No relevant resource is found in the selected language.

This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our privacy policy>Search

Reminder

To have a better experience, please upgrade your IE browser.

upgrade

HUAWEI CLOUD Stack 6.5.0 Alarm and Event Reference 04

Rate and give feedback:
Huawei uses machine translation combined with human proofreading to translate this document to different languages in order to help you better understand the content of this document. Note: Even the most advanced machine translation cannot match the quality of professional translators. Huawei shall not bear any responsibility for translation accuracy and it is recommended that you refer to the English document (a link for which has been provided).
ALM-103 Failed to get token from IAM

ALM-103 Failed to get token from IAM

Description

This alarm is generated when the token fails to be obtained from IAM in small-scale scenarios.

Attribute

Alarm ID

Alarm Severity

Alarm Type

103

Major

Environment alarm

Parameters

Parameter Name

Parameter Description

kind

Resource type.

namespace

Name of the project to which the resource belongs.

name

Resource name.

uid

Unique ID of the resource.

OriginalEventTime

Event generation time.

EventSource

Name of the component that reports an event.

EventMessage

Supplementary information about an event.

Impact on the System

If the token fails to be obtained, user operations are restricted.

System Actions

The system keeps obtaining the token.

Possible Causes

The kube-controller-manager fails to obtain the token from IAM because the IAM address is unreachable or the IAM service is unavailable.

Procedure

  1. Obtain the namespace from the Location Info field in the alarm information.

    1. Use a browser to log in to the FusionStage OM zone console.
      1. Log in to ManageOne Maintenance Portal.
        • Login address: https://Address for accessing the homepage of ManageOne Maintenance Portal:31943, for example, https://oc.type.com:31943.
        • The default username is admin, and the default password is Huawei12#$.
      2. On the O&M Maps page, click the FusionStage link under Quick Links to go to the FusionStage OM zone console.
    2. Choose Application Operations > Application Operations from the main menu.
    3. In the navigation pane on the left, choose Alarm Center > Alarm List and query the alarm by setting query criteria.
    4. Click to expand the alarm information. Record the value of namespace in Location Info, that is namespace.

  2. Use PuTTY to log in to the manage_lb1_ip node.

    The default username is paas, and the default password is QAZ2wsx@123!.

  3. Run the following command and enter the password of the root user to switch to the root user:

    su - root

    Default password: QAZ2wsx@123!

  4. Run the following command to query the instance name of kube-controller-manager.

    kubectl get po -n {namespace} | grep kube-controller-manager

    In the preceding command, {namespace} is the namespace obtained in 1.

    kube-controller-manager-paas-10-118-29-64   2/2       Running            2          36m

  5. Run the following command to obtain the node address where the instance resides.

    kubectl get pod -n fst-manage {kube-controller-managerName} -o yaml | grep hostIP

    The following information is displayed:

     hostIP: 10.118.29.64

    In the preceding command, {kube-controller-managerName} is the name of kube-controller-managerobtained in 4. For example:

    kubectl get pod -n fst-manage kube-controller-manager-paas-10-118-29-64 -o yaml | grep hostIP

  6. Identify the fault cause.

    1. Run the following command to log in the node where the instance resides.

      ssh NodeAddress

      In the preceding command, NodeAddress is the node address obtained in 5.

    2. Run the following commands to view the ingress-controller log:

      cd /var/paas/sys/log/kubernetes/kube-controller-manager/

      vi kube-service-controller.log

      Press ?, enter iam-address, and press Enter. Obtain the URL for obtaining the token.

    3. Run the following command to check whether the IAM address is reachable.

      curl -k -v url/v3/auth/tokens

      url indicates the URL for obtaining the token obtained in 6.b. For example: curl -k -v https://10.118.29.178:26330/v3/auth/tokens

      Collect the displayed information and contact technical support for assistance.

Alarm Clearing

This alarm will be automatically cleared after the fault is rectified.

Related Information

None

Translation
Download
Updated: 2019-08-30

Document ID: EDOC1100062365

Views: 49154

Downloads: 33

Average rating:
This Document Applies to these Products
Related Version
Related Documents
Share
Previous Next