https://rancher.com/ logo
#rke2
Title
# rke2
l

little-actor-95014

10/03/2022, 8:57 PM
Anyone else seeing Calico's ServiceAccoun token expire and breaking spawning containers with
"plugin type="calico" failed (add): error getting ClusterInformation: connection is unauthorized: Unauthorized"
since upgrading to
v1.24.6+rke2r1
from a 1.23 release? I assume it's something to do with the change to service account configs in 1.24 with
LegacyServiceAccountTokenNoAutoGeneration
going to enabled by default?
c

creamy-pencil-82913

10/03/2022, 9:32 PM
no… did calico itself get upgraded properly? Are you using the packaged Calico or have you deployed it on your own?
l

little-actor-95014

10/03/2022, 9:35 PM
We're using packaged calico. From what I can tell it upgraded right, it's young enough and the image version matches what the release notes for 1.24.6 say. The token in /etc/cni/net.d/calico-kubeconfig is expired, I do not know if a) that expect, or B) actually causing the issue
I should clarify we're using canal as the CNI rather than just calico
(I do also have a Rancher support case open in parallel to asking here, just thought I'd ask just in case 🙂 )
b

bland-account-99790

10/04/2022, 12:30 PM
Do you have a link to it? That will help us 😉
b

bumpy-farmer-58104

10/04/2022, 1:29 PM
Hey @little-actor-95014 I see that one of our engineers is working the case with you. I will get @bland-account-99790 and @creamy-pencil-82913 the information behind the scenes and ensure the context is consistent
b

bland-account-99790

10/06/2022, 4:56 PM
65 Views