Uploaded image for project: 'OpenShift Bugs'
  1. OpenShift Bugs
  2. OCPBUGS-63563

kube-apiserver operator repeatedly regenerates aggregator client CA certs causing configmap size to exceed 65,535 bytes limit

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Undefined Undefined
    • None
    • 4.16
    • kube-apiserver
    • None
    • Quality / Stability / Reliability
    • False
    • Hide

      None

      Show
      None
    • None
    • Moderate
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      Description of problem:

          This hit an issue where the kube-apiserver operator created certs over and over again in configmap cm  kube-apiserver-aggregator-client-ca in project  openshift-config-managed, which was copied to other configmaps to be loaded up by the kube-apiserver. 
       The operator should have logic to prevent too man certs being created, there should be some check to make sure that the cert file does not go over the limit of 65,535 bytes
      
      
      

       

      Version-Release number of selected component (if applicable):

          

      How reproducible:

          

      Steps to Reproduce:

          1.
          2.
          3.
          

      Actual results:

          

      Expected results:

          

      Additional info:

          

              Unassigned Unassigned
              rhn-support-hmongia Harshit Mongia
              None
              None
              Ke Wang Ke Wang
              None
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated: