PostgreSQL cluster remains "InProgress" after database certificate change
search cancel

PostgreSQL cluster remains "InProgress" after database certificate change

book

Article ID: 400954

calendar_today

Updated On:

Products

VMware Data Services Manager

Issue/Introduction

When user changes the TLS certificate of a PostgreSQL cluster, in rare occasions the cluster status remains InProgress and database service becomes inaccessible.
Same might be triggered when user modifies DNS names while using DSM-managed certificates.

This state is permanent and remediation requires manual intervention.

Environment

DSM version 9.0.0 and below

Cause

When user changes the TLS certificate of PostgreSQL cluster, not all data pods receive the new one on time.

This causes communication failure between data pods and the monitor because of certificate mismatch.

Postgres service is then brought down for safety reasons.

The same can be caused by DNS name change when using DSM-managed certificates. This effectively causes certificate rotation.

Resolution

This has been addressed in DSM 9.0.1

If you encounter this issue please contact VMware support for assistance