Files
actions-runner-controller/controllers
Nikola JokicandCopilot App f22def86e0 Recreate the listener pod when its config secret changes
Replacing the integrity hash with a pod spec comparison lost the one
signal the spec cannot carry. The listener mounts its config as a secret
volume and parses it once at startup, so a change to the scale set URL,
the TLS certificate, the metrics configuration or the scaler tuning only
reaches the listener after a restart. The pod references the secret by
name, so the spec is byte-identical before and after and the pod was
never recreated.

The desired pod now carries the config secret's resource version as an
annotation, which is free to read and moves exactly when the secret is
written. An empty annotation on the live pod is ignored so that pods
created by an older controller are not all recreated on upgrade.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
2026-09-09 10:41:31 +02:00
..