Bug 1420667

Summary: master.etcd-client.crt and master.etcd-client.key wouldn't be redeployed in embedded-etcd env
Product: OpenShift Container Platform Reporter: Gaoyun Pei <gpei>
Component: InstallerAssignee: Andrew Butcher <abutcher>
Status: CLOSED ERRATA QA Contact: Gaoyun Pei <gpei>
Severity: medium Docs Contact:
Priority: medium    
Version: 3.5.0CC: aos-bugs, jokerman, mmccomas, sreber
Target Milestone: ---   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Fixed In Version: Doc Type: No Doc Update
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2017-04-11 21:23:41 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Bug Depends On:    
Bug Blocks: 1397958    

Description Gaoyun Pei 2017-02-09 08:50:18 UTC
Description of problem:
For embedded-etcd env, certificate redeploy playbooks wouldn't redeploy the etcd client certificates files: master.etcd-client.crt and master.etcd-client.key.

Version-Release number of selected component (if applicable):

How reproducible:

Steps to Reproduce:
1.Run 'ansible-playbook -i host playbooks/byo/openshift-cluster/redeploy-etcd-certificates.yml'
'ansible-playbook -i host playbooks/byo/openshift-cluster/redeploy-master-certificates.yml'

Actual results:
It's a little hard to say which playbook should redeploy the two etcd client certificates files in embedded-etcd env, but none of them did that.

Expected results:

Additional info:

Comment 1 openshift-github-bot 2017-02-10 19:02:40 UTC
Commit pushed to master at https://github.com/openshift/openshift-ansible

Merge pull request #3331 from abutcher/embedded-etcd-client-cert

Bug 1420667: Ensure etcd client certs are regenerated with embedded etcd.

Comment 3 Gaoyun Pei 2017-02-12 03:33:20 UTC
Verify this bug with openshift-ansible-3.5.7-1.git.0.5010dec.el7.noarch.rpm

After redeploy master certificates in embedded-etcd env, master.etcd-client.crt and master.etcd-client.key files also were replaced.