Uploaded image for project: 'OpenShift Bugs'
  1. OpenShift Bugs
  2. OCPBUGS-61221

Upgrade documentation should ensure ccoctl uses the cluster's actual bound service account signing key

XMLWordPrintable

    • Quality / Stability / Reliability
    • False
    • Hide

      None

      Show
      None
    • None
    • Important
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      Description of problem:

          The documentation currently describes how to update the manual mode short-term token credentials using ccoctl as part of the upgrade process. However, it assumes the user still has the original output directory. When these steps are followed without this directory, a new keypair is created by the ccoctl tool. This updates the key in the oidc issuer such that it no longer matches the keypair in the actual cluster. To resolve this, the documentation needs to be updated to add steps to obtain the bound service account signing key and place it into the output dir prior to running the ccoctl command.

      Version-Release number of selected component (if applicable):

          4.19, 4.18, and prior

      How reproducible:

      always when the output dir is empty    

      Steps to Reproduce:

          1. Create an OIDC cluster (gcp, azure, or aws)
          2. Follow the manual mode oidc documention with a clean output dir
          3. The core operators will start failing to authenticate.
          

      Actual results:

          Core operators will fail to authenticate

      Expected results:

      Core operators should not fail to authenticate    

      Additional info:

      https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/updating_clusters/preparing-to-update-a-cluster#preparing-manual-creds-update

              rhn-support-sslocket Shafer Slockett
              jstuever@redhat.com Jeremiah Stuever
              None
              None
              Jianping Shu Jianping Shu
              None
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Created:
                Updated: