Uploaded image for project: 'OpenShift Bugs'
  1. OpenShift Bugs
  2. OCPBUGS-77890

OCP4.18 - IPSEC (full) installation failed - libreswan not installed on some hosts

    • None
    • False
    • Hide

      None

      Show
      None
    • None
    • Important
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      Description of problem:

      Following documentation to enable IPSEC (Full), observed node rollover (MCP) . Noted that nodes seem to accept the latest MCP rollout, daemon pod parses IPSEC/libreswan installation, reports success. IPSEC pods cannot schedule correctly, pluto/libreswan not running. Libreswan RPM not located on host afterwards.

       

      Version-Release number of selected component (if applicable):

      4.18.22

      How reproducible:

      Once cluster - twice in a row, different z-streams of 4.18.

      Steps to Reproduce:

      • Unclear replicator steps - one cluster impacted repeatedly, unable to configure IPSEC (customer env)

      Actual results:

      Node returns to READY, but IPSEC/libreswan not installed.

      Expected results:

      Libreswan installation should succeed, node should become ready with IPSEC 

      Additional data:

       

      • Each time this has been attempted, the MCP rollout has been stalled by webhooks and PDB drains - this is a separate issue but does contribute to delayed parsing of machine-config content across all nodes. 

      See first comment for logs and reporting. 

      Linked customer cases:

      04389859 (proactive planning case - has latest MG)

      04354482 (previous attempt - failure/rollback - has sosreport/mg/inspects)

      04283486 (previous attempt - failure/rollback - has must-gather)

              bbennett@redhat.com Ben Bennett
              rhn-support-wrussell Will Russell
              Anurag Saxena Anurag Saxena
              None
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated: