Bug 1734674 - CSI controller sidecars can't access CSI driver socket
Summary: CSI controller sidecars can't access CSI driver socket
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: OpenShift Container Platform
Classification: Red Hat
Component: Storage
Version: 4.2.0
Hardware: Unspecified
OS: Unspecified
unspecified
medium
Target Milestone: ---
: 4.2.0
Assignee: Jan Safranek
QA Contact: Chao Yang
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2019-07-31 07:46 UTC by Jan Safranek
Modified: 2019-10-16 06:34 UTC (History)
4 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2019-10-16 06:34:11 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Github openshift csi-external-attacher pull 15 0 None None None 2019-07-31 09:08:56 UTC
Github openshift csi-external-provisioner pull 14 0 None None None 2019-07-31 09:08:58 UTC
Github openshift csi-external-resizer pull 3 0 None None None 2019-07-31 09:09:10 UTC
Github openshift csi-external-snapshotter pull 10 0 None None None 2019-07-31 09:09:07 UTC
Github openshift csi-livenessprobe pull 11 0 None None None 2019-07-31 09:09:05 UTC
Github openshift csi-node-driver-registrar pull 10 0 None None None 2019-07-31 09:09:02 UTC
Red Hat Product Errata RHBA-2019:2922 0 None None None 2019-10-16 06:34:23 UTC

Description Jan Safranek 2019-07-31 07:46:34 UTC
When AWS EBS CSI driver is deployed with OCP sidecars, csi-external-provisioner and csi-external-attacher cannot access unix domain socket provided by the CSI driver.

All CSI sidecars run as a dedicated user (e.g. csi-provisioner, usually with UID 1000), while the driver runs as root. The driver creates its socket with permissions 0755, not allowing the sidecars to write to the socket.

Comment 3 errata-xmlrpc 2019-10-16 06:34:11 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2019:2922


Note You need to log in before you can comment on or make changes to this bug.