Ingress Pod RBAC Issues with Cluster-Scoped Permissions
Issue
The ingress-controller Pod in namespace prod-network fails with:
- RBAC errors when accessing cluster-scoped resources (ingressclasses, nodes).
- IP allocation issues (secondary symptom).
User 'system:serviceaccount:prod-network:ingress-sa' cannot list resource 'ingressclasses' in API group 'networking.k8s.io' at the cluster scope
User 'system:serviceaccount:prod-network:ingress-sa' cannot get resource 'nodes' in API group '' at the cluster scope
Environment
OpenShift Container Platform 4.x
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.