Bug 1837123
| Summary: | redeploy-certificates.yaml did not update certificates properly | ||
|---|---|---|---|
| Product: | OpenShift Container Platform | Reporter: | Brandon Smitley <bsmitley> |
| Component: | Installer | Assignee: | Russell Teague <rteague> |
| Installer sub component: | openshift-ansible | QA Contact: | Gaoyun Pei <gpei> |
| Status: | CLOSED ERRATA | Docs Contact: | |
| Severity: | high | ||
| Priority: | high | CC: | adahiya, aos-bugs, bleanhar, mfojtik, openshift-bugs-escalate, rbost, slaznick, takirby |
| Version: | 3.11.0 | ||
| Target Milestone: | --- | ||
| Target Release: | 3.11.z | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | Bug Fix | |
| Doc Text: |
Adds a check of the master-config.yaml to determine if the client.CA has
been reverted. If not, the play will fail indicating
openshift_redeploy_openshift_ca=true must be set in the inventory.
This check will prevent inadvertant certificate redeploy when the
OpenShift CA has been updated and not rolled out.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | 2020-10-22 11:02:22 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
Brandon Smitley
2020-05-18 21:26:59 UTC
Moving to the ansible team, I do not know what the playbook actually does. To be reviewed as part of https://issues.redhat.com/browse/CORS-1470 Jira issue https://issues.redhat.com/browse/CORS-1470 was not scheduled for the current sprint. Verify this bug with openshift-ansible-3.11.299-1.git.0.2dfaf92.el7.noarch.rpm.
1. Redeploy openshift CA
ansible-playbook openshift-ansible/playbooks/openshift-master/redeploy-openshift-ca.yml -v
2. Redeploy openshift certificates
ansible-playbook openshift-ansible/playbooks/redeploy-certificates.yml -v
09-29 22:11:48 TASK [Check servingInfo.clientCA = ca.crt in master config] ********************
09-29 22:11:48 fatal: [ec2-52-90-69-73.compute-1.amazonaws.com]: FAILED! => {"changed": false, "msg": "Detected an incomplete OpenShift CA redeployment. Please set openshift_redeploy_openshift_ca=true in the inventory and re-run redeploy-certifcates.yml\n"}
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory (OpenShift Container Platform 3.11.306 bug fix and enhancement update), and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2020:4170 |