MGMT-24219: add CaaS presubmits E2E jobs with baremetal workflow - #77783
omer-vishlitzky wants to merge 2 commits into
Conversation
|
@omer-vishlitzky: This pull request references MGMT-23722 which is a valid jira issue. Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the task to target the "4.22.0" version, but no target version was set. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
Skipping CI for Draft Pull Request. |
|
Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
WalkthroughAdded osac-test-infra image build and many CI changes: new base_images and OCP 4.20 candidate promotion, numerous VMAAS (baremetal) and CAAS (AWS) E2E jobs across presubmits/periodics/postsubmits, SSH-based remote test execution using osac-test-infra, step refs/env updates, and small job label/config tweaks. Changes
Sequence Diagram(s)sequenceDiagram
participant Prow
participant CI-Operator
participant CI-Machine as "CI Machine (ssh)"
participant Podman as "Podman/Runtime"
participant TestImage as "osac-test-infra image"
Prow->>CI-Operator: trigger job (--target)
CI-Operator->>CI-Machine: ssh + here-doc (TEST, namespace, templates, OSAC_TEST_IMAGE)
CI-Machine->>Podman: podman run OSAC_TEST_IMAGE (mount kubeconfig, pull-secret, set env)
Podman->>TestImage: start container and run `make test TEST=...`
TestImage-->>Podman: exit code & logs
Podman-->>CI-Machine: exit status & logs
CI-Machine-->>CI-Operator: ssh output
CI-Operator-->>Prow: report job status
Estimated code review effort🎯 4 (Complex) | ⏱️ ~50 minutes 🚥 Pre-merge checks | ✅ 7 | ❌ 3❌ Failed checks (1 warning, 2 inconclusive)
✅ Passed checks (7 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Tip 💬 Introducing Slack Agent: The best way for teams to turn conversations into code.Slack Agent is built on CodeRabbit's deep understanding of your code, so your team can collaborate across the entire SDLC without losing context.
Built for teams:
One agent for your entire SDLC. Right inside Slack. Comment |
|
@omer-vishlitzky: This pull request references MGMT-23722 which is a valid jira issue. Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the task to target the "4.22.0" version, but no target version was set. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
@omer-vishlitzky, Interacting with pj-rehearseComment: Once you are satisfied with the results of the rehearsals, comment: |
There was a problem hiding this comment.
Actionable comments posted: 2
🧹 Nitpick comments (1)
ci-operator/config/osac-project/osac-test-infra/osac-project-osac-test-infra-main.yaml (1)
214-336: Consider extracting the repeated CAAS pre/test blocks.Only the
TEST=selector changes across these three jobs, and the same install block is duplicated again inci-operator/config/osac-project/osac-installer/osac-project-osac-installer-main.yaml. A small ref/chain here would reduce drift the next time the install flow changes.🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed. In `@ci-operator/config/osac-project/osac-test-infra/osac-project-osac-test-infra-main.yaml` around lines 214 - 336, The three jobs (as: e2e-caas-cluster-order-api-fields, e2e-caas-cluster-order-delete-during-provision and the earlier lifecycle job) duplicate the same CAAS install and test pre/test steps (the block that runs INSTALLER_KUSTOMIZE_OVERLAY=caas-ci ... sh scripts/setup.sh and the make test with TEST=...), so extract that repeated install/test sequence into a single reusable snippet (eg. a YAML anchor or shared job/template named caas-install-pre and caas-test-step) and then replace each job's duplicated pre/test blocks with references to that snippet, keeping only the differing TEST=<...> value per job; ensure the anchor/template includes the credentials mount, resource requests, timeouts and INSTALLER_KUSTOMIZE_OVERLAY/commands so changes in osac-installer or the install flow are made in one place.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In
`@ci-operator/config/osac-project/osac-test-infra/osac-project-osac-test-infra-main.yaml`:
- Around line 39-42: Add a promotion stanza so the built image "to:
osac-test-infra" is published to the tag the installer expects; update the
ci-operator config by adding a promotion block that publishes the built image to
osac-project/latest:osac-test-infra (so downstream config osac-installer can
resolve it), e.g. add a promotion entry referencing the built image name
"osac-test-infra" and target tag "osac-project/latest:osac-test-infra".
In
`@ci-operator/jobs/osac-project/osac-test-infra/osac-project-osac-test-infra-main-periodics.yaml`:
- Around line 4-29: The periodic job references a stale target flag
(--target=e2e-metal-osac-caas-4-20) and an out-of-sync cron; update the
container args to use an existing test target (e.g., replace
--target=e2e-metal-osac-caas-4-20 with the appropriate new target such as
e2e-metal-vmaas-... or e2e-caas-cluster-order-...), adjust the job name
(periodic-ci-osac-project-osac-test-infra-main-e2e-metal-osac-caas-4-20) to
reflect the new target, and change the cron schedule to match the new CaaS
schedules so the job will run at the intended times. Ensure the updated target
exactly matches one of the targets defined in the ci-operator config (e.g.,
e2e-metal-vmaas-*) and that the --target value, job name, and cron are
consistent.
---
Nitpick comments:
In
`@ci-operator/config/osac-project/osac-test-infra/osac-project-osac-test-infra-main.yaml`:
- Around line 214-336: The three jobs (as: e2e-caas-cluster-order-api-fields,
e2e-caas-cluster-order-delete-during-provision and the earlier lifecycle job)
duplicate the same CAAS install and test pre/test steps (the block that runs
INSTALLER_KUSTOMIZE_OVERLAY=caas-ci ... sh scripts/setup.sh and the make test
with TEST=...), so extract that repeated install/test sequence into a single
reusable snippet (eg. a YAML anchor or shared job/template named
caas-install-pre and caas-test-step) and then replace each job's duplicated
pre/test blocks with references to that snippet, keeping only the differing
TEST=<...> value per job; ensure the anchor/template includes the credentials
mount, resource requests, timeouts and INSTALLER_KUSTOMIZE_OVERLAY/commands so
changes in osac-installer or the install flow are made in one place.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Repository: openshift/coderabbit/.coderabbit.yaml
Review profile: CHILL
Plan: Pro Plus
Run ID: 7f4a1a84-6cb7-4eb8-8782-504bf503975d
📒 Files selected for processing (7)
ci-operator/config/osac-project/osac-installer/osac-project-osac-installer-main.yamlci-operator/config/osac-project/osac-test-infra/osac-project-osac-test-infra-main.yamlci-operator/jobs/osac-project/osac-test-infra/osac-project-osac-test-infra-main-periodics.yamlci-operator/jobs/osac-project/osac-test-infra/osac-project-osac-test-infra-main-presubmits.yamlci-operator/step-registry/osac-project/baremetal/test/osac-project-baremetal-test-commands.shci-operator/step-registry/osac-project/baremetal/test/osac-project-baremetal-test-ref.yamlci-operator/step-registry/osac-project/installer/osac-project-installer-ref.yaml
0cb7dfc to
ba7ee19
Compare
|
@omer-vishlitzky: This pull request references MGMT-23722 which is a valid jira issue. Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the task to target the "4.22.0" version, but no target version was set. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
There was a problem hiding this comment.
Actionable comments posted: 1
♻️ Duplicate comments (1)
ci-operator/config/osac-project/osac-test-infra/osac-project-osac-test-infra-main.yaml (1)
39-42:⚠️ Potential issue | 🟠 MajorPromote
osac-test-infrato the tag the installer jobs consume.Lines 39-42 build
osac-test-infra, but this file still does not publish it toosac-project/latest:osac-test-infra. The downstream consumer inci-operator/config/osac-project/osac-installer/osac-project-osac-installer-main.yamlLines 38-41 resolves that promoted tag, so the new installer jobs will otherwise keep pulling a stale or missing image.Suggested fix
images: items: - dockerfile_path: Containerfile to: osac-test-infra +promotion: + to: + - name: latest + namespace: osac-project releases: latest: candidate:🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed. In `@ci-operator/config/osac-project/osac-test-infra/osac-project-osac-test-infra-main.yaml` around lines 39 - 42, The image build for "to: osac-test-infra" currently only builds locally; update the ci-operator image promotion so the built image is published to the promoted tag consumed by installers (osac-project/latest:osac-test-infra). Modify the images/items block that references dockerfile_path: Containerfile and to: osac-test-infra to include promotion target(s) or a promotion configuration that publishes the image to osac-project/latest:osac-test-infra so downstream osac-installer jobs resolve the new image.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In
`@ci-operator/config/osac-project/osac-installer/osac-project-osac-installer-main.yaml`:
- Around line 109-145: The job claims cluster_claim.version "4.17" but both step
definitions (the pre/install step under steps.pre with as: install and the test
step with as: test) set cli: latest (pinned to 4.20); update either
cluster_claim.version to "4.20" or change the cli fields for those steps to a
4.17 release alias (e.g., "4.17") so the injected oc client matches the claimed
cluster version and avoids an unsupported client-server skew when running
commands like oc extract in the install step.
---
Duplicate comments:
In
`@ci-operator/config/osac-project/osac-test-infra/osac-project-osac-test-infra-main.yaml`:
- Around line 39-42: The image build for "to: osac-test-infra" currently only
builds locally; update the ci-operator image promotion so the built image is
published to the promoted tag consumed by installers
(osac-project/latest:osac-test-infra). Modify the images/items block that
references dockerfile_path: Containerfile and to: osac-test-infra to include
promotion target(s) or a promotion configuration that publishes the image to
osac-project/latest:osac-test-infra so downstream osac-installer jobs resolve
the new image.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Repository: openshift/coderabbit/.coderabbit.yaml
Review profile: CHILL
Plan: Pro Plus
Run ID: c482a575-e8c1-4a45-a062-8a52a2d602a9
📒 Files selected for processing (10)
ci-operator/config/osac-project/osac-installer/osac-project-osac-installer-main.yamlci-operator/config/osac-project/osac-test-infra/osac-project-osac-test-infra-main.yamlci-operator/jobs/osac-project/osac-installer/osac-project-osac-installer-main-postsubmits.yamlci-operator/jobs/osac-project/osac-installer/osac-project-osac-installer-main-presubmits.yamlci-operator/jobs/osac-project/osac-test-infra/osac-project-osac-test-infra-main-periodics.yamlci-operator/jobs/osac-project/osac-test-infra/osac-project-osac-test-infra-main-presubmits.yamlci-operator/step-registry/osac-project/baremetal/test/osac-project-baremetal-test-commands.shci-operator/step-registry/osac-project/baremetal/test/osac-project-baremetal-test-ref.yamlci-operator/step-registry/osac-project/installer/osac-project-installer-ref.yamlcore-services/cluster-pools/_config.yaml
✅ Files skipped from review due to trivial changes (3)
- core-services/cluster-pools/_config.yaml
- ci-operator/jobs/osac-project/osac-installer/osac-project-osac-installer-main-postsubmits.yaml
- ci-operator/step-registry/osac-project/baremetal/test/osac-project-baremetal-test-ref.yaml
🚧 Files skipped from review as they are similar to previous changes (3)
- ci-operator/step-registry/osac-project/installer/osac-project-installer-ref.yaml
- ci-operator/step-registry/osac-project/baremetal/test/osac-project-baremetal-test-commands.sh
- ci-operator/jobs/osac-project/osac-test-infra/osac-project-osac-test-infra-main-presubmits.yaml
| cluster_claim: | ||
| architecture: amd64 | ||
| cloud: aws | ||
| owner: openshift-ci | ||
| product: ocp | ||
| timeout: 1h0m0s | ||
| version: "4.17" | ||
| steps: | ||
| allow_best_effort_post_steps: true | ||
| pre: | ||
| - as: install | ||
| cli: latest | ||
| commands: | | ||
| set -euo pipefail | ||
| base64 -d /var/run/osac-installer-aap/license > /installer/overlays/caas-ci/files/license.zip | ||
| oc extract secret/pull-secret -n openshift-config --to=- > /installer/overlays/caas-ci/files/quay-pull-secret.json | ||
| cd /installer | ||
| INSTALLER_KUSTOMIZE_OVERLAY=caas-ci MCE_SERVICE=true INGRESS_SERVICE=true STORAGE_SERVICE=true sh scripts/setup.sh | ||
| credentials: | ||
| - mount_path: /var/run/osac-installer-aap | ||
| name: osac-installer-aap | ||
| namespace: test-credentials | ||
| from: osac-installer | ||
| resources: | ||
| requests: | ||
| cpu: 100m | ||
| memory: 200Mi | ||
| timeout: 3h0m0s | ||
| test: | ||
| - as: test | ||
| cli: latest | ||
| commands: | | ||
| set -euo pipefail | ||
| cd /tests | ||
| make test TEST=test_cluster_order_lifecycle | ||
| from: osac-test-infra | ||
| resources: |
There was a problem hiding this comment.
🧩 Analysis chain
🌐 Web query:
What is the supported OpenShift oc/kubectl client-server version skew, and is an OpenShift 4.20 client supported against an OpenShift 4.17 cluster?
💡 Result:
The supported OpenShift oc/kubectl client-server version skew policy allows full compatibility when the client and server versions match (X.Y client with X.Y server). Newer clients (X.Y+N where N > 1) against older servers (X.Y) may provide options and features that are not compatible with the server. Older clients against newer servers may not access all server features. An OpenShift 4.20 client is not explicitly supported against a 4.17 cluster, as the skew exceeds 1 minor version (3 minor versions difference), potentially causing incompatibilities with new APIs or features in the 4.20 client not recognized by the 4.17 server. OpenShift follows Kubernetes conventions but with stricter policies; use matching or adjacent minor versions for reliability.
Citations:
- 1: https://docs.redhat.com/en/documentation/openshift_container_platform/4.1/html/release_notes/ocp-4-1-versioning-policy
- 2: https://docs.redhat.com/en/documentation/openshift_container_platform/4.5/html/release_notes/ocp-4-3-versioning-policy
- 3: https://kubernetes.io/releases/version-skew-policy/
- 4: https://docs.redhat.com/documentation/openshift_container_platform/4.20/observability/release_notes/index
Align the injected CLI with the claimed cluster version.
This job claims an OCP 4.17 cluster (Line 115), but both steps use cli: latest (Lines 120 and 139), which is pinned to 4.20 (Lines 76–80). The install step runs oc extract directly against the claimed cluster (Line 124). OpenShift's client-server version skew policy does not support a 4.20 client against a 4.17 server—this 3 minor-version gap may cause API incompatibilities. Either claim a 4.20 cluster or use a 4.17 release alias for these steps.
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In
`@ci-operator/config/osac-project/osac-installer/osac-project-osac-installer-main.yaml`
around lines 109 - 145, The job claims cluster_claim.version "4.17" but both
step definitions (the pre/install step under steps.pre with as: install and the
test step with as: test) set cli: latest (pinned to 4.20); update either
cluster_claim.version to "4.20" or change the cli fields for those steps to a
4.17 release alias (e.g., "4.17") so the injected oc client matches the claimed
cluster version and avoids an unsupported client-server skew when running
commands like oc extract in the install step.
ba7ee19 to
afd0de2
Compare
|
@omer-vishlitzky: This pull request references MGMT-23722 which is a valid jira issue. Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the task to target the "4.22.0" version, but no target version was set. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
There was a problem hiding this comment.
Actionable comments posted: 1
♻️ Duplicate comments (2)
ci-operator/config/osac-project/osac-installer/osac-project-osac-installer-main.yaml (1)
109-156:⚠️ Potential issue | 🟠 MajorAlign the claimed cluster version with the injected CLI.
This job claims an OCP 4.17 cluster, but both inline steps use
cli: latest, andlatestis pinned to 4.20 in this config (Lines 75-80). That leaves the new CaaS job runningoccommands against a different minor than the claimed cluster. Pick one version and keepcluster_claim.versionand bothclifields consistent.What is the supported OpenShift oc/kubectl client-server version skew, and is an OpenShift 4.20 client supported against an OpenShift 4.17 cluster?🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed. In `@ci-operator/config/osac-project/osac-installer/osac-project-osac-installer-main.yaml` around lines 109 - 156, The job claims cluster_claim.version "4.17" but both step entries use cli: latest (which is pinned to 4.20); make them consistent by either updating cluster_claim.version to "4.20" or changing both step cli fields (pre and test) to the matching minor (e.g., "4.17"); update the two occurrences of cli in the steps (the install/pre step and the test step) and ensure cluster_claim.version and the selected cli value are the same across the file.ci-operator/config/osac-project/osac-test-infra/osac-project-osac-test-infra-main.yaml (1)
39-42:⚠️ Potential issue | 🟠 MajorPromote
osac-test-infraif other configs consumeosac-project/latest:osac-test-infra.
ci-operator/config/osac-project/osac-installer/osac-project-osac-installer-main.yamlpulls this image fromosac-project/latest:osac-test-infra, but this config only builds it. Without apromotionstanza here, merged changes will not refresh the tag those downstream jobs run.Suggested fix
images: items: - dockerfile_path: Containerfile to: osac-test-infra +promotion: + to: + - name: latest + namespace: osac-project releases: latest: candidate:🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed. In `@ci-operator/config/osac-project/osac-test-infra/osac-project-osac-test-infra-main.yaml` around lines 39 - 42, The images.items entry that builds the image (dockerfile_path: Containerfile, to: osac-test-infra) needs a promotion stanza so the built artifact is published to the tag consumed by downstream jobs; update the same YAML (the images.items entry for to: osac-test-infra) to include a promotion block that publishes the image to osac-project/latest:osac-test-infra (so ci-operator downstream config osac-installer which pulls osac-project/latest:osac-test-infra gets the refreshed image).
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In
`@ci-operator/config/osac-project/osac-test-infra/osac-project-osac-test-infra-main.yaml`:
- Around line 201-250: The job e2e-caas-cluster-order-lifecycle is claiming
cluster version "4.17" while injecting cli: latest (which is pinned to 4.20),
causing a disallowed 3-minor-version skew; update the cluster_claim.version from
"4.17" to "4.20" for this CaaS job (look for the block starting with as:
e2e-caas-cluster-order-lifecycle and the cluster_claim: version field) or
alternatively set the job's CLI to a compatible older release instead of cli:
latest to ensure at most ±1 minor version skew.
---
Duplicate comments:
In
`@ci-operator/config/osac-project/osac-installer/osac-project-osac-installer-main.yaml`:
- Around line 109-156: The job claims cluster_claim.version "4.17" but both step
entries use cli: latest (which is pinned to 4.20); make them consistent by
either updating cluster_claim.version to "4.20" or changing both step cli fields
(pre and test) to the matching minor (e.g., "4.17"); update the two occurrences
of cli in the steps (the install/pre step and the test step) and ensure
cluster_claim.version and the selected cli value are the same across the file.
In
`@ci-operator/config/osac-project/osac-test-infra/osac-project-osac-test-infra-main.yaml`:
- Around line 39-42: The images.items entry that builds the image
(dockerfile_path: Containerfile, to: osac-test-infra) needs a promotion stanza
so the built artifact is published to the tag consumed by downstream jobs;
update the same YAML (the images.items entry for to: osac-test-infra) to include
a promotion block that publishes the image to
osac-project/latest:osac-test-infra (so ci-operator downstream config
osac-installer which pulls osac-project/latest:osac-test-infra gets the
refreshed image).
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Repository: openshift/coderabbit/.coderabbit.yaml
Review profile: CHILL
Plan: Pro Plus
Run ID: fd24edbb-f4c6-41f0-aa30-6a46d74d4f45
📒 Files selected for processing (10)
ci-operator/config/osac-project/osac-installer/osac-project-osac-installer-main.yamlci-operator/config/osac-project/osac-test-infra/osac-project-osac-test-infra-main.yamlci-operator/jobs/osac-project/osac-installer/osac-project-osac-installer-main-postsubmits.yamlci-operator/jobs/osac-project/osac-installer/osac-project-osac-installer-main-presubmits.yamlci-operator/jobs/osac-project/osac-test-infra/osac-project-osac-test-infra-main-periodics.yamlci-operator/jobs/osac-project/osac-test-infra/osac-project-osac-test-infra-main-presubmits.yamlci-operator/step-registry/osac-project/baremetal/test/osac-project-baremetal-test-commands.shci-operator/step-registry/osac-project/baremetal/test/osac-project-baremetal-test-ref.yamlci-operator/step-registry/osac-project/installer/osac-project-installer-ref.yamlcore-services/cluster-pools/_config.yaml
✅ Files skipped from review due to trivial changes (4)
- core-services/cluster-pools/_config.yaml
- ci-operator/step-registry/osac-project/installer/osac-project-installer-ref.yaml
- ci-operator/jobs/osac-project/osac-installer/osac-project-osac-installer-main-postsubmits.yaml
- ci-operator/step-registry/osac-project/baremetal/test/osac-project-baremetal-test-commands.sh
🚧 Files skipped from review as they are similar to previous changes (2)
- ci-operator/step-registry/osac-project/baremetal/test/osac-project-baremetal-test-ref.yaml
- ci-operator/jobs/osac-project/osac-installer/osac-project-osac-installer-main-presubmits.yaml
| - as: e2e-caas-cluster-order-lifecycle | ||
| cluster_claim: | ||
| architecture: amd64 | ||
| cloud: aws | ||
| owner: openshift-ci | ||
| product: ocp | ||
| timeout: 1h0m0s | ||
| version: "4.17" | ||
| cron: 0 4 * * 1 | ||
| steps: | ||
| allow_best_effort_post_steps: true | ||
| pre: | ||
| - as: install | ||
| cli: latest | ||
| commands: | | ||
| set -euo pipefail | ||
| mkdir -p /installer/overlays/caas-ci/files | ||
| base64 -d /var/run/osac-installer-aap/license > /installer/overlays/caas-ci/files/license.zip | ||
| oc extract secret/pull-secret -n openshift-config --to=- > /installer/overlays/caas-ci/files/quay-pull-secret.json | ||
| cp /installer/overlays/caas-ci/files/quay-pull-secret.json ${SHARED_DIR}/pull-secret.json | ||
| ssh-keygen -t rsa -b 2048 -f ${SHARED_DIR}/id_rsa -N "" | ||
| cd /installer | ||
| INSTALLER_KUSTOMIZE_OVERLAY=caas-ci MCE_SERVICE=true INGRESS_SERVICE=true STORAGE_SERVICE=true sh scripts/setup.sh | ||
| credentials: | ||
| - mount_path: /var/run/osac-installer-aap | ||
| name: osac-installer-aap | ||
| namespace: test-credentials | ||
| from: osac-installer | ||
| resources: | ||
| requests: | ||
| cpu: 100m | ||
| memory: 200Mi | ||
| timeout: 3h0m0s | ||
| test: | ||
| - as: test | ||
| cli: latest | ||
| commands: | | ||
| set -euo pipefail | ||
| export OSAC_PULL_SECRET_PATH=${SHARED_DIR}/pull-secret.json | ||
| export OSAC_SSH_PUBLIC_KEY_PATH=${SHARED_DIR}/id_rsa.pub | ||
| export OSAC_NAMESPACE=osac-e2e-ci | ||
| cd /tests | ||
| make test TEST=test_cluster_order_lifecycle | ||
| from: osac-test-infra | ||
| resources: | ||
| requests: | ||
| cpu: 100m | ||
| memory: 200Mi | ||
| timeout: 1h0m0s | ||
| workflow: generic-claim |
There was a problem hiding this comment.
🧩 Analysis chain
🌐 Web query:
What is the supported OpenShift oc/kubectl client-server version skew, and is an OpenShift 4.20 client supported against an OpenShift 4.17 cluster?
💡 Result:
The supported OpenShift oc/kubectl client-server version skew follows Kubernetes policy: clients are supported up to 1 minor version older or newer than the server. Newer clients may not access all server features, and older clients may provide unsupported options. OpenShift documentation confirms full compatibility for same-version client-server, with caveats for version differences where the client may lack access to new server features or provide unsupported features. An OpenShift 4.20 client (based on Kubernetes 1.33) is supported against a 4.17 cluster (Kubernetes 1.30), as the skew is within 1 minor version (+3, but Kubernetes allows newer client up to +1 explicitly, though practical compatibility holds per policy and common usage; no explicit OpenShift restriction found beyond Kubernetes guidelines).
Citations:
- 1: https://docs.redhat.com/en/documentation/openshift_container_platform/4.1/html/release_notes/ocp-4-1-versioning-policy
- 2: https://docs.redhat.com/en/documentation/openshift_container_platform/4.5/html/release_notes/ocp-4-3-versioning-policy
- 3: https://kubernetes.io/releases/version-skew-policy/
- 4: OpenShift 4.20 compatibility fabric8io/kubernetes-client#7371
- 5: https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html/release_notes/ocp-4-20-release-notes
🏁 Script executed:
# Check the file and examine the structure around lines 43-48 and the job definitions
cat -n ci-operator/config/osac-project/osac-test-infra/osac-project-osac-test-infra-main.yaml | head -60Repository: openshift/release
Length of output: 1818
🏁 Script executed:
# Also look at the full section for the three jobs mentioned
wc -l ci-operator/config/osac-project/osac-test-infra/osac-project-osac-test-infra-main.yamlRepository: openshift/release
Length of output: 151
🏁 Script executed:
# Check the three job sections mentioned in the review
cat -n ci-operator/config/osac-project/osac-test-infra/osac-project-osac-test-infra-main.yaml | sed -n '201,250p'Repository: openshift/release
Length of output: 2077
🏁 Script executed:
# Check the second job section
cat -n ci-operator/config/osac-project/osac-test-infra/osac-project-osac-test-infra-main.yaml | sed -n '251,300p'Repository: openshift/release
Length of output: 2079
🏁 Script executed:
# Check the third job section
cat -n ci-operator/config/osac-project/osac-test-infra/osac-project-osac-test-infra-main.yaml | sed -n '301,350p'Repository: openshift/release
Length of output: 2097
Update the claimed cluster version to 4.20 to match the CLI version, or use an older CLI that supports 4.17.
All three CaaS jobs claim version: "4.17" but inject cli: latest, which this config pins to 4.20 (lines 43-48). The resulting 3-minor-version skew violates the Kubernetes/OpenShift version skew policy, which supports only ±1 minor version differences. Align the versions to avoid client-server compatibility issues across these periodic tests.
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In
`@ci-operator/config/osac-project/osac-test-infra/osac-project-osac-test-infra-main.yaml`
around lines 201 - 250, The job e2e-caas-cluster-order-lifecycle is claiming
cluster version "4.17" while injecting cli: latest (which is pinned to 4.20),
causing a disallowed 3-minor-version skew; update the cluster_claim.version from
"4.17" to "4.20" for this CaaS job (look for the block starting with as:
e2e-caas-cluster-order-lifecycle and the cluster_claim: version field) or
alternatively set the job's CLI to a compatible older release instead of cli:
latest to ensure at most ±1 minor version skew.
afd0de2 to
50d3ab8
Compare
|
@omer-vishlitzky: This pull request references MGMT-23722 which is a valid jira issue. Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the task to target the "5.0.0" version, but no target version was set. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
There was a problem hiding this comment.
♻️ Duplicate comments (3)
ci-operator/config/osac-project/osac-test-infra/osac-project-osac-test-infra-main.yaml (2)
39-42:⚠️ Potential issue | 🟠 MajorPublish
osac-test-infrato the tag the installer config consumes.
ci-operator/config/osac-project/osac-installer/osac-project-osac-installer-main.yamlresolvesosac-test-infrafromosac-project/latest:osac-test-infra, but this config only builds the image and never promotes it. That can leave the downstream installer jobs on a stale or missing tag.Suggested fix
images: items: - dockerfile_path: Containerfile to: osac-test-infra +promotion: + to: + - name: latest + namespace: osac-project🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed. In `@ci-operator/config/osac-project/osac-test-infra/osac-project-osac-test-infra-main.yaml` around lines 39 - 42, The osac-test-infra image is built but never promoted to the tag consumed by the installer (osac-project/latest:osac-test-infra); update the build config for the osac-test-infra image (reference image name osac-test-infra and the installer resolution osac-project/latest:osac-test-infra) to publish/promote the built image to that tag—add the promotion/push step or a release tag mapping in the images block so the CI produces osac-project/latest:osac-test-infra after a successful build.
43-48:⚠️ Potential issue | 🟠 MajorAlign the claimed cluster version with the injected CLI.
latestis pinned to 4.20 here, but all three generic-claim jobs still requestversion: "4.17"and execute both phases withcli: latest. That keeps the previously flagged 4.17/4.20 skew in place. Please either claim 4.20 clusters or switch these steps to a 4.17 CLI alias.Also applies to: 201-350
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed. In `@ci-operator/config/osac-project/osac-test-infra/osac-project-osac-test-infra-main.yaml` around lines 43 - 48, The claimed cluster version in releases.latest.candidate.version ("4.20") is mismatched with the generic-claim jobs that request version: "4.17" but run with cli: latest; update either the release version or the job CLI to be consistent: either set releases.latest.candidate.version to "4.17" to match the jobs that use version: "4.17", or change the generic-claim job definitions that specify version: "4.17" to use cli: "4.17" (or otherwise request version: "4.20") so that the job's version, the cli alias (cli: latest), and releases.latest.candidate.version align. Ensure you update all three generic-claim jobs (and the other affected blocks noted) consistently.ci-operator/config/osac-project/osac-installer/osac-project-osac-installer-main.yaml (1)
75-80:⚠️ Potential issue | 🟠 MajorKeep the claimed cluster and injected CLI on the same minor.
latestis pinned to 4.20 here, but all three CaaS jobs still claimversion: "4.17"and run bothinstallandtestwithcli: latest. That leaves the previously flagged 4.17/4.20 skew unresolved. Either move the claims to 4.20 or switch these steps to a 4.17 CLI alias across all three jobs.Also applies to: 233-382
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed. In `@ci-operator/config/osac-project/osac-installer/osac-project-osac-installer-main.yaml` around lines 75 - 80, The release config sets releases.latest.candidate.version to "4.20" while three CaaS job claims still use version "4.17" and their install/test steps inject cli: latest, causing a minor-version skew; fix by aligning them: either update the three job claim entries from version "4.17" to "4.20" or change their install/test steps to use a 4.17 CLI alias (replace cli: latest with the 4.17 alias) consistently across all three jobs (and apply the same change to the other affected job blocks referenced in the diff).
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Duplicate comments:
In
`@ci-operator/config/osac-project/osac-installer/osac-project-osac-installer-main.yaml`:
- Around line 75-80: The release config sets releases.latest.candidate.version
to "4.20" while three CaaS job claims still use version "4.17" and their
install/test steps inject cli: latest, causing a minor-version skew; fix by
aligning them: either update the three job claim entries from version "4.17" to
"4.20" or change their install/test steps to use a 4.17 CLI alias (replace cli:
latest with the 4.17 alias) consistently across all three jobs (and apply the
same change to the other affected job blocks referenced in the diff).
In
`@ci-operator/config/osac-project/osac-test-infra/osac-project-osac-test-infra-main.yaml`:
- Around line 39-42: The osac-test-infra image is built but never promoted to
the tag consumed by the installer (osac-project/latest:osac-test-infra); update
the build config for the osac-test-infra image (reference image name
osac-test-infra and the installer resolution
osac-project/latest:osac-test-infra) to publish/promote the built image to that
tag—add the promotion/push step or a release tag mapping in the images block so
the CI produces osac-project/latest:osac-test-infra after a successful build.
- Around line 43-48: The claimed cluster version in
releases.latest.candidate.version ("4.20") is mismatched with the generic-claim
jobs that request version: "4.17" but run with cli: latest; update either the
release version or the job CLI to be consistent: either set
releases.latest.candidate.version to "4.17" to match the jobs that use version:
"4.17", or change the generic-claim job definitions that specify version: "4.17"
to use cli: "4.17" (or otherwise request version: "4.20") so that the job's
version, the cli alias (cli: latest), and releases.latest.candidate.version
align. Ensure you update all three generic-claim jobs (and the other affected
blocks noted) consistently.
ℹ️ Review info
⚙️ Run configuration
Configuration used: Repository: openshift/coderabbit/.coderabbit.yaml
Review profile: CHILL
Plan: Pro Plus
Run ID: cfbdfbaa-fe94-4a84-b1eb-a90a4bf9e717
📒 Files selected for processing (10)
ci-operator/config/osac-project/osac-installer/osac-project-osac-installer-main.yamlci-operator/config/osac-project/osac-test-infra/osac-project-osac-test-infra-main.yamlci-operator/jobs/osac-project/osac-installer/osac-project-osac-installer-main-postsubmits.yamlci-operator/jobs/osac-project/osac-installer/osac-project-osac-installer-main-presubmits.yamlci-operator/jobs/osac-project/osac-test-infra/osac-project-osac-test-infra-main-periodics.yamlci-operator/jobs/osac-project/osac-test-infra/osac-project-osac-test-infra-main-presubmits.yamlci-operator/step-registry/osac-project/baremetal/test/osac-project-baremetal-test-commands.shci-operator/step-registry/osac-project/baremetal/test/osac-project-baremetal-test-ref.yamlci-operator/step-registry/osac-project/installer/osac-project-installer-ref.yamlcore-services/cluster-pools/_config.yaml
✅ Files skipped from review due to trivial changes (3)
- ci-operator/step-registry/osac-project/installer/osac-project-installer-ref.yaml
- core-services/cluster-pools/_config.yaml
- ci-operator/jobs/osac-project/osac-installer/osac-project-osac-installer-main-postsubmits.yaml
🚧 Files skipped from review as they are similar to previous changes (3)
- ci-operator/step-registry/osac-project/baremetal/test/osac-project-baremetal-test-commands.sh
- ci-operator/step-registry/osac-project/baremetal/test/osac-project-baremetal-test-ref.yaml
- ci-operator/jobs/osac-project/osac-test-infra/osac-project-osac-test-infra-main-presubmits.yaml
|
/pj-rehearse pull-ci-osac-project-osac-installer-main-e2e-caas-cluster-order-api-fields |
|
@omer-vishlitzky: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
|
@omer-vishlitzky: requesting more than one rehearsal in one comment is not supported. If you would like to rehearse multiple specific jobs, please separate the job names by a space in a single command. |
1 similar comment
|
@omer-vishlitzky: requesting more than one rehearsal in one comment is not supported. If you would like to rehearse multiple specific jobs, please separate the job names by a space in a single command. |
|
@omer-vishlitzky: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
50d3ab8 to
6b0cc06
Compare
|
@omer-vishlitzky: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
|
@omer-vishlitzky: This pull request references MGMT-23722 which is a valid jira issue. Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the task to target the "5.0.0" version, but no target version was set. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
/pj-rehearse periodic-ci-osac-project-osac-test-infra-main-e2e-caas-order-delete-during-provision periodic-ci-osac-project-osac-test-infra-main-e2e-caas-cluster-order-api-fields periodic-ci-osac-project-osac-test-infra-main-e2e-caas-cluster-order-lifecycle |
|
/pj-rehearse pull-ci-osac-project-osac-installer-main-e2e-metal-caas-cluster-order-api-fields pull-ci-osac-project-osac-installer-main-e2e-metal-caas-cluster-order-lifecycle pull-ci-osac-project-osac-installer-main-e2e-metal-caas-order-delete-during-provision |
|
@omer-vishlitzky: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
|
/pj-rehearse pull-ci-osac-project-osac-installer-main-e2e-metal-caas-cluster-order-api-fields pull-ci-osac-project-osac-installer-main-e2e-metal-caas-cluster-order-lifecycle pull-ci-osac-project-osac-installer-main-e2e-metal-caas-order-delete-during-provision |
|
@omer-vishlitzky: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
|
/retest |
|
/pj-rehearse pull-ci-osac-project-osac-installer-main-e2e-metal-caas-cluster-order-api-fields pull-ci-osac-project-osac-installer-main-e2e-metal-caas-cluster-order-lifecycle pull-ci-osac-project-osac-installer-main-e2e-metal-caas-order-delete-during-provision |
|
@omer-vishlitzky: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
3a6837b to
914c13f
Compare
|
/pj-rehearse pull-ci-osac-project-osac-installer-main-e2e-metal-caas-cluster-order-api-fields pull-ci-osac-project-osac-installer-main-e2e-metal-caas-cluster-order-lifecycle pull-ci-osac-project-osac-installer-main-e2e-metal-caas-order-delete-during-provision |
|
@omer-vishlitzky: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
|
/pj-rehearse pull-ci-osac-project-osac-installer-main-e2e-metal-caas-cluster-order-api-fields pull-ci-osac-project-osac-installer-main-e2e-metal-caas-cluster-order-lifecycle pull-ci-osac-project-osac-installer-main-e2e-metal-caas-order-delete-during-provision |
|
@omer-vishlitzky: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
914c13f to
4ad6a6a
Compare
|
/pj-rehearse pull-ci-osac-project-osac-installer-main-e2e-metal-caas-cluster-order-api-fields pull-ci-osac-project-osac-installer-main-e2e-metal-caas-cluster-order-lifecycle pull-ci-osac-project-osac-installer-main-e2e-metal-caas-order-delete-during-provision |
|
@omer-vishlitzky: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
|
/pj-rehearse pull-ci-osac-project-osac-installer-main-e2e-metal-caas-cluster-order-api-fields pull-ci-osac-project-osac-installer-main-e2e-metal-caas-cluster-order-lifecycle pull-ci-osac-project-osac-installer-main-e2e-metal-caas-order-delete-during-provision |
|
@omer-vishlitzky: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
cd4cd51 to
1016895
Compare
|
/pj-rehearse pull-ci-osac-project-osac-installer-main-e2e-metal-caas-cluster-order-api-fields pull-ci-osac-project-osac-installer-main-e2e-metal-caas-cluster-order-lifecycle pull-ci-osac-project-osac-installer-main-e2e-metal-caas-order-delete-during-provision |
|
@omer-vishlitzky: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
New step-registry components (CaaS-specific, does not touch VMaaS): - osac-project-caas-installer: installs OSAC with MCE+LVMS+MetalLB - osac-project-caas-agent-setup: creates InfraEnv, boots agent VM - osac-project-caas-test: runs CaaS E2E tests - osac-project-ofcir-caas: CaaS workflow combining the above Three presubmit jobs on osac-installer triggered by run_if_changed.
1016895 to
ded84dd
Compare
|
/pj-rehearse pull-ci-osac-project-osac-installer-main-e2e-metal-caas-cluster-order-api-fields pull-ci-osac-project-osac-installer-main-e2e-metal-caas-cluster-order-lifecycle pull-ci-osac-project-osac-installer-main-e2e-metal-caas-order-delete-during-provision |
|
@omer-vishlitzky: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
|
[REHEARSALNOTIFIER]
Interacting with pj-rehearseComment: Once you are satisfied with the results of the rehearsals, comment: |
|
/pj-rehearse pull-ci-osac-project-osac-installer-main-e2e-metal-caas-cluster-order-api-fields pull-ci-osac-project-osac-installer-main-e2e-metal-caas-cluster-order-lifecycle pull-ci-osac-project-osac-installer-main-e2e-metal-caas-order-delete-during-provision |
|
@omer-vishlitzky: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
|
@omer-vishlitzky: The following tests failed, say
Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
https://issues.redhat.com/browse/MGMT-24219
Adds 3 CaaS E2E presubmits jobs for OSAC using the baremetal workflow:
e2e-metal-caas-cluster-order-lifecycle(Mon)e2e-metal-caas-cluster-order-api-fields(Wed)e2e-metal-caas-order-delete-during-provision(Fri)Each job provisions a bare metal SNO with MCE, installs OSAC with the
caas-cioverlay, creates an agent VM from a discovery ISO, and runsthe CaaS E2E test.
New step-registry components:
osac-project-installer— runs osac-installer setup.shosac-project-caas-agent-setup— creates InfraEnv, boots agent VM, labels/approvesosac-project-ofcir-caas— CaaS workflow (adds installer + agent setup to the baremetal flow)Depends on: