-
Notifications
You must be signed in to change notification settings - Fork 402
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
TRT-540: Add privileged label to infra namespaces #3328
TRT-540: Add privileged label to infra namespaces #3328
Conversation
/test e2e-openstack |
/cc @jcpowermac @mandre |
Hmm, the installation failed at bootstrap for all platforms, including aws and gcp that shouldn't be affected by this patch. |
Awesome! Thanks for this...been seeing these errors in the kubelet while debugging another issue. |
This has been affecting kubelet creating mirror pods for keepalived, haproxy etc.
7eb8cbf
to
08f620a
Compare
/test e2e-openstack |
It turned out the aws and gcp failures were related to the change. I think yaml was interpreting false without quotes as boolean type. Therefore unmarshalling got a panic trying to convert boolean to string. The panic can be observed from cluster-version-operator log on bootstrap node. Here is an example:
That said, I am not sure why cluster-version-operator for aws and gcp are Running sync for namespace "openshift-openstack-infra". |
vSphere failures are unrelated to this PR. Probably disk or cpu performance issue in CI vsphere environment. |
/lgtm |
OpenStack failure also probably unrelated. |
/test e2e-metal-ipi-ovn-ipv6 |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I confirm that the openstack failure is unrelated.
/lgtm
/test e2e-metal-ipi-ovn-ipv6 |
Are we expecting any of the other tests to pass? |
Honestly I am not sure. The metal-ipi-ovn-ipv6 jobs ran at least a couple of times. First time, it failed with installation. The job ended getting three master nodes with no worker nodes. The second run passed installation. But getting lease was taking close to 2 hours and therefore the job is terminated after timeout. I am going to try rerun those after hours here to see what I will get tomorrow. |
/test e2e-metal-ipi-ovn-ipv6 |
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: jcpowermac, mandre, sinnykumari, xueqzhan The full list of commands accepted by this bot can be found here. The pull request process is described here
Needs approval from an approver in each of these files:
Approvers can indicate their approval by writing |
/retest-required |
1 similar comment
/retest-required |
@xueqzhan: The following tests failed, say
Full PR test history. Your PR dashboard. Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. I understand the commands that are listed here. |
/retest-required |
/cherry-pick release-4.11 |
@stlaz: new pull request created: #3346 In response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
This has been affecting kubelet creating mirror pods for keepalived, haproxy etc.
- What I did
Add privileged labels to infra namespaces.
- How to verify it
Kubelet logs should not have errors about "Failed creating a mirror pod for .... is forbidden: violates PodSecurity" error.
- Description for the changelog
Since this PR: openshift/cluster-kube-apiserver-operator#1369, many pods are affected and fail to create. The infra namespaces are affecting kubelets. The following are some sample errors.
You can see the error in this job run: https://gcsweb-ci.apps.ci.l2s4.p1.openshiftapps.com/gcs/origin-ci-test/logs/periodic-ci-shiftstack-shiftstack-ci-main-periodic-4.12-e2e-openstack-serial/1567141456282390528/artifacts/e2e-openstack-serial/gather-extra/artifacts/nodes/c1fh9587-c805c-lqm8z-master-0/journal