vault cert expiration is not monitored

Bug #1998174 reported by Linda Guo
16
This bug affects 3 people
Affects Status Importance Assigned to Milestone
OpenStack Nova Compute Charm
Invalid
Undecided
Unassigned
vault-charm
Fix Committed
Critical
Andreas Hamacher

Bug Description

when vault is running on https, the cert expiration is not being monitored.

If vault cert expired, nova-compute and ceph-osd will be unable to do cert verify, then if node is rebooted, ceph-osd can not be decrypted, all OSDs will be taken down.

Tags: bseng-616
Linda Guo (lihuiguo)
summary: - vault cert expeiration is not monitored
+ vault cert expiration is not monitored
Changed in charm-openstack-service-checks:
importance: Undecided → Critical
Linda Guo (lihuiguo)
description: updated
description: updated
Linda Guo (lihuiguo)
description: updated
Eric Chen (eric-chen)
tags: added: bseng-616
Linda Guo (lihuiguo)
affects: charm-openstack-service-checks → vault-charm
Changed in vault-charm:
status: New → Triaged
Changed in vault-charm:
assignee: nobody → Andreas Hamacher (andreashamacher)
Revision history for this message
Andreas Hamacher (andreashamacher) wrote :

Submitted patch ( currently blocked by CI issues )
https://review.opendev.org/c/openstack/charm-vault/+/867596

Eric Chen (eric-chen)
Changed in vault-charm:
status: Triaged → Fix Committed
Revision history for this message
Felipe Reyes (freyes) wrote :

marking charm-nova-compute task a invalid since cert monitoring belongs to vault(-charm).

Changed in charm-nova-compute:
status: New → Invalid
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.