Bug 1625766 - [apb] CLI tool produces failed provision when running as cluster-admin
Summary: [apb] CLI tool produces failed provision when running as cluster-admin
Keywords:
Status: CLOSED WONTFIX
Alias: None
Product: OpenShift Container Platform
Classification: Red Hat
Component: Documentation
Version: 3.11.0
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
: ---
Assignee: Latha S
QA Contact: Xiaoli Tian
Latha S
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2018-09-05 19:41 UTC by Dylan Murray
Modified: 2023-09-15 01:27 UTC (History)
4 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2022-08-08 13:10:57 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Bugzilla 1613664 0 medium CLOSED [apb-tools] apb bundle provision/deprovision failed when deployed by cluster-admin due to anyuid scc issue 2021-02-22 00:41:40 UTC

Internal Links: 1613664

Description Dylan Murray 2018-09-05 19:41:46 UTC
Document URL: 
https://docs.okd.io/latest/apb_devel/cli_tooling.html

Section Number and Name: 
https://docs.okd.io/latest/apb_devel/cli_tooling.html#apb-devel-cli-install-prereqs-access-permissions

Describe the issue: When running the CLI tool as cluster-admin, OpenShift will schedule the APB pod in the `anyuid` Security Context Constraint. This is well documented here: https://docs.okd.io/latest/architecture/additional_concepts/authorization.html#scc-prioritization

This causes issues with some APBs because they require running tasks which annotate the currently running pod. This is not allowed in the `anyuid` scc. We documented this in this comment: https://bugzilla.redhat.com/show_bug.cgi?id=1613664#c7

Suggestions for improvement: Provide warning that running the CLI tool as a cluster-admin will cause APB pods to be deployed under `anyuid` scc which causes some APBs to fail.

Additional information:

Comment 8 Red Hat Bugzilla 2023-09-15 01:27:39 UTC
The needinfo request[s] on this closed bug have been removed as they have been unresolved for 365 days


Note You need to log in before you can comment on or make changes to this bug.