Cluster Operator's default clusterrolebindings are lost
Issue
- RBAC of cluster operators and core workloads such
openshift-oauth-apiserver
were lost which caused authentication outage, and operator pods were not functioning properly - You may see pods in
crashloopback
phase for the affected operators
# oc get pods -A | grep CrashLoopBackOff
openshift-cluster-storage-operator cluster-storage-operator-7b96c5f8f8-84fjt 0/1 CrashLoopBackOff 1276 5d
openshift-cluster-storage-operator csi-snapshot-controller-operator-798d979c86-chkpc 0/1 CrashLoopBackOff 1278 5d
openshift-config-operator openshift-config-operator-6c76c8474f-p99zp 0/1 CrashLoopBackOff 2605 5d
openshift-console-operator console-operator-57f8fb59bd-2hqtz 0/1 CrashLoopBackOff 2371 5d
openshift-kube-apiserver-operator kube-apiserver-operator-9976978cd-7fvdq 0/1 CrashLoopBackOff 1278 5d
openshift-kube-descheduler-operator cluster-dbdd779dd-5jbcz 0/1 CrashLoopBackOff 1339 5d
openshift-kube-storage-version-migrator-operator kube-storage-version-migrator-operator-6cf7c56549-6v5hf 0/1 CrashLoopBackOff 1278 5d
openshift-operator-lifecycle-manager packageserver-546cd65986-4qwzq 0/1 CrashLoopBackOff 2365 5d
openshift-operator-lifecycle-manager packageserver-546cd65986-qjjvc 0/1 CrashLoopBackOff 2365 5d
openshift-service-ca-operator service-ca-operator-7b6c99b5b7-zs2dk 0/1 CrashLoopBackOff 1278 5d
Environment
- OpenShift Container Platform
- 4.6.31
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.