Uploaded image for project: 'OpenShift Bugs'
  1. OpenShift Bugs
  2. OCPBUGS-31861

AWS privileges required by hive operator for OCP cluster build

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Critical Critical
    • None
    • 4.14.z
    • Documentation
    • Important
    • False
    • Hide

      None

      Show
      None

      Description of problem:

      What are the list of AWS credentials/privileges required for Cluster build using Hive.    
      - The customer use Hive Operator to build new OpenShift clusters at scale. But their Cloud Services team recently introduced new AWS SCP policies which caused the cluster builds to fail.  
      ~~~
      msg=Consuming Bootstrap Ignition Config from target directory\nlevel=info msg=Credentials loaded from default AWS environment variables\nlevel=warning msg=Action not allowed with tested creds action=iam:CreateUser\nlevel=warning msg=Tested creds not able to perform all requested actions\nlevel=info msg=Creating infrastructure resources...\nlevel=info msg=Waiting up to 20m0s (until 12:56PM UTC) for the Kubernetes API at https://api.xxx.xxx.xxx.xxx.xxx.xxx:6443.
      ~~~
       
      - After further investigation, they noticed that before actually building a cluster, Hive Operator is trying to simulate with AWS if it has all the right privileges to successfully build it. And want to know the list of all the AWS privileges which are required by Hive Operator to build a cluster so that their Cloud Services team can whitelist all the privileges alongside with the simulator ones. 

            ocp-docs-bot OCP DocsBot
            rhn-support-cchouhan Chandan Chouhan
            Votes:
            0 Vote for this issue
            Watchers:
            4 Start watching this issue

              Created:
              Updated: