Repository navigation
TektonConfig from 0.80.0 fails to create pods on MicroShift due to SCC errors #3484
Description
Activity
- addedkind/bugCategorizes issue or PR as related to a bug.Categorizes issue or PR as related to a bug.
on Jun 9, 2026 @kastl-ars I think you are installing the Kubernetes target on an openshift (microshift) cluster. https://infra.tekton.dev/tekton-releases/operator/previous/v0.80.0/openshift-release.yaml should work though.
cc @tektoncd/operator-maintainers I think we need to update the release note to point to both (it's in the release assets but we don't link it on top of the release notes).
Thanks for the hint, I'll try that. I was not aware of an
openshift-release.yaml...Could you please fix the documentation to mention that? The documentation really needs some love, if you don't mind me saying that...
https://github.com/tektoncd/operator/blob/main/docs/install.md
Thanks for the hint, I'll try that. I was not aware of an
openshift-release.yaml...Using this file, I get one CRD always being shown as outdated in ArgoCD:
openshiftpipelinesascodes.operator.tekton.devThe bigger problem seems to be that MicroShift does not provide the
apiservers.config.openshift.ioCRD. The openshift-pipelines-operator pod crashes:{"level":"panic","timestamp":"2026-06-10T06:18:20.011Z","logger":"tekton-operator-lifecycle","caller":"tektonconfig/controller.go:62","msg":"Couldn't setup APIServer TLS profile watch: accessing APIServer resource: the server could not find the requested resource (get apiservers.config.openshift.io cluster)","commit":"ca2b95e-dirty","knative.dev/pod":"openshift-pipelines-operator-65cdd899b4-gjpth","stacktrace":"github.com/tektoncd/operator/pkg/reconciler/openshift/tektonconfig.NewController\n\tgithub.com/tektoncd/operator/pkg/reconciler/openshift/tektonconfig/controller.go:62\nknative.dev/pkg/injection/sharedmain.ControllersAndWebhooksFromCtors\n\tknative.dev/pkg@v0.0.0-20260406140200-cb58ae50e894/injection/sharedmain/main.go:534\nknative.dev/pkg/injection/sharedmain.MainWithConfig\n\tknative.dev/pkg@v0.0.0-20260406140200-cb58ae50e894/injection/sharedmain/main.go:299\ngithub.com/tektoncd/operator/pkg/reconciler/platform.startMain\n\tgithub.com/tektoncd/operator/pkg/reconciler/platform/platform.go:112\ngithub.com/tektoncd/operator/pkg/reconciler/platform.StartMainWithSelectedControllers\n\tgithub.com/tektoncd/operator/pkg/reconciler/platform/platform.go:130\nmain.main\n\tgithub.com/tektoncd/operator/cmd/openshift/operator/main.go:27\nruntime.main\n\truntime/proc.go:285"} panic: Couldn't setup APIServer TLS profile watch: accessing APIServer resource: the server could not find the requested resource (get apiservers.config.openshift.io cluster)I'll dig into this and see if I can fix it somehow...
The bigger problem seems to be that MicroShift does not provide the
apiservers.config.openshift.ioCRD.OK, so this seems to be a fundamental (but intentional) difference between OpenShift and MicroShift.
I could get the operator installed and running from the operatorhub.
But the error with the TektonConfig stays the same, I have deployments without pods due to SCC errors...
cc @tektoncd/operator-maintainers
HI @enarha, Can you have a look please, microshift doesnt expose apiservers.config.openshift.io, we need to make the code more reliable and fix the panic
In the mean time @kastl-ars You can set enableCentralTLSConfig: to false (under Tektonconfig>Openshift), that will disable collecting tls profile from apiservers.config.openshift.ioIndeed the code expects the APIServer CRD to exist on every OpenShift cluster. I did test that with older OpenShift version and I believe I also tested ROSA/HyperShift. I was not aware of the MicroShift flavor and I'll have a look. Thanks for reporting the issue.
Expected Behavior
There should be no errors and all pods should come up properly.
Actual Behavior
The
TektonConfigresource is looking like this:Steps to Reproduce the Problem
https://infra.tekton.dev/tekton-releases/operator/latest/release.yamlTektonConfigfromhttps://raw.githubusercontent.com/tektoncd/operator/main/config/crs/openshift/config/all/operator_v1alpha1_config_cr.yamlAdditional Info
Kubernetes version: v1.34.7
This is a OpenShift MicroShift singlenode machine, so there is no GUI and no marketplace to install the official RedHat Pipelines Operator.
Kind Regards,
Johannes