-
Notifications
You must be signed in to change notification settings - Fork 29
feat: pod reload on configmaps and falco separated configmaps #2057
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Haven't gotten a chance to deploy locally but the changes to support configmaps look good from a review standpoint. Some other comments on docs mostly.
| @@ -1,14 +1,14 @@ | |||
| --- | |||
| title: Secret Pod Reload | |||
| title: Resource Pod Reload | |||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Let's make sure to add a doc redirect to the docs site since this one has been linked in release notes, etc. I also wonder if it makes more sense to just call it "pod reloading"?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Yeah tracking the redirect, put up a PR for that. I like the idea of calling the doc Pod Reload, simpler, more straightforward.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Let's rename the file to match, which should make the docs PR correct 😄
Description
Previously all Falco configmaps for rules were combined into a single configmap, this raised concerns that over time as those rules change the configmap could become too large. This PR will separate each ruleset out into its own configmap.
Additionally, when Falco ruleset changes and we update a configmap we want our pods to reload so that Falco starts using that new configmap. Previously uds core only supported pod reloading on secret changes, this PR will expand that functionality to work with configmaps as well as secrets.
Related Issue
Fixes #1972
Type of change
Checklist before merging