Bug Description
Filed on behalf of @canonical/solutions-qa
In our Charm endpoint integration testing, we generated the bundle as described below based on the metadata for vault-k8s from Charmhub. But the bundle's deployment never completes because neighbor vault remains stuck Waiting for CA certificate to be accessible in the charm. This has been observed even with different channels and revisions of vault-k8s.
See one relevant run in Test Observer here. See more such runs here
Are we missing something in the bundle? Or, is the metadata for the charm in Charmhub somehow incomplete?
To Reproduce
juju deploy the following bundle:
applications:
neighbor:
base: ubuntu@22.04
channel: 1.16/stable
charm: vault-k8s
options: {}
revision: 502
scale: 1
trust: true
self-signed-certificates:
base: ubuntu@24.04
channel: 1/stable
charm: self-signed-certificates
options: {}
revision: 317
scale: 1
trust: true
target:
base: ubuntu@24.04
channel: 1.18/stable
charm: vault-k8s
options:
pki_ca_common_name: charmqa
revision: 446
scale: 1
trust: true
bundle: kubernetes
relations:
- - neighbor:tls-certificates-access
- target:vault-pki
- - self-signed-certificates:certificates
- target:tls-certificates-pki
neigbhor charm will stay stuck in waiting status for at least 15 minutes.
Environment
Juju 3/stable and Canonical K8s
Relevant log output
2026-02-21T07:39:53.968Z WARNING juju-log vault-peers:0: Secret self-signed-vault-ca-certificate not found:
2026-02-21T07:39:53.990Z WARNING juju-log vault-peers:0: No relations found for tls-certificates-pki
2026-02-21T07:39:54.043Z DEBUG juju-log vault-peers:0: Adding unit status WaitingStatus('Waiting for CA certificate to be accessible in the charm')
Additional context
The target does show that it successfully created CA certificate:
2026-02-21T07:40:57.817Z WARNING unit.target/0.juju-log Secret self-signed-vault-ca-certificate not found:
2026-02-21T07:40:57.821Z INFO unit.target/0.juju-log Secret self-signed-vault-ca-certificate added to application
Bug Description
Filed on behalf of @canonical/solutions-qa
In our Charm endpoint integration testing, we generated the bundle as described below based on the metadata for
vault-k8sfrom Charmhub. But the bundle's deployment never completes becauseneighborvault remains stuckWaiting for CA certificate to be accessible in the charm. This has been observed even with different channels and revisions ofvault-k8s.See one relevant run in Test Observer here. See more such runs here
Are we missing something in the bundle? Or, is the metadata for the charm in Charmhub somehow incomplete?
To Reproduce
juju deploythe following bundle:neigbhorcharm will stay stuck inwaitingstatus for at least 15 minutes.Environment
Juju 3/stable and Canonical K8s
Relevant log output
Additional context
The
targetdoes show that it successfully created CA certificate: