Repository navigation
Fix certificate reload issue when files are moved - #210
Conversation
There was a problem hiding this comment.
Pull request overview
This PR fixes certificate reload issues in Kubernetes environments by adding support for file rename operations. Kubernetes updates certificates using a write-then-rename pattern that wasn't being detected by the existing InCloseWrite event watcher on Linux. The fix adds notify.InMovedTo to the watched events and includes comprehensive integration tests to verify the new behavior.
- Adds
notify.InMovedToevent to Linux file watcher to detect certificate updates via rename operations - Introduces integration tests for certificate reload via rename operations
- Increases test timeout to accommodate file system event processing delays
Reviewed changes
Copilot reviewed 2 out of 2 changed files in this pull request and generated 2 comments.
| File | Description |
|---|---|
| certs/event_linux.go | Adds notify.InMovedTo to the list of watched file system events for certificate files on Linux |
| certs/certificate2_test.go | Adds new test cases and helper function parameter to test certificate reload via rename operations, updates all existing test calls with the new parameter, and increases test timeout for reliability |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
ff18901 to
4ab686a
Compare
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 2 out of 2 changed files in this pull request and generated 2 comments.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 2 out of 2 changed files in this pull request and generated no new comments.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Certificates were not properly reloaded in Kubernetes, because it uses a slightly different method of replacing certificates:
/tmp/minio/certs/public.crt~./tmp/minio/certs/public.crt~to/tmp/minio/certs/public.crt.Since
event_linux.gois only watchingnotify.InCloseWriteit did trigger whenpublic.crt~is written, but the actual certificate hasn't been updated yet. After addingnotify.InMovedToit also gets triggered after the rename. This caused a race condition between reloading the certificate and the rename operation.The PR also adds a unit test to check this behavior.
PS: This doesn't seem to be caused by #198. The previous certificate manager also didn't watch the
notify.InMovedToevent.