Description of problem:
I installed a fresh cluster and created a user in the htpasswd file. The user can log in, can create new projects and deploy an app. However, when browsing over to the deployment or the replica set, and switching to the "pods" tab, you get the error: "Restricted Access". There is no problem to list pods in the Pods page with this user, so there should also be no problem listing the deployment's pods.
Version-Release number of selected component (if applicable):
Steps to Reproduce:
1. Create a user and log in with it
2. Create a new project
3. Create a new application (I created hello-openshift)
4. Browse to the deployment page, select the deployment, and switch to the "Pods" tab
pods is forbidden: User "alice" cannot list resource "pods" in API group "" at the cluster scope
Deployment pods should be listed
The cluster is a libvirt cluster simulating bare metals, installed with the dev-scripts.
There is likely a missing role/permission rule for the created users of this auth mechanism here (and doc step to identify the need). Assigning to auth to take a look to fill in the gap.
Moving to console, `pods is forbidden: User "alice" cannot list resource "pods" in API group "" at the cluster scope` means cluster-level pods search was performed although the user expected a namespaced search. Idk whether it's intended or not.
now we could see pod list under pod tab with normal user
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.
For information on the advisory, and where to find the updated
files, follow the link below.
If the solution does not work for you, open a new bug report.