Uploaded image for project: 'OpenShift Bugs'
  1. OpenShift Bugs
  2. OCPBUGS-50995

Default service account able to query thanos in clusters with long upgrade history

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Not a Bug
    • Icon: Major Major
    • None
    • 4.8.z, 4.16
    • Monitoring
    • None
    • Quality / Stability / Reliability
    • False
    • Hide

      None

      Show
      None
    • None
    • Moderate
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      Description of problem:

      Default service account able to query thanos in clusters with long upgrade history - example customers cluster upgraded from 4.8.23 -> 4.16.16    

      Version-Release number of selected component (if applicable):

          

      How reproducible:

      Witnessed on a customer call - TAM is installing a 4.8 cluster to attempt to replicate    

      Steps to Reproduce:

      Deploy cluster at 4.8.23  
      upgrade to 4.16.16 
      
      Mount default service account into a pod and query the thanos endpoint: 
      using instructions from this KCS: https://access.redhat.com/solutions/7080873 
      
      Do not create the cluster role binding.      

      Actual results:

      in cluster upgraded from 4.8 we can query metrics  

      Expected results:

      as in fresh install of 4.16 we cannot query metrics without the clusterrole binding    

      Additional info:

          

              rh-ee-amrini Ayoub Mrini
              rhn-support-nigsmith Nigel Smith
              None
              None
              Junqi Zhao Junqi Zhao
              None
              Votes:
              0 Vote for this issue
              Watchers:
              7 Start watching this issue

                Created:
                Updated:
                Resolved: