Skip to content

ROSAENG-58795 | config: prow hive connection - #82509

Merged
openshift-merge-bot[bot] merged 5 commits into
openshift:mainfrom
davidleerh:ROSAENG-58795-INFRA
Jul 30, 2026
Merged

ROSAENG-58795 | config: prow hive connection#82509
openshift-merge-bot[bot] merged 5 commits into
openshift:mainfrom
davidleerh:ROSAENG-58795-INFRA

Conversation

@davidleerh

@davidleerh davidleerh commented Jul 27, 2026

Copy link
Copy Markdown
Contributor

Summary by CodeRabbit

Updated the OpenShift release CI prow presubmit job definitions for the rosa-clusters-service Konflux master branch to enable Hive connectivity by granting intranet access (alongside nested-podman) to the pr-check-rosa-hcp, pr-check-aws, pr-check-gcp, pr-check-rosa-classic, and pr-check-core jobs. The jobs now target cluster build05 and mount the rosa-clusters-service-sandbox secret with restrict_network_access: false so the checks can reach the required network resources. Additionally, the PR was labeled for network-access rehearsals and rehearsals for the ROSA HCP pr-check were re-requested as needed.

| config: prow hive connection
@coderabbitai

coderabbitai Bot commented Jul 27, 2026

Copy link
Copy Markdown
Contributor

Walkthrough

The Prow configuration updates five ROSA clusters service PR-check jobs to target build05, add the intranet capability, and disable network-access restriction for the rosa-clusters-service-sandbox secrets mount.

Changes

ROSA PR-check configuration

Layer / File(s) Summary
Update PR-check execution settings
ci-operator/config/openshift-online/rosa-clusters-service/openshift-online-rosa-clusters-service-konflux-master.yaml
The ROSA HCP, AWS, GCP, ROSA Classic, and core jobs target build05, include intranet capability, and set restrict_network_access: false for the sandbox secrets mount.

Estimated code review effort: 2 (Simple) | ~5 minutes

Suggested reviewers: robpblake, lucasponce

🚥 Pre-merge checks | ✅ 14 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Title check ⚠️ Warning The title mentions a Prow Hive connection, but the changes only update job capabilities, cluster target, and network access settings. Rename the PR title to reflect the actual Prow config changes, such as updating job capabilities, cluster selection, and network access settings.
✅ Passed checks (14 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Stable And Deterministic Test Names ✅ Passed PR only changes ci-operator YAML; no Ginkgo It/Describe/Context/When titles or test code were modified.
Test Structure And Quality ✅ Passed PR changes only ci-operator YAML and generated presubmits; no Ginkgo tests or runtime assertions are touched.
Microshift Test Compatibility ✅ Passed Only ci-operator/prow YAML changed; no Ginkgo tests or API usage were added, so MicroShift compatibility isn’t implicated.
Single Node Openshift (Sno) Test Compatibility ✅ Passed Only ci-operator YAML changed; no Ginkgo test definitions or guards were added or modified.
Topology-Aware Scheduling Compatibility ✅ Passed Only CI job configs changed (cluster/build05, intranet, network access); no deployment manifests, controllers, affinity, node selectors, or PDBs were modified.
Ote Binary Stdout Contract ✅ Passed Only ci-operator/Prow YAML changed; no process-level code or stdout writes in main/suite setup were modified.
Ipv6 And Disconnected Network Test Compatibility ✅ Passed PR only changes CI config/presubmit YAML; no new Ginkgo tests or test logic to evaluate for IPv4/disconnected issues.
No-Weak-Crypto ✅ Passed The PR only adjusts Prow test config (cluster/network-access settings); no MD5/SHA1/DES/RC4/3DES/Blowfish/ECB or custom crypto code is present.
Container-Privileges ✅ Passed The changed Prow job config adds intranet/nested-podman and network access flags, but no privileged, hostPID/Network/IPC, SYS_ADMIN, or allowPrivilegeEscalation settings are present.
No-Sensitive-Data-In-Logs ✅ Passed PASS: The change only edits Prow config; it adds no new log statements or sensitive values, and the diff shows no passwords/tokens/PII.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@davidleerh

Copy link
Copy Markdown
Contributor Author

/label network-access-rehearsals-ok

@openshift-ci

openshift-ci Bot commented Jul 27, 2026

Copy link
Copy Markdown
Contributor

@davidleerh: The label(s) /label network-access-rehearsals-ok cannot be applied. These labels are supported: acknowledge-critical-fixes-only, platform/aws, platform/azure, platform/baremetal, platform/google, platform/libvirt, platform/openstack, ga, tide/merge-method-merge, tide/merge-method-rebase, tide/merge-method-squash, px-approved, docs-approved, qe-approved, ux-approved, no-qe, rebase/manual, cluster-config-api-changed, run-integration-tests, verified, ready-for-human-review, approved, backport-risk-assessed, bugzilla/valid-bug, cherry-pick-approved, jira/skip-dependent-bug-check, jira/valid-bug, ok-to-test, priority/ci-critical, stability-fix-approved, staff-eng-approved. Is this label configured under labels -> additional_labels or labels -> restricted_labels in plugin.yaml?

Details

In response to this:

/label network-access-rehearsals-ok

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@openshift-ci
openshift-ci Bot requested review from lucasponce and robpblake July 27, 2026 18:45
@openshift-ci openshift-ci Bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Jul 27, 2026
@openshift-merge-bot openshift-merge-bot Bot added the rehearsals-ack Signifies that rehearsal jobs have been acknowledged label Jul 27, 2026
@davidleerh

Copy link
Copy Markdown
Contributor Author

/pj-rehearse network-access-allowed

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

@davidleerh: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel.

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

@davidleerh: PR author isn't allowed to allow network access rehearsals. This must be done by a different member of the openshift org

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In
`@ci-operator/config/openshift-online/rosa-clusters-service/openshift-online-rosa-clusters-service-konflux-master.yaml`:
- Line 58: Regenerate the derived Prow/job configuration using make update after
the openshift-online-rosa-clusters-service input change, and include all
resulting generated output changes, particularly for capabilities,
restrict_network_access, and secrets.
- Around line 68-75: Review the pr-check-aws job’s use of the
rosa-clusters-service-sandbox secret and document its PR-controlled execution
scope, or replace it with least-privilege, non-sensitive credentials. Ensure the
secret cannot expose sensitive values through the job’s unrestricted network
access, and apply the same validation to both affected PR-check jobs.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Central YAML (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: 825bd4be-4c09-4ce6-843b-43b387c4a13a

📥 Commits

Reviewing files that changed from the base of the PR and between f951496 and 3a807ee.

📒 Files selected for processing (1)
  • ci-operator/config/openshift-online/rosa-clusters-service/openshift-online-rosa-clusters-service-konflux-master.yaml

- always_run: false
as: pr-check-rosa-hcp
capabilities:
- intranet

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

# Locate the referenced CI config and inspect relevant sections plus nearby metadata references.
target="ci-operator/config/openshift-online/rosa-clusters-service/openshift-online-rosa-clusters-service-konflux-master.yaml"
if [ -f "$target" ]; then
  echo "== referenced file line count =="
  wc -l "$target"
  echo
  echo "== referenced relevant sections =="
  sed -n '45,145p' "$target" | nl -ba -v45
else
  echo "Referenced file not found: $target"
fi

echo
echo "== generated metadata files in repo =="
git ls-files | rg '(^|/)(zz_generated_metadata|registry-metadata|ci-operator-config|jobs|\.pb\.txt|\.conf$)' || true

echo
echo "== nearby ci-operator config metadata/header =="
sed -n '1,60p' "$target" | nl -ba -v1

Repository: openshift/release

Length of output: 386


🏁 Script executed:

#!/bin/bash
set -euo pipefail

# Inspect Makefile generation targets and whether make update/job generation references Prow/job outputs.
echo "== Makefile generation targets =="
if [ -f Makefile ]; then
  rg -n 'update|registry-metadata|ci-operator-config|jobs|Prow|prow|job' Makefile -C 2 || true
else
  echo "Makefile not found in repository root"
fi

echo
echo "== exact generated/prow job files likely tied to this repo =="
git ls-files ci-operator/config/openshift-online/rosa-clusters-service | sort

Repository: openshift/release

Length of output: 15596


Regenerate the derived Prow job configuration.

This CI operator config changes generated job inputs (capabilities, restrict_network_access, and secrets), so include the regenerated Prow/job outputs from make update before merging.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In
`@ci-operator/config/openshift-online/rosa-clusters-service/openshift-online-rosa-clusters-service-konflux-master.yaml`
at line 58, Regenerate the derived Prow/job configuration using make update
after the openshift-online-rosa-clusters-service input change, and include all
resulting generated output changes, particularly for capabilities,
restrict_network_access, and secrets.

Sources: Coding guidelines, Learnings

Comment on lines +68 to +75
restrict_network_access: false
secrets:
- mount_path: /usr/local/rosa-clusters-service-sandbox
name: rosa-clusters-service-sandbox
- always_run: false
as: pr-check-aws
capabilities:
- intranet

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟠 Major | 🏗️ Heavy lift

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo "Relevant file excerpt:"
sed -n '1,170p' ci-operator/config/openshift-online/rosa-clusters-service/openshift-online-rosa-clusters-service-konflux-master.yaml

echo
echo "Search for rosa-clusters-service-sandbox and restrict/intranet:"
rg -n "rosa-clusters-service-sandbox|restrict_network_access|intranet|always_run|as: pr-check" ci-operator/config/openshift-online/rosa-clusters-service -S || true

echo
echo "Generated/config metadata presence:"
git ls-files | rg 'zz_generated_metadata|metadata|ci-operator/config/openshift-online/rosa-clusters-service|Makefile' || true

echo
echo "Makefile targets:"
if [ -f Makefile ]; then sed -n '1,220p' Makefile; fi

Repository: openshift/release

Length of output: 50374


🌐 Web query:

ci-operator restricted network access intranet capability PR check secret mount security

💡 Result:

In the OpenShift CI (ci-operator) environment, restricted network access and intranet capability are managed through specific configuration flags and capability definitions to balance security with functional requirements [1][2]. Restricted Network Access and Intranet Capability By default, jobs in the OpenShift CI environment operate with restricted network access. To enable connectivity to the Red Hat intranet, the restrict_network_access flag must be set to false within the test section of the ci-operator configuration [1]. Additionally, jobs requiring this access must specify the intranet capability in their configuration block, which instructs the dispatcher to select a cluster that supports intranet connectivity [2]. PR Check Requirements For security, tests that set restrict_network_access: false are subject to strict PR validation. These tests require both the approved label and a network-access-rehearsals-ok label to be present on the pull request [1]. The network-access-rehearsals-ok label must be added by an authorized OpenShift organization member (not the PR author) via the /pj-rehearse network-access-allowed command [1]. If these requirements are not met, the CI platform will not trigger the test, and some build farm clusters do not support intranet access at all [1]. Secret Mount Security CI jobs access sensitive information by mounting Kubernetes secrets or by utilizing the Secrets Store CSI driver to fetch secrets from Google Secret Manager (GSM) [3][4]. - Access Model: The security model is designed to prevent users from reading secret values back [5][4]. Only the CI infrastructure can read and mount the secrets during job execution [5][4]. - Mounting: Secrets can be mounted at specific paths defined in the ci-operator credentials or secrets stanzas [3][4]. When using the CSI driver, secrets are mounted as files into the pod's filesystem, often utilizing a tmpfs to avoid writing sensitive data to durable storage [6][7]. - Principle of Least Privilege: To enhance security, it is recommended to use separate namespaces for sensitive workloads, avoid broad roles, and restrict access to the minimum set of permissions required [7]. Anyone with access to a namespace or the ability to create pods within it may theoretically be able to access mounted secrets, reinforcing the need for controlled access to the CI environment [6][7].

Citations:


🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo "Target file with line numbers:"
cat -n ci-operator/config/openshift-online/rosa-clusters-service/openshift-online-rosa-clusters-service-konflux-master.yaml | sed -n '1,160p'

echo
echo "Local metadata/generated files for target org/repo:"
git ls-files | rg 'ci-operator/config/openshift-online/rosa-clusters-service|zz_generated_metadata|prowjobs|openshift-online' || true

echo
echo "Intranet jobs with secret mounts nearby:"
rg -n -C 8 'secrets:|mount_path:|name: rosa-clusters-service-sandbox|restrict_network_access: false|intranet|name: pr-check-aws|name: post-' ci-operator/config/openshift-online/rosa-clusters-service -S || true

echo
echo "CI docs config excerpt if present:"
if [ -f ci-docs.yaml ] || [ -d ci-docs ]; then echo found; fi

Repository: openshift/release

Length of output: 47790


🌐 Web query:

Red Hat CI operator restrict_network_access false intranet approval required PR jobs

💡 Result:

In the context of OpenShift CI (Prow), setting restrict_network_access: false in a ci-operator job configuration effectively permits the job to bypass standard firewall restrictions, allowing broader network access (such as connecting to the Red Hat intranet) [1][2][3]. Because this configuration change poses security risks, the pj-rehearse tool—which manages pre-submit rehearsals—automatically disables rehearsals for any PR that modifies this setting [2][4][3]. To proceed with such a job, a specific approval process is required: 1. Manual Intervention: An openshift organization member (who is not the author of the PR) must comment on the PR with the command: /pj-rehearse network-access-allowed [3][5][6]. 2. Validation: This command adds a required label to the PR, which explicitly allows the rehearsals to run [3][5][6]. 3. Final Acknowledgment: Once the rehearsals have run and the results are verified, the PR must receive an acknowledgment (usually via the /pj-rehearse ack command) to unblock the merge process [3][5][6]. Additionally, jobs requiring access to the Red Hat intranet must be configured with the intranet capability in the capabilities block of the ci-operator configuration to ensure they are dispatched to compatible infrastructure [1][5].

Citations:


Verify the PR-check secret scope.

These jobs both mount rosa-clusters-service-sandbox and disable network restrictions at lines 68-126. If the PR-check path can execute PR-controlled code, document or restrict rosa-clusters-service-sandbox to least-privilege/non-sensitive credentials so credentials cannot be exfiltrated over the unrestricted egress path.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In
`@ci-operator/config/openshift-online/rosa-clusters-service/openshift-online-rosa-clusters-service-konflux-master.yaml`
around lines 68 - 75, Review the pr-check-aws job’s use of the
rosa-clusters-service-sandbox secret and document its PR-controlled execution
scope, or replace it with least-privilege, non-sensitive credentials. Ensure the
secret cannot expose sensitive values through the job’s unrestricted network
access, and apply the same validation to both affected PR-check jobs.

| config: prow hive connection
@openshift-merge-bot

Copy link
Copy Markdown
Contributor

@davidleerh: pj-rehearse could not automatically process this event because the request waited in queue for longer than 5 minutes. Use /pj-rehearse to trigger rehearsals manually.

| config: prow hive connection
@gdbranco

Copy link
Copy Markdown
Contributor

/pj-rehearse network-access-allowed

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

@gdbranco: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel.

@davidleerh

Copy link
Copy Markdown
Contributor Author

/pj-rehearse pull-ci-openshift-online-rosa-clusters-service-konflux-master-pr-check-rosa-hcp

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

@davidleerh: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel.

@davidleerh

Copy link
Copy Markdown
Contributor Author

/pj-rehearse pull-ci-openshift-online-rosa-clusters-service-konflux-master-pr-check-rosa-hcp

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

@davidleerh: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel.

@davidleerh

Copy link
Copy Markdown
Contributor Author

/pj-rehearse pull-ci-openshift-online-rosa-clusters-service-konflux-master-pr-check-rosa-hcp

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

@davidleerh: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel.

@davidleerh

Copy link
Copy Markdown
Contributor Author

/pj-rehearse pull-ci-openshift-online-rosa-clusters-service-konflux-master-pr-check-rosa-hcp

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

@davidleerh: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel.

@davidleerh

Copy link
Copy Markdown
Contributor Author

/pj-rehearse pull-ci-openshift-online-rosa-clusters-service-konflux-master-pr-check-rosa-hcp

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

@davidleerh: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel.

@davidleerh

Copy link
Copy Markdown
Contributor Author

/pj-rehearse pull-ci-openshift-online-rosa-clusters-service-konflux-master-pr-check-rosa-hcp

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

@davidleerh: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel.

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

@davidleerh: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel.

@davidleerh

Copy link
Copy Markdown
Contributor Author

/pj-rehearse pull-ci-openshift-online-rosa-clusters-service-konflux-master-pr-check-rosa-hcp

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

@davidleerh: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel.

@davidleerh

Copy link
Copy Markdown
Contributor Author

/pj-rehearse pull-ci-openshift-online-rosa-clusters-service-konflux-master-pr-check-aws
/pj-rehearse pull-ci-openshift-online-rosa-clusters-service-konflux-master-pr-check-gcp
/pj-rehearse pull-ci-openshift-online-rosa-clusters-service-konflux-master-pr-check-rosa-classic
/pj-rehearse pull-ci-openshift-online-rosa-clusters-service-konflux-master-pr-check-core

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

@davidleerh: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel.

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

@davidleerh: requesting more than one rehearsal in one comment is not supported. If you would like to rehearse multiple specific jobs, please separate the job names by a space in a single command.

2 similar comments
@openshift-merge-bot

Copy link
Copy Markdown
Contributor

@davidleerh: requesting more than one rehearsal in one comment is not supported. If you would like to rehearse multiple specific jobs, please separate the job names by a space in a single command.

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

@davidleerh: requesting more than one rehearsal in one comment is not supported. If you would like to rehearse multiple specific jobs, please separate the job names by a space in a single command.

@davidleerh

Copy link
Copy Markdown
Contributor Author

/pj-rehearse pull-ci-openshift-online-rosa-clusters-service-konflux-master-pr-check-gcp

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

@davidleerh: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel.

@davidleerh

Copy link
Copy Markdown
Contributor Author

/pj-rehearse pull-ci-openshift-online-rosa-clusters-service-konflux-master-pr-check-rosa-classic

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

@davidleerh: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel.

@davidleerh

Copy link
Copy Markdown
Contributor Author

/pj-rehearse pull-ci-openshift-online-rosa-clusters-service-konflux-master-pr-check-core

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

@davidleerh: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel.

@davidleerh

Copy link
Copy Markdown
Contributor Author

/pj-rehearse pull-ci-openshift-online-rosa-clusters-service-konflux-master-pr-check-gcp

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

@davidleerh: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel.

@davidleerh

Copy link
Copy Markdown
Contributor Author

/pj-rehearse pull-ci-openshift-online-rosa-clusters-service-konflux-master-pr-check-gcp

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

@davidleerh: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel.

@davidleerh

Copy link
Copy Markdown
Contributor Author

/pj-rehearse pull-ci-openshift-online-rosa-clusters-service-konflux-master-pr-check-core

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

@davidleerh: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel.

@gdbranco

Copy link
Copy Markdown
Contributor

/pj-rehearse pull-ci-openshift-online-rosa-clusters-service-konflux-master-pr-check-core

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

@gdbranco: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel.

@gdbranco

Copy link
Copy Markdown
Contributor

/lgtm

@openshift-ci openshift-ci Bot added the lgtm Indicates that a PR is ready to be merged. label Jul 30, 2026
@openshift-ci

openshift-ci Bot commented Jul 30, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: davidleerh, gdbranco

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-merge-bot
openshift-merge-bot Bot merged commit f90da6e into openshift:main Jul 30, 2026
20 of 21 checks passed
amogh-redhat pushed a commit to amogh-redhat/release that referenced this pull request Aug 5, 2026
* ROSAENG-58795
| config: prow hive connection

* ROSAENG-58795
| config: prow hive connection

* ROSAENG-58795
| config: prow hive connection

* ROSAENG-58795 | config: prow hive connection

* ROSAENG-58795 | config: prow hive connection
TimurMP pushed a commit to TimurMP/release that referenced this pull request Aug 9, 2026
* ROSAENG-58795
| config: prow hive connection

* ROSAENG-58795
| config: prow hive connection

* ROSAENG-58795
| config: prow hive connection

* ROSAENG-58795 | config: prow hive connection

* ROSAENG-58795 | config: prow hive connection
TimurMP pushed a commit to TimurMP/release that referenced this pull request Sep 5, 2026
* ROSAENG-58795
| config: prow hive connection

* ROSAENG-58795
| config: prow hive connection

* ROSAENG-58795
| config: prow hive connection

* ROSAENG-58795 | config: prow hive connection

* ROSAENG-58795 | config: prow hive connection
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. lgtm Indicates that a PR is ready to be merged. network-access-rehearsals-ok rehearsals-ack Signifies that rehearsal jobs have been acknowledged

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants