-
Bug
-
Resolution: Done
-
Major
-
None
-
4.18
-
Quality / Stability / Reliability
-
False
-
-
None
-
None
-
None
-
None
-
None
-
None
-
None
-
None
-
None
-
None
-
None
-
None
-
None
-
None
Description of problem:
IHAC trying to install a hosted cluster using kubevrt platform in disconnected environment. The management cluster is disconnected as well. The MCE version being used is 2.8.1. The installation fails at the very initial stage with following error - ~~~ 2025-05-27T14:30:18.235140470Z {"level":"error","ts":"2025-05-27T14:30:18Z","msg":"Reconciler error","controller":"hostedcluster","controllerGroup":"hypershift.openshift.io","controllerKind":"HostedCluster","HostedCluster":{"name":"test4","namespace":"clusters"},"namespace":"cluste rs","name":"test4","reconcileID":"5ce2d2d7-fd7f-4a7c-b787-a08efe9d14db","error":"failed to determine if release image multi-arch: failed to retrieve manifest docker-na-public.artifactory.swg-devops.com/hyc-abell-devops-team-dev-offline-docker-local/delld/hcp/openshift-release-dev/o cp-release:4.18.12-x86_64: Head "https://docker-na-public.artifactory.swg-devops.com/v2/hyc-abell-devops-team-dev-offline-docker-local/delld/hcp/openshift-release-dev/ocp-release/manifests/4.18.12-x86_64\": unknown: Authentication is required","stacktrace":"sigs.k8s.io/controller- runtime/pkg/internal/controller.(*Controller).reconcileHandler\n\t/remote-source/app/vendor/sigs.k8s.io/controller-runtime/pkg/internal/controller/controller.go:324\nsigs.k8s.io/controller-runtime/pkg/internal/controller.(*Controller).processNextWorkItem\n\t/remote-source/app/vendo r/sigs.k8s.io/controller-runtime/pkg/internal/controller/controller.go:261\nsigs.k8s.io/controller-runtime/pkg/internal/controller.(*Controller).Start.func2.2\n\t/remote-source/app/vendor/sigs.k8s.io/controller-runtime/pkg/internal/controller/controller.go:222" ~~~ The customer has correct pull secrets on the management cluster and the secret created by the hosted cluster creation is the same. Images can be fetched from the management cluster nodes using the same pull secret. The management cluster has the IDMS and ITMS applied. The hosted cluster creation does identify the mirror registry, but fails to authenticate against the pull secret. The customer has not created a config map for mirror registry CA certificate, as they have the certificate signed by a well known certificate signing authority. There are no control plane pods created. The installation fails at very initial stage with the error. The MCE version is 2.8.1. The customer is not using ACM. Just MCE.
Version-Release number of selected component (if applicable):
How reproducible:
Setup a management cluster in disconnected environment, follow the document and mirror images as specified in the document. Once done, created the hosted cluster upon kubevrt. HCP cluster version being installed - 4.18.12 MCE Version - 2.8.1 document followed - https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html-single/hosted_control_planes/index#deploying-hosted-control-planes-on-openshift-virtualization-in-a-disconnected-environment
Steps to Reproduce:
1. Install a management cluster in disconnected environment 2. Mirror the required images and apply the IDMS to the management cluster 3. Install the hosted cluster
Actual results:
HCP cluster installation fails
Expected results:
The installation should succeed
Additional info:
- Slack threads raised for the issue: link - https://redhat-external.slack.com/archives/C01C8502FMM/p1748893168164399