keep LB addons' settings unchanged unless explicitly specified #3800
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Issue
resolves #3780
Description
This PR changes the behavior of annotations related to Application LoadBalancer add-ons:
alb.ingress.kubernetes.io/waf-acl-id
alb.ingress.kubernetes.io/wafv2-acl-arn
alb.ingress.kubernetes.io/shield-advanced-protection
Previous, when those annotations is not specified, the controller will make sure those add-ons don't exists on loadBalancer, i.e. delete all existing WAFClassic/WAFv2/ShieldProtection.
We have decided to change the behavior such that if those annotations is not specified or empty, the controller will keep the existing add-ons(if any) unchanged. And users have to explicitly disable add-ons via annotations:
alb.ingress.kubernetes.io/waf-acl-id: none
alb.ingress.kubernetes.io/wafv2-acl-arn: none
alb.ingress.kubernetes.io/shield-advanced-protection: false
Checklist
README.md
, or thedocs
directory)BONUS POINTS checklist: complete for good vibes and maybe prizes?! 🤯