Bug 1542162

Summary: [3.7] redeploy_node_certificates.yaml restarts docker daemon
Product: OpenShift Container Platform Reporter: Scott Dodson <sdodson>
Component: InstallerAssignee: Scott Dodson <sdodson>
Status: CLOSED ERRATA QA Contact: Gaoyun Pei <gpei>
Severity: high Docs Contact:
Priority: unspecified    
Version: 3.7.0CC: abutcher, aos-bugs, dmoessne, farandac, gpei, joboyer, jokerman, mmccomas
Target Milestone: ---   
Target Release: 3.7.z   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
The docker daemon was incorrectly restarted when redeploying node certificates. This is only necessary when deploying a new CA and can safely be skipped which ensures that running pods are not restarted when updating node certificates.
Story Points: ---
Clone Of: 1537726 Environment:
Last Closed: 2018-04-05 09:38:31 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Bug Depends On: 1537726    
Bug Blocks:    

Comment 2 Scott Dodson 2018-02-05 17:55:04 UTC
In openshift-ansible-3.9.0-0.36.0 and later

Comment 3 Gaoyun Pei 2018-02-06 07:38:30 UTC
Verify this bug with openshift-ansible-3.7.28-1.git.0.12b5132.el7.noarch

Run node cert redeployment playbook, docker was not restart during redeployment.
ansible-playbook -i host -v /usr/share/ansible/openshift-ansible/playbooks/byo/openshift-cluster/redeploy-node-certificates.yml


PLAY [Restart nodes] ********************************************************************************************************************************************************

TASK [Gathering Facts] ******************************************************************************************************************************************************
ok: [qe-gpei-node-registry-router-1.0206-gh1.qe.rhcloud.com]

TASK [Restart docker] *******************************************************************************************************************************************************
skipping: [qe-gpei-node-registry-router-1.0206-gh1.qe.rhcloud.com] => {"changed": false, "skip_reason": "Conditional result was False"}

Comment 7 errata-xmlrpc 2018-04-05 09:38:31 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2018:0636