Uploaded image for project: 'OpenShift Bugs'
  1. OpenShift Bugs
  2. OCPBUGS-60188

UID for some pods in hosted control plane not set correctly

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Duplicate
    • Icon: Normal Normal
    • None
    • 4.20.0
    • HyperShift / ARO
    • Quality / Stability / Reliability
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      Description of problem:

      The following two pods have a UID set to 1001 accross all HostedClusters in Hypershift:
      azure-disk-csi-driver-operator
      azure-file-csi-driver-operator
      
      The following pods don't have a UID set:
      azure-disk-csi-driver-controller
      azure-file-csi-driver-controller
      network-node-identity
      ovnkube-control-plane

      Version-Release number of selected component (if applicable):

          

      How reproducible:

      Create multiple ARO-HCP clusters, check UID from these pods    

      Steps to Reproduce:

          1. create multiple ARO-HCP clusters
          2. check UID from these pods
          3.
          

      Actual results:

      The following two pods have a UID set to 1001 accross all HostedClusters in Hypershift:
      azure-disk-csi-driver-operator
      azure-file-csi-driver-operator
      
      The following pods don't have a UID set:
      azure-disk-csi-driver-controller
      azure-file-csi-driver-controller
      network-node-identity
      ovnkube-control-plane

      Expected results:

          These pods should have a UID set, and be unique across all HostedClusters

      Additional info:

      Test log:
      =========
      $ oc -n clusters-jie-test1 get pods -o json | \
      jq -r '.items[] | select(.metadata.name != "azure-disk-csi-driver-controller" and .metadata.name != "azure-file-csi-driver-controller" and .metadata.name != "azure-disk-csi-driver-operator" and .metadata.name != "azure-file-csi-driver-operator" and .metadata.name != "network-node-identity" and .metadata.name != "ovnkube-control-plane") |
             "\(.metadata.name) runAsUser: \(.spec.securityContext.runAsUser // "N/A")"'
      azure-disk-csi-driver-controller-5d47b97695-bhqzg runAsUser: N/A
      azure-disk-csi-driver-operator-55cf8844bb-bnrd4 runAsUser: 1001
      azure-file-csi-driver-controller-57499d7547-f5zkl runAsUser: N/A
      azure-file-csi-driver-operator-7954997bb8-rzrfw runAsUser: 1001
      capi-provider-79964f9dc8-c5jwn runAsUser: 1001
      catalog-operator-596d68d884-zbqr2 runAsUser: 1001
      certified-operators-catalog-7dd696db96-86w5d runAsUser: 1001
      cloud-controller-manager-azure-7f85f6fc86-gc7xw runAsUser: 1001
      cloud-network-config-controller-b849468d5-9lgzw runAsUser: 1001
      cluster-api-6bb8c7f7f4-pbnrr runAsUser: 1001
      cluster-image-registry-operator-64587d9fd6-p9zfz runAsUser: 1001
      cluster-network-operator-7779b6754f-6hk2k runAsUser: 1001
      cluster-node-tuning-operator-5c86b4f76c-vvsqb runAsUser: 1001
      cluster-policy-controller-74f6dfdbb7-cqgvt runAsUser: 1001
      cluster-storage-operator-769987644d-dv24k runAsUser: 1001
      cluster-version-operator-776dd8687-c5prh runAsUser: 1001
      community-operators-catalog-67c58c7cb-zm94d runAsUser: 1001
      control-plane-operator-699ff84fc8-jt9cc runAsUser: 1001
      control-plane-pki-operator-78f97b5fbf-tsslz runAsUser: 1001
      csi-snapshot-controller-d464b65cb-qh9x8 runAsUser: 1001
      csi-snapshot-controller-operator-6c68f9df75-zddqg runAsUser: 1001
      dns-operator-84c5d9468f-fmm72 runAsUser: 1001
      etcd-0 runAsUser: 1001
      featuregate-generator-frlzw runAsUser: 1001
      hosted-cluster-config-operator-7cf67b467b-pqmlg runAsUser: 1001
      ignition-server-7869b9f5d4-hjqz7 runAsUser: 1001
      ignition-server-proxy-66c5f69ddb-p9s2j runAsUser: 1001
      ingress-operator-7dffb954ff-hl2j4 runAsUser: 1001
      konnectivity-agent-5cfc75d45f-wstnw runAsUser: 1001
      kube-apiserver-544474cdf9-6zrd4 runAsUser: 1001
      kube-controller-manager-8b576df5b-nt476 runAsUser: 1001
      kube-scheduler-85f7d755b-t5fzc runAsUser: 1001
      machine-approver-55f8bdcd49-2j67q runAsUser: 1001
      multus-admission-controller-86755bcb7d-rb8qd runAsUser: 1001
      network-node-identity-fbf57dc54-7rjjw runAsUser: N/A
      oauth-openshift-54bcf85c76-xzc2d runAsUser: 1001
      olm-operator-85cfc5676f-f2dx9 runAsUser: 1001
      openshift-apiserver-58489f689b-kng5k runAsUser: 1001
      openshift-controller-manager-67788b75d8-gjvrg runAsUser: 1001
      openshift-oauth-apiserver-68464dfd7f-mczsv runAsUser: 1001
      openshift-route-controller-manager-55694c8b59-sx49h runAsUser: 1001
      ovnkube-control-plane-57549c68c9-xwjq8 runAsUser: N/A
      packageserver-647c6c8c77-ncqpr runAsUser: 1001
      redhat-marketplace-catalog-7d6cf6d7ff-wfnjh runAsUser: 1001
      redhat-operators-catalog-84b8f99bbb-r7f75 runAsUser: 1001
      jiezhao-mac:hypershift jiezhao$ 
      
      
      $ oc -n clusters-jie-test2 get pods -o json | \
      jq -r '.items[] | select(.metadata.name != "azure-disk-csi-driver-controller" and .metadata.name != "azure-file-csi-driver-controller" and .metadata.name != "azure-disk-csi-driver-operator" and .metadata.name != "azure-file-csi-driver-operator" and .metadata.name != "network-node-identity" and .metadata.name != "ovnkube-control-plane") |
             "\(.metadata.name) runAsUser: \(.spec.securityContext.runAsUser // "N/A")"'
      azure-disk-csi-driver-controller-7db66d4b4-sdwlf runAsUser: N/A
      azure-disk-csi-driver-operator-77994f6b79-jjkzm runAsUser: 1001
      azure-file-csi-driver-controller-8c944bd59-zg245 runAsUser: N/A
      azure-file-csi-driver-operator-6f5d87647c-krsk9 runAsUser: 1001
      capi-provider-5c44749cfd-4bm4s runAsUser: 1002
      catalog-operator-98698ffc4-pk4vh runAsUser: 1002
      certified-operators-catalog-78c58c47f-c4qzc runAsUser: 1002
      cloud-controller-manager-azure-5f6db985c4-q8j22 runAsUser: 1002
      cloud-network-config-controller-6cb7d9db8-bjnnh runAsUser: 1002
      cluster-api-6cbb869b6d-5xgfd runAsUser: 1002
      cluster-image-registry-operator-57c747c747-h9zfg runAsUser: 1002
      cluster-network-operator-76b76466d-sjsdg runAsUser: 1002
      cluster-node-tuning-operator-7bdc8df9b5-2w545 runAsUser: 1002
      cluster-policy-controller-6d95b897fd-8ghfg runAsUser: 1002
      cluster-storage-operator-7f7885d6f7-4h5vs runAsUser: 1002
      cluster-version-operator-56fcfc74ff-s9sdq runAsUser: 1002
      community-operators-catalog-9f76f8dcf-8tsg5 runAsUser: 1002
      control-plane-operator-cd8fb748d-2pn4w runAsUser: 1002
      control-plane-pki-operator-fcfc8bdc5-2rgc6 runAsUser: 1002
      csi-snapshot-controller-6d5584f759-ptrlg runAsUser: 1002
      csi-snapshot-controller-operator-7d5487c9d7-cvg2j runAsUser: 1002
      dns-operator-59ff54b4b6-zl7gp runAsUser: 1002
      etcd-0 runAsUser: 1002
      featuregate-generator-n5hkh runAsUser: 1002
      hosted-cluster-config-operator-78b6cd5bd9-rqqwp runAsUser: 1002
      ignition-server-74c8cd5cd4-7zp2x runAsUser: 1002
      ignition-server-proxy-6df88c658f-snk4k runAsUser: 1002
      ingress-operator-778dffff48-h8p6d runAsUser: 1002
      konnectivity-agent-7fc69c6ddb-ccssc runAsUser: 1002
      kube-apiserver-785dfb8657-xb9jj runAsUser: 1002
      kube-controller-manager-85c6c6cdbf-xr94p runAsUser: 1002
      kube-scheduler-94b96c55-5s5ml runAsUser: 1002
      machine-approver-78c6cc65f9-jjlnr runAsUser: 1002
      multus-admission-controller-64c8d9fb64-9lqz7 runAsUser: 1002
      network-node-identity-797c4d4f66-blb4w runAsUser: N/A
      oauth-openshift-67c984bc84-fhtjb runAsUser: 1002
      olm-operator-5587c9477b-vh4m6 runAsUser: 1002
      openshift-apiserver-5b9cdc9457-h79nm runAsUser: 1002
      openshift-controller-manager-68d854c45f-cxxsf runAsUser: 1002
      openshift-oauth-apiserver-8658d44c88-75gk2 runAsUser: 1002
      openshift-route-controller-manager-847dc7947-5j6bb runAsUser: 1002
      ovnkube-control-plane-69d75c9cb9-q78m6 runAsUser: N/A
      packageserver-5fc8db5c66-ljdqv runAsUser: 1002
      redhat-marketplace-catalog-6cdd6497f6-kzd6j runAsUser: 1002
      redhat-operators-catalog-7b88b4db7-57crm runAsUser: 1002
      
      
      $ oc -n clusters-jie-test3 get pods -o json | \
      jq -r '.items[] | select(.metadata.name != "azure-disk-csi-driver-controller" and .metadata.name != "azure-file-csi-driver-controller" and .metadata.name != "azure-disk-csi-driver-operator" and .metadata.name != "azure-file-csi-driver-operator" and .metadata.name != "network-node-identity" and .metadata.name != "ovnkube-control-plane") |
             "\(.metadata.name) runAsUser: \(.spec.securityContext.runAsUser // "N/A")"'
      azure-disk-csi-driver-controller-75f54b8544-8sd2k runAsUser: N/A
      azure-disk-csi-driver-operator-5d8bf94b4-5s4zf runAsUser: 1001
      azure-file-csi-driver-controller-6bfc9cb785-hd9t7 runAsUser: N/A
      azure-file-csi-driver-operator-7c57f66b66-xwl7g runAsUser: 1001
      capi-provider-bcc49bccd-fsrw8 runAsUser: 1003
      catalog-operator-5fb77c8f9f-g758j runAsUser: 1003
      certified-operators-catalog-6cfb6f9bb-8kmj6 runAsUser: 1003
      cloud-controller-manager-azure-d974dd74f-lg8hl runAsUser: 1003
      cloud-network-config-controller-779946d57f-qrwl8 runAsUser: 1003
      cluster-api-d978f9754-885f9 runAsUser: 1003
      cluster-image-registry-operator-78d7759dcc-bdhg5 runAsUser: 1003
      cluster-network-operator-54bc774854-562w2 runAsUser: 1003
      cluster-node-tuning-operator-7bff96dc67-2kd6b runAsUser: 1003
      cluster-policy-controller-58c54bf54-945xb runAsUser: 1003
      cluster-storage-operator-5d474fddcd-h2q7m runAsUser: 1003
      cluster-version-operator-6897df7fcc-7nc7d runAsUser: 1003
      community-operators-catalog-5947b67874-5zmkd runAsUser: 1003
      control-plane-operator-7fd96c9d58-96pfh runAsUser: 1003
      control-plane-pki-operator-56f7f6f869-5xwmc runAsUser: 1003
      csi-snapshot-controller-7bdd6f8d98-g6mk5 runAsUser: 1003
      csi-snapshot-controller-operator-86db8cf6bc-bb9vs runAsUser: 1003
      dns-operator-7845997d65-x529h runAsUser: 1003
      etcd-0 runAsUser: 1003
      featuregate-generator-nhjm9 runAsUser: 1003
      hosted-cluster-config-operator-768b96697c-wnj2k runAsUser: 1003
      ignition-server-85bb47ff4f-z52r7 runAsUser: 1003
      ignition-server-proxy-856bc56659-p29k2 runAsUser: 1003
      ingress-operator-bdbcbc4d4-k292t runAsUser: 1003
      konnectivity-agent-56dbf7d955-jfdkh runAsUser: 1003
      kube-apiserver-66d6964dd7-xdkjp runAsUser: 1003
      kube-controller-manager-6cb98d8b79-t5dls runAsUser: 1003
      kube-scheduler-6b4cb5d869-x7fs9 runAsUser: 1003
      machine-approver-6469d858d9-cbls9 runAsUser: 1003
      multus-admission-controller-5b4f485998-bpbqn runAsUser: 1003
      network-node-identity-7f67b56994-xs7k8 runAsUser: N/A
      oauth-openshift-7c46bb55c6-rdkd7 runAsUser: 1003
      olm-operator-5ccd445d5b-v4kd9 runAsUser: 1003
      openshift-apiserver-fc9488bfc-j2m76 runAsUser: 1003
      openshift-controller-manager-75dbc99476-g8526 runAsUser: 1003
      openshift-oauth-apiserver-764c5f9997-nsf72 runAsUser: 1003
      openshift-route-controller-manager-66c5c665cf-kpp2d runAsUser: 1003
      ovnkube-control-plane-7d8f64f59f-9sjgl runAsUser: N/A
      packageserver-6cc57676b5-7s894 runAsUser: 1003
      redhat-marketplace-catalog-c5944d57-xjkwz runAsUser: 1003
      redhat-operators-catalog-7958f8dc68-tn8d4 runAsUser: 1003
      jiezhao-mac:hypershift jiezhao$ 

              rh-ee-brcox Bryan Cox
              rhn-support-jiezhao Jie Zhao
              None
              None
              Jie Zhao Jie Zhao
              None
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Created:
                Updated:
                Resolved: