OpenShift nodes become "Ready" before the SDN finishes updating the firewall ruleset
Issue
- After upgrading OpenShift to 3.7, we've started seeing nodes being marked "Ready" before the iptables rulesets have been fully updated. As a result pods can fail to start because they can't talk to the Internal Registry. We've seen a delay of up to 5 minutes before everything fully synchronizes.
Environment
- OpenShift Container Platform (OCP) 3.7
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.