Uploaded image for project: 'OpenShift Bugs'
  1. OpenShift Bugs
  2. OCPBUGS-32514

IBU upgrade fails during the upgrade stage when running recert: `Err` value: could not remove key: f:etcd-peer-sno.kni-qe-2.lab.eng.rdu2.redhat.com.crt'

XMLWordPrintable

    • Critical
    • No
    • Rejected
    • False
    • Hide

      None

      Show
      None

      Description of problem:

        IBU upgrade fails during the upgrade stage when running recert with the following error:
      
              Rollback due to postpivot failure: failed to run once recert for post pivot: failed recert full flow: failed to run recert tool container: 2024-04-19 15:30:24 - INFO - src/cluster_crypto/crypto_utils.rs:245: using openssl: OpenSSL 3.0.7 1 Nov 2022 (Library: OpenSSL 3.0.7 1 Nov 2022)        2024-04-19 15:30:36 - WARN - src/cluster_crypto/crypto_objects.rs:81: ignoring error from processing pem-looking text at location k8s:ConfigMap/kube-system:cluster-config-v1:/data/install-config, without encoding, unknown: processing pem bundle
              2024-04-19 15:30:39 - WARN - src/cluster_crypto/crypto_objects.rs:81: ignoring error from processing pem-looking text at location k8s:ConfigMap/openshift-etcd:cluster-config-v1:/data/install-config, without encoding, unknown: processing pem bundle
              2024-04-19 15:30:46 - INFO - src/cluster_crypto/cert_key_pair.rs:173: Using custom private key for CN kube-apiserver-localhost-signer
              2024-04-19 15:30:47 - INFO - src/cluster_crypto/cert_key_pair.rs:173: Using custom private key for CN kube-apiserver-service-network-signer
              2024-04-19 15:30:47 - INFO - src/cluster_crypto/cert_key_pair.rs:173: Using custom private key for CN kube-apiserver-lb-signer
              thread 'main' panicked at 'called `Result::unwrap()` on an `Err` value: could not remove key: f:etcd-peer-sno.kni-qe-2.lab.eng.rdu2.redhat.com.crt', src/ocp_postprocess/hostname_rename/etcd_rename.rs:69:101
              note: run with `RUST_BACKTRACE=1` environment variable to display a backtrace
      

      Version-Release number of selected component (if applicable):

          4.16.0-0.nightly-2024-04-16-015315
          lifecycle-agent.v4.16.0(lifecycle-agent-operator-bundle-container-v4.16.0-32, brew.registry.redhat.io/openshift4/recert-rhel9@sha256:f1b6f75ce508ee25b496caa833e0be70abb1dd5f2dc3dbae1e0e11f5f8600f68)

      How reproducible:

          2/2 times so far

      Steps to Reproduce:

          1. Generate a seed image on a 4.16 SNO 
          2. Run the IBU upgrade process on a 4.14 SNO with 4.16 LCA installed
          3. Check Upgrade stage result
          

      Actual results:

          Upgrade failed while running recert with the following error:
              Rollback due to postpivot failure: failed to run once recert for post pivot: failed recert full flow: failed to run recert tool container: 2024-04-19 15:30:24 - INFO - src/cluster_crypto/crypto_utils.rs:245: using openssl: OpenSSL 3.0.7 1 Nov 2022 (Library: OpenSSL 3.0.7 1 Nov 2022)        2024-04-19 15:30:36 - WARN - src/cluster_crypto/crypto_objects.rs:81: ignoring error from processing pem-looking text at location k8s:ConfigMap/kube-system:cluster-config-v1:/data/install-config, without encoding, unknown: processing pem bundle
              2024-04-19 15:30:39 - WARN - src/cluster_crypto/crypto_objects.rs:81: ignoring error from processing pem-looking text at location k8s:ConfigMap/openshift-etcd:cluster-config-v1:/data/install-config, without encoding, unknown: processing pem bundle
              2024-04-19 15:30:46 - INFO - src/cluster_crypto/cert_key_pair.rs:173: Using custom private key for CN kube-apiserver-localhost-signer
              2024-04-19 15:30:47 - INFO - src/cluster_crypto/cert_key_pair.rs:173: Using custom private key for CN kube-apiserver-service-network-signer
              2024-04-19 15:30:47 - INFO - src/cluster_crypto/cert_key_pair.rs:173: Using custom private key for CN kube-apiserver-lb-signer
              thread 'main' panicked at 'called `Result::unwrap()` on an `Err` value: could not remove key: f:etcd-peer-sno.kni-qe-2.lab.eng.rdu2.redhat.com.crt', src/ocp_postprocess/hostname_rename/etcd_rename.rs:69:101
              note: run with `RUST_BACKTRACE=1` environment variable to display a backtrace
              : exit status 101
      

      Expected results:

          No failure

      Additional info:

          seed image can be pulled from registry.ztp-hub-00.mobius.lab.eng.rdu2.redhat.com:5000/ibu/seed:4.16.0-0.nightly-2024-04-16-015315

            mresvani@redhat.com Michail Resvanis
            mcornea@redhat.com Marius Cornea
            Marius Cornea Marius Cornea
            Votes:
            0 Vote for this issue
            Watchers:
            6 Start watching this issue

              Created:
              Updated: