-
Bug
-
Resolution: Done-Errata
-
Undefined
-
4.15.z, 4.17.z, 4.16.z, 4.18.0, 4.19.0
Description of problem:
The IPsec for east west traffic has following issues: 1. When ipsec pod is rebooted due to some reasons, there is unnecessary reboot of pluto service which causes intermittent traffic failure even there is no changes with ipsec connections. 2. CNO is still rendering narrowing=yes which is no longer needed. 3. After IPsec is deployed, when machine config pool goes into progressing state while installing or removing some other machine configs (or) node reboot cause IPsec being disabled in OVN.
Version-Release number of selected component (if applicable):
How reproducible:
Steps to Reproduce:
1. 2. 3.
Actual results:
Expected results:
Additional info:
- depends on
-
OCPBUGS-50616 Graceful cleanup of IPsec states
-
- Verified
-
- is duplicated by
-
OCPBUGS-51285 IPSec issue discovered for cluster upgraded from 4.14 to 4.15.45 which has pinned libreswan version
-
- Closed
-
- links to
-
RHBA-2025:4712 OpenShift Container Platform 4.18.z bug fix update