Re: [openstack-dev] [magnum] K8S apiserver key sync

2018-06-20 Thread Remo Mattei
Thanks Fei, I did post the question on that channel no much noise there though.. I would really like to get this configured since we are pushing for production. Thanks > On Jun 20, 2018, at 8:27 PM, Fei Long Wang wrote: > > Hi Remo, > > I can't see obvious issue from the log you posted.

Re: [openstack-dev] [magnum] K8S apiserver key sync

2018-06-20 Thread Fei Long Wang
Hi Remo, I can't see obvious issue from the log you posted. You can pop up at #openstack-containers IRC channel as for Magnum questions. Cheers. On 21/06/18 08:56, Remo Mattei wrote: > Hello guys, what will be the right channel to as a question about > having K8 (magnum working with Tripleo)? 

Re: [openstack-dev] [magnum] K8S apiserver key sync

2018-06-20 Thread Remo Mattei
Hello guys, what will be the right channel to as a question about having K8 (magnum working with Tripleo)? I have the following errors.. http://pastebin.mattei.co/index.php/view/2d1156f1 Any tips are appreciated. Thanks Remo > On Jun 19, 2018, at 2:13 PM, Fei Long Wang wrote: > > Hi

Re: [openstack-dev] [magnum] K8S apiserver key sync

2018-06-19 Thread Fei Long Wang
Hi there, For people who maybe still interested in this issue. I have proposed a patch, see https://review.openstack.org/576029 And I have verified with Sonobuoy for both multi masters (3 master nodes) and single master clusters, all worked. Any comments will be appreciated. Thanks. On 21/05/18

Re: [openstack-dev] [magnum] K8S apiserver key sync

2018-05-20 Thread Sergey Filatov
Hi! I’d like to initiate a discussion about this bug: [1]. To resolve this issue we need to generate a secret cert and pass it to master nodes. We also need to store it somewhere to support scaling. This issue is specific for kubernetes drivers. Currently in magnum we have a general cert manager

Re: [openstack-dev] [magnum] K8S apiserver key sync

2018-04-23 Thread Spyros Trigazis
Hi Sergey, In magnum queens we can set the private ca as a service account key. Here [1] we can set the ca.key file. When the label cert_manager_api is set to true. Cheers, Spyros [1]