the template service broker is installed as a daemonset. It creates a project without checking whether there is a default node selector and the tries to schedule the pods to all the nodes. This fails if the cluster is installed with different regions and some of the regions are not schedulable with the default node selector. This always happens in standard installs because there are at least two regions: infranodes and worker nodes. Sometime masters are also in a separate region.
https://github.com/openshift/openshift-ansible/pull/6386
QE, please can you ensure that after install, for the TSB daemonset, there is one pod per infra node, in state Running, and that no other pods exist for the TSB daemonset.
The fix is in the installer, not in OCP. To test, need to install OCP 3.7 with a version of the ansible installer that includes the PR.
Not fixed with latest OCP 3.7 build openshift-ansible-3.7.15-1.git.0.b20e6be.el7.noarch.rpm Could you please indicate which build to verify the bug Thanks.
Yes, looks like the fix is not in 3.7.15. Presumably it will be in the following release.
not work as expected. openshift-ansible-3.7.18-1.git.0.a01e769.el7.noarch.rpm PR is included # cat main.yml --- # placeholder file? template_service_broker_remove: False template_service_broker_install: True openshift_template_service_broker_namespaces: ['openshift'] template_service_broker_selector: { "region": "infra" } [root@host-172-16-120-8 ~]# oc get ds -n openshift-template-service-broker NAME DESIRED CURRENT READY UP-TO-DATE AVAILABLE NODE-SELECTOR AGE apiserver 5 5 5 5 5 role=node 24m
Weihua, please could you provide more detail on how you're running ansible / access to your environment? I'm pretty sure that role=node must be being overridden somewhere by your config, but I'm not clear where.
Thanks, Jim. You are right. This Bug is Fixed. openshift-ansible-3.7.18-1.git.0.a01e769.el7.noarch.rpm [root@host-172-16-120-49 ~]# oc get ds -n openshift-template-service-broker NAME DESIRED CURRENT READY UP-TO-DATE AVAILABLE NODE-SELECTOR AGE apiserver 0 0 0 0 0 region=infra 36m
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2018:0113