Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Fix ComputeDomain daemon permissions on OpenShift

Closed
#3,010 1 comment 0 reactions 1 assignee View on GitHub

Maintainers usually reply within 1 day

@rahulait is already working on this.

Since Oct 5, 2026.

  • #3011 by @rahulait — open

Assessment

This issue has not been assessed yet.

Description

bug

Description:

When testing MNNVL on OpenShift 4.22.1 with NVL72 nodes and GPU Operator v26.7.1, ComputeDomain daemon Pods encounter two permission failures:

  1. Incorrect SCC selection: Pods are admitted under restricted-v2 and crash because they cannot write /imexd/imexd.cfg. Although the daemon’s service account is listed in the nvidia-dra-driver SCC, that SCC has no priority, allowing OpenShift to prefer restricted-v2.
  2. Missing RBAC permission: The daemon’s ClusterRole lacks delete on computedomaincliques.resource.nvidia.com. Owner-reference admission rejects its requests with:
   cannot set an ownerRef on a resource you can't delete

Expected behavior:

ComputeDomain daemon Pods should start successfully and manage clique owner references.

Proposed fix:

Give the custom DRA SCC a positive priority and add the missing clique permission to both the daemon’s ClusterRole and the Operator’s Helm/OLM RBAC.

Dominant language
Go
Stars
2.9k
Forks
569
Avg merge
1d 10h
Merged PRs (30d)
78

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from NVIDIA/gpu-operator

All issues in NVIDIA/gpu-operator

Similar issues

More Go issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.