Skip to content

feat(workbenches): mirror workbenchNamespace into DSC status - #3890

Merged
openshift-merge-bot[bot] merged 1 commit into
opendatahub-io:mainfrom
harshad16:ensure-legacy-workbench
Jul 30, 2026
Merged

openshift-merge-bot[bot] merged 1 commit into
opendatahub-io:mainfrom
harshad16:ensure-legacy-workbench

Conversation

@harshad16

@harshad16 harshad16 commented Jul 29, 2026 •

Copy link
Copy Markdown
Member

Project workbenchNamespace from the Workbenches module CR onto status.components.workbenches via an optional workbenches-only writer, so the dashboard can resolve the legacy notebooks namespace without changing the generic release/managementState mirroring from #3838.

Description

Add a workbenches-only optional hook on top of the existing #3838 WriteDSCComponentStatus flow:

  • Parse workbenchNamespace from the Workbenches module CR in GetModuleStatus()
  • Introduce optional DSCWorkbenchNamespaceWriter (implemented only by the workbenches handler)
  • During ComputeModulesStatus, after generic WriteDSCComponentStatus, call writeDSCWorkbenchNamespace() to set/clear status.components.workbenches.workbenchNamespace

Note: This intentionally does not restore full typed status projection or change how other modules mirror status into the DSC.

JIRA: https://redhat.atlassian.net/browse/RHOAIENG-79812
Related-to: opendatahub-io/workbenches-operator#77

How Has This Been Tested?

  • Unit tests for WriteDSCWorkbenchNamespace (set, clear when disabled, interface compliance)
  • E2e assert: status.components.workbenches.workbenchNamespace matches configured legacy namespace in ValidateWorkbenchesNamespaceConfiguration
  • Deploy platform operator from this branch on a RHOAI cluster with workbenchNamespace: rhods-notebooks
  • Verify DSC status:
    oc get dsc default-dsc -o jsonpath='{.status.components.workbenches.workbenchNamespace}{"\n"}'
    Expected: rhods-notebooks
  • Create a notebook from the dashboard and confirm it lands in rhods-notebooks, not redhat-ods-applications

Screenshot or short clip

Merge criteria

  • You have read the contributors guide.
  • Commit messages are meaningful - have a clear and concise summary and detailed explanation of what was changed and why.
  • Pull Request contains a description of the solution, a link to the JIRA issue, and to any dependent or related Pull Request.
  • Testing instructions have been added in the PR body (for PRs involving changes that are not immediately obvious).
  • The developer has manually tested the changes and verified that the changes work
  • The developer has run the integration test pipeline and verified that it passed successfully
  • New RELATED_IMAGE mappings are listed in ODH-Build-Config and RHOAI-Build-Config (CI validates names against build-config repos). Include links to build-config PRs in the description.

E2E test suite update requirement

When bringing new changes to the operator code, such changes are by default required to be accompanied by extending and/or updating the E2E test suite accordingly.

To opt-out of this requirement:

  1. Please inspect the opt-out guidelines, to determine if the nature of the PR changes allows for skipping this requirement
  2. If opt-out is applicable, provide justification in the dedicated E2E update requirement opt-out justification section below
  3. Check the checkbox below:
  • Skip requirement to update E2E test suite for this PR
  1. Submit/save these changes to the PR description. This will automatically trigger the check.

E2E update requirement opt-out justification

Summary by CodeRabbit

  • New Features
    • Workbenches now mirrors its configured namespace into the Data Science Cluster status for improved visibility.
    • Legacy “additional component status” fields are populated when supported by the active module handler.
  • Bug Fixes
    • Module status computation now preserves an existing Workbenches namespace in Data Science Cluster status if module status retrieval fails.
    • Workbenches namespace status is cleared when management is disabled or when the configured namespace is empty.
  • Tests
    • Added unit tests for mirroring/clearing and status preservation.
    • Updated e2e validations to assert the namespace in Data Science Cluster status.

@coderabbitai

coderabbitai Bot commented Jul 29, 2026 •

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Central YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: c502d60c-dd26-4b4c-a6a6-b23edc3d0bf8

📥 Commits

Reviewing files that changed from the base of the PR and between ecba7e7 and de08b0f.

📒 Files selected for processing (6)
  • internal/controller/modules/modules_controller_actions.go
  • internal/controller/modules/modules_controller_actions_test.go
  • internal/controller/modules/types.go
  • internal/controller/modules/workbenches/handler.go
  • internal/controller/modules/workbenches/handler_test.go
  • tests/e2e/workbenches_test.go

📝 Walkthrough

Walkthrough

Adds an optional module hook for writing legacy DataScienceCluster status fields. Module reconciliation invokes the hook for enabled and disabled modules. The Workbenches handler mirrors the spec namespace into status, clears it when disabled or empty, and initializes component status as needed. Unit and end-to-end tests cover namespace mirroring, clearing, error handling, and application namespace placement.

Estimated code review effort: 3 (Moderate) | ~20 minutes

🚥 Pre-merge checks | ✅ 10
✅ Passed checks (10 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly matches the main change: mirroring workbenchNamespace into DSC status for Workbenches.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Contribution Quality And Spam Detection ✅ Passed No CWE-20/CWE-74-style security theater; PR is scoped, multi-file, linked to Jira, and adds unit/E2E coverage.
No Hardcoded Secrets ✅ Passed PASS: No CWE-798/CWE-321 indicators; touched files contain no hardcoded api_key/secret/token/password literals, embedded creds, private keys, or long base64 blobs.
No Weak Cryptography ✅ Passed No MD5/SHA1/DES/RC4/ECB/3DES/Blowfish, no custom crypto, and no secret/token/HMAC comparisons in touched files; CWE-327/CWE-208 not triggered.
No Injection Vectors ✅ Passed No CWE-89/78/79/94/502 sink patterns in touched non-test code; changes only mirror a CR field into DSC status.
No Privileged Containers ✅ Passed PASS: Diff only touches Go/tests; no manifests, Helm templates, or Dockerfiles changed, and scans found no privileged settings (CWE-250/CWE-266).
No Sensitive Data In Logs ✅ Passed Added logs only emit module name and generic error values; no passwords, tokens, PII, bodies, or credentials. CWE-532 not triggered.

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
internal/controller/modules/workbenches/handler_test.go (1)

189-199: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Cover clearing when the namespace becomes empty.

The implementation clears on !enabled || workbenchNamespace == "", but this test only exercises enabled=false with a non-empty argument. Add an enabled=true → empty-value case.

Suggested test
+func TestWriteDSCWorkbenchNamespace_ClearsWhenEmpty(t *testing.T) {
+	g := NewWithT(t)
+	h := NewHandler()
+	dsc := &dscv2.DataScienceCluster{}
+
+	h.WriteDSCWorkbenchNamespace(dsc, true, "rhods-notebooks")
+	h.WriteDSCWorkbenchNamespace(dsc, true, "")
+
+	g.Expect(dsc.Status.Components.Workbenches.WorkbenchNamespace).Should(BeEmpty())
+}
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@internal/controller/modules/workbenches/handler_test.go` around lines 189 -
199, Extend TestWriteDSCWorkbenchNamespace_ClearsWhenDisabled to also call
WriteDSCWorkbenchNamespace with enabled=true and an empty namespace after
setting a non-empty namespace. Assert WorkbenchNamespace is empty, covering
clearing when the namespace value becomes empty independently of the disabled
case.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@internal/controller/modules/base.go`:
- Line 330: Update the status.workbenchNamespace extraction in the surrounding
controller flow to capture and propagate the error returned by
unstructured.NestedString instead of discarding it; only call
writeDSCWorkbenchNamespace when parsing succeeds. Add a malformed-status test
case verifying the accessor error is returned and the existing workbench
namespace is not cleared.

---

Nitpick comments:
In `@internal/controller/modules/workbenches/handler_test.go`:
- Around line 189-199: Extend TestWriteDSCWorkbenchNamespace_ClearsWhenDisabled
to also call WriteDSCWorkbenchNamespace with enabled=true and an empty namespace
after setting a non-empty namespace. Assert WorkbenchNamespace is empty,
covering clearing when the namespace value becomes empty independently of the
disabled case.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Central YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: a9397f91-efbf-46ec-a00d-18ab7753f326

📥 Commits

Reviewing files that changed from the base of the PR and between 5a5bece and ca9a275.

📒 Files selected for processing (6)
  • internal/controller/modules/base.go
  • internal/controller/modules/modules_controller_actions.go
  • internal/controller/modules/types.go
  • internal/controller/modules/workbenches/handler.go
  • internal/controller/modules/workbenches/handler_test.go
  • tests/e2e/workbenches_test.go

Comment thread internal/controller/modules/base.go Outdated
Comment thread internal/controller/modules/base.go Outdated
@harshad16
harshad16 force-pushed the ensure-legacy-workbench branch 2 times, most recently from fb76f21 to 4cfd189 Compare July 29, 2026 20:22
Comment thread internal/controller/modules/modules_controller_actions.go Outdated
Comment thread internal/controller/modules/modules_controller_actions.go Outdated
@harshad16
harshad16 force-pushed the ensure-legacy-workbench branch from 4cfd189 to ecba7e7 Compare July 29, 2026 21:48

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@internal/controller/modules/modules_controller_actions.go`:
- Around line 604-606: Update
internal/controller/modules/workbenches/handler.go:146-168 so
WriteLegacyStatusFields uses WorkbenchesCommonStatus.WorkbenchNamespace from the
Workbenches CR status rather than
dsc.Spec.Components.Workbenches.WorkbenchNamespace, passing that observed value
through the legacy writer contract as needed. Update
internal/controller/modules/modules_controller_actions.go:604-606 to mirror the
same observed WorkbenchNamespace value when writing legacy status fields;
preserve existing error handling.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Central YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: c4914ea3-386e-4c0b-bf75-f65e11c707a0

📥 Commits

Reviewing files that changed from the base of the PR and between fb76f21 and ecba7e7.

📒 Files selected for processing (6)
  • internal/controller/modules/modules_controller_actions.go
  • internal/controller/modules/modules_controller_actions_test.go
  • internal/controller/modules/types.go
  • internal/controller/modules/workbenches/handler.go
  • internal/controller/modules/workbenches/handler_test.go
  • tests/e2e/workbenches_test.go
🚧 Files skipped from review as they are similar to previous changes (1)
  • internal/controller/modules/types.go

Comment thread internal/controller/modules/modules_controller_actions.go
// namespace.
//
// TODO: Remove once dashboard reads workbenchNamespace directly from the Workbenches
// CR (workbenches-operator status) instead of DSC status.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

do we have a jira tracker for this?

@jstourac jstourac left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm

I've put one comment, otherwise LGTM. I'm not sure about the e2e test failures - doesn't seem to be related to the changes here on the first sight, but I didn't go deep.

@harshad16

Copy link
Copy Markdown
Member Author

The e2e tests seems to be failing due to this error:

"Failed to watch","reflector":"go/pkg/mod/k8s.io/client-go@v0.35.0/tools/cache/reflector.go:289","type":"*v1.APIServer","error":"failed to list *v1.APIServer: apiservers.config.openshift.io is forbidden: User \"system:serviceaccount:opendatahub:kuberay-operator\" cannot list resource \"apiservers\" in API group \"config.openshift.io\" at the cluster scope"

Seems like someone worked on fix: #3847
however closed it.
any suggestion , what to do for getting e2e fixed for having this across finish line ?
@carlkyrillos @davidebianchi

same as: #3882 (comment)

@asmigala

Copy link
Copy Markdown
Member

@harshad16 the ray sha has since been updated here, but not sure if that contains the fix, checking

@davidebianchi

Copy link
Copy Markdown
Member

The issue is related to a sha upgrade, but we need before ray to sync downstream to have e2e working again. It seems also a feastoperator permission error

@harshad16

Copy link
Copy Markdown
Member Author

@harshad16 the ray sha has since been updated here, but not sure if that contains the fix, checking

@asmigala , seems like some more fix went in yesterday opendatahub-io/kuberay#224
shall i pull in the lastest sha and test this out ?

@davidebianchi

Copy link
Copy Markdown
Member

We need to merge #3882 before, since it fix another issue with e2e. I already updated in #3882 the sha for kuberay, but it's missing the sync downstream

Project workbenchNamespace onto status.components.workbenches via
an optional workbenches-only writer, so the dashboard can resolve
the legacy notebooks namespace without changing the generic
release/managementState mirroring from opendatahub-io#3838.

Signed-off-by: Harshad Reddy Nalla <hnalla@redhat.com>
@harshad16
harshad16 force-pushed the ensure-legacy-workbench branch from ecba7e7 to de08b0f Compare July 30, 2026 15:57
@openshift-ci openshift-ci Bot removed the lgtm label Jul 30, 2026
@carlkyrillos

Copy link
Copy Markdown
Member

/test opendatahub-operator-e2e
/test opendatahub-operator-rhoai-e2e

Restarting tests now that openshift/release#82675 has merged

@codecov

codecov Bot commented Jul 30, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 60.00000% with 12 lines in your changes missing coverage. Please review.
✅ Project coverage is 59.71%. Comparing base (92c3bc8) to head (de08b0f).
⚠️ Report is 2 commits behind head on main.

Files with missing lines Patch % Lines
...l/controller/modules/modules_controller_actions.go 33.33% 6 Missing and 2 partials ⚠️
internal/controller/modules/workbenches/handler.go 77.77% 2 Missing and 2 partials ⚠️
Additional details and impacted files
@@            Coverage Diff             @@
##             main    #3890      +/-   ##
==========================================
+ Coverage   59.62%   59.71%   +0.09%     
==========================================
  Files         217      217              
  Lines       17002    17032      +30     
==========================================
+ Hits        10137    10171      +34     
+ Misses       5950     5944       -6     
- Partials      915      917       +2     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@carlkyrillos

Copy link
Copy Markdown
Member

/hold
Holding until #3813 is merged since the modularization PRs are top priority

@carlkyrillos

Copy link
Copy Markdown
Member

/unhold

@openshift-ci

openshift-ci Bot commented Jul 30, 2026

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: carlkyrillos, cgoodfred, davidebianchi

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:
  • OWNERS [carlkyrillos,cgoodfred,davidebianchi]

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-merge-bot
openshift-merge-bot Bot merged commit 573ae31 into opendatahub-io:main Jul 30, 2026
25 of 27 checks passed
@github-project-automation github-project-automation Bot moved this from Todo to Done in ODH Platform Planning Jul 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

6 participants