Uploaded image for project: 'OpenShift Bugs'
  1. OpenShift Bugs
  2. OCPBUGS-69765

AWS Confidential Compute: OSTree Prepare OS/ service takes too long to complete, causing Bootstrap time out

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Critical Critical
    • None
    • 4.21
    • RHCOS
    • None
    • None
    • False
    • Hide

      None

      Show
      None
    • None
    • Critical
    • None
    • None
    • None
    • Proposed
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      Description of problem:

      Create an OCP cluster with confidential computing on AWS, the bootstrap process is likely to time out.
      Checking the journal.log, seen OSTree Prepare OS/ takes ~ 12 mins to complete:
      Thu 2025-12-18 01:56:50 UTC ip-10-0-101-183 init.scope[1]: Starting OSTree Prepare OS/...
      ...
      Thu 2025-12-18 02:08:55 UTC ip-10-0-101-183 init.scope[1]: Stopped OSTree Prepare OS/.
      Thu 2025-12-18 02:08:55 UTC ip-10-0-101-183 init.scope[1]: Read-Only Sysroot Migration was skipped because of an unmet condition check (ConditionPathIsReadWrite=/sysroot).
      Thu 2025-12-18 02:08:55 UTC ip-10-0-101-183 init.scope[1]: Starting Download the OpenShift Release Image...
      
      Compared to a non-confidential computing cluster, the process is very quick (~2min):
      Thu 2025-12-18 06:40:29 UTC ip-10-0-112-130 init.scope[1]: Starting OSTree Prepare OS/...
      ...
      Thu 2025-12-18 06:42:10 UTC ip-10-0-112-130 init.scope[1]: Stopped OSTree Prepare OS/.
      Thu 2025-12-18 06:42:10 UTC ip-10-0-112-130 init.scope[1]: Read-Only Sysroot Migration was skipped because of an unmet condition check (ConditionPathIsReadWrite=/sysroot).
      Thu 2025-12-18 06:42:10 UTC ip-10-0-112-130 init.scope[1]: Starting Download the OpenShift Release Image...
      
          

      Version-Release number of selected component (if applicable):

      4.21.0-0.nightly-2025-12-15-125449
          

      How reproducible:

      About 6 out of 10 attempts fail.
          

      Steps to Reproduce:

          1.
      Create an AWS confidential computing cluster
      compute:
      - architecture: amd64
        hyperthreading: Enabled
        name: worker
        platform:
          aws:
            type: m6a.2xlarge
            amiID: ami-0620723a637bda50d
            cpuOptions:
              confidentialCompute: AMDEncryptedVirtualizationNestedPaging
        replicas: 3
      controlPlane:
        architecture: amd64
        hyperthreading: Enabled
        name: master
        platform:
          aws:
            type: m6a.2xlarge
            amiID: ami-0620723a637bda50d
            cpuOptions:
              confidentialCompute: AMDEncryptedVirtualizationNestedPaging
        replicas: 3
      platform:
        aws:
          region: us-east-2
      
          2.
          3.
          

      Actual results:

         bootstrap process failed
          

      Expected results:

         installation succeeded
          

      Additional info:

          

              Unassigned Unassigned
              yunjiang-1 Yunfei Jiang
              None
              None
              Michael Nguyen Michael Nguyen
              None
              Votes:
              0 Vote for this issue
              Watchers:
              6 Start watching this issue

                Created:
                Updated: