Bug 2132074 - MTC Operator pods not coming up on OCP 4.12
Summary: MTC Operator pods not coming up on OCP 4.12
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Migration Toolkit for Containers
Classification: Red Hat
Component: Operator
Version: 1.7.5
Hardware: Unspecified
OS: Unspecified
unspecified
urgent
Target Milestone: ---
: 1.7.5
Assignee: Jason Montleon
QA Contact: ssingla
Anjana Suparna Sriram
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2022-10-04 14:55 UTC by ssingla
Modified: 2022-10-31 11:10 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2022-10-31 11:10:35 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Github migtools mig-operator pull 852 0 None Merged Add SCC Adjustment for Pod Security on 4.12 2022-10-04 19:34:25 UTC
Github migtools mig-operator pull 853 0 None Merged [release-1.7.5] Add SCC Adjustment for Pod Security on 4.12 (#852) 2022-10-04 19:34:25 UTC
Red Hat Product Errata RHBA-2022:7262 0 None None None 2022-10-31 11:10:40 UTC

Description ssingla 2022-10-04 14:55:02 UTC
Description of problem: On installing MTC 1.7.5 on OCP 4.12, the migration operator pods are not spinning up due to PSA changes in OCP 4.12.


Version-Release number of selected component (if applicable):
OCP 4.12
MTC 1.7.5

How reproducible:
Always

Steps to Reproduce:

Install MTC 1.7.5 on OCP 4.12 cluster


Actual results:
ReplicaSet  failed to create pods with below error:

 ReplicaFailure   True    FailedCreate
Events:
  Type     Reason        Age                            From                   Message
  ----     ------        ----                           ----                   -------
  Warning  FailedCreate  <invalid>                      replicaset-controller  Error creating: pods "migration-operator-68bf58c696-fj84p" is forbidden: violates PodSecurity "restricted:latest": allowPrivilegeEscalation != false (container "operator" must set securityContext.allowPrivilegeEscalation=false), unrestricted capabilities (container "operator" must set securityContext.capabilities.drop=["ALL"]), runAsNonRoot != true (pod or container "operator" must set securityContext.runAsNonRoot=true), seccompProfile (pod or container "operator" must set securityContext.seccompProfile.type to "RuntimeDefault" or "Localhost")



Expected results:

MTC should be successfully installed on OCP 4.12

Additional info:

Comment 1 Jason Montleon 2022-10-04 16:37:39 UTC
I think we will fix this with https://github.com/migtools/mig-operator/pull/852

Please test when able and let me know if it doesn't work so we can further investigate.

Comment 16 errata-xmlrpc 2022-10-31 11:10:35 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (Migration Toolkit for Containers (MTC) 1.7.5 bug fix update), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2022:7262


Note You need to log in before you can comment on or make changes to this bug.