Bug 1735180
| Summary: | master bootstrap credentials are not managed | ||
|---|---|---|---|
| Product: | OpenShift Container Platform | Reporter: | David Eads <deads> |
| Component: | Machine Config Operator | Assignee: | Antonio Murdaca <amurdaca> |
| Status: | CLOSED DEFERRED | QA Contact: | Michael Nguyen <mnguyen> |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | 4.2.0 | CC: | amurdaca, aos-bugs, cfergeau, erich, harpatil, jokerman, mfuruta, rh-container, rphillips, sapandit, scuppett |
| Target Milestone: | --- | ||
| Target Release: | 4.6.0 | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | If docs needed, set a value | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2020-09-01 08:29:51 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | |||
| Bug Blocks: | 1693951 | ||
|
Description
David Eads
2019-07-31 18:56:33 UTC
> Now that the MCO doesn't reboot a machine for every update, this should work.
This would be news to me if the MCD does this now.
If it does not, then we are looking at two reboots per node during install: one for the original pivot and one to apply the changed MC that includes the new bootstrap credentials.
I misunderstood how the kubelet ca updates were being handled. If they are rebooting all the machines, I guess you face a similar choice here. Regardless, this is the only thing I'm aware of that prevents an immediate shutdown of a cluster after installation. We really need the MCD to be more feature-rich to make this work. In particular, we need to be able to reproject files changed in the MC without a reboot. Rebooting the nodes twice during install is a disruptive change. For this reason, I'm deferring to 4.3. I've talked to Antonio and this functionality is a priority for MCO in 4.3. I'll reference a Jira story tracking the progress when one exists. Is this the root cause for: https://bugzilla.redhat.com/show_bug.cgi?id=1693951 Hello, I found that we had changed Target release recently from 4.5.0 to 4.6.0 now. I believe this BZ has something to do with RFE-297/MSTR-931 , if my understanding is correct, there's possibility that we would miss landing the feature of fully guaranteed/tested shutdown procedure on v4.5 (or 4.5.z) ? ( MSTR-931 seems still pointing to 4.5, so replease correct me if I am mistaken.) I’d like to get a better understanding of the current situation, would you please clarify it to set appropriate expactation to the customers ? I am grateful for your help and clarification. Thank you, BR, Masaki This doesn't seem to be related to node, requesting MCO team to look into it. Adding UpcomingSprint as this won't make the current sprint. We'll try to work on this bug in the next sprint. I'm not sure about the status of this - there has been some work last year from David https://github.com/openshift/machine-config-operator/pull/1027 but we kind of lost track, is there still something needed from the MCO? Adding UpcomingSprint Adding UpcomingSprint as I won't be able to finish this by the current sprint. I'll revisit from next week. Adding UpcomingSprint as I've been busy with 4.6 features delivery. We'll attempt this next sprint. The needinfo request[s] on this closed bug have been removed as they have been unresolved for 1000 days |