From 952891cc51d74e82a06b7bf351875370a4eb7211 Mon Sep 17 00:00:00 2001 From: "Dr. Stefan Schimanski" Date: Wed, 16 Oct 2024 14:34:46 +0200 Subject: [PATCH] server: wire kcp-ca as root-ca, ending up in service account token secrets Signed-off-by: Dr. Stefan Schimanski --- charts/kcp/templates/server-deployment.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/charts/kcp/templates/server-deployment.yaml b/charts/kcp/templates/server-deployment.yaml index c59e28c..532cf30 100644 --- a/charts/kcp/templates/server-deployment.yaml +++ b/charts/kcp/templates/server-deployment.yaml @@ -123,7 +123,7 @@ spec: - --tls-cert-file=/etc/kcp/tls/server/tls.crt - --service-account-key-file=/etc/kcp/tls/service-account/tls.key - --service-account-private-key-file=/etc/kcp/tls/service-account/tls.key - - --root-ca-file=/etc/kcp/tls/service-account-ca/tls.crt + - --root-ca-file=/etc/kcp/tls/ca/tls.crt - --enable-home-workspaces={{ .Values.kcp.homeWorkspaces.enabled }} {{- if .Values.kcp.logicalClusterAdminFlag }} - --logical-cluster-admin-kubeconfig=/etc/kcp/logical-cluster-admin/kubeconfig/kubeconfig