Uploaded image for project: 'OpenShift Bugs'
  1. OpenShift Bugs
  2. OCPBUGS-1085

Errors running must-gather on 4.12: " is forbidden: violates PodSecurity "restricted:latest"

    • Icon: Bug Bug
    • Resolution: Duplicate
    • Icon: Major Major
    • None
    • 4.12.0
    • oc
    • None
    • Quality / Stability / Reliability
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • None
    • None
    • Rejected
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      Here's what happens when I try to run collect must-gather on OCP4.12

      OCP version: 4.12.0-0.nightly-2022-09-08-114806

      oc adm must-gather --dest-dir=/home/kni/test_artifacts/must-gather.out
      [must-gather ] OUT Using must-gather plug-in image: quay.io/openshift-release-dev/ocp-v4.0-art-dev@sha256:7f2749be2f0435b6e5674e035af81dc8e7f4629fbfa9adf2e62ae2bed0243f53
      When opening a support case, bugzilla, or issue please include the following summary data along with any other requested information:
      ClusterID: fa3a07a1-5471-400a-bdef-6afe3a9f9325
      ClusterVersion: Stable at "4.12.0-0.nightly-2022-09-08-114806"
      ClusterOperators:
      All healthy and stable

      [must-gather ] OUT namespace/openshift-must-gather-8jtvk created
      [must-gather ] OUT clusterrolebinding.rbac.authorization.k8s.io/must-gather-627c9 created
      [must-gather ] OUT clusterrolebinding.rbac.authorization.k8s.io/must-gather-627c9 deleted
      [must-gather ] OUT namespace/openshift-must-gather-8jtvk deleted

      Error running must-gather collection:
      <nil>

      Falling back to `oc adm inspect clusteroperators.v1.config.openshift.io` to collect basic cluster information.
      Gathering data for ns/openshift-config...
      Gathering data for ns/openshift-config-managed...
      Gathering data for ns/openshift-authentication...
      Gathering data for ns/openshift-authentication-operator...
      Gathering data for ns/openshift-ingress...
      Gathering data for ns/openshift-oauth-apiserver...
      Gathering data for ns/openshift-machine-api...
      Gathering data for ns/openshift-cloud-controller-manager-operator...
      Gathering data for ns/openshift-cloud-controller-manager...
      Gathering data for ns/openshift-cloud-credential-operator...
      Gathering data for ns/openshift-config-operator...
      Gathering data for ns/openshift-console-operator...
      Gathering data for ns/openshift-console...
      Gathering data for ns/openshift-cluster-storage-operator...
      Gathering data for ns/openshift-dns-operator...
      Gathering data for ns/openshift-dns...
      Gathering data for ns/openshift-etcd-operator...
      Gathering data for ns/openshift-etcd...
      Gathering data for ns/openshift-image-registry...
      Gathering data for ns/openshift-ingress-operator...
      Gathering data for ns/openshift-ingress-canary...
      Gathering data for ns/openshift-insights...
      Gathering data for ns/openshift-kube-apiserver-operator...
      Gathering data for ns/openshift-kube-apiserver...
      Gathering data for ns/openshift-kube-controller-manager...
      Gathering data for ns/openshift-kube-controller-manager-operator...
      Gathering data for ns/kube-system...
      Gathering data for ns/openshift-kube-scheduler...
      Gathering data for ns/openshift-kube-scheduler-operator...
      Gathering data for ns/openshift-kube-storage-version-migrator...
      Gathering data for ns/openshift-kube-storage-version-migrator-operator...
      Gathering data for ns/openshift-cluster-machine-approver...
      Gathering data for ns/openshift-machine-config-operator...
      Gathering data for ns/openshift-kni-infra...
      Gathering data for ns/openshift-openstack-infra...
      Gathering data for ns/openshift-ovirt-infra...
      Gathering data for ns/openshift-vsphere-infra...
      Gathering data for ns/openshift-nutanix-infra...
      Gathering data for ns/openshift-marketplace...
      Gathering data for ns/openshift-monitoring...
      Gathering data for ns/openshift-user-workload-monitoring...
      Gathering data for ns/openshift-multus...
      Gathering data for ns/openshift-ovn-kubernetes...
      Gathering data for ns/openshift-host-network...
      Gathering data for ns/openshift-network-diagnostics...
      Gathering data for ns/openshift-network-operator...
      Gathering data for ns/openshift-cloud-network-config-controller...
      Gathering data for ns/openshift-cluster-node-tuning-operator...
      Gathering data for ns/openshift-apiserver-operator...
      Gathering data for ns/openshift-apiserver...
      Gathering data for ns/openshift-controller-manager-operator...
      Gathering data for ns/openshift-controller-manager...
      Gathering data for ns/openshift-route-controller-manager...
      Gathering data for ns/openshift-cluster-samples-operator...
      Gathering data for ns/openshift-operator-lifecycle-manager...
      Gathering data for ns/openshift-service-ca-operator...
      Gathering data for ns/openshift-service-ca...
      Gathering data for ns/openshift-cluster-csi-drivers...
      Wrote inspect data to /home/kni/test_artifacts/must-gather.out/inspect.local.4562574244593319483.
      error running backup collection: errors occurred while gathering data:
      [skipping gathering controlplanemachinesets.machine.openshift.io/cluster due to error: a resource cannot be retrieved by name across all namespaces, skipping gathering clusterroles.rbac.authorization.k8s.io/system:registry due to error: clusterroles.rbac.authorization.k8s.io "system:registry" not found, skipping gathering clusterrolebindings.rbac.authorization.k8s.io/registry-registry-role due to error: clusterrolebindings.rbac.authorization.k8s.io "registry-registry-role" not found, skipping gathering secrets/support due to error: secrets "support" not found, skipping gathering endpoints/host-etcd-2 due to error: endpoints "host-etcd-2" not found, skipping gathering sharedconfigmaps.sharedresource.openshift.io due to error: the server doesn't have a resource type "sharedconfigmaps", skipping gathering sharedsecrets.sharedresource.openshift.io due to error: the server doesn't have a resource type "sharedsecrets"]

      Reprinting Cluster State:
      When opening a support case, bugzilla, or issue please include the following summary data along with any other requested information:
      ClusterID: fa3a07a1-5471-400a-bdef-6afe3a9f9325
      ClusterVersion: Stable at "4.12.0-0.nightly-2022-09-08-114806"
      ClusterOperators:
      All healthy and stable

      Error from server (Forbidden): pods "must-gather-9k49v" is forbidden: violates PodSecurity "restricted:latest": allowPrivilegeEscalation != false (containers "gather", "copy" must set securityContext.allowPrivilegeEscalation=false), unrestricted capabilities (containers "gather", "copy" must set securityContext.capabilities.drop=["ALL"]), runAsNonRoot != true (pod or containers "gather", "copy" must set securityContext.runAsNonRoot=true), seccompProfile (pod or containers "gather", "copy" must set securityContext.seccompProfile.type to "RuntimeDefault" or "Localhost")

              lmurthy Latha Sreenivasa Murthy
              achuzhoy@redhat.com Alexander Chuzhoy
              None
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated:
                Resolved: