@@ -31,7 +31,6 @@ import (
31
31
const (
32
32
kubernetesPKIVolumeName = "etc-kubernetes-pki"
33
33
caCertificatesVolumeName = "etc-ca-certificates"
34
- sslCertsVolumeName = "etc-ssl-certs"
35
34
usrShareCACertificatesVolumeName = "usr-share-ca-certificates"
36
35
usrLocalShareCaCertificateVolumeName = "usr-local-share-ca-certificates"
37
36
schedulerKubeconfigVolumeName = "scheduler-kubeconfig"
@@ -162,7 +161,6 @@ func (d Deployment) setVolumes(podSpec *corev1.PodSpec, tcp kamajiv1alpha1.Tenan
162
161
for _ , fn := range []func (* corev1.PodSpec , kamajiv1alpha1.TenantControlPlane ){
163
162
d .buildPKIVolume ,
164
163
d .buildCAVolume ,
165
- d .buildSSLCertsVolume ,
166
164
d .buildShareCAVolume ,
167
165
d .buildLocalShareCAVolume ,
168
166
d .buildSchedulerVolume ,
@@ -250,22 +248,6 @@ func (d Deployment) buildCAVolume(podSpec *corev1.PodSpec, tcp kamajiv1alpha1.Te
250
248
}
251
249
}
252
250
253
- func (d Deployment ) buildSSLCertsVolume (podSpec * corev1.PodSpec , tcp kamajiv1alpha1.TenantControlPlane ) {
254
- found , index := utilities .HasNamedVolume (podSpec .Volumes , sslCertsVolumeName )
255
- if ! found {
256
- index = len (podSpec .Volumes )
257
- podSpec .Volumes = append (podSpec .Volumes , corev1.Volume {})
258
- }
259
-
260
- podSpec .Volumes [index ].Name = sslCertsVolumeName
261
- podSpec .Volumes [index ].VolumeSource = corev1.VolumeSource {
262
- Secret : & corev1.SecretVolumeSource {
263
- SecretName : tcp .Status .Certificates .CA .SecretName ,
264
- DefaultMode : pointer .To (int32 (420 )),
265
- },
266
- }
267
- }
268
-
269
251
func (d Deployment ) buildShareCAVolume (podSpec * corev1.PodSpec , tcp kamajiv1alpha1.TenantControlPlane ) {
270
252
found , index := utilities .HasNamedVolume (podSpec .Volumes , usrShareCACertificatesVolumeName )
271
253
if ! found {
@@ -521,11 +503,6 @@ func (d Deployment) buildControllerManager(podSpec *corev1.PodSpec, tenantContro
521
503
ReadOnly : true ,
522
504
MountPath : "/etc/ca-certificates" ,
523
505
})
524
- d .ensureVolumeMount (& volumeMounts , corev1.VolumeMount {
525
- Name : sslCertsVolumeName ,
526
- ReadOnly : true ,
527
- MountPath : "/etc/ssl/certs" ,
528
- })
529
506
d .ensureVolumeMount (& volumeMounts , corev1.VolumeMount {
530
507
Name : usrShareCACertificatesVolumeName ,
531
508
ReadOnly : true ,
@@ -655,11 +632,6 @@ func (d Deployment) buildKubeAPIServer(podSpec *corev1.PodSpec, tenantControlPla
655
632
ReadOnly : true ,
656
633
MountPath : "/etc/ca-certificates" ,
657
634
})
658
- d .ensureVolumeMount (& volumeMounts , corev1.VolumeMount {
659
- Name : sslCertsVolumeName ,
660
- ReadOnly : true ,
661
- MountPath : "/etc/ssl/certs" ,
662
- })
663
635
d .ensureVolumeMount (& volumeMounts , corev1.VolumeMount {
664
636
Name : usrShareCACertificatesVolumeName ,
665
637
ReadOnly : true ,
0 commit comments