Uploaded image for project: 'Cluster Observability Operator'
  1. Cluster Observability Operator
  2. COO-945

Error '65534 is not an allowed group' displays in event when Create monitoringstack

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Normal Normal
    • None
    • 1.1.1
    • operator
    • None
    • Quality / Stability / Reliability
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      Launch Openshift cluster which uses Security Context Constraints (SCCs)
      Install COO 1.1.1 and create monitoring stack
      Prometheus pod failed to create

      % oc get event
      LAST SEEN   TYPE      REASON             OBJECT                                                        MESSAGE
      67s         Normal    NoPods             poddisruptionbudget/example-app-monitoring-stack-prometheus   No matching pods found
      ......
      44s         Normal    Started            pod/prometheus-example-app-monitoring-stack-1                 Started container thanos-sidecar 67s         Warning   FailedCreate       statefulset/prometheus-example-app-monitoring-stack           create Pod prometheus-example-app-monitoring-stack-0 in StatefulSet prometheus-example-app-monitoring-stack failed error: pods "prometheus-example-app-monitoring-stack-0" is forbidden: unable to validate against any security context constraint: [provider "anyuid": Forbidden: not usable by user or serviceaccount, provider restricted-v2: .spec.securityContext.fsGroup: Invalid value: []int64{65534}: 65534 is not an allowed group, provider restricted-v2: .initContainers[0].runAsUser: Invalid value: 65534: must be in the ranges: [1000830000, 1000839999], provider restricted-v2: .containers[0].runAsUser: Invalid value: 65534: must be in the ranges: [1000830000, 1000839999], provider restricted-v2: .containers[1].runAsUser: Invalid value: 65534: must be in the ranges: [1000830000, 1000839999], provider restricted-v2: .containers[2].runAsUser: Invalid value: 65534: must be in the ranges: [1000830000, 1000839999], provider "restricted": Forbidden: not usable by user or serviceaccount, provider "nonroot-v2": Forbidden: not usable by user or serviceaccount, provider "nonroot": Forbidden: not usable by user or serviceaccount, provider "hostmount-anyuid": Forbidden: not usable by user or serviceaccount, provider "machine-api-termination-handler": Forbidden: not usable by user or serviceaccount, provider "hostnetwork-v2": Forbidden: not usable by user or serviceaccount, provider "hostnetwork": Forbidden: not usable by user or serviceaccount, provider "hostaccess": Forbidden: not usable by user or serviceaccount, provider "node-exporter": Forbidden: not usable by user or serviceaccount, provider "privileged": Forbidden: not usable by user or serviceaccount] 67s         Normal    SuccessfulCreate   statefulset/prometheus-example-app-monitoring-stack           create Pod prometheus-example-app-monitoring-stack-0 in StatefulSet prometheus-example-app-monitoring-stack successful 67s         Normal    SuccessfulCreate   statefulset/prometheus-example-app-monitoring-stack           create Pod prometheus-example-app-monitoring-stack-1 in StatefulSet prometheus-example-app-monitoring-stack successful

              Unassigned Unassigned
              hongyli@redhat.com Hongyan Li
              None
              None
              None
              None
              None
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated: