Skip to content

MON-4527: ClusterMonitoring NodeExporterConfig logic - #2919

Merged
openshift-merge-bot[bot] merged 5 commits into
openshift:mainfrom
marioferh:logic_NodeExporter
Jun 25, 2026
Merged

openshift-merge-bot[bot] merged 5 commits into
openshift:mainfrom
marioferh:logic_NodeExporter

Conversation

@marioferh

Copy link
Copy Markdown
Contributor

No description provided.

@marioferh

Copy link
Copy Markdown
Contributor Author

/hold
include this commit: #2907 wait for merge and rebase

@openshift-ci openshift-ci Bot added the do-not-merge/hold Indicates that a PR should not merge because someone has issued a /hold command. label May 6, 2026
@openshift-ci
openshift-ci Bot requested review from machine424 and simonpasquier May 6, 2026 11:21
@openshift-ci openshift-ci Bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label May 6, 2026
@coderabbitai

coderabbitai Bot commented May 6, 2026 •

Copy link
Copy Markdown

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

This change adds detection of a top-level nodeExporter key in the ClusterMonitoring ConfigMap and extends mergeClusterMonitoringCRD to accept a nodeExporterDeclaredByConfigMap flag. It implements helpers to detect empty NodeExporter specs/collectors, maps CR collectionPolicy values into enabled/disabled collector flags, and conditionally merges CRD NodeExporter fields (resources, maxProcs, ignored devices, collector enablement) only when the ConfigMap omits nodeExporter. Unit tests for detection, emptiness checks, and merge precedence were added. go.mod updates the github.com/openshift/api version.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

🚥 Pre-merge checks | ✅ 12 | ❌ 3

❌ Failed checks (3 warnings)

Check name Status Explanation Resolution
Description check ⚠️ Warning No pull request description was provided by the author; the description is entirely empty. Add a pull request description explaining the changes, the rationale for the merge strategy updates, and any testing performed to validate the NodeExporter configuration handling.
Docstring Coverage ⚠️ Warning Docstring coverage is 55.56% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
Test Structure And Quality ⚠️ Warning The test file config_merge_test.go contains 4 unresolved Git merge conflict markers that break compilation: <<<<<<< HEAD (line 128, 155, 358, 414) causing syntax errors. Resolve all merge conflicts in pkg/manifests/config_merge_test.go by choosing or integrating the conflicting changes between HEAD and the merged branch (f1ac5ee).
✅ Passed checks (12 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Stable And Deterministic Test Names ✅ Passed Tests use standard Go testing, not Ginkgo. All test names (both function and subtest) are static, descriptive strings with no dynamic content like timestamps, UUIDs, or generated identifiers.
Microshift Test Compatibility ✅ Passed No Ginkgo e2e tests were added. New tests in config_merge_test.go are standard Go unit tests, not Ginkgo-style tests. Custom check is not applicable.
Single Node Openshift (Sno) Test Compatibility ✅ Passed PR adds no Ginkgo e2e tests. All changes are to production code and standard Go unit tests in pkg/manifests/, not e2e test files.
Topology-Aware Scheduling Compatibility ✅ Passed PR modifies only configuration parsing in pkg/manifests/ (config.go, config_merge.go, tests); no deployment manifests or scheduling constraints are introduced.
Ote Binary Stdout Contract ✅ Passed No stdout contract violations found. All error output uses os.Stderr; klog initialized with flags for stderr; no fmt.Print or direct stdout writes in process-level code.
Ipv6 And Disconnected Network Test Compatibility ✅ Passed No Ginkgo e2e tests added. Only standard Go unit tests for internal config logic without network assumptions or external connectivity requirements.
No-Weak-Crypto ✅ Passed No weak cryptographic algorithms (MD5, SHA1, DES, RC4, 3DES, Blowfish, ECB), custom crypto implementations, or non-constant-time secret comparisons detected in modified files.
Container-Privileges ✅ Passed PR modifies only Go source code for NodeExporter configuration logic; no Kubernetes manifest files or container security settings are changed.
No-Sensitive-Data-In-Logs ✅ Passed No logging of sensitive data found. New NodeExporterConfig code contains no logging calls and does not expose credentials, configuration content, or sensitive information.
Title check ✅ Passed The title clearly and specifically references MON-4527 and accurately describes the main change: implementing ClusterMonitoring NodeExporterConfig logic including presence detection and merge behavior adjustments.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Comment @coderabbitai help to get the list of available commands.

Comment thread pkg/manifests/types.go Outdated
// Defines the nodes on which the Pods are scheduled.
NodeSelector map[string]string `json:"nodeSelector,omitempty"`
// Defines tolerations for the pods.
Tolerations []v1.Toleration `json:"tolerations,omitempty"`

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

should we hide theses settings from the "official" doc?
I understand that we added these fields for consistency but I have a hard time seeing a use case for node selector and tolerations in the scope of a daemonset like node_exporter.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

yep, I was trying to clarify this with @danielmellado this morning.
Do you agree with Simon?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The api design added that for consistency among all the other components as requested by the api tram. That said, we might for now not directly use them in CMO and that wouldn't hurt.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

we should probably revisit if there's no concrete use case because while the API would be consistent, it would still be confusing for users. I agree that for now, we should just drop the fields and not port them to the existing config.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

agree

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@marioferh

Copy link
Copy Markdown
Contributor Author

/retest-required

@marioferh
marioferh force-pushed the logic_NodeExporter branch 2 times, most recently from 4da24ae to f1ac5ee Compare May 7, 2026 08:28

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🧹 Nitpick comments (1)
pkg/manifests/config_merge_test.go (1)

341-345: ⚡ Quick win

Weak assertion: Softirqs.Enabled defaults to false, so this test passes even if DoNotCollect mapping is never exercised.

Softirqs is not set in the cmc initialization defaults, so its zero value is already false. The assertion require.False(t, ...) cannot distinguish "mapping worked correctly" from "code path was never reached."

A more conclusive test uses a collector whose default is true — NetDev (Enabled: true by default) or NetClass (Enabled: true) — and asserts that setting DoNotCollect flips it to false:

✅ Stronger proposed assertion
-t.Run("CR maps DoNotCollect to disabled", func(t *testing.T) {
-    c, err := NewConfigFromStringAndClusterMonitoringResource("{}", softirqsCR(configv1alpha1.NodeExporterCollectorCollectionPolicyDoNotCollect))
-    require.NoError(t, err)
-    require.False(t, c.ClusterMonitoringConfiguration.NodeExporterConfig.Collectors.Softirqs.Enabled)
-})
+t.Run("CR maps DoNotCollect to disabled", func(t *testing.T) {
+    // NetDev defaults to Enabled:true, so DoNotCollect must flip it to false.
+    cm := &configv1alpha1.ClusterMonitoring{
+        Spec: configv1alpha1.ClusterMonitoringSpec{
+            NodeExporterConfig: configv1alpha1.NodeExporterConfig{
+                Collectors: configv1alpha1.NodeExporterCollectorConfig{
+                    NetDev: configv1alpha1.NodeExporterCollectorNetDevConfig{
+                        CollectionPolicy: configv1alpha1.NodeExporterCollectorCollectionPolicyDoNotCollect,
+                    },
+                },
+            },
+        },
+    }
+    c, err := NewConfigFromStringAndClusterMonitoringResource("{}", cm)
+    require.NoError(t, err)
+    require.False(t, c.ClusterMonitoringConfiguration.NodeExporterConfig.Collectors.NetDev.Enabled)
+})

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Central YAML (inherited)

Review profile: CHILL

Plan: Enterprise

Run ID: bacadb7f-7bbf-4aeb-abb4-4546c420ea2b

📥 Commits

Reviewing files that changed from the base of the PR and between 4da24ae and f1ac5ee.

⛔ Files ignored due to path filters (6)
  • go.sum is excluded by !**/*.sum
  • vendor/github.com/openshift/api/config/v1/types_cluster_operator.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/openshift/api/config/v1alpha1/types_cluster_monitoring.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/openshift/api/config/v1alpha1/zz_generated.deepcopy.go is excluded by !**/vendor/**, !vendor/**, !**/zz_generated*
  • vendor/github.com/openshift/api/config/v1alpha1/zz_generated.swagger_doc_generated.go is excluded by !**/vendor/**, !vendor/**, !**/zz_generated*
  • vendor/modules.txt is excluded by !**/vendor/**, !vendor/**
📒 Files selected for processing (4)
  • go.mod
  • pkg/manifests/config.go
  • pkg/manifests/config_merge.go
  • pkg/manifests/config_merge_test.go
🚧 Files skipped from review as they are similar to previous changes (1)
  • go.mod

Comment thread pkg/manifests/config_merge_test.go
Comment thread pkg/manifests/config_merge.go Outdated
Comment thread pkg/manifests/config_merge.go Outdated
// configMapYAMLDeclaresNodeExporter reports whether the cluster-monitoring-config body includes a
// top-level nodeExporter key (including explicit null). Phase 1: if set, the ConfigMap wins for
// the whole nodeExporter stanza and the ClusterMonitoring CR's nodeExporterConfig is ignored.
func configMapYAMLDeclaresNodeExporter(cmYAML string) bool {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The merge logic shouldn't depend on the input YAML. Can we refactor the config creation logic to avoid this?

@openshift-ci openshift-ci Bot added the needs-rebase Indicates a PR cannot be merged because it has merge conflicts with HEAD. label Jun 8, 2026
@marioferh
marioferh force-pushed the logic_NodeExporter branch from 1f054af to c455b9d Compare June 8, 2026 10:13
@openshift-ci openshift-ci Bot removed the needs-rebase Indicates a PR cannot be merged because it has merge conflicts with HEAD. label Jun 8, 2026
@marioferh
marioferh force-pushed the logic_NodeExporter branch from c455b9d to fa3dac9 Compare June 8, 2026 14:29
Comment thread pkg/manifests/config.go Outdated
func NewConfigFromStringAndClusterMonitoringResource(content string, cmr *configv1alpha1.ClusterMonitoring) (*Config, error) {
nodeExporterDeclaredByConfigMap := configMapDeclaresNodeExporter(content)

cmc := ClusterMonitoringConfiguration{

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

would it be possible to avoid initialization of the node_exporter fields and move this to applyDefaults()? it would remove the need for a different treatment when merging the node_exporter configuration.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think so. Done

@marioferh

Copy link
Copy Markdown
Contributor Author

/test e2e-aws-ovn

@openshift-ci openshift-ci Bot added the needs-rebase Indicates a PR cannot be merged because it has merge conflicts with HEAD. label Jun 9, 2026
@marioferh
marioferh force-pushed the logic_NodeExporter branch from fa3dac9 to 4850982 Compare June 9, 2026 07:42
@openshift-ci openshift-ci Bot removed the needs-rebase Indicates a PR cannot be merged because it has merge conflicts with HEAD. label Jun 9, 2026
@marioferh

Copy link
Copy Markdown
Contributor Author

/test generate

1 similar comment
@marioferh

Copy link
Copy Markdown
Contributor Author

/test generate

@danielmellado

Copy link
Copy Markdown
Contributor

/test e2e-hypershift-conformance

@simonpasquier simonpasquier left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

another option would be turn the bool fields controlling the enabled-by-default collector to pointers.

type NodeExporterCollectorNetDevConfig struct {
	// A Boolean flag that enables or disables the `netdev` collector.
	Enabled *bool `json:"enabled,omitempty"`
}
...
type NodeExporterCollectorNetClassConfig struct {
	// A Boolean flag that enables or disables the `netclass` collector.
	Enabled *bool `json:"enabled,omitempty"`
	// A Boolean flag that activates the `netlink` implementation of the `netclass` collector.
	// Its default value is `true`: activating the netlink mode.
	// This implementation improves the performance of the `netclass` collector.
	UseNetlink *bool `json:"useNetlink,omitempty"`
}

And inside applyDefaults(), set the fields to true if they are undefined/nil.

(the systemd collector doesn't need to be included because it's disabled by default)

marioferh and others added 3 commits June 10, 2026 19:11
Phase 1: if cluster-monitoring-config YAML declares nodeExporter, keep the
ConfigMap and ignore the CR for that block; otherwise map CR fields into
ClusterMonitoringConfiguration (collectors, resources, maxProcs, devices,
nodeSelector, tolerations).

Pass ConfigMap YAML into mergeClusterMonitoringCRD for key presence checks.
Apply nodeSelector and tolerations on the node-exporter DaemonSet when set.

Bump github.com/openshift/api and refresh generated API docs.

Co-authored-by: Cursor <cursoragent@cursor.com>
Use a nil *NodeExporterConfig to detect ConfigMap overrides instead of
re-parsing the cluster-monitoring-config YAML during CR merge.

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
@marioferh
marioferh force-pushed the logic_NodeExporter branch from 8d2bcef to 64c07a6 Compare June 10, 2026 17:15
Use pointer bools for netdev and netclass so omitted ConfigMap fields
keep their enabled-by-default values, and apply defaults in applyDefaults()
instead of re-unmarshaling the ConfigMap.

Co-authored-by: Cursor <cursoragent@cursor.com>
Comment thread pkg/manifests/config_merge.go Outdated
Iterate collection policies in a loop instead of repeating the same
condition for each collector.

Co-authored-by: Cursor <cursoragent@cursor.com>
@simonpasquier

Copy link
Copy Markdown
Contributor

/skip

@simonpasquier

Copy link
Copy Markdown
Contributor

/lgtm

@openshift-ci openshift-ci Bot added the lgtm Indicates that a PR is ready to be merged. label Jun 15, 2026
@openshift-ci

openshift-ci Bot commented Jun 15, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: marioferh, simonpasquier

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:
  • OWNERS [marioferh,simonpasquier]

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@marioferh

Copy link
Copy Markdown
Contributor Author

/test e2e-aws-ovn

@marioferh

Copy link
Copy Markdown
Contributor Author

/unhold

@marioferh

Copy link
Copy Markdown
Contributor Author

/test e2e-aws-ovn

@openshift-ci openshift-ci Bot removed the do-not-merge/hold Indicates that a PR should not merge because someone has issued a /hold command. label Jun 23, 2026
@marioferh marioferh changed the title MON-4527 - ClusterMonitoring NodeExporterConfig logic MON-4527: ClusterMonitoring NodeExporterConfig logic Jun 23, 2026
@openshift-ci-robot openshift-ci-robot added the jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. label Jun 23, 2026
@openshift-ci-robot

openshift-ci-robot commented Jun 23, 2026 •

Copy link
Copy Markdown
Contributor

@marioferh: This pull request references MON-4527 which is a valid jira issue.

Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the story to target the "5.0.0" version, but no target version was set.

Details

In response to this:

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@simonpasquier

Copy link
Copy Markdown
Contributor

/verified by tests

@openshift-ci-robot openshift-ci-robot added the verified Signifies that the PR passed pre-merge verification criteria label Jun 24, 2026
@openshift-ci-robot

Copy link
Copy Markdown
Contributor

@simonpasquier: This PR has been marked as verified by tests.

Details

In response to this:

/verified by tests

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

/retest-required

Remaining retests: 0 against base HEAD 8a48083 and 2 for PR HEAD 00408da in total

@marioferh

Copy link
Copy Markdown
Contributor Author

/retest-required

@simonpasquier

Copy link
Copy Markdown
Contributor

/test e2e-aws-ovn

@openshift-ci

openshift-ci Bot commented Jun 25, 2026 •

Copy link
Copy Markdown
Contributor

@marioferh: The following test failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test name Commit Details Required Rerun command
ci/prow/versions 00408da link false /test versions

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

/retest-required

Remaining retests: 0 against base HEAD 410e15d and 1 for PR HEAD 00408da in total

@openshift-merge-bot
openshift-merge-bot Bot merged commit 90ca0c2 into openshift:main Jun 25, 2026
22 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. lgtm Indicates that a PR is ready to be merged. verified Signifies that the PR passed pre-merge verification criteria

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants