From 9452473bf6afb7814287902e19abb11603a8ff63 Mon Sep 17 00:00:00 2001 From: Ben Vincent Date: Sat, 25 Jul 2026 23:03:36 +1000 Subject: [PATCH] Roll cephrgw-operator to v0.3.1 (CRD staleness warning) (#290) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit ## Why cephrgw-operator **v0.3.1** logs a startup WARNING when its installed CRDs are missing or older than the operator (operator repo #6, merged) — added precisely because the CRD tag drifted behind the image before. The new startup check reads the `CustomResourceDefinition` objects, so it needs a small RBAC grant. ## Changes - bump the operator image `git.unkin.net/unkin/cephrgw-operator` → `v0.3.1` - bump the CRD `install.yaml` tag → `v0.3.1` (keep CRDs in step with the image — the invariant the v0.3.1 warning enforces) - add `apiextensions.k8s.io/customresourcedefinitions: [get, list]` to the operator ClusterRole so the startup check is not RBAC-denied Validated with `kustomize build` on the au-syd1 overlay; the v0.3.1 CRD URL resolves. Supersedes nothing outstanding (the earlier CRD-tag PR #286 to v0.3.0 already merged). https://claude.ai/code/session_016CEncETbf8cvy1PhsHfFHM Reviewed-on: https://git.unkin.net/unkin/argocd-apps/pulls/290 Co-authored-by: Ben Vincent Co-committed-by: Ben Vincent --- apps/base/cephrgw-system/deployment.yaml | 2 +- apps/base/cephrgw-system/kustomization.yaml | 2 +- apps/base/cephrgw-system/rbac.yaml | 4 ++++ 3 files changed, 6 insertions(+), 2 deletions(-) diff --git a/apps/base/cephrgw-system/deployment.yaml b/apps/base/cephrgw-system/deployment.yaml index 2e005fe..93a543f 100644 --- a/apps/base/cephrgw-system/deployment.yaml +++ b/apps/base/cephrgw-system/deployment.yaml @@ -24,7 +24,7 @@ spec: runAsNonRoot: true containers: - name: operator - image: git.unkin.net/unkin/cephrgw-operator:v0.3.0 + image: git.unkin.net/unkin/cephrgw-operator:v0.3.1 args: - --metrics-bind-address=:8080 - --health-probe-bind-address=:8081 diff --git a/apps/base/cephrgw-system/kustomization.yaml b/apps/base/cephrgw-system/kustomization.yaml index 6df7822..388fe1d 100644 --- a/apps/base/cephrgw-system/kustomization.yaml +++ b/apps/base/cephrgw-system/kustomization.yaml @@ -6,7 +6,7 @@ resources: - namespace.yaml # CRDs are pulled from the cephrgw-operator repo at the matching tag rather # than vendored here, so they never drift from the operator. - - https://git.unkin.net/unkin/cephrgw-operator/raw/tag/v0.3.0/config/crd/install.yaml + - https://git.unkin.net/unkin/cephrgw-operator/raw/tag/v0.3.1/config/crd/install.yaml - rbac.yaml - deployment.yaml - vaultauth.yaml diff --git a/apps/base/cephrgw-system/rbac.yaml b/apps/base/cephrgw-system/rbac.yaml index aad1349..aabefcc 100644 --- a/apps/base/cephrgw-system/rbac.yaml +++ b/apps/base/cephrgw-system/rbac.yaml @@ -23,6 +23,10 @@ rules: - apiGroups: ["coordination.k8s.io"] resources: ["leases"] verbs: ["get", "list", "watch", "create", "update", "patch", "delete"] + # v0.3.1 startup check reads its own CRDs to warn if they are stale/missing. + - apiGroups: ["apiextensions.k8s.io"] + resources: ["customresourcedefinitions"] + verbs: ["get", "list"] --- apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRoleBinding