Skip to content

TektonConfig from 0.80.0 fails to create pods on MicroShift due to SCC errors #3484

Description

@kastl-ars

Expected Behavior

There should be no errors and all pods should come up properly.

Actual Behavior

Events:
  Type     Reason        Age                  From                   Message
  ----     ------        ----                 ----                   -------
  Warning  FailedCreate  5m1s (x18 over 15m)  replicaset-controller  Error creating: pods "tekton-pipelines-controller-6dccf778c7-" is forbidden: unable to validate against any security context constraint: [provider "anyuid": Forbidden: not usable by user or serviceaccount, provider restricted-v2: .containers[0].runAsUser: Invalid value: 65532: must be in the ranges: [1000220000, 1000229999], provider restricted-v3: .spec.securityContext.hostUsers: Invalid value: null: Host Users must be set to false, provider "restricted": Forbidden: not usable by user or serviceaccount, provider "nonroot-v2": Forbidden: not usable by user or serviceaccount, provider "nonroot": Forbidden: not usable by user or serviceaccount, provider "hostmount-anyuid": Forbidden: not usable by user or serviceaccount, provider "hostnetwork-v2": Forbidden: not usable by user or serviceaccount, provider "hostnetwork": Forbidden: not usable by user or serviceaccount, provider "hostaccess": Forbidden: not usable by user or serviceaccount, provider "privileged": Forbidden: not usable by user or serviceaccount]

The TektonConfig resource is looking like this:

$ k get tektonconfig config
NAME     VERSION   READY   REASON
config   v0.80.0   False   Components not in ready state: TektonPipeline: reconcile again and proceed
$

Steps to Reproduce the Problem

  1. Install the tekton-operator via https://infra.tekton.dev/tekton-releases/operator/latest/release.yaml
  2. Create the TektonConfig from https://raw.githubusercontent.com/tektoncd/operator/main/config/crs/openshift/config/all/operator_v1alpha1_config_cr.yaml
  3. There are deployments and replicaSets, but no pods due to the SCC errors.

Additional Info

Kubernetes version: v1.34.7

This is a OpenShift MicroShift singlenode machine, so there is no GUI and no marketplace to install the official RedHat Pipelines Operator.

Kind Regards,
Johannes

Activity

  1. added
    kind/bugCategorizes issue or PR as related to a bug.
    on Jun 9, 2026
  2. vdemeester commented on Jun 9, 2026

    @vdemeester
    Member

    @kastl-ars I think you are installing the Kubernetes target on an openshift (microshift) cluster. https://infra.tekton.dev/tekton-releases/operator/previous/v0.80.0/openshift-release.yaml should work though.

    cc @tektoncd/operator-maintainers I think we need to update the release note to point to both (it's in the release assets but we don't link it on top of the release notes).

  3. kastl-ars commented on Jun 10, 2026

    @kastl-ars
    Author

    Thanks for the hint, I'll try that. I was not aware of an openshift-release.yaml...

    Could you please fix the documentation to mention that? The documentation really needs some love, if you don't mind me saying that...

    https://github.com/tektoncd/operator/blob/main/docs/install.md

  4. kastl-ars commented on Jun 10, 2026

    @kastl-ars
    Author

    Thanks for the hint, I'll try that. I was not aware of an openshift-release.yaml...

    Using this file, I get one CRD always being shown as outdated in ArgoCD: openshiftpipelinesascodes.operator.tekton.dev

    The bigger problem seems to be that MicroShift does not provide the apiservers.config.openshift.io CRD. The openshift-pipelines-operator pod crashes:

    {"level":"panic","timestamp":"2026-06-10T06:18:20.011Z","logger":"tekton-operator-lifecycle","caller":"tektonconfig/controller.go:62","msg":"Couldn't setup APIServer TLS profile watch: accessing APIServer resource: the server could not find the requested resource (get apiservers.config.openshift.io cluster)","commit":"ca2b95e-dirty","knative.dev/pod":"openshift-pipelines-operator-65cdd899b4-gjpth","stacktrace":"github.com/tektoncd/operator/pkg/reconciler/openshift/tektonconfig.NewController\n\tgithub.com/tektoncd/operator/pkg/reconciler/openshift/tektonconfig/controller.go:62\nknative.dev/pkg/injection/sharedmain.ControllersAndWebhooksFromCtors\n\tknative.dev/pkg@v0.0.0-20260406140200-cb58ae50e894/injection/sharedmain/main.go:534\nknative.dev/pkg/injection/sharedmain.MainWithConfig\n\tknative.dev/pkg@v0.0.0-20260406140200-cb58ae50e894/injection/sharedmain/main.go:299\ngithub.com/tektoncd/operator/pkg/reconciler/platform.startMain\n\tgithub.com/tektoncd/operator/pkg/reconciler/platform/platform.go:112\ngithub.com/tektoncd/operator/pkg/reconciler/platform.StartMainWithSelectedControllers\n\tgithub.com/tektoncd/operator/pkg/reconciler/platform/platform.go:130\nmain.main\n\tgithub.com/tektoncd/operator/cmd/openshift/operator/main.go:27\nruntime.main\n\truntime/proc.go:285"}
    panic: Couldn't setup APIServer TLS profile watch: accessing APIServer resource: the server could not find the requested resource (get apiservers.config.openshift.io cluster)
    

    I'll dig into this and see if I can fix it somehow...

  5. kastl-ars commented on Jun 11, 2026

    @kastl-ars
    Author

    The bigger problem seems to be that MicroShift does not provide the apiservers.config.openshift.io CRD.

    OK, so this seems to be a fundamental (but intentional) difference between OpenShift and MicroShift.

    I could get the operator installed and running from the operatorhub.

    But the error with the TektonConfig stays the same, I have deployments without pods due to SCC errors...

  6. vdemeester commented on Jun 11, 2026

    @vdemeester
    Member

    cc @tektoncd/operator-maintainers

  7. jkhelil commented on Jun 15, 2026

    @jkhelil
    Member

    HI @enarha, Can you have a look please, microshift doesnt expose apiservers.config.openshift.io, we need to make the code more reliable and fix the panic
    In the mean time @kastl-ars You can set enableCentralTLSConfig: to false (under Tektonconfig>Openshift), that will disable collecting tls profile from apiservers.config.openshift.io

  8. self-assigned this
    on Jun 15, 2026
  9. enarha commented on Jun 15, 2026

    @enarha
    Contributor

    Indeed the code expects the APIServer CRD to exist on every OpenShift cluster. I did test that with older OpenShift version and I believe I also tested ROSA/HyperShift. I was not aware of the MicroShift flavor and I'll have a look. Thanks for reporting the issue.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

kind/bugCategorizes issue or PR as related to a bug.

Type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions