Bug 2004264 - Cannot use AlreadyExists if ResourceQuota is present in the namespace and is primed
Summary: Cannot use AlreadyExists if ResourceQuota is present in the namespace and is ...
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Migration Toolkit for Containers
Classification: Red Hat
Component: Controller
Version: 1.5.0
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: ---
: 1.7.0
Assignee: Jaydip Gabani
QA Contact: Xin jiang
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2021-09-14 20:20 UTC by Alay Patel
Modified: 2022-03-24 06:32 UTC (History)
4 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2022-03-24 06:32:26 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Github konveyor mig-controller pull 1267 0 None open Bug 2004264: Making sure if the error is due to resourcequota or not 2022-02-04 15:06:07 UTC
Red Hat Product Errata RHBA-2022:1043 0 None None None 2022-03-24 06:32:38 UTC

Description Alay Patel 2021-09-14 20:20:11 UTC
Description of problem:

If a ResourceQuota Object is present in a namespaces and if user or controller tries to create the same object again it will be returned with 403 Forbidden error instead of `resource AlreadyExists` error. 

mig-controller creates the resource and then looks for IsAlreadyError(err). Although, if the resource exists and if the resourcequota is primed, it will give 403 forbidden and will fail the mig-migration.

See this from the CLI:

create the following resources

1. quota

apiVersion: v1
kind: ResourceQuota
metadata:
  name: pod-quota
spec:
  hard:
    pods: "1"
2. pod

apiVersion: v1
kind: Pod
metadata:
  labels:
    app.kubernetes.io/component: rsync-stunnel-mover
    app.kubernetes.io/name: volsync-src-my-source
    app.kubernetes.io/part-of: volsync
  name: busybox
  namespace: scribe-source
spec:
  containers:
  - command:
    - /bin/bash
    - -c
    - sleep 3600
    image: quay.io/konveyor/rsync-transfer:latest
    imagePullPolicy: Always
    name: rsync
    resources: {}
    securityContext:
      capabilities:
        drop:
        - MKNOD
        - SETPCAP
      privileged: false
      readOnlyRootFilesystem: true
      runAsUser: 0
    terminationMessagePath: /dev/termination-log
    terminationMessagePolicy: File

3. create the pod again:
$ oc create -f /tmp/pod.yaml
Error from server (Forbidden): error when creating "/tmp/pod.yaml": pods "busybox" is forbidden: exceeded quota: pod-quota, requested: pods=1, used: pods=1, limited: pods=1

Version-Release number of selected component (if applicable):
1.4+

How reproducible:
Always

Steps to Reproduce:
1. Create ResourceQuota on the destination cluster with 2Gi request limit on persistent volumes

apiVersion: v1
kind: ResourceQuota
metadata:
  name: storagequota
spec:
  hard:
    requests.storage: "2Gi"
2. Run the stage migration with pvc of 2 gigs in the source namespace, it will pass
3. Run the stage migration again. It will complete with warnings. DVM will fail

Actual results:
Complete with warning

Expected results:
Complete without warnings

Additional info:

Comment 8 errata-xmlrpc 2022-03-24 06:32:26 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (Migration Toolkit for Containers (MTC) 1.7.0 release advisory), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2022:1043


Note You need to log in before you can comment on or make changes to this bug.