Uploaded image for project: 'OpenShift Request For Enhancement'
  1. OpenShift Request For Enhancement
  2. RFE-1790

Provide a recovery path if the etcd singers are deleted accidentally

XMLWordPrintable

    • Icon: Feature Request Feature Request
    • Resolution: Done
    • Icon: Normal Normal
    • None
    • None
    • etcd
    • False
    • False
    • Undefined

      1. What is the nature and description of the request?

      If the customer deletes the etcd secrets/signers by mistake, there should be a way to recover, either by:

      • automatic generation of new signers
        • Detect signers/certs were deleted, and trigger a new signer/cert generation.
      • or, by using Disaster Recovery 
        • Use currently functional etcd database for recovery.
        • Restore should trigger regeneration of the signers and certs
          • etcd scales back to single member
          • generates new signers
          • restarts with new certs
          • scales up.
      • Use the signer and cert files on the disk to restore deleted signers.

      2. Why does the customer need this? (List the business requirements here)

      Accidental deletion of resources due to human error can lead customer to a situation where they cannot recover.

      Here is an example of such a situation:

      https://bugzilla.redhat.com/show_bug.cgi?id=1889003

      3. List any affected packages or components.

      Openshift 4 etcd and etcd operator.

              wcabanba@redhat.com William Caban
              skolicha1@redhat.com Suresh Kolichala (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              7 Start watching this issue

                Created:
                Updated:
                Resolved: