implement kyverno admission webhook - crossplane.io/external-name
cannot be changed once created
#3198
haarchri
started this conversation in
Knowledge base
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
due to a misconfiguration in one of our composition we accidentally created a lot kms cmk keys in our aws accounts which let to a huge amount of unintended cost and a lot of work to cleanup the unused keys.
the problem here is that the id/external-name for a kms-key is created by aws - and provider-aws is still re-creating the kms-key after every composition reconciliation... :/ because of the following patch:
please not do this 👎 in your composition patches ;)
directly after we added a kyverno admission webhook - that the
crossplane.io/external-name
cannot be changed once created like:Beta Was this translation helpful? Give feedback.
All reactions