Uploaded image for project: 'OpenShift Bugs'
  1. OpenShift Bugs
  2. OCPBUGS-38689

[gcp] uninstalling failed to delete k8s firewall-rules for a Shared VPC installation using minimum permissions

XMLWordPrintable

    • Important
    • Yes
    • Rejected
    • False
    • Hide

      None

      Show
      None
    • Hide
      When installing OpenShift cluster into GCP shared VPC using the minimum permissions, and without specifying controlPlane.platform.gcp.serviceAccount in install-config, installation can succeed along with k8s firewall-rules being created in the shared VPC, but destroying the cluster will fail to delete these k8s firewall-rules due to lack of permissions in the host project.
      Show
      When installing OpenShift cluster into GCP shared VPC using the minimum permissions, and without specifying controlPlane.platform.gcp.serviceAccount in install-config, installation can succeed along with k8s firewall-rules being created in the shared VPC, but destroying the cluster will fail to delete these k8s firewall-rules due to lack of permissions in the host project.
    • Known Issue
    • In Progress

      Description of problem:

      Uninstalling failed to delete k8s firewall-rules for a Shared VPC installation using minimum permissions.

      Version-Release number of selected component (if applicable):

      4.18.0-0.nightly-2024-08-19-002129

      How reproducible:

      Always

      Steps to Reproduce:

      1. "create install-config", and then insert the interested settings (see [1])
      2. activate the service account having the minimum required permissions for Shared VPC installation (see [2])
      3. "create cluster" and make sure it succeed (see [3])
      4. "destroy cluster" (see [4])     

      Actual results:

      "destroy cluster" keeps telling warnings on lack of permissions deleting k8s firewall-rules in the host project

      Expected results:

      "destroy cluster" should not complain about lack of permissions deleting k8s firewall-rules in the host project    

      Additional info:

      FYI https://issues.redhat.com/browse/OCPBUGS-38152?focusedId=25382865&page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel#comment-25382865
      

              rh-ee-bbarbach Brent Barbachem
              rhn-support-jiwei Jianli Wei
              Jianli Wei Jianli Wei
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated: