feat(GCP-431): pass network service account to hypershift GCP e2e tests - #77415
Conversation
Extract the cloud-network SA created by hypershift create iam gcp and pass it as --e2e.gcp-network-sa to the e2e test binary so the cloud-network-config-controller pod gets WIF credentials. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
|
/hold |
|
[REHEARSALNOTIFIER]
Prior to this PR being merged, you will need to either run and acknowledge or opt to skip these rehearsals. Interacting with pj-rehearseComment: Once you are satisfied with the results of the rehearsals, comment: |
|
/lgtm |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: apahim, cblecker The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
|
/pj-rehearse pull-ci-openshift-hypershift-main-e2e-gke |
|
@cblecker: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
|
@cblecker: requesting more than one rehearsal in one comment is not supported. If you would like to rehearse multiple specific jobs, please separate the job names by a space in a single command. |
|
/pj-rehearse pull-ci-openshift-hypershift-main-e2e-v2-gke |
|
@cblecker: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
|
/pj-rehearse pull-ci-openshift-hypershift-main-e2e-gke pull-ci-openshift-hypershift-main-e2e-v2-gke |
|
@cblecker: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
|
@apahim: The following tests failed, say
Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
|
/pj-rehearse pull-ci-openshift-hypershift-main-e2e-gke |
|
@cblecker: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
|
/pj-rehearse pull-ci-openshift-hypershift-main-e2e-gke |
|
@cblecker: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
|
/pj-rehearse skip |
|
@cblecker: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
|
/hold cancel |
1d73cfc
into
openshift:main
|
@cblecker, |
…78662) The v2 GKE e2e workflow (hypershift-gcp-gke-e2e-v2) creates a hosted cluster directly via the hypershift CLI in the hypershift-gcp-create chain. Since openshift/hypershift#7824 made --network-service-account a required flag, the chain must read the network SA saved to SHARED_DIR by hypershift-gcp-hosted-cluster-setup and forward it to the CLI. This is a follow-up to #77415, which fixed the same issue for the v1 (hypershift-gcp-run-e2e) flow. Assisted-by: Claude:claude-opus-4-6[1m]
…ts (openshift#77415) Extract the cloud-network SA created by hypershift create iam gcp and pass it as --e2e.gcp-network-sa to the e2e test binary so the cloud-network-config-controller pod gets WIF credentials. Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
…ts (openshift#77415) Extract the cloud-network SA created by hypershift create iam gcp and pass it as --e2e.gcp-network-sa to the e2e test binary so the cloud-network-config-controller pod gets WIF credentials. Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
…penshift#78662) The v2 GKE e2e workflow (hypershift-gcp-gke-e2e-v2) creates a hosted cluster directly via the hypershift CLI in the hypershift-gcp-create chain. Since openshift/hypershift#7824 made --network-service-account a required flag, the chain must read the network SA saved to SHARED_DIR by hypershift-gcp-hosted-cluster-setup and forward it to the CLI. This is a follow-up to openshift#77415, which fixed the same issue for the v1 (hypershift-gcp-run-e2e) flow. Assisted-by: Claude:claude-opus-4-6[1m]
…ts (openshift#77415) Extract the cloud-network SA created by hypershift create iam gcp and pass it as --e2e.gcp-network-sa to the e2e test binary so the cloud-network-config-controller pod gets WIF credentials. Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
…penshift#78662) The v2 GKE e2e workflow (hypershift-gcp-gke-e2e-v2) creates a hosted cluster directly via the hypershift CLI in the hypershift-gcp-create chain. Since openshift/hypershift#7824 made --network-service-account a required flag, the chain must read the network SA saved to SHARED_DIR by hypershift-gcp-hosted-cluster-setup and forward it to the CLI. This is a follow-up to openshift#77415, which fixed the same issue for the v1 (hypershift-gcp-run-e2e) flow. Assisted-by: Claude:claude-opus-4-6[1m]
…ts (openshift#77415) Extract the cloud-network SA created by hypershift create iam gcp and pass it as --e2e.gcp-network-sa to the e2e test binary so the cloud-network-config-controller pod gets WIF credentials. Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
…penshift#78662) The v2 GKE e2e workflow (hypershift-gcp-gke-e2e-v2) creates a hosted cluster directly via the hypershift CLI in the hypershift-gcp-create chain. Since openshift/hypershift#7824 made --network-service-account a required flag, the chain must read the network SA saved to SHARED_DIR by hypershift-gcp-hosted-cluster-setup and forward it to the CLI. This is a follow-up to openshift#77415, which fixed the same issue for the v1 (hypershift-gcp-run-e2e) flow. Assisted-by: Claude:claude-opus-4-6[1m]
…ts (openshift#77415) Extract the cloud-network SA created by hypershift create iam gcp and pass it as --e2e.gcp-network-sa to the e2e test binary so the cloud-network-config-controller pod gets WIF credentials. Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
…penshift#78662) The v2 GKE e2e workflow (hypershift-gcp-gke-e2e-v2) creates a hosted cluster directly via the hypershift CLI in the hypershift-gcp-create chain. Since openshift/hypershift#7824 made --network-service-account a required flag, the chain must read the network SA saved to SHARED_DIR by hypershift-gcp-hosted-cluster-setup and forward it to the CLI. This is a follow-up to openshift#77415, which fixed the same issue for the v1 (hypershift-gcp-run-e2e) flow. Assisted-by: Claude:claude-opus-4-6[1m]
…ts (openshift#77415) Extract the cloud-network SA created by hypershift create iam gcp and pass it as --e2e.gcp-network-sa to the e2e test binary so the cloud-network-config-controller pod gets WIF credentials. Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
…penshift#78662) The v2 GKE e2e workflow (hypershift-gcp-gke-e2e-v2) creates a hosted cluster directly via the hypershift CLI in the hypershift-gcp-create chain. Since openshift/hypershift#7824 made --network-service-account a required flag, the chain must read the network SA saved to SHARED_DIR by hypershift-gcp-hosted-cluster-setup and forward it to the CLI. This is a follow-up to openshift#77415, which fixed the same issue for the v1 (hypershift-gcp-run-e2e) flow. Assisted-by: Claude:claude-opus-4-6[1m]
…ts (openshift#77415) Extract the cloud-network SA created by hypershift create iam gcp and pass it as --e2e.gcp-network-sa to the e2e test binary so the cloud-network-config-controller pod gets WIF credentials. Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
…penshift#78662) The v2 GKE e2e workflow (hypershift-gcp-gke-e2e-v2) creates a hosted cluster directly via the hypershift CLI in the hypershift-gcp-create chain. Since openshift/hypershift#7824 made --network-service-account a required flag, the chain must read the network SA saved to SHARED_DIR by hypershift-gcp-hosted-cluster-setup and forward it to the CLI. This is a follow-up to openshift#77415, which fixed the same issue for the v1 (hypershift-gcp-run-e2e) flow. Assisted-by: Claude:claude-opus-4-6[1m]
Summary
cloud-networkservice account created byhypershift create iam gcpand pass it as--e2e.gcp-network-sato the e2e test binary so the cloud-network-config-controller pod gets WIF credentials.Dependencies
Changes
ci-operator/step-registry/hypershift/gcp/hosted-cluster-setup/hypershift-gcp-hosted-cluster-setup-commands.sh: ExtractNETWORK_SAfrom IAM output and save to${SHARED_DIR}/network-saci-operator/step-registry/hypershift/gcp/run-e2e/hypershift-gcp-run-e2e-commands.sh: Readnetwork-saand pass--e2e.gcp-network-sato e2e binaryTest plan
hypershift-operatorandhypershift-testsimages rebuild with CNCC support/holdand let CI rehearsal jobs pass🤖 Generated with Claude Code