tailscale/kube
Tom Meadows 044221b8c6
kube/certs: discover TLS domains from TCP TerminateTLS handlers (#19020) (#19021)
After #18179 switched to L4 TCPForward, EnsureCertLoops found no
domains since it only checked service.Web entries. Certs were never
provisioned, leaving kube-apiserver ProxyGroups stuck at 0/N ready.

Fixes #19019


(cherry picked from commit a565833998)

Signed-off-by: Raj Singh <raj@tailscale.com>
Co-authored-by: Raj Singh <raj@tailscale.com>
2026-03-19 11:49:36 +00:00
..
certs kube/certs: discover TLS domains from TCP TerminateTLS handlers (#19020) (#19021) 2026-03-19 11:49:36 +00:00
egressservices all: remove AUTHORS file and references to it 2026-01-23 15:49:45 -08:00
health all: remove AUTHORS file and references to it 2026-01-23 15:49:45 -08:00
ingressservices all: remove AUTHORS file and references to it 2026-01-23 15:49:45 -08:00
k8s-proxy/conf all: remove AUTHORS file and references to it 2026-01-23 15:49:45 -08:00
kubeapi all: remove AUTHORS file and references to it 2026-01-23 15:49:45 -08:00
kubeclient all: remove AUTHORS file and references to it 2026-01-23 15:49:45 -08:00
kubetypes cmd/{containerboot,k8s-operator}: reissue auth keys for broken proxies (#16450) (#18962) 2026-03-11 12:50:02 +00:00
localclient cmd/containerboot,kube: enable autoadvertisement of Tailscale services on containerboot (#18527) 2026-02-20 15:52:34 -08:00
metrics all: remove AUTHORS file and references to it 2026-01-23 15:49:45 -08:00
services cmd/containerboot,kube: enable autoadvertisement of Tailscale services on containerboot (#18527) 2026-02-20 15:52:34 -08:00
state all: remove AUTHORS file and references to it 2026-01-23 15:49:45 -08:00