Closed atropos112 closed 2 years ago
hmm that is interesting.. what k3s version are you using? did you have any special configurations or resources installed on the cluster?
Hello, I have version 1.23.4k3s1, no special configuration I don't think. This appears to be proxy related and I am running Kube VIP but the settings there are pretty standard.
Hi @atropos112
I was trying to reproduce this issue:
kubectl apply
of any relevant resources and datree worked as expected - blocked the resources that didn't follow the default policyAfter that, a quick search of the error log took me to this issue and to a comment that could be relevant: https://github.com/rancher/rancher/issues/20651#issuecomment-515653801 Could it be related to that issue?
If not, do you have a way to reproduce this?
@atropos112 did you have a chance to check it? We want to know if we can close this issue.
Hello, I am sorry for delaying I was on holidays and didn't have access to my cluster to try. What appears to have caused the issue was the kube-vip pods were crashlooping, I came to conclusion that it was likely to be Datree because once I deleted it the crashlooping has stopped and everything worked. But I have now tried it again and they are not crashlooping suggesting that I was in fact incorrect, I am clueless as to why at the time removing datree admission webhook has changed anything. Thank you for checking ! I'll close because the problem seems to be elsewhere thank you for your investigation !
Running a home setup (a hobby) using k3s on 3 nodes. after installing admission-webhook-datree on 2 nodes (free tier) using
Everything worked ok. Few hours later I had to restart a node (for unrelated reasons) and this is where I've noticed worrying behaviour, namely the node was connecting for a brief moment and then dropping out again, repeating this few times before giving up and killing the k3s process.
I have decided to restart other nodes as well and all of the nodes exhibited the same behaviour, eventually I saw in logs
and decided to try uninstall datree admission webhook (during that moment when the nodes are connected), this resolved my problem. I am wondering what is it that I did wrong that caused such big issue, surely the webhook should not by any means intervene with node coming back up.