Bug 1673155
| Summary: | Inconsistency when ProjectRequestTemplate specified with and without namespace identifier | ||||||||
|---|---|---|---|---|---|---|---|---|---|
| Product: | OpenShift Container Platform | Reporter: | brad.williams | ||||||
| Component: | Master | Assignee: | David Eads <deads> | ||||||
| Status: | CLOSED ERRATA | QA Contact: | zhou ying <yinzhou> | ||||||
| Severity: | unspecified | Docs Contact: | |||||||
| Priority: | unspecified | ||||||||
| Version: | 4.1.0 | CC: | aos-bugs, deads, jokerman, jupierce, mfojtik, mmccomas, yinzhou | ||||||
| Target Milestone: | --- | Keywords: | Reopened | ||||||
| Target Release: | 4.1.0 | ||||||||
| Hardware: | Unspecified | ||||||||
| OS: | Unspecified | ||||||||
| Whiteboard: | |||||||||
| Fixed In Version: | Doc Type: | If docs needed, set a value | |||||||
| Doc Text: | Story Points: | --- | |||||||
| Clone Of: | Environment: | ||||||||
| Last Closed: | 2019-06-04 10:42:31 UTC | Type: | Bug | ||||||
| Regression: | --- | Mount Type: | --- | ||||||
| Documentation: | --- | CRM: | |||||||
| Verified Versions: | Category: | --- | |||||||
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||||
| Cloudforms Team: | --- | Target Upstream Version: | |||||||
| Embargoed: | |||||||||
| Attachments: |
|
||||||||
|
Description
brad.williams
2019-02-06 19:24:33 UTC
Created attachment 1527672 [details]
projects.config.openshift.io CR
// TemplateReference references a template in a specific namespace.
// The namespace must be specified at the point of use.
type TemplateReference struct {
// name is the metadata.name of the referenced project request template
Name string `json:"name"`
}
See: https://github.com/openshift/cluster-openshift-apiserver-operator/blob/b23dac5f69383c0f70ac86089ef4df6c484f64b0/vendor/github.com/openshift/api/config/v1/types_project.go#L22-L21
Once we have `oc explain config.openshift.io` hopefully this will be more clear.
Also we don't want to check whether the template exists or not in the operator.
I think I see it. There's a piece of wiring missing. Good catch. I think I've got it here https://github.com/openshift/cluster-openshift-apiserver-operator/pull/149 Confirmed with OCP: [root@dhcp-140-138 yamlfile]# oc get clusterversion NAME VERSION AVAILABLE PROGRESSING SINCE STATUS version 4.0.0-0.nightly-2019-03-06-074438 True False 27h Cluster version is 4.0.0-0.nightly-2019-03-06-074438 The result is : When I create the CR with projectRequestTemplate=openshift-config/project-request , then the openshift-apiserver's configmap is "projectRequestTemplate": "openshift-config/openshift-config/project-request", then the project template not works well; When I create the CR with projectRequestTemplate=project-request, then the openshift-apiserver's configmap is "projectRequestTemplate": "openshift-config/project-request", the project template works. Hmm strange, the admission validation should return error when you set this field to `openshift-config/project-request` (as it should only allow the name). Can you paste the exact CR you created with this? [root@preserve-yinzhourhel-1 home]# oc get projects.config.openshift.io cluster -o yaml
apiVersion: config.openshift.io/v1
kind: Project
metadata:
creationTimestamp: 2019-03-13T08:42:21Z
generation: 1
name: cluster
resourceVersion: "116377"
selfLink: /apis/config.openshift.io/v1/projects/cluster
uid: ea93f1b7-456b-11e9-a203-02c79379c738
spec:
projectRequestMessage: ""
projectRequestTemplate:
name: openshift-config/project-request
[root@preserve-yinzhourhel-1 home]# oc get cm config -n openshift-apiserver -o yaml
apiVersion: v1
data:
config.yaml: |
{"aggregatorConfig":{"allowedNames":["kube-apiserver-proxy","system:kube-apiserver-proxy","system:openshift-aggregator"],"clientCA":"/var/run/configmaps/aggregator-client-ca/ca-bundle.crt","extraHeaderPrefixes":["X-Remote-Extra-"],"groupHeaders":["X-Remote-Group"],"usernameHeaders":["X-Remote-User"]},"apiVersion":"openshiftcontrolplane.config.openshift.io/v1","auditConfig":{"auditFilePath":"/var/log/openshift-apiserver/audit.log","enabled":true,"logFormat":"json","maximumFileSizeMegabytes":100,"maximumRetainedFiles":10,"policyConfiguration":{"apiVersion":"audit.k8s.io/v1beta1","kind":"Policy","omitStages":["RequestReceived"],"rules":[{"level":"None","resources":[{"group":"","resources":["events"]}]},{"level":"None","nonResourceURLs":["/api*","/version","/healthz"],"userGroups":["system:authenticated","system:unauthenticated"]},{"level":"Metadata","omitStages":["RequestReceived"]}]}},"imagePolicyConfig":{"internalRegistryHostname":"image-registry.openshift-image-registry.svc:5000"},"kind":"OpenShiftAPIServerConfig","projectConfig":{"projectRequestMessage":"","projectRequestTemplate":"openshift-config/openshift-config/project-request"},"routingConfig":{"subdomain":"apps.qe-yinzhou-upgrade.qe.devcluster.openshift.com"}}
Confirmed with latest OCP, the issue has fixed:
[zhouying@dhcp-140-138 ~]$ oc version --short
Client Version: v4.0.22
Server Version: v1.12.4+befe71b
Payload: 4.0.0-0.nightly-2019-03-15-063749
When try to create the project.config with
projectRequestTemplate:
name: openshift-config/project-request
will failed with error: The Project "" is invalid: spec.projectRequestTemplate.name: Invalid value: "openshift-config/project-request": a DNS-1123 subdomain must consist of lower case alphanumeric characters, '-' or '.', and must start and end with an alphanumeric character (e.g. 'example.com', regex used for validation is '[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*')
When create the project.config with
projectRequestTemplate:
name: project-request
Will succeed.
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2019:0758 |