-
Notifications
You must be signed in to change notification settings - Fork 2.8k
fix(aws): support aws_ca_bundle #5665
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
|
Hi @mwmix. Thanks for your PR. I'm waiting for a kubernetes-sigs member to verify that this patch is reasonable to test. If it is, they should reply with Once the patch is verified, the new status will be reflected by the I understand the commands that are listed here. Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
provider/aws/instrumented_config.go
Outdated
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Configuring metrics per provider not a great idea. Please avoid that.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I agree with you, I've been struggling to find a better implementation. Any insights would be appreciated.
provider/aws/config.go
Outdated
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
config.WithHTTPClient(extdnshttp.NewInstrumentedClient(AWSHTTPCLIENT)),^ Something simliar
What happens if we simply add WithCustomCABundle, my understanding it could work, even if we wrapping http client
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I tried to come up with a way to do what you suggested before I dived down the middleware rabbit hole. But, I kept hitting road blocks. The closest I could get was this and we get a type error:
func NewInstrumentedAWSClient(next *awshttp.BuildableClient) *awshttp.BuildableClient) {
next.WithTransportOptions(func(transport *http.Transport) {
transport = NewInstrumentedTransport(next)
})
}
The type error is
cannot use next (variable of type *"github.com/aws/aws-sdk-go-v2/aws/transport/http".BuildableClient) as "net/http".RoundTripper value in argument to NewInstrumentedTransport: *"github.com/aws/aws-sdk-go-v2/aws/transport/http".BuildableClient does not implement "net/http".RoundTripper (missing method RoundTrip)
So the WithCustomCABundle would "work" and so does just updating my systems trusted ca list. However, the moment we set AWS_CA_BUNDLE even with the WithCustomCABundle set then we still hit that error. One workaround would be to use WithCustomCABundle pulling the value from AWS_CA_BUNDLE and then unsetting the environment variable so the SDK doesn't use it. But, I imagine that has it's own issues ...
When looking at other projects such as otel and based on my own reading of the documentation it seemed like this was the expected interface for adding this sort of functionality.
I'm not really married to any particular solution and appreciate your feedback. I've been trying my best to minimize the impact of the changes while preserving the existing instrumentation but haven't found any cleaner way around it.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I do not have access to AWS. If you could reproduce it with kind+localstack or similar, might be able to have a look.
Have you tried WithCustomCABundle?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
As well, have you tried for example
config.WithHTTPClient(extdnshttp.NewInstrumentedClient(&http.Client{Transport: transport.NewBuildableClient().GetTransport()})),There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I tried WithCustomCABundle() and the error still appears when I try to run with the AWS_CA_BUNDLE defined.
I just also finished testing the last example you gave me above with the same result :(
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Gotcha
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Just a note about opentelemetry. It's ok to have a middleware support, but still expected to to support RoundTrippers https://github.com/open-telemetry/opentelemetry-go-contrib/blob/caee80916a50f168c7152967dabaefd0c3cd17c0/instrumentation/net/http/otelhttp/transport.go#L26
Basically to be a consistent across multiple libraries. With aws there is no such option, it's quite aws specific
provider/aws/instrumented_config.go
Outdated
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Can we keep everything within the existing package sigs.k8s.io/external-dns/pkg/http, unless there’s a circular dependency that prevents it or other valid reason?
Please note that packages named utils are not being approved at this time.
For reference, see this example where a similar utils package was proposed but not accepted: #5189 (comment).
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Sure, ty for the insight. I'll update the MR appropriately.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Is it possible to reuse this certs or location https://github.com/kubernetes-sigs/external-dns/tree/master/internal/testresources?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Yeah absolutely, I didn't realize you already had some stashed away in the repo! :)
7b1027a to
ae5a1bd
Compare
ivankatliarchuk
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
There should be a simple reason why certificate bundle is not loaded. Hard to say without how-to-reproduce example
provider/aws/config.go
Outdated
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
As well, have you tried for example
config.WithHTTPClient(extdnshttp.NewInstrumentedClient(&http.Client{Transport: transport.NewBuildableClient().GetTransport()})),|
The WHY is not working is described here https://github.com/aws/aws-sdk-go-v2/blob/f9f7a6bb124a1a7daffc65db40053d97678bd371/config/env_config.go#L174-L189. In principal, AWS sdk instead of Transport should have RoundTripper, as go http library does. Could we add to our instrumenter an option to wrap and return Transport if Middleware is an OK way, but AWS library middleware is just to complex. |
|
Technically, if we passing a Transport Just need to find out how to enhance it with our metrics. |
|
I'm unsure actually. I do get why AWS team done it that way, but not simple to extend. /ok-to-test |
|
/retitle fix(aws): support aws_ca_bundle |
pkg/http/http.go
Outdated
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Ideally this should stay. The plan is to wrap it like here
external-dns/pkg/metrics/metrics.go
Line 38 in 789494f
| RegisterMetric.MustRegister(NewGaugeFuncMetric(prometheus.GaugeOpts{ |
external-dns/controller/controller.go
Line 38 in 789494f
| registryErrorsTotal = metrics.NewCounterWithOpts( |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Changing this, may affect kube monitoring as well, which is not desirable.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I pushed a new commit which refactors the fix to use the common metrics registry. Does that work? Or do we want to split that into a different PR?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
If you have time, would be better to slice PRs.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Okay I've modified this PR so it has what I hope is the minimum set of changes you were hoping for. I'll have another PR out either later tonight / tomorrow which will be branched off this with the other changes I made.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Opened PR #5677 for the metrics refactoring.
mloiseleur
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The code LGTM.
Like for the previous change on metrics, the latest refactor asked by @ivankatliarchuk should go in its own dedicated PR.
=> Would you please extract the code in pkg/http & pkg/metrics in a dedicated refactor PR ?
90d10ba to
474d1fc
Compare
Yep can do, new PR opened #5717. |
5a6a8b3 to
45c8da8
Compare
provider/aws/instrumented_config.go
Outdated
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I wonder how this works without issues. The package pkg/http depends on pkg/metrics. Interesting, I would expect cyclic dependency
|
/lgtm |
|
It seems like no issues. so lgtm as well /approve |
|
Fixes #5666 |
|
/remove-approve |
45c8da8 to
937be24
Compare
|
Ah I see the issue this isn't using the refactored stuff. I've re-based everything and pushed updates. I can build locally and run. |
ivankatliarchuk
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
/approve
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: ivankatliarchuk The full list of commands accepted by this bot can be found here. The pull request process is described here
Needs approval from an approver in each of these files:
Approvers can indicate their approval by writing |
…o v0.19.0 (#805) This PR contains the following updates: | Package | Update | Change | |---|---|---| | [registry.k8s.io/external-dns/external-dns](https://github.com/kubernetes-sigs/external-dns) | minor | `v0.18.0` -> `v0.19.0` | --- ### Release Notes <details> <summary>kubernetes-sigs/external-dns (registry.k8s.io/external-dns/external-dns)</summary> ### [`v0.19.0`](https://github.com/kubernetes-sigs/external-dns/releases/tag/v0.19.0) [Compare Source](kubernetes-sigs/external-dns@v0.18.0...v0.19.0) #### General information - :information\_source: CLI flags allows to set behavior of previous version on the two breaking changes included in this release, if needed. - :information\_source: Thanks to [@​valerian-roche](https://github.com/valerian-roche), this version can reduce the *average* memory usage by \~10 times, see [#​5596](kubernetes-sigs/external-dns#5596) ####⚠️ Breaking Changes - feat(nodes)!: expose external ipv6 by default by [@​mloiseleur](https://github.com/mloiseleur) in [#​5575](kubernetes-sigs/external-dns#5575) - feat(traefik)!: disable legacy listeners on traefik.containo.us API Group by [@​mloiseleur](https://github.com/mloiseleur) in [#​5565](kubernetes-sigs/external-dns#5565) #### 🚀 Features - feat(aws): add support for ap-east-2 by [@​chemi0213](https://github.com/chemi0213) in [#​5638](kubernetes-sigs/external-dns#5638) - feat(aws): add support for geoproximity routing by [@​prasadkatti](https://github.com/prasadkatti) in [#​5347](kubernetes-sigs/external-dns#5347) - feat(azure): update Azure provider configuration and documentation by [@​antchand](https://github.com/antchand) in [#​5648](kubernetes-sigs/external-dns#5648) - feat(chart): add option to configure annotationFilter via dedicated helm value by [@​dshatokhin](https://github.com/dshatokhin) in [#​5737](kubernetes-sigs/external-dns#5737) - feat(events): raise k8s events with fake provider by [@​ivankatliarchuk](https://github.com/ivankatliarchuk) in [#​5659](kubernetes-sigs/external-dns#5659) - feat(metrics): publish build\_info metric by [@​ivankatliarchuk](https://github.com/ivankatliarchuk) in [#​5643](kubernetes-sigs/external-dns#5643) - feat(nodes)!: expose external ipv6 by default by [@​mloiseleur](https://github.com/mloiseleur) in [#​5575](kubernetes-sigs/external-dns#5575) - feat(source/istio): support version 1.25+ by [@​ivankatliarchuk](https://github.com/ivankatliarchuk) in [#​5611](kubernetes-sigs/external-dns#5611) - feat(source/pods): support for annotation and label filter by [@​ivankatliarchuk](https://github.com/ivankatliarchuk) in [#​5583](kubernetes-sigs/external-dns#5583) - feat(source): support --event flags with sources pod and node by [@​ivankatliarchuk](https://github.com/ivankatliarchuk) in [#​5642](kubernetes-sigs/external-dns#5642) - feat(source): use transformers in pod informers to reduce memory footprint by [@​valerian-roche](https://github.com/valerian-roche) in [#​5596](kubernetes-sigs/external-dns#5596) - feat(traefik)!: disable legacy listeners on traefik.containo.us API Group by [@​mloiseleur](https://github.com/mloiseleur) in [#​5565](kubernetes-sigs/external-dns#5565) #### 🐛 Bug fixes - fix(api): rollback oas and update linter by [@​ivankatliarchuk](https://github.com/ivankatliarchuk) in [#​5723](kubernetes-sigs/external-dns#5723) - fix(aws): support aws\_ca\_bundle by [@​mwmix](https://github.com/mwmix) in [#​5665](kubernetes-sigs/external-dns#5665) - fix(chart): Change .extraContainers type to array by [@​svengreb](https://github.com/svengreb) in [#​5564](kubernetes-sigs/external-dns#5564) - fix(cloudflare): display of action in logs by [@​vflaux](https://github.com/vflaux) in [#​5550](kubernetes-sigs/external-dns#5550) - fix(cloudflare): set comments properly by [@​7onn](https://github.com/7onn) in [#​5582](kubernetes-sigs/external-dns#5582) - fix(cloudflare): unnecessary record updates by [@​vflaux](https://github.com/vflaux) in [#​5770](kubernetes-sigs/external-dns#5770) - fix(controller): panic in events.Controller.Add() by [@​vflaux](https://github.com/vflaux) in [#​5766](kubernetes-sigs/external-dns#5766) - fix(docs): Fixing some errors in the dev-guide example. by [@​mwmix](https://github.com/mwmix) in [#​5662](kubernetes-sigs/external-dns#5662) - fix(endpoint): domains handling with idna by [@​ivankatliarchuk](https://github.com/ivankatliarchuk) in [#​5685](kubernetes-sigs/external-dns#5685) - fix(helm): resolve RBAC permissions for namespaced gateway sources by [@​u-kai](https://github.com/u-kai) in [#​5578](kubernetes-sigs/external-dns#5578) - fix(helm): Update helm value schema to allow `create-only` policy type by [@​coltonhughes](https://github.com/coltonhughes) in [#​5627](kubernetes-sigs/external-dns#5627) - fix(http): concurrent map read/write by [@​ivankatliarchuk](https://github.com/ivankatliarchuk) in [#​5753](kubernetes-sigs/external-dns#5753) - fix(instrumented\_http): migrate to own http instrumenter by [@​ivankatliarchuk](https://github.com/ivankatliarchuk) in [#​5650](kubernetes-sigs/external-dns#5650) - fix(metrics): make prometheus labels more type safe by [@​mwmix](https://github.com/mwmix) in [#​5717](kubernetes-sigs/external-dns#5717) - fix(oas): add required properties to api components by [@​evilhamsterman](https://github.com/evilhamsterman) in [#​5696](kubernetes-sigs/external-dns#5696) - fix(pihole): create record for all targets by [@​vkolobara](https://github.com/vkolobara) in [#​5584](kubernetes-sigs/external-dns#5584) - fix(provider/aws): null pointer when records mailformed by [@​ivankatliarchuk](https://github.com/ivankatliarchuk) in [#​5639](kubernetes-sigs/external-dns#5639) - fix(provider/aws-sd): fix namespace type filtering by [@​ivankatliarchuk](https://github.com/ivankatliarchuk) in [#​5682](kubernetes-sigs/external-dns#5682) - fix(provider): IDNA awareness in the zone finder by [@​hanapedia](https://github.com/hanapedia) in [#​5705](kubernetes-sigs/external-dns#5705) - fix(rbac): conditional endpointslices perms by [@​vflaux](https://github.com/vflaux) in [#​5746](kubernetes-sigs/external-dns#5746) - fix: reduce warning by using idna profile by [@​szuecs](https://github.com/szuecs) in [#​5587](kubernetes-sigs/external-dns#5587) - fix(rfc2136): Use correct index for accessing UpdateOld if there are multiple chunks by [@​schwajo](https://github.com/schwajo) in [#​5542](kubernetes-sigs/external-dns#5542) - fix(source): respect --expose-internal-ipv6 flag on NodePort services by [@​jonasbadstuebner](https://github.com/jonasbadstuebner) in [#​5652](kubernetes-sigs/external-dns#5652) - fix(source/service): disable node informer when not required by [@​ivankatliarchuk](https://github.com/ivankatliarchuk) in [#​5613](kubernetes-sigs/external-dns#5613) - fix(source/service): disable pod and endpointSlices informers when they are not needed by [@​ivankatliarchuk](https://github.com/ivankatliarchuk) in [#​5646](kubernetes-sigs/external-dns#5646) - fix(source/service): make sure only unique targets available for futher processing by [@​ivankatliarchuk](https://github.com/ivankatliarchuk) in [#​5614](kubernetes-sigs/external-dns#5614) - fix(txt-registry): skip creation of already-existing TXT records ([#​4914](kubernetes-sigs/external-dns#4914)) by [@​u-kai](https://github.com/u-kai) in [#​5459](kubernetes-sigs/external-dns#5459) - fix: zonefinder used wrong quotation style by [@​szuecs](https://github.com/szuecs) in [#​5588](kubernetes-sigs/external-dns#5588) #### 📝 Documentation - docs: add information on external webhook usage by [@​Raffo](https://github.com/Raffo) in [#​5606](kubernetes-sigs/external-dns#5606) - docs: add new webhook provider SAKURA Cloud into README by [@​ippanpeople](https://github.com/ippanpeople) in [#​5784](kubernetes-sigs/external-dns#5784) - docs(aws): add helm repo command to the tutorial by [@​raghu-manne](https://github.com/raghu-manne) in [#​5618](kubernetes-sigs/external-dns#5618) - docs: fix typo in compatibility table by [@​vflaux](https://github.com/vflaux) in [#​5769](kubernetes-sigs/external-dns#5769) - docs(istio): document ingress annotation by [@​ivankatliarchuk](https://github.com/ivankatliarchuk) in [#​5756](kubernetes-sigs/external-dns#5756) - docs(providers): add Myra Security DNS to the list by [@​armaaar](https://github.com/armaaar) in [#​5671](kubernetes-sigs/external-dns#5671) - docs(readme): update k8s compatiblity table by [@​vflaux](https://github.com/vflaux) in [#​5747](kubernetes-sigs/external-dns#5747) - docs: remove substitution in AES keygen examples by [@​super-octo-spoon](https://github.com/super-octo-spoon) in [#​5686](kubernetes-sigs/external-dns#5686) - docs(source/service): headless records and root/base domain by [@​ivankatliarchuk](https://github.com/ivankatliarchuk) in [#​5624](kubernetes-sigs/external-dns#5624) #### 📦 Others - chore(ci): improve releaser script by [@​mloiseleur](https://github.com/mloiseleur) in [#​5571](kubernetes-sigs/external-dns#5571) - chore(ci): update labels automation by [@​mloiseleur](https://github.com/mloiseleur) in [#​5580](kubernetes-sigs/external-dns#5580) - chore(cloudflare): migrate CreateDNSRecord() to new lib by [@​vflaux](https://github.com/vflaux) in [#​5779](kubernetes-sigs/external-dns#5779) - chore(cloudflare): migrate DNSRecord to new lib struct by [@​vflaux](https://github.com/vflaux) in [#​5762](kubernetes-sigs/external-dns#5762) - chore(cloudflare): rename zoneService fields by [@​vflaux](https://github.com/vflaux) in [#​5761](kubernetes-sigs/external-dns#5761) - chore(cloudflare): upgrade library to v5 by [@​vflaux](https://github.com/vflaux) in [#​5734](kubernetes-sigs/external-dns#5734) - chore(cloudflare): use lib v4 for regional services by [@​vflaux](https://github.com/vflaux) in [#​5609](kubernetes-sigs/external-dns#5609) - chore(codebase): code reuse by [@​ivankatliarchuk](https://github.com/ivankatliarchuk) in [#​5607](kubernetes-sigs/external-dns#5607) - chore(codebase): enable linter nonamedreturns by [@​ivankatliarchuk](https://github.com/ivankatliarchuk) in [#​5594](kubernetes-sigs/external-dns#5594) - chore(codebase): remove pointer to an interface by [@​ivankatliarchuk](https://github.com/ivankatliarchuk) in [#​5625](kubernetes-sigs/external-dns#5625) - chore(deps): bump github.com/cloudflare/cloudflare-go/v4 from 4.5.1 to 4.6.0 in the dev-dependencies group by [@​app/dependabot](https://github.com/app/dependabot) in [#​5645](kubernetes-sigs/external-dns#5645) - chore(deps): bump github.com/digitalocean/godo from 1.155.0 to 1.156.0 in the dev-dependencies group by [@​app/dependabot](https://github.com/app/dependabot) in [#​5623](kubernetes-sigs/external-dns#5623) - chore(deps): bump github.com/oracle/oci-go-sdk/v65 from 65.94.0 to 65.95.0 in the dev-dependencies group by [@​app/dependabot](https://github.com/app/dependabot) in [#​5597](kubernetes-sigs/external-dns#5597) - chore(deps): bump google.golang.org/api from 0.239.0 to 0.240.0 in the dev-dependencies group by [@​app/dependabot](https://github.com/app/dependabot) in [#​5605](kubernetes-sigs/external-dns#5605) - chore(deps): bump renovatebot/github-action from 43.0.1 to 43.0.2 in the dev-dependencies group by [@​app/dependabot](https://github.com/app/dependabot) in [#​5592](kubernetes-sigs/external-dns#5592) - chore(deps): bump renovatebot/github-action from 43.0.2 to 43.0.3 in the dev-dependencies group by [@​app/dependabot](https://github.com/app/dependabot) in [#​5644](kubernetes-sigs/external-dns#5644) - chore(deps): bump renovatebot/github-action from 43.0.4 to 43.0.5 in the dev-dependencies group by [@​app/dependabot](https://github.com/app/dependabot) in [#​5691](kubernetes-sigs/external-dns#5691) - chore(deps): bump the dev-dependencies group across 1 directory with 10 updates by [@​app/dependabot](https://github.com/app/dependabot) in [#​5760](kubernetes-sigs/external-dns#5760) - chore(deps): bump the dev-dependencies group across 1 directory with 17 updates by [@​app/dependabot](https://github.com/app/dependabot) in [#​5704](kubernetes-sigs/external-dns#5704) - chore(deps): bump the dev-dependencies group across 1 directory with 17 updates by [@​app/dependabot](https://github.com/app/dependabot) in [#​5726](kubernetes-sigs/external-dns#5726) - chore(deps): bump the dev-dependencies group across 1 directory with 18 updates by [@​app/dependabot](https://github.com/app/dependabot) in [#​5739](kubernetes-sigs/external-dns#5739) - chore(deps): bump the dev-dependencies group across 1 directory with 2 updates by [@​app/dependabot](https://github.com/app/dependabot) in [#​5667](kubernetes-sigs/external-dns#5667) - chore(deps): bump the dev-dependencies group across 1 directory with 2 updates by [@​app/dependabot](https://github.com/app/dependabot) in [#​5732](kubernetes-sigs/external-dns#5732) - chore(deps): bump the dev-dependencies group across 1 directory with 2 updates by [@​app/dependabot](https://github.com/app/dependabot) in [#​5759](kubernetes-sigs/external-dns#5759) - chore(deps): bump the dev-dependencies group across 1 directory with 3 updates by [@​app/dependabot](https://github.com/app/dependabot) in [#​5579](kubernetes-sigs/external-dns#5579) - chore(deps): bump the dev-dependencies group across 1 directory with 5 updates by [@​app/dependabot](https://github.com/app/dependabot) in [#​5690](kubernetes-sigs/external-dns#5690) - chore(deps): bump the dev-dependencies group across 1 directory with 8 updates by [@​app/dependabot](https://github.com/app/dependabot) in [#​5637](kubernetes-sigs/external-dns#5637) - chore(deps): bump the dev-dependencies group across 1 directory with 8 updates by [@​app/dependabot](https://github.com/app/dependabot) in [#​5658](kubernetes-sigs/external-dns#5658) - chore(deps): bump the dev-dependencies group with 10 updates by [@​app/dependabot](https://github.com/app/dependabot) in [#​5668](kubernetes-sigs/external-dns#5668) - chore(deps): bump the dev-dependencies group with 2 updates by [@​app/dependabot](https://github.com/app/dependabot) in [#​5610](kubernetes-sigs/external-dns#5610) - chore(deps): bump the dev-dependencies group with 3 updates by [@​app/dependabot](https://github.com/app/dependabot) in [#​5628](kubernetes-sigs/external-dns#5628) - chore(deps): bump the dev-dependencies group with 4 updates by [@​app/dependabot](https://github.com/app/dependabot) in [#​5593](kubernetes-sigs/external-dns#5593) - chore(deps): bump the dev-dependencies group with 4 updates by [@​app/dependabot](https://github.com/app/dependabot) in [#​5673](kubernetes-sigs/external-dns#5673) - chore(deps): bump the dev-dependencies group with 9 updates by [@​app/dependabot](https://github.com/app/dependabot) in [#​5763](kubernetes-sigs/external-dns#5763) - chore(deps): update golangci-lint version to v2.2.2 by [@​dongjiang1989](https://github.com/dongjiang1989) in [#​5670](kubernetes-sigs/external-dns#5670) - chore(endpoint): fix typo by [@​bachorp](https://github.com/bachorp) in [#​5787](kubernetes-sigs/external-dns#5787) - chore(github-actions): test execution with low resources by [@​ivankatliarchuk](https://github.com/ivankatliarchuk) in [#​5729](kubernetes-sigs/external-dns#5729) - chore(github): enchance issue-template for bug-report by [@​ivankatliarchuk](https://github.com/ivankatliarchuk) in [#​5692](kubernetes-sigs/external-dns#5692) - chore(helm): add rbac unit-tests for istio sources by [@​ivankatliarchuk](https://github.com/ivankatliarchuk) in [#​5752](kubernetes-sigs/external-dns#5752) - chore(metrics): refactor metrics to use common registry by [@​mwmix](https://github.com/mwmix) in [#​5677](kubernetes-sigs/external-dns#5677) - chore(plan): added tests for cases with asterisks by [@​ivankatliarchuk](https://github.com/ivankatliarchuk) in [#​5640](kubernetes-sigs/external-dns#5640) - chore(provider/aws): reduce if-nesting for dryRun condition by [@​ivankatliarchuk](https://github.com/ivankatliarchuk) in [#​5688](kubernetes-sigs/external-dns#5688) - chore: release chart for v0.18.0 by [@​elafarge](https://github.com/elafarge) in [#​5633](kubernetes-sigs/external-dns#5633) - chore(release): updates kustomize & docs with v0.18.0 by [@​mloiseleur](https://github.com/mloiseleur) in [#​5573](kubernetes-sigs/external-dns#5573) - chore(source/istio): replace kube API calls with caching and ingress informers by [@​ivankatliarchuk](https://github.com/ivankatliarchuk) in [#​5743](kubernetes-sigs/external-dns#5743) - chore(source/net-filter): improve flow logic and add more tests by [@​ivankatliarchuk](https://github.com/ivankatliarchuk) in [#​5629](kubernetes-sigs/external-dns#5629) - chore(source): reorganise sources and wrappers by [@​ivankatliarchuk](https://github.com/ivankatliarchuk) in [#​5598](kubernetes-sigs/external-dns#5598) - chore(source): use types instead of strings by [@​ivankatliarchuk](https://github.com/ivankatliarchuk) in [#​5699](kubernetes-sigs/external-dns#5699) - chore(store\*): add reduce complexity and improve code coverage by [@​AndrewCharlesHay](https://github.com/AndrewCharlesHay) in [#​5568](kubernetes-sigs/external-dns#5568) - refactor(annotations): use common prefix to simplify filtering in informer transformers by [@​valerian-roche](https://github.com/valerian-roche) in [#​5621](kubernetes-sigs/external-dns#5621) - refactor(cloudflare): use lib v4 for zone services by [@​AndrewCharlesHay](https://github.com/AndrewCharlesHay) in [#​5654](kubernetes-sigs/external-dns#5654) - refactor(provider/cloudflare): use local regionalHostname struct by [@​vflaux](https://github.com/vflaux) in [#​5615](kubernetes-sigs/external-dns#5615) - refactor(source): document and add debug information on wrappers by [@​ivankatliarchuk](https://github.com/ivankatliarchuk) in [#​5687](kubernetes-sigs/external-dns#5687) - refactor(source/istio): add transformers by [@​ivankatliarchuk](https://github.com/ivankatliarchuk) in [#​5728](kubernetes-sigs/external-dns#5728) - refactor: use slices.Contains instead of handrolled for loop by [@​szuecs](https://github.com/szuecs) in [#​5589](kubernetes-sigs/external-dns#5589) - test: improve coverage on http and metrics by [@​mwmix](https://github.com/mwmix) in [#​5712](kubernetes-sigs/external-dns#5712) - test(source/istio): add missing edge cases with tests by [@​ivankatliarchuk](https://github.com/ivankatliarchuk) in [#​5715](kubernetes-sigs/external-dns#5715) - tests(source/crd): increase timeouts when it can randomly fails by [@​vflaux](https://github.com/vflaux) in [#​5785](kubernetes-sigs/external-dns#5785) #### 📦 Docker Image ``` docker pull registry.k8s.io/external-dns/external-dns:v0.19.0 ``` #### New Contributors - [@​svengreb](https://github.com/svengreb) made their first contribution in [#​5564](kubernetes-sigs/external-dns#5564) - [@​schwajo](https://github.com/schwajo) made their first contribution in [#​5542](kubernetes-sigs/external-dns#5542) - [@​valerian-roche](https://github.com/valerian-roche) made their first contribution in [#​5621](kubernetes-sigs/external-dns#5621) - [@​chemi0213](https://github.com/chemi0213) made their first contribution in [#​5638](kubernetes-sigs/external-dns#5638) - [@​vkolobara](https://github.com/vkolobara) made their first contribution in [#​5584](kubernetes-sigs/external-dns#5584) - [@​raghu-manne](https://github.com/raghu-manne) made their first contribution in [#​5618](kubernetes-sigs/external-dns#5618) - [@​coltonhughes](https://github.com/coltonhughes) made their first contribution in [#​5627](kubernetes-sigs/external-dns#5627) - [@​elafarge](https://github.com/elafarge) made their first contribution in [#​5633](kubernetes-sigs/external-dns#5633) - [@​mwmix](https://github.com/mwmix) made their first contribution in [#​5662](kubernetes-sigs/external-dns#5662) - [@​super-octo-spoon](https://github.com/super-octo-spoon) made their first contribution in [#​5686](kubernetes-sigs/external-dns#5686) - [@​armaaar](https://github.com/armaaar) made their first contribution in [#​5671](kubernetes-sigs/external-dns#5671) - [@​hanapedia](https://github.com/hanapedia) made their first contribution in [#​5705](kubernetes-sigs/external-dns#5705) - [@​evilhamsterman](https://github.com/evilhamsterman) made their first contribution in [#​5696](kubernetes-sigs/external-dns#5696) - [@​dshatokhin](https://github.com/dshatokhin) made their first contribution in [#​5737](kubernetes-sigs/external-dns#5737) - [@​antchand](https://github.com/antchand) made their first contribution in [#​5648](kubernetes-sigs/external-dns#5648) - [@​ippanpeople](https://github.com/ippanpeople) made their first contribution in [#​5784](kubernetes-sigs/external-dns#5784) - [@​bachorp](https://github.com/bachorp) made their first contribution in [#​5787](kubernetes-sigs/external-dns#5787) **Full Changelog**: <kubernetes-sigs/external-dns@v0.18.0...v0.19.0> </details> --- ### Configuration 📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0MS45My4yIiwidXBkYXRlZEluVmVyIjoiNDEuOTMuMiIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiZGVwL21pbm9yIl19--> Reviewed-on: https://codeberg.org/JesusMtnez/homelab/pulls/805 Co-authored-by: JesusMtnez-bot <[email protected]> Co-committed-by: JesusMtnez-bot <[email protected]>

What does it do ?
Fixes an issue when you have the AWS_CA_BUNDLE set and are using the 'aws' provider. The error is as follows:
Motivation
This causes me a ton of headache recently and I was forced to use a Debian based container of the tool as opposed to the scratch based one.
More