Component rebuild timing and mechanics

After updating istio-mesh-mode in the Cloudera Data Warehouse ConfigMap and restarting the Cloudera Data Warehouse server and worker deployments, you must rebuild all existing Database Catalogs and Virtual Warehouses before resuming workload traffic.

  • Namespace label propagation: Restarting the Cloudera Data Warehouse server and worker deployments allows the system to load updated configuration settings, but it does not update existing Kubernetes namespaces. Triggering a rebuild calls UpdateNamespace, which propagates and updates Istio labels on existing namespaces. Full environment deactivation and reactivation is not required.
  • Preventing mTLS mismatches: If components are not rebuilt, mixed Istio label states will exist across the environment. This mTLS configuration mismatch causes cross-namespace communication failures such as between a Virtual Warehouse and the Database Catalog metastore.
  • Rebuild sequence: Individual Database Catalogs and Virtual Warehouses can be rebuilt in any order, provided all components are rebuilt before serving production traffic.