Merge pull request #11397 from johngmyers/no-discoverystore

Don't publish OIDC discovery if DiscoveryStore not set
This commit is contained in:
Kubernetes Prow Robot 2021-05-07 03:11:10 -07:00 committed by GitHub
commit bdc4d6ab5b
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
2 changed files with 2 additions and 2 deletions

View File

@ -374,7 +374,7 @@ func ValidateCluster(c *kops.Cluster, strict bool) field.ErrorList {
}
said := c.Spec.ServiceAccountIssuerDiscovery
if said != nil {
if said != nil && said.DiscoveryStore != "" {
saidStore := said.DiscoveryStore
saidStoreField := fieldSpec.Child("serviceAccountIssuerDiscovery", "discoveryStore")
base, err := vfs.Context.BuildVfsPath(saidStore)

View File

@ -53,7 +53,7 @@ type oidcDiscovery struct {
func (b *IssuerDiscoveryModelBuilder) Build(c *fi.ModelBuilderContext) error {
said := b.Cluster.Spec.ServiceAccountIssuerDiscovery
if said == nil {
if said == nil || said.DiscoveryStore == "" {
return nil
}