x509: certificate signed by unknown authority in cattle-cluster-agent
0 reputation · 09 Jan 2024, 00:27 UTC
TLS Handshake Failure in Downstream Clusters
When deploying Rancher 2.x with private CA certificates or a custom certificate authority, downstream cluster agents may fail to establish a secure connection to the Rancher server. This typically manifests as the cattle-cluster-agent or cattle-node-agent pods entering a CrashLoopBackOff state.
Trust Chain Configuration
The agent relies on a CA checksum to validate the server's identity. If TLS is terminated at an external load balancer or proxy before reaching the Rancher ingress, the certificate chain presented to the agent may differ from the one generated by Rancher, leading to validation failures.
There is uncertainty regarding the optimal trust configuration when using a hybrid approach of external termination and internal re-encryption, specifically concerning how the agent's CA bundle is updated during certificate rotation without triggering cluster-wide disconnects.
- How does the agent handle a mismatch between the served certificate chain and the
cacertssetting during a rolling update? - What is the impact of external TLS termination on the agent's ability to verify the Rancher server's identity via the registration command checksum?