Skip to content

fix(dhcp): makedhcp -n fails on a new Kea management node before makedns -n - #7891

Merged
dhilst merged 8 commits into
xcat2:masterfrom
VersatusHPC:fix/kea-makedhcp-before-makedns
Oct 1, 2026
Merged

dhilst merged 8 commits into
xcat2:masterfrom
VersatusHPC:fix/kea-makedhcp-before-makedns

Conversation

@dhilst

@dhilst dhilst commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

makedhcp -n fails on a new management node that uses the Kea backend, until makedns -n has
run:

Error: Unable to find DDNS key material for Kea D2. Run makedns with dnshandler=ddns first.

xcatconfig writes site.dnshandler=ddns on every new installation, so kea_ddns_enabled in
dhcp.pm reports DDNS on and kea_build_ddns_intent then requires the TSIG secret. Only
makedns -n writes that secret, to /etc/xcat/ddns.key and to the omapi row of the passwd
table. The ISC backend reads no key, so an ISC management node runs makedhcp -n without one. The
Kea backend plan states that basic DHCP and PXE support must not depend on DDNS unless a
deployment enables site.dnshandler=ddns, and xcatconfig enables it for every installation.

kea_build_ddns_intent now reports a deferral instead of an error when it finds no key material.
kea_apply_ddns_intent attaches the D2 connection to the DHCPv4 and DHCPv6 configurations only
when a key exists, and returns the deferral for makedhcp to print as a warning. A management node
that has run makedns -n gets the same configuration as before.

dhcp_kea_ddns_deferral.t captures the missing key reported as an error. It also holds down the two
boundaries the change must keep: a management node whose site.dnshandler is not ddns asks for no
D2 configuration, and an unreadable networks table stays an error. The test fails without the fix.

makedhcp -n fails on a new management node that uses the Kea backend:

    Error: Unable to find DDNS key material for Kea D2. Run makedns with
    dnshandler=ddns first.

xcatconfig writes site.dnshandler=ddns on every new installation, so the Kea
backend asks for the DDNS key, and only makedns -n creates it. No case covers
that order.

kea_makedhcp_without_ddns_key removes both places the Kea backend reads the key
from, runs makedhcp -n, and reads the rendered kea-dhcp4.conf. It then restores
the key material and runs makedhcp -n again, so the case also holds down the
configuration that a management node with a key must keep.

Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
kea_build_ddns_intent returns an error when no DDNS key material exists, and
makedhcp -n reports it instead of configuring Kea. No unit test reads that
decision, so the error path and the D2 path are both unmeasured.

dhcp_kea_ddns_deferral.t drives kea_build_ddns_intent with and without key
material, and drives the sub that attaches the D2 connection to the DHCPv4 and
DHCPv6 configurations. It also holds down the two boundaries the change must
keep: a management node whose site.dnshandler is not ddns asks for no D2
configuration, and an unreadable networks table stays an error.

Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
makedhcp -n fails on a new management node that uses the Kea backend:

    Error: Unable to find DDNS key material for Kea D2. Run makedns with
    dnshandler=ddns first.

xcatconfig writes site.dnshandler=ddns on every new installation, so
kea_ddns_enabled reports DDNS on, and kea_build_ddns_intent then requires
/etc/xcat/ddns.key. Only makedns -n writes that file. The ISC backend reads no
key, so an ISC management node runs makedhcp -n without one. The Kea backend
plan states that basic DHCP and PXE support must not depend on DDNS.

kea_build_ddns_intent now reports a deferral instead of an error when it finds
no key material. kea_apply_ddns_intent attaches the D2 connection only when a
key exists, and returns the deferral for makedhcp to print as a warning. A
management node with key material gets the same configuration as before.

Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
kea_makedhcp_without_ddns_key covers the same decision as
dhcp_kea_ddns_deferral.t, and no suite runs it: the GitHub workflow runs
prove -r xCAT-test/unit, and no CD bundle names the case.

Delta debugging at commit scope dropped it. The unit test still fails on the
unfixed tree, so the defect stays captured.

Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
The comment stated the xcatconfig default and then repeated the reason for the
change, which the commit message already carries. Keep the condition only.

Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
… key

kea_build_ddns_intent returned the deferral under a deferred key. No other
xCAT code uses that key: dhcp.pm reports through error, warning, node and
data, and makedhcp already passed this message to the callback as a warning.

The intent hash now carries the message under warning, so one name describes
it from the hash to the callback. Behaviour does not change.

Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
@dhilst dhilst added this to the 2.20 milestone Sep 30, 2026
@dhilst dhilst self-assigned this Sep 30, 2026

@viniciusferrao viniciusferrao left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@dhilst

After running makedhcp -n, makedns -n and makedhcp -a, the DHCP configs still lack dhcp-ddns, and the D2 config is never written.

The -a path applies DDNS settings to fresh intents but saves the previously loaded configs.

We need either complete this transition when the key appears, or have the warning explicitly request rerunning makedhcp -n followed by makedhcp -a after makedns -n.

That should be covered by the recovery sequence in a regression test.

On a new Kea management node, makedhcp -n defers DDNS because no key
exists. After makedns -n writes the key, makedhcp -a keeps the DHCPv4
configuration without dhcp-ddns and writes no kea-dhcp-ddns.conf, so
DNS updates stay off.

The test runs makedhcp -n without a key, adds the key, runs
makedhcp -a, and checks the rendered DHCPv4 and D2 configurations.

Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
On a new Kea management node, makedhcp -n defers DDNS until makedns -n
writes the key. makedhcp -a then applied the D2 settings to the fresh
intents, but saved the loaded configurations, which had no dhcp-ddns.
It also wrote no kea-dhcp-ddns.conf, so DNS updates stayed off.

When DDNS is on and the loaded DHCPv4 configuration has no dhcp-ddns,
makedhcp -a now copies the D2 settings into the loaded DHCPv4 and DHCPv6
configurations, writes the D2 configuration and, when enabled, the
Control Agent configuration. It then enables and restarts the Kea
services.

Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
@viniciusferrao
viniciusferrao self-requested a review September 30, 2026 19:36

@viniciusferrao viniciusferrao left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM.

@dhilst
dhilst merged commit 7950283 into xcat2:master Oct 1, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants