Secret Store Service fails to reconcile due to api-aggregator service account permission errors
search cancel

Secret Store Service fails to reconcile due to api-aggregator service account permission errors

book

Article ID: 449235

calendar_today

Updated On:

Products

VMware vSphere Kubernetes Service

Issue/Introduction

  • The Secret Store Service repeatedly fails to reconcile.
  • The permission test with the below command returns "no":

    kubectl auth can-i get configmap/extension-apiserver-authentication -n kube-system --as="system:serviceaccount:svc-secret-store-domain-c##:api-aggregator"

Environment

vSphere Kubernetes Service

Cause

This issue occurs in Secret Store Service because the package does not automatically create the necessary RoleBinding for the api-aggregator service account to access the required extension-apiserver-authentication.

Resolution

This issue has been resolved in the latest releases of the Secret Store Service (9.0.2.0 and above). To remediate this failure, upgrade the Secret Store Service to a compatible version as per Supervisor version. Refer Broadcom Interoperability Matrix

Secret Store Service Download: Broadcom Support Portal