Ingress Pod RBAC Issues with Cluster-Scoped Permissions

Solution Verified - Updated -

Issue

The ingress-controller Pod in namespace prod-network fails with:

  • RBAC errors when accessing cluster-scoped resources (ingressclasses, nodes).
  • IP allocation issues (secondary symptom).
User 'system:serviceaccount:prod-network:ingress-sa' cannot list resource 'ingressclasses' in API group 'networking.k8s.io' at the cluster scope  
User 'system:serviceaccount:prod-network:ingress-sa' cannot get resource 'nodes' in API group '' at the cluster scope

Environment

OpenShift Container Platform 4.x

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.

Current Customers and Partners

Log in for full access

Log In

New to Red Hat?

Learn more about Red Hat subscriptions

Using a Red Hat product through a public cloud?

How to access this content