Fixed
- Dex restarts when a referenced client Secret changes: the referenced Secrets (
clientSecretRefon a pre-defined client,secretRefon an extra client) are projected into the dex container as files, one per client, and the liveness probe compares each file with the environment variable dex started from; a rotated value fails the probe naming the client’s variable, the kubelet restarts the container and dex loads the new secret, about a minute after the Secret changed and without any other change. Before, dex kept the value it read at start-up until something else restarted it, and the client’s flows failed withinvalid_clientin between. Installations without referenced clients render unchanged; thechecksum/configroll on a configuration change is unchanged.