Bug 2004264

Summary: Cannot use AlreadyExists if ResourceQuota is present in the namespace and is primed
Product: Migration Toolkit for Containers Reporter: Alay Patel <alpatel>
Component: ControllerAssignee: Jaydip Gabani <jgabani>
Status: CLOSED ERRATA QA Contact: Xin jiang <xjiang>
Severity: medium Docs Contact:
Priority: medium    
Version: 1.5.0CC: ernelson, midays, rjohnson, sgoodman
Target Milestone: ---   
Target Release: 1.7.0   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2022-03-24 06:32:26 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Alay Patel 2021-09-14 20:20:11 UTC
Description of problem:

If a ResourceQuota Object is present in a namespaces and if user or controller tries to create the same object again it will be returned with 403 Forbidden error instead of `resource AlreadyExists` error. 

mig-controller creates the resource and then looks for IsAlreadyError(err). Although, if the resource exists and if the resourcequota is primed, it will give 403 forbidden and will fail the mig-migration.

See this from the CLI:

create the following resources

1. quota

apiVersion: v1
kind: ResourceQuota
metadata:
  name: pod-quota
spec:
  hard:
    pods: "1"
2. pod

apiVersion: v1
kind: Pod
metadata:
  labels:
    app.kubernetes.io/component: rsync-stunnel-mover
    app.kubernetes.io/name: volsync-src-my-source
    app.kubernetes.io/part-of: volsync
  name: busybox
  namespace: scribe-source
spec:
  containers:
  - command:
    - /bin/bash
    - -c
    - sleep 3600
    image: quay.io/konveyor/rsync-transfer:latest
    imagePullPolicy: Always
    name: rsync
    resources: {}
    securityContext:
      capabilities:
        drop:
        - MKNOD
        - SETPCAP
      privileged: false
      readOnlyRootFilesystem: true
      runAsUser: 0
    terminationMessagePath: /dev/termination-log
    terminationMessagePolicy: File

3. create the pod again:
$ oc create -f /tmp/pod.yaml
Error from server (Forbidden): error when creating "/tmp/pod.yaml": pods "busybox" is forbidden: exceeded quota: pod-quota, requested: pods=1, used: pods=1, limited: pods=1

Version-Release number of selected component (if applicable):
1.4+

How reproducible:
Always

Steps to Reproduce:
1. Create ResourceQuota on the destination cluster with 2Gi request limit on persistent volumes

apiVersion: v1
kind: ResourceQuota
metadata:
  name: storagequota
spec:
  hard:
    requests.storage: "2Gi"
2. Run the stage migration with pvc of 2 gigs in the source namespace, it will pass
3. Run the stage migration again. It will complete with warnings. DVM will fail

Actual results:
Complete with warning

Expected results:
Complete without warnings

Additional info:

Comment 8 errata-xmlrpc 2022-03-24 06:32:26 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (Migration Toolkit for Containers (MTC) 1.7.0 release advisory), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2022:1043