Description of problem: When calling ' oc adm groups sync' it reports that some groups are outside the group base, which is true, but intended. However, the utility returns an error code '1' in this case, which will lead to failed cron jobs. when running the command, it returns an error code: # oc adm groups sync --sync-config=augmented_active_directory_config.yaml --confirm=false >sync_output 2>&1 # echo $? When looking at the output, there is no other error then the on 'group outside the base dn' # grep Error sync_output | grep -c -v 'outside of the base' 0 Version-Release number of selected component (if applicable): How reproducible: Steps to Reproduce: 1. 2. 3. Actual results: It returns a postive error code Expected results: Should not return any errors Additional info:
This seems like minor annoyance that will be fixed in the next release. Sally, we should identify the place where this error happens and make it not error.
Your use-case looks wrong. Why don't you broaden the DN of the group tree if you want groups that are outside your current tree? If it's because there's more groups than you'd like to sync, use whitelisting/blacklisting.
You don't want to do that, you just want that the sync to pass, I misunderstood.
The openshift/oc pull 405 does not fully resolve this issue, I'm moving back to modified while I open a follow-up PR.
Actually, @pmali the PR linked to this report (https://github.com/openshift/oc/pull/405) resolves this bug, please move back to ON_QA and verify. I'll clone/open a new bz for follow-up work - The follow-up is for RFC 2307 instead of Active Directory. Thanks
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2020:2409
The needinfo request[s] on this closed bug have been removed as they have been unresolved for 1000 days