Uploaded image for project: 'MicroShift'
  1. MicroShift
  2. USHIFT-1631

pod security logs are missing in sos report

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done
    • Icon: Normal Normal
    • openshift-4.14
    • None
    • None
    • None
    • Quality / Stability / Reliability
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • uShift Sprint 241, uShift Sprint 242
    • None
    • None
    • None

      Description of problem:

      The PodSecurityAdmission audit logs are not available in the sos report.  MicroShift is configured to write them the default location: /var/log/kube-apiserver.  The logs can provide critical info for debugging and security audits, and should be included with the sos report.

      Version-Release number of selected component (if applicable):

      4.13,4.14

      How reproducible:

      100%

      Steps to Reproduce:

      1. After starting microshift, run `/var/tmp/sosreport-rhel-92-2023-08-28-ejrrohb-obfuscated.tar.xz`
      2. Decompress and extract the archive
      3. Search for the audit log: `find ./ -name *audit.log*`
      

      Actual results:

      `find` returns no results

      Expected results:

      the path of audit.log is returned

      Additional info:

       

       

              jcope@redhat.com Jon Cope
              jcope@redhat.com Jon Cope
              None
              None
              None
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: