Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions Makefile
Original file line number Diff line number Diff line change
Expand Up @@ -102,9 +102,9 @@ REPO?=tigera/operator
PACKAGE_NAME?=github.com/tigera/operator
LOCAL_USER_ID?=$(shell id -u $$USER)
# The project Go version.
GO_VERSION?=1.26.5
GO_VERSION?=1.27.0
# Version of Kubernetes to use for dependencies, tests, and kubectl.
K8S_VERSION?=v1.37.0-beta.0
K8S_VERSION?=v1.37.0
# The version of LLVM to use for the go-build image.
LLVM_VERSION?=21.1.8
# Calico toolchain versions and the calico/go-build image to use.
Expand Down
8 changes: 4 additions & 4 deletions pkg/controller/installation/core_controller.go
Original file line number Diff line number Diff line change
Expand Up @@ -1472,12 +1472,12 @@ func (r *ReconcileInstallation) Reconcile(ctx context.Context, request reconcile
if needsNamespaceMigration {
if err := r.namespaceMigration.Run(ctx, reqLogger); err != nil {
r.status.SetDegraded(operatorv1.ResourceMigrationError, "error migrating resources to calico-system", err, reqLogger)
// We should always requeue a migration problem. Don't return error
// to make sure we never start backing off retrying.
return reconcile.Result{Requeue: true}, nil
// Always requeue a migration problem. Returning nil rather than the
// error keeps the retry interval flat instead of escalating.
return reconcile.Result{RequeueAfter: utils.StandardRetry}, nil
}
// Requeue so we can update our resources (without the migration changes)
return reconcile.Result{Requeue: true}, nil
return reconcile.Result{RequeueAfter: utils.StandardRetry}, nil
} else if r.namespaceMigration.NeedCleanup() {
if err := r.namespaceMigration.CleanupMigration(ctx, reqLogger); err != nil {
r.status.SetDegraded(operatorv1.ResourceMigrationError, "error migrating resources to calico-system", err, reqLogger)
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -97,6 +97,7 @@ func (r *LogStorageConditions) Reconcile(ctx context.Context, request reconcile.
// The LogStorage was modified after we read it - our cached copy is stale. Requeue and
// recompute the conditions from the updated object instead of reporting an error.
reqLogger.V(3).Info("Conflict updating LogStorage status conditions, retrying")
//nolint:staticcheck // SA1019: a conflict wants a prompt retry, not a flat delay
return reconcile.Result{Requeue: true}, nil
}
log.WithValues("reason", err).Info("Failed to update LogStorage status conditions")
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -337,6 +337,7 @@ var _ = Describe("Monitor controller tests", func() {
},
},
HTTPConfigWithoutTLS: monitoringv1.HTTPConfigWithoutTLS{
//nolint:staticcheck // SA1019: mirrors the deprecated field monitor.go still renders
BearerTokenSecret: &corev1.SecretKeySelector{
LocalObjectReference: corev1.LocalObjectReference{
Name: monitor.TigeraExternalPrometheus,
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -279,9 +279,7 @@ func (r *ReconcilePacketCapture) Reconcile(ctx context.Context, request reconcil
}),
}

if pcPolicy := render.PacketCaptureAPIPolicy(packetCaptureApiCfg); pcPolicy != nil {
components = append(components, pcPolicy)
}
components = append(components, render.PacketCaptureAPIPolicy(packetCaptureApiCfg))

if err = imageset.ApplyImageSet(ctx, r.client, r.opts.Variant, components...); err != nil {
r.status.SetDegraded(operatorv1.ResourceUpdateError, "Error with images from ImageSet", err, reqLogger)
Expand Down
1 change: 1 addition & 0 deletions pkg/enterprise/render/logcollector/fluentbit_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -425,6 +425,7 @@ var _ = Describe("Tigera Secure Fluent Bit rendering tests", func() {
// fluentdDaemonSet field, using the fluentd-era container names.
cfg.LogCollector = &operatorv1.LogCollector{
Spec: operatorv1.LogCollectorSpec{
//nolint:staticcheck // SA1019: the deprecated alias is what this covers
FluentdDaemonSet: &operatorv1.FluentBitDaemonSet{
Spec: &operatorv1.FluentBitDaemonSetSpec{
Template: &operatorv1.FluentBitDaemonSetPodTemplateSpec{
Expand Down
1 change: 1 addition & 0 deletions pkg/enterprise/render/monitor/monitor.go
Original file line number Diff line number Diff line change
Expand Up @@ -1769,6 +1769,7 @@ func (mc *monitorComponent) externalServiceMonitor() (client.Object, bool) {
},
},
HTTPConfigWithoutTLS: monitoringv1.HTTPConfigWithoutTLS{
//nolint:staticcheck // SA1019: migrating to authorization changes the rendered ServiceMonitor
BearerTokenSecret: &ep.BearerTokenSecret,
},
},
Expand Down
52 changes: 26 additions & 26 deletions pkg/render/gateway/component.go
Original file line number Diff line number Diff line change
Expand Up @@ -194,33 +194,33 @@ func (c *gatewayComponent) backendAccess() (*rbacv1.Role, *rbacv1.RoleBinding) {
// own ServiceAccount, the identity that renders the gateway resources.
func (c *gatewayComponent) access(name, namespace string, rules []rbacv1.PolicyRule) (*rbacv1.Role, *rbacv1.RoleBinding) {
return &rbacv1.Role{
TypeMeta: metav1.TypeMeta{Kind: "Role", APIVersion: "rbac.authorization.k8s.io/v1"},
ObjectMeta: metav1.ObjectMeta{
Name: name,
Namespace: namespace,
Labels: map[string]string{GatewayLabel: c.cfg.ResourcePrefix},
},
Rules: rules,
}, &rbacv1.RoleBinding{
TypeMeta: metav1.TypeMeta{Kind: "RoleBinding", APIVersion: "rbac.authorization.k8s.io/v1"},
ObjectMeta: metav1.ObjectMeta{
Name: name,
Namespace: namespace,
Labels: map[string]string{GatewayLabel: c.cfg.ResourcePrefix},
},
RoleRef: rbacv1.RoleRef{
APIGroup: "rbac.authorization.k8s.io",
Kind: "Role",
Name: name,
},
Subjects: []rbacv1.Subject{
{
Kind: "ServiceAccount",
Name: common.OperatorServiceAccount(),
Namespace: common.OperatorNamespace(),
},
TypeMeta: metav1.TypeMeta{Kind: "Role", APIVersion: "rbac.authorization.k8s.io/v1"},
ObjectMeta: metav1.ObjectMeta{
Name: name,
Namespace: namespace,
Labels: map[string]string{GatewayLabel: c.cfg.ResourcePrefix},
},
Rules: rules,
}, &rbacv1.RoleBinding{
TypeMeta: metav1.TypeMeta{Kind: "RoleBinding", APIVersion: "rbac.authorization.k8s.io/v1"},
ObjectMeta: metav1.ObjectMeta{
Name: name,
Namespace: namespace,
Labels: map[string]string{GatewayLabel: c.cfg.ResourcePrefix},
},
RoleRef: rbacv1.RoleRef{
APIGroup: "rbac.authorization.k8s.io",
Kind: "Role",
Name: name,
},
Subjects: []rbacv1.Subject{
{
Kind: "ServiceAccount",
Name: common.OperatorServiceAccount(),
Namespace: common.OperatorNamespace(),
},
}
},
}
}

func (c *gatewayComponent) tlsSecret() *corev1.Secret {
Expand Down