-
Bug
-
Resolution: Done-Errata
-
Normal
-
4.14.0, 4.15.0
-
Moderate
-
No
-
Rejected
-
False
-
Description of problem:
Role assignment for Azure AD Workload Identity performed by ccoctl does not provide an option to scope role assignments to a resource group containing customer vnet in a byo vnet installation workflow. https://docs.openshift.com/container-platform/4.13/installing/installing_azure/installing-azure-vnet.html
Version-Release number of selected component (if applicable):
4.14.0
How reproducible:
100%
Steps to Reproduce:
1. Create Azure resource group and vnet for OpenShift within that resource group. 2. Create Azure AD Workload Identity infrastructure with ccoctl. 3. Follow steps to configure existing vnet for installation setting networkResourceGroupName within the install config. 4. Attempt cluster installation.
Actual results:
Cluster installation fails.
Expected results:
Cluster installation succeeds.
Additional info:
ccoctl must be extended to accept a parameter specifying the network resource group name and scope relevant component role assignments to the network resource group in addition to the installation resource group.
- blocks
-
OCPBUGS-19865 Azure AD Workload Identity does not work with bring your own vnet
- Closed
-
CCO-380 CI Integration-Azure Managed Identity (Workload Identity) Support
- Closed
- is cloned by
-
OCPBUGS-19865 Azure AD Workload Identity does not work with bring your own vnet
- Closed
- is duplicated by
-
OCPBUGS-19047 When creating an Azure Workload Identity cluster on an existing vnet, the creation failed due to permission errors.
- Closed
- links to
-
RHEA-2023:7198 rpm