Join GitHub today
GitHub is home to over 20 million developers working together to host and review code, manage projects, and build software together.
Worker did not receive kubelet-auth-flags post upgrade #238
Comments
chuckbutler
referenced this issue
in kubernetes/kubernetes
Mar 20, 2017
Closed
Certificate error after upgrading CDK to 1.5.2 -> 1.5.3 #43209
tvansteenburgh
self-assigned this
Mar 22, 2017
Cynerva
referenced this issue
in juju-solutions/kubernetes
Apr 7, 2017
Closed
Ensure restart happens when the restart-needed flag is set #118
chuckbutler
added
the
status/fix-released
label
Apr 21, 2017
chuckbutler
closed this
Apr 21, 2017
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
chuckbutler commentedMar 17, 2017
X509 errors have been cropping up ever since i upgraded to 1.5.3. This appears related to the PR that landed authentication on the kubelet daemon, where flags were added but it doesn't appear the defaults file was updated with these new flags.
To test, deploy 1.5.x then upgrade to 1.5.3
Issue any kubectl command that is going to require the master to talk to the worker, such as kubectl logs on a pod.
x509: certificate signed by unknown authority
It looks like the
--tls*flags from https://github.com/kubernetes/kubernetes/pull/41919/files#diff-bdfd6f6b79f7f3171e9f0167164a7c98R340 didnt' quite make the upgrade.