fix(openbao-operator): declaratively restart the wedged manager #128
Loading…
Reference in a new issue
No description provided.
Delete branch "fix/openbao-operator-restart"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
URGENT, via GitOps per operator instruction. The OpenBao operator's reconcile loop froze on 2026-08-28: lastRenewalTime stopped advancing on every OpenBaoDynamicSecret, and an annotation nudge on the CR was ignored. Consequences already landed: the binjovi-staging static database credential rotated in PostgreSQL without reaching its Secret, so the v0.1.135 staging deploy crash-loops on invalid_password and every binjovi train is blocked at staging. The binjovi production credential rotates on 2026-09-03 - same wedge, two-day fuse.
Fix: a dated pod-template annotation added to the operator's existing Kustomization Deployment patch - a declarative rollout restart through Flux, no hand-touched cluster state. Bump the date for any future restart. After the roll, the manager re-reconciles, the staging Secret refreshes, and its rolloutRestartTargets bounce binjovi-staging.
https://claude.ai/code/session_01LeVatedQ4sCA1u6LHjo7B5