Uploaded image for project: 'Red Hat Advanced Cluster Management'
  1. Red Hat Advanced Cluster Management
  2. ACM-27290

Fix restrictive image policy for OCP 4.19+ in disconnected installs (Follow-up to ACM-21309)

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Major Major
    • None
    • None
    • None
    • None
    • False
    • Hide

      None

      Show
      None
    • False
    • None

      The previous fix for ACM-21309 (PR #7807) attempted to allow unsigned images by setting a global default: insecureAcceptAnything policy.
      However, installations on OCP 4.19 still fail when pulling from registry.redhat.io with: Source image rejected: A signature was required.

      Investigation (supported by OCPBUGS-55106) reveals that RHCOS 4.19 ships with a /etc/containers/policy.json that explicitly enforces signature verification for:
      - registry.redhat.io
      - registry.access.redhat.com

      These are defined under the docker transport.
      Because specific scope matches take precedence over the default scope, the global insecure setting is ignored for these registries.

      This ticket tracks the fix to explicitly inject insecureAcceptAnything for these specific registry scopes under the docker transport.

              rh-ee-ovishlit Omer Vishlitzky
              rh-ee-ovishlit Omer Vishlitzky
              Gal Amado Gal Amado
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Created:
                Updated: