Skip to content

fix(ray): bump kuberay manifests to include apiservers RBAC - #3847

Closed
jeffdyoung wants to merge 1 commit into
opendatahub-io:mainfrom
jeffdyoung:fix/kuberay-apiservers-rbac
Closed

jeffdyoung wants to merge 1 commit into
opendatahub-io:mainfrom
jeffdyoung:fix/kuberay-apiservers-rbac

Conversation

@jeffdyoung

@jeffdyoung jeffdyoung commented Jul 22, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Bumps kuberay manifest pin from 8c772cc to c992b37 (opendatahub-io/kuberay#214)
  • Adds apiservers resource to the config.openshift.io RBAC rule in opt/manifests/ray/rbac/role.yaml

Problem

The kuberay operator image (v1.4.4, deployed via RELATED_IMAGE override) reads apiservers.config.openshift.io for TLS profile resolution (RHOAIENG-61067). The pinned manifests at 8c772cc only grant access to authentications and oauths, causing the kuberay-operator pod to CrashLoopBackOff:

"unable to resolve TLS configuration: reading APIServer TLS profile:
 apiservers.config.openshift.io \"cluster\" is forbidden:
 User \"system:serviceaccount:opendatahub:kuberay-operator\" cannot get
 resource \"apiservers\" in API group \"config.openshift.io\""

This blocks all CI runs that enable the Ray component.

Test plan

  • Manual e2e run on ROSA 4.21 (3-worker c6a.2xlarge) — Ray component deploys, all Ray tests pass, zero CrashLoopBackOff
  • Prow e2e CI passes

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores
    • Updated the pinned Ray component reference used when fetching OpenDataHub manifests.

Bump kuberay manifest pin from 8c772cc to c992b37 (opendatahub-io/kuberay#214).

The kuberay operator image (deployed via RELATED_IMAGE override) reads
apiservers.config.openshift.io for TLS profile resolution. The RBAC at
the previous pin (8c772cc) only grants access to authentications and
oauths in config.openshift.io, causing the kuberay-operator pod to
CrashLoopBackOff with:

  "unable to resolve TLS configuration: reading APIServer TLS profile:
   apiservers.config.openshift.io \"cluster\" is forbidden"

Upstream fix: RHOAIENG-61067 (opendatahub-io/kuberay@c992b37).
Tested: manual e2e run on ROSA 4.21 — Ray component deploys and all
Ray tests pass with this change.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@openshift-ci

openshift-ci Bot commented Jul 22, 2026

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
Once this PR has been reviewed and has the lgtm label, please assign zdtsw for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@coderabbitai

coderabbitai Bot commented Jul 22, 2026 •

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Central YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Enterprise

Run ID: f0230e9b-4c7e-4e0b-bc39-ba34475c70c2

📥 Commits

Reviewing files that changed from the base of the PR and between 7659a92 and 0b27009.

📒 Files selected for processing (1)
  • get_all_manifests.sh

📝 Walkthrough

Walkthrough

Updates the pinned opendatahub-io/kuberay development commit for the ray entry in ODH_COMPONENT_MANIFESTS. OpenDataHub mode now fetches the Ray operator configuration from the new exact repository revision.

Estimated code review effort: 1 (Trivial) | ~2 minutes

🚥 Pre-merge checks | ✅ 10
✅ Passed checks (10 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately describes the KubeRay manifest bump and RBAC change for apiservers access.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Contribution Quality And Spam Detection ✅ Passed Legit bug fix: linked Jira/PR, manual e2e, and no second-category spam/security-theater signal beyond a templated description.
No Hardcoded Secrets ✅ Passed Only a commit-SHA pin changed in get_all_manifests.sh; no api_key/secret/token/password literals, creds-in-URL, or long base64 blobs were added (CWE-798/522/259 clear).
No Weak Cryptography ✅ Passed Diff only repins a manifest SHA in get_all_manifests.sh; no added MD5/SHA1/DES/RC4/3DES/Blowfish/ECB, custom crypto, or secret compares (CWE-327/CWE-208).
No Injection Vectors ✅ Passed PASS: Changed only a hardcoded commit pin in get_all_manifests.sh; no user-controlled SQL/shell/eval/yaml/HTML sinks were added (CWE-78/89/94/502/79).
No Privileged Containers ✅ Passed Diff only updates get_all_manifests.sh pin; no manifest/Dockerfile changes and no privileged, host*, SYS_ADMIN, or root settings found.
No Sensitive Data In Logs ✅ Passed PASS: HEAD diff only bumps a KubeRay SHA in get_all_manifests.sh; no new log/echo statements or secret-bearing fields were added, so no CWE-532 exposure.

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

1 participant