IBM Support

LI82719: INSTALLATION OF MANAGEMENT SUBSYSTEM STUCK IN PENDING STATE

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • Azure deployment of apiconnect failing because of
    
    message: 'admission webhook "validation.gatekeeper.sh" denied
    the request: [azurepolicy-k8sazurecontainernoprivilegees-9da38b
    cc8a9e804xxxxx]Privilege escalation container is not allowed: se
    

Local fix

  • Explicitly setting allowPrivilegeEscalation: false in the
    initContainers SecurityContext section.
    
    temporarily disabling the policy
    
    Once postgres is deployed edit the 3 postgres deployments (
    leader and 2 replicas ) and add
    
    allowPrivilegeEscalation: false
    
    to Security Context of initContainers
    
    Once deployment is over the policy can be added back again but
    note for any upgrade or scenario that will involve pgcluster
    being removed ( for example change to S3 backup settings ) we
    will need to apply the workaround again until the fix arrives
    

Problem summary

  • In certain customer Azure systems when
    azurepolicy-k8sazurecontainernoprivilegees is enabled APIC
    installation will be blocked as init container called
    set-libpq-certs is not complaint with the policy requirements
    

Problem conclusion

  • Fixed in 10.0.5.2 and greater
    
    Fix is to add proper security context for the affected init
    container
    

Temporary fix

Comments

APAR Information

  • APAR number

    LI82719

  • Reported component name

    API CONNECT ENT

  • Reported component ID

    5725Z2201

  • Reported release

    A0X

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2022-08-23

  • Closed date

    2022-12-12

  • Last modified date

    2023-01-27

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    API CONNECT ENT

  • Fixed component ID

    5725Z2201

Applicable component levels

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSMNED","label":"IBM API Connect"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"A0X","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
27 January 2023