Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

VDS: Log and record Vault request failures #508

Merged
merged 1 commit into from
Dec 8, 2023

Conversation

benashz
Copy link
Collaborator

@benashz benashz commented Dec 8, 2023

The VDS controller failed to report whenever a secret sync action had failed. With this PR all secret failures are recorded to the event recorder and logged.

Sample log output:

2023-12-08T13:26:25Z    ERROR   syncSecret      Vault request failed    {"controller": "vaultdynamicsecret", "controllerGroup": "secrets.hashicorp.com", "controllerKind": "VaultDynamicSecret", "VaultDynamicSecret": {"name":"create-static-create-static-creds-0","namespace":"vds-a1xdxdsw4y-k8s-ns"}, "namespace": "vds-a1xdxdsw4y-k8s-ns", "name": "create-static-create-static-creds-0", "reconcileID": "24d2a885-2123-4295-a2f3-98333ff59f10", "path": "vds-a1xdxdsw4y-db/static-creds/dev-postgres-static", "method": "GET", "error": "Error making API request.\n\nURL: GET http://vault.vault.svc.cluster.local:8200/v1/vds-a1xdxdsw4y-db/static-creds/dev-postgres-static\nCode: 403. Errors:\n\n* 1 error occurred:\n\t* permission denied\n\n"}
github.com/hashicorp/vault-secrets-operator/controllers.(*VaultDynamicSecretReconciler).syncSecret
        /workspace/controllers/vaultdynamicsecret_controller.go:304
github.com/hashicorp/vault-secrets-operator/controllers.(*VaultDynamicSecretReconciler).Reconcile
        /workspace/controllers/vaultdynamicsecret_controller.go:210
sigs.k8s.io/controller-runtime/pkg/internal/controller.(*Controller).Reconcile
        /go/pkg/mod/sigs.k8s.io/[email protected]/pkg/internal/controller/controller.go:119
sigs.k8s.io/controller-runtime/pkg/internal/controller.(*Controller).reconcileHandler
        /go/pkg/mod/sigs.k8s.io/[email protected]/pkg/internal/controller/controller.go:316
sigs.k8s.io/controller-runtime/pkg/internal/controller.(*Controller).processNextWorkItem
        /go/pkg/mod/sigs.k8s.io/[email protected]/pkg/internal/controller/controller.go:266
sigs.k8s.io/controller-runtime/pkg/internal/controller.(*Controller).Start.func2.2
        /go/pkg/mod/sigs.k8s.io/[email protected]/pkg/internal/controller/controller.go:227

Sample event:

6m34s       Warning   SecretSyncError   vaultdynamicsecret/create-static-create-static-creds-0   Failed to sync the secret, horizon=6.60288929s, err=Error making API request....

Fixes #507

@benashz benashz requested a review from a team as a code owner December 8, 2023 13:11
@benashz benashz requested review from kschoche and tvoran December 8, 2023 13:17
@adrianmoisey
Copy link
Contributor

This fix looks like exactly what I was looking for, thanks!

@benashz benashz added this to the v0.4.3 milestone Dec 8, 2023
@benashz benashz force-pushed the VAULT-22567/vds-report-all-syncSecret-errors branch from 6a02913 to 6dafc2e Compare December 8, 2023 13:26
Copy link
Contributor

@kschoche kschoche left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Lgtm

@benashz benashz merged commit b4a7416 into main Dec 8, 2023
@benashz benashz deleted the VAULT-22567/vds-report-all-syncSecret-errors branch December 8, 2023 15:12
adrianmoisey pushed a commit to adrianmoisey/vault-secrets-operator that referenced this pull request Jan 16, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

VDS secret sync errors are not reported
3 participants