Harden OpenShift manual-install SCC troubleshooting guidance
@olivergondza ci sta già lavorando.
Dal 15/9/2026.
Valutazione
Questa issue non è ancora stata valutata.
Descrizione
Summary
The OpenShift manual-install documentation recommends granting the privileged SCC to the default ServiceAccount in openshift-gitops-operator when the operator image fails the non-root policy.
Rationale
Granting privileged to default makes it available to every workload that uses that ServiceAccount in the namespace. The guidance should not broaden SCC permissions for unrelated workloads.
Affected area
argocd-operator/docs/install/openshift.md- The
runAsUser breaks non-root policytroubleshooting note in the manual-install section.
Required changes
Replace the default ServiceAccount workaround with guidance that uses a dedicated ServiceAccount for the affected deployment. Identify or recommend the least-privileged SCC that resolves the image policy error. State how to bind that SCC only to the dedicated ServiceAccount.
Acceptance criteria
- The documentation does not instruct users to grant
privilegedSCC todefault. - The affected operator deployment uses a dedicated ServiceAccount when an SCC exception is required.
- The documentation recommends the least-privileged suitable SCC before
privileged. - The guidance explains the scope of the SCC binding.
Backlinks
- PR: https://github.com/redhat-developer/gitops-operator/pull/1294
- Review comment: https://github.com/redhat-developer/gitops-operator/pull/1294#discussion_r4016160278
- Requested by: @olivergondza
- Lingua principale
- Go
- Stelle
- 188
- Fork
- 359
- Merge medio
- 3g 12h
- PR unite (30g)
- 21
Guida per i contributori
Apri la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di redhat-developer/gitops-operator
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 86/100
redhat-developer/gitops-operator#1287 ·
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 45/100
redhat-developer/gitops-operator#1311 ·
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 52/100
redhat-developer/gitops-operator#1139 ·
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 35/100
redhat-developer/gitops-operator#634 · 1 commento ·
-
triage:required
Difficoltà 4/5 3-5 giorni Idoneità per principianti 48/100
redhat-developer/gitops-operator#572 · 2 commenti ·
Tutte le issue di redhat-developer/gitops-operator
Issue simili
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 65/100
-
bug group: validation priority: low
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
codecheckers/chekhov#51 ·
-
Creating worktree from an existing remote branch with a slash in it, has unexpected behaviour Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 70/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100