forked from rook/rook
In createOrUpdateCephUser, when the desired user carries no explicit keys the reconciler falls back to the live RGW user's keys. If that live user also has zero keys the code intends to fail, but it built the error with errors.Wrapf(err, ...) at a point where err is already nil (the prior SetUserQuota error was handled and returned just above). errors.Wrapf(nil, ...) returns nil, so the failure was swallowed and createOrUpdateCephUser returned success on a user the operator itself flagged as broken. The reconcile then continued to generateCephUserSecret, which indexes userConfig.Keys[0] to populate the Kubernetes secret and panicked on the empty key slice. The reconciler's deferred RecoverAndLogException caught and logged that panic, so the reconcile was abandoned before it reached the Ready status update; and because the recovered Reconcile returns a zero Result with a nil error, the request was not requeued either. The user was left neither marked Ready nor retried. Construct the error with errors.Errorf so the intended failure is surfaced instead of being swallowed. Add a regression test that returns a keyless live user and asserts a non-nil "no keys set" error. Signed-off-by: Anas Khan <83116240+anxkhn@users.noreply.github.com> Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>