Uploaded image for project: 'OpenShift Bugs'
  1. OpenShift Bugs
  2. OCPBUGS-64830

The namespace created by `oc adm node-image create` contains incorrect PSA labels

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Undefined Undefined
    • None
    • 4.20.z
    • oc / node-image
    • None
    • Quality / Stability / Reliability
    • False
    • Hide

      None

      Show
      None
    • None
    • Moderate
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      Description of problem:

      
      The running `oc adm node-image create` the created namespace contains the restricted PSA label, but the pod needs to run with the escalated privileges. 
      
      /// error
      error: cannot create pod: pods "node-joiner-ts2vl" is forbidden: violates PodSecurity "restricted:latest": allowPrivilegeEscalation != false (container "node-joiner" must set securityContext.allowPrivilegeEscalation=false), unrestricted capabilities (container "node-joiner" must set securityContext.capabilities.drop=["ALL"]), runAsNonRoot != true (pod or container "node-joiner" must set securityContext.runAsNonRoot=true)
      
          

      Version-Release number of selected component (if applicable):

      Openshift Container Platfrom 4.20
      Openshift Container Platfrom 4.21
          

      How reproducible:

      
          

      Steps to Reproduce:

          1.
          2.
          3.
          

      Actual results:

      
          

      Expected results:

      
          

      Additional info:

      
          

              rwsu1@redhat.com Richard Su
              rhn-support-vwalek Vladislav Walek
              Richard Su
              None
              Manoj Hans Manoj Hans
              None
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

                Created:
                Updated: