1.21: k8s-keystone-auth pods stuck in Pending with: secret "keystone-auth-certs" not found

Bug #1926973 reported by George Kraft
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
CDK Addons
Fix Released
Critical
George Kraft

Bug Description

On Charmed Kubernetes 1.21, running Kubernetes 1.21.

test_keystone failed, with k8s-keystone-auth pods stuck in pending:

Warning FailedMount 104s (x82 over 152m) kubelet MountVolume.SetUp failed for volume "certs" : secret "keystone-auth-certs" not found

The keystone-auth-certs secret is missing from cdk-addons 1.21.0. The file is there, but incomplete, and no secret named keystone-auth-certs is ever applied.

Revision history for this message
George Kraft (cynerva) wrote :

The secret was removed from the upstream cloud-provider-openstack repo[1], but unfortunately, the cdk-addons build accidentally produced a file from nothing[2] and continued on.

[1]: https://github.com/kubernetes/cloud-provider-openstack/pull/1153
[2]: https://github.com/charmed-kubernetes/cdk-addons/blob/9df68b75d272428d4dc96da07a8d3e7c2fdc8b29/get-addon-templates#L282

Revision history for this message
George Kraft (cynerva) wrote :

We are treating this as field critical since major functionality (keystone auth) does not work with k8s 1.21.

Changed in cdk-addons:
importance: Undecided → Critical
assignee: nobody → George Kraft (cynerva)
status: New → In Progress
Revision history for this message
George Kraft (cynerva) wrote :
Revision history for this message
George Kraft (cynerva) wrote :
Revision history for this message
George Kraft (cynerva) wrote :
Changed in cdk-addons:
status: In Progress → Fix Committed
milestone: none → 1.21+ck1
Changed in cdk-addons:
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.