SCG AND VAULT INTEGRATION: LOGIN UNAUTHORIZED DUE TO: X509: CERTIFICATE SIGNED BY UNKNOWN AUTHORITY

We were trying to integrate Spring Cloud Gateway running on K8S with HashiCorp Vault. Wanted to share info how we resolved these issues.

Issue 1: [ERROR] auth.kubernetes.auth_kubernetes: login unauthorized due to: Post “https://10.0.0.:6443/apis/authentication.k8s.io/v1/tokenreviews”: x509: certificate signed by unknown authority

Solution: We used following kubernetes auth config to authenticate client to vault:
vault write auth/kubernetes/config token_reviewer_jwt=”$SA_JWT_TOKEN” kubernetes_host=”$K8S_HOST” kubernetes_ca_cert=”$SA_CA_CRT” issuer=”https://kubernetes.default.svc.cluster.local” disable_iss_validation=”true”

We extracted certificate info using below command:
export SA_CA_CRT=$(kubectl config view –raw –minify –flatten –output ‘jsonpath={.clusters[].cluster.certificate-authority-data}’ | base64 –decode)

While copying the certificate info to vault container we used echo $SA_CA_CRT instead of echo “$SA_CA_CRT”. Due to this new line characters from certificate were removed due to which certificate format became non compliant with pem format. After extracting certificate info using double quote, SCG was able to authenticate with Vault.

Issue 2: Authentication is failing with: {“kind”:”Status”,”apiVersion”:”v1″,”metadata”:{},”status”:”Failure”,”message”:”tokenreviews.authentication.k8s.io is forbidden: User \”system:serviceaccount:dev-scg:service-account-scg\” cannot create resource \”tokenreviews\” in API group \”authentication.k8s.io\” at the cluster scope”,”reason”:”Forbidden”,”details”:{“group”:”authentication.k8s.io”,”kind”:”tokenreviews”},”code”:403}

Solution: As per the above error message, service account doesn’t have right cluster role to create resource tokenreviews. Issue got resolved after creating cluster role binding as below:

  apiVersion: rbac.authorization.k8s.io/v1beta1
  kind: ClusterRoleBinding
  metadata:
    name: dev-tokenreview-binding
    namespace: dev-scg
  roleRef:
    apiGroup: rbac.authorization.k8s.io
    kind: ClusterRole
    name: system:auth-delegator
  subjects:
  - kind: ServiceAccount
    name: dev-scg-user
    namespace: dev-scg

Issue 3: SCG container’s state was not changing to ready state and was getting restarted repeatedly.

Solution: We didn’t observe much activity in gateway logs and after writing below few lines, SCG container was getting restarted.

2022-11-07 15:10:07.106 INFO 1 — [ main] trationDelegate$BeanPostProcessorChecker : Bean ‘reactorDeferringLoadBalancerExchangeFilterFunction’ of type [org.springframework.cloud.client.loadbalancer.reactive.DeferringLoadBalancerExchangeFilterFunction] is not eligible for getting processed by all BeanPostProcessors (for example: not eligible for auto-proxying)
2022-11-07 15:10:30.516 INFO 1 — [ main] i.p.s.c.g.session.SessionConfiguration : hazelcastServiceName = jwt-gateway-headless

We took thread dump of the SCG and analyzed. Classloader thread had spent more than 90 seconds and still could not load all the classes. Meanwhile, readiness probe had been killing the container before it was fully started. All this happened due to very low cpu limits applied on the pod. SCG container got into ready state after increasing cpu limits.

Comments

Popular posts from this blog

SOA SUITE 12.2.1.4 INSTALLATION: GOT EXCEPTION WHEN AUTO CONFIGURING THE SCHEMA COMPONENT(S) WITH DATA OBTAINED FROM SHADOW TABLE

HOW WE REDUCED SOA OSB PROVISIONING FROM 4 DAYS TO 4 HOURS

RABBITMQ CONNECTION ERROR: JAVAX.NET.SSL.SSLHANDSHAKEEXCEPTION: INVALID ECDH SERVERKEYEXCHANGE SIGNATURE