Regenerating Keystone certificates causes "Unauthorized" errors

Bug #1906545 reported by Peter De Sousa
10
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Kubernetes Control Plane Charm
Triaged
Medium
Unassigned

Bug Description

Hi,

When following the steps in: https://ubuntu.com/kubernetes/docs/ldap, if the certificates for the Keystone endpoints are re-generated and re-applied to the kubernetes-master unit and the keystone units, kubectl will fail to login always and return "Unauthorized".

Workaround:

Remove the keystone kubernetes-master relation completely, then re-add.

To do this run:

watch -n 20 juju remove-relation kubernetes-master keystone

Until "ERROR" is shown.

Then re-add the relation with juju add-relation kubernetes-master keystone

Cheers,

Peter

Revision history for this message
George Kraft (cynerva) wrote :

What charm revisions did you encounter this with?

Changed in charm-kubernetes-master:
status: New → Incomplete
Revision history for this message
Peter De Sousa (pjds) wrote :

Hi George,

The charm versions are attached as a versioned overlay, bundle to follow.

Revision history for this message
Peter De Sousa (pjds) wrote :

Bundle attached

George Kraft (cynerva)
Changed in charm-kubernetes-master:
status: Incomplete → New
George Kraft (cynerva)
Changed in charm-kubernetes-master:
importance: Undecided → Medium
status: New → Triaged
Peter De Sousa (pjds)
description: updated
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.