Uploaded image for project: 'Knative Serving'
  1. Knative Serving
  2. SRVKS-823

User "system:serviceaccount:openshift-serverless:knative-openshift-ingress" cannot create resource "events" in API group "" in the namespace "foo"' (will not retry!)

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done
    • Icon: Undefined Undefined
    • 1.18.0, 1.19.0
    • 1.17.0, 1.18.0
    • None
    • False
    • False

      knative-openshift-ingress logs errors like

      E0929 12:53:42.136498       1 event.go:264] Server rejected event '&v1.Event{TypeMeta:v1.TypeMeta{Kind:"", APIVersion:""}, ObjectMeta:v1.ObjectMeta{Name:"event-display-5.16a94c1bc9f6c312", GenerateName:"", Namespace:"sink-binding-0", SelfLink:"", UID:"", ResourceVersion:"", Generation:0, CreationTimestamp:v1.Time{Time:time.Time{wall:0x0, ext:0, loc:(*time.Location)(nil)}}, DeletionTimestamp:(*v1.Time)(nil), DeletionGracePeriodSeconds:(*int64)(nil), Labels:map[string]string(nil), Annotations:map[string]string(nil), OwnerReferences:[]v1.OwnerReference(nil), Finalizers:[]string(nil), ClusterName:"", ManagedFields:[]v1.ManagedFieldsEntry(nil)}, InvolvedObject:v1.ObjectReference{Kind:"Ingress", Namespace:"sink-binding-0", Name:"event-display-5", UID:"7a2449b5-62be-4def-9106-11384e2f37ca", APIVersion:"networking.internal.knative.dev/v1alpha1", ResourceVersion:"348426", FieldPath:""}, Reason:"FinalizerUpdateFailed", Message:"Failed to update finalizers for \"event-display-5\": ingresses.networking.internal.knative.dev \"event-display-5\" not found", Source:v1.EventSource{Component:"ingress-controller", Host:""}, FirstTimestamp:v1.Time{Time:time.Time{wall:0xc04d36558807e712, ext:5602614421241, loc:(*time.Location)(0x2d71d00)}}, LastTimestamp:v1.Time{Time:time.Time{wall:0xc04d36558807e712, ext:5602614421241, loc:(*time.Location)(0x2d71d00)}}, Count:1, Type:"Warning", EventTime:v1.MicroTime{Time:time.Time{wall:0x0, ext:0, loc:(*time.Location)(nil)}}, Series:(*v1.EventSeries)(nil), Action:"", Related:(*v1.ObjectReference)(nil), ReportingController:"", ReportingInstance:""}': 'events is forbidden: User "system:serviceaccount:openshift-serverless:knative-openshift-ingress" cannot create resource "events" in API group "" in the namespace "sink-binding-0"' (will not retry!)
      

      so apparently "system:serviceaccount:openshift-serverless:knative-openshift-ingress" lack rolebinding to create events in ksvcs' namespaces.

              markusthoemmes Markus Thömmes (Inactive)
              maschmid@redhat.com Marek Schmidt
              Marek Schmidt Marek Schmidt
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Created:
                Updated:
                Resolved: