Error presenting challenge: secrets "ovh-credentials" is forbidden

Viewed 75

Situation (Resolved)

I am trying to create a certificate using cert-manager for ovh on kubernetes.

Problem

The challenge created by the certificate shows the following error:

Error presenting challenge: secrets "ovh-credentials" is forbidden: User "system:serviceaccount:default:cert-manager-webhook-ovh-1658181107" cannot get resource "secrets" in API group "" in the namespace "default"

Information

I checked the ovh-credentials existed in the default namespace:

$ kubectl get secret -n default
NAME                                                        TYPE                 DATA   AGE
ovh-credentials                                             Opaque               1      22m

Here is my current Certificate:

apiVersion: cert-manager.io/v1
kind: Certificate
metadata:
  name: altarise-registry-cert # name of the certificate
  labels:
    app.kubernetes.io/name: altarise-registry-cert # name of the certificate
    app.kubernetes.io/tier: backend
    app.kubernetes.io/managed-by: Ops
spec:
  dnsNames:
  - registry.altarise.net # name of the domain you want to validate the certificate
  issuerRef:
    name: ovh-altarise # name of the issuer you created before
    kind: Issuer
  secretName: altarise-registry-cert

Resolution

I found out I put the wrong serviceAccount name inside my RoleAccount that gives access to secrets.

1 Answers

Posting your resolution as an answer, for greater visibility for community members.

The error message indicates to ServiceAccount cert-manager-webhook-ovh of default namespace. In this type of scenario there might be two possibilities, that is:

  1. One reason could be you are giving permission to the ServiceAccount of a different namespace. But in your use case the namespace specified has been mentioned correctly.
  2. The other one could be the Service Account mentioned in the Role while granting permission to get the secret to the cert-manager-webhook-ovh service account might be mentioned incorrectly. So, check whether the Service Account which is mentioned in Role is the correct one.

You can refer to the Github link for more information on granting permission to get the secret to the cert-manager-webhook-ovh service account.

Related