Uploaded image for project: 'OpenShift SDN'
  1. OpenShift SDN
  2. SDN-5422

Impact statement request for OCPBUGS-41823 After upgrading a full ipsec cluster to 4.15.25 pods on nodes will lose the ability to communicate with other pods on different nodes intermittently

XMLWordPrintable

    • Icon: Spike Spike
    • Resolution: Done
    • Icon: Critical Critical
    • None
    • None
    • None
    • False
    • None
    • False
    • ---
    • 0
    • 0

      Impact statement for the OCPBUGS-41823 series:

      Which 4.y.z to 4.y'.z' updates increase vulnerability?

      Customer upgrading OCP from 4.14 to 4.15 with IPsec configuration (or) Enabling 'Full' mode IPsec on a fresh 4.15 cluster having a higher chance of this vulnerability.

      Which types of clusters?

      This happens only on the IPsec enabled OCP clusters.

      What is the impact? Is it serious enough to warrant removing update recommendations?

      Once the cluster is hit with the issue, pod to pod communication is broken between a set of nodes which may impact overall functionality of the cluster and it may even cause production outage.

      How involved is remediation?

      The remediation is to restart IPsec pods until it resolves the issue, but this procedure is not guaranteed.

      Is this a regression?

      This is still being worked on to find out the root cause of the problem, can't confirm this is a regression issue.

              pepalani@redhat.com Periyasamy Palanisamy
              afri@afri.cz Petr Muller
              Votes:
              0 Vote for this issue
              Watchers:
              10 Start watching this issue

                Created:
                Updated:
                Resolved: