Description of problem: During an upgrade of the control-plane of a test cluster using 3.11.0-0.10.0: 11:26:55 fatal: [free-int-master-3c664 -> None]: FAILED! => {"changed": false, "finished": false, "msg": "Timed out accepting certificate signing requests. Failing as requested.", "nodes": [{"client_accepted": false, "csrs": {}, "denied": false, "name": "ip-172-31-50-177.ec2.internal", "server_accepted": false}], "results": [], "state": "approve", "timeout": true} Version-Release number of the following components: 3.11.0-0.10.0 How reproducible: Retrying the operation produced the same result. Steps to Reproduce: 1. Run control plane upgrade
When testing, skipping this task[1] would allow the upgrade to complete. [1] https://github.com/openshift/openshift-ansible/blob/master/roles/openshift_node/tasks/upgrade/restart.yml#L48-L53
We're quite certain that this will also happen during 3.10.z.
For 3.11: https://github.com/openshift/openshift-ansible/pull/9488
Commit pushed to master at https://github.com/openshift/openshift-ansible https://github.com/openshift/openshift-ansible/commit/a1d87c62487f8d2454e8ddd759cddf8dd9233002 Merge pull request #9488 from mtnbikenc/fix-1609907 [Bug 1609907] Remove node CSR approval from upgrade in 3.11
*** Bug 1612144 has been marked as a duplicate of this bug. ***
openshift-ansible-3.11.0-0.14.0
Verified on openshift-ansible-3.11.0-0.14.0.git.0.7bd4429None.noarch
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2018:2652