[release-4.11] OCPBUGS-14456, OCPBUGS-14457: Handle mTLS CRLs, and fix accidental CRL duplication#942
Conversation
|
@rfredette: This pull request references Jira Issue OCPBUGS-14457, which is invalid:
Comment The bug has been updated to refer to the pull request using the external bug tracker. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
925c0e5 to
fbb9d67
Compare
Leave a stub of the CRL controller to clean up any existing configmaps. The stub controller will need to be removed in a future release Use cluster-wide proxy for CRL downloads when available Add a test with several test cases to test CRL management, and a test to test CRL updates
fbb9d67 to
1f0f54a
Compare
|
/hold This PR (and the tests) depends on openshift/router#492. |
|
e2e-aws-operator - Investigation for 13810 happening in: #940. |
|
e2e-aws-single-node - "Failed while waiting on imagestream import" /test e2e-aws-single-node |
|
/test e2e-aws-operatoe I see failures for the mTLS tests: |
|
@frobware: The specified target(s) for
The following commands are available to trigger optional jobs:
Use
DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
|
/test e2e-aws-operator |
This is not a problem; see #942 (comment). |
|
/lgtm |
|
/approve |
|
/label cherry-pick-approved, |
|
@lihongan: The label(s) DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
|
/label cherry-pick-approved |
|
/unhold |
|
/retest-required |
|
/jira refresh |
|
@lihongan: This pull request references Jira Issue OCPBUGS-14457, which is valid. 6 validation(s) were run on this bug
Requesting review from QA contact: DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
|
/test all |
|
level=fatal msg=failed to fetch Terraform Variables: failed to fetch dependency of "Terraform Variables": failed to generate asset "Platform Provisioning Check": baseDomain: Invalid value: "origin-ci-int-aws.dev.rhcloud.com": the zone already has record sets for the domain of the cluster: [api.ci-op-ih8pi4zj-51128.origin-ci-int-aws.dev.rhcloud.com. (A), \052.apps.ci-op-ih8pi4zj-51128.origin-ci-int-aws.dev.rhcloud.com. (A)] /test e2e-aws-operator |
|
Failed: [sig-arch][Late] operators should not create watch channels very often [Suite:openshift/conformance/parallel] /test e2e-aws-single-node |
See also: https://redhat-internal.slack.com/archives/CEKNRGF25/p1686218879266109 |
x509.RevocationList was added in go 1.19 (deprecating pkix.CertificateList), but 4.11 is built with go 1.18.
e8a2a58 to
1e9876c
Compare
This is a no-edit commit. See: https://redhat-internal.slack.com/archives/CEKNRGF25/p1686220147776379?thread_ts=1686218879.266109&cid=CEKNRGF25 /lgtm |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: frobware, Miciah The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
|
/skip |
|
@rfredette: The following test failed, say
Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. I understand the commands that are listed here. |
|
@rfredette: Jira Issue OCPBUGS-14457: All pull requests linked via external trackers have merged: Jira Issue OCPBUGS-14457 has been moved to the MODIFIED state. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
|
Fix included in accepted release 4.11.0-0.nightly-2023-06-08-182148 |
Manual cherry pick & squash of #939
Leave a stub of the CRL controller to clean up any existing configmaps. The stub controller will need to be removed in a future release
Use cluster-wide proxy for CRL downloads when available
Add a test with several test cases to test CRL management, and a test to test CRL updates