From 3099e0f16e1ffdb5f7602afe4d29de11ab9c1793 Mon Sep 17 00:00:00 2001 From: Nicu Reut Date: Thu, 19 Jun 2025 10:19:03 +0000 Subject: [PATCH] [force] Use latest secret version when reading dns secret Signed-off-by: Nicu Reut --- cluster/expected/infra/expected.json | 2 +- cluster/pulumi/infra/src/network.ts | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/cluster/expected/infra/expected.json b/cluster/expected/infra/expected.json index f7a2a767a1..4d9fc56d6b 100644 --- a/cluster/expected/infra/expected.json +++ b/cluster/expected/infra/expected.json @@ -616,7 +616,7 @@ }, { "custom": true, - "id": "projects/da-cn-devnet/secrets/dns01-sa-key-secret/versions/1", + "id": "projects/da-cn-devnet/secrets/dns01-sa-key-secret/versions/latest", "inputs": {}, "name": "dns01-sa-key-secret", "provider": "", diff --git a/cluster/pulumi/infra/src/network.ts b/cluster/pulumi/infra/src/network.ts index 98a6da2f6e..29f6c4e759 100644 --- a/cluster/pulumi/infra/src/network.ts +++ b/cluster/pulumi/infra/src/network.ts @@ -180,7 +180,7 @@ function clusterCertificate( gcp.secretmanager.SecretVersion.get( 'dns01-sa-key-secret', - `projects/${GCP_PROJECT}/secrets/${gcpSecretName}/versions/1` + `projects/${GCP_PROJECT}/secrets/${gcpSecretName}/versions/latest` ).secretData.apply(dns01SaKeySecret => { new k8s.core.v1.Secret( 'clouddns-dns01-solver-svc-acct',