Skip to content

Adding explanation about potential SPIRE agents issues after cluster restart#129

Merged
sabre1041 merged 2 commits into
validatedpatterns:mainfrom
p-rog:ztwim-doc
May 8, 2026
Merged

Adding explanation about potential SPIRE agents issues after cluster restart#129
sabre1041 merged 2 commits into
validatedpatterns:mainfrom
p-rog:ztwim-doc

Conversation

@p-rog
Copy link
Copy Markdown
Collaborator

@p-rog p-rog commented May 7, 2026

If the cluster is down longer than certificate TTL, on startup, the server generates a new  self-signed CA, but the SPIRE agents, still have the old trust bundle cached locally and when they try to re-attest, the TLS handshake fails. This issue is now documented and explain how to handle it.

Copy link
Copy Markdown
Collaborator

@sabre1041 sabre1041 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Very good content @p-rog

Would you be able to review the linting error?

@p-rog
Copy link
Copy Markdown
Collaborator Author

p-rog commented May 8, 2026

Very good content @p-rog

Would you be able to review the linting error?

Sorry, I missed that. Fixed :)

Copy link
Copy Markdown
Collaborator

@sabre1041 sabre1041 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@sabre1041 sabre1041 merged commit 0123194 into validatedpatterns:main May 8, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants