Pods Controlled By Job unable to terminate until finalizers are deleted manually after namespace excluded in gatekeeper
Issue
- Pods Controlled By Job unable to terminate until finalizers are deleted manually after namespace excluded in gatekeeper.
- During node drains, pods created from an existing Running Job are left in Terminating state. The finalizers cannot be deleted for these pods, until their namespace is added in the excludeNamespace of assign
runtimeclassandfsgroupresources respectively. The pods are created by the job and affected by the gatekeeper policies. Is this behaviour expected?
Environment
- Red Hat Openshift Container Platform, v4.13
- Gatekeeper, v3.14
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.