-
Bug
-
Resolution: Done
-
Critical
-
None
-
None
-
False
-
None
-
False
-
OCP 4.11.2
I've attached must-gather.tar.gz
We are installing on GCP using the cco utility and "manual" credentialsMode. After some time, the image-registry operator begins to crashloop, with the error:
controller.go:373] unable to sync: unable to sync storage configuration: Get "https://storage.googleapis.com/storage/v1/b/cahartma-0921cluster1-qcjgt-image-registry-us-east1-hqrjkdcwvy?alt=json&prettyPrint=false&projection=full": oauth2/google: unable to generate access token: Post "https://iamcredentials.googleapis.com/v1/projects/-/serviceAccounts/cahartma-092-openshift-i-wxvrd@openshift-observability.iam.gserviceaccount.com:generateAccessToken": oauth2/google: status code 400: {"error":"invalid_grant","error_description":"Unable to verify the ID Token signature."
- is related to
-
CCO-123 Update openshift operators to consume new 'external_account' type credentials
- Closed
- relates to
-
OCPSTRAT-469 Install and upgrade OpenShift with GCP Workload Identity
- Closed
- links to