<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Dynatrace operator cannot pull ag image - connection denied in Container platforms</title>
    <link>https://community.dynatrace.com/t5/Container-platforms/Dynatrace-operator-cannot-pull-ag-image-connection-denied/m-p/192675#M103</link>
    <description>&lt;P&gt;We got the same image pull error when using the new token with the added permission for - Create ActiveGate tokens&lt;/P&gt;</description>
    <pubDate>Mon, 15 Aug 2022 15:46:53 GMT</pubDate>
    <dc:creator>jordan_rose</dc:creator>
    <dc:date>2022-08-15T15:46:53Z</dc:date>
    <item>
      <title>Dynatrace operator cannot pull ag image - connection denied</title>
      <link>https://community.dynatrace.com/t5/Container-platforms/Dynatrace-operator-cannot-pull-ag-image-connection-denied/m-p/192661#M100</link>
      <description>&lt;P&gt;Hi All, I'm posting here since we are pretty stuck on this topic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are attempting to migrate to the Dynatrace Operator and when ag pod starts and attempts to pull the activegate image from our managed cluster we get "&lt;SPAN&gt;image pull back off&lt;/SPAN&gt;" errors. Pod output eludes to connection being denied by our cluster. We manage our own domain name and ssl certs and have tried adding the cert in a config map.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I cant seem to find solid doc on how to resolve this or about adding the certs properly, any help here is much appreciated.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2022 09:29:23 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Container-platforms/Dynatrace-operator-cannot-pull-ag-image-connection-denied/m-p/192661#M100</guid>
      <dc:creator>jordan_rose</dc:creator>
      <dc:date>2022-08-16T09:29:23Z</dc:date>
    </item>
    <item>
      <title>Re: Dynatrace operator cannot pull ag image - connection denied</title>
      <link>https://community.dynatrace.com/t5/Container-platforms/Dynatrace-operator-cannot-pull-ag-image-connection-denied/m-p/192662#M101</link>
      <description>&lt;P&gt;Did you confirm the API Token if has the required scopes?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Read configuration&lt;/LI&gt;&lt;LI&gt;Write configuration&lt;/LI&gt;&lt;LI&gt;Read settings&lt;/LI&gt;&lt;LI&gt;Write settings&lt;/LI&gt;&lt;LI&gt;Read entities&lt;/LI&gt;&lt;LI&gt;Installer download&lt;/LI&gt;&lt;LI&gt;Access problem and event feed, metrics, and topology&lt;/LI&gt;&lt;LI&gt;Create ActiveGate tokens&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Aug 2022 14:39:36 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Container-platforms/Dynatrace-operator-cannot-pull-ag-image-connection-denied/m-p/192662#M101</guid>
      <dc:creator>dannemca</dc:creator>
      <dc:date>2022-08-15T14:39:36Z</dc:date>
    </item>
    <item>
      <title>Re: Dynatrace operator cannot pull ag image - connection denied</title>
      <link>https://community.dynatrace.com/t5/Container-platforms/Dynatrace-operator-cannot-pull-ag-image-connection-denied/m-p/192664#M102</link>
      <description>&lt;P&gt;I used the "Deploy Dynatrace &amp;gt; Openshift" screen to create the tokens, this method creates a data ingest token and an Operator Token but neither include the "Create ActiveGate tokens" permission. I will try again with that permission added to the operator token.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Aug 2022 14:49:10 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Container-platforms/Dynatrace-operator-cannot-pull-ag-image-connection-denied/m-p/192664#M102</guid>
      <dc:creator>jordan_rose</dc:creator>
      <dc:date>2022-08-15T14:49:10Z</dc:date>
    </item>
    <item>
      <title>Re: Dynatrace operator cannot pull ag image - connection denied</title>
      <link>https://community.dynatrace.com/t5/Container-platforms/Dynatrace-operator-cannot-pull-ag-image-connection-denied/m-p/192675#M103</link>
      <description>&lt;P&gt;We got the same image pull error when using the new token with the added permission for - Create ActiveGate tokens&lt;/P&gt;</description>
      <pubDate>Mon, 15 Aug 2022 15:46:53 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Container-platforms/Dynatrace-operator-cannot-pull-ag-image-connection-denied/m-p/192675#M103</guid>
      <dc:creator>jordan_rose</dc:creator>
      <dc:date>2022-08-15T15:46:53Z</dc:date>
    </item>
    <item>
      <title>Re: Dynatrace operator cannot pull ag image - connection denied</title>
      <link>https://community.dynatrace.com/t5/Container-platforms/Dynatrace-operator-cannot-pull-ag-image-connection-denied/m-p/192678#M104</link>
      <description>&lt;P&gt;can you send here the error line you are getting in the pods log?&lt;/P&gt;</description>
      <pubDate>Mon, 15 Aug 2022 18:21:37 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Container-platforms/Dynatrace-operator-cannot-pull-ag-image-connection-denied/m-p/192678#M104</guid>
      <dc:creator>dannemca</dc:creator>
      <dc:date>2022-08-15T18:21:37Z</dc:date>
    </item>
    <item>
      <title>Re: Dynatrace operator cannot pull ag image - connection denied</title>
      <link>https://community.dynatrace.com/t5/Container-platforms/Dynatrace-operator-cannot-pull-ag-image-connection-denied/m-p/192679#M105</link>
      <description>&lt;P&gt;Thanks for reply - we have been through many iterations of trying this and this is the latest error we are getting. We are using the cluster node IP address in the apiurl since the vip seems to be unreachable from the pods. (replaced some IPs and envid with "X's")&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;&lt;SPAN&gt;Generated from kubelet on workernode2 times in the last&amp;nbsp;0 minutes&lt;/SPAN&gt;&lt;SPAN&gt;Failed to pull image "xx.xx.xx.xx/e/envIDxxx/linux/activegate:latest": rpc error: code = Unknown desc = error pinging docker registry xx.xx.xx.xx: Get "https://xx.xx.xx.xx/v2/":&amp;nbsp;&amp;nbsp;x509: cannot validate certificate for xx.xx.xx.xx because it doesn't contain any IP SANs&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Aug 2022 19:10:16 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Container-platforms/Dynatrace-operator-cannot-pull-ag-image-connection-denied/m-p/192679#M105</guid>
      <dc:creator>jordan_rose</dc:creator>
      <dc:date>2022-08-15T19:10:16Z</dc:date>
    </item>
    <item>
      <title>Re: Dynatrace operator cannot pull ag image - connection denied</title>
      <link>https://community.dynatrace.com/t5/Container-platforms/Dynatrace-operator-cannot-pull-ag-image-connection-denied/m-p/192684#M106</link>
      <description>&lt;P&gt;Certificate issue, you can try to figure out how to properly add the certificate for this managed host in your cluster, or use the&amp;nbsp;&lt;SPAN&gt;'skipCertCheck&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;true' in Dynakube.yaml, right below apiUrl&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;# Optional: Disable certificate validation checks for installer download and API communication&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;#&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;skipCertCheck&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;true&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 15 Aug 2022 20:15:21 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Container-platforms/Dynatrace-operator-cannot-pull-ag-image-connection-denied/m-p/192684#M106</guid>
      <dc:creator>dannemca</dc:creator>
      <dc:date>2022-08-15T20:15:21Z</dc:date>
    </item>
    <item>
      <title>Re: Dynatrace operator cannot pull ag image - connection denied</title>
      <link>https://community.dynatrace.com/t5/Container-platforms/Dynatrace-operator-cannot-pull-ag-image-connection-denied/m-p/192685#M107</link>
      <description>&lt;P&gt;We do have the skipCertCheck set to true. As far as adding the cert we cant seem to find some solid doc on it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When you say add the add the "&lt;SPAN&gt;certificate for this managed host in your cluster&lt;/SPAN&gt;" - we should be focused on adding the cert for our dynatrace managed cluster url to the Dynatrace operator, correct. We tried to do this via config map and still couldnt get this working.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Worth noting we have had a support ticket open for a while now and havent found a resolution.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Aug 2022 20:26:30 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Container-platforms/Dynatrace-operator-cannot-pull-ag-image-connection-denied/m-p/192685#M107</guid>
      <dc:creator>jordan_rose</dc:creator>
      <dc:date>2022-08-15T20:26:30Z</dc:date>
    </item>
    <item>
      <title>Re: Dynatrace operator cannot pull ag image - connection denied</title>
      <link>https://community.dynatrace.com/t5/Container-platforms/Dynatrace-operator-cannot-pull-ag-image-connection-denied/m-p/192687#M108</link>
      <description>&lt;P&gt;Hi Jordan,&amp;nbsp;&lt;/P&gt;&lt;P&gt;This error will generally be thrown from the machine where the commands are getting executed as the server from where you are executing the command dont trust the docker registry self signed certificates.&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can make the docker trust the self-signed certificate by placing the self-signed certificate to the “/etc/docker/certs.d/&amp;lt;docker_registry_hostname&amp;gt;:&amp;lt;docker_registry_host_port&amp;gt;/ca.crt” on the machine where you are trying to run the docker command.&lt;/P&gt;&lt;P&gt;You can follow the steps how to trust a self signed certificate for docker registry searching it from any official docker document.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2022 04:54:56 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Container-platforms/Dynatrace-operator-cannot-pull-ag-image-connection-denied/m-p/192687#M108</guid>
      <dc:creator>techean</dc:creator>
      <dc:date>2022-08-16T04:54:56Z</dc:date>
    </item>
    <item>
      <title>Re: Dynatrace operator cannot pull ag image - connection denied</title>
      <link>https://community.dynatrace.com/t5/Container-platforms/Dynatrace-operator-cannot-pull-ag-image-connection-denied/m-p/192991#M109</link>
      <description>&lt;P&gt;Turns out it was a cert/trusted connection issue. We ended up pulling the image from an AG and adding the certs there. Our dev env doesnt have access to connect directly to our vip on prod netscaler and we couldnt bypass the vip without having proper certs in place.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Aug 2022 13:40:55 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Container-platforms/Dynatrace-operator-cannot-pull-ag-image-connection-denied/m-p/192991#M109</guid>
      <dc:creator>jordan_rose</dc:creator>
      <dc:date>2022-08-19T13:40:55Z</dc:date>
    </item>
    <item>
      <title>Re: Dynatrace operator cannot pull ag image - connection denied</title>
      <link>https://community.dynatrace.com/t5/Container-platforms/Dynatrace-operator-cannot-pull-ag-image-connection-denied/m-p/197750#M1370</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;Do we need to set up AG to do this? Just one cluster node is not enough, is it? What is the exact information about this? Can't I install for OPC if I don't have an AG?&lt;/P&gt;</description>
      <pubDate>Fri, 04 Nov 2022 08:27:07 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Container-platforms/Dynatrace-operator-cannot-pull-ag-image-connection-denied/m-p/197750#M1370</guid>
      <dc:creator>oakdag</dc:creator>
      <dc:date>2022-11-04T08:27:07Z</dc:date>
    </item>
    <item>
      <title>Re: Dynatrace operator cannot pull ag image - connection denied</title>
      <link>https://community.dynatrace.com/t5/Container-platforms/Dynatrace-operator-cannot-pull-ag-image-connection-denied/m-p/197798#M1371</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/44945"&gt;@oakdag&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;First question: I think the best practice is to use AG if it is possible, but with proper firewall rules your oneagents from OPC can connect directly to DT cluster nodes. I recommend to use AG.&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.dynatrace.com/support/help/setup-and-configuration/setup-on-container-platforms/kubernetes/get-started-with-kubernetes-monitoring#prerequisites" target="_blank"&gt;Get started with Kubernetes/OpenShift monitoring | Dynatrace Docs&lt;/A&gt;&lt;/P&gt;&lt;P&gt;"Pods must allow egress to your Dynatrace environment or to your Environment ActiveGate in order for metric routing to work properly."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can use your exiting AG (outside of OPC) or you can install a containerized AG within OPC with dynakube operator (you can define the numbers of the containerized AG with dynakube custom resource yaml). I recommend the containerized AG.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Second question: Which cluster node do you think? OPC or DT. In case of DT one node is enough with the recommended resources (can be found in the documentation) In case of OPC one worker node is enough for the containerized AG.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Third question:&amp;nbsp;&lt;A href="https://www.dynatrace.com/support/help/setup-and-configuration/setup-on-container-platforms/kubernetes/get-started-with-kubernetes-monitoring#prerequisites" target="_blank"&gt;Get started with Kubernetes/OpenShift monitoring | Dynatrace Docs&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Fourth question: See above, answer is No.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope it helps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mizső&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Nov 2022 14:22:26 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Container-platforms/Dynatrace-operator-cannot-pull-ag-image-connection-denied/m-p/197798#M1371</guid>
      <dc:creator>Mizső</dc:creator>
      <dc:date>2022-11-04T14:22:26Z</dc:date>
    </item>
    <item>
      <title>Re: Dynatrace operator cannot pull ag image - connection denied</title>
      <link>https://community.dynatrace.com/t5/Container-platforms/Dynatrace-operator-cannot-pull-ag-image-connection-denied/m-p/197874#M1378</link>
      <description>&lt;P&gt;Hi Mizsö,&lt;/P&gt;&lt;P&gt;Thanks a lot. I' ve been solved this issue. I installed valid certificate after solved.&amp;nbsp;Actually, I had done it a few times before installing the certificate and this was not a problem, but this time I could only solve it after installing the certificate. Moreover, it did not happen even though I used the noskipcert parameter. Thanks again for your comments.&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2022 10:50:09 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Container-platforms/Dynatrace-operator-cannot-pull-ag-image-connection-denied/m-p/197874#M1378</guid>
      <dc:creator>oakdag</dc:creator>
      <dc:date>2022-11-07T10:50:09Z</dc:date>
    </item>
    <item>
      <title>Re: Dynatrace operator cannot pull ag image - connection denied</title>
      <link>https://community.dynatrace.com/t5/Container-platforms/Dynatrace-operator-cannot-pull-ag-image-connection-denied/m-p/207910#M1526</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/44945"&gt;@oakdag&lt;/a&gt;&amp;nbsp;, can you explain how you "installed" the Cerficate we are facing the same issue when trying to pull the images from a managed cluster&amp;nbsp;&lt;SPAN&gt;x509: "certificate signed by unknown authority", how did obtain the certificate did you install it using a configMap ?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 08:33:32 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Container-platforms/Dynatrace-operator-cannot-pull-ag-image-connection-denied/m-p/207910#M1526</guid>
      <dc:creator>leon_vanzyl</dc:creator>
      <dc:date>2023-03-24T08:33:32Z</dc:date>
    </item>
  </channel>
</rss>

