linkerd2/controller/proxy-injector
Alex Leong ca1077bb08
Read trust roots from configmap (#6455)
Fixes #6452 

We add a `linkerd-identity-trust-roots` ConfigMap which contains the configured trust root bundle.  The proxy template partial is modified so that core control plane components load this bundle from the configmap through the downward API.

The identity controller is updated to mount this new configmap as a volume read the trust root bundle at startup.

Similarly, the proxy-injector also mounts this new configmap.  For each pod it injects, it reads the trust root bundle file and sets it on the injected pod.

Signed-off-by: Alex Leong <alex@buoyant.io>
2021-07-28 13:23:15 -07:00
..
fake Set `LINKERD2_PROXY_INBOUND_PORTS` during injection (#6445) 2021-07-09 11:52:20 -05:00
metrics.go Update Injection to use new linkerd-config.values (#5036) 2020-10-07 09:54:34 -07:00
webhook.go Read trust roots from configmap (#6455) 2021-07-28 13:23:15 -07:00
webhook_test.go Add ns annotation inheritance to pods (#6002) (#6002) 2021-04-20 22:25:02 -04:00