Description of problem: When the "restricted" SCC is changed to have a "runAsUser" value of "RunAsAny" it results in the service-ca pod not starting up and remaining in a "CreateContainerConfigError" state. The pod yaml notes: container has runAsNonRoot and image will run as root (pod: "service-ca-78d76c8f96-9d94g_openshift-service-ca(164c78e4-4e79-47d3-afca-53358e43e70b)", container: service-ca-controller) Version-Release number of selected component (if applicable): 4.7.11 How reproducible: Always Steps to Reproduce: 1. Set the "restricted" SCC to have a "runAsUser" value of "RunAsAny" 2. Restart the service-ca pod. 3. Pod will not start up.
https://docs.openshift.com/container-platform/4.7/authentication/managing-security-context-constraints.html
The docs in https://bugzilla.redhat.com/show_bug.cgi?id=1969230#c1 say you should not change the default SCCs.
Also, your bug report is different from the original.