Skip to content

[Backport release-1.6] fix(kubernetes): probe Keycloak CRDs by output in oidc-bootstrap cleanup - #4571

Open
github-actions[bot] wants to merge 1 commit into
release-1.6from
backport-3520-to-release-1.6
Open

github-actions[bot] wants to merge 1 commit into
release-1.6from
backport-3520-to-release-1.6

Conversation

@github-actions

Copy link
Copy Markdown

Description

Backport of #3520 to release-1.6.

`kubectl api-resources --api-group=<absent group>` exits 0 and prints an
empty list, so guarding on the exit code always fell through. The delete
then failed with `the server doesn't have a resource type "keycloakclient"`
— `--ignore-not-found` covers a missing object, not an unknown type.

Because the oidc-bootstrap Job is a post-install/post-upgrade Helm hook,
that failure blocked the Helm upgrade of every `kubernetes-<cluster>`
release on any cluster without the EDP Keycloak operator CRDs, which is
the default configuration (`oidc.mode: None`).

Capture the discovery output once and gate each delete on its own
resource type, matching the probe idiom already used by the platform
migrations and the ouroboros cleanup hook.

Fixes #3516

Signed-off-by: Mattia Eleuteri <[email protected]>
Assisted-by: LLM
(cherry picked from commit 06400ac)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant