Skip to content

[BUG] Issue loading ca-bundle into the openshift-service-ca pod #394

@jparrill

Description

@jparrill

What happened:

Once executed the microshift run 1 pod stays on Crashloopbackoff and other 2 in Creating state:

image

What you expected to happen:

Microshift fully running

How to reproduce it (as minimally and precisely as possible):

  1. Deploy a VM, and follow the quickstart
  2. Compile the binary and run it

Environment:

  • Microshift version (use microshift version):
MicroShift Version: 4.8.0-0.microshift-unknown
Base OKD Version: 4.8.0-0.okd-2021-10-10-030117
  • Hardware configuration: VM x86
  • OS (e.g: cat /etc/os-release):
NAME=Fedora
VERSION="34 (Cloud Edition)"
ID=fedora
VERSION_ID=34
VERSION_CODENAME=""
PLATFORM_ID="platform:f34"
PRETTY_NAME="Fedora 34 (Cloud Edition)"
ANSI_COLOR="0;38;2;60;110;180"
LOGO=fedora-logo-icon
CPE_NAME="cpe:/o:fedoraproject:fedora:34"
HOME_URL="https://fedoraproject.org/"
DOCUMENTATION_URL="https://docs.fedoraproject.org/en-US/fedora/34/system-administrators-guide/"
SUPPORT_URL="https://fedoraproject.org/wiki/Communicating_and_getting_help"
BUG_REPORT_URL="https://bugzilla.redhat.com/"
REDHAT_BUGZILLA_PRODUCT="Fedora"
REDHAT_BUGZILLA_PRODUCT_VERSION=34
REDHAT_SUPPORT_PRODUCT="Fedora"
REDHAT_SUPPORT_PRODUCT_VERSION=34
PRIVACY_POLICY_URL="https://fedoraproject.org/wiki/Legal:PrivacyPolicy"
VARIANT="Cloud Edition"
VARIANT_ID=cloud
  • Kernel (e.g. uname -a):
Linux microshift.acheron.local 5.11.12-300.fc34.x86_64 #1 SMP Wed Apr 7 16:31:13 UTC 2021 x86_64 x86_64 x86_64 GNU/Linux

Relevant Logs

type=AVC msg=audit(1635433963.422:3839): avc:  denied  { read } for  pid=53085 comm="service-ca-oper" name="ca-bundle.crt" dev="vda1" ino=661166 scontext=system_u:system_r:container_t:s0:c476,c599 tcontext=unconfined_u:object_r:var_lib_t:s0 tclass=file permissive=0

Metadata

Metadata

Assignees

No one assigned

    Labels

    kind/bugCategorizes issue or PR as related to a bug.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions