Skip to content

馃悰 Increase default server IdleTimeout to 120s - #3616

Merged
kubernetes-prow[bot] merged 1 commit into
kubernetes-sigs:mainfrom
jdymitarai:fix-webhook-idle-timeout
Oct 5, 2026
Merged

kubernetes-prow[bot] merged 1 commit into
kubernetes-sigs:mainfrom
jdymitarai:fix-webhook-idle-timeout

Conversation

@jdymitarai

Copy link
Copy Markdown
Contributor

When kube-apiserver communicates with admission webhooks over HTTP/1.1, client-go uses http.DefaultTransport's 90s idle timeout. Because controller-runtime's internal httpserver also defaulted IdleTimeout to 90s, both sides close idle connections at approximately the same time, leading to intermittent EOF / broken pipe transport errors on reused connections.

This increases the default server IdleTimeout to 120s so that clients initiate closing idle connections before the server drops them.

Fixes #3614

@kubernetes-prow kubernetes-prow Bot added the cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. label Oct 3, 2026
@kubernetes-prow

Copy link
Copy Markdown
Contributor

Welcome @jdymitarai!

It looks like this is your first PR to kubernetes-sigs/controller-runtime 馃帀. Please refer to our pull request process documentation to help your PR have a smooth ride to approval.

You will be prompted by a bot to use commands during the review process. Do not be afraid to follow the prompts! It is okay to experiment. Here is the bot commands documentation.

You can also check if kubernetes-sigs/controller-runtime has its own contribution guidelines.

You may want to refer to our testing guide if you run into trouble with your tests not passing.

If you are having difficulty getting your pull request seen, please follow the recommended escalation practices. Also, for tips and tricks in the contribution process you may want to read the Kubernetes contributor cheat sheet. We want to make sure your contribution gets all the attention it needs!

Thank you, and welcome to Kubernetes. 馃槂

@kubernetes-prow kubernetes-prow Bot added the needs-ok-to-test Indicates a PR that requires an org member to verify it is safe to test. label Oct 3, 2026
@kubernetes-prow

Copy link
Copy Markdown
Contributor

Hi @jdymitarai. Thanks for your PR.

I'm waiting for a kubernetes-sigs member to verify that this patch is reasonable to test. If it is, they should reply with /ok-to-test on its own line. Until that is done, I will not automatically test new commits in this PR, but the usual testing commands by org members will still work.

Regular contributors should join the org to skip this step.

Once the patch is verified, the new status will be reflected by the ok-to-test label.

I understand the commands that are listed here.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@kubernetes-prow kubernetes-prow Bot added the size/M Denotes a PR that changes 30-99 lines, ignoring generated files. label Oct 3, 2026

@alvaroaleman alvaroaleman left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks

@kubernetes-prow kubernetes-prow Bot added the lgtm "Looks good to me", indicates that a PR is ready to be merged. label Oct 3, 2026
@kubernetes-prow

Copy link
Copy Markdown
Contributor

LGTM label has been added.

DetailsGit tree hash: 80ab6469f84b86a1e9516464902891eb29f141a1

@kubernetes-prow

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: alvaroaleman, jdymitarai

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@kubernetes-prow kubernetes-prow Bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Oct 3, 2026
@alvaroaleman

Copy link
Copy Markdown
Member

/hold
so @sbueringer can have a look

@kubernetes-prow kubernetes-prow Bot added the do-not-merge/hold Indicates that a PR should not merge because someone has issued a /hold command. label Oct 3, 2026
@jdymitarai
jdymitarai force-pushed the fix-webhook-idle-timeout branch from 18a9ec6 to 06a9101 Compare October 3, 2026 05:42
@kubernetes-prow kubernetes-prow Bot removed the lgtm "Looks good to me", indicates that a PR is ready to be merged. label Oct 3, 2026
@kubernetes-prow
kubernetes-prow Bot requested a review from alvaroaleman October 3, 2026 05:42
@jdymitarai

Copy link
Copy Markdown
Contributor Author

/test pull-controller-runtime-test

@kubernetes-prow

Copy link
Copy Markdown
Contributor

@jdymitarai: Cannot trigger testing until a trusted user reviews the PR and leaves an /ok-to-test message.

Details

In response to this:

/test pull-controller-runtime-test

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@jdymitarai

jdymitarai commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor Author

Updated the unit test to use t.Context() instead of context.Background() to resolve the forbidigo linter failure. Could an org member please re-trigger /ok-to-test? Thanks!

@alvaroaleman

Copy link
Copy Markdown
Member

/test pull-controller-runtime-test

@jdymitarai
jdymitarai force-pushed the fix-webhook-idle-timeout branch from 06a9101 to 13ba018 Compare October 4, 2026 00:08
When kube-apiserver makes admission calls to webhook servers over HTTP/1.1, the client-go transport uses http.DefaultTransport's 90s idle timeout. Because controller-runtime's internal httpserver also set IdleTimeout to 90s, both client and server close idle connections at approximately the same time, leading to intermittent EOF / broken pipe failures during admission requests.

Increase the default server IdleTimeout to 120s so the client initiates closing idle connections first.

Signed-off-by: jdymitarai <o10040115@gmail.com>
@jdymitarai
jdymitarai force-pushed the fix-webhook-idle-timeout branch from 13ba018 to 9eede03 Compare October 4, 2026 08:01
@jdymitarai

Copy link
Copy Markdown
Contributor Author

Updated the suite and test to \package httpserver\ with Ginkgo \SpecContext\ so that the test binary registers Ginkgo flags properly and complies with \ orbidigo. Could an org member please re-trigger /ok-to-test? Thanks!

@sbueringer

sbueringer commented Oct 5, 2026 •

Copy link
Copy Markdown
Member

/ok-to-test
/lgtm

/hold cancel

Thx!

@kubernetes-prow kubernetes-prow Bot added ok-to-test Indicates a non-member PR verified by an org member that is safe to test. and removed do-not-merge/hold Indicates that a PR should not merge because someone has issued a /hold command. needs-ok-to-test Indicates a PR that requires an org member to verify it is safe to test. labels Oct 5, 2026
@kubernetes-prow kubernetes-prow Bot added the lgtm "Looks good to me", indicates that a PR is ready to be merged. label Oct 5, 2026
@kubernetes-prow

Copy link
Copy Markdown
Contributor

LGTM label has been added.

DetailsGit tree hash: 7aa9da4431f5486120ff55b72a78df660b1c451f

@kubernetes-prow
kubernetes-prow Bot merged commit 38fe15b into kubernetes-sigs:main Oct 5, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. lgtm "Looks good to me", indicates that a PR is ready to be merged. ok-to-test Indicates a non-member PR verified by an org member that is safe to test. size/M Denotes a PR that changes 30-99 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Webhook server IdleTimeout (90s) equals kube-apiserver's client idle timeout, so admission calls intermittently fail with EOF

3 participants