Hi !
To improve the safety and reliability of the Operator, I'm currently considering implementing the mechanism described below.
Would you be open to accepting a pull request for this once I have it ready?
If this approach doesn't align with the project's design direction, please feel free to reject the idea—no worries at all!
Configuration Validation Before Secret Update
Before the operator updates the runtime configuration Secret (<instance>-haproxy-config), it validates the generated haproxy.cfg using a short-lived Kubernetes Job:
-
Build the generated haproxy.cfg and all referenced certificate/config files.
-
Create a temporary validation Secret.
-
Start a short-lived Job using the same image as the target HAProxy instance (spec.image, fallback haproxy:latest) and run:
haproxy -c -f /usr/local/etc/haproxy/haproxy.cfg
-
If validation succeeds, update the runtime configuration Secret.
-
If validation fails, do not update the runtime configuration Secret, and set the Error status on the Instance and related configuration resources.
-
Clean up temporary validation resources (Job and Secret) automatically (via TTL) and explicitly by the operator.
Looking forward to hearing your thoughts!
Hi !
To improve the safety and reliability of the Operator, I'm currently considering implementing the mechanism described below.
Would you be open to accepting a pull request for this once I have it ready?
If this approach doesn't align with the project's design direction, please feel free to reject the idea—no worries at all!
Configuration Validation Before Secret Update
Before the operator updates the runtime configuration
Secret(<instance>-haproxy-config), it validates the generatedhaproxy.cfgusing a short-lived KubernetesJob:Build the generated
haproxy.cfgand all referenced certificate/config files.Create a temporary validation
Secret.Start a short-lived
Jobusing the same image as the target HAProxy instance (spec.image, fallbackhaproxy:latest) and run:haproxy -c -f /usr/local/etc/haproxy/haproxy.cfg
If validation succeeds, update the runtime configuration
Secret.If validation fails, do not update the runtime configuration
Secret, and set theErrorstatus on theInstanceand related configuration resources.Clean up temporary validation resources (
JobandSecret) automatically (via TTL) and explicitly by the operator.Looking forward to hearing your thoughts!