Bug 1501254 - Service secret was not deleted after deprovision
Summary: Service secret was not deleted after deprovision
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: OpenShift Container Platform
Classification: Red Hat
Component: Management Console
Version: 3.7.0
Hardware: Unspecified
OS: Unspecified
medium
low
Target Milestone: ---
: 3.9.0
Assignee: David Taylor
QA Contact: Zhang Cheng
URL:
Whiteboard:
: 1505777 1505791 (view as bug list)
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2017-10-12 09:32 UTC by Zhang Cheng
Modified: 2018-03-28 14:07 UTC (History)
10 users (show)

Fixed In Version:
Doc Type: No Doc Update
Doc Text:
undefined
Clone Of:
Environment:
Last Closed: 2018-03-28 14:07:14 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2018:0489 0 None None None 2018-03-28 14:07:53 UTC

Comment 1 Paul Morie 2017-10-13 16:15:33 UTC
Reassigning to Jay Boyd because this appears to be a bug with the catalog.

Comment 2 Jay Boyd 2017-10-17 16:24:53 UTC
The secret 'dh-mediawiki123-apb-parameters-i9cwj' is not from Service Catalog.  It's from the oc console.  I can reproduce, I see the secret still present after deprovisioning.

Comment 3 Jay Boyd 2017-10-17 17:03:46 UTC
I discussed with Sam, this is a known issue and will be addressed in 3.8.

Comment 4 Samuel Padgett 2017-10-17 17:13:58 UTC
We cannot set an owner reference from the secret to the service instance in 3.7 due to limitations with garbage collection in 3.7. We should be able to fix this in 3.8.

Comment 5 Zhang Cheng 2017-10-24 10:47:11 UTC
*** Bug 1505777 has been marked as a duplicate of this bug. ***

Comment 6 Ben Parees 2017-10-24 13:53:04 UTC
*** Bug 1505791 has been marked as a duplicate of this bug. ***

Comment 7 Zhang Cheng 2017-11-20 07:40:56 UTC
Why "target release" still is ocp3.7?

Comment 8 David Taylor 2018-01-18 15:42:27 UTC
Verified Secret/Binding was removed after deprovisioning.

Using oc v3.9.0-alpha.3 and latest console code and docker images.


Provisioned Service:

oc get secrets -n my-second-project | grep postgresql
postgresql                                      Opaque                                3         25m
postgresql-persistent-parameterspi9as           Opaque                                1         25m
postgresql-persistent-r2gd2-credentials-1m4r0   Opaque                                4         16m

After Deprovisioning Service:

oc get secrets -n my-second-project | grep postgresql
<no output>

Comment 9 Jessica Forrester 2018-01-18 16:02:26 UTC
Since we know this was fixed by a k8s rebase I will just mark as fixed by https://github.com/openshift/origin/pull/18003

Comment 10 Zhang Cheng 2018-01-19 02:46:53 UTC
QE also verified with latest downstream image. Passed.

Comment 14 errata-xmlrpc 2018-03-28 14:07:14 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2018:0489


Note You need to log in before you can comment on or make changes to this bug.