fix(chart): roll dploy pod when secrets change - #44
Open
AYDEV-FR wants to merge 1 commit into
Open
Conversation
dploy reads OIDC_CLIENT_SECRET and the JWKS/issuer values from the chart-managed Secret as environment variables, which are injected once at container start. When Helm updates the Secret (e.g. rotating the OIDC client_secret) the Deployment pod template is unchanged, so Kubernetes never rolls the pod and the running process keeps the stale secret — silently breaking CTFd SSO with "invalid_client" at the token endpoint until a manual `kubectl rollout restart`. Add a checksum/secret pod annotation hashing the rendered Secret so any value change triggers a rollout automatically.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
dploy reads
OIDC_CLIENT_SECRET(andJWKS_URL/JWT_ISSUER/ issuer values) from the chart-managed*-secretsSecret as environment variables, injected once at container start.When Helm updates that Secret — e.g. rotating the OIDC
client_secret— the Deployment's pod template is unchanged, so Kubernetes does not roll the pod. The running process keeps the old secret and dploy fails the CTFd token exchange with:…silently, until someone runs
kubectl rollout restart deploy/dploy. Hit this in practice while rotating the dploy↔CTFd OIDC secret.Fix
Add a
checksum/secretpod annotation that hashes the renderedsecret.yaml, so any change to its values rolls the pod automatically (standard Helm pattern). Verified withhelm template:podAnnotationsauth.oidcClientSecretchanges → pod rollsNo behavioural change when secrets are unchanged.