forked from rook/rook
Our admission webhooks will now run as part of the Operator container and not an additional deployment. This has the advantage of consuming fewer resources in the cluster and not having to manage affinities and tolerations. This only drawback is that the Secret containing the certificates is not mounted anymore and the content needs to be written inside the Operator. This is not practical since we also need to watch for the Secret content to change. Meaning that the certificates have been renewed and the webhook server needs to use them. A new approach is on its way to hopefully simplify this last issue and implement a watcher for the Secret. In the meantime, users need to use the cert-manager or renew certificates manually. Additionally, they must update the ValidatingWebhookConfiguration object with the new CA bundle. Signed-off-by: Sébastien Han <seb@redhat.com>