Why is Mongo unable to use my keyfile to set up Replicaset authentication?

Viewed 727

I am attempting to enable authentication on a MongoDB Replicaset running on an Openshift Cluster. As far as the documentation is concerned my setup should be okay, but I am getting the following error: {"t":{"$date":"2022-01-21T17:42:38.738+00:00"},"s":"I", "c":"ACCESS", "id":20254, "ctx":"main","msg":"Read security file failed","attr":{"error":{"code":30,"codeName":"InvalidPath","errmsg":"error opening file: /etc/mongo/replkey: bad file"}}}

I haven't been able to find any solution searching around online, so if anyone has any ideas as to what the problem could be I would appreciate the help.

I created the key file using: openssl rand -base64 756 > replkey

My docker file:

FROM mongo:4.4.12-rc1-focal
RUN apt-key adv --keyserver hkp://keyserver.ubuntu.com:80 --recv 2930ADAE8CAF5059EE73BB4B58712A2291FA4AD5
COPY ./replkey /etc/mongo/
RUN chmod 400 /etc/mongo/replkey && chown mongodb:root /etc/mongo/replkey

My Statefulset portion of the deployment:

apiVersion: apps/v1
kind: StatefulSet
metadata:
  name: mongodb-rs
spec:
  selector:
    matchLabels:
      app: mongodb-rs # has to match .spec.template.metadata.labels
  serviceName: mongodb-rs
  replicas: 1
  podManagementPolicy: Parallel
  template:
    metadata:
      labels:
        app: mongodb-rs
        role: mongodb-rs
        environment: prod
    spec:
      serviceAccount: mongo
      affinity: # control where pod is deployed
        podAntiAffinity: # repel away from these kinds of pods
          preferredDuringSchedulingIgnoredDuringExecution:
          - weight: 100 # higher means its more important
            podAffinityTerm:
              labelSelector: # match based on labels of pods
                matchExpressions:
                - key: app
                  operator: In
                  values: [ "kafka", "mongodb-rs" ]
              topologyKey: kubernetes.io/hostname
      terminationGracePeriodSeconds: 10
      containers:
        - name: mongodb-container
          image: <registry url>/mongodb:authtest
          imagePullPolicy: Always
          command:
            - "mongod"
          args:
            - "--auth"
            - "--port=27017"
            - "--dbpath=/mongo-disk"
            - "--replSet=mongodb-rs"
            # - "--smallfiles"
            # - "--noprealloc"
            - "--bind_ip=0.0.0.0"
            - "--keyFile=/etc/mongo/replkey"
          resources:
            requests:
              cpu: 100m
              memory: 512Mi
          ports:
            - name: mongodb-port
              protocol: TCP
              containerPort: 27017
          volumeMounts:
            - name: storage
              mountPath: /mongo-disk
        - name: mongodb-sidecar
          image: <registry url>/mongo-sidecar:<image tag>
          resources:
            requests:
              cpu: 5m
              memory: 96Mi
          env:
            - name: KUBERNETES_POD_LABELS
              value: "role=mongodb-rs,environment=prod" # must match with .spec.template.metadata.labels
            - name: KUBERNETES_NAMESPACE
              valueFrom:
                fieldRef:
                  fieldPath: metadata.namespace
            - name: KUBERNETES_SERVICE_NAME
              value: "mongodb-rs"
            - name: MONGO_PORT
              value: "27017"
            - name: MONGO_CONFIG_SVR
              value: "false"
            - name: MONGO_SSL
              value: "false"
  volumeClaimTemplates:
  - metadata:
      name: storage
    spec:
      accessModes: [ "ReadWriteOnce" ]
      storageClassName: "ibmc-vpc-block-10iops-tier"
      resources:
        requests:
          storage: "200Gi"
0 Answers
Related