Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[BUG] It is nonstop syncing a roletemplate with a clusterrole #45517

Open
samjustus opened this issue May 16, 2024 · 1 comment
Open

[BUG] It is nonstop syncing a roletemplate with a clusterrole #45517

samjustus opened this issue May 16, 2024 · 1 comment
Assignees
Labels
area/rbac kind/bug Issues that are defects reported by users or that we know have reached a real release priority/0 team/collie the team that is responsible for auth and rbac within rancher
Milestone

Comments

@samjustus
Copy link
Collaborator

samjustus commented May 16, 2024

Rancher Server Setup

  • Rancher version: 2.7.5, 2.9.0-head

Issue description:

It's nonstop syncing a roletemplate with a clusterrole that are seemingly the same and have the same 'rules:' section.

Business impact:

A lot of logs

Troubleshooting steps:

We compare the rules between the two roles and confirmed that they are same. But, we are seeing this in the logs

rancher-74f4d76887-nw9fm rancher 2023/08/26 01:37:43 [INFO] Updating role rt-4wcnr in c-xkcxk because of rules difference with roleTemplate QL-ClusterAdmin (rt-4wcnr).
rancher-74f4d76887-nw9fm rancher 2023/08/26 01:37:43 [INFO] Updating role rt-4wcnr in c-xkcxk because of rules difference with roleTemplate QL-ClusterAdmin (rt-4wcnr).
rancher-74f4d76887-nw9fm rancher 2023/08/26 01:37:43 [INFO] Updating role rt-4wcnr in c-xkcxk because of rules difference with roleTemplate QL-ClusterAdmin (rt-4wcnr).
rancher-74f4d76887-nw9fm rancher 2023/08/26 01:37:43 [INFO] Updating role rt-4wcnr in c-xkcxk because of rules difference with roleTemplate QL-ClusterAdmin (rt-4wcnr).
rancher-74f4d76887-nw9fm rancher 2023/08/26 01:37:43 [INFO] Updating role rt-4wcnr in c-xkcxk because of rules difference with roleTemplate QL-ClusterAdmin (rt-4wcnr).
rancher-74f4d76887-nw9fm rancher 2023/08/26 01:37:43 [INFO] [mgmt-auth-crtb-controller] Updating role rt-4wcnr in namespace c-xkcxk
rancher-74f4d76887-nw9fm rancher 2023/08/26 01:37:43 [INFO] [mgmt-auth-crtb-controller] Updating role rt-4wcnr in namespace c-xkcxk
rancher-74f4d76887-nw9fm rancher 2023/08/26 01:37:43 [INFO] [mgmt-auth-crtb-controller] Updating role rt-4wcnr in namespace c-xkcxk
rancher-74f4d76887-nw9fm rancher 2023/08/26 01:37:43 [INFO] [mgmt-auth-crtb-controller] Updating role rt-4wcnr in namespace c-xkcxk
rancher-74f4d76887-nw9fm rancher 2023/08/26 01:37:43 [INFO] [mgmt-auth-crtb-controller] Updating role rt-4wcnr in namespace c-xkcxk
rancher-74f4d76887-nw9fm rancher 2023/08/26 01:37:43 [INFO] Updating role rt-4wcnr in c-xkcxk because of rules difference with roleTemplate QL-ClusterAdmin (rt-4wcnr).
rancher-74f4d76887-nw9fm rancher 2023/08/26 01:37:43 [INFO] [mgmt-auth-crtb-controller] Updating role rt-4wcnr in namespace c-xkcxk
rancher-74f4d76887-nw9fm rancher 2023/08/26 01:37:43 [INFO] Updating role rt-4wcnr in c-xkcxk because of rules difference with roleTemplate QL-ClusterAdmin (rt-4wcnr).
rancher-74f4d76887-nw9fm rancher 2023/08/26 01:37:43 [INFO] [mgmt-auth-crtb-controller] Updating role rt-4wcnr in namespace c-xkcxk
rancher-74f4d76887-nw9fm rancher 2023/08/26 01:37:43 [INFO] Updating role rt-4wcnr in c-xkcxk because of rules difference with roleTemplate QL-ClusterAdmin (rt-4wcnr).
rancher-74f4d76887-nw9fm rancher 2023/08/26 01:37:43 [INFO] [mgmt-auth-crtb-controller] Updating role rt-4wcnr in namespace c-xkcxk
rancher-74f4d76887-nw9fm rancher 2023/08/26 01:37:43 [INFO] [mgmt-auth-crtb-controller] Updating role rt-4wcnr in namespace c-xkcxk
rancher-74f4d76887-nw9fm rancher 2023/08/26 01:37:43 [INFO] Updating role rt-4wcnr in c-xkcxk because of rules difference with roleTemplate QL-ClusterAdmin (rt-4wcnr).
rancher-74f4d76887-nw9fm rancher 2023/08/26 01:37:44 [INFO] [mgmt-auth-crtb-controller] Updating role rt-4wcnr in namespace c-xkcxk
rancher-74f4d76887-nw9fm rancher 2023/08/26 01:37:44 [INFO] [mgmt-auth-crtb-controller] Updating role rt-4wcnr in namespace c-xkcxk
rancher-74f4d76887-nw9fm rancher 2023/08/26 01:37:44 [INFO] Updating role rt-4wcnr in c-xkcxk because of rules difference with roleTemplate QL-ClusterAdmin (rt-4wcnr).
rancher-74f4d76887-nw9fm rancher 2023/08/26 01:37:44 [INFO] Updating role rt-4wcnr in c-xkcxk because of rules difference with roleTemplate QL-ClusterAdmin (rt-4wcnr).
rancher-74f4d76887-nw9fm rancher 2023/08/26 01:37:44 [INFO] [mgmt-auth-crtb-controller] Updating role rt-4wcnr in namespace c-xkcxk
rancher-74f4d76887-nw9fm rancher 2023/08/26 01:37:44 [INFO] Updating role rt-4wcnr in c-xkcxk because of rules difference with roleTemplate QL-ClusterAdmin (rt-4wcnr).
rancher-74f4d76887-nw9fm rancher 2023/08/26 01:37:44 [INFO] [mgmt-auth-crtb-controller] Updating role rt-4wcnr in namespace c-xkcxk
rancher-74f4d76887-nw9fm rancher 2023/08/26 01:37:44 [INFO] Updating role rt-4wcnr in c-xkcxk because of rules difference with roleTemplate QL-ClusterAdmin (rt-4wcnr)

Actual behavior:
It is comparing the rules when the 2 roles are the same

Expected behavior:
Not comparison

SURE-6824

@samjustus samjustus added kind/bug Issues that are defects reported by users or that we know have reached a real release area/rbac team/collie the team that is responsible for auth and rbac within rancher priority/0 labels May 16, 2024
@samjustus samjustus added this to the v2.9-Next1 milestone May 16, 2024
@samjustus
Copy link
Collaborator Author

@raulcabello assigning you to this as you worked on #40484

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
area/rbac kind/bug Issues that are defects reported by users or that we know have reached a real release priority/0 team/collie the team that is responsible for auth and rbac within rancher
Projects
None yet
Development

No branches or pull requests

2 participants