Skip to content

feat(chaos): integrate operator-chaos L3 SDK tests for both controllers - #834

Merged
openshift-merge-bot[bot] merged 1 commit into
opendatahub-io:mainfrom
jstourac:operatorChaos2
Jul 13, 2026
Merged

openshift-merge-bot[bot] merged 1 commit into
opendatahub-io:mainfrom
jstourac:operatorChaos2

Conversation

@jstourac

@jstourac jstourac commented Jun 9, 2026 •

Copy link
Copy Markdown
Member

Jira: RHOAIENG-70591

Summary

Add Level 3 operator-chaos integration with ChaosClient SDK tests for
both the ODH and upstream notebook reconcilers, using isolated envtest
environments (no controller manager) for deterministic fault injection.

What changed

  • Add operator-chaos/pkg/sdk as a Go dependency in both controllers;
    sync k8s API versions to v0.35.2 in notebook-controller
  • Create chaostests/ packages with isolated envtest setup (API server +
    etcd only) enabling deterministic Create/Delete fault testing
  • ODH controller: 10 Ginkgo specs covering Get, List, Create, Update,
    Delete faults, transient recovery, and intermittent errors
  • Upstream controller: 7 Ginkgo specs covering Get, List, Create faults,
    transient recovery, and intermittent errors (no Update-no-drift or
    Delete tests as the reconciler always detects StatefulSet drift and
    does not handle finalizers)
  • Add 5 experiment YAMLs under chaos/experiments/ adapted from upstream
    (pod-kill, network-partition, webhook-disrupt, rbac-revoke,
    deployment-scale-zero)
  • Add make test-chaos Makefile targets with -coverpkg=./controllers/...
    for accurate coverage attribution
  • Extend CI workflow to validate experiments, run chaos SDK tests, and
    upload coverage to Codecov with a dedicated chaos flag
  • Update AGENTS.md and component READMEs with chaos testing documentation

Co-authored-by: Cursor cursoragent@cursor.com


Adds Level 3 of the operator-chaos shift-left integration for workbenches, building on the L1+L2 foundation merged in #832. This follows the pattern established in model-registry-operator PR #525.

Test plan

  • make test-chaos — 6 passed, 0 failed
  • make test (full ODH suite) — 130 passed, 0 failed (no regressions)
  • make test (upstream notebook-controller) — all passed
  • make chaos-validate — knowledge model valid, preflight passed
  • CI workflow runs successfully on PR

  • The commits are squashed in a cohesive manner and have meaningful messages.
  • Testing instructions have been added in the PR body (for PRs involving changes that are not immediately obvious).
  • The developer has manually tested the changes and verified that the changes work

Summary by CodeRabbit

  • New Features
    • Expanded chaos validation in CI to validate all experiment definitions and run chaos coverage tests for both notebook controllers, with results uploaded to Codecov.
    • Added new chaos experiment scenarios (pod kill, deployment scale-down, network partition, RBAC revoke, and webhook disruption).
  • Tests
    • Introduced make test-chaos targets to run ChaosClient SDK resilience tests locally for both components.
  • Documentation
    • Updated chaos validation and maintenance guidance, including new maturity level expectations and experiment/knowledge model workflow.

@openshift-ci

openshift-ci Bot commented Jun 9, 2026

Copy link
Copy Markdown

Skipping CI for Draft Pull Request.
If you want CI signal for your change, please convert it to an actual PR.
You can still manually trigger a test run with /test all

@coderabbitai

coderabbitai Bot commented Jun 9, 2026 •

Copy link
Copy Markdown
📝 Walkthrough

Walkthrough

Changes

The PR adds operator-chaos validation for both notebook controllers: CI trigger expansion, experiment YAML validation, new test-chaos targets, envtest-based chaos suites, shared test image wiring, and updated module dependencies. It also adds five chaos experiment manifests and updates AGENTS/README guidance for L1-L3 validation, local execution, and maintenance.

Estimated code review effort: 4 (Complex) | ~60 minutes

Sequence Diagram(s)

sequenceDiagram
  participant GitHubActions
  participant operator-chaos
  participant make test-chaos
  GitHubActions->>operator-chaos: validate chaos/experiments/*.yaml
  GitHubActions->>make test-chaos: run notebook-controller and odh-notebook-controller chaos suites
Loading

Supply-chain findings

  • github.com/opendatahub-io/operator-chaos is added via pseudo-version in both go.mod files. Treat this as a supply-chain entry point; verify go.sum and module provenance. CWE-829.
  • .github/workflows/operator_chaos_validation.yaml executes operator-chaos validate in CI. If the binary is fetched externally, pin and verify integrity. CWE-494.
  • rbac-revoke.yaml and webhook-disrupt.yaml encode dangerous actions (allowDangerous: true, failurePolicy: Ignore). Keep execution strictly gated to schema validation; accidental live execution would create authorization and admission-control exposure. CWE-863.
🚥 Pre-merge checks | ✅ 10
✅ Passed checks (10 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Contribution Quality And Spam Detection ✅ Passed Broad, repo-specific changes across tests/CI/docs with a Jira link; only one mild templated-content signal, no second category.
No Hardcoded Secrets ✅ Passed No CWE-798 indicators in the changed files: no hardcoded creds, embedded-credential URLs, or long base64 blobs; only test fixtures and a GitHub secret reference.
No Weak Cryptography ✅ Passed No CWE-327/328/208 findings: changed files add no banned primitives, custom crypto, or secret/token/HMAC comparisons.
No Injection Vectors ✅ Passed No CWE-89/78/94/502/79 sinks found; workflow and Makefile shell steps use fixed constants/paths, not untrusted input.
No Privileged Containers ✅ Passed Changed chaos YAMLs contain no privileged/host*/*allowPrivilegeEscalation fields; runtime images remain non-root. No CWE-250 issue introduced.
No Sensitive Data In Logs ✅ Passed No new CWE-532-style leaks found; added logs are generic test harness output, and workflow/Makefile changes don't echo secrets or raw bodies.
Title check ✅ Passed The title accurately captures the main change: integrating operator-chaos L3 SDK tests for both controllers.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@openshift-ci openshift-ci Bot added the size/xl label Jun 9, 2026
@jstourac jstourac changed the title wip feat(chaos): integrate ChaosClient SDK tests and experiment YAMLs (L3) Jun 9, 2026
@openshift-ci openshift-ci Bot added size/xl and removed size/xl labels Jun 9, 2026
@openshift-ci openshift-ci Bot added size/xl and removed size/xl labels Jun 9, 2026
@codecov-commenter

codecov-commenter commented Jun 9, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 64.69%. Comparing base (5d0d761) to head (f7a47c1).

Additional details and impacted files

Impacted file tree graph

@@            Coverage Diff             @@
##             main     #834      +/-   ##
==========================================
+ Coverage   63.75%   64.69%   +0.94%     
==========================================
  Files          15       15              
  Lines        2974     2974              
==========================================
+ Hits         1896     1924      +28     
+ Misses        895      874      -21     
+ Partials      183      176       -7     
Flag Coverage Δ
chaos 17.41% <ø> (?)
notebook-controller 35.38% <ø> (ø)
odh-notebook-controller 73.12% <ø> (-0.18%) ⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.
see 5 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@rhods-ci-bot

Copy link
Copy Markdown

/group-test

Comment thread components/odh-notebook-controller/go.mod Outdated
@jstourac jstourac self-assigned this Jun 11, 2026
@openshift-ci openshift-ci Bot added size/l and removed size/xl labels Jun 19, 2026
@rhods-ci-bot

Copy link
Copy Markdown

/group-test

@openshift-ci openshift-ci Bot added size/l and removed size/l labels Jun 22, 2026
@openshift-ci openshift-ci Bot added size/l and removed size/l labels Jun 29, 2026
@rhods-ci-bot

Copy link
Copy Markdown

/group-test

@openshift-ci openshift-ci Bot added size/l and removed size/l labels Jun 30, 2026
@rhods-ci-bot

Copy link
Copy Markdown

/group-test

@openshift-ci openshift-ci Bot added size/xxl and removed size/xxl labels Jul 1, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
components/notebook-controller/chaostests/suite_test.go (1)

28-29: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚖️ Poor tradeoff

Ginkgo v1 is unsupported upstream.

Ginkgo v1 (github.com/onsi/ginkgo) reached its end of maintenance and the project states "you are using Ginkgo V2 (V1 is no longer supported - see here for the migration guide)". Building new chaos test infrastructure on an unsupported major version means no further bugfixes/security patches for the test framework itself, and blocks future dependency upgrades that assume v2 (e.g., transitive packages that dot-import ginkgo/v2 will conflict at init time).

Also applies to: 36-38

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@components/notebook-controller/chaostests/suite_test.go` around lines 28 -
29, Update the chaos test suite to use Ginkgo v2 instead of the unsupported v1
dot-imports. In suite_test.go, replace the current ginkgo/gomega imports used by
the suite setup and any related helpers with the v2 packages and adjust any
affected symbols such as RunSpecs, RegisterFailHandler, and Expect to their
v2-compatible usage. Make the same migration anywhere else in the chaos test
package that still imports the old Ginkgo v1 symbols so the suite compiles
cleanly on a single supported major version.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@components/odh-notebook-controller/README.md`:
- Around line 216-218: Update the maintenance directive in the README snippet to
match the coding guideline by changing the non-committal “consider adding”
wording to an imperative “add” in the sentence about new sub-reconcilers or API
operations, so the instruction clearly points to adding corresponding
ChaosClient SDK test scenarios in chaostests/chaos_test.go.

---

Nitpick comments:
In `@components/notebook-controller/chaostests/suite_test.go`:
- Around line 28-29: Update the chaos test suite to use Ginkgo v2 instead of the
unsupported v1 dot-imports. In suite_test.go, replace the current ginkgo/gomega
imports used by the suite setup and any related helpers with the v2 packages and
adjust any affected symbols such as RunSpecs, RegisterFailHandler, and Expect to
their v2-compatible usage. Make the same migration anywhere else in the chaos
test package that still imports the old Ginkgo v1 symbols so the suite compiles
cleanly on a single supported major version.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Central YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Enterprise

Run ID: 41d7f33a-968b-49c3-83c6-bd718e6d9a0d

📥 Commits

Reviewing files that changed from the base of the PR and between 4a3e7c6 and 870a243.

⛔ Files ignored due to path filters (2)
  • components/notebook-controller/go.sum is excluded by !**/*.sum, !**/*.sum
  • components/odh-notebook-controller/go.sum is excluded by !**/*.sum, !**/*.sum
📒 Files selected for processing (20)
  • .github/workflows/operator_chaos_validation.yaml
  • AGENTS.md
  • chaos/experiments/deployment-scale-zero.yaml
  • chaos/experiments/network-partition.yaml
  • chaos/experiments/pod-kill.yaml
  • chaos/experiments/rbac-revoke.yaml
  • chaos/experiments/webhook-disrupt.yaml
  • components/notebook-controller/Makefile
  • components/notebook-controller/README.md
  • components/notebook-controller/chaostests/chaos_test.go
  • components/notebook-controller/chaostests/suite_test.go
  • components/notebook-controller/go.mod
  • components/odh-notebook-controller/Makefile
  • components/odh-notebook-controller/README.md
  • components/odh-notebook-controller/chaostests/chaos_test.go
  • components/odh-notebook-controller/chaostests/suite_test.go
  • components/odh-notebook-controller/controllers/notebook_controller_test.go
  • components/odh-notebook-controller/controllers/notebook_mlflow_test.go
  • components/odh-notebook-controller/controllers/suite_test.go
  • components/odh-notebook-controller/go.mod
✅ Files skipped from review due to trivial changes (3)
  • chaos/experiments/rbac-revoke.yaml
  • components/notebook-controller/README.md
  • components/odh-notebook-controller/controllers/suite_test.go
🚧 Files skipped from review as they are similar to previous changes (9)
  • chaos/experiments/pod-kill.yaml
  • chaos/experiments/webhook-disrupt.yaml
  • components/odh-notebook-controller/controllers/notebook_controller_test.go
  • components/odh-notebook-controller/controllers/notebook_mlflow_test.go
  • .github/workflows/operator_chaos_validation.yaml
  • chaos/experiments/deployment-scale-zero.yaml
  • chaos/experiments/network-partition.yaml
  • components/notebook-controller/go.mod
  • components/odh-notebook-controller/go.mod

Comment thread components/odh-notebook-controller/README.md
@rhods-ci-bot

Copy link
Copy Markdown

/group-test

@rhods-ci-bot

Copy link
Copy Markdown

/group-test

Add Level 3 operator-chaos integration with ChaosClient SDK tests for
both the ODH and upstream notebook reconcilers, using isolated envtest
environments (no controller manager) for deterministic fault injection.

- Add operator-chaos/pkg/sdk as a Go dependency in both controllers;
  sync k8s API versions to v0.35.2 in notebook-controller
- Create chaostests/ packages with isolated envtest setup (API server +
  etcd only) enabling deterministic Create/Delete fault testing
- ODH controller: 10 Ginkgo specs covering Get, List, Create, Update,
  Delete faults, transient recovery, and intermittent errors
- Upstream controller: 7 Ginkgo specs covering Get, List, Create faults,
  transient recovery, and intermittent errors (no Update-no-drift or
  Delete tests as the reconciler always detects StatefulSet drift and
  does not handle finalizers)
- Add 5 experiment YAMLs under chaos/experiments/ adapted from upstream
  (pod-kill, network-partition, webhook-disrupt, rbac-revoke,
  deployment-scale-zero)
- Add `make test-chaos` Makefile targets with -coverpkg=./controllers/...
  for accurate coverage attribution
- Extend CI workflow to validate experiments, run chaos SDK tests, and
  upload coverage to Codecov with a dedicated `chaos` flag
- Update AGENTS.md and component READMEs with chaos testing documentation

Co-authored-by: Cursor <cursoragent@cursor.com>
@openshift-ci openshift-ci Bot added size/xxl and removed size/xxl labels Jul 1, 2026
@jstourac jstourac changed the title feat(chaos): integrate ChaosClient SDK tests and experiment YAMLs (L3) feat(chaos): integrate operator-chaos L3 SDK tests for both controllers Jul 1, 2026
@openshift-ci openshift-ci Bot added size/xxl and removed size/xxl labels Jul 1, 2026
@rhods-ci-bot

Copy link
Copy Markdown

/group-test

@harshad16 harshad16 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The core design - isolated envtest, per-component L3 SDK tests, CI wiring.
Thank you for working on this.

/lgtm
/approve

@openshift-ci

openshift-ci Bot commented Jul 13, 2026

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: harshad16

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-merge-bot
openshift-merge-bot Bot merged commit d886335 into opendatahub-io:main Jul 13, 2026
15 checks passed
@openshift-ci openshift-ci Bot removed the size/xxl label Jul 13, 2026
@rhods-ci-bot

Copy link
Copy Markdown

/group-test

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants