Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1610991 - [3.7] Provision call failed: deploymentconfigs is forbidden: User cannot get deploymentconfigs in project
[3.7] Provision call failed: deploymentconfigs is forbidden: User cannot get ...
Status: CLOSED ERRATA
Product: OpenShift Container Platform
Classification: Red Hat
Component: Templates (Show other bugs)
3.7.0
Unspecified Unspecified
high Severity high
: ---
: 3.7.z
Assigned To: Ben Parees
Dongbo Yan
: Reopened
: 1584105 (view as bug list)
Depends On: 1562527 1610994 1610995
Blocks:
  Show dependency treegraph
 
Reported: 2018-08-01 16:18 EDT by Ben Parees
Modified: 2018-08-29 07:39 EDT (History)
16 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Cause: Groups associated w/ a user were not checked when performing access checks to look up the readiness of objects created by the templates. Consequence: For objects the user could only access due to their group membership, objects would be created by the template, but could not be checked for readiness, resulting in a readiness failure at the template instance level. Fix: Pass the user's groups when performing the readiness check operation, not just when performing the object creation. Result: Objects can successfully be checked for readiness as long as the user's group membership permits the check.
Story Points: ---
Clone Of: 1562527
Environment:
Last Closed: 2018-08-29 07:39:55 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Comment 1 Ben Parees 2018-08-02 13:16:16 EDT
*** Bug 1584105 has been marked as a duplicate of this bug. ***
Comment 2 Ben Parees 2018-08-02 14:21:28 EDT
https://github.com/openshift/ose/pull/1384
Comment 4 Dongbo Yan 2018-08-23 06:05:14 EDT
Test with
# openshift version
openshift v3.7.62
kubernetes v1.7.6+a08f5eeb62
etcd 3.2.8

Reproduce steps:
1. Login openshift with user1 and create project 
2. Create user group and add admin role to group
$oc adm groups new testgroup user1 user2
$oc policy add-role-to-group admin testgroup -n testproject

3. Login to the webconsole as user2
4. Using the web console, switch to that testproject and add the httpd service catalog item, click through accepting defaults

5. Check serviceinstance status
$oc get serviceinstance
$oc describe serviceinstance/httpd-example-v8fpv

Actual result:
servicesintance is ready
Comment 6 errata-xmlrpc 2018-08-29 07:39:55 EDT
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2018:2547

Note You need to log in before you can comment on or make changes to this bug.