@@ -12,6 +12,7 @@ import (
1212 "github.com/openshift/library-go/pkg/controller/factory"
1313 corev1informers "k8s.io/client-go/informers/core/v1"
1414 "k8s.io/client-go/tools/cache"
15+ "k8s.io/klog/v2"
1516
1617 "k8s.io/apimachinery/pkg/api/errors"
1718 "k8s.io/apimachinery/pkg/util/sets"
@@ -75,6 +76,7 @@ func (c *AuthConfigChecker) OIDCAvailable() (bool, error) {
7576 nodesWithEmptyRevision := false
7677 for _ , nodeStatus := range kas .Status .NodeStatuses {
7778 if nodeStatus .CurrentRevision > 0 {
79+ klog .Infof ("[debug-801] node '%s' is on revision %d" , nodeStatus .NodeName , nodeStatus .CurrentRevision )
7880 observedRevisions .Insert (nodeStatus .CurrentRevision )
7981 } else {
8082 nodesWithEmptyRevision = true
@@ -93,6 +95,7 @@ func (c *AuthConfigChecker) OIDCAvailable() (bool, error) {
9395 // ensure every observed revision includes an auth-config revisioned configmap
9496 _ , err := c .kasConfigMapLister .ConfigMaps ("openshift-kube-apiserver" ).Get (fmt .Sprintf ("auth-config-%d" , revision ))
9597 if errors .IsNotFound (err ) {
98+ klog .Infof ("[debug-801] configmap auth-config-%d not found" , revision )
9699 return false , nil
97100 } else if err != nil {
98101 return false , fmt .Errorf ("getting configmap openshift-kube-apiserver/auth-config-%d: %v" , revision , err )
@@ -109,6 +112,7 @@ func (c *AuthConfigChecker) OIDCAvailable() (bool, error) {
109112 if ! strings .Contains (cm .Data ["config.yaml" ], `"oauthMetadataFile":""` ) ||
110113 strings .Contains (cm .Data ["config.yaml" ], `"authentication-token-webhook-config-file":` ) ||
111114 ! strings .Contains (cm .Data ["config.yaml" ], `"authentication-config":["/etc/kubernetes/static-pod-resources/configmaps/auth-config/auth-config.json"]` ) {
115+ klog .Infof ("[debug-801] configmap config-%d does not contain expected OIDC config" , revision )
112116 return false , nil
113117 }
114118 }
0 commit comments