Skip to content

[e2e] bump generated key size - #2153

Merged
openshift-merge-bot[bot] merged 1 commit into
openshift:masterfrom
jrvaldes:test-azure-job-private-keys
May 2, 2024
Merged

[e2e] bump generated key size#2153
openshift-merge-bot[bot] merged 1 commit into
openshift:masterfrom
jrvaldes:test-azure-job-private-keys

Conversation

@jrvaldes

@jrvaldes jrvaldes commented May 1, 2024

Copy link
Copy Markdown
Contributor

This change increases the size of the generated private keys in the e2e test suite so that it complies with the smaller size of keys in recent openssl version.

See https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html-single/9.3_release_notes/index

This change increases the size of the generated private keys in the
e2e test suite so that it complies with the smaller size of keys in
recent openssl version.

See https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html-single/9.3_release_notes/index
@openshift-ci openshift-ci Bot added the do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. label May 1, 2024
@openshift-ci

openshift-ci Bot commented May 1, 2024

Copy link
Copy Markdown
Contributor

Skipping CI for Draft Pull Request.
If you want CI signal for your change, please convert it to an actual PR.
You can still manually trigger a test run with /test all

@jrvaldes

jrvaldes commented May 1, 2024

Copy link
Copy Markdown
Contributor Author

/test azure-e2e-operator

@jrvaldes
jrvaldes marked this pull request as ready for review May 1, 2024 17:33
@openshift-ci openshift-ci Bot removed the do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. label May 1, 2024
@openshift-ci
openshift-ci Bot requested review from mansikulkarni96 and sebsoto May 1, 2024 17:33
@sebsoto

sebsoto commented May 1, 2024

Copy link
Copy Markdown
Contributor

/approve

@jrvaldes

jrvaldes commented May 1, 2024

Copy link
Copy Markdown
Contributor Author

I logged in the CI cluster and the e2e passed the issue

ack/run-ci-e2e-test.sh -t basic
/cli/oc
Client Version: v4.2.0-alpha.0-2287-g51e5705
Kustomize Version: v5.0.4-0.20230601165947-6ce0bf390ce3
Server Version: 4.16.0-0.ci.test-2024-05-01-181036-ci-op-rcd3mt3r-latest
Kubernetes Version: v1.29.0-rc.1.3936+d1ec84aa4c0ca4-dirty
Error from server (NotFound): namespaces "openshift-windows-machine-config-operator" not found
time="2024-05-01T19:09:39Z" level=info msg="All validation tests have completed successfully"
Error from server (NotFound): namespaces "openshift-windows-machine-config-operator" not found
namespace/openshift-windows-machine-config-operator created
namespace/openshift-windows-machine-config-operator labeled
Command "packagemanifests" is deprecated, support for the packagemanifests format will be removed in operator-sdk v2.0.0. Use bundles to package your operator instead. Migrate your packagemanifest to a bundle using 'operator-sdk pkgman-to-bundle' command. Run 'operator-sdk pkgman-to-bundle --help' for more details.
time="2024-05-01T19:09:40Z" level=info msg="Creating windows-machine-config-operator registry"
time="2024-05-01T19:09:40Z" level=info msg="  Creating ConfigMap \"openshift-windows-machine-config-operator/windows-machine-config-operator-registry-manifests-package\""
time="2024-05-01T19:09:40Z" level=info msg="  ConfigMap \"openshift-windows-machine-config-operator/windows-machine-config-operator-registry-manifests-package\" created"
time="2024-05-01T19:09:40Z" level=info msg="  Creating ConfigMap \"openshift-windows-machine-config-operator/windows-machine-config-operator-registry-manifests-10-16-0\""
time="2024-05-01T19:09:40Z" level=info msg="  ConfigMap \"openshift-windows-machine-config-operator/windows-machine-config-operator-registry-manifests-10-16-0\" created"
time="2024-05-01T19:09:40Z" level=info msg="  Creating Deployment \"openshift-windows-machine-config-operator/windows-machine-config-operator-registry-server\""
time="2024-05-01T19:09:40Z" level=info msg="  Deployment \"openshift-windows-machine-config-operator/windows-machine-config-operator-registry-server\" created"
time="2024-05-01T19:09:40Z" level=info msg="  Creating Service \"openshift-windows-machine-config-operator/windows-machine-config-operator-registry-server\""
time="2024-05-01T19:09:40Z" level=info msg="  Service \"openshift-windows-machine-config-operator/windows-machine-config-operator-registry-server\" created"
time="2024-05-01T19:09:40Z" level=info msg="Waiting for Deployment \"openshift-windows-machine-config-operator/windows-machine-config-operator-registry-server\" rollout to complete"
time="2024-05-01T19:09:40Z" level=info msg="  Waiting for Deployment \"openshift-windows-machine-config-operator/windows-machine-config-operator-registry-server\" to rollout: 0 out of 1 new replicas have been updated"
time="2024-05-01T19:09:41Z" level=info msg="  Waiting for Deployment \"openshift-windows-machine-config-operator/windows-machine-config-operator-registry-server\" to rollout: 0 of 1 updated replicas are available"
time="2024-05-01T19:09:46Z" level=info msg="  Deployment \"openshift-windows-machine-config-operator/windows-machine-config-operator-registry-server\" successfully rolled out"
time="2024-05-01T19:09:46Z" level=info msg="Created CatalogSource: windows-machine-config-operator-catalog"
time="2024-05-01T19:09:46Z" level=info msg="OperatorGroup \"operator-sdk-og\" created"
time="2024-05-01T19:09:46Z" level=info msg="Created Subscription: windows-machine-config-operator-v10-16-0-sub"
time="2024-05-01T19:09:54Z" level=info msg="Approved InstallPlan install-d8h2g for the Subscription: windows-machine-config-operator-v10-16-0-sub"
time="2024-05-01T19:09:54Z" level=info msg="Waiting for ClusterServiceVersion \"openshift-windows-machine-config-operator/windows-machine-config-operator.v10.16.0\" to reach 'Succeeded' phase"
time="2024-05-01T19:09:54Z" level=info msg="  Waiting for ClusterServiceVersion \"openshift-windows-machine-config-operator/windows-machine-config-operator.v10.16.0\" to appear"
time="2024-05-01T19:09:57Z" level=info msg="  Found ClusterServiceVersion \"openshift-windows-machine-config-operator/windows-machine-config-operator.v10.16.0\" phase: Pending"
time="2024-05-01T19:10:01Z" level=info msg="  Found ClusterServiceVersion \"openshift-windows-machine-config-operator/windows-machine-config-operator.v10.16.0\" phase: Installing"
time="2024-05-01T19:11:59Z" level=info msg="  Found ClusterServiceVersion \"openshift-windows-machine-config-operator/windows-machine-config-operator.v10.16.0\" phase: Succeeded"
time="2024-05-01T19:11:59Z" level=info msg="OLM has successfully installed \"windows-machine-config-operator.v10.16.0\""
deployment "windows-machine-config-operator" successfully rolled out
Testing against Windows Server 2022
?   	github.com/openshift/windows-machine-config-operator/test/e2e/clusterinfo	[no test files]
?   	github.com/openshift/windows-machine-config-operator/test/e2e/providers	[no test files]
?   	github.com/openshift/windows-machine-config-operator/test/e2e/providers/aws	[no test files]
?   	github.com/openshift/windows-machine-config-operator/test/e2e/providers/azure	[no test files]
?   	github.com/openshift/windows-machine-config-operator/test/e2e/providers/gcp	[no test files]
?   	github.com/openshift/windows-machine-config-operator/test/e2e/providers/machineset	[no test files]
?   	github.com/openshift/windows-machine-config-operator/test/e2e/providers/none	[no test files]
?   	github.com/openshift/windows-machine-config-operator/test/e2e/providers/nutanix	[no test files]
?   	github.com/openshift/windows-machine-config-operator/test/e2e/providers/vsphere	[no test files]
?   	github.com/openshift/windows-machine-config-operator/test/e2e/smb	[no test files]
?   	github.com/openshift/windows-machine-config-operator/test/e2e/windows	[no test files]
=== RUN   TestWMCO
2024/05/01 19:12:40 Testing against Windows Server 2022
=== RUN   TestWMCO/operator_deployed_without_private_key_secret
--- PASS: TestWMCO (0.37s)
    --- PASS: TestWMCO/operator_deployed_without_private_key_secret (0.08s)
PASS
ok  	github.com/openshift/windows-machine-config-operator/test/e2e	0.526s
?   	github.com/openshift/windows-machine-config-operator/test/e2e/clusterinfo	[no test files]
?   	github.com/openshift/windows-machine-config-operator/test/e2e/providers	[no test files]
?   	github.com/openshift/windows-machine-config-operator/test/e2e/providers/aws	[no test files]
?   	github.com/openshift/windows-machine-config-operator/test/e2e/providers/azure	[no test files]
?   	github.com/openshift/windows-machine-config-operator/test/e2e/providers/gcp	[no test files]
?   	github.com/openshift/windows-machine-config-operator/test/e2e/providers/machineset	[no test files]
?   	github.com/openshift/windows-machine-config-operator/test/e2e/providers/none	[no test files]
?   	github.com/openshift/windows-machine-config-operator/test/e2e/providers/nutanix	[no test files]
?   	github.com/openshift/windows-machine-config-operator/test/e2e/providers/vsphere	[no test files]
?   	github.com/openshift/windows-machine-config-operator/test/e2e/smb	[no test files]
?   	github.com/openshift/windows-machine-config-operator/test/e2e/windows	[no test files]
=== RUN   TestWMCO
2024/05/01 19:12:44 Testing against Windows Server 2022
=== RUN   TestWMCO/create
=== RUN   TestWMCO/create/Creation
=== RUN   TestWMCO/create/Creation/Machine_controller
=== RUN   TestWMCO/create/Creation/Machine_controller/Machine_configuration_while_private_key_change
2024/05/01 19:12:45 waiting (timeout: 5m0s) for 1 Windows Machines to reach phase "Provisioned"
2024/05/01 19:12:55 10.039814925s time is required for 1 Machines without the ignore label to reach phase Provisioned
2024/05/01 19:12:55 waiting (timeout: 15m0s) for machine e2e-wm-6vqw8 to be deleted
2024/05/01 19:14:55 waiting for machine e2e-wm-6vqw8 to be deleted
2024/05/01 19:16:55 waiting for machine e2e-wm-6vqw8 to be deleted
2024/05/01 19:18:55 waiting for machine e2e-wm-6vqw8 to be deleted
2024/05/01 19:20:55 waiting for machine e2e-wm-6vqw8 to be deleted
2024/05/01 19:22:55 waiting (timeout: 5m0s) for 1 Windows Machines to reach phase "Provisioned"
2024/05/01 19:23:00 5.035044233s time is required for 1 Machines without the ignore label to reach phase Provisioned
2024/05/01 19:24:00 waiting for 0/1 Windows nodes
2024/05/01 19:25:00 waiting for 0/1 Windows nodes
2024/05/01 19:26:00 waiting for 0/1 Windows nodes
2024/05/01 19:27:00 waiting for 0/1 Windows nodes
2024/05/01 19:28:00 5m0.057786884s time is required to configure 1 nodes
W0501 19:28:00.814075   15534 warnings.go:70] would violate PodSecurity "restricted:latest": host namespaces (hostNetwork=true), allowPrivilegeEscalation != false (container "print-logs-e2e-wm-w8zpf" must set securityContext.allowPrivilegeEscalation=false), unrestricted capabilities (container "print-logs-e2e-wm-w8zpf" must set securityContext.capabilities.drop=["ALL"]), seccompProfile (pod or container "print-logs-e2e-wm-w8zpf" must set securityContext.seccompProfile.type to "RuntimeDefault" or "Localhost")
=== RUN   TestWMCO/create/Creation/ConfigMap_controller
2024/05/01 19:28:36 waiting (timeout: 5m0s) for 1 Windows Machines to reach phase "Provisioned"
2024/05/01 19:28:46 10.032737614s time is required for 1 Machines with the ignore label to reach phase Provisioned
W0501 19:29:46.571431   15534 warnings.go:70] would violate PodSecurity "restricted:latest": host namespaces (hostNetwork=true), allowPrivilegeEscalation != false (container "change-default-shell" must set securityContext.allowPrivilegeEscalation=false), unrestricted capabilities (container "change-default-shell" must set securityContext.capabilities.drop=["ALL"]), seccompProfile (pod or container "change-default-shell" must set securityContext.seccompProfile.type to "RuntimeDefault" or "Localhost")
2024/05/01 19:29:51 failed to change e2e-4cd4w default shell to Powershell
W0501 19:30:46.564186   15534 warnings.go:70] would violate PodSecurity "restricted:latest": host namespaces (hostNetwork=true), allowPrivilegeEscalation != false (container "change-default-shell" must set securityContext.allowPrivilegeEscalation=false), unrestricted capabilities (container "change-default-shell" must set securityContext.capabilities.drop=["ALL"]), seccompProfile (pod or container "change-default-shell" must set securityContext.seccompProfile.type to "RuntimeDefault" or "Localhost")
=== RUN   TestWMCO/create/Creation/ConfigMap_controller/VM_is_configured_by_ConfigMap_controller
2024/05/01 19:34:07 waiting for 0/1 Windows nodes
2024/05/01 19:35:07 waiting for 0/1 Windows nodes
2024/05/01 19:36:07 waiting for 0/1 Windows nodes
2024/05/01 19:37:07 waiting for 0/1 Windows nodes
2024/05/01 19:38:07 5m0.044153367s time is required to configure 1 nodes
W0501 19:38:07.621480   15534 warnings.go:70] would violate PodSecurity "restricted:latest": host namespaces (hostNetwork=true), allowPrivilegeEscalation != false (container "print-logs-byoh-e2e-4cd4w" must set securityContext.allowPrivilegeEscalation=false), unrestricted capabilities (container "print-logs-byoh-e2e-4cd4w" must set securityContext.capabilities.drop=["ALL"]), seccompProfile (pod or container "print-logs-byoh-e2e-4cd4w" must set securityContext.seccompProfile.type to "RuntimeDefault" or "Localhost")
=== RUN   TestWMCO/create/Nodes_ready_and_schedulable
=== RUN   TestWMCO/create/Nodes_ready_and_schedulable/e2e-wm-w8zpf
=== RUN   TestWMCO/create/Nodes_ready_and_schedulable/e2e-4cd4w
=== RUN   TestWMCO/create/Node_annotations
=== RUN   TestWMCO/create/Node_annotations/e2e-wm-w8zpf
=== RUN   TestWMCO/create/Node_annotations/e2e-4cd4w
=== RUN   TestWMCO/create/Node_Metadata
=== RUN   TestWMCO/create/Node_Metadata/e2e-wm-w8zpf_Validation_Tests
=== RUN   TestWMCO/create/Node_Metadata/e2e-wm-w8zpf_Validation_Tests/Worker_Label
=== RUN   TestWMCO/create/Node_Metadata/e2e-wm-w8zpf_Validation_Tests/Version_Annotation
=== RUN   TestWMCO/create/Node_Metadata/e2e-wm-w8zpf_Validation_Tests/Public_Key_Annotation
=== RUN   TestWMCO/create/Node_Metadata/e2e-4cd4w_Validation_Tests
=== RUN   TestWMCO/create/Node_Metadata/e2e-4cd4w_Validation_Tests/Worker_Label
=== RUN   TestWMCO/create/Node_Metadata/e2e-4cd4w_Validation_Tests/Version_Annotation
=== RUN   TestWMCO/create/Node_Metadata/e2e-4cd4w_Validation_Tests/Public_Key_Annotation
=== RUN   TestWMCO/create/Node_Metadata/Windows_node_metadata_not_applied_to_Linux_nodes
=== RUN   TestWMCO/create/Services_ConfigMap_validation
=== RUN   TestWMCO/create/Services_ConfigMap_validation/Services_ConfigMap_contents
=== RUN   TestWMCO/create/Services_ConfigMap_validation/Services_ConfigMap_contents/windows_exporter
=== RUN   TestWMCO/create/Services_ConfigMap_validation/Services_ConfigMap_contents/kube-proxy
=== RUN   TestWMCO/create/Services_ConfigMap_validation/Services_ConfigMap_contents/hybrid-overlay-node
=== RUN   TestWMCO/create/Services_ConfigMap_validation/Services_ConfigMap_contents/kubelet
=== RUN   TestWMCO/create/Services_ConfigMap_validation/Services_ConfigMap_contents/windows-instance-config-daemon
=== RUN   TestWMCO/create/Services_ConfigMap_validation/Services_ConfigMap_contents/containerd
=== RUN   TestWMCO/create/Services_ConfigMap_validation/Services_ConfigMap_contents/cloud-node-manager
=== RUN   TestWMCO/create/Services_ConfigMap_validation/Services_ConfigMap_re-creation
=== RUN   TestWMCO/create/Services_ConfigMap_validation/Invalid_services_ConfigMap_deletion
=== RUN   TestWMCO/create/Services_running
=== RUN   TestWMCO/create/Services_running/e2e-wm-w8zpf
W0501 19:39:15.546273   15534 warnings.go:70] would violate PodSecurity "restricted:latest": host namespaces (hostNetwork=true), allowPrivilegeEscalation != false (container "get-windows-svc-list" must set securityContext.allowPrivilegeEscalation=false), unrestricted capabilities (container "get-windows-svc-list" must set securityContext.capabilities.drop=["ALL"]), seccompProfile (pod or container "get-windows-svc-list" must set securityContext.seccompProfile.type to "RuntimeDefault" or "Localhost")
=== RUN   TestWMCO/create/Services_running/e2e-wm-w8zpf/kubelet
=== RUN   TestWMCO/create/Services_running/e2e-wm-w8zpf/windows-instance-config-daemon
=== RUN   TestWMCO/create/Services_running/e2e-wm-w8zpf/containerd
=== RUN   TestWMCO/create/Services_running/e2e-wm-w8zpf/cloud-node-manager
=== RUN   TestWMCO/create/Services_running/e2e-wm-w8zpf/windows_exporter
=== RUN   TestWMCO/create/Services_running/e2e-wm-w8zpf/kube-proxy
=== RUN   TestWMCO/create/Services_running/e2e-wm-w8zpf/hybrid-overlay-node
=== RUN   TestWMCO/create/Services_running/e2e-4cd4w
W0501 19:39:20.770332   15534 warnings.go:70] would violate PodSecurity "restricted:latest": host namespaces (hostNetwork=true), allowPrivilegeEscalation != false (container "get-windows-svc-list" must set securityContext.allowPrivilegeEscalation=false), unrestricted capabilities (container "get-windows-svc-list" must set securityContext.capabilities.drop=["ALL"]), seccompProfile (pod or container "get-windows-svc-list" must set securityContext.seccompProfile.type to "RuntimeDefault" or "Localhost")
=== RUN   TestWMCO/create/Services_running/e2e-4cd4w/windows_exporter
=== RUN   TestWMCO/create/Services_running/e2e-4cd4w/kube-proxy
=== RUN   TestWMCO/create/Services_running/e2e-4cd4w/hybrid-overlay-node
=== RUN   TestWMCO/create/Services_running/e2e-4cd4w/kubelet
=== RUN   TestWMCO/create/Services_running/e2e-4cd4w/windows-instance-config-daemon
=== RUN   TestWMCO/create/Services_running/e2e-4cd4w/containerd
=== RUN   TestWMCO/create/Services_running/e2e-4cd4w/cloud-node-manager
=== RUN   TestWMCO/create/NodeTaint_validation
=== RUN   TestWMCO/create/CSR_Validation
=== RUN   TestWMCO/create/Certificates
=== RUN   TestWMCO/create/Certificates/Kubelet_CA_rotation
=== RUN   TestWMCO/create/Certificates/Kubelet_CA_rotation/node/e2e-wm-w8zpf

@jrvaldes

jrvaldes commented May 1, 2024

Copy link
Copy Markdown
Contributor Author

/test remaining-required

@openshift-ci

openshift-ci Bot commented May 1, 2024

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: jrvaldes, sebsoto

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci openshift-ci Bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label May 1, 2024
@saifshaikh48

Copy link
Copy Markdown
Contributor

/lgtm

@openshift-ci openshift-ci Bot added the lgtm Indicates that a PR is ready to be merged. label May 1, 2024
@openshift-ci-robot

Copy link
Copy Markdown

/retest-required

Remaining retests: 0 against base HEAD 1eb6a41 and 2 for PR HEAD 7bf4f94 in total

@sebsoto

sebsoto commented May 2, 2024

Copy link
Copy Markdown
Contributor

/retest-required

@openshift-ci

openshift-ci Bot commented May 2, 2024

Copy link
Copy Markdown
Contributor

@jrvaldes: all tests passed!

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. I understand the commands that are listed here.

@openshift-merge-bot
openshift-merge-bot Bot merged commit d1b4951 into openshift:master May 2, 2024
@jrvaldes
jrvaldes deleted the test-azure-job-private-keys branch May 26, 2026 14:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. lgtm Indicates that a PR is ready to be merged.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants