Closed Gerrit91 closed 1 year ago
Explanation of the annotation: https://github.com/gardener/gardener/pull/4873
What happens if the ServiceAccount is not there, or not valid anymore ???
We excluded the metallb resources from the gardener-resource-manager webhook to continue using static tokens for them. Otherwise we run into the problem that when rolling the speaker DaemonSet, the VPN connection will break for shoots with single nodes and then for continuing the rollout the pod cannot be started because the kube-apiserver cannot reach the gardener-resource-manager webhook anymore --> leads to shoot with broken VPN and MetalLB broken.
Otherwise, when users configure node taints, these components are misscheduled.
For example: