Uploaded image for project: 'OpenShift Bugs'
  1. OpenShift Bugs
  2. OCPBUGS-62070

The kube-rbac-proxy-federate container reporting TLS handshake error

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Undefined Undefined
    • None
    • 4.16.z
    • apiserver-auth
    • None
    • Quality / Stability / Reliability
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      Description of problem:

      I am opening this bug because bug https://issues.redhat.com/browse/OCPBUGS-5916 was closed and marked as obsolete. We found similar errors reported in container kube-rbac-proxy-federate of pod prometheus-user-workload-0 and in container kube-rbac-proxy-web of pod prometheus-k8s-1:
      
      ---
      $ oc logs prometheus-user-workload-0 -c kube-rbac-proxy-federate -n openshift-user-workload-monitoring
      ...
      2025-09-19T02:12:54.625440238-05:00 I0919 07:12:54.623962       1 log.go:245] http: TLS handshake error from 172.17.3.202:41346: write tcp 172.17.39.19:9092->172.17.3.202:41346: write: connection reset by peer
      2025-09-19T02:12:56.582878353-05:00 I0919 07:12:56.582810       1 log.go:245] http: TLS handshake error from 172.17.7.5:40134: write tcp 172.17.39.19:9092->172.17.7.5:40134: write: connection reset by peer
      2025-09-19T02:12:59.631695751-05:00 I0919 07:12:59.631569       1 log.go:245] http: TLS handshake error from 172.17.3.202:39450: write tcp 172.17.39.19:9092->172.17.3.202:39450: write: connection reset by peer
      2025-09-19T02:13:01.589863199-05:00 I0919 07:13:01.589807       1 log.go:245] http: TLS handshake error from 172.17.7.5:40148: write tcp 172.17.39.19:9092->172.17.7.5:40148: write: connection reset by peer
      
      ---
      $ oc logs prometheus-k8s-1 -n openshift-monitoring -c kube-rbac-proxy-web
      ...
      2025-09-19T02:01:36.637882599-05:00 I0919 07:01:36.637784       1 log.go:245] http: TLS handshake error from 172.17.7.5:38818: write tcp 172.17.7.47:9091->172.17.7.5:38818: write: connection reset by peer
      2025-09-19T02:01:41.400995583-05:00 I0919 07:01:41.400900       1 log.go:245] http: TLS handshake error from 172.17.7.5:38826: write tcp 172.17.7.47:9091->172.17.7.5:38826: write: connection reset by peer
      2025-09-19T02:01:45.371744209-05:00 I0919 07:01:45.371655       1 log.go:245] http: TLS handshake error from 172.17.3.202:59778: write tcp 172.17.7.47:9091->172.17.3.202:59778: write: connection reset by peer
      2025-09-19T02:01:45.730408189-05:00 I0919 07:01:45.730330       1 log.go:245] http: TLS handshake error from 172.17.3.202:59792: write tcp 172.17.7.47:9091->172.17.3.202:59792: write: connection reset by peer
      2025-09-19T02:01:46.651882563-05:00 I0919 07:01:46.651469       1 log.go:245] http: TLS handshake error from 172.17.7.5:57618: write tcp 172.17.7.47:9091->172.17.7.5:57618: write: connection reset by peer

      Version-Release number of selected component (if applicable):

          

      How reproducible:

          

      Steps to Reproduce:

          1.
          2.
          3.
          

      Actual results:

          

      Expected results:

          

      Additional info:

          

              Unassigned Unassigned
              rhn-support-macastil Mario Castillo
              None
              None
              Xingxing Xia Xingxing Xia
              None
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated: