Bug 1699467 - Running redeploy CA and openshift redeploy certificates , causes all nodes to become notready.
Summary: Running redeploy CA and openshift redeploy certificates , causes all nodes t...
Alias: None
Product: OpenShift Container Platform
Classification: Red Hat
Component: Installer
Version: 3.10.0
Hardware: Unspecified
OS: Unspecified
Target Milestone: ---
: 3.10.z
Assignee: Joseph Callen
QA Contact: Gaoyun Pei
Depends On: 1652746
TreeView+ depends on / blocked
Reported: 2019-04-12 19:13 UTC by Joseph Callen
Modified: 2019-07-01 08:17 UTC (History)
7 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of: 1652746
Last Closed: 2019-06-11 09:30:48 UTC
Target Upstream Version:

Attachments (Terms of Use)

System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2019:0786 0 None None None 2019-06-11 09:30:59 UTC

Comment 2 Joseph Callen 2019-04-15 13:08:53 UTC
PR: https://github.com/openshift/openshift-ansible/pull/11496

Comment 3 Joseph Callen 2019-04-16 18:27:53 UTC
In build: openshift-ansible-3.10.138-1

Comment 5 Gaoyun Pei 2019-04-22 06:27:58 UTC
Verify this bug with openshift-ansible-3.10.139-1.git.0.02bc5db.el7

1. Run playbooks/openshift-master/redeploy-openshift-ca.yml to redeploy OpenShift CA cert
2. With openshift_redeploy_openshift_ca=true added in inventory file, run playbooks/redeploy-certificates.yml to redeploy the OpenShift certs

After redeployment, node certs and node bootstrap.kubeconfig get recreated.
Node certs were issued by the new CA, bootstrap.kubeconfig get updated with new CA.

All nodes are in Ready status and all pods are running, no pending csr, move this bug to VERIFIED.

Comment 7 errata-xmlrpc 2019-06-11 09:30:48 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.


Note You need to log in before you can comment on or make changes to this bug.