Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.

Bug 1955322

Summary: [assisted operator] Ipv6 disconnected registry cert failing to mount to assisted-service pod
Product: OpenShift Container Platform Reporter: bjacot
Component: assisted-installerAssignee: yevgeny shnaidman <yshnaidm>
assisted-installer sub component: stand-alone QA Contact: bjacot
Status: CLOSED DUPLICATE Docs Contact:
Severity: high    
Priority: high CC: alazar, aos-bugs, asegurap, fpercoco
Version: 4.8Keywords: TestBlocker, Triaged
Target Milestone: ---   
Target Release: 4.8.0   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard: AI-Team-Platform
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2021-05-10 12:54:29 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description bjacot 2021-04-29 20:51:22 UTC
Description of problem:
When using a disco ipv6 environment the enduser needs to pass the registry cert to the assisted-service pod.  If not when trying to deploy an sno cluster seeing an issue with the assisted-service pod and x509 cert issue.

I attempted to add the mount to the CSV which gets passed to the operator. Once the agent is applied for the assisted-service pod the cert mount point is not getting passed in.

w/a is to scale down the assisted-service operator pod.  Update the assisted-service deployment with the cert mount point but DO NOT scale up the assisted-service operator.  If the assisted-service operator is scaled back it will detect the config and overwrite to some default value.

Error when registry cert is not mounted to the assisted-service pod:
Message:               The Spec could not be synced due to backend error: command oc adm release info -o template --template '{{.metadata.version}}' --insecure=false registry.ocp-edge-cluster-bjacot2-0.qe.lab.redhat.com:5000/openshift-release-dev/ocp-release:4.8.0-fc.0-x86_64 exited with non-zero exit code 1: 
error: unable to connect to image repository registry.ocp-edge-cluster-bjacot2-0.qe.lab.redhat.com:5000/openshift-release-dev/ocp-release:4.8.0-fc.0-x86_64: Get "https://registry.ocp-edge-cluster-bjacot2-0.qe.lab.redhat.com:5000/v2/": x509: certificate signed by unknown authority


w/a:
apply this to assisted-service deployment post of scaling down operator
        volumeMounts:
        - mountPath: /etc/pki/ca-trust/extracted/pem
          name: registry-ca
          readOnly: true
      volumes:
      - configMap:
          defaultMode: 420
          items:
          - key: ca-bundle.crt
            path: tls-ca-bundle.pem
          name: registry-ca
        name: registry-ca

create a cm for registry-ca with the cert entry
[kni@provisionhost-0-0 assisted-installer-operator]$ oc get cm | grep reg
registry-ca                               1      144m

btw:
the work around does work but is ugly to have scale the operator down and leave it down.

Comment 1 Flavio Percoco 2021-05-10 12:54:29 UTC
closing this as a duplicate of 1943558. Please re-open if you think otherwise :)

*** This bug has been marked as a duplicate of bug 1943558 ***