Skip to content

Conversation

@haircommander
Copy link
Member

- What I did

this static pod fails on creation because static pods can't have an attached service account.
This would normally not be that problematic (the mirror pod creation fails in the API server, but continues in kubelet),
however, Multus queries the API-server for pod status, and fails if it can't be found.
This, this pod is never actually created.

- How to verify it

kubelet_service.log:Nov 10 03:07:32.757094 ip-10-0-143-173 hyperkube[1522]: E1110 03:07:32.757070    1522 kubelet.go:1583] Failed creating a mirror pod for "recyler-pod-ip-10-0-143-173.ec2.internal_openshift-infra(c4a6d0bdd7ae69ac5efa10a12ad33bc0)": pods "recyler-pod-ip-10-0-143-173.ec2.internal" is forbidden: a mirror pod may not reference service accounts
...
crio_service.log:Nov 10 03:07:32.798133 ip-10-0-143-173 crio[1487]: time="2020-11-10 03:07:32.798004563Z" level=error msg="Error adding network: Multus: [openshift-infra/recyler-pod-ip-10-0-143-173.ec2.internal]: error getting pod: pods \"recyler-pod-ip-10-0-143-173.ec2.internal\" not found" file="ocicni/ocicni.go:771"

does not appear

- Description for the changelog

this static pod fails on creation because static pods can't have an attached service account.
This would normally not be that problematic (the mirror pod creation fails in the API server, but continues in kubelet),
however, Multus queries the API-server for pod status, and fails if it can't be found.
This, this pod is never actually created.

Signed-off-by: Peter Hunt <[email protected]>
@haircommander
Copy link
Member Author

@bertinatto PTAL

@haircommander
Copy link
Member Author

(I happened upon this by poking through the logs of #2210 trying to figure out why it failed, my understanding is incomplete but hopefully near-correct)

@haircommander haircommander changed the title recycler pod: drop serviceAccount recycler pod: drop serviceAccountName Nov 10, 2020
Copy link
Contributor

@kikisdeliveryservice kikisdeliveryservice left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This seems sane to me but I defer to @bertinatto to LGTM as they originally added this template.

@openshift-ci-robot openshift-ci-robot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Nov 10, 2020
@haircommander
Copy link
Member Author

/retest

1 similar comment
@bertinatto
Copy link
Member

/retest

@bertinatto
Copy link
Member

/lgtm

This makes sense to me. This template is a copy of the one used in 3.x, so I'm not sure why we haven't seen this before.

@openshift-ci-robot openshift-ci-robot added the lgtm Indicates that a PR is ready to be merged. label Nov 16, 2020
@openshift-ci-robot
Copy link
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: bertinatto, haircommander, kikisdeliveryservice

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:
  • OWNERS [kikisdeliveryservice]

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-bot
Copy link
Contributor

/retest

Please review the full test history for this PR and help us cut down flakes.

9 similar comments
@openshift-bot
Copy link
Contributor

/retest

Please review the full test history for this PR and help us cut down flakes.

@openshift-bot
Copy link
Contributor

/retest

Please review the full test history for this PR and help us cut down flakes.

@openshift-bot
Copy link
Contributor

/retest

Please review the full test history for this PR and help us cut down flakes.

@openshift-bot
Copy link
Contributor

/retest

Please review the full test history for this PR and help us cut down flakes.

@openshift-bot
Copy link
Contributor

/retest

Please review the full test history for this PR and help us cut down flakes.

@openshift-bot
Copy link
Contributor

/retest

Please review the full test history for this PR and help us cut down flakes.

@openshift-bot
Copy link
Contributor

/retest

Please review the full test history for this PR and help us cut down flakes.

@openshift-bot
Copy link
Contributor

/retest

Please review the full test history for this PR and help us cut down flakes.

@openshift-bot
Copy link
Contributor

/retest

Please review the full test history for this PR and help us cut down flakes.

@kikisdeliveryservice
Copy link
Contributor

kikisdeliveryservice commented Nov 17, 2020

lots of retesting will remove hold when they start to pass overall..

/hold

@openshift-ci-robot openshift-ci-robot added the do-not-merge/hold Indicates that a PR should not merge because someone has issued a /hold command. label Nov 17, 2020
@bertinatto
Copy link
Member

/retest

@openshift-merge-robot
Copy link
Contributor

openshift-merge-robot commented Nov 18, 2020

@haircommander: The following tests failed, say /retest to rerun all failed tests:

Test name Commit Details Rerun command
ci/prow/e2e-gcp-op 319b105 link /test e2e-gcp-op
ci/prow/okd-e2e-aws 319b105 link /test okd-e2e-aws

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. I understand the commands that are listed here.

@sjenning
Copy link
Contributor

I don't believe we need this.

This pod was not intended to be a static pod in the first place. See #2238

@haircommander if you agree, can you close this?

@sjenning
Copy link
Contributor

@haircommander I also pulled in the typo fix for recyler

@haircommander
Copy link
Member Author

agreed that this can be closed!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. do-not-merge/hold Indicates that a PR should not merge because someone has issued a /hold command. lgtm Indicates that a PR is ready to be merged.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants