<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACI with Kubernetes needs a fix(Ansible version and Docker cert) in DevNet Sandbox</title>
    <link>https://community.cisco.com/t5/devnet-sandbox/aci-with-kubernetes-needs-a-fix-ansible-version-and-docker-cert/m-p/3888579#M3785</link>
    <description>&lt;P&gt;cisco Umbrella skewed the TLS checks:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;[developer@sbx20kube01 ~]$ echo | openssl s_client -connect storage.googleapis.com:443   | egrep "^subject=|^issuer="                     
depth=3 O = Cisco, CN = Cisco Umbrella Root CA
verify return:1
depth=2 C = US, ST = California, L = San Francisco, O = Cisco, CN = Cisco Umbrella Primary SubCA
verify return:1
depth=1 O = Cisco, CN = Cisco Umbrella Secondary SubCA pao-SG
verify return:1
depth=0 C = US, ST = California, L = San Francisco, O = "OpenDNS, Inc.", CN = *.opendns.com
verify return:1
DONE
subject=/C=US/ST=California/L=San Francisco/O=OpenDNS, Inc./CN=*.opendns.com
issuer=/O=Cisco/CN=Cisco Umbrella Secondary SubCA pao-SG&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&lt;/PRE&gt;</description>
    <pubDate>Thu, 11 Jul 2019 16:16:52 GMT</pubDate>
    <dc:creator>tipkopf</dc:creator>
    <dc:date>2019-07-11T16:16:52Z</dc:date>
    <item>
      <title>ACI with Kubernetes needs a fix(Ansible version and Docker cert)</title>
      <link>https://community.cisco.com/t5/devnet-sandbox/aci-with-kubernetes-needs-a-fix-ansible-version-and-docker-cert/m-p/3887601#M3782</link>
      <description>&lt;P&gt;Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;with Kubernetes 1.15 the lab does not work anymore:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;_kube-system(10388e5ca072958c4f33ec2488d20b33)" with CreatePodSandboxError: "CreatePodSandbox for pod \"etcd-sbx20kube01.localdomain_kube-system(10388e5ca072958c4f33ec2488d20b33)\" failed: rpc error: code = 2 desc = failed pulling image \"gcr.io/google_containers/pause-amd64:3.0\": x509: certificate signed by unknown authority"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried with specifying 1.14.3 that worked for me a month ago to no avail. This is step #8&amp;nbsp;&lt;A href="https://developer.cisco.com/learning/tracks/acik8s/acik8s-setup/acik8s-install/step/8" target="_blank" rel="noopener"&gt;https://developer.cisco.com/learning/tracks/acik8s/acik8s-setup/acik8s-install/step/8&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;running a playbook succeeds only up to 'network':&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;./auto_deploy.sh POD_NUM POD_PASS network&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;next step 'k8' won't work. Also ansible 2.8 is no good, for the playbooks in the lab 2.6.4 is a must:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;sudo ~/sbx_acik8s/venv/bin/pip install ansible==2.6.4&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2019 09:35:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/devnet-sandbox/aci-with-kubernetes-needs-a-fix-ansible-version-and-docker-cert/m-p/3887601#M3782</guid>
      <dc:creator>tipkopf</dc:creator>
      <dc:date>2019-07-10T09:35:02Z</dc:date>
    </item>
    <item>
      <title>Re: ACI with Kubernetes needs a fix(Ansible version and Docker cert)</title>
      <link>https://community.cisco.com/t5/devnet-sandbox/aci-with-kubernetes-needs-a-fix-ansible-version-and-docker-cert/m-p/3888579#M3785</link>
      <description>&lt;P&gt;cisco Umbrella skewed the TLS checks:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;[developer@sbx20kube01 ~]$ echo | openssl s_client -connect storage.googleapis.com:443   | egrep "^subject=|^issuer="                     
depth=3 O = Cisco, CN = Cisco Umbrella Root CA
verify return:1
depth=2 C = US, ST = California, L = San Francisco, O = Cisco, CN = Cisco Umbrella Primary SubCA
verify return:1
depth=1 O = Cisco, CN = Cisco Umbrella Secondary SubCA pao-SG
verify return:1
depth=0 C = US, ST = California, L = San Francisco, O = "OpenDNS, Inc.", CN = *.opendns.com
verify return:1
DONE
subject=/C=US/ST=California/L=San Francisco/O=OpenDNS, Inc./CN=*.opendns.com
issuer=/O=Cisco/CN=Cisco Umbrella Secondary SubCA pao-SG&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&lt;/PRE&gt;</description>
      <pubDate>Thu, 11 Jul 2019 16:16:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/devnet-sandbox/aci-with-kubernetes-needs-a-fix-ansible-version-and-docker-cert/m-p/3888579#M3785</guid>
      <dc:creator>tipkopf</dc:creator>
      <dc:date>2019-07-11T16:16:52Z</dc:date>
    </item>
  </channel>
</rss>

