Skip to content

Fix set blockOwnerDeletion failures for OwnerReferencesPermissionEnforcement enabled clusters - #797

Merged
diviner524 merged 1 commit into
GoogleCloudPlatform:masterfrom
kaovilai:issue434
Apr 10, 2023
Merged

diviner524 merged 1 commit into
GoogleCloudPlatform:masterfrom
kaovilai:issue434

Conversation

@kaovilai

@kaovilai kaovilai commented Mar 31, 2023 •

Copy link
Copy Markdown
Contributor

Fixes #434

If OwnerReferencesPermissionEnforcement admission controller is enabled, such as on OpenShift, ConfigConnector operator would fail with error forbidden: cannot set blockOwnerDeletion if an ownerReference refers to a resource you can't set finalizers on

This PR ensures that operator's manager role has sufficient permission to update finalizer on a configconnector resource which will then allow us to set blockOwnerDeletion on resources created via Reconcile of a ConfigConnector.

@google-cla

google-cla Bot commented Mar 31, 2023

Copy link
Copy Markdown

Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA).

View this failed invocation of the CLA check for more information.

For the most up to date status, view the checks section at the bottom of the pull request.

@kaovilai kaovilai changed the title Corrects RBAC OwnerReferencesPermissionEnforcement enabled clusters Corrects RBAC for OwnerReferencesPermissionEnforcement enabled clusters Mar 31, 2023
@kaovilai

Copy link
Copy Markdown
Contributor Author

Working on obtaining CLA with @eparis

@kaovilai

kaovilai commented Apr 1, 2023

Copy link
Copy Markdown
Contributor Author

Looked for ways to test SA clusterrole.. seems like not easy with envtest.

@kaovilai kaovilai changed the title Corrects RBAC for OwnerReferencesPermissionEnforcement enabled clusters Fix setting blockOwnerDeletion failures for OwnerReferencesPermissionEnforcement enabled clusters Apr 1, 2023
@kaovilai kaovilai changed the title Fix setting blockOwnerDeletion failures for OwnerReferencesPermissionEnforcement enabled clusters Fix set blockOwnerDeletion failures for OwnerReferencesPermissionEnforcement enabled clusters Apr 1, 2023
@kaovilai

kaovilai commented Apr 3, 2023

Copy link
Copy Markdown
Contributor Author

@diviner524 could you please review?

Comment thread operator/config/rbac/role.yaml Outdated
If [OwnerReferencesPermissionEnforcement](https://kubernetes.io/docs/reference/access-authn-authz/admission-controllers/#ownerreferencespermissionenforcement) is turned on, such as on OpenShift, ConfigConnector operator would fail with error `forbidden: cannot set blockOwnerDeletion if an ownerReference refers to a resource you can't set finalizers on`

Signed-off-by: Tiger Kaovilai 

Limit finalizers role to update verb

Signed-off-by: Tiger Kaovilai 
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Operator needs finalizer permission in RBAC to work in OpenShift

2 participants