Remove service accounts cache (#685)

For optimization purposes operator was creating a cache map to remember
if service accounts and role binding was deployed to a namespace. This
could lead to a problem, when a namespace was deleted, since this
cache was not synchronized. For the sake of correctness remove the
cache, and check every time if required service account and rbac is
present. In the normal case this introduces an overhead of two API calls
per an event (one to get a service accounts, one to get a role binding),
which should not be a problem, unless proven otherwise.
This commit is contained in:
Dmitry Dolgov
2019-10-11 11:06:14 +02:00
committed by GitHub
parent e3b39a5cbe
commit 647a4d3023
2 changed files with 4 additions and 7 deletions
-1
View File
@@ -58,7 +58,6 @@ type Controller struct {
PodServiceAccount *v1.ServiceAccount
PodServiceAccountRoleBinding *rbacv1beta1.RoleBinding
namespacesWithDefinedRBAC sync.Map
}
// NewController creates a new controller