Skip to content

Conversation

Tenzer
Copy link
Contributor

@Tenzer Tenzer commented Jul 8, 2025

What type of PR is this?

/kind bug

What this PR does / why we need it:

With urllib3 2.4.0 stricter certificate validity checks were added when running on Python 3.13+: urllib3/urllib3#3571.

This triggers errors such as the following:

[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: Missing Authority Key Identifier

It is however only for users with Kubernetes clusters that have been set up without proper, valid certificates. Notably, this was the case for AWS EKS clusters created with Kubernetes v1.16 and earlier.

Which issue(s) this PR fixes:

Fixes #2394

Special notes for your reviewer:

Does this PR introduce a user-facing change?

NONE

Additional documentation e.g., KEPs (Kubernetes Enhancement Proposals), usage docs, etc.:


@k8s-ci-robot k8s-ci-robot added release-note-none Denotes a PR that doesn't merit a release note. kind/bug Categorizes issue or PR as related to a bug. cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. labels Jul 8, 2025
@k8s-ci-robot k8s-ci-robot requested a review from roycaihw July 8, 2025 13:39
@k8s-ci-robot
Copy link
Contributor

Welcome @Tenzer!

It looks like this is your first PR to kubernetes-client/python 🎉. Please refer to our pull request process documentation to help your PR have a smooth ride to approval.

You will be prompted by a bot to use commands during the review process. Do not be afraid to follow the prompts! It is okay to experiment. Here is the bot commands documentation.

You can also check if kubernetes-client/python has its own contribution guidelines.

You may want to refer to our testing guide if you run into trouble with your tests not passing.

If you are having difficulty getting your pull request seen, please follow the recommended escalation practices. Also, for tips and tricks in the contribution process you may want to read the Kubernetes contributor cheat sheet. We want to make sure your contribution gets all the attention it needs!

Thank you, and welcome to Kubernetes. 😃

@k8s-ci-robot k8s-ci-robot requested a review from yliaog July 8, 2025 13:39
@k8s-ci-robot k8s-ci-robot added the size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. label Jul 8, 2025
@Tenzer
Copy link
Contributor Author

Tenzer commented Jul 9, 2025

The test failure is courtesy of #2406.

Should I fix it in this PR by fixing the syntax in watch_test.py?

@yliaog
Copy link
Contributor

yliaog commented Jul 10, 2025

The test failure is courtesy of #2406.

Should I fix it in this PR by fixing the syntax in watch_test.py?

Yes, please. Thanks.

@k8s-ci-robot k8s-ci-robot added size/M Denotes a PR that changes 30-99 lines, ignoring generated files. and removed size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. labels Jul 10, 2025
@roycaihw
Copy link
Member

/assign @yliaog

@yliaog
Copy link
Contributor

yliaog commented Aug 14, 2025

/retest

@yliaog
Copy link
Contributor

yliaog commented Aug 14, 2025

/close

will reopen to trigger the CI

@k8s-ci-robot
Copy link
Contributor

@yliaog: Closed this PR.

In response to this:

/close

will reopen to trigger the CI

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@yliaog
Copy link
Contributor

yliaog commented Aug 14, 2025

/open

@yliaog
Copy link
Contributor

yliaog commented Aug 14, 2025

/reopen

@k8s-ci-robot k8s-ci-robot reopened this Aug 14, 2025
@k8s-ci-robot
Copy link
Contributor

@yliaog: Reopened this PR.

In response to this:

/reopen

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@yliaog
Copy link
Contributor

yliaog commented Aug 18, 2025

@Tenzer do you mind to rebase your PR ? I commented out the problematic test, but if your fix works, could you uncomment it with your fix?

@k8s-ci-robot k8s-ci-robot added the needs-rebase Indicates a PR cannot be merged because it has merge conflicts with HEAD. label Aug 18, 2025
@Tenzer Tenzer force-pushed the urllib3-upper-limit branch from 2a8e250 to 5af0548 Compare August 26, 2025 12:15
@k8s-ci-robot k8s-ci-robot added size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. and removed needs-rebase Indicates a PR cannot be merged because it has merge conflicts with HEAD. size/M Denotes a PR that changes 30-99 lines, ignoring generated files. labels Aug 26, 2025
With urllib3 2.4.0 stricter certificate validity checks were added when running
on Python 3.13+: urllib3/urllib3#3571.

This triggers errors such as the following:

> [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: Missing Authority
> Key Identifier

It is however only for users with Kubernetes clusters that have been set up
without proper, valid certificates. Notably, this was the case for AWS EKS
clusters created with Kubernetes v1.16 and earlier.
@Tenzer Tenzer force-pushed the urllib3-upper-limit branch from 5af0548 to b647e9a Compare August 26, 2025 12:16
@Tenzer
Copy link
Contributor Author

Tenzer commented Aug 26, 2025

I have rebased my PR now. The test_watch_with_deserialize_param test just seems to be stalling when I try to run it locally, so I'm not sure it is working correctly. I have removed my changes to that test so this only deals with the urllib3 dependency.

@yliaog
Copy link
Contributor

yliaog commented Aug 26, 2025

/lgtm
/approve

@k8s-ci-robot k8s-ci-robot added the lgtm "Looks good to me", indicates that a PR is ready to be merged. label Aug 26, 2025
@k8s-ci-robot
Copy link
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: Tenzer, yliaog

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@k8s-ci-robot k8s-ci-robot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Aug 26, 2025
@k8s-ci-robot k8s-ci-robot merged commit 6e7c539 into kubernetes-client:master Aug 26, 2025
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
approved Indicates a PR has been approved by an approver from all required OWNERS files. cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. kind/bug Categorizes issue or PR as related to a bug. lgtm "Looks good to me", indicates that a PR is ready to be merged. release-note-none Denotes a PR that doesn't merit a release note. size/XS Denotes a PR that changes 0-9 lines, ignoring generated files.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

urllib3 v2.4.0 on Python 3.13 doesn't work with EKS
4 participants