In audit logs localhost-recovery-client gets forbid error for kube-scheduler and kube-apiserver
Issue
- In audit logs
local-host-recovery-clientgetting"authorization.k8s.io/decision": "forbid"alert forkube-schedulerandkube-apiserver.
"requestReceivedTimestamp": "2023-09-11T21:57:58.861580Z",
"stageTimestamp": "2023-09-11T21:57:58.889064Z",
"annotations": {
"authentication.k8s.io/legacy-token": "system:serviceaccount:openshift-kube-apiserver:localhost-recovery-client",
"authorization.k8s.io/decision": "forbid",
"authorization.k8s.io/reason": "",
"openshift.io/unready": "loopback=true,,readyz=false"
Environment
- Red Hat OpenShift Container Platform 4.x
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.