OpenShift 4: Webhook calls fail repeatedly when calling to pods in a namespace with networkpolicies
Issue
- Observe the following (or similar) webhook calls failing repeatedly in logs for
openshift-kube-apiserverpod logs:
2025-03-20T04:55:19.418653261Z W0320 04:55:19.418545 15 dispatcher.go:210] Failed calling webhook, failing open vault.hashicorp.com: failed calling webhook "vault.hashicorp.com": failed to call webhook: Post "https://vault-agent-injector-svc.vault.svc:443/mutate?timeout=10s": context deadline exceeded
2025-03-20T04:55:19.418653261Z E0320 04:55:19.418571 15 dispatcher.go:214] failed calling webhook "vault.hashicorp.com": failed to call webhook: Post "https://vault-agent-injector-svc.vault.svc:443/mutate?timeout=10s": context deadline exceeded
- Observe that there are network policies in the target namespace
vault
Environment
- Red Hat OpenShift Container Platform (RHOCP) 4.x
- OVNKubernetes
- Network Policies
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.