ROSAENG-64532: remove CDO rebalancer RoleBinding (fixes OHSS-58441) - #2878
openshift-merge-bot[bot] merged 2 commits into
Conversation
Delete the osd-rebalance-infra-nodes RoleBinding targeting namespace openshift-custom-domains-operator. Phase 1 of the CDO decommission removed the CDO namespace from clusters without the keep-label. The rebalancer SSS still tries to apply this RoleBinding to that namespace, causing ClusterSync failure on hibernation resume and blocking LS auto-clear. This is the minimal fix extracted from PR openshift#2869 (full MCC cleanup) which is still under review. Co-authored-by: Cursor <cursoragent@cursor.com>
|
@aliceh: This pull request references ROSAENG-64532 which is a valid jira issue. Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the task to target the "5.1.0" version, but no target version was set. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository YAML (base), Central YAML (inherited) Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (1)
💤 Files with no reviewable changes (1)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. WalkthroughThe pull request deletes the RoleBinding that granted the ChangesOSD rebalance RBAC
Priority: ➖ Normal Estimated code review effort: 1 (Trivial) | ~3 minutes Change: Bug fix Merge Risk: ⚪ Minimal · up to The change removes the obsolete RoleBinding described in the PR scope, with no unresolved concrete risk identified. 🚥 Pre-merge checks | ✅ 15✅ Passed checks (15 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
|
@aliceh: all tests passed! Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
|
/lgtm |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: aliceh, dustman9000 The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
Delete the osd-serviceaccounts/aws SSS that creates a ServiceAccount in namespace openshift-custom-domains-operator. Same class of failure as the rebalancer RoleBinding (PR #2878): Hive tries to create a resource in a namespace that no longer exists after CDO Phase 1 removal, causing ClusterSync failure and blocking LS auto-clear on hibernation resume. The file contains only the CDO ServiceAccount — no other resources. Co-authored-by: Cursor <cursoragent@cursor.com>
Summary
Minimal fix for OHSS-58441: delete the single RoleBinding that targets
namespace: openshift-custom-domains-operator.Phase 1 of the CDO decommission (ROSAENG-64532) removed the CDO namespace from clusters without the
custom-domains-operator/keeplabel. Theosd-rebalance-infra-nodes-non-frSSS still applies this RoleBinding to that namespace, causing ClusterSync failure on hibernation resume and blocking LS auto-clear.This is the only file causing the ClusterSync failure. It grants the infra-node rebalancer access to the CDO namespace — it is not used by any other operator or service.
Extracted from PR #2869 (full MCC CDO cleanup, still under review) to unblock the immediate operational impact.
What this does NOT touch
non-fr/usesresourceApplyMode: Upsert)Test plan
Made with Cursor
Summary by CodeRabbit