Troubleshooting secrets
Review the following information for troubleshooting tips for working with secrets.
If a service certificate generation fails with (service’s
service.beta.openshift.io/serving-cert-generation-error annotation
contains):
secret/ssl-key references serviceUID 62ad25ca-d703-11e6-9d6f-0e9c0057b608, which does not match 77b6dd80-d716-11e6-9d6f-0e9c0057b60
The service that generated the certificate no longer exists, or has a different
serviceUID. You must force certificates regeneration by removing the old
secret, and clearing the following annotations on the service
service.beta.openshift.io/serving-cert-generation-error,
service.beta.openshift.io/serving-cert-generation-error-num:
-
Delete the secret:
$ oc delete secret <secret_name> -
Clear the annotations:
$ oc annotate service <service_name> service.beta.openshift.io/serving-cert-generation-error-$ oc annotate service <service_name> service.beta.openshift.io/serving-cert-generation-error-num-
|
|
The command removing annotation has a |