Skip to content

Conversation

@openshift-cherrypick-robot

This is an automated cherry-pick of #185

/assign adambkaplan

`/etc/pki/ca-trust` contains the system trust stores for a wide array of
applications. Making this a mount point in buildah causes the original
data in the base image to overlayed by the contents in the build container.
As a result, `/etc/pki/ca-trust` cannot be altered unless another layer is
added to the image being built via a COPY or ADD instruction.

This will revert the mount of `/etc/pki/ca-trust`, thereby removing the ability
of builds to use the cluster trust bundle. This capability will be restored in
a future OpenShift release as an opt-in enhancement.
@openshift-ci-robot
Copy link
Contributor

@openshift-cherrypick-robot: Bugzilla bug 1891759 has been cloned as Bugzilla bug 1895093. Retitling PR to link against new bug.
/retitle [release-4.6] Bug 1895093: Do not mount /etc/pki/ca-trust in builds

Details

In response to this:

[release-4.6] Bug 1891759: Do not mount /etc/pki/ca-trust in builds

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

@openshift-ci-robot openshift-ci-robot changed the title [release-4.6] Bug 1891759: Do not mount /etc/pki/ca-trust in builds [release-4.6] Bug 1895093: Do not mount /etc/pki/ca-trust in builds Nov 5, 2020
@openshift-ci-robot openshift-ci-robot added bugzilla/severity-high Referenced Bugzilla bug's severity is high for the branch this PR is targeting. bugzilla/invalid-bug Indicates that a referenced Bugzilla bug is invalid for the branch this PR is targeting. labels Nov 5, 2020
@openshift-ci-robot
Copy link
Contributor

@openshift-cherrypick-robot: This pull request references Bugzilla bug 1895093, which is invalid:

  • expected dependent Bugzilla bug 1891759 to be in one of the following states: VERIFIED, RELEASE_PENDING, CLOSED (ERRATA), but it is MODIFIED instead

Comment /bugzilla refresh to re-evaluate validity if changes to the Bugzilla bug are made, or edit the title of this pull request to link to a different bug.

Details

In response to this:

[release-4.6] Bug 1895093: Do not mount /etc/pki/ca-trust in builds

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

@gabemontero
Copy link
Contributor

/assign @bparees

@adambkaplan 's disablement of the release image breaking change while @coreydaley works on the new opt-in solution just merged into 4.7/master and here is the 4.6.z cherry pick

(Adam's out for the rest of today if you want this approved etc. before tomorrow)

/lgtm

@openshift-ci-robot openshift-ci-robot added the lgtm Indicates that a PR is ready to be merged. label Nov 5, 2020
@bparees
Copy link
Contributor

bparees commented Nov 5, 2020

/approve

let's make sure DPTP knows this is coming since this will get us back to a "good" state for building image-registry/etc, until the opt-in feature is complete.

cc @dmage

@openshift-ci-robot
Copy link
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: bparees, gabemontero, openshift-cherrypick-robot

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci-robot openshift-ci-robot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Nov 5, 2020
@gabemontero
Copy link
Contributor

/approve

let's make sure DPTP knows this is coming since this will get us back to a "good" state for building image-registry/etc, until the opt-in feature is complete.

cc @dmage

I did communicate this to @stevekuznetsov

@gabemontero
Copy link
Contributor

/approve
let's make sure DPTP knows this is coming since this will get us back to a "good" state for building image-registry/etc, until the opt-in feature is complete.
cc @dmage

I did communicate this to @stevekuznetsov

toward the bottom of this thread: https://coreos.slack.com/archives/CBN38N3MW/p1604591017248200

@bparees
Copy link
Contributor

bparees commented Nov 5, 2020

I did communicate this to @stevekuznetsov

awesome, thank you!

@openshift-bot
Copy link
Contributor

/bugzilla refresh

Recalculating validity in case the underlying Bugzilla bug has changed.

@openshift-ci-robot
Copy link
Contributor

@openshift-bot: This pull request references Bugzilla bug 1895093, which is invalid:

  • expected dependent Bugzilla bug 1891759 to be in one of the following states: VERIFIED, RELEASE_PENDING, CLOSED (ERRATA), but it is ON_QA instead

Comment /bugzilla refresh to re-evaluate validity if changes to the Bugzilla bug are made, or edit the title of this pull request to link to a different bug.

Details

In response to this:

/bugzilla refresh

Recalculating validity in case the underlying Bugzilla bug has changed.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

@openshift-ci-robot openshift-ci-robot added bugzilla/severity-urgent Referenced Bugzilla bug's severity is urgent for the branch this PR is targeting. and removed bugzilla/severity-high Referenced Bugzilla bug's severity is high for the branch this PR is targeting. labels Nov 6, 2020
@openshift-bot
Copy link
Contributor

/retest

Please review the full test history for this PR and help us cut down flakes.

1 similar comment
@openshift-bot
Copy link
Contributor

/retest

Please review the full test history for this PR and help us cut down flakes.

@adambkaplan
Copy link
Contributor

/bugzilla refresh

@openshift-ci-robot openshift-ci-robot added bugzilla/valid-bug Indicates that a referenced Bugzilla bug is valid for the branch this PR is targeting. and removed bugzilla/invalid-bug Indicates that a referenced Bugzilla bug is invalid for the branch this PR is targeting. labels Nov 6, 2020
@openshift-ci-robot
Copy link
Contributor

@adambkaplan: This pull request references Bugzilla bug 1895093, which is valid. The bug has been moved to the POST state. The bug has been updated to refer to the pull request using the external bug tracker.

6 validation(s) were run on this bug
  • bug is open, matching expected state (open)
  • bug target release (4.6.z) matches configured target release for branch (4.6.z)
  • bug is in the state NEW, which is one of the valid states (NEW, ASSIGNED, ON_DEV, POST, POST)
  • dependent bug Bugzilla bug 1891759 is in the state VERIFIED, which is one of the valid states (VERIFIED, RELEASE_PENDING, CLOSED (ERRATA))
  • dependent Bugzilla bug 1891759 targets the "4.7.0" release, which is one of the valid target releases: 4.7.0
  • bug has dependents
Details

In response to this:

/bugzilla refresh

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

@adambkaplan
Copy link
Contributor

Patch manager note - this fixes an urgent regression in builds that impacts the ability of teams to build images on CI.

@sdodson sdodson added the cherry-pick-approved Indicates a cherry-pick PR into a release branch has been approved by the release branch manager. label Nov 6, 2020
@openshift-merge-robot openshift-merge-robot merged commit d3c038b into openshift:release-4.6 Nov 6, 2020
@openshift-ci-robot
Copy link
Contributor

@openshift-cherrypick-robot: All pull requests linked via external trackers have merged:

Bugzilla bug 1895093 has been moved to the MODIFIED state.

Details

In response to this:

[release-4.6] Bug 1895093: Do not mount /etc/pki/ca-trust in builds

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. bugzilla/severity-urgent Referenced Bugzilla bug's severity is urgent for the branch this PR is targeting. bugzilla/valid-bug Indicates that a referenced Bugzilla bug is valid for the branch this PR is targeting. cherry-pick-approved Indicates a cherry-pick PR into a release branch has been approved by the release branch manager. lgtm Indicates that a PR is ready to be merged.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

8 participants