Skip to content

fix: OpenShift cleanup container permission denied with PVC storage#2081

Open
kristina-solovyova wants to merge 1 commit intomainfrom
01-16-fix_run_cleanup_container_as_privileged_root_on_openshift_for_pvc-backed_storage
Open

fix: OpenShift cleanup container permission denied with PVC storage#2081
kristina-solovyova wants to merge 1 commit intomainfrom
01-16-fix_run_cleanup_container_as_privileged_root_on_openshift_for_pvc-backed_storage

Conversation

@kristina-solovyova
Copy link
Collaborator

@kristina-solovyova kristina-solovyova commented Jan 16, 2026

Copy link
Collaborator Author


How to use the Graphite Merge Queue

Add the label main-merge-queue to this PR to add it to the merge queue.

You must have a Graphite account in order to use the merge queue. Sign up using this link.

An organization admin has required the Graphite Merge Queue in this repository.

Please do not merge from GitHub as this will restart CI on PRs being processed by the merge queue.

This stack of pull requests is managed by Graphite. Learn more about stacking.

@kristina-solovyova kristina-solovyova marked this pull request as ready for review January 16, 2026 12:16
@graphite-app graphite-app bot requested review from assafgi and tigrawap and removed request for tigrawap January 16, 2026 12:16
@kristina-solovyova kristina-solovyova force-pushed the 01-16-fix_run_cleanup_container_as_privileged_root_on_openshift_for_pvc-backed_storage branch from ff90d52 to cbad1d0 Compare January 16, 2026 12:19
@graphite-app
Copy link

graphite-app bot commented Jan 16, 2026

Graphite Automations

"Add anton/matt/sergey/kristina as reviwers on operator PRs" took an action on this PR • (01/16/26)

2 reviewers were added to this PR based on Anton Bykov's automation.

@kristina-solovyova kristina-solovyova force-pushed the 01-16-fix_run_cleanup_container_as_privileged_root_on_openshift_for_pvc-backed_storage branch from cbad1d0 to d716b7e Compare January 16, 2026 12:21
- Add OpenShift detection for PVC case in cleanup to run as privileged
- Add RunAsUser: 0 to cleanup security context when privileged
- Fix SCC field name from allowedVolumeTypes to volumes (correct OpenShift API)
- Add recommended minimum volume types to all SCCs per OpenShift docs

Ref: https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html/authentication_and_authorization/managing-pod-security-policies
@kristina-solovyova kristina-solovyova force-pushed the 01-16-fix_run_cleanup_container_as_privileged_root_on_openshift_for_pvc-backed_storage branch from d716b7e to 2409852 Compare January 16, 2026 12:23
@assafgi assafgi requested a review from a team as a code owner January 28, 2026 18:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants