Bug 1877952
| Summary: | Empty router-certs secret results in log spam | |||
|---|---|---|---|---|
| Product: | OpenShift Container Platform | Reporter: | Maru Newby <mnewby> | |
| Component: | apiserver-auth | Assignee: | Maru Newby <mnewby> | |
| Status: | CLOSED ERRATA | QA Contact: | pmali | |
| Severity: | unspecified | Docs Contact: | ||
| Priority: | unspecified | |||
| Version: | 4.6 | CC: | aos-bugs, mfojtik, pasik | |
| Target Milestone: | --- | |||
| Target Release: | 4.6.0 | |||
| Hardware: | Unspecified | |||
| OS: | Unspecified | |||
| Whiteboard: | ||||
| Fixed In Version: | Doc Type: | If docs needed, set a value | ||
| Doc Text: | Story Points: | --- | ||
| Clone Of: | ||||
| : | 1877960 (view as bug list) | Environment: | ||
| Last Closed: | 2020-10-27 16:40:07 UTC | Type: | Bug | |
| Regression: | --- | Mount Type: | --- | |
| Documentation: | --- | CRM: | ||
| Verified Versions: | Category: | --- | ||
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | ||
| Cloudforms Team: | --- | Target Upstream Version: | ||
| Embargoed: | ||||
| Bug Depends On: | ||||
| Bug Blocks: | 1877960 | |||
QA: The fix has already merged (back in June). One possible strategy to verify is to disable the ingress operator and manually remove the data from the openshift-config-managed/router-certs secret and ensure that the mentioned error message does not appear in the logs. Once you're comfortable marking this bz as verified I will be able to merge the 4.5 backport. Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory (OpenShift Container Platform 4.6 GA Images), and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2020:4196 |
If openshift-config-managed/router-certs secret does not contain any certs, the auth operator logs will be filled with the following errors: E0909 19:49:58.876033 1 base_controller.go:180] "ConfigObserver" controller failed to sync "key", err: .servingInfo.namedCertificates accessor error: <nil> is of the type <nil>, expected []interface{} While an empty router-certs secret is an anomalous condition, this error being logged by the auth operator complicates someone trying to troubleshoot the issue, as per [1]. 1: https://bugzilla.redhat.com/show_bug.cgi?id=1876919