Skip to content

Commit

Permalink
backport of commit 18a8217
Browse files Browse the repository at this point in the history
  • Loading branch information
tgross committed Nov 3, 2022
1 parent 37c0067 commit 3403951
Show file tree
Hide file tree
Showing 3 changed files with 13 additions and 2 deletions.
3 changes: 3 additions & 0 deletions .changelog/15121.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
wi: Fixed a bug where clients running pre-1.4.0 allocations would erase the token used to query service registrations after upgrade
```
8 changes: 6 additions & 2 deletions client/allocrunner/taskrunner/identity_hook.go
Original file line number Diff line number Diff line change
Expand Up @@ -36,7 +36,9 @@ func (h *identityHook) Prestart(ctx context.Context, req *interfaces.TaskPrestar
defer h.lock.Unlock()

token := h.tr.alloc.SignedIdentities[h.taskName]
h.tr.setNomadToken(token)
if token != "" {
h.tr.setNomadToken(token)
}
return nil
}

Expand All @@ -45,6 +47,8 @@ func (h *identityHook) Update(_ context.Context, req *interfaces.TaskUpdateReque
defer h.lock.Unlock()

token := h.tr.alloc.SignedIdentities[h.taskName]
h.tr.setNomadToken(token)
if token != "" {
h.tr.setNomadToken(token)
}
return nil
}
4 changes: 4 additions & 0 deletions client/allocrunner/taskrunner/task_runner.go
Original file line number Diff line number Diff line change
Expand Up @@ -424,6 +424,10 @@ func NewTaskRunner(config *Config) (*TaskRunner, error) {
return nil, err
}

// Use the client secret only as the initial value; the identity hook will
// update this with a workload identity if one is available
tr.setNomadToken(config.ClientConfig.Node.SecretID)

// Initialize the runners hooks. Must come after initDriver so hooks
// can use tr.driverCapabilities
tr.initHooks()
Expand Down

0 comments on commit 3403951

Please sign in to comment.