green-spoon-79486
04/05/2024, 7:42 PMAdmission webhook "<http://rancher.cattle.io.clusterroletemplatebindings.management.cattle.io|rancher.cattle.io.clusterroletemplatebindings.management.cattle.io>" denied the request: user "system:serviceaccount:cattle-system:rancher" (groups=["system:serviceaccounts" "system:serviceaccounts:cattle-system" "system:authenticated"]) is attempting to grant RBAC permissions not currently held: {NonResourceURLs:["*"], Verbs:["*"]}
It appears there is no service account, clusterrole or clusterrolebinding for system:serviceaccount:cattle-system
. I'm not finding much about what rancher is doing with RBAC inside the cluster. Does anyone have any info on this? Why is Rancher not creating the service account / clusterrole / clusterrolebinding it needs to create a cluster?