Skip to content

Expose validating webhook for shoots in the garden cluster #16

@rfranzke

Description

@rfranzke

What would you like to be added:
The shoot-cert-service extension should ship a validating webhook binary that can be deployed to the garden cluster and that checks whether the provided CertConfig in the .spec.extensions[].providerConfig is valid.

Why is this needed:
https://gardener.cloud/050-tutorials/content/howto/x509_certificates/#issuer states that the issuer name in the CertConfig may not be garden. This should be properly validated to prevent misconfiguration.

Metadata

Metadata

Assignees

No one assigned

    Labels

    kind/enhancementEnhancement, improvement, extensionlifecycle/frozenIndicates that an issue or PR should not be auto-closed due to staleness.triage/acceptedIndicates an issue or PR is ready to be actively worked on.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions