Bug ID 1962261: The controller-manager pods can enter CrashLoopBackOff due to expired API server certificate

Last Modified: Jun 28, 2025

Affected Product(s):
F5OS F5OS-C, Install/Upgrade(all modules)

Known Affected Versions:
F5OS-C 1.5.1, F5OS-C 1.6.0, F5OS-C 1.6.1, F5OS-C 1.6.2, F5OS-C 1.8.1

Opened: May 28, 2025

Severity: 2-Critical

Symptoms

After a controller restart, controller-manager pods enter CrashLoopBackOff state, if the API server certificate has expired.

Impact

The controller-manager pods are currently experiencing a recurring crash loop and new blades can not be added.

Conditions

API server certificate is expired and a controller is rebooted.

Workaround

To check if cert is expired: oc get secret apiserver-ssl -n kube-service-catalog -o jsonpath='{.data.tls\.crt}' | base64 --decode | openssl x509 -noout -enddate As the root user: docker exec -it orchestration_manager bash ansible-playbook -v -i /tmp/omd/etc_ansible_hosts playbooks/openshift-service-catalog/config.yml This script takes about 5 minutes to run and then the pods are fixed.

Fix Information

None

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips