Back to bug 2142902

Who When What Removed Added
OpenShift BugZilla Robot 2022-11-15 12:48:39 UTC Status NEW POST
OpenShift BugZilla Robot 2022-11-15 12:48:40 UTC Link ID Github red-hat-storage/rook/pull/429
Mudit Agarwal 2022-11-15 13:03:32 UTC CC muagarwa
Mudit Agarwal 2022-11-15 13:03:43 UTC Severity unspecified high
krishnaram Karthick 2022-11-21 05:57:33 UTC CC kramdoss
RHEL Program Management 2022-11-24 07:27:30 UTC Target Release --- ODF 4.10.10
OpenShift BugZilla Robot 2022-11-28 17:23:32 UTC Status POST MODIFIED
Rejy M Cyriac 2022-11-30 11:13:39 UTC CC rcyriac
Target Release ODF 4.10.10 ---
Sunil Kumar Acharya 2022-11-30 11:40:07 UTC CC sheggodu
RHEL Program Management 2022-12-15 07:28:33 UTC Target Release --- ODF 4.10.10
Sunil Kumar Acharya 2022-12-15 07:52:37 UTC Flags needinfo?(tnielsen)
Madhu Rajanna 2022-12-15 07:58:32 UTC Assignee tnielsen mrajanna
Doc Type If docs needed, set a value Bug Fix
Doc Text Cause:
A Liveness sidecar container deployed with the CSI pods will be helpful to check csi driver is appropriately responding or not. And there is no liveness or readiness kubernetes probe added for this one; it was running without TLS.

Consequence: services running without TLS might be problematic if customers are worried about security.

Fix: Disable the Liveness container in all cephCSI Pods.

Result: No service will be running in CephCSI pods without TLS, and one less container in cephCSI Pods.
Travis Nielsen 2022-12-19 17:45:26 UTC Flags needinfo?(tnielsen)
Red Hat Bugzilla 2022-12-31 19:54:50 UTC CC nberry
QA Contact nberry
Red Hat Bugzilla 2023-01-01 07:23:10 UTC CC tnielsen
Red Hat Bugzilla 2023-01-01 08:32:23 UTC CC kramdoss
Alasdair Kergon 2023-01-04 04:43:18 UTC QA Contact nberry
Alasdair Kergon 2023-01-04 05:07:00 UTC CC kramdoss
Alasdair Kergon 2023-01-04 05:18:56 UTC CC nberry
Alasdair Kergon 2023-01-04 05:49:38 UTC CC tnielsen
Sunil Kumar Acharya 2023-01-10 05:35:55 UTC Fixed In Version 4.10.10-1
Status MODIFIED ON_QA
krishnaram Karthick 2023-01-10 09:04:51 UTC QA Contact nberry dosypenk
Daniel Osypenko 2023-01-10 09:23:15 UTC Status ON_QA VERIFIED
Red Hat Bugzilla 2023-01-31 23:37:28 UTC CC madam
Kusuma 2023-02-20 11:05:26 UTC Doc Text Cause:
A Liveness sidecar container deployed with the CSI pods will be helpful to check csi driver is appropriately responding or not. And there is no liveness or readiness kubernetes probe added for this one; it was running without TLS.

Consequence: services running without TLS might be problematic if customers are worried about security.

Fix: Disable the Liveness container in all cephCSI Pods.

Result: No service will be running in CephCSI pods without TLS, and one less container in cephCSI Pods.
Previously, services running without the TLS was problematic if security was the main concern for the customers. This was because a Liveness sidecar container deployed with the CSI pods to check if CSI dirver is responding appropriately or not, was running without TLS.

With this fix, Liveness container in all Ceph CSI pods are disabled and as a result, no service is running in Ceph CSI pods without TLS, and one less container in Ceph CSI pods.
CC kbg
errata-xmlrpc 2023-02-20 14:34:20 UTC Status VERIFIED RELEASE_PENDING
errata-xmlrpc 2023-02-20 15:40:44 UTC Status RELEASE_PENDING CLOSED
Resolution --- ERRATA
Last Closed 2023-02-20 15:40:44 UTC
errata-xmlrpc 2023-02-20 15:40:50 UTC Link ID Red Hat Product Errata RHBA-2023:0827
Elad 2023-08-09 17:03:01 UTC CC odf-bz-bot

Back to bug 2142902