-
Bug
-
Resolution: Done
-
Major
-
None
-
4.18.z
-
None
-
None
-
False
-
-
None
-
Moderate
-
None
-
None
-
None
-
None
-
None
-
None
-
None
-
None
-
None
-
None
-
None
-
None
Description of problem:
Customer is facing an issue where the kube-apiserver, openshift-apiserver and authentication COs are stuck in progressing state with EncryptionMigrationControllerProgressing after a restore was performed from etcd backup.
NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE
authentication 4.18.22 True True False 48m EncryptionMigrationControllerProgressing: migrating resources to a new write key: [oauth.openshift.io/oauthaccesstokens oauth.openshift.io/oauthauthorizetokens]
kube-apiserver 4.18.22 True True False 34d EncryptionMigrationControllerProgressing: migrating resources to a new write key: [core/configmaps core/secrets]
openshift-apiserver 4.18.22 True True False 20d EncryptionMigrationControllerProgressing: migrating resources to a new write key: [route.openshift.io/routes]
Seems similar to https://access.redhat.com/solutions/6518161 and https://access.redhat.com/solutions/6515171 but we are not seeing any webhook failure messages. The etcd performance also looked okay.
Also, looking at the COs status, it seems that the encryption is already complete.
Version-Release number of selected component (if applicable):
4.18.22
How reproducible:
In customer environment
Steps to Reproduce:
Etcd restore from backup was performed as per https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html/backup_and_restore/control-plane-backup-and-restore#manually-restoring-cluster-etcd-backup_dr-restoring-cluster-state
Actual results:
The COs are stuick in Progressing state.
Expected results:
The COs should be in Available state.
Additional info: