Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Give the operator permission to give permission to pod/logs get #1000

Merged
merged 1 commit into from
Oct 10, 2023

Conversation

bdunne
Copy link
Member

@bdunne bdunne commented Oct 10, 2023

Followup to #999

Fixes:

2023-10-10T16:16:02Z	ERROR	Reconciler error	{"controller": "manageiq", "controllerGroup": "manageiq.org", "controllerKind": "ManageIQ", "ManageIQ": {"name":"manageiq-sample","namespace":"miq"}, "namespace": "miq", "name": "manageiq-sample", "reconcileID": "8c9e0471-2231-4d18-ac75-7ef1530ccaed", "error": "roles.rbac.authorization.k8s.io \"manageiq-automation\" is forbidden: user \"system:serviceaccount:miq:manageiq-operator\" (groups=[\"system:serviceaccounts\" \"system:serviceaccounts:miq\" \"system:authenticated\"]) is attempting to grant RBAC permissions not currently held:\n{APIGroups:[\"\"], Resources:[\"pods/logs\"], Verbs:[\"get\"]}"} sigs.k8s.io/controller-runtime/pkg/internal/controller.(*Controller).reconcileHandler
	/go/pkg/mod/sigs.k8s.io/[email protected]/pkg/internal/controller/controller.go:329
sigs.k8s.io/controller-runtime/pkg/internal/controller.(*Controller).processNextWorkItem
	/go/pkg/mod/sigs.k8s.io/[email protected]/pkg/internal/controller/controller.go:266
sigs.k8s.io/controller-runtime/pkg/internal/controller.(*Controller).Start.func2.2
	/go/pkg/mod/sigs.k8s.io/[email protected]/pkg/internal/controller/controller.go:227

Fixes:
2023-10-10T16:16:02Z	ERROR	Reconciler error	{"controller": "manageiq", "controllerGroup": "manageiq.org", "controllerKind": "ManageIQ", "ManageIQ": {"name":"manageiq-sample","namespace":"miq"}, "namespace": "miq", "name": "manageiq-sample", "reconcileID": "8c9e0471-2231-4d18-ac75-7ef1530ccaed", "error": "roles.rbac.authorization.k8s.io \"manageiq-automation\" is forbidden: user \"system:serviceaccount:miq:manageiq-operator\" (groups=[\"system:serviceaccounts\" \"system:serviceaccounts:miq\" \"system:authenticated\"]) is attempting to grant RBAC permissions not currently held:\n{APIGroups:[\"\"], Resources:[\"pods/logs\"], Verbs:[\"get\"]}"}
sigs.k8s.io/controller-runtime/pkg/internal/controller.(*Controller).reconcileHandler
	/go/pkg/mod/sigs.k8s.io/[email protected]/pkg/internal/controller/controller.go:329
sigs.k8s.io/controller-runtime/pkg/internal/controller.(*Controller).processNextWorkItem
	/go/pkg/mod/sigs.k8s.io/[email protected]/pkg/internal/controller/controller.go:266
sigs.k8s.io/controller-runtime/pkg/internal/controller.(*Controller).Start.func2.2
	/go/pkg/mod/sigs.k8s.io/[email protected]/pkg/internal/controller/controller.go:227
@miq-bot
Copy link
Member

miq-bot commented Oct 10, 2023

Checked commit bdunne@4a7896c with ruby 2.6.10, rubocop 1.28.2, haml-lint 0.35.0, and yamllint
1 file checked, 1 offense detected

**

  • 💣 💥 🔥 🚒 - Linter/Yaml - missing config files

@Fryguy Fryguy merged commit a281143 into ManageIQ:master Oct 10, 2023
3 checks passed
@Fryguy
Copy link
Member

Fryguy commented Oct 10, 2023

Backported to quinteros in commit 4d46872.

commit 4d46872acc845ce6a6d3d6fe9fa751bf6be5ac48
Author: Jason Frey <[email protected]>
Date:   Tue Oct 10 13:12:57 2023 -0400

    Merge pull request #1000 from bdunne/automation_role_pods_logs
    
    Give the operator permission to give permission to pod/logs get
    
    (cherry picked from commit a281143223f073f851c63de9aa11008f9d88c431)

Fryguy added a commit that referenced this pull request Oct 10, 2023
Give the operator permission to give permission to pod/logs get

(cherry picked from commit a281143)
@bdunne bdunne deleted the automation_role_pods_logs branch October 10, 2023 17:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants