Uploaded image for project: 'AMQ Streams'
  1. AMQ Streams
  2. ENTMQST-6340

Improve documentation, logging, and automation of certificate renewal activities on OpenShift

XMLWordPrintable

    • Icon: Story Story
    • Resolution: Done
    • Icon: Undefined Undefined
    • 2.9.0.GA
    • None
    • None
    • None
    • False
    • None
    • False

      A noted pain point for Streams users on OpenShift is renewal or replacement of certificates - particularly when updating user-provided CA certificates. There are several points at which the process can go wrong, including renaming of the old certificates, encoding of secrets, updating the generation or just general SSL usage errors. Once the issues occur, we often see unhelpful error messages logged that don't give much insight into which secret or resource is misconfigured or how to recover, like pods in crash loop logging errors like "No CA found. Thus exiting."

      Anything we an do to ease this process, like more helpful logging, more explicit documentation or utilities to automate certificate updates would be very helpful.

              Unassigned Unassigned
              rhn-support-dhawkins Duane Hawkins
              Lukas Kral Lukas Kral
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated:
                Resolved: