From 430bd79bed35701a3f9932735918cce6123de59c Mon Sep 17 00:00:00 2001 From: Suriya Date: Mon, 20 Jul 2026 11:31:08 +0530 Subject: [PATCH] Revert --token-ttl=0 on dashboard - broke login entirely Login stopped working the moment this shipped. Suspect this dashboard version treats token-ttl=0 as "expire immediately" rather than "never expire". Reverting to the default (900s) to restore working login; the idle-timeout annoyance can be revisited with a large finite value instead of 0, tested before shipping. Co-Authored-By: Claude Sonnet 5 --- manifests/alaska/k8s-dashboard.yaml | 13 ++++++------- 1 file changed, 6 insertions(+), 7 deletions(-) diff --git a/manifests/alaska/k8s-dashboard.yaml b/manifests/alaska/k8s-dashboard.yaml index 3de5b97..7b6bca0 100644 --- a/manifests/alaska/k8s-dashboard.yaml +++ b/manifests/alaska/k8s-dashboard.yaml @@ -62,13 +62,12 @@ spec: args: - --auto-generate-certificates - --namespace=kubernetes-dashboard - # Disables the default 15-minute idle session timeout, so a - # logged-in session persists instead of dropping back to the - # token screen. The service account token itself already - # doesn't expire (it's a Secret-backed legacy token, not a - # short-lived TokenRequest one) - this was purely the - # dashboard's own session cache. - - --token-ttl=0 + # --token-ttl=0 was tried here to disable the 15-min idle + # timeout, but login broke immediately after that pod came up - + # in this dashboard version, 0 appears to mean "expire + # immediately" rather than "never expire". Reverted; back to + # the default 900s timeout until a properly-tested value (e.g. + # a long finite number of seconds) is confirmed safe. volumeMounts: - name: kubernetes-dashboard-certs mountPath: /certs