baarde / cert-manager-webhook-ovh

OVH Webhook for Cert Manager
Apache License 2.0
93 stars 62 forks source link

Waiting for DNS-01 challenge propagation: dial tcp [IP]:53: i/o timeout #13

Open nhat-tong opened 2 years ago

nhat-tong commented 2 years ago

Hi,

I want to use DNS01 challenge for wildcard certificate. I have configured my OVH credentials with the right permissions but when calling OVH I have this error:

Status: Presented: true Processing: true Reason: Waiting for DNS-01 challenge propagation: dial tcp 10.10.2.3:53: i/o timeout State: pending

I don't understand what it means, especially this ip (10.10.2.3). I don't have any pod within cluster with this ip.

By the way, a record type TXT named "_acme-challenge.XXX.com" have been created in dns zone on OVH side. I could confirm that the webhook client was able to talk to OVH with the right permissions.

@baarde: do you have any thoughts concerning this error ?

Thanks in advance,

Cluster: OpenShift 4 Cert Manager version: 1.6.0 Acme server (staging). https://acme-staging-v02.api.letsencrypt.org/directory Webhook OVH version: 0.3.0

------------------------------------------------------ Webhook Client Logs ------------------------------------------------ I1102 11:05:30.778796 1 trace.go:205] Trace[477362888]: "Create" url:/apis/XXX/v1alpha1/ovh,user-agent:controller/v0.0.0 (linux/amd64) kubernetes/$Format/leader-election,audit-id:39a76cfa-73a4-4c10-970a-2b6ac6961091,client:10.64.84.31,accept:application/json, /,protocol:HTTP/2.0 (02-Nov-2021 11:05:30.023) (total time: 754ms): Trace[477362888]: ---"Object stored in database" 754ms (11:05:30.778) Trace[477362888]: [754.909453ms] [754.909453ms] END