Uploaded image for project: 'Hybrid Application Console'
  1. Hybrid Application Console
  2. HAC-4273

[ROSA Hypershift] "OIDC and operator roles" cluster installation step is waiting state when no operator roles created prior to installation.

XMLWordPrintable

      Description of problem:

      The ROSA hypershift cluster installation initiated from UI is stuck with waiting state on the "OIDC and operator roles" step. This is because the user did not run the `rosa create operator role` cli command shown in the "Cluster roles and policies" step. 

      If this is a mandatory requirement i.e create the operator roles prior to start of the installation, we should need to get an acknowledgment (probably  Cluster roles and policies step) at from user that operator roles are created. In the installation step, the waiting state should be changed to action required with set of operator role commands.
      How reproducible:

       Always

      Steps to reproduce:

      1. Launch OCM UI Staging.
      2. Open ROSA wizard and select control plane type as "Hosted"
      3. Proceed to next steps by providing all required values in each step.
      4. Reach "Cluster roles and policies" step.
      5. Choose config id and operator role prefix.( Do not run suggested operator role creation command).
      6. Click "Next" step and click "Create cluster".
      7. View the cluster installation.

      Actual results:

      ROSA hypershift installation step "OIDC and operator roles" stuck in waiting state with no useful information to the user what was going wrong.

      Expected results:

      ROSA hypershift installation should be successful and if no operator roles found, it should create respective roles automatically during installation. It should not block the installation process.

      If creating operator roles manually is a requirement for ROSA Hypershift then following improvements are suggested.

      1. Introduce  an acknowledgment (probably  Cluster roles and policies step) from user that operator roles are created (to make sure they  are notified).
      2. In the installation step, the waiting state should be changed to action required with set of operator role commands.

       

      Acceptance Criteria:

      • The text in the Action Required popup for HCP clusters should read:

      Action required: Creaete OIDC and operator roles

      Your cluster will procceed to ready state only after the operator roles and OIDC provier are created.

      To create operator-roles, run the following command:

       rosa create operator-roles --hosted-cp --prefix "grergr-c8y6" --oidc-config-id "22phvja6kkki8f7h8mmk46a7j2h26uk1"    

       To create an oidc provider, run the following command:

      rosa create oidc-provider --oidc-config-id "22phvja6kkki8f7h8mmk46a7j2h26uk1" 

      Tech Notes:

      There seems to be two scenerios in which HCP cluster will be stuck at 'Waiting':

      1. If missing oidc-provider roles for the selected oidc-config, or...
      1. User failed to run the rosa cli command to create the operator roles

       

      Other Options/Questions

      • What does the CLI do in this case?  Answer: CLI doesn't let proceed forward without a ODIC provider and the operator roles
      • Can HCP cluster creation could continue without OIDC/op-roles?  Answer:  No, cannot
      • Follow up:
        • Would be great if CS backend indicated what it was 'waiting...' on (roles or OIDC provider)
        • Need CS backend to validate if OIDC config/provider and Operator roles exist before moving off of `Step 5:  OIDC config and operator roles`

       

        1. [HAC-4273] [ROSA Hypershift] _OIDC and operator roles_ cluster installation step is waiting state wh.png
          43 kB
          David Taylor
        2. action_required_link.png
          28 kB
          David Taylor
        3. dt-rosa-manual-Red-Hat-OpenShift-Cluster-Manager.png
          46 kB
          David Taylor
        4. HCP Action Required - Google Slides.png
          89 kB
          David Taylor
        5. image-2023-06-19-17-41-21-861.png
          100 kB
          Jayakrishnan Mekkattillam
        6. image-2023-07-18-18-07-05-240.png
          354 kB
          Thi Le
        7. image-2023-07-18-18-08-38-246.png
          62 kB
          Thi Le
        8. image-2023-08-03-15-02-27-104.png
          46 kB
          David Taylor
        9. oidc_now.png
          108 kB
          David Taylor
        10. oidc-later.png
          127 kB
          David Taylor

            dtaylor@redhat.com David Taylor
            jmekkatt@redhat.com Jayakrishnan Mekkattillam
            Jayakrishnan Mekkattillam Jayakrishnan Mekkattillam
            Votes:
            0 Vote for this issue
            Watchers:
            6 Start watching this issue

              Created:
              Updated:
              Resolved: