The kube-apiserver is restarting unexpectedly due to etcd encryption key rotation in RHOCP 4
Issue
- Weekly, random restarts of the
kube-apiserver
Pods are experienced in OpenShift 4 cluster. -
Control Plane components restart unexpectedly, and the following event can be seen in the logs of the
kube-apiserver-operator
:Event(v1.ObjectReference{Kind:"Deployment", Namespace:"openshift-kube-apiserver-operator", Name:"kube-apiserver-operator", UID:"58d40d83-ca5b-4029-b82a-fce2e96cad40", APIVersion:"apps/v1", ResourceVersion:"", FieldPath:""}): type: 'Normal' reason: 'EncryptionKeyCreated' Secret "encryption-key-openshift-kube-apiserver-7" successfully created: ["rotation-interval-has-passed"]
Environment
- Red Hat OpenShift Container Platform (RHOCP)
- 4
- Encrypted etcd
kube-apiserver
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.