Uploaded image for project: 'OpenShift Bugs'
  1. OpenShift Bugs
  2. OCPBUGS-44760

OLM doesn't support for user defined ServiceAccount for OperatorGroup.

XMLWordPrintable

    • Critical
    • No
    • Bulbasaur OLM Sprint 262
    • 1
    • False
    • Hide

      None

      Show
      None
    • Hide
      Beyond Kubernetes 1.22, the service account token secret is not automatically, created. Therefore, when OLM is not able to find the service account token secret, it should request one from the k8s api server.

      Ref: https://kubernetes.io/docs/reference/access-authn-authz/service-accounts-admin/#manual-secret-management-for-serviceaccounts
      Show
      Beyond Kubernetes 1.22, the service account token secret is not automatically, created. Therefore, when OLM is not able to find the service account token secret, it should request one from the k8s api server. Ref: https://kubernetes.io/docs/reference/access-authn-authz/service-accounts-admin/#manual-secret-management-for-serviceaccounts
    • Bug Fix
    • In Progress

      This is a clone of issue OCPBUGS-42360. The following is the description of the original issue:

      Description of problem:

          due to https://issues.redhat.com/browse/API-1644, no token was generate for sa automatically, it is needed to add one step to create the token manually. 

      Version-Release number of selected component (if applicable):

      After creating a new service account, one step should be added to create a long-lived API token

      How reproducible:

          always

      Steps to Reproduce:

      secret yaml file exmaple:
      
      xzha@xzha1-mac OCP-24771 % cat secret.yaml 
      apiVersion: v1
      kind: Secret
      metadata:
        name: scoped
        annotations:
          kubernetes.io/service-account.name: scoped
      type: kubernetes.io/service-account-token

      Actual results:

        

      Expected results:

         

      Additional info:

        

              rh-ee-jkeister Jordan Keister
              openshift-crt-jira-prow OpenShift Prow Bot
              Xia Zhao Xia Zhao
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

                Created:
                Updated: