-
Bug
-
Resolution: Unresolved
-
Undefined
-
None
-
None
-
None
Description of Problem
- The cluster role created for the ApplicationSet controller is missing required permissions, causing failures when reconciling.
Additional Info
Problem Reproduction
- <How do we reproduce the problem?>
Reproducibility
- <Always/Intermittent/Only Once>
Prerequisites/Environment
- <OpenShift, managed service (e.g., ROSA, ARO), operators, layered product, and other software versions, build details>
Steps to Reproduce
Steps to reproduce the behavior:
- Setup argocd that has cluster scope enabled
- Create ApplicationSet resource in a different namespace that the argocd
- ApplicationSet controller fails with missing permissions
"failed to list *v1alpha1.AppProject: appprojects.argoproj.io is forbidden: User \"system:serviceaccount:argocd:argocd-applicationset-controller\" cannot list resource \"appprojects\" in API group \"argoproj.io\" at the cluster scope
Expected Results
- ApplicationSet controller should be able to reconcile and create applications
Actual Results
- ...
Problem Analysis
- <Completed by engineering team as part of the triage/refinement process>
Root Cause
- <What is the root cause of the problem? Or, why is it not a bug?>
Workaround (If Possible)
- <Are there any workarounds we can provide to the customers?>
Fix Approaches
- <If we decide to fix this bug, how will we do it?>
Acceptance Criteria
- ...
Definition of Done
- Code Complete:
- All code has been written, reviewed, and approved.
- Tested:
- Unit tests have been written and passed.
- Ensure code coverage is not reduced with the changes.
- Integration tests have been automated.
- System tests have been conducted, and all critical bugs have been fixed.
- Tested and merged on OpenShift either upstream or downstream on a local build.
- Documentation:
- User documentation or release notes have been written (if applicable).
- Build:
- Code has been successfully built and integrated into the main repository / project.
- Midstream changes (if applicable) are done, reviewed, approved and merged.
- Review:
- Code has been peer-reviewed and meets coding standards.
- All acceptance criteria defined in the user story have been met.
- Tested by reviewer on OpenShift.
- Deployment:
- The feature has been deployed on OpenShift cluster for testing.