Uploaded image for project: 'Red Hat Advanced Cluster Management'
  1. Red Hat Advanced Cluster Management
  2. ACM-4612

ManifestWork not created for auto import pair token

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done
    • Icon: Major Major
    • None
    • ACM 2.8.0, ACM 2.7.0
    • Business Continuity
    • False
    • None
    • False
    • No

      When restoring the imported managed clusters, if the MSA auto import feature is used and the auto-import-pair token is used , you see this error

      This is because the RoleBinding for the auto-import-account-pair service account was not created.

       

      The workaround is to manually create the role binding on the managed cluster

       

      • lastTransitionTime: "2023-03-28T15:02:13Z"
        message: 'AutoImportSecretInvalid hosting-cluster/auto-import-secret; please check
        its permission, apply resources error: secrets "bootstrap-hub-kubeconfig" is
        forbidden: User "system:serviceaccount:open-cluster-management-agent-addon:auto-import-account-pair"
        cannot get resource "secrets" in API group "" in the namespace "open-cluster-management-agent"'
        reason: ManagedClusterImportFailed
        status: "False"
        type: ManagedClusterImportSucceeded

       
      kind: ClusterRoleBinding
      apiVersion: rbac.authorization.k8s.io/v1
      metadata:
      name:managedserviceaccount-import-pair
      subjects:
      -kind:ServiceAccount
      name:auto-import-account-pair
      namespace:open-cluster-management-agent-addon
      roleRef:
      apiGroup:rbac.authorization.k8s.io
      kind:ClusterRole
      name:klusterlet-bootstrap-kubeconfig

            vbirsan@redhat.com Valentina Birsan
            vbirsan@redhat.com Valentina Birsan
            Thuy Nguyen Thuy Nguyen
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated:
              Resolved:

                Estimated:
                Original Estimate - 1 day
                1d
                Remaining:
                Remaining Estimate - 1 day
                1d
                Logged:
                Time Spent - Not Specified
                Not Specified