-
Notifications
You must be signed in to change notification settings - Fork 47
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
gMSA question/issue #382
Comments
Hey, I'm wondering how you use gMSA with AKS Arc. We have gMSA for containers with a non-domain joined host in use. The credspec file and permissions are done by Add-AksHciGMSACredentialSpec. Why do you use |
I'm not using docker run to run the container. I followed the instructions you referenced to install the webhook via powershell, and to properly annotate pods to use it. Everything works as expected except intermittently, one specific api call will fail: when you attempt to translate a Sid to an account name or vice-versa. More generally, I can see from this command This appears to be a much older version than the latest release on https://github.com/kubernetes-sigs/windows-gmsa/releases I could try deploying the web hook directly from there to get the latest version, but I'd rather Microsoft update the image used with Install-AksHciGMSAWebhook so I don't have to. |
I've run into this issue on an AKS on Windows Server Cluster microsoft/Windows-Containers#405
It appears there may be a fix available. However, in the case of AKS on Windows Server, the gMSA Web Hook is installed through Powershell. Will the updated webhook be incorporated into a new release? Or is there another way to update the webhook?
The text was updated successfully, but these errors were encountered: