Bug 1848956
| Summary: | KMP requires downtime for CA stabilization during certificate rotation | ||||||||
|---|---|---|---|---|---|---|---|---|---|
| Product: | Container Native Virtualization (CNV) | Reporter: | Geetika Kapoor <gkapoor> | ||||||
| Component: | Networking | Assignee: | Petr Horáček <phoracek> | ||||||
| Status: | CLOSED ERRATA | QA Contact: | Ofir Nash <onash> | ||||||
| Severity: | medium | Docs Contact: | |||||||
| Priority: | medium | ||||||||
| Version: | 2.4.0 | CC: | cnv-qe-bugs, ncredi, onash | ||||||
| Target Milestone: | --- | ||||||||
| Target Release: | 2.6.0 | ||||||||
| Hardware: | Unspecified | ||||||||
| OS: | Unspecified | ||||||||
| Whiteboard: | |||||||||
| Fixed In Version: | cluster-network-addons-operator-container-v2.5.0-8 | Doc Type: | If docs needed, set a value | ||||||
| Doc Text: | Story Points: | --- | |||||||
| Clone Of: | Environment: | ||||||||
| Last Closed: | 2021-03-10 11:16:12 UTC | Type: | Bug | ||||||
| Regression: | --- | Mount Type: | --- | ||||||
| Documentation: | --- | CRM: | |||||||
| Verified Versions: | Category: | --- | |||||||
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||||
| Cloudforms Team: | --- | Target Upstream Version: | |||||||
| Embargoed: | |||||||||
| Attachments: |
|
||||||||
|
Description
Geetika Kapoor
2020-06-19 11:33:10 UTC
Thanks for opening this. Since the rotation interval is quite long and the downtime happens only on opted in namespaces, I suggest we handle this in 2.5 (and not as a 2.4 blocker). We need HCO to expose rotation parameters on its API. That will happen only in 2.6. Created attachment 1742246 [details]
vm-fedora
VM Fedora with namespace: kmp-ns-bug
Created attachment 1742247 [details]
kmp-namespace
Verified. Steps verified: 1. Create a certificate with the given scripts. 2. Create namespace with label: "mutatevirtualmachines.kubemacpool.io: allocate" and apply (oc apply -f namespace.yaml) - Attached namespace.yaml 3. Create VM under the namespace created - Attached vm-fedora.yaml 4. Check that VM is created successfully and running, KMP pods are running. 5. Delete VM works successfully without latency/downtime. Comment on attachment 1742247 [details]
kmp-namespace
KMP Namespace example - kmp-ns-bug.
Has label: "mutatevirtualmachines.kubemacpool.io: allocate"
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory (Moderate: OpenShift Virtualization 2.6.0 security and bug fix update), and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHSA-2021:0799 |