Bug 2065085

Summary: Upgrade OpenShift 4.10.3 to 4.10.4 fails with sandboxed containers operator installed
Product: OpenShift Container Platform Reporter: Sascha Grunert <sgrunert>
Component: Machine Config OperatorAssignee: MCO Team <team-mco>
Machine Config Operator sub component: Machine Config Operator QA Contact: Rio Liu <rioliu>
Status: CLOSED DUPLICATE Docs Contact:
Severity: high    
Priority: unspecified CC: aos-bugs, fgiudici, gkurz, mkrejci
Version: 4.10   
Target Milestone: ---   
Target Release: ---   
Hardware: x86_64   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2022-03-22 10:33:25 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Comment 1 Francesco Giudici 2022-03-22 10:33:25 UTC
This issue is known, a workaround is presented in release notes:
https://docs.openshift.com/container-platform/4.10/sandboxed_containers/sandboxed-containers-release-notes.html#sandboxed-containers-1-2-known-issues

Another bug is tracking the issue, setting this as duplicate.

*** This bug has been marked as a duplicate of bug 2057545 ***

Comment 2 Greg Kurz 2022-03-22 11:04:00 UTC
(In reply to Francesco Giudici from comment #1)
> This issue is known, a workaround is presented in release notes:
> https://docs.openshift.com/container-platform/4.10/sandboxed_containers/
> sandboxed-containers-release-notes.html#sandboxed-containers-1-2-known-issues
> 
> Another bug is tracking the issue, setting this as duplicate.
> 
> *** This bug has been marked as a duplicate of bug 2057545 ***

BTW, even if OSC is the new kid in town, the failing component is the
MCO pod, which should better describe the privileges it needs so that
the admission process doesn't choose the OSC SCC for it.

Changing the component accordingly for the records.