cassandra-medusa icon indicating copy to clipboard operation
cassandra-medusa copied to clipboard

K8ssandra medusa container can't connect to s3 storage with self-signed certificate

Open handrea2009 opened this issue 2 years ago • 6 comments

K8ssandra medusa containers fails to start cause it can't connect to s3 compatible storage with self-signed certificate. The medusa container log the following errors (I got the same whether secure = false or secure = true in medusa.ini)

`[2022-12-21 06:55:58,111] DEBUG: Starting new HTTPS connection (1): XXXXXX.com:443 Traceback (most recent call last): File "/home/cassandra/.local/lib/python3.6/site-packages/urllib3/connectionpool.py", line 706, in urlopen chunked=chunked, File "/home/cassandra/.local/lib/python3.6/site-packages/urllib3/connectionpool.py", line 382, in _make_request self.validate_conn(conn) File "/home/cassandra/.local/lib/python3.6/site-packages/urllib3/connectionpool.py", line 1010, in validate_conn conn.connect() File "/home/cassandra/.local/lib/python3.6/site-packages/urllib3/connection.py", line 426, in connect tls_in_tls=tls_in_tls, File "/home/cassandra/.local/lib/python3.6/site-packages/urllib3/util/ssl.py", line 450, in ssl_wrap_socket sock, context, tls_in_tls, server_hostname=server_hostname File "/home/cassandra/.local/lib/python3.6/site-packages/urllib3/util/ssl.py", line 493, in _ssl_wrap_socket_impl return ssl_context.wrap_socket(sock, server_hostname=server_hostname) File "/usr/lib/python3.6/ssl.py", line 407, in wrap_socket _context=self, _session=session) File "/usr/lib/python3.6/ssl.py", line 817, in init self.do_handshake() File "/usr/lib/python3.6/ssl.py", line 1077, in do_handshake self._sslobj.do_handshake() File "/usr/lib/python3.6/ssl.py", line 689, in do_handshake self._sslobj.do_handshake() ssl.SSLError: [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed (_ssl.c:852)

During handling of the above exception, another exception occurred:

Traceback (most recent call last): File "/home/cassandra/.local/lib/python3.6/site-packages/requests/adapters.py", line 449, in send timeout=timeout File "/home/cassandra/.local/lib/python3.6/site-packages/urllib3/connectionpool.py", line 756, in urlopen method, url, error=e, _pool=self, _stacktrace=sys.exc_info()[2] File "/home/cassandra/.local/lib/python3.6/site-packages/urllib3/util/retry.py", line 574, in increment raise MaxRetryError(_pool, url, error or ResponseError(cause)) urllib3.exceptions.MaxRetryError: HTTPSConnectionPool(host='XXXXXX.com', port=443): Max retries exceeded with url: /backup-medusa (Caused by SSLError(SSLError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed (_ssl.c:852)'),))

During handling of the above exception, another exception occurred:

Traceback (most recent call last): File "/usr/lib/python3.6/runpy.py", line 193, in _run_module_as_main "main", mod_spec) File "/usr/lib/python3.6/runpy.py", line 85, in _run_code exec(code, run_globals) File "/home/cassandra/medusa/service/grpc/server.py", line 158, in medusa_pb2_grpc.add_MedusaServicer_to_server(MedusaService(config), server) File "/home/cassandra/medusa/service/grpc/server.py", line 44, in init self.storage = Storage(config=self.config.storage) File "/home/cassandra/medusa/storage/init.py", line 72, in init self.storage_driver = self._connect_storage() File "/home/cassandra/medusa/storage/init.py", line 88, in _connect_storage s3_storage = S3BaseStorage(self._config) File "/home/cassandra/medusa/storage/abstract_storage.py", line 40, in init self.bucket = self.driver.get_container(container_name=config.bucket_name) File "/home/cassandra/.local/lib/python3.6/site-packages/libcloud/storage/drivers/s3.py", line 357, in get_container method='HEAD') File "/home/cassandra/.local/lib/python3.6/site-packages/libcloud/common/base.py", line 623, in request headers=headers, stream=stream) File "/home/cassandra/.local/lib/python3.6/site-packages/libcloud/http.py", line 232, in request verify=self.verification File "/home/cassandra/.local/lib/python3.6/site-packages/requests/sessions.py", line 542, in request resp = self.send(prep, **send_kwargs) File "/home/cassandra/.local/lib/python3.6/site-packages/requests/sessions.py", line 655, in send r = adapter.send(request, **kwargs) File "/home/cassandra/.local/lib/python3.6/site-packages/requests/adapters.py", line 514, in send raise SSLError(e, request=request) requests.exceptions.SSLError: HTTPSConnectionPool(host='XXXXX.com', port=443): Max retries exceeded with url: /backup-medusa (Caused by SSLError(SSLError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed (_ssl.c:852)'),))`

handrea2009 avatar Dec 21 '22 08:12 handrea2009