Description of problem: Installs of ipsec profiles are failing in 4.11.0-0.nightly-2022-06-01-200905 because the ovn-ipsec pods are not rolling out. The error in the the ovn-keys container is: ++ hostname + kubectl delete --ignore-not-found=true csr/ip-10-0-62-21 Error from server (Forbidden): certificatesigningrequests.certificates.k8s.io "ip-10-0-62-21" is forbidden: User "system:serviceaccount:openshift-ovn-kubernetes:ovn-kubernetes-node" cannot delete resource "certificatesigningrequests" in API group "certificates.k8s.io" at the cluster scope Version-Release number of selected component (if applicable): 4.11.0-0.nightly-2022-06-01-200905 How reproducible: Always for ipsec profiles Additional info: I will add must-gather location in a follow up comment
@mheib Assigning to you, please reassign if appropriate.
Also failed in QE 4.11 e2e CI: https://mastern-jenkins-csb-openshift-qe.apps.ocp-c1.prod.psi.redhat.com/job/ocp-common/job/Flexy-install/108870/console and https://mastern-jenkins-csb-openshift-qe.apps.ocp-c1.prod.psi.redhat.com/job/ocp-common/job/Flexy-install/108819/console
Same error and root cause as" https://bugzilla.redhat.com/show_bug.cgi?id=2091167#c1
ipsec profiles are installing ok now *** This bug has been marked as a duplicate of bug 2091167 ***