Skip to content

save the keystore passphrase when agent.properties is missing on a new kvm host - #14361

Draft
Damans227 wants to merge 1 commit into
apache:mainfrom
Damans227:nl/issue-13079
Draft

Damans227 wants to merge 1 commit into
apache:mainfrom
Damans227:nl/issue-13079

Conversation

@Damans227

@Damans227 Damans227 commented Oct 8, 2026 •

Copy link
Copy Markdown
Collaborator

Fixes #13079

Adding a fresh KVM host fails when /etc/cloudstack/agent/agent.properties does not exist yet. keystore-setup only saves the keystore passphrase when that file is already there, so on a new host the passphrase is never written. The next step, keystore-cert-import, reads the passphrase from that file, finds nothing and exits, and after three tries the add fails with "Failed to setup certificate in the KVM agent's keystore file". This creates the file when it is missing, so the passphrase is saved and the host adds on the first try. When the file already has a passphrase it is reused as before.

Test:

On a KVM lab, put a host in maintenance and remove it. On the host, stop cloudstack-agent and clear /etc/cloudstack/agent/ so only environment.properties and log4j-cloud.xml are left. Then add it back with cmk add host hypervisor=KVM url=http://10.0.33.100 .... For before, the same steps with main's keystore-setup copied onto the host.

Before: add fails, no agent.properties is created.

(HTTP 530, error code 9999) Could not add host at [http://10.0.33.100] ... due to: [ can't setup agent, due to com.cloud.utils.exception.CloudRuntimeException: Failed to import certificates into agent keystore via SSH on host: 10.0.33.100 ...]

management-server.log, same output three times:

Executing cmd: sudo /usr/share/cloudstack-common/scripts/util/keystore-cert-import /etc/cloudstack/agent/agent.properties ...
SSH command output:Failed to find keystore passphrase from file: /etc/cloudstack/agent/agent.properties, quitting!
WARN  [c.c.h.k.d.KvmServerDiscoverer] can't setup agent, due to com.cloud.utils.exception.CloudRuntimeException: Failed to import certificates into agent keystore via SSH on host: 10.0.33.100

On the host:

cloudstack-keystore-setup: Cannot chmod /etc/cloudstack/agent/agent.properties
# ls /etc/cloudstack/agent
cloud.csr  cloud.jks  environment.properties  log4j-cloud.xml

After: host adds on the first try.

"name": "pr14361-n79-kvm-ol8-kvm2",
"resourcestate": "Enabled",
"state": "Up"
cloudstack-keystore-setup: Props file does not exist, creating it
cloudstack-keystore-setup: New keystore password set
KvmServerDiscoverer Succeeded to import certificate in the keystore for agent on the KVM host: 10.0.33.100. Agent secured and trusted.

Removing the host and adding it again without clearing the folder reuses the saved passphrase, and agent.properties still has one keystore.passphrase line:

cloudstack-keystore-setup: Password extraction successful

@Damans227

Copy link
Copy Markdown
Collaborator Author

@blueorangutan package

@blueorangutan

Copy link
Copy Markdown

@Damans227 a [SL] Jenkins job has been kicked to build packages. It will be bundled with no SystemVM templates. I'll keep you posted as I make progress.

@codecov

codecov Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 19.91%. Comparing base (17294ca) to head (b6ce66e).

Additional details and impacted files
@@             Coverage Diff              @@
##               main   #14361      +/-   ##
============================================
- Coverage     19.91%   19.91%   -0.01%     
+ Complexity    20198    20195       -3     
============================================
  Files          6373     6373              
  Lines        577234   577234              
  Branches      70696    70696              
============================================
- Hits         114945   114942       -3     
- Misses       449724   449726       +2     
- Partials      12565    12566       +1     
Flag Coverage Δ
uitests 3.70% <ø> (ø)
unittests 21.18% <ø> (-0.01%) ⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@blueorangutan

Copy link
Copy Markdown

Packaging result [SF]: ✔️ el8 ✔️ el9 ✔️ el10 ✔️ debian ✔️ suse15. SL-JID 19471

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[4.22] keystore-setup script does not create agent.properties on fresh KVM hosts

2 participants