Bug 2072730 - Upgrade: UOCR should not try to create an enforced copy of an already enforced policy
Summary: Upgrade: UOCR should not try to create an enforced copy of an already enforce...
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: OpenShift Container Platform
Classification: Red Hat
Component: Telco Edge
Version: 4.10
Hardware: Unspecified
OS: Unspecified
low
low
Target Milestone: ---
: 4.10.z
Assignee: melserng
QA Contact: yliu1
URL:
Whiteboard:
: 2072604 (view as bug list)
Depends On: 2044304
Blocks: 2072604
TreeView+ depends on / blocked
 
Reported: 2022-04-06 21:07 UTC by OpenShift BugZilla Robot
Modified: 2022-07-11 15:28 UTC (History)
4 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2022-07-11 15:28:27 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Github openshift-kni cluster-group-upgrades-operator pull 150 0 None open [release-4.10] Bug 2072730: Ignore policies that have remediationAction enforce 2022-04-27 14:00:22 UTC
Red Hat Product Errata RHBA-2022:5514 0 None None None 2022-07-11 15:28:44 UTC

Description OpenShift BugZilla Robot 2022-04-06 21:07:48 UTC
+++ This bug was initially created as a clone of Bug #2044304 +++

Description of problem:

Currently, it is possible to add a managedPolicy in a ClusterGroupUpgrade manifest that is already enforced.

Version-Release number of selected component (if applicable):
4.10

How reproducible:
Always

Steps to Reproduce:
1. Create an enforced ACM policy by creating an ACM policy directly or a PGT with the remediationAction equals to enforce
2. Verify that the policy is patching the targeted clusters
3. Create a CGU manifest that includes the previous enforced policy

Actual results:
A copy of the previous enforced policy is created by the UOCR in enforce mode too

Expected results:
No copy policy needs to be created by the UOCR since the original policy was set to enforce.

Additional info:

Comment 2 jun 2022-05-05 16:17:21 UTC
*** Bug 2072604 has been marked as a duplicate of this bug. ***

Comment 5 yliu1 2022-07-07 18:43:13 UTC
Verified in latest 4.10 TALM build. 
Enforce policies are ignored. 

2022-07-07T18:41:25.355Z	INFO	controllers.ClusterGroupUpgrade	[doManagedPoliciesExist] Ignoring policy common-config-policy with remediationAction enforce
2022-07-07T18:41:25.355Z	INFO	controllers.ClusterGroupUpgrade	[doManagedPoliciesExist] Ignoring policy common-subscriptions-policy with remediationAction enforce

Comment 7 errata-xmlrpc 2022-07-11 15:28:27 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (OpenShift Container Platform 4.10.22 extras update), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2022:5514


Note You need to log in before you can comment on or make changes to this bug.