fix: sanitize wildcard hostnames in certificate resource ID for ACM tags#4846
fix: sanitize wildcard hostnames in certificate resource ID for ACM tags#4846Dasmat13 wants to merge 1 commit into
Conversation
Signed-off-by: Dasmat13 <gptdasmat@gmail.com>
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: Dasmat13 The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
|
Hi @Dasmat13. Thanks for your PR. I'm waiting for a kubernetes-sigs member to verify that this patch is reasonable to test. If it is, they should reply with Tip We noticed you've done this a few times! Consider joining the org to skip this step and gain Once the patch is verified, the new status will be reflected by the I understand the commands that are listed here. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
Description
This pull request resolves a bug where ACM certificate requests fail for Ingresses with wildcard hostnames due to invalid character restrictions in AWS tag values (#4836).
The certificate
resourceIDembeds theDomainNameand is used as theingress.k8s.aws/resourcetracking tag value. However, AWS ACM API validation rejects*in tag values ([\p{L}\p{Z}\p{N}_.:/=+\-@]*), causingRequestCertificatecalls to fail with a400 ValidationExceptionfor wildcard host configurations.This change sanitizes the
resourceIDby replacing the*character with"wildcard"inbuildCertificateResourceID(). The actualDomainNameandSubjectAlternativeNamessent to ACM remain unchanged, ensuring certificate coverage is unaffected while preventing the validation failure.Testing
buildCertificateResourceID().test/e2e/ingress/acm_ingress_test.goexercising wildcard-host Ingress certificate validation.go test ./pkg/...) pass successfully.