Uploaded image for project: 'OpenShift Bugs'
  1. OpenShift Bugs
  2. OCPBUGS-5409

pod / application start problem on ocp 4.11

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done
    • Icon: Major Major
    • None
    • 4.11.z
    • Containers
    • None
    • Quality / Stability / Reliability
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • None
    • None
    • Rejected
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      Description of problem:

      pod / application start problem on ocp 4.11

      Version-Release number of selected component (if applicable):

       

      How reproducible:

       

      Steps to Reproduce:

      We have installed a new openshift cluster, version 4.11 and we are going to migrate our applications from old cluster to new cluster. Old cluster version is 4.8. DevOps team updated their ci/cd pipeline and if a deployment starts to a project, it  deploys on both clusters. However, pods in new cluster cant start, they get "exec /app/run-java.sh: permission denied" error, while pods on old cluster works properly. Also, tested the same deployment on ocp 4.10, there was no problem. We found that, there are some scc changes in ocp 4.11 (https://access.redhat.com/articles/6973044, https://access.redhat.com/solutions/6975936). However, our applications are java based and does not require any high privilege, we are not assigning any special permission like anyuid etc on old clusters.  we, also, followed the steps described in KB article,https://access.redhat.com/articles/6973044 and created clusterrolebinding / rolebindings for test nothing changed, pods continue to get permission error.
      
      We found that if we change entrypoint in dockerfile from ENTRYPOINT ["/app/run-java.sh"]  to ENTRYPOINT ["/bin/sh","/app/run-java.sh"]  pods starts working normally. We want to understand that what cause this issue?
       

      Actual results:

       

      Expected results:

       

      Additional info:

       

              tsweeney@redhat.com Tom Sweeney
              rhn-support-vismishr Vishvranjan Mishra
              None
              None
              None
              None
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated:
                Resolved: