-
Bug
-
Resolution: Unresolved
-
Critical
-
None
-
4.12.0
-
Quality / Stability / Reliability
-
False
-
-
None
-
Critical
-
None
-
None
-
None
-
Rejected
-
None
-
None
-
None
-
None
-
None
-
None
-
None
-
None
Description of problem:
setup sriov 4.12 operator, the sriov config daemon pod cannot be ready due to 83s Warning FailedCreate daemonset/sriov-network-config-daemon (combined from similar events): Error creating: pods "sriov-network-config-daemon-r2985" is forbidden: violates PodSecurity "restricted:latest": host namespaces (hostNetwork=true, hostPID=true), privileged (containers "sriov-cni", "sriov-infiniband-cni", "sriov-network-config-daemon" must not set securityContext.privileged=true), allowPrivilegeEscalation != false (containers "sriov-cni", "sriov-infiniband-cni", "sriov-network-config-daemon" must set securityContext.allowPrivilegeEscalation=false), unrestricted capabilities (containers "sriov-cni", "sriov-infiniband-cni", "sriov-network-config-daemon" must set securityContext.capabilities.drop=["ALL"]), restricted volume types (volumes "host", "cnibin" use restricted volume type "hostPath"), runAsNonRoot != true (pod or containers "sriov-cni", "sriov-infiniband-cni", "sriov-network-config-daemon" must set securityContext.runAsNonRoot=true), seccompProfile (pod or containers "sriov-cni", "sriov-infiniband-cni", "sriov-network-config-daemon" must set securityContext.seccompProfile.type to "RuntimeDefault" or "Localhost") # oc get ds -n openshift-sriov-network-operator NAME DESIRED CURRENT READY UP-TO-DATE AVAILABLE NODE SELECTOR AGE network-resources-injector 3 3 3 3 3 beta.kubernetes.io/os=linux 13h operator-webhook 3 3 3 3 3 beta.kubernetes.io/os=linux 13h sriov-network-config-daemon 0 0 0 0 0 beta.kubernetes.io/os=linux,node-role.kubernetes.io/worker= 13h
Version-Release number of selected component (if applicable):
4.12.0-0.nightly-2022-09-07-032607 4.12.0-202209071228
How reproducible:
always
Steps to Reproduce:
1. setup 4.12 cluster 2. setup sriov operator 3.
Actual results:
sriov config daemon pods cannot be ready
Expected results:
sriov config daemon pods can be ready
Additional info:
- is cloned by
-
OCPBUGS-2126 sriov config daemon pod crash
-
- Closed
-