AuthHub - OPA service unable to download AuthPolicies
search cancel

AuthHub - OPA service unable to download AuthPolicies

book

Article ID: 268322

calendar_today

Updated On:

Products

VIP Authentication Hub

Issue/Introduction

We have recently discovered some error logs from OPA. Since February 15th, we have seen the following error log:

Bundle load failed: request failed: Get "https://auth-admin.dev-ssp.svc:443/admin/v1/AuthPolicies/download": dial tcp 10.137.x.x:443: connect: connection refused

The impact of this is not clear. The service has been functional and have notice no service interruptions due to this. 

Wondering if there is any insight from Broadcom's side about the cause / scope / resolution for this. 

Environment

Release : AuthHub 2.1

Resolution

The error message is specific to the AuthHub startup phase, occurring when the OPA pod starts before the Admin pod. Once the Admin pod is up and running, the error message should disappear. The OPA policy pod attempts to download the policies periodically, retrieving the entire set each time. It's important to note that this error message does not affect the functionality of the AuthHub product in any way.