From 798535164ae11a7e3c036ed7793aa884942edc88 Mon Sep 17 00:00:00 2001 From: "Dr. Stefan Schimanski" Date: Wed, 4 Jul 2018 19:09:26 +0200 Subject: [PATCH] apiserver: don't create self-signed certs with disabled secure serving --- staging/src/k8s.io/apiserver/pkg/server/options/serving.go | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/staging/src/k8s.io/apiserver/pkg/server/options/serving.go b/staging/src/k8s.io/apiserver/pkg/server/options/serving.go index 5d21da26179..ee9cebacd04 100644 --- a/staging/src/k8s.io/apiserver/pkg/server/options/serving.go +++ b/staging/src/k8s.io/apiserver/pkg/server/options/serving.go @@ -236,7 +236,7 @@ func (s *SecureServingOptions) ApplyTo(config **server.SecureServingInfo) error } func (s *SecureServingOptions) MaybeDefaultWithSelfSignedCerts(publicAddress string, alternateDNS []string, alternateIPs []net.IP) error { - if s == nil { + if s == nil || (s.BindPort == 0 && s.Listener == nil) { return nil } keyCert := &s.ServerCert.CertKey