Skip to content

Is there any way to recover from a broken auto-unseal integration? #927

Description

@motjuste

Bug Description

Once two vaults have been deployed successfully and completely with auto-unseal integration, if we break the integration and re-add it, the auto-unsealed vault app never auto-unseals.

As part of Charm endpoint QA at SolutionsQA, one of our tests is to verify the resiliency of charms after an existing integration is broken and re-added, expecting that the charms automatically heal themselves.

I know that the documentation warns against this, but it does not provide what can be done to actually recover from this situation.

We consistently notice in our testing that, e.g. as in this run, the vault app that was expected to be auto-unseal stays stuck with the message "Please unseal Vault" even after the integration has been added back.

Please let us know if there are any steps we could implement in our testing to recover from broken auto-unseal integration.


Filed on behalf of @canonical/solutions-qa

To Reproduce

Minimal bundle:

applications:
  neighbor:
    base: ubuntu@22.04
    channel: 1.16/stable
    charm: vault-k8s
    options: {}
    revision: 502
    scale: 1
    trust: true
  target:
    base: ubuntu@24.04
    channel: 1.19/edge
    charm: vault-k8s
    options: {}
    revision: 513
    scale: 1
    trust: true
bundle: kubernetes
relations:
- - neighbor:vault-autounseal-requires
  - target:vault-autounseal-provides
  1. Deploy a minimal bundle like the one above.
  2. init, unseal, and authorize the unsealer vault (target)
  3. init, wait for auto-unseal, authorize the unsealed vault ('neighbor`)
  4. remove the auto-unseal integration and wait for removal
  5. add the auto-unseal integration back

Environment

Juju 3.6.14, Canonical K8s 1.32.10

Relevant log output

See below for link to a crashdump

Additional context

Crashdump from that sample run: here

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions