Bug 2273386 - change odf CSV pods to read only root file system
Summary: change odf CSV pods to read only root file system
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat OpenShift Data Foundation
Classification: Red Hat Storage
Component: odf-operator
Version: 4.16
Hardware: Unspecified
OS: Unspecified
unspecified
high
Target Milestone: ---
: ODF 4.16.0
Assignee: Nitin Goyal
QA Contact: Filip Balák
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2024-04-04 15:02 UTC by Nitin Goyal
Modified: 2024-07-17 13:18 UTC (History)
3 users (show)

Fixed In Version: 4.16.0-72
Doc Type: No Doc Update
Doc Text:
Clone Of:
Environment:
Last Closed: 2024-07-17 13:17:59 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Github red-hat-storage odf-operator pull 396 0 None open bundle: add readOnlyRootFilesystem for odf-operator 2024-04-05 07:11:33 UTC
Github red-hat-storage odf-operator pull 397 0 None open Bug 2273386:[release-4.16] bundle: add readOnlyRootFilesystem for odf-operator 2024-04-08 15:27:54 UTC
Red Hat Product Errata RHSA-2024:4591 0 None None None 2024-07-17 13:18:02 UTC

Description Nitin Goyal 2024-04-04 15:02:59 UTC
Description of problem (please be detailed as possible and provide log
snippests):


Change the readOnlyRootFilesystem permissions of the containers related to odf.

Comment 6 Mudit Agarwal 2024-04-09 02:31:09 UTC
We need clones for 4.15/4.14 as well

Comment 9 Filip Balák 2024-04-25 12:06:17 UTC
Containers in ocs-operator and odf-operator-controller-manager pods are updated.

Regression runs didn't find any error directly caused by those changes (except when test case tried to manipulate directly read only filesystem)
tier1:  https://ocs4-jenkins-csb-odf-qe.apps.ocp-c1.prod.psi.redhat.com/job/qe-deploy-ocs-cluster-prod/11508/
tier3:  https://ocs4-jenkins-csb-odf-qe.apps.ocp-c1.prod.psi.redhat.com/job/qe-deploy-ocs-cluster-prod/11488/
tier4a: https://ocs4-jenkins-csb-odf-qe.apps.ocp-c1.prod.psi.redhat.com/job/qe-deploy-ocs-cluster-prod/11506/
tier4b: https://ocs4-jenkins-csb-odf-qe.apps.ocp-c1.prod.psi.redhat.com/job/qe-deploy-ocs-cluster-prod/11515/
tier4c: https://ocs4-jenkins-csb-odf-qe.apps.ocp-c1.prod.psi.redhat.com/job/qe-deploy-ocs-cluster-prod/11499/

Errors were compared to regression run history https://docs.google.com/spreadsheets/d/1akrwspvWglSs905x2JcydJNH08WO6Ptri-hrkZ2VO80/edit#gid=40270420

Tested ODF versions:
4.16.0-84, 4.16.0-81, 4.16.0-78, 4.16.0-72

--> VERIFIED

Comment 10 errata-xmlrpc 2024-07-17 13:17:59 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (Important: Red Hat OpenShift Data Foundation 4.16.0 security, enhancement & bug fix update), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHSA-2024:4591


Note You need to log in before you can comment on or make changes to this bug.