Skip to content

OCPBUGS-23418: Machine-config controller should not log about non-existent pull-secret changes#5625

Merged
openshift-merge-bot[bot] merged 1 commit intoopenshift:mainfrom
dkhater-redhat:fix-pull-secret-log-spam-master
Feb 12, 2026
Merged

OCPBUGS-23418: Machine-config controller should not log about non-existent pull-secret changes#5625
openshift-merge-bot[bot] merged 1 commit intoopenshift:mainfrom
dkhater-redhat:fix-pull-secret-log-spam-master

Conversation

@dkhater-redhat
Copy link
Contributor

@dkhater-redhat dkhater-redhat commented Feb 5, 2026

- What I did
Fixed false-positive log spam where MCC logged "Re-syncing ControllerConfig due to secret pull-secret change" every ~25 minutes even though the pull-secret secret hadn't actually changed.

- How to verify it
Check logs on a running cluster

  1. Install a cluster with this fix
  2. Wait 1+ hours without modifying the pull-secret
  3. Check MCC logs:
    oc logs -n openshift-machine-config-operator -l k8s-app=machine-config-controller -c machine-config-controller --tail=-1 | grep -c 'Re-syncing ControllerConfig due to secret pull-secret change'
  4. Expected: Count should be 0 (no false positives)
  5. Without fix: Count would be ~7+ over a few hours

- Description for the changelog

@dkhater-redhat dkhater-redhat changed the title machine-config-daemon: openshift: Exposure of Sensitive Data in Log Files in the Machine Configuration Daemon. [openshift-4] Machine-config controller should not log about non-existent pull-secret changes Feb 5, 2026
@dkhater-redhat dkhater-redhat changed the title Machine-config controller should not log about non-existent pull-secret changes OCPBUGS-23418: Machine-config controller should not log about non-existent pull-secret changes Feb 5, 2026
@dkhater-redhat dkhater-redhat force-pushed the fix-pull-secret-log-spam-master branch from 7457eb9 to a9f3029 Compare February 5, 2026 15:48
@dkhater-redhat
Copy link
Contributor Author

/jira refresh

1 similar comment
@dkhater-redhat
Copy link
Contributor Author

/jira refresh

@umohnani8
Copy link
Contributor

Great fix!
/lgtm
/approve

@dkhater-redhat
Copy link
Contributor Author

/jira refresh

@openshift-ci-robot openshift-ci-robot added jira/severity-low Referenced Jira bug's severity is low for the branch this PR is targeting. jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. jira/valid-bug Indicates that a referenced Jira bug is valid for the branch this PR is targeting. labels Feb 5, 2026
@openshift-ci-robot
Copy link
Contributor

@dkhater-redhat: This pull request references Jira Issue OCPBUGS-23418, which is valid.

3 validation(s) were run on this bug
  • bug is open, matching expected state (open)
  • bug target version (4.22.0) matches configured target version for branch (4.22.0)
  • bug is in the state POST, which is one of the valid states (NEW, ASSIGNED, POST)

Requesting review from QA contact:
/cc @HarshwardhanPatil07

The bug has been updated to refer to the pull request using the external bug tracker.

Details

In response to this:

/jira refresh

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@umohnani8
Copy link
Contributor

/lgtm
/approve

@openshift-ci openshift-ci bot added lgtm Indicates that a PR is ready to be merged. approved Indicates a PR has been approved by an approver from all required OWNERS files. labels Feb 5, 2026
@HarshwardhanPatil07
Copy link

Pre-merge Verification: PASSED

Environment Setup:
Platform: AWS
Fixed Version: 4.22.0-0-2026-02-06-055557-test-ci-ln-85jv8sb-latest

1. Verification on Fixed main (Success)

Observation: The count remained stable at 2 and did not increment over time (pull-secret was not modified).

Verification Steps:

harshpat@harshpat-thinkpadp1gen4i:~/Downloads$ oc get clusterversion
NAME      VERSION                                                AVAILABLE   PROGRESSING   SINCE   STATUS
version   4.22.0-0-2026-02-06-055557-test-ci-ln-85jv8sb-latest   True        False         64m     Cluster version is 4.22.0-0-2026-02-06-055557-test-ci-ln-85jv8sb-latest
harshpat@harshpat-thinkpadp1gen4i:~/Downloads$ oc logs -n openshift-machine-config-operator -l k8s-app=machine-config-controller -c machine-config-controller --tail=-1 | grep -c 'Re-syncing ControllerConfig due to secret pull-secret change'
2

After some time

harshpat@harshpat-thinkpadp1gen4i:~/Downloads$ oc logs -n openshift-machine-config-operator -l k8s-app=machine-config-controller -c machine-config-controller --tail=-1 | grep -c 'Re-syncing ControllerConfig due to secret pull-secret change'
2

/label qe-approved
/verified by @HarshwardhanPatil07

@openshift-ci openshift-ci bot added the qe-approved Signifies that QE has signed off on this PR label Feb 6, 2026
@openshift-ci-robot openshift-ci-robot added the verified Signifies that the PR passed pre-merge verification criteria label Feb 6, 2026
@openshift-ci-robot
Copy link
Contributor

@HarshwardhanPatil07: This PR has been marked as verified by @HarshwardhanPatil07.

Details

In response to this:

Pre-merge Verification: PASSED

Environment Setup:
Platform: AWS
Fixed Version: 4.22.0-0-2026-02-06-055557-test-ci-ln-85jv8sb-latest

1. Verification on Fixed main (Success)

Observation: The count remained stable at 2 and did not increment over time (pull-secret was not modified).

Verification Steps:

harshpat@harshpat-thinkpadp1gen4i:~/Downloads$ oc get clusterversion
NAME      VERSION                                                AVAILABLE   PROGRESSING   SINCE   STATUS
version   4.22.0-0-2026-02-06-055557-test-ci-ln-85jv8sb-latest   True        False         64m     Cluster version is 4.22.0-0-2026-02-06-055557-test-ci-ln-85jv8sb-latest
harshpat@harshpat-thinkpadp1gen4i:~/Downloads$ oc logs -n openshift-machine-config-operator -l k8s-app=machine-config-controller -c machine-config-controller --tail=-1 | grep -c 'Re-syncing ControllerConfig due to secret pull-secret change'
2

After some time

harshpat@harshpat-thinkpadp1gen4i:~/Downloads$ oc logs -n openshift-machine-config-operator -l k8s-app=machine-config-controller -c machine-config-controller --tail=-1 | grep -c 'Re-syncing ControllerConfig due to secret pull-secret change'
2

/label qe-approved
/verified by @HarshwardhanPatil07

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@dkhater-redhat
Copy link
Contributor Author

/retest-required

1 similar comment
@dkhater-redhat
Copy link
Contributor Author

/retest-required

@dkhater-redhat
Copy link
Contributor Author

/test verify

@openshift-ci-robot openshift-ci-robot removed the verified Signifies that the PR passed pre-merge verification criteria label Feb 10, 2026
@openshift-ci openshift-ci bot removed the lgtm Indicates that a PR is ready to be merged. label Feb 10, 2026
make verify error
@dkhater-redhat dkhater-redhat force-pushed the fix-pull-secret-log-spam-master branch from dadb03c to 1cf8e05 Compare February 10, 2026 18:18
@dkhater-redhat
Copy link
Contributor Author

/verified by @HarshwardhanPatil07
had to push a change for the make verify error

@openshift-ci-robot openshift-ci-robot added the verified Signifies that the PR passed pre-merge verification criteria label Feb 10, 2026
@openshift-ci-robot
Copy link
Contributor

@dkhater-redhat: This PR has been marked as verified by @HarshwardhanPatil07.

Details

In response to this:

/verified by @HarshwardhanPatil07
had to push a change for the make verify error

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

Copy link
Member

@isabella-janssen isabella-janssen left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm

@openshift-ci openshift-ci bot added the lgtm Indicates that a PR is ready to be merged. label Feb 12, 2026
@openshift-ci
Copy link
Contributor

openshift-ci bot commented Feb 12, 2026

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: dkhater-redhat, HarshwardhanPatil07, isabella-janssen, umohnani8

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:
  • OWNERS [dkhater-redhat,isabella-janssen,umohnani8]

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@dkhater-redhat
Copy link
Contributor Author

/retest-required

@openshift-merge-bot openshift-merge-bot bot merged commit 18f57e2 into openshift:main Feb 12, 2026
9 of 15 checks passed
@openshift-ci-robot
Copy link
Contributor

@dkhater-redhat: Jira Issue Verification Checks: Jira Issue OCPBUGS-23418
✔️ This pull request was pre-merge verified.
✔️ All associated pull requests have merged.
✔️ All associated, merged pull requests were pre-merge verified.

Jira Issue OCPBUGS-23418 has been moved to the MODIFIED state and will move to the VERIFIED state when the change is available in an accepted nightly payload. 🕓

Details

In response to this:

- What I did
Fixed false-positive log spam where MCC logged "Re-syncing ControllerConfig due to secret pull-secret change" every ~25 minutes even though the pull-secret secret hadn't actually changed.

- How to verify it
Check logs on a running cluster

  1. Install a cluster with this fix
  2. Wait 1+ hours without modifying the pull-secret
  3. Check MCC logs:
    oc logs -n openshift-machine-config-operator -l k8s-app=machine-config-controller -c machine-config-controller --tail=-1 | grep -c 'Re-syncing ControllerConfig due to secret pull-secret change'
  4. Expected: Count should be 0 (no false positives)
  5. Without fix: Count would be ~7+ over a few hours

- Description for the changelog

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@dkhater-redhat
Copy link
Contributor Author

/cherry-pick release-4.21

@openshift-cherrypick-robot

@dkhater-redhat: new pull request created: #5659

Details

In response to this:

/cherry-pick release-4.21

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. jira/severity-low Referenced Jira bug's severity is low for the branch this PR is targeting. jira/valid-bug Indicates that a referenced Jira bug is valid for the branch this PR is targeting. jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. lgtm Indicates that a PR is ready to be merged. qe-approved Signifies that QE has signed off on this PR verified Signifies that the PR passed pre-merge verification criteria

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants