Uploaded image for project: 'Red Hat OpenStack Services on OpenShift'
  1. Red Hat OpenStack Services on OpenShift
  2. OSPRH-7374

TLS-e adoption guide shouldn't recommend rebooting the data plane

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done
    • Icon: Normal Normal
    • None
    • None
    • None
    • DFG Security: UC Sprint 97, DFG Security: UC Sprint 98
    • Important

      The TLS-e section of the adoption docs contains the following:

      "After the adoption procedure is finished, the cert-manager operator is responsible for issuing and refreshing new certificates when they expire. However, since Compute services are not restarted during adoption, you need to restart the data plane (Compute) nodes before the certificates expire. Check the expiration dates of all certificates and plan accordingly."

      This shouldn't be necessary because the OpenStack services are started in new containers, and libvirt is de-containerized (it ran in container in 17.1 and it runs on the host in RHOSO data plane).

      Note: There is a WIP bug about the 17 containers not getting properly cleaned up (OSPRH-7129) but these old containers aren't the ones that form the RHOSO data plane.

            ggrasza@redhat.com Grzegorz Grasza
            jstransk@redhat.com Jiri Stransky
            rhos-dfg-security
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved: