From 33ced6cc343e90217d276d45a83d11e8f590367d Mon Sep 17 00:00:00 2001 From: tcondeixa Date: Tue, 18 Aug 2026 17:59:26 +0200 Subject: [PATCH] clean the kube2iam annotations when the role is empty --- pkg/cluster/sync.go | 22 ++++++++++++++++++++++ 1 file changed, 22 insertions(+) diff --git a/pkg/cluster/sync.go b/pkg/cluster/sync.go index 664c67b7e..6a83b0a46 100644 --- a/pkg/cluster/sync.go +++ b/pkg/cluster/sync.go @@ -1793,6 +1793,28 @@ func (c *Cluster) syncLogicalBackupJob() error { return fmt.Errorf("could not patch annotations of the logical backup job %q: %v", jobName, err) } } + + if c.OpConfig.KubeIAMRole == "" { + patch, err := json.Marshal(map[string]interface{}{ + "metadata": map[string]interface{}{ + "annotations": map[string]*string{constants.KubeIAmAnnotation: nil}, + }, + "spec": map[string]interface{}{ + "jobTemplate": map[string]interface{}{ + "metadata": map[string]interface{}{ + "annotations": map[string]*string{constants.KubeIAmAnnotation: nil}, + }, + }, + }, + }) + if err != nil { + return fmt.Errorf("could not marshal kube2iam annotation removal patch for logical backup job %q: %v", jobName, err) + } + _, err = c.KubeClient.CronJobs(c.Namespace).Patch(context.TODO(), jobName, types.StrategicMergePatchType, patch, metav1.PatchOptions{}) + if err != nil { + return fmt.Errorf("could not remove kube2iam annotation from logical backup job %q: %v", jobName, err) + } + } c.LogicalBackupJob = desiredJob return nil }