fix(setup): converge the workload felis-config mirror on every apply path (#52)
felis setup's in-TUI applies (storage / connection / edge) refreshed only the control-namespace felis-config Secret; the workload-namespace mirror kept the render from the previous run's startup pass until the next setup or installer run. Found live: after 's -> Local' the minecraft copy still carried user_uploads_context = s3://felis-wizard-uploads while the control copy and both tomls were local. The 'configure email' path already overwrote both mirrors, so storage/connection were the odd ones out. Move the mirror refresh into applyFelisConfigSecret — the single choke point every apply path calls — best-effort with a warning, since a control-plane default install may not have the workload namespace at all. The smtp helper drops its now-duplicate felis-config block.
This commit is contained in:
2 files changed
+47
-19
No files matched your search
+7
-18
@@ -384,13 +384,13 @@ func applySMTPSecret(ctx context.Context, password string) error {
|
||||
}
|
||||
|
||||
// replicateSMTPToWorkloadNamespace refreshes the workload-namespace (minecraft)
|
||||
// copies of felis-smtp and felis-config after email is reconfigured. The
|
||||
// reaper's CronJob runs there and resolves both by local reference — a
|
||||
// secretKeyRef is namespace-local, and `felis setup` creates the felis-config
|
||||
// replica create-if-absent, so without this refresh a later SMTP change would
|
||||
// never reach the pre-reap warning emails. Deliberately OVERWRITES both: these
|
||||
// are mirrors of the control-namespace sources, and a stale mirror is exactly
|
||||
// the failure this closes.
|
||||
// copy of felis-smtp after email is reconfigured. The reaper's CronJob runs
|
||||
// there and resolves the password by local reference — a secretKeyRef is
|
||||
// namespace-local — so without this refresh a later SMTP change would never
|
||||
// reach the pre-reap warning emails. Deliberately OVERWRITES: this is a mirror
|
||||
// of the control-namespace source, and a stale mirror is exactly the failure
|
||||
// this closes. The felis-config mirror rides along in applyFelisConfigSecret,
|
||||
// which every apply path refreshes.
|
||||
func replicateSMTPToWorkloadNamespace(ctx context.Context, password string) error {
|
||||
cfg, err := config.Load(hostSetupConfigPath)
|
||||
if err != nil {
|
||||
@@ -407,16 +407,5 @@ func replicateSMTPToWorkloadNamespace(ctx context.Context, password string) erro
|
||||
if err := kubectlWithInput(ctx, smtpManifest, "-n", ns, "apply", "-f", "-"); err != nil {
|
||||
return fmt.Errorf("replicate %s to %s: %w", platform.SMTPSecretName, ns, err)
|
||||
}
|
||||
manifest, err := kubectlOutput(ctx,
|
||||
"-n", ns, "create", "secret", "generic", "felis-config",
|
||||
"--from-file=felis.toml="+podSetupConfigPath,
|
||||
"--dry-run=client", "-o", "yaml",
|
||||
)
|
||||
if err != nil {
|
||||
return fmt.Errorf("render felis-config for %s: %w", ns, err)
|
||||
}
|
||||
if err := kubectlWithInput(ctx, manifest, "-n", ns, "apply", "-f", "-"); err != nil {
|
||||
return fmt.Errorf("replicate felis-config to %s: %w", ns, err)
|
||||
}
|
||||
return nil
|
||||
}
|
||||
Reference in new issue
Block a user