#OCP TLS workaround using Operator deployment

1 messages · Page 1 of 1 (latest)

ionic agate
#

Hi, we're running in operator mode on 21.07, attempting to upgrade to 22.10, but ran into the TLS issue described in this recent KB article, OCP 4.10 vs 4.11 mentioned. Behavior is otherwise matching.
https://kb.netapp.com/Advice_and_Troubleshooting/Cloud_Services/Astra_Trident/Trident_does_not_run_due_to_TLSv1.2_mismatch_on_Openshift_FIPS_setup

The instructions provided in the KB seem to be related to a standard installation, is there a workaround possible when using the operator?

prisma flicker
#

Hi @ionic agate, are you using OCP FIPS? If so there isn't a work around when using the Operator. It is necessary to use custom yaml.

urban pulsar
#

@ionic agate I was going to reformat that KB a little bit in the near future. It isn't as clear as it ought to be. The highlighted section can be added to each probe section. The startupProbe section is required, but if it were me, I'd add the exec to each section. Just don't miss the note at the bottom....
Note: if you are changing all three probes, the readinessProbe requires /readiness at the end of that URL, not /liveliness