Bug 1602120
Summary: | [Term based registry] Installer fails to authenticate against prod secure registry | ||||||
---|---|---|---|---|---|---|---|
Product: | OpenShift Container Platform | Reporter: | Vikas Laad <vlaad> | ||||
Component: | Installer | Assignee: | Michael Gugino <mgugino> | ||||
Status: | CLOSED ERRATA | QA Contact: | Johnny Liu <jialiu> | ||||
Severity: | medium | Docs Contact: | |||||
Priority: | unspecified | ||||||
Version: | 3.11.0 | CC: | aos-bugs, dma, dmoessne, jiajliu, jokerman, mjahangi, mmccomas, shlao, wmeng, xtian, zitang | ||||
Target Milestone: | --- | ||||||
Target Release: | 3.11.0 | ||||||
Hardware: | Unspecified | ||||||
OS: | Unspecified | ||||||
Whiteboard: | |||||||
Fixed In Version: | Doc Type: | If docs needed, set a value | |||||
Doc Text: | Story Points: | --- | |||||
Clone Of: | Environment: | ||||||
Last Closed: | 2018-10-11 07:21:41 UTC | Type: | Bug | ||||
Regression: | --- | Mount Type: | --- | ||||
Documentation: | --- | CRM: | |||||
Verified Versions: | Category: | --- | |||||
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||
Cloudforms Team: | --- | Target Upstream Version: | |||||
Embargoed: | |||||||
Bug Depends On: | 1612104 | ||||||
Bug Blocks: | |||||||
Attachments: |
|
Description
Vikas Laad
2018-07-17 20:28:00 UTC
Aside from I think we're validating incorrect variables. https://github.com/openshift/openshift-ansible/pull/9237 Will also need this patch: https://github.com/openshift/openshift-ansible/pull/9244 Currently, oreg_host is equal to '' if not oreg_url is not explicitly set in inventory; this is the value used for which registry to create credentials to. Patch updates to account for new enterprise reg. I also hit the same issue, openshift-ansible-3.11.0-0.7.0.git.0.6e3e78eNone.noarch + ansible-2.6. Inventory file and installation log will be attached soon. This is blocking QE's testing. Created attachment 1464871 [details]
installation log with inventory file embedded
I also tested it with the latest openshift-ansible master branch (the last commit id: ec178734d6e555a87f66e2cc9ced23d854b5c9ba), also reproduce. PR merged in master. The PR is available since openshift-ansible-3.11.0-0.8.0 I need to get some patches out to resolve this. For now, workaround, set following inv var: oreg_test_login: False Retest with openshift-ansible-3.11.0-0.10.0.git.0.91bb588None.noarch + "registry.dev.redhat.io" registry + "oreg_test_login=false" setting in inventory file, still reproduced. Also hit the issue on openshift-ansible-3.11.0-0.10.0.git.0.91bb588None.noarch when do upgrade test with "registry.redhat.io" registry and correct oreg_auth_user+oreg_auth_password. Based on comment 22, found workaround, removing testblocker keyword. https://github.com/openshift/openshift-ansible/pull/9490 follow up fixes This issue should be fixed on openshift-ansible-3.11.0-0.13.0.git.0.16dc599None.noarch. But upgrade still failed for another blocker bug 1612144. Should be in openshift-ansible-3.11.0-0.15.0 Verified this bug with openshift-ansible-3.11.0-0.15.0.git.0.842d3d1None + "5318290|aosqeaosqe" as oreg_auth_user, and PASS. TASK [container_runtime : Create credentials for docker cli registry auth (alternative)] *** Wednesday 15 August 2018 16:06:51 +0800 (0:00:02.721) 0:01:56.806 ****** FAILED - RETRYING: Create credentials for docker cli registry auth (alternative) (3 retries left). FAILED - RETRYING: Create credentials for docker cli registry auth (alternative) (2 retries left). changed: [host-8-252-102.host.centralci.eng.rdu2.redhat.com] => {"attempts": 3, "changed": true, "rc": 0} Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2018:2652 |