You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

OpenShift无法创建Pod:runAsGroup与命名空间注解值不匹配求助

PostgreSQL DeploymentConfig 部署问题排查

问题说明

尝试通过OpenShift Template部署PostgreSQL应用,执行时遭Kyverno准入Webhook拒绝,已确认runAsUser和runAsGroup符合SCC配置,但仍因runAsGroup不匹配报错。

模板YAML代码

apiVersion: template.openshift.io/v1
kind: Template
labels:
  template: postgres
message: |-
  To test deployment for postgres.
metadata:
  annotations:
    description: Deploys postgress on Openshift.
    openshift.io/display-name: postgress
    openshift.io/long-description: postgres
    openshift.io/provider-display-name: xxxx
    tags: database
    template.openshift.io/bindable: "false"
  name: postgres    
objects:

- apiVersion: apps.openshift.io/v1
  kind: DeploymentConfig
  metadata:
    annotations:
      template.alpha.openshift.io/wait-for-ready: 'true'
    labels:
      app: ${APPLICATION_NAME}
      template: postgresql-ephemeral-template
    name: ${POSTGRESQL_HOST}
  spec:
    replicas: 1
    selector:
      name: ${POSTGRESQL_HOST}
    strategy:
      type: Recreate
    template:
      metadata:
        labels:
          name: ${POSTGRESQL_HOST}
      spec:
        containers:
        - env:
          - name: POSTGRESQL_USER
            valueFrom:
              secretKeyRef:
                key: database-user
                name: postgresql
          - name: POSTGRESQL_PASSWORD
            valueFrom:
              secretKeyRef:
                key: database-password
                name: postgresql
          - name: POSTGRESQL_DATABASE
            valueFrom:
              secretKeyRef:
                key: database-name
                name: postgresql
          image: rhel8/postgresql-12
          imagePullPolicy: IfNotPresent
          livenessProbe:
            exec:
              command:
              - "/usr/libexec/check-container"
              - "--live"
            initialDelaySeconds: 120
            timeoutSeconds: 10
          name: ${POSTGRESQL_HOST}
          ports:
          - containerPort: 5432
            protocol: TCP
          readinessProbe:
            exec:
              command:
              - "/usr/libexec/check-container"
            initialDelaySeconds: 5
            timeoutSeconds: 1
          resources:
            limits:
              memory: 1Gi
          securityContext: 
            capabilities: {}
            privileged: false
          terminationMessagePath: /dev/termination-log
          volumeMounts:
          - mountPath: /var/lib/pgsql/data
            name: postgresql-data
        dnsPolicy: ClusterFirst
        restartPolicy: Always
        schedulerName: default-scheduler
        securityContext: 
          runAsUser: 2222
          runAsGroup: 1111
        terminationGracePeriodSeconds: 30
        volumes:
        - name: postgresql-data
          persistentVolumeClaim:
            claimName: ${PERSISTENT_VOLUME_CLAIM_DB}

    triggers:
    - imageChangeParams:
        automatic: true
        containerNames:
        - ${POSTGRESQL_HOST}
        from:
          kind: ImageStreamTag
          name: postgresql:12
          namespace: airflow-data-factory
      type: ImageChange
    - type: ConfigChange

- apiVersion: v1
  stringData:
    database-name: ${POSTGRESQL_DATABASE}
    database-password: ${POSTGRESQL_PASSWORD}
    database-user: ${POSTGRESQL_USER}
    connection-string: postgresql+psycopg2://${POSTGRESQL_USER}:${POSTGRESQL_PASSWORD}@${POSTGRESQL_HOST}:5432/${POSTGRESQL_DATABASE}
    result-backend: db+postgresql://${POSTGRESQL_USER}:${POSTGRESQL_PASSWORD}@${POSTGRESQL_HOST}:5432/${POSTGRESQL_DATABASE}
  kind: Secret
  metadata:
    labels:
      app: ${APPLICATION_NAME}
      template: postgresql-ephemeral-template
    name: postgresql
  type: Opaque

- apiVersion: v1
  kind: Service
  metadata:
    labels:
      app: ${APPLICATION_NAME}
      template: postgresql-ephemeral-template
    name: ${POSTGRESQL_HOST}
  spec:
    ports:
    - name: ${POSTGRESQL_HOST}
      port: 5432
      protocol: TCP
      targetPort: 5432
    selector:
      name: ${POSTGRESQL_HOST}
    sessionAffinity: None
    type: ClusterIP
  status:
    loadBalancer: {}

- apiVersion: v1
  kind: PersistentVolumeClaim
  metadata:
    name: ${PERSISTENT_VOLUME_CLAIM_DB}
    namespace: airflow-data-factory
  spec:
    storageClassName: openshift-trident-ext4
    accessModes:
      - "ReadWriteOnce"
    resources:
      requests:
        storage: ${PERSISTENT_VOLUME_CLAIM_DB_SIZE}

parameters:
- description: Name of the application
  displayName: Application name
  name: APPLICATION_NAME
  value: postgres
- description: PostgreSQL host
  displayName: PostgreSQL hostname
  name: POSTGRESQL_HOST
  value: postgresql
  required: true
- description: Username for PostgreSQL user that will be used for accessing the database
  displayName: PostgreSQL connection username
  from: 'user[a-z0-9]{5}'
  generate: expression
  name: POSTGRESQL_USER
  required: true
- description: Password for the PostgreSQL connection user
  displayName: PostgreSQL connection password
  from: '[a-zA-Z0-9]{16}'
  generate: expression
  name: POSTGRESQL_PASSWORD
  required: true
- description: Database name for PostgreSQL database
  displayName: PostgreSQL connection database
  from: 'airflow[a-z0-9]{5}'
  generate: expression
  name: POSTGRESQL_DATABASE
  required: true
- description: Attached PERSISTENT volume claim name for storing metadata in PostgreSQL database
  displayName: PERSISTENT volume claim name (database)
  name: PERSISTENT_VOLUME_CLAIM_DB
  value: storage-db-pvc
- description: Size of the metadata volume storage
  displayName: Metadata volume storage size
  name: PERSISTENT_VOLUME_CLAIM_DB_SIZE
  value: "1Gi"

报错信息

Stop retrying: couldn't create deployer pod for "zzzzzzzzzz/postgresql-7": admission webhook "validate.kyverno.something-ignore" denied the request: policy Pod/namespace_name/postgresql-7-deploy for resource violations: add-securitycontext: update-runasgroup: The runAsGroup does not match the field value from the annotation in the namespace. ensure-readonly-lustre: ensure-readonly-lustre: preconditions not met

排查建议

  1. 核对Namespace注解值
    错误明确指出runAsGroup与目标namespace的注解值不匹配,先检查namespace的相关注解(比如openshift.io/sa.scc.run-as-group或自定义注解),确保模板中runAsGroup: 1111与注解值完全一致。

  2. 检查Kyverno策略规则
    问题来自Kyverno的add-securitycontext策略下的update-runasgroup规则,需确认该策略是否强制namespace内所有Pod使用统一的runAsGroup值,或者是否可配置例外规则绕过检查。

  3. 补全容器级安全上下文
    当前模板仅在Pod级别设置了runAsGroup,容器级别未配置。部分Kyverno策略可能要求容器级也同步设置对应参数,可尝试在容器的securityContext中添加runAsGroup: 1111,保持与Pod级别的一致性。

  4. 验证Deployer Pod规则
    OpenShift DeploymentConfig的deployer Pod会继承主配置的安全上下文,但需确认是否有专门针对deployer Pod的SCC或Kyverno规则生效。可临时查看deployer Pod的预期配置,对比模板提交内容是否符合要求。

  5. 修正PVC命名空间
    模板中PVC指定了固定namespaceairflow-data-factory,若部署时使用的目标namespace不一致,会导致权限或资源找不到的问题。可移除PVC的namespace字段,让其继承模板部署的目标namespace,或确保部署命令指定的namespace与PVC的namespace一致。


内容的提问来源于stack exchange,提问作者Nandan Thakur

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.24 11:18:08