Uploaded image for project: 'Red Hat Advanced Cluster Management'
  1. Red Hat Advanced Cluster Management
  2. ACM-26280

VM (on spoke) Configuration tab fails to configure for secrets/configmaps on Fleet UI

XMLWordPrintable

    • Quality / Stability / Reliability
    • False
    • Hide

      None

      Show
      None
    • False
    • Important
    • None

      Description of problem:

      The configuration tab's environment section (the inline secret/configmap viewer) likely still uses the ocp's console's default resource fetching.

       

      curl (for config map)- 

      curl 'https://console-openshift-console.apps.slot-03.dev09.red-chesterfield.com/api/kubernetes/api/v1/namespaces/default/configmaps?limit=250' \
        -H 'Accept: application/json' \
        -H 'Accept-Language: en-US,en;q=0.9' \
        -H 'Connection: keep-alive' \
        -b 'openshift-session-token-console-854f6f555b-lqvjz=MTc2Mjk5NjI4NHxwMnJUZWVGZlRGNnJJZU1ZUXZiWW1nc2VpYXFyQWJaQk9rZlo2clllRGZVWllfb2xrWVFJcW1yUkZJV3dXdzNUUm9fbEFYaE44Z0VRUE82eVdWdG5jZmN0ZEhqeEpnUzhIemhrQzl4cE45NU83SXlsZ1U1MlVCUFdhS2dZRGI2WGRBazd1LXBzbzNqeDByVzI0WDMzWExZdHkwNXVPcHlTSmpaeDZSdnp2Tlk1R0pVUFVIdTVBUnZFSWh0UnR4WlFWMUZBNWw4eW5MUDNjc3g2NHVrX2NiZXIwS1dZT0NNNUFmVVRpLTJJbmtPMWFXTmJEdEhCc0t4dEpJV1U0dGM0b3h0RVNiV29ESHhIZ0E1OU5jSjdvT1JYczY0MEtjZzVObXB5bnJobUNYY2FtblRHRDBzVG1BYUZEUVd5NlV4RWRIMEVZSXZHQm85SFdva0hmRjBmc3cyZXBOU09ZZEZiaGRzWTd4aVNUcWVxd1dVRlBPRmpmaHJhOUszSTN4Z0xfWkR1U2xvY1BpMmU2cTNBU09taVYzLTIzR21kbFJXY25wWGVHbHJqY0QwV0QxeTFsT2kzV3Y2UkdFND18ZWRNuhabRdFX-hzL0L-ggchskmfGAYKyCom57aEoAP0=; openshift-refresh-token=MTc2Mjk5NjI4NHxuc25lVXBRdE51WEVYU1YwTW0zOVJIQ0VEaFhTdlg5eUJrSy12cWVMbXFsZ2c3UEhVS2JxSFlrTUdkdlJocWdvSEZzOV9DbjdOX09DdndKOWJIMlpiWGtpaHpES01BPT18QDS48cw-a1bSav1kJZ6-KSD_eqfXPk1tLQrInMEjGe0=; 1e2670d92730b515ce3a1bb65da45062=f2e315d068f9b6fe9a3d215659f9e94a; watch=qJPrXaa0; analytics_session_id=1762994494573; csrf-token=c3y5lj_qArDsukSfFFhqOelGJEewJdcdQBCBIBzEmvbmNkfR-628gJBjaLS0bhO7; ajs_user_id=304f9f4e87894918469fd23932d5ddd2151c621d; ajs_anonymous_id=0fe3de95-b2e0-4c25-a7aa-67d3136340a5; analytics_session_id.last_access=1762996309913' \
        -H 'Referer: https://console-openshift-console.apps.slot-03.dev09.red-chesterfield.com/k8s/cluster/slot-04/ns/default/kubevirt.io~v1~VirtualMachine/admin-test-vm-spoke/configuration/storage' \
        -H 'Sec-Fetch-Dest: empty' \
        -H 'Sec-Fetch-Mode: cors' \
        -H 'Sec-Fetch-Site: same-origin' \
        -H 'User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36' \
        -H 'sec-ch-ua: "Chromium";v="142", "Google Chrome";v="142", "Not_A Brand";v="99"' \
        -H 'sec-ch-ua-mobile: ?0' \
        -H 'sec-ch-ua-platform: "macOS"' \
        --insecure

       

      Trying to configure/add config map, secret, sertvice account as the following user -

       

      On a VM residing on spoke doesn't work.

      Here, kubevirt.io:view role doesn't grant secrets/configmaps access,  but kubevirt.io-acm-managed:admin does, so the user should be able to see and modify those resources on the spoke.

       

      Version-Release number of selected component (if applicable): 2.15-165 (oct25th build)

      How reproducible: Always

        1. image-2025-11-12-20-31-58-864.png
          99 kB
          Atif Shafi
        2. image-2025-11-12-20-32-47-762.png
          501 kB
          Atif Shafi
        3. image-2025-12-01-04-34-24-154.png
          264 kB
          Atif Shafi
        4. image-2025-12-01-04-36-21-552.png
          246 kB
          Atif Shafi
        5. image-2025-12-01-04-37-21-874.png
          249 kB
          Atif Shafi

              rhn-support-ashafi Atif Shafi
              rhn-support-ashafi Atif Shafi
              Atif Shafi Atif Shafi
              ACM QE Team
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated: