Skip to content

Commit 98c545c

Browse files
authored
fix: revert default secret lifetime to 1 day (#628)
1 parent 0a35f98 commit 98c545c

File tree

3 files changed

+8
-8
lines changed

3 files changed

+8
-8
lines changed

rust/crd/src/lib.rs

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1086,7 +1086,7 @@ pub struct NameNodeConfig {
10861086
}
10871087

10881088
impl NameNodeConfigFragment {
1089-
const DEFAULT_NAME_NODE_SECRET_LIFETIME: Duration = Duration::from_days_unchecked(7);
1089+
const DEFAULT_NAME_NODE_SECRET_LIFETIME: Duration = Duration::from_days_unchecked(1);
10901090

10911091
pub fn default_config(cluster_name: &str, role: &HdfsRole) -> Self {
10921092
Self {
@@ -1223,7 +1223,7 @@ pub struct DataNodeConfig {
12231223
}
12241224

12251225
impl DataNodeConfigFragment {
1226-
const DEFAULT_DATA_NODE_SECRET_LIFETIME: Duration = Duration::from_days_unchecked(7);
1226+
const DEFAULT_DATA_NODE_SECRET_LIFETIME: Duration = Duration::from_days_unchecked(1);
12271227

12281228
pub fn default_config(cluster_name: &str, role: &HdfsRole) -> Self {
12291229
Self {
@@ -1342,7 +1342,7 @@ pub struct JournalNodeConfig {
13421342
}
13431343

13441344
impl JournalNodeConfigFragment {
1345-
const DEFAULT_JOURNAL_NODE_SECRET_LIFETIME: Duration = Duration::from_days_unchecked(7);
1345+
const DEFAULT_JOURNAL_NODE_SECRET_LIFETIME: Duration = Duration::from_days_unchecked(1);
13461346
pub fn default_config(cluster_name: &str, role: &HdfsRole) -> Self {
13471347
Self {
13481348
resources: ResourcesFragment {

tests/templates/kuttl/kerberos/20-assert.yaml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -31,6 +31,6 @@ apiVersion: kuttl.dev/v1beta1
3131
kind: TestAssert
3232
timeout: 600
3333
commands:
34-
- script: kubectl -n $NAMESPACE get sts/hdfs-namenode-default -o yaml | yq -e '.spec.template.spec.volumes.[] | select(.name == "tls" and .ephemeral.volumeClaimTemplate.metadata.annotations."secrets.stackable.tech/backend.autotls.cert.lifetime" == "7d")'
35-
- script: kubectl -n $NAMESPACE get sts/hdfs-datanode-default -o yaml | yq -e '.spec.template.spec.volumes.[] | select(.name == "tls" and .ephemeral.volumeClaimTemplate.metadata.annotations."secrets.stackable.tech/backend.autotls.cert.lifetime" == "1d")'
36-
- script: kubectl -n $NAMESPACE get sts/hdfs-journalnode-default -o yaml | yq -e '.spec.template.spec.volumes.[] | select(.name == "tls" and .ephemeral.volumeClaimTemplate.metadata.annotations."secrets.stackable.tech/backend.autotls.cert.lifetime" == "2d")'
34+
- script: kubectl -n $NAMESPACE get sts/hdfs-namenode-default -o yaml | yq -e '.spec.template.spec.volumes.[] | select(.name == "tls" and .ephemeral.volumeClaimTemplate.metadata.annotations."secrets.stackable.tech/backend.autotls.cert.lifetime" == "1d")'
35+
- script: kubectl -n $NAMESPACE get sts/hdfs-datanode-default -o yaml | yq -e '.spec.template.spec.volumes.[] | select(.name == "tls" and .ephemeral.volumeClaimTemplate.metadata.annotations."secrets.stackable.tech/backend.autotls.cert.lifetime" == "2d")'
36+
- script: kubectl -n $NAMESPACE get sts/hdfs-journalnode-default -o yaml | yq -e '.spec.template.spec.volumes.[] | select(.name == "tls" and .ephemeral.volumeClaimTemplate.metadata.annotations."secrets.stackable.tech/backend.autotls.cert.lifetime" == "3d")'

tests/templates/kuttl/kerberos/20-install-hdfs.txt.j2

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -44,7 +44,7 @@ spec:
4444
replicas: 2
4545
dataNodes:
4646
config:
47-
requestedSecretLifetime: 1d
47+
requestedSecretLifetime: 2d
4848
logging:
4949
enableVectorAgent: {{ lookup('env', 'VECTOR_AGGREGATOR') | length > 0 }}
5050
roleGroups:
@@ -58,4 +58,4 @@ spec:
5858
default:
5959
replicas: 3
6060
config:
61-
requestedSecretLifetime: 2d
61+
requestedSecretLifetime: 3d

0 commit comments

Comments
 (0)