Patch RBAC roles weren’t created correctly in production most likely after merging and pushing to prod this PR:
https://github.com/RedHatInsights/rbac-config/pull/338
Related MR:
https://gitlab.cee.redhat.com/service/app-interface/-/merge_requests/51816
--
it looks that this change was seeded on 23 Nov and MR was merged on 15 Nov - according logs in kibana:
Added new permissions:
https://kibana.apps.crcp01ue1.o9m8.p1.openshiftapps.com/app/kibana#/discover?_g=(filters:!(),refreshInterval:(pause:!t,value:0),time:(from:now-13d,to:now))&_a=(columns:!(_source),filters:!(),index:'43c5fed0-d5ce-11ea-b58c-a7c95afd7a5d',interval:auto,query:(language:kuery,query:'@message:%20%22Created%20permission%22'),sort:!())
Added new role Patch Viewer:
https://kibana.apps.crcp01ue1.o9m8.p1.openshiftapps.com/app/kibana#/discover?_g=(filters:!(),refreshInterval:(pause:!t,value:0),time:(from:now-13d,to:now))&_a=(columns:!(_source),filters:!(),index:'43c5fed0-d5ce-11ea-b58c-a7c95afd7a5d',interval:auto,query:(language:kuery,query:'@message:%20%22Created%20system%20role%22'),sort:!())
Patch administrator Updated:
https://kibana.apps.crcp01ue1.o9m8.p1.openshiftapps.com/app/kibana#/discover?_g=(filters:!(),refreshInterval:(pause:!t,value:0),time:(from:now-13d,to:now))&_a=(columns:!(_source),filters:!(),index:'43c5fed0-d5ce-11ea-b58c-a7c95afd7a5d',interval:auto,query:(language:kuery,query:'@message:%20%22Updated%20system%20role%22'),sort:!())
Logs did not give us that those permission were deleted.
Suggested solution is to run seed process again by version in rbac config of mentioned roles.