Uploaded image for project: 'OpenShift Logging'
  1. OpenShift Logging
  2. LOG-2546

TLS handshake error on loki-gateway for FIPS cluster

XMLWordPrintable

    • False
    • None
    • False
    • NEW
    • VERIFIED
    • Log Storage - Sprint 222

      Issue:

      Loki-gateway is down with TLS handshake error after LokiStack CR is created on FIPS cluster.

      2022/04/27 21:17:18 http: TLS handshake error from 10.129.2.1:35780: tls: client offered only unsupported versions: [303]
      
      

      Querier and Compactor also have DNS errors.

      Querier logs

      Steps to reproduce:

      1) Provision fips enabled cluster

      2) Deploy Loki Operator from grafana/loki repo

      3) Create S3 bucket secret

      4) Create LokiStack CR

      apiVersion: loki.grafana.com/v1beta1
      kind: LokiStack
      metadata:
        name: lokistack-dev
      spec:
        size: 1x.extra-small
        storage:
          secret:
            name: test
            type: s3
        storageClassName: gp2
        tenants:
          mode: openshift-logging 

      CSV:

      [kbharti@cube hack]$ oc get csv -n openshift-logging
      NAME                               DISPLAY                            VERSION     REPLACES   PHASE
      cluster-logging.5.4.0-140          Red Hat OpenShift Logging          5.4.0-140              Succeeded
      elasticsearch-operator.5.4.0-154   OpenShift Elasticsearch Operator   5.4.0-154              Succeeded
      loki-operator.v0.0.1               Loki Operator                      0.0.1                  Succeeded 

            rojacob@redhat.com Robert Jacob
            rhn-support-kbharti Kabir Bharti
            Kabir Bharti Kabir Bharti
            Votes:
            0 Vote for this issue
            Watchers:
            6 Start watching this issue

              Created:
              Updated:
              Resolved: