Bug 1447249
| Summary: | 'oadm registry --fs-group=xx' command result in pods deployment pending if don't add "- system:serviceaccount:default:deployer" to scc/hostnetwork->users | ||
|---|---|---|---|
| Product: | OpenShift Container Platform | Reporter: | ge liu <geliu> |
| Component: | Image Registry | Assignee: | Oleg Bulatov <obulatov> |
| Status: | CLOSED ERRATA | QA Contact: | ge liu <geliu> |
| Severity: | low | Docs Contact: | |
| Priority: | low | ||
| Version: | 3.6.0 | CC: | aos-bugs, bparees, dyan, geliu, mfojtik |
| Target Milestone: | --- | ||
| Target Release: | 3.6.z | ||
| Hardware: | x86_64 | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | No Doc Update | |
| Doc Text: |
This bug is about documentation itself.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | 2018-06-07 08:40:35 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
ge liu
2017-05-02 08:36:33 UTC
Oleg another one, probably just some doc updates to: https://docs.openshift.org/latest/install_config/registry/deploy_registry_existing_clusters.html though i'm a little confused as to why setting an fsgroup would require "scc/hostnetwork", so it's probably worth validating this behavior and talking to the storage/security folks. The integrated registry runs in the default namespace and have restrictions from SCC.
By default the registry gets the restricted SCC, and it restricts fsgroups based on the namespace annotation:
$ oc get ns default -o go-template='{{index .metadata.annotations "openshift.io/sa.scc.supplemental-groups"}}{{"\n"}}'
1000000000/10000
So, if you want to use --fs-group, you should select the ID from the range: 1000000000 <= id < 1000000000+10000. For example:
oc adm registry --fs-group=1000000000
But you should be aware that on different clusters you may have different ranges in annotations. So a value that works on a cluster may not work on another cluster.
ge liu, can you confirm that selecting proper value helps?
Oleg Bulatov, I remembered that I used 1000020000 or 1000030000, and it seems that there is not notification in doc about this limitation, right? Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2018:1801 |