-
Bug
-
Resolution: Unresolved
-
Normal
-
None
-
4.17.0, 4.18.0
This is a clone of issue OCPBUGS-39340. The following is the description of the original issue:
—
Description of problem:
After successful installation IPI or UPI cluster using minimum permissions, when destroying the cluster, it keeps telling error "failed to list target tcp proxies: googleapi: Error 403: Required 'compute.regionTargetTcpProxies.list' permission" unexpectedly.
Version-Release number of selected component (if applicable):
4.17.0-0.nightly-2024-09-01-175607
How reproducible:
Always
Steps to Reproduce:
1. try IPI or UPI installation using minimum permissions, and make sure it succeeds 2. destroy the cluster using the same GCP credentials
Actual results:
It keeps telling below errors until timeout. 08-27 14:51:40.508 level=debug msg=Target TCP Proxies: failed to list target tcp proxies: googleapi: Error 403: Required 'compute.regionTargetTcpProxies.list' permission for 'projects/openshift-qe', forbidden ...output omitted... 08-27 15:08:18.801 level=debug msg=Target TCP Proxies: failed to list target tcp proxies: googleapi: Error 403: Required 'compute.regionTargetTcpProxies.list' permission for 'projects/openshift-qe', forbidden
Expected results:
It should not try to list regional target tcp proxies, because CAPI installation only creates global target tcp proxy. And the service account given to installer already has the required compute.targetTcpProxies permissions (see [1] and [2]).
Additional info:
FYI the latest IPI PROW CI test was about 19 days ago, where no such issue, see https://qe-private-deck-ci.apps.ci.l2s4.p1.openshiftapps.com/view/gs/qe-private-deck/logs/periodic-ci-openshift-openshift-tests-private-release-4.17-amd64-nightly-gcp-ipi-mini-perm-custom-type-f28/1823483536926052352 Required GCP permissions for installer-provisioned infrastructure https://docs.openshift.com/container-platform/4.16/installing/installing_gcp/installing-gcp-account.html#minimum-required-permissions-ipi-gcp_installing-gcp-account Required GCP permissions for user-provisioned infrastructure https://docs.openshift.com/container-platform/4.16/installing/installing_gcp/installing-gcp-user-infra.html#minimum-required-permissions-upi-gcp_installing-gcp-user-infra
- clones
-
OCPBUGS-39340 [GCP] destroying a cluster of IPI/UPI minimum permissions got error "Required 'compute.regionTargetTcpProxies.list' permission"
- Verified
- is blocked by
-
OCPBUGS-39340 [GCP] destroying a cluster of IPI/UPI minimum permissions got error "Required 'compute.regionTargetTcpProxies.list' permission"
- Verified
- links to