Bug 2046554
Summary: | infrastructure-operator pod crashes due to insufficient privileges in ACM 2.5 | ||
---|---|---|---|
Product: | Red Hat Advanced Cluster Management for Kubernetes | Reporter: | Thuy Nguyen <thnguyen> |
Component: | Cluster Lifecycle | Assignee: | Jian Qiu <jqiu> |
Status: | CLOSED ERRATA | QA Contact: | Hui Chen <huichen> |
Severity: | high | Docs Contact: | Christopher Dawson <cdawson> |
Priority: | unspecified | ||
Version: | rhacm-2.5 | CC: | akrzos, asegurap, ccrum, dhuynh, jagray, mfilanov, mhrivnak, smiron, yuhe |
Target Milestone: | --- | Flags: | bot-tracker-sync:
rhacm-2.5+
|
Target Release: | rhacm-2.5 | ||
Hardware: | Unspecified | ||
OS: | Unspecified | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | If docs needed, set a value | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2022-06-09 02:08:48 UTC | Type: | Bug |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
Thuy Nguyen
2022-01-26 23:01:38 UTC
@mfilanov Hi Michael, Do you know how do we set up the RBAC for AI on ACM? if so can you please let me know, I will try to follow the previous steps to add the above. Hey, all the RNAC config is located at https://github.com/openshift/assisted-service/tree/master/config/rbac @asegurap do you know how it is being deployed or how we can debug it? Wasn't there some automation to convert the CSV (https://github.com/openshift/assisted-service/blob/master/deploy/olm-catalog/manifests/assisted-service-operator.clusterserviceversion.yaml) into manifests for ACM's helm chart? I understood that the artifact being released and handed off would be an OLM bundle, and that ACM could then consume that for integration into ACM via a helm chart. Is that what's happening, or did we settle into some other process? *** Bug 2050363 has been marked as a duplicate of this bug. *** I believe the acm is using https://github.com/stolostron/assisted-service-chart to convert the csv to acm deployments. It seems the AI added some new clusterrole entries, such as clusterrolebindings at https://github.com/openshift/assisted-service/blob/master/deploy/olm-catalog/manifests/assisted-service-operator.clusterserviceversion.yaml, however, the acm side didn't update these new clusterroles to the converter code. @jagray can you please help us update the acm's converter code? Also @mhrivnak can you please let up know if there's a way to identify all the new changes to the csv? do we just do a diff of the commit? I've updated the automation. This seems to have picked up some role changes: https://github.com/stolostron/assisted-service-chart/commit/103d0e9c4c73cc9ae87e1e2984640fbd4afb559f. The workflow had been disabled because there hadn't been activity in the repo for 60 days, which I wasn't aware happened. Hi @thnguyen Do can you please try out our latest image to see if the above changes made by Jakob is working or not? The automation is best, but a diff of CSV would of course show any changes. Looks like this should be resolved now. @izhang, please change the status to ON_QA if the fix is already in and ready to test. Please also include the upstream/downstream build that contains the fix. Thank you. @jagray Hi Jakob, Do you know the specific build for this issue? I only know the change was committed on Feb 7, 2022. Any build after that date will have the change. I have version 2.5.0-DOWNSTREAM-2022-02-10-07-31-45 of ACM deployed and I no longer see the infrastructure operator crashlooping FWIW Validated on 2.5.0-DOWNSTREAM-2022-02-14-13-53-12. Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory (Important: Red Hat Advanced Cluster Management 2.5 security updates, images, and bug fixes), and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHSA-2022:4956 This comment was flagged a spam, view the edit history to see the original text if required. The needinfo request[s] on this closed bug have been removed as they have been unresolved for 120 days |