How to run the cert-regeneration-controller manually via podman on a master node to recover expired control-plane certificates in RHOCP 4

Solution Verified - Updated -

Issue

  • The control-plane certificates are expired and the cluster does not recover automatically.
  • The cert-regeneration-controller sidecar inside the kube-apiserver static pod, which is expected to regenerate expired certificates offline, hangs with no error:
    Waiting for caches to sync for CABundleController
  • The kube-apiserver-operator Deployment is 0/1, so no in-cluster component regenerates the expired serving and client certificates.
  • The leaf certificates managed by the kube-apiserver-operator (load balancer serving certificate, kube-controller-manager client certificate) stay expired even after the signers are regenerated with oc adm ocp-certificates.

Environment

Environment

  • Red Hat OpenShift Container Platform (RHOCP) 4
    • 4.19

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.

Current Customers and Partners

Log in for full access

Log In

New to Red Hat?

Learn more about Red Hat subscriptions

Using a Red Hat product through a public cloud?

How to access this content