Bug 1658003
Summary: | Document Redeploy of EFK certificates | ||
---|---|---|---|
Product: | OpenShift Container Platform | Reporter: | sfu <sfu> |
Component: | Documentation | Assignee: | Michael Burke <mburke> |
Status: | CLOSED CURRENTRELEASE | QA Contact: | Anping Li <anli> |
Severity: | unspecified | Docs Contact: | Vikram Goyal <vigoyal> |
Priority: | unspecified | ||
Version: | 3.9.0 | CC: | aos-bugs, ewolinet, jcantril, jokerman, mburke, mmccomas, rmeggins |
Target Milestone: | --- | Keywords: | Reopened |
Target Release: | 3.11.z | ||
Hardware: | Unspecified | ||
OS: | Unspecified | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | If docs needed, set a value | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2019-01-02 16:12:27 UTC | Type: | Bug |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
sfu@redhat.com
2018-12-11 01:47:42 UTC
Closing WONTFIX. It is possible to rerun ansible which should redeploy with updated certificates. After rerun the /usr/share/ansible/openshift-ansible/playbooks/openshift-logging/config.yml ansible script, the cert will not update. such as /etc/elasticsearch/secret/admin-ca admin-cert in es pod. the content are same after rerun. @Eric, Can you comment about how the certs should be regenerated. You will need to first remove the certificates that are stored on your `oo_first_master` node, they will be in the path {/location/of/your/base/ocp/install}/logging. The ansible role will create new certificates if they do not exist here, it should then go through and recreate the secrets with these new certificates. Converting to a docs bug so we can identify it properly @Xiaoli Please take a look. https://github.com/openshift/openshift-docs/pull/13107/ |