Slackbot
11/09/2022, 10:56 AMBenjamin Tan
11/09/2022, 3:16 PMBenjamin Tan
11/09/2022, 3:16 PMKostas Vasilopoulos
11/09/2022, 3:17 PMBenjamin Tan
11/09/2022, 3:17 PMKostas Vasilopoulos
11/09/2022, 3:17 PMKostas Vasilopoulos
11/09/2022, 3:19 PMBenjamin Tan
11/09/2022, 3:20 PMkubectl get svc -n <cert-manager-namespace> ?Kostas Vasilopoulos
11/09/2022, 3:26 PMKostas Vasilopoulos
11/09/2022, 7:04 PM➜ ~ kubectl get svc -n cert-manager
NAME TYPE CLUSTER-IP EXTERNAL-IP PORT(S) AGE
cert-manager ClusterIP 10.43.228.217 <none> 9402/TCP 34h
cert-manager-webhook ClusterIP 10.43.253.27 <none> 443/TCP 34hKostas Vasilopoulos
11/10/2022, 9:50 AMBenjamin Tan
11/10/2022, 4:00 PMkubectl describe certificate -n cert-manager-test
say?Kostas Vasilopoulos
11/10/2022, 4:01 PMcert-manager-test or cert-manager ?Benjamin Tan
11/10/2022, 4:04 PMcert-manager 😄Kostas Vasilopoulos
11/10/2022, 4:06 PMKostas Vasilopoulos
11/10/2022, 4:07 PMcat <<EOF > test-resources.yaml
apiVersion: v1
kind: Namespace
metadata:
name: cert-manager-test
---
apiVersion: <http://cert-manager.io/v1|cert-manager.io/v1>
kind: Issuer
metadata:
name: test-selfsigned
namespace: cert-manager-test
spec:
selfSigned: {}
---
apiVersion: <http://cert-manager.io/v1|cert-manager.io/v1>
kind: Certificate
metadata:
name: selfsigned-cert
namespace: cert-manager-test
spec:
dnsNames:
- <http://example.com|example.com>
secretName: selfsigned-cert-tls
issuerRef:
name: test-selfsigned
EOFBenjamin Tan
11/10/2022, 4:07 PMKostas Vasilopoulos
11/10/2022, 4:10 PM~ kubectl apply -f test-resources.yaml
namespace/cert-manager-test unchanged
Error from server (InternalError): error when creating "test-resources.yaml": Internal error occurred: failed calling webhook "<http://webhook.cert-manager.io|webhook.cert-manager.io>": unexpected error when reading response body. Please retry. Original error: context deadline exceeded
Error from server (InternalError): error when creating "test-resources.yaml": Internal error occurred: failed calling webhook "<http://webhook.cert-manager.io|webhook.cert-manager.io>": unexpected error when reading response body. Please retry. Original error: context deadline exceededBenjamin Tan
11/10/2022, 4:11 PMKostas Vasilopoulos
11/10/2022, 4:13 PMThe trouble with the messageis that it obfuscates the part of the HTTP connection that timed out. When this message appears, we can't tell which part of the HTTP interaction timed out. It might be the DNS resolution, the TCP handshake, the TLS handshake, sending the HTTP request or receiving the HTTP response.context deadline exceeded
Benjamin Tan
11/10/2022, 4:14 PMkubectl get issuer -ABenjamin Tan
11/10/2022, 4:14 PMKostas Vasilopoulos
11/10/2022, 4:15 PMBenjamin Tan
11/10/2022, 4:16 PMkubectl -n cert-manager port-forward deploy/cert-manager-webhook 10250Kostas Vasilopoulos
11/10/2022, 4:17 PMBenjamin Tan
11/10/2022, 4:17 PMKostas Vasilopoulos
11/10/2022, 4:18 PMKostas Vasilopoulos
11/10/2022, 4:30 PMBenjamin Tan
11/10/2022, 4:34 PMBenjamin Tan
11/10/2022, 4:35 PMBo
11/14/2022, 7:46 PMKostas Vasilopoulos
11/14/2022, 8:15 PM➜ ~ curl -vsS --resolve cert-manager-webhook.cert-manager.svc:10250:127.0.0.1 \
--service-name cert-manager-webhook-ca \
--cacert <(kubectl -n cert-manager get secret cert-manager-webhook-ca -ojsonpath='{.<http://data.ca|data.ca>\.crt}' | base64 -d) \
<https://cert-manager-webhook.cert-manager.svc:10250/validate>
* Added cert-manager-webhook.cert-manager.svc:10250:127.0.0.1 to DNS cache
* Uses proxy env variable no_proxy == 'cert-manager-webhook.cert-manager.svc'
* Hostname cert-manager-webhook.cert-manager.svc was found in DNS cache
* Trying 127.0.0.1:10250...
* TCP_NODELAY set
* Connected to cert-manager-webhook.cert-manager.svc (127.0.0.1) port 10250 (#0)
* ALPN, offering h2
* ALPN, offering http/1.1
* successfully set certificate verify locations:
* CAfile: /proc/self/fd/11
CApath: /etc/ssl/certs
* TLSv1.3 (OUT), TLS handshake, Client hello (1):
* TLSv1.3 (IN), TLS handshake, Server hello (2):
* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):
* TLSv1.3 (IN), TLS handshake, Request CERT (13):
* TLSv1.3 (IN), TLS handshake, Certificate (11):
* TLSv1.3 (OUT), TLS alert, unknown CA (560):
* SSL certificate problem: self signed certificate in certificate chain
* Closing connection 0
curl: (60) SSL certificate problem: self signed certificate in certificate chain
More details here: <https://curl.haxx.se/docs/sslcerts.html>
curl failed to verify the legitimacy of the server and therefore could not
establish a secure connection to it. To learn more about this situation and
how to fix it, please visit the web page mentioned above.
and then using -k arg to get our around SSL certificate error we get.
~ curl -k -vsS --resolve cert-manager-webhook.cert-manager.svc:10250:127.0.0.1 \
--service-name cert-manager-webhook-ca \
--cacert <(kubectl -n cert-manager get secret cert-manager-webhook-ca -ojsonpath='{.<http://data.ca|data.ca>\.crt}' | base64 -d) \
<https://cert-manager-webhook.cert-manager.svc:10250/validate>
* Added cert-manager-webhook.cert-manager.svc:10250:127.0.0.1 to DNS cache
* Uses proxy env variable no_proxy == 'cert-manager-webhook.cert-manager.svc'
* Hostname cert-manager-webhook.cert-manager.svc was found in DNS cache
* Trying 127.0.0.1:10250...
* TCP_NODELAY set
* Connected to cert-manager-webhook.cert-manager.svc (127.0.0.1) port 10250 (#0)
* ALPN, offering h2
* ALPN, offering http/1.1
* successfully set certificate verify locations:
* CAfile: /proc/self/fd/11
CApath: /etc/ssl/certs
* TLSv1.3 (OUT), TLS handshake, Client hello (1):
* TLSv1.3 (IN), TLS handshake, Server hello (2):
* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):
* TLSv1.3 (IN), TLS handshake, Request CERT (13):
* TLSv1.3 (IN), TLS handshake, Certificate (11):
* TLSv1.3 (IN), TLS handshake, CERT verify (15):
* TLSv1.3 (IN), TLS handshake, Finished (20):
* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):
* TLSv1.3 (OUT), TLS handshake, Certificate (11):
* TLSv1.3 (OUT), TLS handshake, Finished (20):
* SSL connection using TLSv1.3 / TLS_AES_128_GCM_SHA256
* ALPN, server accepted to use h2
* Server certificate:
* subject: CN=95.217.221.39@1634235922
* start date: Oct 14 17:25:22 2021 GMT
* expire date: Oct 14 17:25:22 2022 GMT
* issuer: CN=95.217.221.39-ca@1634235922
* SSL certificate verify result: self signed certificate in certificate chain (19), continuing anyway.
* Using HTTP2, server supports multi-use
* Connection state changed (HTTP/2 confirmed)
* Copying HTTP/2 data in stream buffer to connection buffer after upgrade: len=0
* Using Stream ID: 1 (easy handle 0x55b718f3f2f0)
> GET /validate HTTP/2
> Host: cert-manager-webhook.cert-manager.svc:10250
> user-agent: curl/7.68.0
> accept: */*
>
* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):
* Connection state changed (MAX_CONCURRENT_STREAMS == 250)!
< HTTP/2 404
< content-type: text/plain; charset=utf-8
< x-content-type-options: nosniff
< content-length: 19
< date: Mon, 14 Nov 2022 08:31:24 GMT
<
404 page not found
* Connection #0 to host cert-manager-webhook.cert-manager.svc left intactKostas Vasilopoulos
11/14/2022, 8:16 PMKostas Vasilopoulos
11/15/2022, 7:44 AM2022-11-15T01:26:24+02:00 time="2022-11-14T23:26:24Z" level=info msg="Creating ingress default-domain- to get a ingress IP automatically"
2022-11-15T01:26:24+02:00 time="2022-11-14T23:26:24Z" level=info msg="Waiting for ingress default-domain-kw4qp to be ready"
2022-11-15T01:46:24+02:00 panic: Error getting domain suffix: failed to wait for ingress default-domain-kw4qp to be ready: timed out waiting for the condition