-
Bug
-
Resolution: Done-Errata
-
Normal
-
None
-
4.15
-
None
-
Moderate
-
No
-
Rejected
-
False
-
In secrets-store-csi-driver operator, it reports the permission missing:
W1201 02:02:27.901026 1 reflector.go:535] k8s.io/client-go@v0.28.4/tools/cache/reflector.go:229: failed to list *v1.APIServer: apiservers.config.openshift.io is forbidden: User "system:serviceaccount:openshift-cluster-csi-drivers:secrets-store-csi-driver-operator" cannot list resource "apiservers" in API group "config.openshift.io" at the cluster scope E1201 02:02:27.901057 1 reflector.go:147] k8s.io/client-go@v0.28.4/tools/cache/reflector.go:229: Failed to watch *v1.APIServer: failed to list *v1.APIServer: apiservers.config.openshift.io is forbidden: User "system:serviceaccount:openshift-cluster-csi-drivers:secrets-store-csi-driver-operator" cannot list resource "apiservers" in API group "config.openshift.io" at the cluster scope
And I have a question, so all the ClusterCSIDriver should have the permission even they might not need to talk to apiservers?
- links to
-
RHSA-2023:7198 OpenShift Container Platform 4.15 security update