/grpc/internal/envconfig/envconfig.go @@ -150,8 +150,18 @@ var ( // throttling limit if unforeseen issues arise, and it will be removed in a // future release. // - // TODO: Remove this env var once v1.83.0 is release. + // TODO: Remove this env var once v1.83.0 is released. ControlBufferThrottleLimit = uint64FromEnv("GRPC_GO_EXPERIMENTAL_CONTROL_BUFFER_THROTTLE_LIMIT", 100, 1, 10000) + + // EnableReceiveBufferCompaction enables the compaction of data buffers + // to reduce the number of buffers in the receive buffer. + // + // This environment variable serves as an escape hatch to disable the + // feature if unforeseen issues arise, and it will be removed in a future + // release. + // + // TODO: Remove this env var once v1.85.0 is released. + EnableReceiveBufferCompaction = boolFromEnv("GRPC_GO_EXPERIMENTAL_ENABLE_RECEIVE_BUFFER_COMPACTION", true) ) func boolFromEnv(envVar string, def bool) bool { diff --git a/vendor/google.golang.org/grpc/internal/envconfig/xds.go b/vendor/google.golang.org/grpc/internal/envconfig/xds.go index a2312f8eacf..e4b69191382 100644 --- a/vendor/google.golang.org/grpc/internal/envconfig/xds.go +++ b/vendor/google.golang.org/grpc/internal/envconfig/xds.go @@ -69,9 +69,8 @@ var ( // https://github.com/grpc/proposal/blob/master/A87-mtls-spiffe-support.md XDSSPIFFEEnabled = boolFromEnv("GRPC_EXPERIMENTAL_XDS_MTLS_SPIFFE", false) - // XDSHTTPConnectEnabled is true if gRPC should parse custom Metadata - // configuring use of an HTTP CONNECT proxy via xDS from cluster resources. - // For more details, see: + // XDSHTTPConnectEnabled controls support for dynamic HTTP CONNECT proxying + // configured via the xDS control plane. For more details, see: // https://github.com/grpc/proposal/blob/master/A86-xds-http-connect.md XDSHTTPConnectEnabled = boolFromEnv("GRPC_EXPERIMENTAL_XDS_HTTP_CONNECT", false) @@ -88,7 +87,7 @@ var ( // XDSORCAToLRSPropEnabled controls whether ORCA metrics are explicitly // filtered and prefix-propagated to the LRS server. For more details, see: // https://github.com/grpc/proposal/blob/master/A85-lrs-custom-metrics-changes.md - XDSORCAToLRSPropEnabled = boolFromEnv("GRPC_EXPERIMENTAL_XDS_ORCA_LRS_PROPAGATION", false) + XDSORCAToLRSPropEnabled = boolFromEnv("GRPC_EXPERIMENTAL_XDS_ORCA_LRS_PROPAGATION", true) // XDSClientExtProcEnabled indicates whether ExtProc filter is enabled on // the client side. For more details, see: diff --git a/vendor/google.golang.org/grpc/internal/grpcsync/callback_serializer.go b/vendor/google.golang.org/grpc/internal/grpcsync/callback_serializer.go index 9b6d8a1fa3f..d4999fcca83 100644 --- a/vendor/google.golang.org/grpc/internal/grpcsync/callback_serializer.go +++ b/vendor/google.golang.org/grpc/internal/grpcsync/callback_serializer.go @@ -20,10 +20,15 @@ package grpcsync import ( "context" + "errors" "google.golang.org/grpc/internal/buffer" ) +// ErrSerializerClosed is returned by ScheduleAndWait if the CallbackSerializer +// was closed before the callback could be scheduled. +var ErrSerializerClosed = errors.New("callback serializer is closed") + // CallbackSerializer provides a mechanism to schedule callbacks in a // synchronized manner. It provides a FIFO guarantee on the order of execution // of scheduled callbacks. New callbacks can be scheduled by invoking the @@ -77,6 +82,27 @@ func (cs *CallbackSerializer) ScheduleOr(f func(ctx context.Context), onFailure } } +// ScheduleAndWait schedules the provided callback function f to be executed in +// the order it was added and blocks until f has run. If the context passed to +// NewCallbackSerializer was canceled before this method is called, f is not run +// and ScheduleAndWait returns ErrSerializerClosed. +// +// Callbacks are expected to honor the context when performing any blocking +// operations, and should return early when the context is canceled. +func (cs *CallbackSerializer) ScheduleAndWait(f func(ctx context.Context)) error { + done := make(chan struct{}) + var err error + cs.ScheduleOr(func(ctx context.Context) { + f(ctx) + close(done) + }, func() { + err = ErrSerializerClosed + close(done) + }) + <-done + return err +} + func (cs *CallbackSerializer) run(ctx context.Context) { defer close(cs.done) diff --git a/vendor/google.golang.org/grpc/internal/mem/buffer_pool.go b/vendor/google.golang.org/grpc/internal/mem/buffer_pool.go index 2d83b2eced1..00aeca419fe 100644 --- a/vendor/google.golang.org/grpc/internal/mem/buffer_pool.go +++ b/vendor/google.golang.org/grpc/internal/mem/buffer_pool.go @@ -26,12 +26,26 @@ import ( "slices" "sort" "sync" + + "google.golang.org/grpc/internal" ) const ( goPageSize = 4 * 1024 // 4KiB. N.B. this must be a power of 2. ) +var ( + // BufferPoolingThreshold is the minimum size of a buffer that can be pooled. + // This is used to determine whether to pool buffers or allocate them directly. + BufferPoolingThreshold = 1 << 10 +) + +func init() { + internal.SetBufferPoolingThresholdForTesting = func(threshold int) { + BufferPoolingThreshold = threshold + } +} + var uintSize = bits.UintSize // use a variable for mocking during tests. // bufferPool is a copy of the public bufferPool interface used to avoid diff --git a/vendor/google.golang.org/grpc/internal/resolver/config_selector.go b/vendor/google.golang.org/grpc/internal/resolver/config_selector.go index 6320e9b576b..238950bbbf9 100644 --- a/vendor/google.golang.org/grpc/internal/resolver/config_selector.go +++ b/vendor/google.golang.org/grpc/internal/resolver/config_selector.go @@ -24,7 +24,6 @@ import ( "sync" "google.golang.org/grpc/internal/serviceconfig" - "google.golang.org/grpc/metadata" "google.golang.org/grpc/resolver" ) @@ -52,82 +51,7 @@ type RPCConfig struct { Context context.Context MethodConfig serviceconfig.MethodConfig // configuration to use for this RPC OnCommitted func() // Called when the RPC has been committed (retries no longer possible) - Interceptor ClientInterceptor -} - -// ClientStream is the same as grpc.ClientStream, but defined here for circular -// dependency reasons. -type ClientStream interface { - // Header returns the header metadata received from the server if there - // is any. It blocks if the metadata is not ready to read. - Header() (metadata.MD, error) - // Trailer returns the trailer metadata from the server, if there is any. - // It must only be called after stream.CloseAndRecv has returned, or - // stream.Recv has returned a non-nil error (including io.EOF). - Trailer() metadata.MD - // CloseSend closes the send direction of the stream. It closes the stream - // when non-nil error is met. It is also not safe to call CloseSend - // concurrently with SendMsg. - CloseSend() error - // Context returns the context for this stream. - // - // It should not be called until after Header or RecvMsg has returned. Once - // called, subsequent client-side retries are disabled. - Context() context.Context - // SendMsg is generally called by generated code. On error, SendMsg aborts - // the stream. If the error was generated by the client, the status is - // returned directly; otherwise, io.EOF is returned and the status of - // the stream may be discovered using RecvMsg. - // - // SendMsg blocks until: - // - There is sufficient flow control to schedule m with the transport, or - // - The stream is done, or - // - The stream breaks. - // - // SendMsg does not wait until the message is received by the server. An - // untimely stream closure may result in lost messages. To ensure delivery, - // users should ensure the RPC completed successfully using RecvMsg. - // - // It is safe to have a goroutine calling SendMsg and another goroutine - // calling RecvMsg on the same stream at the same time, but it is not safe - // to call SendMsg on the same stream in different goroutines. It is also - // not safe to call CloseSend concurrently with SendMsg. - SendMsg(m any) error - // RecvMsg blocks until it receives a message into m or the stream is - // done. It returns io.EOF when the stream completes successfully. On - // any other error, the stream is aborted and the error contains the RPC - // status. - // - // It is safe to have a goroutine calling SendMsg and another goroutine - // calling RecvMsg on the same stream at the same time, but it is not - // safe to call RecvMsg on the same stream in different goroutines. - RecvMsg(m any) error -} - -// ClientInterceptor is an interceptor for gRPC client streams. -type ClientInterceptor interface { - // NewStream creates a ClientStream for an RPC. - // - // Implementations must delegate stream creation to the provided newStream - // function. To intercept or override stream behavior, implementations - // may wrap the ClientStream returned by the delegate. - // - // Note: RPCInfo.Context is currently unused and will be nil. - // - // The done function is invoked when the RPC has finished using its - // underlying connection or if a connection could not be assigned. Because - // interceptors operate at the application layer, RPC operations may - // continue on the ClientStream even after done has been called. The - // caller must ensure done is non-nil. - // - // To ensure RPC completion notifications propagate through the entire - // interceptor chain, implementations must ensure that the done function - // passed to the delegate newStream invokes the done function passed to - // NewStream. - NewStream(ctx context.Context, ri RPCInfo, done func(), newStream func(ctx context.Context, done func()) (ClientStream, error)) (ClientStream, error) - // Close closes the interceptor. Once called, no new calls to NewStream are - // accepted. Ongoing calls to NewStream are allowed to complete. - Close() + Interceptor any } // ServerInterceptor is an interceptor for incoming RPC's on gRPC server side. diff --git a/vendor/google.golang.org/grpc/internal/transport/client_stream.go b/vendor/google.golang.org/grpc/internal/transport/client_stream.go index ad382b0fda1..046f0a55577 100644 --- a/vendor/google.golang.org/grpc/internal/transport/client_stream.go +++ b/vendor/google.golang.org/grpc/internal/transport/client_stream.go @@ -39,9 +39,8 @@ const nonGRPCDataMaxLen = 1024 type ClientStream struct { Stream // Embed for common stream functionality. - ct *http2Client - done chan struct{} // closed at the end of stream to unblock writers. - doneFunc func() // invoked at the end of stream. + ct *http2Client + done chan struct{} // closed at the end of stream to unblock writers. headerChan chan struct{} // closed to indicate the end of header metadata. header metadata.MD // the received header metadata diff --git a/vendor/google.golang.org/grpc/internal/transport/handler_server.go b/vendor/google.golang.org/grpc/internal/transport/handler_server.go index a8356c9adbc..9cd8d28d33e 100644 --- a/vendor/google.golang.org/grpc/internal/transport/handler_server.go +++ b/vendor/google.golang.org/grpc/internal/transport/handler_server.go @@ -424,7 +424,7 @@ func (ht *serverHandlerTransport) HandleStreams(ctx context.Context, startStream st: ht, headerWireLength: 0, // won't have access to header wire length until golang/go#18997. } - s.Stream.buf.init() + s.Stream.buf.init(ht.bufferPool) s.readRequester = s s.trReader = transportReader{ reader: recvBufferReader{ctx: s.ctx, ctxDone: s.ctx.Done(), recv: &s.buf}, diff --git a/vendor/google.golang.org/grpc/internal/transport/http2_client.go b/vendor/google.golang.org/grpc/internal/transport/http2_client.go index 822c09ba621..10d19774159 100644 --- a/vendor/google.golang.org/grpc/internal/transport/http2_client.go +++ b/vendor/google.golang.org/grpc/internal/transport/http2_client.go @@ -498,10 +498,9 @@ func (t *http2Client) newStream(ctx context.Context, callHdr *CallHdr, handler s ct: t, done: make(chan struct{}), headerChan: make(chan struct{}), - doneFunc: callHdr.DoneFunc, statsHandler: handler, } - s.Stream.buf.init() + s.Stream.buf.init(t.bufferPool) s.Stream.wq.init(defaultWriteQuota, s.done) s.readRequester = s // The client side stream context should have exactly the same life cycle with the user provided context. @@ -998,9 +997,6 @@ func (t *http2Client) closeStream(s *ClientStream, err error, rst bool, rstCode t.controlBuf.executeAndPut(addBackStreamQuota, cleanup) // This will unblock write. close(s.done) - if s.doneFunc != nil { - s.doneFunc() - } } // Close kicks off the shutdown process of the transport. This should be called diff --git a/vendor/google.golang.org/grpc/internal/transport/http2_server.go b/vendor/google.golang.org/grpc/internal/transport/http2_server.go index be8ae9f9c54..82e13e64aa6 100644 --- a/vendor/google.golang.org/grpc/internal/transport/http2_server.go +++ b/vendor/google.golang.org/grpc/internal/transport/http2_server.go @@ -407,7 +407,7 @@ func (t *http2Server) operateHeaders(ctx context.Context, frame *http2.MetaHeade st: t, headerWireLength: int(frame.Header().Length), } - s.Stream.buf.init() + s.Stream.buf.init(t.bufferPool) var ( // if false, content-type was missing or invalid isGRPC = false @@ -522,6 +522,12 @@ func (t *http2Server) operateHeaders(ctx context.Context, frame *http2.MetaHeade delete(mdata, "host") } + // If :authority is still missing, i.e. no host or :authority header is + // present, reject the request as invalid. + if len(mdata[":authority"]) == 0 { + t.writeEarlyAbort(streamID, s.contentSubtype, status.New(codes.Internal, "no host or :authority header present"), http.StatusBadRequest, !frame.StreamEnded()) + return nil + } if frame.StreamEnded() { // s is just created by the caller. No lock needed. s.state = streamReadDone diff --git a/vendor/google.golang.org/grpc/internal/transport/transport.go b/vendor/google.golang.org/grpc/internal/transport/transport.go index 6dfae39849e..5fc901e5cf1 100644 --- a/vendor/google.golang.org/grpc/internal/transport/transport.go +++ b/vendor/google.golang.org/grpc/internal/transport/transport.go @@ -30,11 +30,14 @@ import ( "sync" "sync/atomic" "time" + "unsafe" "golang.org/x/net/http2" "google.golang.org/grpc/codes" "google.golang.org/grpc/credentials" "google.golang.org/grpc/internal/channelz" + "google.golang.org/grpc/internal/envconfig" + imem "google.golang.org/grpc/internal/mem" "google.golang.org/grpc/internal/transport/internal" "google.golang.org/grpc/keepalive" "google.golang.org/grpc/mem" @@ -45,7 +48,30 @@ import ( "google.golang.org/grpc/tap" ) -const logLevel = 2 +const ( + logLevel = 2 + // recvMsgSize estimates the memory overhead of a recvMsg in the backlog. + // It accounts for the recvMsg struct itself and the slice header of the + // underlying buffer's data. + recvMsgSize = int(unsafe.Sizeof(recvMsg{}) + unsafe.Sizeof([]byte{})) + + // utilizationFactor controls when we consider memory utilization acceptable. + // When backlogHeapSize / payloadSize <= utilizationFactor (meaning at least + // 50% of the heap memory is actual payload data), compaction is skipped. + utilizationFactor = 2 +) + +var ( + // compactionThreshold is approx 57KB (on 64-bit systems). It allows + // accumulating up to 1024 1-byte payloads before triggering compaction. + // + // Because individual payloads <= 1024 bytes are allocated on the heap + // outside mem.BufferPool, waiting for at least 1024 bytes to accumulate + // ensures that compaction coalesces those small heap allocations into a + // single large buffer from mem.BufferPool, enabling buffer reuse while + // avoiding frequent copying for small bursts of frames. + compactionThreshold = imem.BufferPoolingThreshold * (recvMsgSize + 1) +) func init() { internal.TimeNowFunc = func() int64 { return time.Now().UnixNano() } @@ -71,23 +97,31 @@ type recvBuffer struct { c chan recvMsg mu sync.Mutex backlog []recvMsg - err error + // uncompactedSuffixLen tracks the number of consecutive data messages at + // the tail of backlog that have not been compacted. + uncompactedSuffixLen int + // uncompactedBytes tracks the total payload bytes across the trailing + // uncompactedSuffixLen messages. + uncompactedBytes int + err error + bufPool mem.BufferPool } // init allows a recvBuffer to be initialized in-place, which is useful // for resetting a buffer or for avoiding a heap allocation when the buffer // is embedded in another struct. -func (b *recvBuffer) init() { +func (b *recvBuffer) init(pool mem.BufferPool) { b.c = make(chan recvMsg, 1) + b.bufPool = pool } func (b *recvBuffer) put(r recvMsg) { b.mu.Lock() + defer b.mu.Unlock() if b.err != nil { // drop the buffer on the floor. Since b.err is not nil, any subsequent reads // will always return an error, making this buffer inaccessible. r.buffer.Free() - b.mu.Unlock() // An error had occurred earlier, don't accept more // data or errors. return @@ -96,13 +130,70 @@ func (b *recvBuffer) put(r recvMsg) { if len(b.backlog) == 0 { select { case b.c <- r: - b.mu.Unlock() return default: } } b.backlog = append(b.backlog, r) - b.mu.Unlock() + b.compactBacklogLocked(r) +} + +func (b *recvBuffer) compactBacklogLocked(r recvMsg) { + if !envconfig.EnableReceiveBufferCompaction { + return + } + if r.buffer == nil { + b.uncompactedBytes = 0 + b.uncompactedSuffixLen = 0 + return + } + + b.uncompactedSuffixLen++ + b.uncompactedBytes += r.buffer.Len() + backlogHeapSize := b.uncompactedSuffixLen*recvMsgSize + b.uncompactedBytes + + // If the memory overhead is less than 50% of the heap usage (e.g., because + // a large DATA frame arrived), the average message size in the suffix is + // large enough that memory bloat is not a concern. Reset suffix tracking. + if backlogHeapSize <= utilizationFactor*b.uncompactedBytes { + b.uncompactedBytes = 0 + b.uncompactedSuffixLen = 0 + return + } + // Avoid compacting too frequently for short bursts of small frames. + // Wait until we have accumulated at least ~1024 small messages (~57 KB). + if backlogHeapSize <= compactionThreshold { + // Still can accumulate more payloads. + return + } + + // Since the memory utilization is less than 50%, the average payload size + // of each recvMsg must be less than recvMsgSize (approx 56 bytes). + // In the worst case for bytes copied (where the average payload is just + // below recvMsgSize), compaction will occur once every: + // compactionThreshold / (recvMsgSize + avg_payload) = ~520 messages, + // copying ~29KB of data. + + start := 0 + newBuf := b.bufPool.Get(b.uncompactedBytes) + startIdx := len(b.backlog) - b.uncompactedSuffixLen + + for i := startIdx; i < len(b.backlog); i++ { + m := b.backlog[i] + b.backlog[i] = recvMsg{} + start += copy((*newBuf)[start:], m.buffer.ReadOnlyData()) + m.buffer.Free() + } + b.backlog[startIdx] = recvMsg{ + buffer: mem.NewBuffer(newBuf, b.bufPool), + } + b.backlog = b.backlog[:startIdx+1] + // After compaction, the suffix is replaced with a single message containing + // the combined payload. The new utilization is close to 1.0 (overhead of + // one recvMsg relative to the large compacted payload), which is well + // below the utilization factor of 2. + b.uncompactedBytes = 0 + b.uncompactedSuffixLen = 0 } func (b *recvBuffer) load() { @@ -110,6 +201,13 @@ func (b *recvBuffer) load() { if len(b.backlog) > 0 { select { case b.c <- b.backlog[0]: + // backlog[0] is only part of the tracked uncompacted suffix if the + // entire backlog currently consists of the suffix. If an earlier + // compaction or reset occurred, backlog[0] is already compacted. + if envconfig.EnableReceiveBufferCompaction && b.uncompactedSuffixLen == len(b.backlog) { + b.uncompactedSuffixLen-- + b.uncompactedBytes -= b.backlog[0].buffer.Len() + } b.backlog[0] = recvMsg{} b.backlog = b.backlog[1:] default: @@ -594,8 +692,6 @@ type CallHdr struct { PreviousAttempts int // value of grpc-previous-rpc-attempts header to set - DoneFunc func() // called when the stream is finished - // Authority is used to explicitly override the `:authority` header. // // This value comes from one of two sources: diff --git a/vendor/google.golang.org/grpc/mem/buffer_pool.go b/vendor/google.golang.org/grpc/mem/buffer_pool.go index 3b02b909164..aa121379fd5 100644 --- a/vendor/google.golang.org/grpc/mem/buffer_pool.go +++ b/vendor/google.golang.org/grpc/mem/buffer_pool.go @@ -59,10 +59,6 @@ func init() { internal.SetDefaultBufferPool = func(pool BufferPool) { defaultBufferPool = pool } - - internal.SetBufferPoolingThresholdForTesting = func(threshold int) { - bufferPoolingThreshold = threshold - } } // DefaultBufferPool returns the current default buffer pool. It is a BufferPool diff --git a/vendor/google.golang.org/grpc/mem/buffers.go b/vendor/google.golang.org/grpc/mem/buffers.go index 2b410b16ebd..9b355d4465b 100644 --- a/vendor/google.golang.org/grpc/mem/buffers.go +++ b/vendor/google.golang.org/grpc/mem/buffers.go @@ -29,6 +29,8 @@ import ( "fmt" "sync" "sync/atomic" + + "google.golang.org/grpc/internal/mem" ) // A Buffer represents a reference counted piece of data (in bytes) that can be @@ -63,8 +65,6 @@ type Buffer interface { } var ( - bufferPoolingThreshold = 1 << 10 - bufferObjectPool = sync.Pool{New: func() any { return new(buffer) }} ) @@ -72,7 +72,7 @@ var ( // equal to the threshold for buffer pooling. This is used to determine whether // to pool buffers or allocate them directly. func IsBelowBufferPoolingThreshold(size int) bool { - return size <= bufferPoolingThreshold + return size <= mem.BufferPoolingThreshold } type buffer struct { diff --git a/vendor/google.golang.org/grpc/stream.go b/vendor/google.golang.org/grpc/stream.go index 4aac644a833..51aff85dfba 100644 --- a/vendor/google.golang.org/grpc/stream.go +++ b/vendor/google.golang.org/grpc/stream.go @@ -201,6 +201,15 @@ func endOfClientStream(cc *ClientConn, err error, opts ...CallOption) { } } +// clientInterceptor is structurally identical to the ClientInterceptor defined +// in internal/xds/httpfilter/httpfilter.go. It is defined locally here so that +// we can type-assert the generic Interceptor field in iresolver.RPCConfig +// without introducing a dependency on xDS packages. +type clientInterceptor interface { + NewStream(ctx context.Context, ri iresolver.RPCInfo, newStream func(ctx context.Context, opts ...CallOption) (ClientStream, error), opts ...CallOption) (ClientStream, error) + Close() +} + func newClientStream(ctx context.Context, desc *StreamDesc, cc *ClientConn, method string, opts ...CallOption) (_ ClientStream, err error) { if channelz.IsOn() { cc.incrCallsStarted() @@ -244,8 +253,11 @@ func newClientStream(ctx context.Context, desc *StreamDesc, cc *ClientConn, meth mc := &emptyMethodConfig var onCommit func() - newStream := func(ctx context.Context, done func()) (iresolver.ClientStream, error) { - return newClientStreamWithParams(ctx, desc, cc, method, mc, onCommit, done, nameResolutionDelayed, opts...) + newStream := func(ctx context.Context, filterOpts ...CallOption) (ClientStream, error) { + if filterOpts != nil { + opts = combine(opts, filterOpts) + } + return newClientStreamWithParams(ctx, desc, cc, method, mc, onCommit, nameResolutionDelayed, opts...) } rpcInfo := iresolver.RPCInfo{Context: ctx, Method: method} @@ -270,20 +282,24 @@ func newClientStream(ctx context.Context, desc *StreamDesc, cc *ClientConn, meth if rpcConfig.Interceptor != nil { rpcInfo.Context = nil ns := newStream - newStream = func(ctx context.Context, done func()) (iresolver.ClientStream, error) { - cs, err := rpcConfig.Interceptor.NewStream(ctx, rpcInfo, done, ns) - if err != nil { - return nil, toRPCErr(err) + if interceptor, ok := rpcConfig.Interceptor.(clientInterceptor); ok { + newStream = func(ctx context.Context, filterOpts ...CallOption) (ClientStream, error) { + cs, err := interceptor.NewStream(ctx, rpcInfo, ns, filterOpts...) + if err != nil { + return nil, toRPCErr(err) + } + return cs, nil } - return cs, nil + } else { + return nil, status.Errorf(codes.Internal, "invalid client interceptor type %T", rpcConfig.Interceptor) } } } - return newStream(ctx, func() {}) + return newStream(ctx) } -func newClientStreamWithParams(ctx context.Context, desc *StreamDesc, cc *ClientConn, method string, mc *serviceconfig.MethodConfig, onCommit, doneFunc func(), nameResolutionDelayed bool, opts ...CallOption) (_ iresolver.ClientStream, err error) { +func newClientStreamWithParams(ctx context.Context, desc *StreamDesc, cc *ClientConn, method string, mc *serviceconfig.MethodConfig, onCommit func(), nameResolutionDelayed bool, opts ...CallOption) (_ ClientStream, err error) { callInfo := defaultCallInfo() if mc.WaitForReady != nil { callInfo.failFast = !*mc.WaitForReady @@ -321,7 +337,6 @@ func newClientStreamWithParams(ctx context.Context, desc *StreamDesc, cc *Client Host: cc.authority, Method: method, ContentSubtype: callInfo.contentSubtype, - DoneFunc: doneFunc, Authority: callInfo.authority, } if allowed := callInfo.acceptedResponseCompressors; len(allowed) > 0 { diff --git a/vendor/google.golang.org/grpc/version.go b/vendor/google.golang.org/grpc/version.go index 53c737feeb9..835dc07fdc5 100644 --- a/vendor/google.golang.org/grpc/version.go +++ b/vendor/google.golang.org/grpc/version.go @@ -19,4 +19,4 @@ package grpc // Version is the current grpc version. -const Version = "1.82.1" +const Version = "1.83.2" diff --git a/vendor/modules.txt b/vendor/modules.txt index 5af64de5328..579b7f73213 100644 --- a/vendor/modules.txt +++ b/vendor/modules.txt @@ -587,7 +587,7 @@ go.yaml.in/yaml/v2 # go.yaml.in/yaml/v3 v3.0.5 ## explicit; go 1.16 go.yaml.in/yaml/v3 -# golang.org/x/crypto v0.54.0 +# golang.org/x/crypto v0.55.0 ## explicit; go 1.25.0 golang.org/x/crypto/pbkdf2 # golang.org/x/mod v0.38.0 @@ -595,7 +595,7 @@ golang.org/x/crypto/pbkdf2 golang.org/x/mod/internal/lazyregexp golang.org/x/mod/module golang.org/x/mod/semver -# golang.org/x/net v0.57.0 +# golang.org/x/net v0.58.0 ## explicit; go 1.25.0 golang.org/x/net/context golang.org/x/net/http/httpguts @@ -626,7 +626,7 @@ golang.org/x/sys/windows/registry # golang.org/x/term v0.45.0 ## explicit; go 1.25.0 golang.org/x/term -# golang.org/x/text v0.40.0 +# golang.org/x/text v0.41.0 ## explicit; go 1.25.0 golang.org/x/text/cases golang.org/x/text/internal @@ -677,7 +677,7 @@ google.golang.org/genproto/googleapis/api/httpbody ## explicit; go 1.25.0 google.golang.org/genproto/googleapis/rpc/errdetails google.golang.org/genproto/googleapis/rpc/status -# google.golang.org/grpc v1.82.1 +# google.golang.org/grpc v1.83.2 ## explicit; go 1.25.0 google.golang.org/grpc google.golang.org/grpc/attributes From 21aa681397ebda2df20b00fca73e9c29958f940f Mon Sep 17 00:00:00 2001 From: Aditya Arora Date: Mon, 28 Sep 2026 16:06:07 -0400 Subject: [PATCH 2/2] chore: revert cert manager changes --- third_party/cert-manager/01-cert-manager.yaml | 77 ---------------- .../cert-manager/02-trust-manager.yaml | 90 ++++++++----------- 2 files changed, 38 insertions(+), 129 deletions(-) diff --git a/third_party/cert-manager/01-cert-manager.yaml b/third_party/cert-manager/01-cert-manager.yaml index 32267cd7df2..c62f2273daf 100644 --- a/third_party/cert-manager/01-cert-manager.yaml +++ b/third_party/cert-manager/01-cert-manager.yaml @@ -14,7 +14,6 @@ metadata: app.kubernetes.io/version: "v1.16.3" app.kubernetes.io/managed-by: Helm helm.sh/chart: cert-manager-v1.16.3 - --- # Source: cert-manager/templates/serviceaccount.yaml apiVersion: v1 @@ -31,7 +30,6 @@ metadata: app.kubernetes.io/version: "v1.16.3" app.kubernetes.io/managed-by: Helm helm.sh/chart: cert-manager-v1.16.3 - --- # Source: cert-manager/templates/webhook-serviceaccount.yaml apiVersion: v1 @@ -48,7 +46,6 @@ metadata: app.kubernetes.io/version: "v1.16.3" app.kubernetes.io/managed-by: Helm helm.sh/chart: cert-manager-v1.16.3 - --- # Source: cert-manager/templates/crds.yaml # @@ -373,8 +370,6 @@ spec: storage: true # END crd - - --- # Source: cert-manager/templates/crds.yaml # START crd @@ -1146,8 +1141,6 @@ spec: storage: true # END crd - - --- # Source: cert-manager/templates/crds.yaml # START crd @@ -4357,8 +4350,6 @@ spec: status: {} # END crd - - --- # Source: cert-manager/templates/crds.yaml # START crd @@ -8088,8 +8079,6 @@ spec: storage: true # END crd - - --- # Source: cert-manager/templates/crds.yaml # START crd @@ -11819,8 +11808,6 @@ spec: storage: true # END crd - - --- # Source: cert-manager/templates/crds.yaml # START crd @@ -12092,7 +12079,6 @@ spec: storage: true # END crd - --- # Source: cert-manager/templates/cainjector-rbac.yaml apiVersion: rbac.authorization.k8s.io/v1 @@ -12126,7 +12112,6 @@ rules: - apiGroups: ["apiextensions.k8s.io"] resources: ["customresourcedefinitions"] verbs: ["get", "list", "watch", "update", "patch"] - --- # Source: cert-manager/templates/rbac.yaml # Issuer controller role @@ -12155,7 +12140,6 @@ rules: - apiGroups: [""] resources: ["events"] verbs: ["create", "patch"] - --- # Source: cert-manager/templates/rbac.yaml # ClusterIssuer controller role @@ -12184,8 +12168,6 @@ rules: - apiGroups: [""] resources: ["events"] verbs: ["create", "patch"] - - --- # Source: cert-manager/templates/rbac.yaml # Certificates controller role @@ -12223,8 +12205,6 @@ rules: - apiGroups: [""] resources: ["events"] verbs: ["create", "patch"] - - --- # Source: cert-manager/templates/rbac.yaml # Orders controller role @@ -12265,8 +12245,6 @@ rules: - apiGroups: [""] resources: ["events"] verbs: ["create", "patch"] - - --- # Source: cert-manager/templates/rbac.yaml # Challenges controller role @@ -12329,8 +12307,6 @@ rules: - apiGroups: [""] resources: ["secrets"] verbs: ["get", "list", "watch"] - - --- # Source: cert-manager/templates/rbac.yaml # ingress-shim controller role @@ -12371,8 +12347,6 @@ rules: - apiGroups: [""] resources: ["events"] verbs: ["create", "patch"] - - --- # Source: cert-manager/templates/rbac.yaml apiVersion: rbac.authorization.k8s.io/v1 @@ -12392,7 +12366,6 @@ rules: - apiGroups: ["cert-manager.io"] resources: ["clusterissuers"] verbs: ["get", "list", "watch"] - --- # Source: cert-manager/templates/rbac.yaml apiVersion: rbac.authorization.k8s.io/v1 @@ -12418,9 +12391,6 @@ rules: - apiGroups: ["acme.cert-manager.io"] resources: ["challenges", "orders"] verbs: ["get", "list", "watch"] - - - --- # Source: cert-manager/templates/rbac.yaml apiVersion: rbac.authorization.k8s.io/v1 @@ -12447,8 +12417,6 @@ rules: - apiGroups: ["acme.cert-manager.io"] resources: ["challenges", "orders"] verbs: ["create", "delete", "deletecollection", "patch", "update"] - - --- # Source: cert-manager/templates/rbac.yaml # Permission to approve CertificateRequests referencing cert-manager.io Issuers and ClusterIssuers @@ -12471,8 +12439,6 @@ rules: resourceNames: - "issuers.cert-manager.io/*" - "clusterissuers.cert-manager.io/*" - - --- # Source: cert-manager/templates/rbac.yaml # Permission to: @@ -12504,8 +12470,6 @@ rules: - apiGroups: ["authorization.k8s.io"] resources: ["subjectaccessreviews"] verbs: ["create"] - - --- # Source: cert-manager/templates/webhook-rbac.yaml apiVersion: rbac.authorization.k8s.io/v1 @@ -12524,7 +12488,6 @@ rules: - apiGroups: ["authorization.k8s.io"] resources: ["subjectaccessreviews"] verbs: ["create"] - --- # Source: cert-manager/templates/cainjector-rbac.yaml apiVersion: rbac.authorization.k8s.io/v1 @@ -12547,8 +12510,6 @@ subjects: - name: cert-manager-cainjector namespace: cert-manager kind: ServiceAccount - - --- # Source: cert-manager/templates/rbac.yaml apiVersion: rbac.authorization.k8s.io/v1 @@ -12571,8 +12532,6 @@ subjects: - name: cert-manager namespace: cert-manager kind: ServiceAccount - - --- # Source: cert-manager/templates/rbac.yaml apiVersion: rbac.authorization.k8s.io/v1 @@ -12595,8 +12554,6 @@ subjects: - name: cert-manager namespace: cert-manager kind: ServiceAccount - - --- # Source: cert-manager/templates/rbac.yaml apiVersion: rbac.authorization.k8s.io/v1 @@ -12619,8 +12576,6 @@ subjects: - name: cert-manager namespace: cert-manager kind: ServiceAccount - - --- # Source: cert-manager/templates/rbac.yaml apiVersion: rbac.authorization.k8s.io/v1 @@ -12643,8 +12598,6 @@ subjects: - name: cert-manager namespace: cert-manager kind: ServiceAccount - - --- # Source: cert-manager/templates/rbac.yaml apiVersion: rbac.authorization.k8s.io/v1 @@ -12667,8 +12620,6 @@ subjects: - name: cert-manager namespace: cert-manager kind: ServiceAccount - - --- # Source: cert-manager/templates/rbac.yaml apiVersion: rbac.authorization.k8s.io/v1 @@ -12691,7 +12642,6 @@ subjects: - name: cert-manager namespace: cert-manager kind: ServiceAccount - --- # Source: cert-manager/templates/rbac.yaml apiVersion: rbac.authorization.k8s.io/v1 @@ -12714,8 +12664,6 @@ subjects: - name: cert-manager namespace: cert-manager kind: ServiceAccount - - --- # Source: cert-manager/templates/rbac.yaml apiVersion: rbac.authorization.k8s.io/v1 @@ -12738,7 +12686,6 @@ subjects: - name: cert-manager namespace: cert-manager kind: ServiceAccount - --- # Source: cert-manager/templates/webhook-rbac.yaml apiVersion: rbac.authorization.k8s.io/v1 @@ -12761,7 +12708,6 @@ subjects: - kind: ServiceAccount name: cert-manager-webhook namespace: cert-manager - --- # Source: cert-manager/templates/cainjector-rbac.yaml # leader election rules @@ -12791,8 +12737,6 @@ rules: - apiGroups: ["coordination.k8s.io"] resources: ["leases"] verbs: ["create"] - - --- # Source: cert-manager/templates/rbac.yaml apiVersion: rbac.authorization.k8s.io/v1 @@ -12816,8 +12760,6 @@ rules: - apiGroups: ["coordination.k8s.io"] resources: ["leases"] verbs: ["create"] - - --- # Source: cert-manager/templates/rbac.yaml apiVersion: rbac.authorization.k8s.io/v1 @@ -12838,8 +12780,6 @@ rules: resources: ["serviceaccounts/token"] resourceNames: ["cert-manager"] verbs: ["create"] - - --- # Source: cert-manager/templates/webhook-rbac.yaml apiVersion: rbac.authorization.k8s.io/v1 @@ -12865,7 +12805,6 @@ rules: - apiGroups: [""] resources: ["secrets"] verbs: ["create"] - --- # Source: cert-manager/templates/cainjector-rbac.yaml # grant cert-manager permission to manage the leaderelection configmap in the @@ -12891,7 +12830,6 @@ subjects: - kind: ServiceAccount name: cert-manager-cainjector namespace: cert-manager - --- # Source: cert-manager/templates/rbac.yaml # grant cert-manager permission to manage the leaderelection configmap in the @@ -12917,8 +12855,6 @@ subjects: - kind: ServiceAccount name: cert-manager namespace: cert-manager - - --- # Source: cert-manager/templates/rbac.yaml # grant cert-manager permission to create tokens for the serviceaccount @@ -12943,8 +12879,6 @@ subjects: - kind: ServiceAccount name: cert-manager namespace: cert-manager - - --- # Source: cert-manager/templates/webhook-rbac.yaml apiVersion: rbac.authorization.k8s.io/v1 @@ -12968,8 +12902,6 @@ subjects: - kind: ServiceAccount name: cert-manager-webhook namespace: cert-manager - - --- # Source: cert-manager/templates/cainjector-service.yaml apiVersion: v1 @@ -12995,7 +12927,6 @@ spec: app.kubernetes.io/name: cainjector app.kubernetes.io/instance: cert-manager app.kubernetes.io/component: "cainjector" - --- # Source: cert-manager/templates/service.yaml apiVersion: v1 @@ -13022,7 +12953,6 @@ spec: app.kubernetes.io/name: cert-manager app.kubernetes.io/instance: cert-manager app.kubernetes.io/component: "controller" - --- # Source: cert-manager/templates/webhook-service.yaml apiVersion: v1 @@ -13053,7 +12983,6 @@ spec: app.kubernetes.io/name: webhook app.kubernetes.io/instance: cert-manager app.kubernetes.io/component: "webhook" - --- # Source: cert-manager/templates/cainjector-deployment.yaml apiVersion: apps/v1 @@ -13121,7 +13050,6 @@ spec: readOnlyRootFilesystem: true nodeSelector: kubernetes.io/os: linux - --- # Source: cert-manager/templates/deployment.yaml apiVersion: apps/v1 @@ -13307,7 +13235,6 @@ spec: fieldPath: metadata.namespace nodeSelector: kubernetes.io/os: linux - --- # Source: cert-manager/templates/webhook-mutating-webhook.yaml apiVersion: admissionregistration.k8s.io/v1 @@ -13417,7 +13344,6 @@ metadata: app.kubernetes.io/version: "v1.16.3" app.kubernetes.io/managed-by: Helm helm.sh/chart: cert-manager-v1.16.3 - --- # Source: cert-manager/templates/startupapicheck-rbac.yaml # create certificate role @@ -13442,7 +13368,6 @@ rules: - apiGroups: ["cert-manager.io"] resources: ["certificaterequests"] verbs: ["create"] - --- # Source: cert-manager/templates/startupapicheck-rbac.yaml apiVersion: rbac.authorization.k8s.io/v1 @@ -13470,7 +13395,6 @@ subjects: - kind: ServiceAccount name: cert-manager-startupapicheck namespace: cert-manager - --- # Source: cert-manager/templates/startupapicheck-job.yaml apiVersion: batch/v1 @@ -13532,4 +13456,3 @@ spec: fieldPath: metadata.namespace nodeSelector: kubernetes.io/os: linux - diff --git a/third_party/cert-manager/02-trust-manager.yaml b/third_party/cert-manager/02-trust-manager.yaml index d55f5b77f8a..8cce328328c 100644 --- a/third_party/cert-manager/02-trust-manager.yaml +++ b/third_party/cert-manager/02-trust-manager.yaml @@ -11,7 +11,6 @@ metadata: app.kubernetes.io/instance: cert-manager app.kubernetes.io/version: "v0.12.0" app.kubernetes.io/managed-by: Helm - --- # Source: trust-manager/templates/crd-trust.cert-manager.io_bundles.yaml apiVersion: apiextensions.k8s.io/v1 @@ -458,7 +457,6 @@ subjects: - kind: ServiceAccount name: trust-manager namespace: cert-manager - --- # Source: trust-manager/templates/role.yaml kind: Role @@ -481,7 +479,6 @@ rules: - "get" - "list" - "watch" - --- # Source: trust-manager/templates/role.yaml kind: Role @@ -506,7 +503,6 @@ rules: - "update" - "watch" - "list" - --- # Source: trust-manager/templates/rolebinding.yaml kind: RoleBinding @@ -528,7 +524,6 @@ subjects: - kind: ServiceAccount name: trust-manager namespace: cert-manager - --- # Source: trust-manager/templates/rolebinding.yaml kind: RoleBinding @@ -550,7 +545,6 @@ subjects: - kind: ServiceAccount name: trust-manager namespace: cert-manager - --- # Source: trust-manager/templates/metrics-service.yaml apiVersion: v1 @@ -574,7 +568,6 @@ spec: name: metrics selector: app: trust-manager - --- # Source: trust-manager/templates/webhook.yaml apiVersion: v1 @@ -598,8 +591,6 @@ spec: name: webhook selector: app: trust-manager - - --- # Source: trust-manager/templates/deployment.yaml apiVersion: apps/v1 @@ -706,8 +697,44 @@ spec: secret: defaultMode: 420 secretName: trust-manager-tls - - +--- +# Source: trust-manager/templates/certificate.yaml +apiVersion: cert-manager.io/v1 +kind: Certificate +metadata: + name: trust-manager + namespace: cert-manager + labels: + app.kubernetes.io/name: trust-manager + helm.sh/chart: trust-manager-v0.12.0 + app.kubernetes.io/instance: cert-manager + app.kubernetes.io/version: "v0.12.0" + app.kubernetes.io/managed-by: Helm +spec: + commonName: "trust-manager.cert-manager.svc" + dnsNames: + - "trust-manager.cert-manager.svc" + secretName: trust-manager-tls + revisionHistoryLimit: 1 + issuerRef: + name: trust-manager + kind: Issuer + group: cert-manager.io +--- +# Source: trust-manager/templates/certificate.yaml +apiVersion: cert-manager.io/v1 +kind: Issuer +metadata: + name: trust-manager + namespace: cert-manager + labels: + app.kubernetes.io/name: trust-manager + helm.sh/chart: trust-manager-v0.12.0 + app.kubernetes.io/instance: cert-manager + app.kubernetes.io/version: "v0.12.0" + app.kubernetes.io/managed-by: Helm +spec: + selfSigned: {} --- # Source: trust-manager/templates/webhook.yaml apiVersion: admissionregistration.k8s.io/v1 @@ -748,44 +775,3 @@ webhooks: name: trust-manager namespace: cert-manager path: /validate-trust-cert-manager-io-v1alpha1-bundle - ---- -# Source: trust-manager/templates/certificate.yaml -apiVersion: cert-manager.io/v1 -kind: Certificate -metadata: - name: trust-manager - namespace: cert-manager - labels: - app.kubernetes.io/name: trust-manager - helm.sh/chart: trust-manager-v0.12.0 - app.kubernetes.io/instance: cert-manager - app.kubernetes.io/version: "v0.12.0" - app.kubernetes.io/managed-by: Helm -spec: - commonName: "trust-manager.cert-manager.svc" - dnsNames: - - "trust-manager.cert-manager.svc" - secretName: trust-manager-tls - revisionHistoryLimit: 1 - issuerRef: - name: trust-manager - kind: Issuer - group: cert-manager.io - - ---- -# Source: trust-manager/templates/certificate.yaml -apiVersion: cert-manager.io/v1 -kind: Issuer -metadata: - name: trust-manager - namespace: cert-manager - labels: - app.kubernetes.io/name: trust-manager - helm.sh/chart: trust-manager-v0.12.0 - app.kubernetes.io/instance: cert-manager - app.kubernetes.io/version: "v0.12.0" - app.kubernetes.io/managed-by: Helm -spec: - selfSigned: {}