SCG AND VAULT INTEGRATION: LOGIN UNAUTHORIZED DUE TO: X509: CERTIFICATE SIGNED BY UNKNOWN AUTHORITY
We were trying to integrate Spring Cloud Gateway running on K8S with HashiCorp Vault. Wanted to share info how we resolved these issues.
Issue 1: [ERROR] auth.kubernetes.auth_kubernetes: login unauthorized due to: Post “https://10.0.0.:6443/apis/authentication.k8s.io/v1/tokenreviews”: x509: certificate signed by unknown authority
Solution: We used following kubernetes auth config to authenticate client to vault:
vault write auth/kubernetes/config token_reviewer_jwt=”$SA_JWT_TOKEN” kubernetes_host=”$K8S_HOST” kubernetes_ca_cert=”$SA_CA_CRT” issuer=”https://kubernetes.default.svc.cluster.local” disable_iss_validation=”true”
We extracted certificate info using below command:
export SA_CA_CRT=$(kubectl config view –raw –minify –flatten –output ‘jsonpath={.clusters[].cluster.certificate-authority-data}’ | base64 –decode)
While copying the certificate info to vault container we used echo $SA_CA_CRT instead of echo “$SA_CA_CRT”. Due to this new line characters from certificate were removed due to which certificate format became non compliant with pem format. After extracting certificate info using double quote, SCG was able to authenticate with Vault.
Issue 2: Authentication is failing with: {“kind”:”Status”,”apiVersion”:”v1″,”metadata”:{},”status”:”Failure”,”message”:”tokenreviews.authentication.k8s.io is forbidden: User \”system:serviceaccount:dev-scg:service-account-scg\” cannot create resource \”tokenreviews\” in API group \”authentication.k8s.io\” at the cluster scope”,”reason”:”Forbidden”,”details”:{“group”:”authentication.k8s.io”,”kind”:”tokenreviews”},”code”:403}
Solution: As per the above error message, service account doesn’t have right cluster role to create resource tokenreviews. Issue got resolved after creating cluster role binding as below:
apiVersion: rbac.authorization.k8s.io/v1beta1
kind: ClusterRoleBinding
metadata:
name: dev-tokenreview-binding
namespace: dev-scg
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: system:auth-delegator
subjects:
- kind: ServiceAccount
name: dev-scg-user
namespace: dev-scgIssue 3: SCG container’s state was not changing to ready state and was getting restarted repeatedly.
Solution: We didn’t observe much activity in gateway logs and after writing below few lines, SCG container was getting restarted.
2022-11-07 15:10:07.106 INFO 1 — [ main] trationDelegate$BeanPostProcessorChecker : Bean ‘reactorDeferringLoadBalancerExchangeFilterFunction’ of type [org.springframework.cloud.client.loadbalancer.reactive.DeferringLoadBalancerExchangeFilterFunction] is not eligible for getting processed by all BeanPostProcessors (for example: not eligible for auto-proxying)
2022-11-07 15:10:30.516 INFO 1 — [ main] i.p.s.c.g.session.SessionConfiguration : hazelcastServiceName = jwt-gateway-headless
We took thread dump of the SCG and analyzed. Classloader thread had spent more than 90 seconds and still could not load all the classes. Meanwhile, readiness probe had been killing the container before it was fully started. All this happened due to very low cpu limits applied on the pod. SCG container got into ready state after increasing cpu limits.
Comments
Post a Comment