Bug 1752045

Summary: No RBAC method for setting ExternalIPs
Product: OpenShift Container Platform Reporter: Casey Callendrello <cdc>
Component: NetworkingAssignee: Aniket Bhat <anbhat>
Networking sub component: openshift-sdn QA Contact: zhaozhanqi <zzhao>
Status: CLOSED ERRATA Docs Contact:
Severity: unspecified    
Priority: unspecified CC: anbhat, danw, weliang
Version: 4.3.z   
Target Milestone: ---   
Target Release: 4.3.0   
Hardware: Unspecified   
OS: Unspecified   
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
: 1759181 1759182 (view as bug list) Environment:
Last Closed: 2020-01-23 11:05:53 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Bug Depends On: 1757553    
Bug Blocks: 1759181    

Comment 1 Dan Winship 2019-09-13 15:04:05 UTC
> The solution is to create a special RBAC check in the ExternalIPAdmissionController[1] that looks like the one in the RestrictedEndpointAdmissionController[2]

The links there are to 4.1, but we'll want to do this in git master first, where the controller has moved to vendor/k8s.io/kubernetes/openshift-kube-apiserver/admission/network/externalipranger/externalip_admission.go

Comment 4 Weibin Liang 2019-10-04 18:09:44 UTC
Verified it on v4.3.0-0.ci-2019-10-04-083724.

Will re-test it when the v4.3 nightly image ready on https://openshift-release.svc.ci.openshift.org/

Comment 5 zhaozhanqi 2019-10-09 09:33:06 UTC
from comment 4. this bug can be verified.

Comment 7 errata-xmlrpc 2020-01-23 11:05:53 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.