-
Notifications
You must be signed in to change notification settings - Fork 462
OCPBUGS-66403: Remove log exposing kubeconfig #5469
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
MCD log on master nodes was exposing the kubeconfig in the logs. Remove that log so we are not accidentally leaking sensitive information. Signed-off-by: Urvashi <umohnani@redhat.com>
|
@umohnani8: This pull request references Jira Issue OCPBUGS-66403, which is invalid:
Comment The bug has been updated to refer to the pull request using the external bug tracker. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
/jira refresh |
|
@umohnani8: This pull request references Jira Issue OCPBUGS-66403, which is valid. The bug has been moved to the POST state. 3 validation(s) were run on this bug
Requesting review from QA contact: DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
/retest |
isabella-janssen
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
/ltgm
|
@umohnani8: The following test failed, say
Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
yuqi-zhang
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
/ltgm
Ah, was wondering why the bot was confused, lol
/lgtm
/label acknowledge-critical-fixes-only
This is log only and should not affect any payloads
|
|
||
| pathToData[kubeConfigPath] = newData | ||
| klog.Infof("Writing new Data to /etc/kubernetes/kubeconfig: %s", string(newData)) | ||
| klog.Infof("Writing new Data to /etc/kubernetes/kubeconfig") |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
nit: technically this should be the unformatted info but it shouldn't affect anything
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: umohnani8, yuqi-zhang The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
|
Verified using IPI on AWS We can see in the master nodes that the certificate is not printed anymore. We have executed the security e2e test cases and we we have reviewed the generated MCD logs. We haven't seen any other certificate being printed. /label qe-approved |
|
@umohnani8: This pull request references Jira Issue OCPBUGS-66403, which is valid. 3 validation(s) were run on this bug
Requesting review from QA contact: DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
@sergiordlr: This PR has been marked as verified by DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
/test e2e-aws-ovn |
5edd33d
into
openshift:main
|
@umohnani8: Jira Issue Verification Checks: Jira Issue OCPBUGS-66403 Jira Issue OCPBUGS-66403 has been moved to the MODIFIED state and will move to the VERIFIED state when the change is available in an accepted nightly payload. 🕓 DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
Fix included in accepted release 4.21.0-0.nightly-2025-12-13-080958 |
Fixes https://issues.redhat.com/browse/OCPBUGS-66403
- What I did
MCD log on master nodes was exposing the kubeconfig in the logs. Remove that log so we are not accidentally leaking sensitive information.
- How to verify it
Ensure the MCD logs no longer have the kubeconfig text showing up in the log.
- Description for the changelog
Remove log exposing kubeconfig in MCD logs