Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.

Bug 1732992

Summary: Race in APIServer Registration on Upgrade
Product: OpenShift Container Platform Reporter: Steve Kuznetsov <skuznets>
Component: kube-apiserverAssignee: Stefan Schimanski <sttts>
Status: CLOSED DUPLICATE QA Contact: Xingxing Xia <xxia>
Severity: urgent Docs Contact:
Priority: urgent    
Version: 4.2.0CC: adahiya, aos-bugs, mfojtik, surbania
Target Milestone: ---   
Target Release: 4.2.0   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard: buildcop
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2019-07-31 06:19:42 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Comment 1 Abhinav Dahiya 2019-07-24 22:36:20 UTC
another one from openstack install
https://prow.svc.ci.openshift.org/view/gcs/origin-ci-test/pr-logs/pull/openshift_installer/2088/pull-ci-openshift-installer-master-e2e-openstack/1200

`Could not update authentication \"cluster\" (12 of 429): the object is invalid, possibly due to local cluster configuration\n* Could not update oauthclient \"console\" (255 of 429): the server does not recognize this resource, check extension API servers`

Comment 2 Michal Fojtik 2019-07-25 08:54:37 UTC
I think there are multiple issues being mixed together in this BZ:

1) https://github.com/openshift/cluster-config-operator/pull/77 should fix the Proxy CR. It was basically created before we create the CRD, which obviously did not worked well.

2) The ServiceMonitor is more complex and belong to monitoring team. I spoke to @sur and he agreed that they should move the CRD creation out of prometheus operator. The reason we saw that error is not because API server has bug in registration or something like that, it was simply because the prometheus operator failed to run (it require worker nodes) and therefore the ServiceMonitor CRD was not installed and therefore the creation of that resource failed (as API server had no idea what that resource is)

@sur, can you please link the Jira issue from you board here?
@stts, I think we should move this to QA when Standa PR is merged.

Comment 4 Michal Fojtik 2019-07-29 10:28:33 UTC
The rest of this BZ is about proxy being created before the proxy CRD is available which might lead to CVO failing the upgrade.
This was fixed here: https://github.com/openshift/cluster-config-operator/pull/77

No backport required, moving to QA to confirm they don't see issues with the Proxy and upgrade anymore.

Comment 5 Xingxing Xia 2019-07-31 06:19:42 UTC
The actual issue above PR fixed is verified in bug 1733015. The remaining issue is tracked in https://jira.coreos.com/browse/MON-732 's bug. Thus this bug is verified and could be closed.

*** This bug has been marked as a duplicate of bug 1733015 ***