You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Add transport URL secret rotation with consumer finalizer
When infra-operator rotates a RabbitMQ transport URL (creating a new
secret and user), consumer operators must hold a consumer finalizer on
the old secret until all their pods have rolled out with the new
credentials. Without this, infra-operator cleans up the old RabbitMQ
user while pods are still connected with old credentials, causing
message bus outages.
Design:
1. Add consumer finalizer to the current transport URL secret early
in reconcile. Set instance.Status.TransportURLSecret for first-time
setup only (when empty or unchanged); during rotation the status
is updated solely by FinalizeSecretRotation at end of reconcile.
2. Pass transportURL.Status.SecretName directly to sub-CR creation
functions and config generation as a parameter — never read from
instance.Status.TransportURLSecret for sub-CR specs.
3. Use statefulset.IsReady() / deployment.IsReady() from lib-common
in all sub-CR controllers for accurate rollout status.
4. Use object.ManageRotationGracePeriod() to enforce a 60-second
grace period before evaluating the rotation guard. This gives
sub-CRs time to detect config changes, update their workloads,
and roll pods — without relying on informer cache freshness.
5. Guard: CredentialRotationGuardReady(true, conditions) — evaluates
AllSubConditionIsTrue after the grace period expires. Only when
all sub-CR conditions are True does FinalizeSecretRotation remove
the consumer finalizer from the old secret.
The same pattern applies to notification transport URL secrets and
application credential secrets where applicable.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
0 commit comments