Bug 1765759
| Summary: | Control Plane Certs Expired, Unable to Recover Certs | ||
|---|---|---|---|
| Product: | OpenShift Container Platform | Reporter: | rvanderp |
| Component: | Etcd | Assignee: | Sam Batschelet <sbatsche> |
| Status: | CLOSED ERRATA | QA Contact: | ge liu <geliu> |
| Severity: | urgent | Docs Contact: | |
| Priority: | unspecified | ||
| Version: | 4.2.0 | CC: | alpatel, aos-bugs, jokerman, mfojtik, tnozicka, yinzhou |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | If docs needed, set a value | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2019-12-20 00:46:48 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
rvanderp
2019-10-25 21:12:21 UTC
> The kubelet is failing to register due to errors connecting to the API server. A check of the exposed cert[ref 1] shows the cert for the CN kube-apiserver-service-network-signer being returned which is causing the kubelet to not authenticate the API server.
AFAIK kubelet doesn't use service network but internal loadbalancer and its cert.
Sending to node team to investigate why kubelet can't connect.
The'll likely need info about the install (architecture, cloud, ...) kubelet logs, and checking the appropriate certs.
The kubelet should be talking to the API server on https://api-int.x.x.x.com:6443/ (note the -int). As Tomas mentioned, we need more information. Confirmed payload 4.2.0-0.nightly-2019-12-11-171302 with UPI on baremetal aws, we could recovery back succeed. Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2019:4181 |