-
Bug
-
Resolution: Done-Errata
-
Normal
-
4.12.z, 4.11.z, 4.10.z
-
None
-
Moderate
-
No
-
SDN Sprint 234, SDN Sprint 235, SDN Sprint 236
-
3
-
False
-
-
N/A
-
Release Note Not Required
Description of problem:
`cluster-reader` ClusterRole should have ["get", "list", "watch"] permissions for a number of privileged CRs, but lacks them for the API Group "k8s.ovn.org", which includes CRs such as EgressFirewalls, EgressIPs, etc.
Version-Release number of selected component (if applicable):
OCP 4.10 - 4.12 OVN
How reproducible:
Always
Steps to Reproduce:
1. Create a cluster with OVN components, e.g. EgressFirewall 2. Check permissions of ClusterRole `cluster-reader`
Actual results:
No permissions for OVN resources
Expected results:
Get, list, and watch verb permissions for OVN resources
Additional info:
Looks like a similar bug was opened for "network-attachment-definitions" in OCPBUGS-6959 (whose closure is being contested).
- blocks
-
OCPBUGS-12854 `cluster-reader` role cannot access "k8s.ovn.org" API Group resources
- Closed
- is cloned by
-
OCPBUGS-12854 `cluster-reader` role cannot access "k8s.ovn.org" API Group resources
- Closed
- is related to
-
OCPBUGS-35387 Add permissions to the view default role for network CRDs
- New
- links to
-
RHEA-2023:5006 rpm
(1 links to)