Bug 2069922 - [RHOCP4.10] What minimum privileges are required for provisioning volume with vSphere CSI?
Summary: [RHOCP4.10] What minimum privileges are required for provisioning volume with...
Keywords:
Status: CLOSED INSUFFICIENT_DATA
Alias: None
Product: OpenShift Container Platform
Classification: Red Hat
Component: Documentation
Version: 4.10
Hardware: Unspecified
OS: Unspecified
medium
high
Target Milestone: ---
: 4.7.z
Assignee: Servesha
QA Contact: Wei Duan
Latha S
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2022-03-30 05:49 UTC by Swati Mulje
Modified: 2023-09-15 01:53 UTC (History)
7 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2022-05-27 09:57:52 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Issue Tracker RFE-2893 0 None None None 2022-05-27 00:10:41 UTC

Description Swati Mulje 2022-03-30 05:49:56 UTC
1. Bug Overview:

a) Description of bug report:

  [RHOCP4.10] What minimum privileges are required for provisioning volume with vSphere CSI?

b) Bug Description:

   From OpenShift Container Platform 4.10 includes a built-in version of the vSphere CSI Operator Driver that is supported by Red Hat.
   Customer wants to allocate only minimum privileges to Vsphere CSI driver.

   Please see doc[A], which explains how to install OpenShift on vSphere with UPI.
   About required vSphere privileges, it just says "This user must have at least the roles and privileges that are required for static or dynamic persistent volume provisioning in vSphere".
   It means that user doesn't need to allocate such a lot of privileges with UPI.

 So, Customer request is to have separate section in document which include required permission info just for enabling vSphere CSI driver in UPI installation page.  


[A] https://docs.openshift.com/container-platform/4.10/installing/installing_vsphere/installing-vsphere.html
  
2. Business impact:

  In actual situation, many VMs are running on our customer's vSphere cluster besides OpenShift.
  To avoid troubles, our customer wants to allocate only minimum privileges to OpenShift.
(For example, it would be a big problem if OpenShift deleted unrelated VM by bug of Machine API. For avoiding such a problem, customer doesn't want to allocate unnecessary privileges).

Thanks,
Swati

Comment 20 Red Hat Bugzilla 2023-09-15 01:53:24 UTC
The needinfo request[s] on this closed bug have been removed as they have been unresolved for 365 days


Note You need to log in before you can comment on or make changes to this bug.