[wip] Prevent duplicate hosts in Ingress rules when using ACME #16312
+173
−136
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
The basic idea is that we don't create ingress rules with multiple hosts for external visibility, as we need to be able merge ACME rules into these hosts.
I don't really like that though as it puts the knowledge of exactly 1 host per external rule in two places (rule creation and ACME rule merging).
Another alternative would be that we accept the incorrect rule merging with multiple hosts that we had before:
This would result in 4 possible routes in the Ingress:
awith pathacme-of-a- correctbwith pathacme-of-a- wrongawith pathacme-of-b- wrongbwith pathacme-of-b- correctThis won't be a problem in practice though as the ACME server would not try to do a request to host
awith pathacme-of-b.This would be a simple loop over existing rules, check if it contains a matching host and merge it inside there (while still preventing double duplicate rules that we had before #16259 )
Let me know what you think of this approach in general.
/cc @dprotaso
Proposed Changes
Release Note