W1019 13:17:31.485724 1 cmd.go:137] Unable to read initial content of "/spoke/hub-kubeconfig/kubeconfig": open /spoke/hub-kubeconfig/kubeconfig: no such file or directory W1019 13:17:31.485844 1 cmd.go:227] Using insecure, self-signed certificates I1019 13:17:31.485968 1 observer_polling.go:159] Starting file observer I1019 13:17:32.030397 1 leaderelection.go:122] The leader election gives 4 retries and allows for 30s of clock skew. The kube-apiserver downtime tolerance is 78s. Worst non-graceful lease acquisition is 2m43s. Worst graceful lease acquisition is {26s}. I1019 13:17:32.030859 1 observer_polling.go:159] Starting file observer W1019 13:17:32.041822 1 builder.go:230] unable to get owner reference (falling back to namespace): pods is forbidden: User "system:serviceaccount:open-cluster-management-agent:klusterlet-registration-sa" cannot list resource "pods" in API group "" in the namespace "open-cluster-management-agent" I1019 13:17:32.042016 1 builder.go:262] registration-agent version - W1019 13:17:33.086108 1 builder.go:321] unable to get cluster infrastructure status, using HA cluster values for leader election: infrastructures.config.openshift.io "cluster" is forbidden: User "system:serviceaccount:open-cluster-management-agent:klusterlet-registration-sa" cannot get resource "infrastructures" in API group "config.openshift.io" at the cluster scope W1019 13:17:33.086227 1 secure_serving.go:69] Use of insecure cipher 'TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256' detected. W1019 13:17:33.086239 1 secure_serving.go:69] Use of insecure cipher 'TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256' detected. I1019 13:17:33.086340 1 leaderelection.go:248] attempting to acquire leader lease open-cluster-management-agent/registration-agent-lock... I1019 13:17:33.086476 1 event.go:285] Event(v1.ObjectReference{Kind:"Namespace", Namespace:"open-cluster-management-agent", Name:"open-cluster-management-agent", UID:"", APIVersion:"v1", ResourceVersion:"", FieldPath:""}): type: 'Warning' reason: 'ClusterInfrastructureStatus' unable to get cluster infrastructure status, using HA cluster values for leader election: infrastructures.config.openshift.io "cluster" is forbidden: User "system:serviceaccount:open-cluster-management-agent:klusterlet-registration-sa" cannot get resource "infrastructures" in API group "config.openshift.io" at the cluster scope I1019 13:17:33.092908 1 requestheader_controller.go:169] Starting RequestHeaderAuthRequestController I1019 13:17:33.092932 1 shared_informer.go:270] Waiting for caches to sync for RequestHeaderAuthRequestController I1019 13:17:33.093672 1 configmap_cafile_content.go:202] "Starting controller" name="client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file" I1019 13:17:33.093697 1 shared_informer.go:270] Waiting for caches to sync for client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file I1019 13:17:33.093643 1 configmap_cafile_content.go:202] "Starting controller" name="client-ca::kube-system::extension-apiserver-authentication::client-ca-file" I1019 13:17:33.093788 1 shared_informer.go:270] Waiting for caches to sync for client-ca::kube-system::extension-apiserver-authentication::client-ca-file I1019 13:17:33.094424 1 dynamic_serving_content.go:132] "Starting controller" name="serving-cert::/tmp/serving-cert-3662442657/tls.crt::/tmp/serving-cert-3662442657/tls.key" I1019 13:17:33.096223 1 secure_serving.go:210] Serving securely on [::]:8443 I1019 13:17:33.096264 1 tlsconfig.go:240] "Starting DynamicServingCertificateController" I1019 13:17:33.194442 1 shared_informer.go:277] Caches are synced for client-ca::kube-system::extension-apiserver-authentication::requestheader-client-ca-file I1019 13:17:33.194457 1 shared_informer.go:277] Caches are synced for RequestHeaderAuthRequestController I1019 13:17:33.194487 1 shared_informer.go:277] Caches are synced for client-ca::kube-system::extension-apiserver-authentication::client-ca-file