I am attempting to enable authentication on a MongoDB Replicaset running on an Openshift Cluster. As far as the documentation is concerned my setup should be okay, but I am getting the following error:
{"t":{"$date":"2022-01-21T17:42:38.738+00:00"},"s":"I", "c":"ACCESS", "id":20254, "ctx":"main","msg":"Read security file failed","attr":{"error":{"code":30,"codeName":"InvalidPath","errmsg":"error opening file: /etc/mongo/replkey: bad file"}}}
I haven't been able to find any solution searching around online, so if anyone has any ideas as to what the problem could be I would appreciate the help.
I created the key file using: openssl rand -base64 756 > replkey
My docker file:
FROM mongo:4.4.12-rc1-focal
RUN apt-key adv --keyserver hkp://keyserver.ubuntu.com:80 --recv 2930ADAE8CAF5059EE73BB4B58712A2291FA4AD5
COPY ./replkey /etc/mongo/
RUN chmod 400 /etc/mongo/replkey && chown mongodb:root /etc/mongo/replkey
My Statefulset portion of the deployment:
apiVersion: apps/v1
kind: StatefulSet
metadata:
name: mongodb-rs
spec:
selector:
matchLabels:
app: mongodb-rs # has to match .spec.template.metadata.labels
serviceName: mongodb-rs
replicas: 1
podManagementPolicy: Parallel
template:
metadata:
labels:
app: mongodb-rs
role: mongodb-rs
environment: prod
spec:
serviceAccount: mongo
affinity: # control where pod is deployed
podAntiAffinity: # repel away from these kinds of pods
preferredDuringSchedulingIgnoredDuringExecution:
- weight: 100 # higher means its more important
podAffinityTerm:
labelSelector: # match based on labels of pods
matchExpressions:
- key: app
operator: In
values: [ "kafka", "mongodb-rs" ]
topologyKey: kubernetes.io/hostname
terminationGracePeriodSeconds: 10
containers:
- name: mongodb-container
image: <registry url>/mongodb:authtest
imagePullPolicy: Always
command:
- "mongod"
args:
- "--auth"
- "--port=27017"
- "--dbpath=/mongo-disk"
- "--replSet=mongodb-rs"
# - "--smallfiles"
# - "--noprealloc"
- "--bind_ip=0.0.0.0"
- "--keyFile=/etc/mongo/replkey"
resources:
requests:
cpu: 100m
memory: 512Mi
ports:
- name: mongodb-port
protocol: TCP
containerPort: 27017
volumeMounts:
- name: storage
mountPath: /mongo-disk
- name: mongodb-sidecar
image: <registry url>/mongo-sidecar:<image tag>
resources:
requests:
cpu: 5m
memory: 96Mi
env:
- name: KUBERNETES_POD_LABELS
value: "role=mongodb-rs,environment=prod" # must match with .spec.template.metadata.labels
- name: KUBERNETES_NAMESPACE
valueFrom:
fieldRef:
fieldPath: metadata.namespace
- name: KUBERNETES_SERVICE_NAME
value: "mongodb-rs"
- name: MONGO_PORT
value: "27017"
- name: MONGO_CONFIG_SVR
value: "false"
- name: MONGO_SSL
value: "false"
volumeClaimTemplates:
- metadata:
name: storage
spec:
accessModes: [ "ReadWriteOnce" ]
storageClassName: "ibmc-vpc-block-10iops-tier"
resources:
requests:
storage: "200Gi"