<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Kubernetes cluster monitoring: Setup issue in Container platforms</title>
    <link>https://community.dynatrace.com/t5/Container-platforms/Kubernetes-cluster-monitoring-Setup-issue/m-p/122438#M498</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have issue to make my ACtiveGAte  communicate properly with the  K8S cluster API.&lt;/P&gt;&lt;P&gt;I keep getting meesage "&lt;EM&gt;There was an error with the TLS handshake. Check out the documentation for further information&lt;/EM&gt;. "&lt;/P&gt;&lt;P&gt;I have identified SSL  exception in the logfile.&lt;/P&gt;&lt;P&gt;&lt;EM&gt;2019-08-27 09:18:42 UTC INFO    [&amp;lt;mhs48859&amp;gt;] [KubernetesFastCheck] Fastcheck failed for endpoint &lt;A href="https://ff-hp-aks-f06197f7.hcp.westeurope.azmk8s.io/api"&gt;https://ff-hp-aks-f06197f7.hcp.westeurope.azmk8s.io/api&lt;/A&gt; with SSL exception sun.secu&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;rity.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested targe&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;t [Suppressing further identical messages for 3600000 ms]&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;What  need to be done to be sure that  the ACtiveGAte  is not blocked anymore by this  Security check ?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;TIA&lt;/P&gt;&lt;P&gt;Jerome&lt;/P&gt;&lt;BR /&gt;</description>
    <pubDate>Tue, 27 Aug 2019 14:56:18 GMT</pubDate>
    <dc:creator>jerome_cizeron</dc:creator>
    <dc:date>2019-08-27T14:56:18Z</dc:date>
    <item>
      <title>Kubernetes cluster monitoring: Setup issue</title>
      <link>https://community.dynatrace.com/t5/Container-platforms/Kubernetes-cluster-monitoring-Setup-issue/m-p/122438#M498</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have issue to make my ACtiveGAte  communicate properly with the  K8S cluster API.&lt;/P&gt;&lt;P&gt;I keep getting meesage "&lt;EM&gt;There was an error with the TLS handshake. Check out the documentation for further information&lt;/EM&gt;. "&lt;/P&gt;&lt;P&gt;I have identified SSL  exception in the logfile.&lt;/P&gt;&lt;P&gt;&lt;EM&gt;2019-08-27 09:18:42 UTC INFO    [&amp;lt;mhs48859&amp;gt;] [KubernetesFastCheck] Fastcheck failed for endpoint &lt;A href="https://ff-hp-aks-f06197f7.hcp.westeurope.azmk8s.io/api"&gt;https://ff-hp-aks-f06197f7.hcp.westeurope.azmk8s.io/api&lt;/A&gt; with SSL exception sun.secu&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;rity.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested targe&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;t [Suppressing further identical messages for 3600000 ms]&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;What  need to be done to be sure that  the ACtiveGAte  is not blocked anymore by this  Security check ?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;TIA&lt;/P&gt;&lt;P&gt;Jerome&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 27 Aug 2019 14:56:18 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Container-platforms/Kubernetes-cluster-monitoring-Setup-issue/m-p/122438#M498</guid>
      <dc:creator>jerome_cizeron</dc:creator>
      <dc:date>2019-08-27T14:56:18Z</dc:date>
    </item>
    <item>
      <title>Re: Kubernetes cluster monitoring: Setup issue</title>
      <link>https://community.dynatrace.com/t5/Container-platforms/Kubernetes-cluster-monitoring-Setup-issue/m-p/122439#M499</link>
      <description>&lt;P&gt;I think this is because ActiveGate can’t accept certificate you have on K8s. If it’s self signed or local it is possible to have issues like that. You need to add root certificate to AG, then everything should work fine:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.dynatrace.com/support/help/setup-and-configuration/dynatrace-activegate/configuration/configure-trusted-root-certificates-on-activegate/"&gt;https://www.dynatrace.com/support/help/setup-and-configuration/dynatrace-activegate/configuration/configure-trusted-root-certificates-on-activegate/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Article above covers this topic. We’ve had same issues and this helped. &lt;/P&gt;&lt;P&gt;Sebastian &lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 27 Aug 2019 15:01:54 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Container-platforms/Kubernetes-cluster-monitoring-Setup-issue/m-p/122439#M499</guid>
      <dc:creator>skrystosik</dc:creator>
      <dc:date>2019-08-27T15:01:54Z</dc:date>
    </item>
    <item>
      <title>Re: Kubernetes cluster monitoring: Setup issue</title>
      <link>https://community.dynatrace.com/t5/Container-platforms/Kubernetes-cluster-monitoring-Setup-issue/m-p/122440#M500</link>
      <description>&lt;P&gt;Hi &lt;A rel="user" href="https://answers.dynatrace.com/users/15061/view.html" nodeid="15061"&gt;@Sebastian K.&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Facing the same certification issue:&lt;/P&gt;&lt;P&gt;We have the most of our active gates on-premise, and it seems the Azure Kubernetes cluster's Kube-API server is not reachable from the active gates.&lt;/P&gt;&lt;P&gt;1. Could you please help me understand what kind of connectivity needs to be setup between the active gate and the KubeAPIServer OR between the ActiveGate and OneAgent PODs? I did not see this is not mentioned in documentation anywhere.&lt;/P&gt;&lt;P&gt;2. I am afraid if this shall require any modification at cluster level, would be hard to convince. What needs be done?&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;Rajesh&lt;/P&gt;</description>
      <pubDate>Tue, 03 Nov 2020 05:01:41 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Container-platforms/Kubernetes-cluster-monitoring-Setup-issue/m-p/122440#M500</guid>
      <dc:creator>rswarnka</dc:creator>
      <dc:date>2020-11-03T05:01:41Z</dc:date>
    </item>
    <item>
      <title>Re: Kubernetes cluster monitoring: Setup issue</title>
      <link>https://community.dynatrace.com/t5/Container-platforms/Kubernetes-cluster-monitoring-Setup-issue/m-p/122441#M501</link>
      <description>&lt;P&gt;You can disable the SSL Validation at the moment you setup the K8 Connection, is not the best... but is something. You also need to be able to reach the API endpoint of the K8.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Nov 2020 14:58:08 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Container-platforms/Kubernetes-cluster-monitoring-Setup-issue/m-p/122441#M501</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2020-11-03T14:58:08Z</dc:date>
    </item>
  </channel>
</rss>

