Comment 1 for bug 1809377

Revision history for this message
Xav Paice (xavpaice) wrote : Re: Scale out broken

I've added the canonical-bootstack tag here, as this affects our production Bootstack environments in the following way:

Firstly, we run K8s clouds, and have a single easyrsa unit there which is a single point of failure. I've not dug into recovery options for this as yet.

Secondly, the Openstack deployments use Easyrsa to provide a TLS cert for etcd, which is used by Vault, which stores the LUKs keys for Ceph. With a single unit of easyrsa, if we lose the host it resides on, re implementing a new easyrsa unit breaks the etcd cluster rendering it unusable, which in turn would do nasty things to Vault.