Bug 1779321
| Summary: | Failed to verify cert generation after 60 iterations when running etcd-member-recover.sh | ||
|---|---|---|---|
| Product: | OpenShift Container Platform | Reporter: | Weibin Liang <weliang> |
| Component: | Etcd | Assignee: | Sam Batschelet <sbatsche> |
| Status: | CLOSED NOTABUG | QA Contact: | ge liu <geliu> |
| Severity: | high | Docs Contact: | |
| Priority: | unspecified | ||
| Version: | 4.3.0 | CC: | mfojtik |
| Target Milestone: | --- | Flags: | weliang:
needinfo-
|
| Target Release: | 4.3.0 | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | If docs needed, set a value | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2019-12-10 13:36:38 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
Weibin Liang
2019-12-03 18:38:43 UTC
I don't see where you followed 5.a of the docs can you verify?
> Set up a temporary etcd certificate signer service on your master where you have restored etcd.
(In reply to Sam Batschelet from comment #1) > I don't see where you followed 5.a of the docs can you verify? > > > Set up a temporary etcd certificate signer service on your master where you have restored etcd. Here is the log running on the master node (steps 5.a) [core@ip-10-0-57-146 ~]$ sudo oc login https://localhost:6443 The server uses a certificate signed by an unknown authority. You can bypass the certificate check, but any data you send to the server could be intercepted by others. Use insecure connections? (y/n): y Authentication required for https://localhost:6443 (openshift) Username: kubeadmin Password: Login successful. You have access to 53 projects, the list has been suppressed. You can list all projects with 'oc projects' Using project "default". Welcome! See 'oc help' to get started. [core@ip-10-0-57-146 ~]$ export KUBE_ETCD_SIGNER_SERVER=$(sudo oc adm release info --image-for kube-etcd-signer-server --registry-config=/var/lib/kubelet/config.json) [core@ip-10-0-57-146 ~]$ sudo -E /usr/local/bin/tokenize-signer.sh ip-10-0-57-147 Populating template /usr/local/share/openshift-recovery/template/kube-etcd-cert-signer.yaml.template Populating template ./assets/tmp/kube-etcd-cert-signer.yaml.stage1 Tokenized template now ready: ./assets/manifests/kube-etcd-cert-signer.yaml [core@ip-10-0-57-146 ~]$ sudo oc create -f assets/manifests/kube-etcd-cert-signer.yaml pod/etcd-signer created > [core@ip-10-0-57-146 ~]$ sudo -E /usr/local/bin/tokenize-signer.sh ip-10-0-57-147
s/10-0-57-146/ip-10-0-57-147 Typo?
```
section 5.v Verify that the signer is listening on this master node.
[core@ip-10-0-143-125 ~]$ ss -ltn | grep 9943
LISTEN 0 128 *:9943 *:*
```
was cert signer running as expected?
Sorry added my own typo .. s/ip-10-0-57-147/ip-10-0-57-146 Close this bug because I did one step wrong when recovery the failed masters |