From 5f2dc42cd063a435d85e995f3a0c6695ed9c2317 Mon Sep 17 00:00:00 2001 From: Ahmed Gaber Date: Wed, 26 Aug 2026 16:05:29 +0100 Subject: [PATCH] feat(ingress-controller): support annotations on the webhook configuration The ValidatingWebhookConfiguration renders with no annotations, so external CA managers cannot be attached to it. With webhook.certificate.provided, operators supply a serving cert (commonly a cert-manager Certificate) but must hand-copy the CA into webhook.certificate.caBundle and re-copy it on rotation. An annotations knob lets cert-manager's cainjector own the caBundle instead (cert-manager.io/inject-ca-from), the standard pattern for webhook trust. --- charts/apisix-ingress-controller/Chart.yaml | 2 +- charts/apisix-ingress-controller/README.md | 1 + charts/apisix-ingress-controller/templates/webhook.yaml | 4 ++++ charts/apisix-ingress-controller/values.yaml | 4 ++++ 4 files changed, 10 insertions(+), 1 deletion(-) diff --git a/charts/apisix-ingress-controller/Chart.yaml b/charts/apisix-ingress-controller/Chart.yaml index 6863b4b7..93ed62b3 100644 --- a/charts/apisix-ingress-controller/Chart.yaml +++ b/charts/apisix-ingress-controller/Chart.yaml @@ -24,7 +24,7 @@ keywords: - nginx - crd type: application -version: 1.3.0 +version: 1.3.1 appVersion: 2.2.0 sources: - https://github.com/apache/apisix-helm-chart diff --git a/charts/apisix-ingress-controller/README.md b/charts/apisix-ingress-controller/README.md index e60da380..8523efba 100644 --- a/charts/apisix-ingress-controller/README.md +++ b/charts/apisix-ingress-controller/README.md @@ -171,6 +171,7 @@ The same for container level, you need to set: | serviceMonitor.namespace | string | `"monitoring"` | @param serviceMonitor.namespace Namespace in which to create the ServiceMonitor | | webhook.certificate.provided | bool | `false` | Set to true if you want to provide your own certificate | | webhook.enabled | bool | `true` | Enable or disable admission webhook | +| webhook.annotations | object | `{}` | Annotations for the ValidatingWebhookConfiguration, e.g. `cert-manager.io/inject-ca-from: /` so cert-manager's cainjector maintains the webhook caBundle. | | webhook.failurePolicy | string | `"Ignore"` | Failure policy for the webhook (Fail or Ignore) | | webhook.port | int | `9443` | The port for the webhook server to listen on | | webhook.timeoutSeconds | int | `10` | Timeout in seconds for the webhook | diff --git a/charts/apisix-ingress-controller/templates/webhook.yaml b/charts/apisix-ingress-controller/templates/webhook.yaml index 8944ea4e..d1bc479b 100644 --- a/charts/apisix-ingress-controller/templates/webhook.yaml +++ b/charts/apisix-ingress-controller/templates/webhook.yaml @@ -39,6 +39,10 @@ apiVersion: admissionregistration.k8s.io/v1 kind: ValidatingWebhookConfiguration metadata: name: {{ include "apisix-ingress-controller-manager.name.fullname" . }}-webhook + {{- with .Values.webhook.annotations }} + annotations: + {{- toYaml . | nindent 4 }} + {{- end }} labels: {{- include "apisix-ingress-controller-manager.labels" . | nindent 4 }} webhooks: diff --git a/charts/apisix-ingress-controller/values.yaml b/charts/apisix-ingress-controller/values.yaml index 519e3756..d2d6e203 100644 --- a/charts/apisix-ingress-controller/values.yaml +++ b/charts/apisix-ingress-controller/values.yaml @@ -105,6 +105,10 @@ config: webhook: # -- Enable or disable admission webhook enabled: true + # -- Annotations for the ValidatingWebhookConfiguration, e.g. + # `cert-manager.io/inject-ca-from: /` so + # cert-manager's cainjector maintains the webhook caBundle. + annotations: {} # -- The port for the webhook server to listen on port: 9443 # -- Failure policy for the webhook (Fail or Ignore)