Bug 1821680 - On recovery flow the csr-controller-ca isn't propagated to openshift-config-managed namespace
Summary: On recovery flow the csr-controller-ca isn't propagated to openshift-config-m...
Keywords:
Status: CLOSED DUPLICATE of bug 1818420
Alias: None
Product: OpenShift Container Platform
Classification: Red Hat
Component: kube-controller-manager
Version: 4.4
Hardware: Unspecified
OS: Unspecified
high
high
Target Milestone: ---
: 4.5.0
Assignee: Tomáš Nožička
QA Contact: zhou ying
URL:
Whiteboard:
Depends On:
Blocks: 1817997 1821683 1827990
TreeView+ depends on / blocked
 
Reported: 2020-04-07 12:08 UTC by Tomáš Nožička
Modified: 2020-05-06 07:49 UTC (History)
5 users (show)

Fixed In Version:
Doc Type: No Doc Update
Doc Text:
Clone Of:
: 1821683 (view as bug list)
Environment:
Last Closed: 2020-05-05 07:02:10 UTC
Target Upstream Version:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Github openshift cluster-kube-controller-manager-operator pull 389 0 None closed Bug 1821680: Sync csr-controller-ca to openshift-config-managed namespace 2020-09-19 15:57:47 UTC

Description Tomáš Nožička 2020-04-07 12:08:46 UTC
When recovering from expired certificates, the refreshed csr-controller-ca configmap needs to be propagated to openshift-config-managed namespace to be consumed by CKAO to trust the new client certs.

Comment 5 zhou ying 2020-04-14 07:34:01 UTC
Refer https://bugzilla.redhat.com/show_bug.cgi?id=1821680#c4, I think we could verify this issue now. tested with payload: 4.5.0-0.nightly-2020-04-12-180647

Comment 6 Tomáš Nožička 2020-05-04 14:58:03 UTC
*** Bug 1818420 has been marked as a duplicate of this bug. ***

Comment 7 Xingxing Xia 2020-05-05 07:02:10 UTC

*** This bug has been marked as a duplicate of bug 1818420 ***


Note You need to log in before you can comment on or make changes to this bug.