OpenShift无法创建Pod:runAsGroup与命名空间注解值不匹配求助
问题说明
尝试通过OpenShift Template部署PostgreSQL应用,执行时遭Kyverno准入Webhook拒绝,已确认runAsUser和runAsGroup符合SCC配置,但仍因runAsGroup不匹配报错。
模板YAML代码
apiVersion: template.openshift.io/v1 kind: Template labels: template: postgres message: |- To test deployment for postgres. metadata: annotations: description: Deploys postgress on Openshift. openshift.io/display-name: postgress openshift.io/long-description: postgres openshift.io/provider-display-name: xxxx tags: database template.openshift.io/bindable: "false" name: postgres objects: - apiVersion: apps.openshift.io/v1 kind: DeploymentConfig metadata: annotations: template.alpha.openshift.io/wait-for-ready: 'true' labels: app: ${APPLICATION_NAME} template: postgresql-ephemeral-template name: ${POSTGRESQL_HOST} spec: replicas: 1 selector: name: ${POSTGRESQL_HOST} strategy: type: Recreate template: metadata: labels: name: ${POSTGRESQL_HOST} spec: containers: - env: - name: POSTGRESQL_USER valueFrom: secretKeyRef: key: database-user name: postgresql - name: POSTGRESQL_PASSWORD valueFrom: secretKeyRef: key: database-password name: postgresql - name: POSTGRESQL_DATABASE valueFrom: secretKeyRef: key: database-name name: postgresql image: rhel8/postgresql-12 imagePullPolicy: IfNotPresent livenessProbe: exec: command: - "/usr/libexec/check-container" - "--live" initialDelaySeconds: 120 timeoutSeconds: 10 name: ${POSTGRESQL_HOST} ports: - containerPort: 5432 protocol: TCP readinessProbe: exec: command: - "/usr/libexec/check-container" initialDelaySeconds: 5 timeoutSeconds: 1 resources: limits: memory: 1Gi securityContext: capabilities: {} privileged: false terminationMessagePath: /dev/termination-log volumeMounts: - mountPath: /var/lib/pgsql/data name: postgresql-data dnsPolicy: ClusterFirst restartPolicy: Always schedulerName: default-scheduler securityContext: runAsUser: 2222 runAsGroup: 1111 terminationGracePeriodSeconds: 30 volumes: - name: postgresql-data persistentVolumeClaim: claimName: ${PERSISTENT_VOLUME_CLAIM_DB} triggers: - imageChangeParams: automatic: true containerNames: - ${POSTGRESQL_HOST} from: kind: ImageStreamTag name: postgresql:12 namespace: airflow-data-factory type: ImageChange - type: ConfigChange - apiVersion: v1 stringData: database-name: ${POSTGRESQL_DATABASE} database-password: ${POSTGRESQL_PASSWORD} database-user: ${POSTGRESQL_USER} connection-string: postgresql+psycopg2://${POSTGRESQL_USER}:${POSTGRESQL_PASSWORD}@${POSTGRESQL_HOST}:5432/${POSTGRESQL_DATABASE} result-backend: db+postgresql://${POSTGRESQL_USER}:${POSTGRESQL_PASSWORD}@${POSTGRESQL_HOST}:5432/${POSTGRESQL_DATABASE} kind: Secret metadata: labels: app: ${APPLICATION_NAME} template: postgresql-ephemeral-template name: postgresql type: Opaque - apiVersion: v1 kind: Service metadata: labels: app: ${APPLICATION_NAME} template: postgresql-ephemeral-template name: ${POSTGRESQL_HOST} spec: ports: - name: ${POSTGRESQL_HOST} port: 5432 protocol: TCP targetPort: 5432 selector: name: ${POSTGRESQL_HOST} sessionAffinity: None type: ClusterIP status: loadBalancer: {} - apiVersion: v1 kind: PersistentVolumeClaim metadata: name: ${PERSISTENT_VOLUME_CLAIM_DB} namespace: airflow-data-factory spec: storageClassName: openshift-trident-ext4 accessModes: - "ReadWriteOnce" resources: requests: storage: ${PERSISTENT_VOLUME_CLAIM_DB_SIZE} parameters: - description: Name of the application displayName: Application name name: APPLICATION_NAME value: postgres - description: PostgreSQL host displayName: PostgreSQL hostname name: POSTGRESQL_HOST value: postgresql required: true - description: Username for PostgreSQL user that will be used for accessing the database displayName: PostgreSQL connection username from: 'user[a-z0-9]{5}' generate: expression name: POSTGRESQL_USER required: true - description: Password for the PostgreSQL connection user displayName: PostgreSQL connection password from: '[a-zA-Z0-9]{16}' generate: expression name: POSTGRESQL_PASSWORD required: true - description: Database name for PostgreSQL database displayName: PostgreSQL connection database from: 'airflow[a-z0-9]{5}' generate: expression name: POSTGRESQL_DATABASE required: true - description: Attached PERSISTENT volume claim name for storing metadata in PostgreSQL database displayName: PERSISTENT volume claim name (database) name: PERSISTENT_VOLUME_CLAIM_DB value: storage-db-pvc - description: Size of the metadata volume storage displayName: Metadata volume storage size name: PERSISTENT_VOLUME_CLAIM_DB_SIZE value: "1Gi"
报错信息
Stop retrying: couldn't create deployer pod for "zzzzzzzzzz/postgresql-7": admission webhook "validate.kyverno.something-ignore" denied the request: policy Pod/namespace_name/postgresql-7-deploy for resource violations: add-securitycontext: update-runasgroup: The runAsGroup does not match the field value from the annotation in the namespace. ensure-readonly-lustre: ensure-readonly-lustre: preconditions not met
排查建议
核对Namespace注解值
错误明确指出runAsGroup与目标namespace的注解值不匹配,先检查namespace的相关注解(比如openshift.io/sa.scc.run-as-group或自定义注解),确保模板中runAsGroup: 1111与注解值完全一致。检查Kyverno策略规则
问题来自Kyverno的add-securitycontext策略下的update-runasgroup规则,需确认该策略是否强制namespace内所有Pod使用统一的runAsGroup值,或者是否可配置例外规则绕过检查。补全容器级安全上下文
当前模板仅在Pod级别设置了runAsGroup,容器级别未配置。部分Kyverno策略可能要求容器级也同步设置对应参数,可尝试在容器的securityContext中添加runAsGroup: 1111,保持与Pod级别的一致性。验证Deployer Pod规则
OpenShift DeploymentConfig的deployer Pod会继承主配置的安全上下文,但需确认是否有专门针对deployer Pod的SCC或Kyverno规则生效。可临时查看deployer Pod的预期配置,对比模板提交内容是否符合要求。修正PVC命名空间
模板中PVC指定了固定namespaceairflow-data-factory,若部署时使用的目标namespace不一致,会导致权限或资源找不到的问题。可移除PVC的namespace字段,让其继承模板部署的目标namespace,或确保部署命令指定的namespace与PVC的namespace一致。
内容的提问来源于stack exchange,提问作者Nandan Thakur

