Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

Group impersonation fails in Console with Direct Authentication: "Failed to load groups - Model does not exist"

Abierto
#17,030 1 comentario 0 reacciones 0 asignados Ver en GitHub

Los mantenedores suelen responder en 1 día

Nadie ha tomado este issue todavía.

Evaluación

Dificultad
3/5
Tiempo estimado
1-2 días
Aptitud para principiantes
67/100
Tipo de issue
Error
Claridad
Bastante claro
Estado de actividad
Tranquilo
Stack tecnológico
typescript

Línea de trabajo

Comienza en el modal “Impersonate user” de la cabecera de Console y en su selector de grupos, que actualmente intenta enumerar recursos Group. Sigue el flujo de carga y envío del selector y verifica después que uno o varios nombres de grupo introducidos manualmente funcionan sin requerir el modelo group.openshift.io y que se evita el error del modelo.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

Summary

When Direct Authentication (structured authentication / external OIDC, aka "BYO" OIDC) is enabled on OpenShift, the built-in OAuth group.openshift.io model no longer exists. User impersonation continues to work fine — the masthead "Impersonate user" flow accepts a username and impersonates it as expected. The problem is scoped to the groups portion of that same modal: when attempting to add groups to an impersonation request, the UI tries to build a selectable list from all Group resources in the cluster. Because the Group model does not exist under Direct Authentication, the groups selector fails with:

Failed to load groups
Model does not exist
Image

Group impersonation itself is still valid and useful in this mode — Kubernetes RBAC continues to honor impersonated groups (Impersonate-Group) regardless of whether the OpenShift group.openshift.io model exists. The problem is purely in the UI's assumption that a discoverable pool of Group resources exists to populate a selectable list.

Version

  • OpenShift Container Platform: 4.22
  • Console: shipped with OCP 4.22
  • Auth mode: Direct Authentication (structured authentication / external OIDC)

Steps to reproduce

  1. Configure a cluster to use Direct Authentication (structured authentication /
    external OIDC), so the built-in group.openshift.io model is gone.
  2. In the Console masthead, open the user menu and choose Impersonate user.
  3. Enter a username — user impersonation works as expected.
  4. Attempt to add/select groups for the impersonation request.
  5. Observe the failed to load groups - model does not exist error; the groups
    selector cannot load.

Current behavior

User impersonation works. Only the groups selector in the impersonation modal is broken: it attempts to enumerate group.openshift.io Group resources to populate a selectable groups list. Under Direct Authentication that model does not exist, so the request fails and group impersonation is unusable in the UI.

Expected behavior

Group impersonation must still work under Direct Authentication. The fix is in
the UI:

  • Allow free-form entry of group names instead of enumerating cluster
    Group resources.
  • Preserve multiple-group impersonation. The current GUI already supports
    selecting multiple groups, and kubectl supports it via a repeatable
    --as-group flag. Free-form entry must likewise accept one or more group
    names.
  • Gracefully handle the absence of the group.openshift.io model — do not
    hard-fail with "model does not exist" when the model is unavailable.

In short: replace the enumerated/selectable group list with free-form entry of one or more group names, preserving the existing multi-group capability.

Non-goal

There is intentionally no authoritative pool of groups to list in this mode. The only way to synthesize one would be to extrapolate group names from RoleBinding / ClusterRoleBinding subjects, which is undesirable (incomplete, misleading, and not a real source of truth) and should not be done. Free-form entry of one or more group names is the correct fix.

Impact

As clusters move to Direct Authentication, the OpenShift group.openshift.io model is eliminated. User impersonation still works, but the Console's dependency on enumerating cluster Group resources makes group impersonation unusable in the UI under Direct Authentication — even though group impersonation remains valid and enforced by Kubernetes RBAC.

Frequency

Reproducible — occurs every time group impersonation is attempted while Direct Authentication is enabled.

Related

  • Jira RFE: RFE-9146 (service account impersonation in the Console)
  • Related PR: openshift/console#17026 — adds first-class service account
    impersonation to the masthead modal (same modal that owns the group selector)
  • Red Hat support case: 04520499
Lenguaje dominante
TypeScript
Estrellas
460
Forks
763
Merge medio
3 d 22 h
PR fusionados (30 d)
72

Preparar el entorno

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de openshift/console

Todos los issues de openshift/console

Issues similares

Más issues de TypeScript

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.