Bug 1395282

Summary: java NPE (appy/create/bulk) - Searchguard plugin
Product: OpenShift Container Platform Reporter: Ricardo Lourenco <rlourenc>
Component: LoggingAssignee: ewolinet
Status: CLOSED NOTABUG QA Contact: Xia Zhao <xiazhao>
Severity: high Docs Contact:
Priority: medium    
Version: 3.3.0CC: aos-bugs, jcantril, lvlcek, rlourenc, tstclair
Target Milestone: ---   
Target Release: ---   
Hardware: x86_64   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2017-01-09 14:20:53 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Attachments:
Description Flags
es data node
none
es master node
none
_cat_allocation none

Description Ricardo Lourenco 2016-11-15 15:25:22 UTC
Created attachment 1220861 [details]
es data node

Description of problem:

During scale-out testing of logging (205 nodes) the following NPE appeared in the elasticsearch logs

Comment 1 Ricardo Lourenco 2016-11-15 15:27:07 UTC
Created attachment 1220863 [details]
es master node

Comment 2 Ricardo Lourenco 2016-11-15 15:32:02 UTC
Created attachment 1220865 [details]
_cat_allocation

Comment 5 ewolinet 2016-11-15 15:51:02 UTC
In the master ES logs, are there entries regarding the searchguard index being created/updated? We should see a different entry for each ES cluster node.

In the past we've seen that not having the ACLs configured yet has been cause for those NPE stack traces to be emitted from Searchguard.

Comment 6 Jeff Cantrill 2016-11-16 14:03:10 UTC
I think this is an error from us not handling a failure scenario properly: https://github.com/fabric8io/openshift-elasticsearch-plugin/blob/ES1.5.x/src/main/java/io/fabric8/elasticsearch/plugin/ActionForbiddenActionFilter.java#L57  likely related to the seeding problem mentioned by @eric.

Comment 8 Ricardo Lourenco 2016-11-16 15:33:33 UTC
Nothing in the logs regarding ACL configuration.

The master logs are attached to this BZ:
https://bugzilla.redhat.com/attachment.cgi?id=1220863

Comment 15 Ricardo Lourenco 2017-01-08 15:54:05 UTC
@Eric,

That's fine by me, I didn't see this error thus far.