ovn-ipsec-host pod on a node fails to start and enters CrashLoopBackOff
Issue
- A cluster with IPsec enabled may experience a degraded clusteroperator/network status, and one of the ovn-ipsec-host pod will be in a CrashLoopBackOff state.
- This is caused by a corrupted /etc/ipsec.d/openshift.conf file on the node, which prevents the ipsec.service from starting.
- This issue can occur following an abrupt node shutdown, such as a power outage, that happens while the ovs-monitor-ipsec daemon is writing to the configuration file.
Environment
- OpenShift Container Platform 4.18 with OVN-Kubernetes and IPsec enabled
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.