Bug 1806908 - openshift-ovirt-infra: Some core components are in openshift.io/run-level 1 and are bypassing SCC, but should not be
Summary: openshift-ovirt-infra: Some core components are in openshift.io/run-level 1 a...
Keywords:
Status: CLOSED NOTABUG
Alias: None
Product: OpenShift Container Platform
Classification: Red Hat
Component: Installer
Version: 4.4
Hardware: Unspecified
OS: Unspecified
high
medium
Target Milestone: ---
: 4.4.0
Assignee: Roy Golan
QA Contact: Jan Zmeskal
URL:
Whiteboard:
Depends On:
Blocks: 1805488 1966621
TreeView+ depends on / blocked
 
Reported: 2020-02-25 10:00 UTC by Stefan Schimanski
Modified: 2023-09-15 00:29 UTC (History)
13 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of: 1805488
Environment:
Last Closed: 2020-02-26 18:37:11 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)

Comment 1 Abhinav Dahiya 2020-02-25 21:41:24 UTC
This namespace hosts the dns and virtual ip components and there is high likely hood these need to run before openshift-apiserver runs. will leave it for RHV team to decide.

Comment 2 Sandro Bonazzola 2020-02-26 13:00:54 UTC
Reducing severity and priority after discussing with the development team about this.

Comment 3 Roy Golan 2020-02-26 14:08:18 UTC
Stefan Aside from not getting root permissions, are there any more implications for run-level != 1 ?

If we can reduce the run-level for that namespace we should do it.

The static pods we need are coredns, mdns-publisher and keepalived. coredns publishes port 53. Is there a run-level 
that would allow me to do that? any documentation on those run-levels?

Comment 4 Scott Dodson 2020-02-26 18:37:11 UTC
The components in this namespace like DNS and API load balancing are required by all other components in the cluster and as such must be run at run level 1.

Comment 5 Red Hat Bugzilla 2023-09-15 00:29:52 UTC
The needinfo request[s] on this closed bug have been removed as they have been unresolved for 500 days


Note You need to log in before you can comment on or make changes to this bug.