Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Properly handle vSphere thumbprint updates #8043

Open
jiayiwang7 opened this issue Apr 24, 2024 · 0 comments
Open

Properly handle vSphere thumbprint updates #8043

jiayiwang7 opened this issue Apr 24, 2024 · 0 comments
Assignees
Labels
Milestone

Comments

@jiayiwang7
Copy link
Member

jiayiwang7 commented Apr 24, 2024

After user rotates vCenter server certificate, the thumbprint also changes. It's required to run EKS-A upgrade to update the existing clusters to use the latest thumbprint or machines cannot be created or rotated. There is a race condition in current EKS-A cluster controller where during a management cluster upgrade with new thumbprint, the vspheredatacenter reconciler might alter the thumbprint to the old one as specified in the workload cluster's datacenterconfig (since the workload cluster is not updated with new thumbprint yet). This causes thumbprint mismatch error during management cluster upgrade when it validates the datacenter connectivity.

The current workaround stated in #8042 requires both management and workload clusters to be updated with new thumbprint at the same time to bypass the issue.

We need to figure out a robust solution to handle thumbprint update, where a user should be able to

  1. update the management cluster with new thumbprint separate from workload cluster upgrade
  2. both CLI and kubectl upgrade should work with thumbprint
  3. no controller(s) needed to be restarted during upgrade
@jiayiwang7 jiayiwang7 added this to the v0.20.0 milestone Apr 24, 2024
@ndeksa ndeksa modified the milestones: v0.20.0, v0.21.0 Jun 12, 2024
@ndeksa ndeksa modified the milestones: v0.21.0, next Jul 18, 2024
@ndeksa ndeksa added the Q42024 label Oct 8, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

5 participants