Group impersonation fails in Console with Direct Authentication: "Failed to load groups - Model does not exist"
Los mantenedores suelen responder en 1 día
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 3/5
- Tiempo estimado
- 1-2 días
- Aptitud para principiantes
- 67/100
- Tipo de issue
- Error
- Claridad
- Bastante claro
- Estado de actividad
- Tranquilo
- Stack tecnológico
- typescript
- Área
- authorization, frontend
Línea de trabajo
Comienza en el modal “Impersonate user” de la cabecera de Console y en su selector de grupos, que actualmente intenta enumerar recursos Group. Sigue el flujo de carga y envío del selector y verifica después que uno o varios nombres de grupo introducidos manualmente funcionan sin requerir el modelo group.openshift.io y que se evita el error del modelo.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Summary
When Direct Authentication (structured authentication / external OIDC, aka "BYO" OIDC) is enabled on OpenShift, the built-in OAuth group.openshift.io model no longer exists. User impersonation continues to work fine — the masthead "Impersonate user" flow accepts a username and impersonates it as expected. The problem is scoped to the groups portion of that same modal: when attempting to add groups to an impersonation request, the UI tries to build a selectable list from all Group resources in the cluster. Because the Group model does not exist under Direct Authentication, the groups selector fails with:
Failed to load groups
Model does not exist
Group impersonation itself is still valid and useful in this mode — Kubernetes RBAC continues to honor impersonated groups (Impersonate-Group) regardless of whether the OpenShift group.openshift.io model exists. The problem is purely in the UI's assumption that a discoverable pool of Group resources exists to populate a selectable list.
Version
- OpenShift Container Platform: 4.22
- Console: shipped with OCP 4.22
- Auth mode: Direct Authentication (structured authentication / external OIDC)
Steps to reproduce
- Configure a cluster to use Direct Authentication (structured authentication /
external OIDC), so the built-ingroup.openshift.iomodel is gone. - In the Console masthead, open the user menu and choose Impersonate user.
- Enter a username — user impersonation works as expected.
- Attempt to add/select groups for the impersonation request.
- Observe the
failed to load groups - model does not existerror; the groups
selector cannot load.
Current behavior
User impersonation works. Only the groups selector in the impersonation modal is broken: it attempts to enumerate group.openshift.io Group resources to populate a selectable groups list. Under Direct Authentication that model does not exist, so the request fails and group impersonation is unusable in the UI.
Expected behavior
Group impersonation must still work under Direct Authentication. The fix is in
the UI:
- Allow free-form entry of group names instead of enumerating cluster
Groupresources. - Preserve multiple-group impersonation. The current GUI already supports
selecting multiple groups, andkubectlsupports it via a repeatable
--as-groupflag. Free-form entry must likewise accept one or more group
names. - Gracefully handle the absence of the
group.openshift.iomodel — do not
hard-fail with "model does not exist" when the model is unavailable.
In short: replace the enumerated/selectable group list with free-form entry of one or more group names, preserving the existing multi-group capability.
Non-goal
There is intentionally no authoritative pool of groups to list in this mode. The only way to synthesize one would be to extrapolate group names from RoleBinding / ClusterRoleBinding subjects, which is undesirable (incomplete, misleading, and not a real source of truth) and should not be done. Free-form entry of one or more group names is the correct fix.
Impact
As clusters move to Direct Authentication, the OpenShift group.openshift.io model is eliminated. User impersonation still works, but the Console's dependency on enumerating cluster Group resources makes group impersonation unusable in the UI under Direct Authentication — even though group impersonation remains valid and enforced by Kubernetes RBAC.
Frequency
Reproducible — occurs every time group impersonation is attempted while Direct Authentication is enabled.
Related
- Jira RFE: RFE-9146 (service account impersonation in the Console)
- Related PR: openshift/console#17026 — adds first-class service account
impersonation to the masthead modal (same modal that owns the group selector) - Red Hat support case: 04520499
- Lenguaje dominante
- TypeScript
- Estrellas
- 460
- Forks
- 763
- Merge medio
- 3 d 22 h
- PR fusionados (30 d)
- 72
Preparar el entorno
- Incluye un Dockerfile o un archivo de Docker Compose
- Tiene una plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de openshift/console
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
openshift/console#16866 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
Los mantenedores suelen responder en 1 día
-
Dificultad 5/5 Más de una semana Aptitud para principiantes 35/100
Los mantenedores suelen responder en 1 día
Todos los issues de openshift/console
Issues similares
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
Los mantenedores suelen responder en 1 día
-
automated issue report
Dificultad 1/5 Menos de una hora Aptitud para principiantes 68/100
-
documentation
Dificultad 1/5 Menos de una hora Aptitud para principiantes 92/100
github/copilot-sdk#2804 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 62/100
drizzle-team/drizzle-orm#6418 ·
Los mantenedores suelen responder en 4 días
-
Dificultad 1/5 Menos de una hora Aptitud para principiantes 92/100
diegosouzapw/OmniRoute#15307 · 1 comentario ·
Los mantenedores suelen responder en 2 días