From ca5e29e6853eac8648b8d76a4795d8aeb714496c Mon Sep 17 00:00:00 2001 From: Ben Vincent Date: Sat, 8 Aug 2026 18:28:41 +1000 Subject: [PATCH] Fix kea CrashLoopBackOff: drop DHCP ntp hostnames, bump to v0.1.1 (#338) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit kea-0/kea-1 crash-looped after the dhcp-system deploy. Two root causes: 1. **kea-dhcp4** rejected the `ntp-servers` option (DHCP code 42) because that option carries IPv4 addresses only, but the KeaCluster supplied rotating `pool.ntp.org` hostnames (`DHCP4_CONFIG_LOAD_FAIL ... Failed to convert string to address '0.au.pool.ntp.org'`). 2. **kea-ctrl-agent/dhcp4** rejected the `/run/kea` unix socket path — kea 2.6.5 permits only `/var/run/kea` (exact-string check). Fixed in kea-operator v0.1.1 (`RunDir=/var/run/kea`). - Remove `ntpServers` from the KeaCluster (not representable via DHCP option 42; add concrete NTP server IPs if ever needed). - Bump kea-operator, kea, and kea-api images v0.1.0 -> v0.1.1 (socket-path fix). kubeconform + pre-commit green. https://claude.ai/code/session_01JUoARVdmhxKQHyyyp1pxeT --------- Co-authored-by: Ben Vincent Reviewed-on: https://git.unkin.net/unkin/argocd-apps/pulls/338 Co-authored-by: Ben Vincent Co-committed-by: Ben Vincent --- apps/base/dhcp-system/cr/keaapi.yaml | 2 +- apps/base/dhcp-system/cr/keacluster.yaml | 10 ++++------ apps/base/dhcp-system/deployment.yaml | 2 +- 3 files changed, 6 insertions(+), 8 deletions(-) diff --git a/apps/base/dhcp-system/cr/keaapi.yaml b/apps/base/dhcp-system/cr/keaapi.yaml index 2d086af..d2c7b7a 100644 --- a/apps/base/dhcp-system/cr/keaapi.yaml +++ b/apps/base/dhcp-system/cr/keaapi.yaml @@ -11,7 +11,7 @@ metadata: argocd.argoproj.io/sync-wave: "1" spec: replicas: 1 - image: git.unkin.net/unkin/kea-api:v0.1.0 + image: git.unkin.net/unkin/kea-api:v0.1.1 tokenSecretName: kea-api-token service: type: ClusterIP diff --git a/apps/base/dhcp-system/cr/keacluster.yaml b/apps/base/dhcp-system/cr/keacluster.yaml index 3ea207b..3b1ce73 100644 --- a/apps/base/dhcp-system/cr/keacluster.yaml +++ b/apps/base/dhcp-system/cr/keacluster.yaml @@ -11,15 +11,13 @@ metadata: argocd.argoproj.io/sync-wave: "1" spec: replicas: 2 - image: git.unkin.net/unkin/kea:v0.1.0 + image: git.unkin.net/unkin/kea:v0.1.1 domainName: main.unkin.net defaultLeaseTime: 1200 maxLeaseTime: 86400 - ntpServers: - - 0.au.pool.ntp.org - - 1.au.pool.ntp.org - - 2.au.pool.ntp.org - - 3.au.pool.ntp.org + # No ntpServers: DHCP option 42 (ntp-servers) carries IPv4 addresses only, so + # the rotating AU pool.ntp.org hostnames cannot be delivered this way (kea + # rejects them at config load). Add concrete NTP server IPs here if needed. ha: mode: hot-standby service: diff --git a/apps/base/dhcp-system/deployment.yaml b/apps/base/dhcp-system/deployment.yaml index 041879c..2f75c40 100644 --- a/apps/base/dhcp-system/deployment.yaml +++ b/apps/base/dhcp-system/deployment.yaml @@ -21,7 +21,7 @@ spec: runAsNonRoot: true containers: - name: operator - image: git.unkin.net/unkin/kea-operator:v0.1.0 + image: git.unkin.net/unkin/kea-operator:v0.1.1 args: - --metrics-bind-address=:8080 - --health-probe-bind-address=:8081