Uploaded image for project: 'OpenShift Service Mesh'
  1. OpenShift Service Mesh
  2. OSSM-6696

istio-cni-node logs errors due to missing permissions for pods at cluster scope

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done
    • Icon: Blocker Blocker
    • None
    • OSSM 2.6.0
    • Customer Impact, Maistra
    • None

      2024-06-19T08:25:04.529398Z	info	Start a UDS server for CNI plugin logs
      2024-06-19T08:25:04.529604Z	info	repair	Start CNI race condition repair.
      2024-06-19T08:25:04.530923Z	info	cluster "" kube client started
      2024-06-19T08:25:04.540517Z	info	klog	k8s.io/client-go@v0.28.3/tools/cache/reflector.go:229: failed to list *v1.Pod: pods is forbidden: User "system:serviceaccount:istio-operator:ossm-cni" cannot list resource "pods" in API group "" at the cluster scope
      2024-06-19T08:25:04.540552Z	error	watch error in cluster : failed to list *v1.Pod: pods is forbidden: User "system:serviceaccount:istio-operator:ossm-cni" cannot list resource "pods" in API group "" at the cluster scope
      2024-06-19T08:25:05.517537Z	info	klog	k8s.io/client-go@v0.28.3/tools/cache/reflector.go:229: failed to list *v1.Pod: pods is forbidden: User "system:serviceaccount:istio-operator:ossm-cni" cannot list resource "pods" in API group "" at the cluster scope
      2024-06-19T08:25:05.517642Z	error	watch error in cluster : failed to list *v1.Pod: pods is forbidden: User "system:serviceaccount:istio-operator:ossm-cni" cannot list resource "pods" in API group "" at the cluster scope
      2024-06-19T08:25:07.302274Z	info	klog	k8s.io/client-go@v0.28.3/tools/cache/reflector.go:229: failed to list *v1.Pod: pods is forbidden: User "system:serviceaccount:istio-operator:ossm-cni" cannot list resource "pods" in API group "" at the cluster scope
      2024-06-19T08:25:07.302306Z	error	watch error in cluster : failed to list *v1.Pod: pods is forbidden: User "system:serviceaccount:istio-operator:ossm-cni" cannot list resource "pods" in API group "" at the cluster scope
      2024-06-19T08:25:08.993926Z	info	waiting for sync...	name=repair controller attempt=50 time=4.462966788s
      

            jewertow@redhat.com Jacek Ewertowski
            jewertow@redhat.com Jacek Ewertowski
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated:
              Resolved: