[jboss-jira] [JBoss JIRA] (WFWIP-156) spec.containers[0].securityContext.securityContext.runAsUser: Invalid value: 1000: must be in the ranges: [1000080000, 1000089999]

Jeff Mesnil (Jira) issues at jboss.org
Fri Mar 22 09:13:01 EDT 2019


    [ https://issues.jboss.org/browse/WFWIP-156?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13712149#comment-13712149 ] 

Jeff Mesnil commented on WFWIP-156:
-----------------------------------

It seems that OpenShift has additional security constraints compare to plain Kubernetes (I tested the operator on Minikube):

* https://github.com/coreos/prometheus-operator/issues/2333
* https://blog.openshift.com/understanding-service-accounts-sccs/

> spec.containers[0].securityContext.securityContext.runAsUser: Invalid value: 1000: must be in the ranges: [1000080000, 1000089999]
> ----------------------------------------------------------------------------------------------------------------------------------
>
>                 Key: WFWIP-156
>                 URL: https://issues.jboss.org/browse/WFWIP-156
>             Project: WildFly WIP
>          Issue Type: Bug
>            Reporter: Martin Choma
>            Assignee: Jeff Mesnil
>            Priority: Major
>
> Trying https://github.com/jmesnil/wildfly-operator/blob/master/README.adoc to install operator on OpenShift. I get error.
> {noformat}
> create Pod myapp-wildflyserver-0 in StatefulSet myapp-wildflyserver failed error: pods "myapp-wildflyserver-0" is forbidden: unable to validate against any security context constraint: [spec.containers[0].securityContext.securityContext.runAsUser: Invalid value: 1000: must be in the ranges: [1000080000, 1000089999]]
> {noformat}



--
This message was sent by Atlassian Jira
(v7.12.1#712002)


More information about the jboss-jira mailing list