Uploaded image for project: 'OpenShift Bugs'
  1. OpenShift Bugs
  2. OCPBUGS-61847

OpenShift API Services don't recover if the cluster misses its 24h cert rotation due to VMs being shutdown

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Major Major
    • None
    • 4.19.z
    • openshift-apiserver
    • None
    • Quality / Stability / Reliability
    • False
    • Hide

      None

      Show
      None
    • None
    • Important
    • Yes
    • All
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      Description of problem:

      
      When stopping the VMs making up a 4.19.x cluster and waiting more than the 24h window where certs get rotated after the install the cluster does no longer recover.
      
      This had been (finally) fixed in 4.4.8. And it now reappears. This is a critical capability for customers (and the demo platform team) to save money when clusters are not in use.
      
          

      4.19.x. Tested with 4.19.10

          How reproducible:{code:none}
      
          

      Steps to Reproduce:

          1. Deploy a 4.19 cluster
          2. After the cluster has settled (all ClusterOperators happy etc.) stop the VMs making up the cluster.
          3. Wait 30 hours (to be sure to miss the 24h cert rotation window)
          4. Start the VMs.
          5. Wait for CSRs to appear. As Pending CSRs appear approve them.
          6. Nodes will report Ready, all ClusterOperators will report Ready
          7. OpenShift api services are not ready (oc get apiservices).
          

      Actual results:

          Can't access Openshift Console. Can't execute openshift specific commands (oc project, ...
          

      Expected results:

          Cluster recovers and is operational
          

      Additional info:

      
          

              Unassigned Unassigned
              wkulhanek Wolfgang Kulhanek
              None
              Alfredo Pizarro, Eric Fried, Vadim Rutkovsky
              Rahul Gangwar Rahul Gangwar
              None
              Votes:
              3 Vote for this issue
              Watchers:
              15 Start watching this issue

                Created:
                Updated: