Uploaded image for project: 'OpenShift Cloud Credential Operator'
  1. OpenShift Cloud Credential Operator
  2. CCO-260

invalid_grant error in the image-registry operator on GCP using WIF

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done
    • Icon: Critical Critical
    • None
    • None
    • Quality / Stability / Reliability
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      OCP 4.11.2

      I've attached must-gather.tar.gz

      We are installing on GCP using the cco utility and "manual" credentialsMode.  After some time, the image-registry operator begins to crashloop, with the error: 

      controller.go:373] unable to sync: unable to sync storage configuration: Get "https://storage.googleapis.com/storage/v1/b/cahartma-0921cluster1-qcjgt-image-registry-us-east1-hqrjkdcwvy?alt=json&prettyPrint=false&projection=full": oauth2/google: unable to generate access token: Post "https://iamcredentials.googleapis.com/v1/projects/-/serviceAccounts/cahartma-092-openshift-i-wxvrd@openshift-observability.iam.gserviceaccount.com:generateAccessToken": oauth2/google: status code 400: {"error":"invalid_grant","error_description":"Unable to verify the ID Token signature."
      

              Unassigned Unassigned
              cahartma@redhat.com Casey Hartman
              None
              None
              None
              None
              None
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: