Uploaded image for project: 'OpenShift Bugs'
  1. OpenShift Bugs
  2. OCPBUGS-62977

ESO can't get secret from AWS secret Manager

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done
    • Icon: Critical Critical
    • None
    • 4.20
    • None
    • Quality / Stability / Reliability
    • False
    • Hide

      None

      Show
      None
    • None
    • Critical
    • None
    • None
    • None
    • Rejected
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      Description of problem:

      The ESO can't get the secret from AWS secretmanager with the network policy updates.
          

      Version-Release number of selected component (if applicable):

      4.20
      test with premergebundle: 
      https://github.com/openshift/external-secrets-operator/pull/74
      https://prow.ci.openshift.org/view/gs/test-platform-results/logs/release-openshift-origin-installer-launch-aws-modern/1976603867499991040
          

      How reproducible:

      always
          

      Steps to Reproduce:

          1.install eso
          2.create the secret for access the aws secretmanager
          3.generate the secretstore
          4. generate the ExternalSecret
          

      Actual results:

      the externalsecret can't ready
          

      the error log:

      
      {"level":"error","ts":1760340720.4172318,"msg":"Reconciler error","controller":"externalsecret","controllerGroup":"external-secrets.io","controllerKind":"ExternalSecret","ExternalSecret":{"name":"externalsecret-80066","namespace":"kaka"},"namespace":"kaka","name":"externalsecret-80066","reconcileID":"dec3be22-e5b8-474b-bddc-173bdad7dfba","error":"error processing spec.dataFrom[0].extract, err: operation error Secrets Manager: GetSecretValue, exceeded maximum number of attempts, 3, https response error StatusCode: 0, RequestID: , request send failed, Post \"https://secretsmanager.us-east-2.amazonaws.com/\": dial tcp: lookup secretsmanager.us-east-2.amazonaws.com: i/o timeout","stacktrace":"sigs.k8s.io/controller-runtime/pkg/internal/controller.(*Controller[...]).reconcileHandler\n\t/go/src/github.com/openshift/external-secrets/vendor/sigs.k8s.io/controller-runtime/pkg/internal/controller/controller.go:353\nsigs.k8s.io/controller-runtime/pkg/internal/controller.(*Controller[...]).processNextWorkItem\n\t/go/src/github.com/openshift/external-secrets/vendor/sigs.k8s.io/controller-runtime/pkg/internal/controller/controller.go:300\nsigs.k8s.io/controller-runtime/pkg/internal/controller.(*Controller[...]).Start.func2.1\n\t/go/src/github.com/openshift/external-secrets/vendor/sigs.k8s.io/controller-runtime/pkg/internal/controller/controller.go:202"}
      

      Expected results:

      get the externalsecret from the aws secretmanager
          

      Additional info:

      
          

              bhb@redhat.com Bharath B
              rhn-support-jfan Jia Fan
              None
              None
              Keenon Lee Keenon Lee
              None
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated:
                Resolved: