Bug 1933664

Summary: Getting Forbidden for image in a container template when creating a sample app
Product: OpenShift Container Platform Reporter: Christoph Jerolimov <cjerolim>
Component: Dev ConsoleAssignee: Christoph Jerolimov <cjerolim>
Status: CLOSED ERRATA QA Contact: spathak <spathak>
Severity: low Docs Contact: Harsh Mishra <hmishra>
Priority: high    
Version: 4.8CC: aos-bugs, hmishra, nmukherj, spathak, tdale
Target Milestone: ---   
Target Release: 4.8.0   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Cause: When creating a sample app the Developer Console creates multiple resources. Some of these resources depends on each other and should be created in a specific order. Consequence: Sometimes an admission plugin fails to check one of this resources and the Sample app could not be created. Fix: Instead of triggering all resources at the same time the code creates now all resources step by step. Result: Creating a sample app is now more stable.
Story Points: ---
Clone Of: Environment:
Last Closed: 2021-07-27 22:48:28 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 1933665, 1934148    
Attachments:
Description Flags
Not getting error for image in a container template when creating a sample app none

Description Christoph Jerolimov 2021-03-01 11:19:28 UTC
Description of problem:
When creating a new Node.js app (I hit the same problem also with the Go app) in the Dev Sandbox, I sometimes get an error:

Error "Forbidden: this image is prohibited by policy: this image is prohibited by policy (changed after admission)" for field "spec.template.spec.containers[0].image".

Version-Release number of selected component (if applicable):
4.6-4.8

How reproducible:
Intermittent

Steps to Reproduce:
1. Go to Add -> Samples
2. Choose either Go or Node.js app
3. Click on create

Actual results:
Error message above was shown sometimes when creating a sample app.

Expected results:
Apps get created without showing any error.

Additional info:
This is a copy of Jira issue https://issues.redhat.com/browse/ODC-5468

Comment 2 spathak@redhat.com 2021-03-01 22:20:49 UTC
Created attachment 1760103 [details]
Not getting error for image in a container template when creating a sample app

Comment 3 spathak@redhat.com 2021-03-01 22:21:27 UTC
Verified on build version: 4.8.0-0.nightly-2021-03-01-031258
Browser version: Chrome 84

Comment 5 Christoph Jerolimov 2021-06-21 09:56:17 UTC
*** Bug 1949542 has been marked as a duplicate of this bug. ***

Comment 6 Rishu Mehra 2021-07-07 07:17:26 UTC
No need to document this Bug for the Release Notes. So the "Doc Text:" field is not required.

Comment 8 errata-xmlrpc 2021-07-27 22:48:28 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (Moderate: OpenShift Container Platform 4.8.2 bug fix and security update), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHSA-2021:2438