How to run the cert-regeneration-controller manually via podman on a master node to recover expired control-plane certificates in RHOCP 4
Issue
- The control-plane certificates are expired and the cluster does not recover automatically.
- The
cert-regeneration-controllersidecar inside the kube-apiserver static pod, which is expected to regenerate expired certificates offline, hangs with no error:
Waiting for caches to sync for CABundleController - The kube-apiserver-operator Deployment is
0/1, so no in-cluster component regenerates the expired serving and client certificates. - The leaf certificates managed by the kube-apiserver-operator (load balancer serving certificate, kube-controller-manager client certificate) stay expired even after the signers are regenerated with
oc adm ocp-certificates.
Environment
Environment
- Red Hat OpenShift Container Platform (RHOCP) 4
- 4.19
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.