Bug 1974745 - Proper logs are not available for encryption-kms-get-kek container in the OSD pods
Summary: Proper logs are not available for encryption-kms-get-kek container in the OSD...
Keywords:
Status: VERIFIED
Alias: None
Product: Red Hat OpenShift Container Storage
Classification: Red Hat Storage
Component: rook
Version: 4.8
Hardware: Unspecified
OS: Unspecified
unspecified
medium
Target Milestone: ---
: OCS 4.8.0
Assignee: Sébastien Han
QA Contact: Shay Rozen
URL:
Whiteboard:
Depends On:
Blocks: 1974748
TreeView+ depends on / blocked
 
Reported: 2021-06-22 12:38 UTC by Rachael
Modified: 2023-08-03 08:29 UTC (History)
3 users (show)

Fixed In Version: 4.8.0-432.ci
Doc Type: No Doc Update
Doc Text:
Clone Of:
: 1974748 (view as bug list)
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Github openshift rook pull 264 0 None open Bug 1974745: ceph: do not leak key encryption key 2021-06-22 14:12:45 UTC
Github rook rook pull 8173 0 None open ceph: do not leak key encryption key 2021-06-22 13:06:03 UTC

Description Rachael 2021-06-22 12:38:42 UTC
Description of problem (please be detailed as possible and provide log
snippets):

In a cluster wide encryption enabled OCS cluster using KMS, proper logs are not listed for the encryption-kms-get-kek container in the OSD pods.

$ oc logs rook-ceph-osd-0-75b6b7b5b7-whfcc -c encryption-kms-get-kek
NoneG+vx1C2ixIQ3rWZpXrQb81jumo+ymKSGwsqxvXCMYlqwi7i5U9gbEzgaPFybIigdRembpkNsADCn375c1yTVYXDshcFPEtOLVkLk7mTOGKetiIgDs4+fupQISTlDaknetH+WIFi7jmMtUboGy6Yxr17O+mitAHCW4zIhju0DRh0=


Version of all relevant components (if applicable):
OCP : 4.8.0-0.nightly-2021-06-19-005119
OCS : ocs-operator.v4.8.0-424.ci


Does this issue impact your ability to continue to work with the product
(please explain in detail what is the user impact)?


Is there any workaround available to the best of your knowledge?
No

Rate from 1 - 5 the complexity of the scenario you performed that caused this
bug (1 - very simple, 5 - very complex)?
2

Can this issue reproducible?
Yes

Can this issue reproduce from the UI?
Yes

If this is a regression, please provide more details to justify this:
Yes. In the previous release of OCS 4.7, the script output was listed in the logs.

Steps to Reproduce:
1. Deploy an OCS cluster with cluster-wide encryption enabled using KMS
2. Once the cluster is successfully deployed, check the logs for encryption-kms-get-kek container
Eg: $ oc logs rook-ceph-osd-0-75b6b7b5b7-whfcc -c encryption-kms-get-kek
NoneG+vx1C2ixIQ3rWZpXrQb81jumo+ymKSGwsqxvXCMYlqwi7i5U9gbEzgaPFybIigdRembpkNsADCn375c1yTVYXDshcFPEtOLVkLk7mTOGKetiIgDs4+fupQISTlDaknetH+WIFi7jmMtUboGy6Yxr17O+mitAHCW4zIhju0DRh0=


Actual results:
Proper logs are not available

Expected results:
Logs containing the output from the script run inside the container should be listed.


Note You need to log in before you can comment on or make changes to this bug.