Bug 1752045 - No RBAC method for setting ExternalIPs
Summary: No RBAC method for setting ExternalIPs
Alias: None
Product: OpenShift Container Platform
Classification: Red Hat
Component: Networking
Version: 4.3.z
Hardware: Unspecified
OS: Unspecified
Target Milestone: ---
: 4.3.0
Assignee: Aniket Bhat
QA Contact: zhaozhanqi
Depends On: 1757553
Blocks: 1759181
TreeView+ depends on / blocked
Reported: 2019-09-13 14:25 UTC by Casey Callendrello
Modified: 2020-01-23 11:06 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
: 1759181 1759182 (view as bug list)
Last Closed: 2020-01-23 11:05:53 UTC
Target Upstream Version:

Attachments (Terms of Use)

System ID Private Priority Status Summary Last Updated
Github openshift origin pull 23783 0 'None' closed Bug 1752045: UPSTREAM: <carry>:Add a RBAC checker for external IP ranger 2020-02-14 08:18:19 UTC
Red Hat Product Errata RHBA-2020:0062 0 None None None 2020-01-23 11:06:22 UTC

Internal Links: 1757553

Comment 1 Dan Winship 2019-09-13 15:04:05 UTC
> The solution is to create a special RBAC check in the ExternalIPAdmissionController[1] that looks like the one in the RestrictedEndpointAdmissionController[2]

The links there are to 4.1, but we'll want to do this in git master first, where the controller has moved to vendor/k8s.io/kubernetes/openshift-kube-apiserver/admission/network/externalipranger/externalip_admission.go

Comment 4 Weibin Liang 2019-10-04 18:09:44 UTC
Verified it on v4.3.0-0.ci-2019-10-04-083724.

Will re-test it when the v4.3 nightly image ready on https://openshift-release.svc.ci.openshift.org/

Comment 5 zhaozhanqi 2019-10-09 09:33:06 UTC
from comment 4. this bug can be verified.

Comment 7 errata-xmlrpc 2020-01-23 11:05:53 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.


Note You need to log in before you can comment on or make changes to this bug.