Troubleshooting the control plane machine set
Use the following information to understand and recover from issues you might encounter.
Checking the control plane machine set custom resource state
Check the state of the control plane machine set custom resource to determine if it is active, inactive, or missing before making configuration changes.
Procedure
-
Determine the state of the CR by running the following command:
$ oc get controlplanemachineset.machine.openshift.io cluster \--namespace openshift-machine-api- A result of
Activeindicates that theControlPlaneMachineSetCR exists and is activated. No administrator action is required. - A result of
Inactiveindicates that aControlPlaneMachineSetCR exists but is not activated. - A result of
NotFoundindicates that there is no existingControlPlaneMachineSetCR.
- A result of
Next steps
To use the control plane machine set, you must ensure that a ControlPlaneMachineSet CR with the correct settings for your cluster exists.
- If your cluster has an existing CR, you must verify that the configuration in the CR is correct for your cluster.
- If your cluster does not have an existing CR, you must create one with the correct configuration for your cluster.
Additional resources
- Activating the control plane machine set custom resource
- Creating a control plane machine set custom resource
Adding a missing Azure internal load balancer
Add the required internalLoadBalancer parameter to Azure control plane resources to ensure proper load balancing configuration.
For more information about where this parameter is located in the Azure provider specification, see the sample Azure provider specification. The placement in the control plane Machine CR is similar.
Procedure
- List the control plane machines in your cluster by running the following command:
$ oc get machines \-l machine.openshift.io/cluster-api-machine-role==master \-n openshift-machine-api
- For each control plane machine, edit the CR by running the following command:
$ oc edit machine <control_plane_machine_name>
- Add the
internalLoadBalancerparameter with the correct details for your cluster and save your changes. - Edit your control plane machine set CR by running the following command:
$ oc edit controlplanemachineset.machine.openshift.io cluster \-n openshift-machine-api
- Add the
internalLoadBalancerparameter with the correct details for your cluster and save your changes.
Next steps
- For clusters that use the default
RollingUpdateupdate strategy, the Operator automatically propagates the changes to your control plane configuration. - For clusters that are configured to use the
OnDeleteupdate strategy, you must replace your control plane machines manually.
Additional resources
Recovering a degraded etcd Operator
Recover a degraded etcd Operator by removing failed members to restore cluster state after machine health check operations.
For example, while performing remediation, the machine health check might delete a control plane machine that is hosting etcd. If the etcd member is not reachable at that time, the etcd Operator becomes degraded.
When the etcd Operator is degraded, manual intervention is required to force the Operator to remove the failed member and restore the cluster state.
Procedure
-
List the control plane machines in your cluster by running the following command:
$ oc get machines \-l machine.openshift.io/cluster-api-machine-role==master \-n openshift-machine-api \-o wideAny of the following conditions might indicate a failed control plane machine:
- The
STATEvalue isstopped. - The
PHASEvalue isFailed. - The
PHASEvalue isDeletingfor more than ten minutes.
warningBefore continuing, ensure that your cluster has two healthy control plane machines. Performing the actions in this procedure on more than one control plane machine risks losing etcd quorum and can cause data loss.
If you have lost the majority of your control plane hosts, leading to etcd quorum loss, then you must follow the disaster recovery procedure "Restoring to an earlier cluster state" instead of this procedure.
- The
-
Edit the machine CR for the failed control plane machine by running the following command:
$ oc edit machine <control_plane_machine_name> -
Remove the contents of the
lifecycleHooksparameter from the failed control plane machine and save your changes. The etcd Operator removes the failed machine from the cluster and can then safely add new etcd members.
Additional resources
Upgrading clusters that run on RHOSP
Review post-upgrade requirements for clusters running on Red Hat OpenStack Platform (RHOSP) to ensure control plane machine sets function correctly.
For clusters that run on RHOSP that were created with OpenShift Container Platform 4.13 or earlier, you might have to perform post-upgrade tasks before you can use control plane machine sets.
Configuring RHOSP clusters that have machines with root volume availability zones after an upgrade
For some clusters that run on Red Hat OpenStack Platform (RHOSP) that you upgrade, you must manually update machine resources before you can use control plane machine sets if the following configurations are true:
- The upgraded cluster was created with OpenShift Container Platform 4.13 or earlier.
- The cluster infrastructure is installer-provisioned.
- Machines were distributed across multiple availability zones.
- Machines were configured to use root volumes for which block storage availability zones were not defined.
To understand why this procedure is necessary, see Solution #7024383.
Procedure
-
For all control plane machines, edit the provider spec for all control plane machines that match the environment. For example, to edit the machine
master-0, enter the following command:$ oc edit machine/<cluster_id>-master-0 -n openshift-machine-apiwhere:
<cluster_id>- Specifies the ID of the upgraded cluster.
-
In the provider spec, set the value of the property
rootVolume.availabilityZoneto the volume of the availability zone you want to use.An example RHOSP provider specproviderSpec:value:apiVersion: machine.openshift.io/v1alpha1availabilityZone: az0cloudName: openstackcloudsSecret:name: openstack-cloud-credentialsnamespace: openshift-machine-apiflavor: m1.xlargeimage: rhcos-4.14kind: OpenstackProviderSpecmetadata:creationTimestamp: nullnetworks:- filter: {}subnets:- filter:name: refarch-lv7q9-nodestags: openshiftClusterID=refarch-lv7q9rootVolume:availabilityZone: novadiskSize: 30sourceUUID: rhcos-4.12volumeType: fast-0securityGroups:- filter: {}name: refarch-lv7q9-masterserverGroupName: refarch-lv7q9-masterserverMetadata:Name: refarch-lv7q9-masteropenshiftClusterID: refarch-lv7q9tags:- openshiftClusterID=refarch-lv7q9trunk: trueuserDataSecret:name: master-user-datawhere:
availabilityZone: nova- Specifies the zone name for the root volume.
noteIf you edited or recreated machine resources after your initial cluster deployment, you might have to adapt these steps for your configuration.
In your RHOSP cluster, find the availability zone of the root volumes for your machines and use that as the value.
-
Run the following command to retrieve information about the control plane machine set resource:
$ oc describe controlplanemachineset.machine.openshift.io/cluster --namespace openshift-machine-api -
Run the following command to edit the resource:
$ oc edit controlplanemachineset.machine.openshift.io/cluster --namespace openshift-machine-api -
For that resource, set the value of the
spec.stateproperty toActiveto activate control plane machine sets for your cluster. The control plane is now ready to be managed by the Cluster Control Plane Machine Set Operator.
Configuring RHOSP clusters that have control plane machines with availability zones after an upgrade
For some clusters that run on Red Hat OpenStack Platform (RHOSP) that you upgrade, you must manually update machine resources before you can use control plane machine sets if the following configurations are true:
- The upgraded cluster was created with OpenShift Container Platform 4.13 or earlier.
- The cluster infrastructure is installer-provisioned.
- Control plane machines were distributed across multiple compute availability zones.
To understand why this procedure is necessary, see Solution #7013893.
Procedure
-
For the
master-1andmaster-2control plane machines, open the provider specs for editing. For example, to edit the first machine, enter the following command:$ oc edit machine/<cluster_id>-master-1 -n openshift-machine-apiwhere:
<cluster_id>- Specifies the ID of the upgraded cluster.
-
For the
master-1andmaster-2control plane machines, edit the value of theserverGroupNameproperty in their provider specs to match that of the machinemaster-0.An example RHOSP provider specproviderSpec:value:apiVersion: machine.openshift.io/v1alpha1availabilityZone: az0cloudName: openstackcloudsSecret:name: openstack-cloud-credentialsnamespace: openshift-machine-apiflavor: m1.xlargeimage: rhcos-4.22kind: OpenstackProviderSpecmetadata:creationTimestamp: nullnetworks:- filter: {}subnets:- filter:name: refarch-lv7q9-nodestags: openshiftClusterID=refarch-lv7q9securityGroups:- filter: {}name: refarch-lv7q9-masterserverGroupName: refarch-lv7q9-master-az0serverMetadata:Name: refarch-lv7q9-masteropenshiftClusterID: refarch-lv7q9tags:- openshiftClusterID=refarch-lv7q9trunk: trueuserDataSecret:name: master-user-datawhere:
serverGroupName- Specifies the server group name. This value must match for machines
master-0,master-1, andmaster-2.
noteIf you edited or recreated machine resources after your initial cluster deployment, you might have to adapt these steps for your configuration.
In your RHOSP cluster, find the server group that your control plane instances are in and use that as the value.
-
Run the following command to retrieve information about the control plane machine set resource:
$ oc describe controlplanemachineset.machine.openshift.io/cluster --namespace openshift-machine-api -
Run the following command to edit the resource:
$ oc edit controlplanemachineset.machine.openshift.io/cluster --namespace openshift-machine-api -
For that resource, set the value of the
spec.stateproperty toActiveto activate control plane machine sets for your cluster. The control plane is now ready to be managed by the Cluster Control Plane Machine Set Operator.
Improving reliability for multiple subnet configurations on Nutanix
To improve reliability and avoid common networking problems with multiple subnet configurations on Nutanix, adhere to the configuration practices that minimize networking conflicts.
The following networking configuration and management practices can help your multiple subnet configuration perform more reliably:
-
To avoid overlapping IP address assignments, use predefined static IP addresses in the
cloud-initmetadata. -
Tag all VMs, disks, and networks with a unique cluster ID.
-
Avoid IP address conflicts by using dedicated subnets for each OpenShift Container Platform cluster: Nutanix uses Nutanix Acropolis Hypervisor (AHV) and Nutanix Prism networking to assign IP addresses to virtual machines (VMs). If a single subnet provides IP addresses for more than one OpenShift Container Platform cluster, AHV or Prism might assign the same IP address to a VM or pod in more than one cluster.
To avoid this issue, use dedicated subnets for each OpenShift Container Platform cluster, even when you have more than one cluster on a single Prism Central instance. You can use the Prism UI or automation tools, such as Terraform or Ansible, to create separate IP address pools for each OpenShift Container Platform cluster.
-
Ensure that each OpenShift Container Platform cluster uses distinct DNS zones and virtual IP address ranges.
-
Avoid DHCP conflicts by maintaining DHCP allocations: If you use Nutanix to manage DHCP allocation, objects in your cluster might have duplicate leases. Duplicate leases can cause DHCP conflicts when you apply changes to the control plane machine set custom resource (CR) specification.
To avoid this issue, regularly remove stale DHCP leases.
-
Use automation tools, such as Terraform or Ansible, to isolate the infrastructure for each OpenShift Container Platform cluster.