go.mod: bump sigs.k8s.io/controller-runtime to v0.23.3
PR #20388 (commit ca9f6971e) bumped k8s.io/* from v0.34 to v0.35 as a transitive effect of pulling in helm v3.21 (for containerd CVE fixes). The old controller-runtime v0.19.4 is aligned with k8s 1.31 APIs and regresses at runtime against v0.35 client-go (informer reflectors stall on Watch responses), leaving the operator unable to reconcile. v0.23.3 is the release aligned with k8s.io/* v0.35 / Kubernetes 1.35. The operator uses a narrow slice of controller-runtime (manager + builder + client + reconcile + handler + source), so this bump is a lift-and-shift: no reconciler wiring changes needed. Test scaffolding fix: controller-runtime v0.20+ populates TypeMeta (Kind/APIVersion) on objects returned by the fake client. The shared expectEqual helper now strips TypeMeta before diffing so existing tests continue to work without needing every 'want' object updated. Tested: deployed to live clusters across Kubernetes 1.33, 1.34, 1.35, and 1.36 (identical build per cluster). Verified the operator starts and reconciles cleanly on all versions with no RBAC/forbidden errors, CRDs establish and enforce validation, and the field indexers resolve correctly under annotation churn (no stale-index misrouting). Exercised the Service, ProxyClass, Connector, egress (simple + ProxyGroup, incl. the EndpointSlice reconciler), and HA ingress-for-pg reconcilers. Confirmed informer/watch recovery after an API server restart forces a re-list/re-watch (the exact regression this bump fixes). Updates tailscale/corp#44898 Signed-off-by: chaosinthecrd <tom@tmlabs.co.uk>
C
chaosinthecrd committed
33042fb97b3224bbc07c1494da01fb391f99e48d
Parent: 014d5bd