Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Failed installation on GKE Autopilot #3437

Open
ivan-molodoria opened this issue Dec 8, 2023 · 0 comments
Open

Failed installation on GKE Autopilot #3437

ivan-molodoria opened this issue Dec 8, 2023 · 0 comments
Labels
question Further information is requested

Comments

@ivan-molodoria
Copy link

Hi! I faced with issue during installation on GKE Autopilot cluster/

Error: INSTALLATION FAILED: admission webhook "warden-validating.common-webhooks.networking.gke.io" denied the request: GKE Warden rejected the request because it violates one or more constraints. Violations details: {"[denied by autogke-default-linux-capabilities]":["linux capability 'CAP_CHOWN' on container 'changeowner' not allowed; Autopilot only allows the capabilities: 'AUDIT_WRITE,CHOWN,DAC_OVERRIDE,FOWNER,FSETID,KILL,MKNOD,NET_BIND_SERVICE,NET_RAW,SETFCAP,SETGID,SETPCAP,SETUID,SYS_CHROOT,SYS_PTRACE'."],"[denied by autogke-no-write-mode-hostpath]":["hostPath volume file-storage in container otelcol is accessed in write mode; disallowed in Autopilot.","hostPath volume varlibdockercontainers used in container otelcol uses path /var/lib/docker/containers which is not allowed in Autopilot. Allowed path prefixes for hostPath volumes are: [/var/log/].","hostPath volume file-storage in container changeowner is accessed in write mode; disallowed in Autopilot."]} Requested by user: '<username>', groups: 'system:authenticated'.

Has anyone know how to fix this?

Thanks in advance!

@ivan-molodoria ivan-molodoria added the question Further information is requested label Dec 8, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
question Further information is requested
Projects
None yet
Development

No branches or pull requests

1 participant