Skip to content

request-cert type client #16

Description

@gertcuykens

request-cert type node works but type client give me the following error

   initContainers:
      - name: init-certs
        image: cockroachdb/cockroach-k8s-request-cert:0.4
        env:
        - name: POD_NAMESPACE
          valueFrom:
            fieldRef:
              fieldPath: metadata.namespace
        volumeMounts:
        - name: certs
          mountPath: /cockroach-certs
        - name: client
          mountPath: /cockroach-client
        command:
        - "/bin/ash"
        - "-xec"
        # - "/request-cert -namespace=${POD_NAMESPACE} -certs-dir=/cockroach-certs -type=node -addresses=localhost,127.0.0.1,$(hostname -f),$(hostname -f | cut -f 1-2 -d '.'),cockroach-lb,cockroachdb-lb.$(hostname -f | cut -f 3- -d '.') -symlink-ca-from=/var/run/secrets/kubernetes.io/serviceaccount/ca.crt;"
        - "/request-cert -namespace=${POD_NAMESPACE} -certs-dir=/cockroach-client -type=client -user=root -symlink-ca-from=/var/run/secrets/kubernetes.io/serviceaccount/ca.crt"
% kubectl get csr
NAME                       AGE       REQUESTOR                                 CONDITION
default.client.root        18m       system:serviceaccount:default:cockroach   Approved,Issued
default.node.cockroach-0   51m       system:serviceaccount:default:cockroach   Approved,Issued
default.node.cockroach-1   48m       system:serviceaccount:default:cockroach   Approved,Issued
default.node.cockroach-2   48m       system:serviceaccount:default:cockroach   Approved,Issued
+ /request-cert '-namespace=default' '-certs-dir=/cockroach-client' '-type=client' '-user=root' '-symlink-ca-from=/var/run/secrets/kubernetes.io/serviceaccount/ca.crt'
2018/10/29 04:06:51 Looking up cert and key under secret default.client.root
W1029 04:06:51.502966       1 client_config.go:529] Neither --kubeconfig nor --master was specified.  Using the inClusterConfig.  This might not work.
2018/10/29 04:06:51 Secret default.client.root not found, sending CSR
Sending create request: default.client.root for 
2018/10/29 04:06:51 failed to get certificate: CertificateSigningRequest.Create(default.client.root) failed: certificatesigningrequests.certificates.k8s.io "default.client.root" already exists

image
PS Not related to the problem but what's the best way to combine node and client cmd into one init cmd? Tried ; but that doesn't work for me.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions