Bug 1679629 - OCP 4.0 the openshift.io/scc annotation is missing on pods.
Summary: OCP 4.0 the openshift.io/scc annotation is missing on pods.
Alias: None
Product: OpenShift Container Platform
Classification: Red Hat
Component: Networking
Version: 4.1.0
Hardware: Unspecified
OS: Unspecified
Target Milestone: ---
: 4.1.0
Assignee: Dan Mace
QA Contact: Hongan Li
Depends On:
TreeView+ depends on / blocked
Reported: 2019-02-21 15:43 UTC by Ryan Howe
Modified: 2022-08-04 22:20 UTC (History)
5 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Last Closed: 2019-06-04 10:44:19 UTC
Target Upstream Version:

Attachments (Terms of Use)

System ID Private Priority Status Summary Last Updated
Github openshift cluster-ingress-operator pull 160 0 'None' closed Bug 1679629: manifests: remove run-level namespace label 2020-11-10 18:28:08 UTC
Red Hat Product Errata RHBA-2019:0758 0 None None None 2019-06-04 10:44:27 UTC

Description Ryan Howe 2019-02-21 15:43:43 UTC
Description of problem:

 In OCP 4.0 the openshift.io/scc annotation is missing on pods. In 3.x this annotation would get set on the pods, gave users the ability to confirm what SCC the pods is running under. 

Version-Release number of selected component (if applicable):
oc v4.0.0-0.171.0
kubernetes v1.12.4+a532756e37
features: Basic-Auth GSSAPI Kerberos SPNEGO

Server XXXXx
kubernetes v1.12.4+f39ab668d3

How reproducible:

Steps to Reproduce:
1. Deploy cluster
2. `oc get pod NAME -o yaml

Actual results:
# oc get pods -n openshift-ingress -o template --template='{{ range .items}}{{.metadata.annotations }}{{end}}'
    "name": "openshift-sdn",
    "ips": [
    "default": true,
    "dns": {}

Expected results:
  Set openshift.io/scc annotation on all pods that get deployed on the cluster:

    openshift.io/scc: restricted  

Comment 3 Erica von Buelow 2019-02-28 16:06:26 UTC
Please re-open if this issue happens on "normal" namespaces (those without the "openshift.io/run-level" annotation).

Comment 4 Mo 2019-02-28 18:01:24 UTC
I have requested that the NE team remove the run-level label from their namespace(s) as an operator at the default run level runs after the openshift api server and thus does not need to skip admission checks (including SCC).

Comment 7 Hongan Li 2019-03-19 10:37:26 UTC
verified with 4.0.0-0.nightly-2019-03-18-200009 and the label 'openshift.io/run-level: "0"' has been removed from openshift-ingress and openshift-ingress-operator namesapce.

Comment 9 errata-xmlrpc 2019-06-04 10:44:19 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.


Note You need to log in before you can comment on or make changes to this bug.