For a Service with http-certificate-type: managed, reconcileManagedCertificate issues a POST /certificates on every single reconcilement and just swallows the resulting uniqueness error, even though the certificate is looked up by its service-UID label right afterwards anyway.
We should look it up first and only create it when it is missing (still tolerating ErrAlreadyExists for the concurrent-create race), which cuts the steady state from a guaranteed-to-fail write plus a list down to a single list.
We can probably reuse our cache package here.
For a Service with http-certificate-type:
managed,reconcileManagedCertificateissues aPOST /certificateson every single reconcilement and just swallows the resulting uniqueness error, even though the certificate is looked up by its service-UID label right afterwards anyway.We should look it up first and only create it when it is missing (still tolerating ErrAlreadyExists for the concurrent-create race), which cuts the steady state from a guaranteed-to-fail write plus a list down to a single list.
We can probably reuse our cache package here.