Uploaded image for project: 'Product Technical Learning'
  1. Product Technical Learning
  2. PTL-13589

ch02s04: Incorrect cidr for security group preventibg EFS mount

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done
    • Icon: Critical Critical
    • CS221 - ROSA4.14-en-1-20240425
    • CS221
    • None
    • False
    • Hide

      None

      Show
      None
    • False
    • 2
    • en-US (English)

      Please fill in the following information:


      URL: https://role.rhu.redhat.com/rol-rhu/app/courses/cs221-4.14/pages/ch02s04
      Reporter RHNID: rhn-support-ablum
      Section Title:  Guided Exercise: Configure EFS Shares for a Single ROSA Project                                                                    

      Issue description

      Step 6.4 details the rule to use for the Source is "Custom: 0.0.0.0/16".  This results in an issue when the kubelet tries to mount the EFS volume for the pod:

      Jun 03 12:55:28 ip-10-1-0-233 kubenswrapper[2111]: E0603 12:55:28.298476    2111 kubelet.go:1948] "Unable to attach or mount volumes for pod; skipping pod" err="unmounted volumes=[etherpad-data], unattached volumes=[], failed to process volumes=[]: timed out waiting for the condition" pod="efs-etherpad/etherpad-54c8556d58-k2j4w"

       

      This is because the SG rule given doesn't match the range for the EFS mount target so the inbound traffic 2049/tcp isn't being allowed.  The PV and PVC are created by successfully but the pod will be stuck in a "ContainerCreating" status.

       

      Workaround:

      Change the SG inbound source to be 0.0.0.0/0

      This isn't good though since it would allow inbound traffic from all IPs.  Better to determine the mount target IP and use a range based on it.  Services > Storage > EFS > (filesystem ID)  > Network tab.  SEE screenshot for the IP address assigned in a sample availability zone.

      Expected result:

      Etherpad pod should be in a running state using the EFS volume.

              rht-hquatrem Herve Quatremain
              rhn-support-ablum Andrew Blum
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: