Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

audit: periodic audit job shows everything as deleted #2055

Closed
spiffxp opened this issue May 18, 2021 · 13 comments
Closed

audit: periodic audit job shows everything as deleted #2055

spiffxp opened this issue May 18, 2021 · 13 comments
Assignees
Labels
area/audit Audit of project resources, audit followup issues, code in audit/ kind/bug Categorizes issue or PR as related to a bug. priority/critical-urgent Highest priority. Must be actively worked on as someone's top priority right now.
Milestone

Comments

@spiffxp
Copy link
Member

spiffxp commented May 18, 2021

Uhhhh, well everything in audit/ getting deleted is certainly disconcerting. I'm going to assume the projects are all still present or we'd have heard a lot more complaints by now. Seems like the first commit for this PR deleted everything.

I'm going to guess #2010 is the culprit, specifically 9ebc221. What bindings does the group have that the service account does not?

Originally posted by @spiffxp in #2011 (comment)

@spiffxp
Copy link
Member Author

spiffxp commented May 18, 2021

/kind bug
/wg k8s-infra
/area audit
/priority critical-urgent
/assign

@k8s-ci-robot k8s-ci-robot added the kind/bug Categorizes issue or PR as related to a bug. label May 18, 2021
@k8s-ci-robot
Copy link
Contributor

@spiffxp: The label(s) area/audit cannot be applied, because the repository doesn't have them.

In response to this:

/kind bug
/wg k8s-infra
/area audit
/priority critical-urgent
/assign

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

@k8s-ci-robot k8s-ci-robot added wg/k8s-infra priority/critical-urgent Highest priority. Must be actively worked on as someone's top priority right now. labels May 18, 2021
@spiffxp
Copy link
Member Author

spiffxp commented May 18, 2021

/milestone v1.22

@k8s-ci-robot k8s-ci-robot added this to the v1.22 milestone May 18, 2021
@spiffxp
Copy link
Member Author

spiffxp commented May 19, 2021

https://testgrid.k8s.io/wg-k8s-infra-k8sio#ci-k8sio-audit - is all green

https://prow.k8s.io/view/gs/kubernetes-jenkins/logs/ci-k8sio-audit/1394799000162406400 - shows the following

### Auditing Project k8s-conform
#### k8s-conform IAM
#### k8s-conform ServiceAccounts
#### k8s-conform Roles
#### Services
ERROR: (gcloud.secrets.describe) PERMISSION_DENIED: Permission 'secretmanager.secrets.get' denied for resource 'projects/k8s-conform/secrets/service-cri-o-key' (or it may not exist).
/home/prow/go/src/github.com/kubernetes/k8s.io
Generate pr-creator binary from k/test-infra/robots

So two bugs jump out:

@spiffxp
Copy link
Member Author

spiffxp commented May 19, 2021

/area audit

@k8s-ci-robot
Copy link
Contributor

@spiffxp: The label(s) area/audit cannot be applied, because the repository doesn't have them.

In response to this:

/area audit

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

@spiffxp
Copy link
Member Author

spiffxp commented May 19, 2021

/area infra/audit

@k8s-ci-robot
Copy link
Contributor

@spiffxp: The label(s) area/infra/audit cannot be applied, because the repository doesn't have them.

In response to this:

/area infra/audit

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

@spiffxp
Copy link
Member Author

spiffxp commented May 19, 2021

/area infra/auditing

@k8s-ci-robot k8s-ci-robot added the area/audit Audit of project resources, audit followup issues, code in audit/ label May 19, 2021
@spiffxp
Copy link
Member Author

spiffxp commented May 19, 2021

@spiffxp
Copy link
Member Author

spiffxp commented May 19, 2021

Holding open to confirm the updated job works as expected

@spiffxp
Copy link
Member Author

spiffxp commented May 20, 2021

/close
Confirmed the job works, latest audit PR is up #2067

@k8s-ci-robot
Copy link
Contributor

@spiffxp: Closing this issue.

In response to this:

/close
Confirmed the job works, latest audit PR is up #2067

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
area/audit Audit of project resources, audit followup issues, code in audit/ kind/bug Categorizes issue or PR as related to a bug. priority/critical-urgent Highest priority. Must be actively worked on as someone's top priority right now.
Projects
None yet
Development

No branches or pull requests

2 participants