Bug 1955322
| Summary: | [assisted operator] Ipv6 disconnected registry cert failing to mount to assisted-service pod | ||
|---|---|---|---|
| Product: | OpenShift Container Platform | Reporter: | bjacot |
| Component: | assisted-installer | Assignee: | yevgeny shnaidman <yshnaidm> |
| assisted-installer sub component: | stand-alone | QA Contact: | bjacot |
| Status: | CLOSED DUPLICATE | Docs Contact: | |
| Severity: | high | ||
| Priority: | high | CC: | alazar, aos-bugs, asegurap, fpercoco |
| Version: | 4.8 | Keywords: | TestBlocker, Triaged |
| Target Milestone: | --- | ||
| Target Release: | 4.8.0 | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | AI-Team-Platform | ||
| Fixed In Version: | Doc Type: | If docs needed, set a value | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2021-05-10 12:54:29 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
closing this as a duplicate of 1943558. Please re-open if you think otherwise :) *** This bug has been marked as a duplicate of bug 1943558 *** |
Description of problem: When using a disco ipv6 environment the enduser needs to pass the registry cert to the assisted-service pod. If not when trying to deploy an sno cluster seeing an issue with the assisted-service pod and x509 cert issue. I attempted to add the mount to the CSV which gets passed to the operator. Once the agent is applied for the assisted-service pod the cert mount point is not getting passed in. w/a is to scale down the assisted-service operator pod. Update the assisted-service deployment with the cert mount point but DO NOT scale up the assisted-service operator. If the assisted-service operator is scaled back it will detect the config and overwrite to some default value. Error when registry cert is not mounted to the assisted-service pod: Message: The Spec could not be synced due to backend error: command oc adm release info -o template --template '{{.metadata.version}}' --insecure=false registry.ocp-edge-cluster-bjacot2-0.qe.lab.redhat.com:5000/openshift-release-dev/ocp-release:4.8.0-fc.0-x86_64 exited with non-zero exit code 1: error: unable to connect to image repository registry.ocp-edge-cluster-bjacot2-0.qe.lab.redhat.com:5000/openshift-release-dev/ocp-release:4.8.0-fc.0-x86_64: Get "https://registry.ocp-edge-cluster-bjacot2-0.qe.lab.redhat.com:5000/v2/": x509: certificate signed by unknown authority w/a: apply this to assisted-service deployment post of scaling down operator volumeMounts: - mountPath: /etc/pki/ca-trust/extracted/pem name: registry-ca readOnly: true volumes: - configMap: defaultMode: 420 items: - key: ca-bundle.crt path: tls-ca-bundle.pem name: registry-ca name: registry-ca create a cm for registry-ca with the cert entry [kni@provisionhost-0-0 assisted-installer-operator]$ oc get cm | grep reg registry-ca 1 144m btw: the work around does work but is ugly to have scale the operator down and leave it down.