Bug 1991462
| Summary: | helper pod runs with root privileges during Must-gather collection(affects ODF Managed Services) | ||
|---|---|---|---|
| Product: | [Red Hat Storage] Red Hat OpenShift Data Foundation | Reporter: | Neha Berry <nberry> |
| Component: | must-gather | Assignee: | yati padia <ypadia> |
| Status: | CLOSED ERRATA | QA Contact: | Elena Bondarenko <ebondare> |
| Severity: | medium | Docs Contact: | |
| Priority: | unspecified | ||
| Version: | 4.7 | CC: | madam, muagarwa, ocs-bugs, odf-bz-bot, omitrani, sabose, sisharma, sostapov, ypadia |
| Target Milestone: | --- | ||
| Target Release: | ODF 4.10.0 | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | 4.10.0-132 | Doc Type: | No Doc Update |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2022-04-13 18:49:40 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
Neha Berry
2021-08-09 08:15:18 UTC
Yeati, what is the latest status on this BZ? The helper pod privileged is changed, but looking into how can we change the privilege for the must-gather pod. Will make a PR for the same by the end of the week. Can't fix it before 4.9 dev freeze and not a blocker. Can be backported if required. Changed the root privilege for helper pod from root to user. ``` [yatipadia@192 ocs-operator]$ oc rsh -n openshift-storage must-gather-rmrm7-helper whoami 1000 ``` Root privilege for the OCP must-gather pod running on master node is not the part of OCS-must-gather. Hence, I would suggest to open a seperate bug under OCP. ``` [yatipadia@192 ocs-operator]$ oc get ns | grep must-gather openshift-must-gather-qpb5r Active 46s [yatipadia@192 ocs-operator]$ oc get pods -n openshift-must-gather-qpb5r NAME READY STATUS RESTARTS AGE must-gather-rmrm7 2/2 Running 0 56s [yatipadia@192 ocs-operator]$ oc rsh -n openshift-must-gather-qpb5r must-gather-rmrm7 whoami Defaulted container "gather" out of: gather, copy root ``` Raised a PR for the same: https://github.com/red-hat-storage/ocs-operator/pull/1397 Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory (Important: Red Hat OpenShift Data Foundation 4.10.0 enhancement, security & bug fix update), and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHSA-2022:1372 |