Loading...
Loading...
Cloned-restore jobs time-out and eventually fail due to an ImagePullError. Upon further investigation, the root cause is that the default SA (in the target namespace) does not have ImageStreams for the pod to pull an image from a private registry. Failed to pull image "image-registry.openshift-image-registry.svc:5000/testify-ps/runner@sha256:9317d61bb7943fb2b3f0d62c37aab233a07a3e0ccc67b104a7e3e69cb778dea0": rpc error: code = Unknown desc = Error reading manifest sha256:9317d61bb7943fb2b3f0d62c37aab233a07a3e0ccc67b104a7e3e69cb778dea0 in image-registry.openshift-image-registry.svc:5000/testify-ps/runner: unauthorized: authentication required
In Openshift 4.x, pods can pull images with the use of ImageStreams. ImageStreamTag represents an image that is retrieved by tag name from an ImageStream. If these are hard-coded in a service account, pods in the target namespace will fail to come up with an ImagePullError. Example Namespace = testify-ps SA = default Target namespace = testify-ps-restore
Identify missing ImageStreamTag(s) Compare information about the source and target namespaces to identify the missing ImageStreamTag(s), then use one of the three options described in the next section to resolve this issue. Use the following command to get show namespace information:
Click on a version to see all relevant bugs
Veeam Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.