Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1466216 - Redeploy etcd ca playbook didn't update correct ca.crt when etcd running as system container
Redeploy etcd ca playbook didn't update correct ca.crt when etcd running as s...
Status: CLOSED ERRATA
Product: OpenShift Container Platform
Classification: Red Hat
Component: Installer (Show other bugs)
3.6.0
Unspecified Unspecified
medium Severity medium
: ---
: 3.9.0
Assigned To: Michael Gugino
Gaoyun Pei
:
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2017-06-29 05:22 EDT by Gaoyun Pei
Modified: 2018-03-28 10:06 EDT (History)
7 users (show)

See Also:
Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2018-03-28 10:06:20 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2018:0489 None None None 2018-03-28 10:06 EDT

  None (edit)
Description Gaoyun Pei 2017-06-29 05:22:01 EDT
Description of problem:
The redeploy-etcd-ca.yml playbook didn't update the ca.crt under /var/lib/etcd/etcd.etcd/etc directory which is used by etcd system container.
 

Version-Release number of selected component (if applicable):
openshift-ansible-3.6.126.1-1.git.0.41d2313.el7.noarch


How reproducible:
Always

Steps to Reproduce:
1.Set up an ocp-3.6 cluster with etcd system container used

2.Run redeploy-etcd-ca.yml playbook to update the ca cert of etcd
ansible-playbook -i host openshift-ansible/playbooks/byo/openshift-cluster/redeploy-etcd-ca.yml

3. Check the ca.crt used by etcd system conatiner
/var/lib/etcd/etcd.etcd/etc/ca.crt
it's still the old one.

Actual results:


Expected results:


Additional info:
Comment 1 Andrew Butcher 2017-07-14 15:12:06 EDT
@Giuseppe Are the etcd certificates copied to /var/lib/etcd/etcd.etcd/etc referenced in any configuration? /etc/etcd/etcd.conf points to the certificates within /etc/etcd/ in my install.

/etc/etcd/etcd.conf:
ETCD_CA_FILE=/etc/etcd/ca.crt
ETCD_CERT_FILE=/etc/etcd/server.crt
ETCD_KEY_FILE=/etc/etcd/server.key
ETCD_PEER_CA_FILE=/etc/etcd/ca.crt
ETCD_PEER_CERT_FILE=/etc/etcd/peer.crt
ETCD_PEER_KEY_FILE=/etc/etcd/peer.key
Comment 2 Giuseppe Scrivano 2017-07-14 18:25:48 EDT
@Andrew for the etcd system container the files under /etc are not used at all (when we first created the etcd system container we didn't have a nice way to do that, we have new features now so it will probably cleaned up later) so for now all the files used by the etcd system container are in /var/lib/etcd/etcd.etcd/etc.

I think it is enough to copy the new files to "etcd_system_container_cert_config_dir" when the directory exists, so they are keep in sync in both directories.

This is what we already do in roles/etcd_server_certificates/tasks/main.yml.
Comment 3 Andrew Butcher 2017-07-17 10:10:06 EDT
Thanks. I think we'll want to update etcd_ca to also sync the CA when replaced.
Comment 4 Giuseppe Scrivano 2017-09-09 07:27:05 EDT
I'd really like to have no differences at all with these files wrt the system container.  To do so we need to be able to specify arbitrary mount points in the system container, this is currently blocked on:

https://bugzilla.redhat.com/show_bug.cgi?id=1484326

Once we have that feature, we can use exactly the same mount points that are used in the Docker container also in the etcd system container, and we will be able to drop all the custom paths to handle the etcd system container differently.
Comment 7 Michael Gugino 2018-01-23 16:36:19 EST
This looks like it was resolved by: https://github.com/openshift/openshift-ansible/pull/5655

That merged in October.
Comment 9 Johnny Liu 2018-01-25 00:33:59 EST
This bug is targeted for 3.9, while this bug is attached to a 3.5/3.6/3.7 errata, pls attach it to a correct errata.
Comment 12 Gaoyun Pei 2018-01-27 00:19:28 EST
Verify this bug with openshift-ansible-3.9.0-0.24.0.git.0.735690f.el7.noarch.rpm

Run etcd redeploy-ca.yml against an ocp-3.9 cluster which is using etcd system container.

#ansible-playbook -i host /usr/share/ansible/openshift-ansible/playbooks/openshift-etcd/redeploy-ca.yml

After playbook finished, the etcd ca cert /etc/etcd/ca.crt was updated as expected.
Comment 15 errata-xmlrpc 2018-03-28 10:06:20 EDT
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2018:0489

Note You need to log in before you can comment on or make changes to this bug.