Uploaded image for project: 'OpenShift Bugs'
  1. OpenShift Bugs
  2. OCPBUGS-74897

Getting the higher priority SCCs after upgrade

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Undefined Undefined
    • None
    • 4.20
    • openshift-apiserver
    • None
    • None
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      Description of problem:

          The customer upgraded the Openshift cluster that is running multicluster-engine from 4.20.3 to 4.20.8. It was running PX-CSI 25.8.1 before the upgrade.
      The upgrade completed but noticed the pods "ironic-proxy" were crashloopbackoff in namespace "openshift-machine-api".
      
      The oc logs were showing these errors:
      [ocpadmin@ocp01-bastion sonya]$ oc logs ironic-proxy-gm5js
      mkdir: cannot create directory '/certs/ca/ironic': Read-only file system
      mktemp: failed to create file via template '/certs/ca/ironic/tls.crt.XXX': No such file or directory
      cp: cannot create regular file '': No such file or directory
      
      We saw these annotations:
      metadata:
        annotations:
          openshift.io/scc: pure-csi-node-plugin-scc
      
      Previously the scc was node-exporter but after pod restarts it changed to pure-csi-node-plugin-scc and also added this in the pod spec:
      readOnlyRootFilesystem: true
      
      Thats the reason for the failure.
      
      Though a patched to the ironic-proxy daemonset and added the below annotation to the template as a workaround works.
      
      openshift.io/required-scc: node-exporterThis will make sure the ironic-proxy pods come up with the correct scc
      
      Customer is still looking for a permanent fix for this to not happened on their environment once patched again.

      Version-Release number of selected component (if applicable):

          

      How reproducible:

          

      Steps to Reproduce:

          1.
          2.
          3.
          

      Actual results:

          

      Expected results:

          

      Additional info:

          

              Unassigned Unassigned
              rhn-support-emagtala Eduardo Magtalas
              None
              None
              Rahul Gangwar Rahul Gangwar
              None
              Votes:
              1 Vote for this issue
              Watchers:
              5 Start watching this issue

                Created:
                Updated: