Skip to content

[OSAC-2135] PRD: CaaS Bare Metal Worker Node Provisioning - #181

Closed
forgeSmith-bot wants to merge 11 commits into
osac-project:mainfrom
forgeSmith-bot:forge/prd/osac-2135
Closed

forgeSmith-bot wants to merge 11 commits into
osac-project:mainfrom
forgeSmith-bot:forge/prd/osac-2135

Conversation

@forgeSmith-bot

@forgeSmith-bot forgeSmith-bot commented Aug 2, 2026 •

Copy link
Copy Markdown

PRD for OSAC-2135

The PRD document is in enhancements/OSAC-2135/prd.md on this branch.

Review the file changes for the latest version. Leave comments on this PR to provide feedback — Forge will regenerate the PRD and push updated commits.

Summary by CodeRabbit

  • Documentation
    • Added product requirements for on-demand bare-metal worker-node provisioning.
    • Documented tenant and administrator workflows for provisioning, registration, cleanup, and infrastructure visibility.
    • Defined resource-selection requirements, standard image usage, cluster-specific configuration, host correlation, and environment isolation.
    • Documented blocking sanitization during cleanup to support secure resource reuse.
    • Recorded scope, exclusions, assumptions, risks, and mitigation strategies.

@openshift-ci
openshift-ci Bot requested review from chenyosef and larsks August 2, 2026 12:01
@coderabbitai

coderabbitai Bot commented Aug 2, 2026 •

Copy link
Copy Markdown

Review Change Stack

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: osac-project/coderabbit/.coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: de88c8f6-293f-4a94-983d-3df67ecf9add

📥 Commits

Reviewing files that changed from the base of the PR and between 36b4e6f and f726d9b.

📒 Files selected for processing (1)
  • enhancements/OSAC-2135/prd.md
🚧 Files skipped from review as they are similar to previous changes (1)
  • enhancements/OSAC-2135/prd.md

Walkthrough

The PRD defines on-demand CaaS bare-metal worker provisioning. It covers provisioning, boot configuration, host correlation, tenant isolation, cleanup, resource selection, user stories, assumptions, dependencies, exclusions, and provenance metadata.

Changes

Bare-metal provisioning requirements

Layer / File(s) Summary
Provisioning scope and lifecycle
enhancements/OSAC-2135/prd.md
Defines the problem, provisioning flow, boot inputs, MAC correlation, tenant isolation, cleanup, resource selection, and exclusions.
Operational roles and dependencies
enhancements/OSAC-2135/prd.md
Defines tenant and cloud provider user stories, ignition assumptions, BMaaS dependencies, and document provenance.

Estimated code review effort: 1 (Trivial) | ~5 minutes

Possibly related PRs

Suggested reviewers: chenyosef, carbonin, larsks

🚥 Pre-merge checks | ✅ 10 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Ai-Attribution ⚠️ Warning ForgeSmith-bot authored all 11 PR commits and the PRD has ai-workflow-provenance, but no Assisted-by or Generated-by trailer appears; no AI Co-Authored-By trailer appears. Add an Assisted-by or Generated-by: ForgeSmith-bot trailer to each AI-generated commit. Do not use Co-Authored-By for the AI tool.
✅ Passed checks (10 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely identifies the OSAC-2135 PRD for CaaS bare-metal worker node provisioning.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
No-Hardcoded-Secrets ✅ Passed The PR adds only a PRD; scans found no API keys, tokens, passwords, private-key material, embedded credentials, or long base64/hex literals.
No-Weak-Crypto ✅ Passed The PR changes only the PRD and adds test | true; the document contains no MD5, SHA1, DES, RC4, Blowfish, ECB, or custom crypto usage.
No-Injection-Vectors ✅ Passed The commit changes only a Markdown PRD; scans found no SQL concatenation, shell=True, eval/exec, pickle.loads, unsafe yaml.load, os.system, or dangerouslySetInnerHTML.
Container-Privileges ✅ Passed The PR changes only enhancements/OSAC-2135/prd.md. The patch contains no container or Kubernetes manifest and no listed privilege settings.
No-Sensitive-Data-In-Logs ✅ Passed The PR adds only test | true to a PRD; no logging code or passwords, tokens, API keys, PII, session IDs, hostnames, or customer data are introduced.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@forgeSmith-bot

Copy link
Copy Markdown
Author

PRD has been revised based on feedback. Please review the updated version.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 6

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@enhancements/OSAC-2135/prd.md`:
- Line 84: Update prd.md so the file ends with exactly one trailing newline,
satisfying the MD047 markdownlint requirement.
- Line 1: Update the compound adjective usage in the PRD, including the title
and the referenced lines, to consistently hyphenate “bare-metal” whenever it
modifies a noun, while preserving the surrounding wording.
- Line 24: Expand the MAC Address Correlation requirement in the PRD to define
the complete matching contract: whether BMaaS exposes one canonical MAC or
multiple values, how CaaS normalizes and compares them with Assisted Installer
agent reports, and the deterministic behavior for missing, duplicate, or changed
MACs. Apply the same clarification to the corresponding repeated requirement.
- Line 27: Clarify the “Race Prevention” requirement by selecting one
authoritative InfraEnv scope and identity key. State explicitly whether node
pools within the same cluster share an InfraEnv, and define when the InfraEnv is
created and deleted so exactly one instance is maintained for the chosen scope.
- Around line 62-64: Update the BMaaS completion-boundary requirements around
“Boundary of Failure” to define an observable completion signal after image
write, ignition delivery, boot, and network readiness are verified. Explicitly
classify failures in those prerequisites as BMaaS-owned, and only classify a
missing agent registration as a CaaS software failure after the defined signal
is emitted.
- Around line 26-32: Clarify the lifecycle scope in the PRD by distinguishing
explicit cluster or node-pool deprovisioning from automated day-2 workload
scaling. Define BareMetalInstance cleanup as applying only to explicit
decommission or scale-down operations, and state that automated workload-driven
scaling remains out of scope unless it is intended to be included.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository: osac-project/coderabbit/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 17565d09-aa4f-45c7-831f-f0f9fd6bb27f

📥 Commits

Reviewing files that changed from the base of the PR and between 9fab7b7 and 2a2f868.

📒 Files selected for processing (1)
  • enhancements/OSAC-2135/prd.md

Comment thread enhancements/OSAC-2135/prd.md Outdated
Comment thread enhancements/OSAC-2135/prd.md Outdated
Comment thread enhancements/OSAC-2135/prd.md Outdated
Comment thread enhancements/OSAC-2135/prd.md Outdated
Comment thread enhancements/OSAC-2135/prd.md Outdated
Comment thread enhancements/OSAC-2135/prd.md Outdated
@forgeSmith-bot

Copy link
Copy Markdown
Author

PRD has been revised based on feedback. Please review the updated version.

@forgeSmith-bot

Copy link
Copy Markdown
Author

PRD has been revised based on feedback. Please review the updated version.

Comment thread enhancements/OSAC-2135/prd.md Outdated
Comment on lines +25 to +30
- **Exposed Values:** BMaaS must expose all physical MAC addresses of the host's network interfaces as a structured list within the `BareMetalInstance` status, clearly identifying the primary/boot interface MAC address as the canonical reference.
- **Normalization and Comparison:** CaaS retrieves this list of MAC addresses, normalizes all values to lowercase, colon-separated format (e.g., `aa:bb:cc:dd:ee:ff`), and compares them against the list of interface MAC addresses reported by the Assisted Installer agent's system discovery reports.
- **Deterministic Edge-Case Behavior:**
- *Missing MACs:* If the `BareMetalInstance` status lacks MAC address information, CaaS will pause provisioning, mark the node's reconcile status as `AwaitingHardwareDiscovery`, and retry with an exponential backoff.
- *Duplicate MACs:* If a MAC address matches multiple `BareMetalInstance` resources or multiple registered agents, CaaS will trigger a high-severity alert, isolate the conflicting hosts/agents in a quarantined state, and fail the affected `ClusterOrder` with a clear validation error.
- *Changed MACs:* The MAC-to-agent mapping contract is immutable once successfully established. Any subsequent changes in the reported MAC addresses of an active instance will trigger a node reconciliation failure, prompting a replacement of the node.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Design details don't belong in the PRD

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Also, I think that if we're having an InfraEnv per cluster then there's no need for matching MAC addresses, but again this is for the design doc

Comment thread enhancements/OSAC-2135/prd.md Outdated
- *Duplicate MACs:* If a MAC address matches multiple `BareMetalInstance` resources or multiple registered agents, CaaS will trigger a high-severity alert, isolate the conflicting hosts/agents in a quarantined state, and fail the affected `ClusterOrder` with a clear validation error.
- *Changed MACs:* The MAC-to-agent mapping contract is immutable once successfully established. Any subsequent changes in the reported MAC addresses of an active instance will trigger a node reconciliation failure, prompting a replacement of the node.
- **Tenant Isolation & Security:** Complete exclusion of CaaS-managed `BareMetalInstances` and underlying `ComputeImages` from tenant-facing APIs and UI consoles.
- **Automatic Lifecycle Cleanup:** Deletion of `BareMetalInstance` resources upon explicit, administrator-initiated cluster decommissioning or manual node pool scale-down operations. This triggers a mandatory, automated, blocking host cleanup (including deep disk wipe, network interface reset, and credentials removal) performed by BMaaS before the host can be returned to the general active inventory pool. This lifecycle cleanup applies exclusively to these manual, administrator-driven operations and does not cover automated workload-driven scaling.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The details of cleanup are handled by BMaaS and should not be detailed here

Comment thread enhancements/OSAC-2135/prd.md Outdated
- *Changed MACs:* The MAC-to-agent mapping contract is immutable once successfully established. Any subsequent changes in the reported MAC addresses of an active instance will trigger a node reconciliation failure, prompting a replacement of the node.
- **Tenant Isolation & Security:** Complete exclusion of CaaS-managed `BareMetalInstances` and underlying `ComputeImages` from tenant-facing APIs and UI consoles.
- **Automatic Lifecycle Cleanup:** Deletion of `BareMetalInstance` resources upon explicit, administrator-initiated cluster decommissioning or manual node pool scale-down operations. This triggers a mandatory, automated, blocking host cleanup (including deep disk wipe, network interface reset, and credentials removal) performed by BMaaS before the host can be returned to the general active inventory pool. This lifecycle cleanup applies exclusively to these manual, administrator-driven operations and does not cover automated workload-driven scaling.
- **Race Prevention:** Allocation of exactly one isolated `InfraEnv` per cluster, uniquely scoped and keyed by the Cluster UUID as its identity key, to prevent cross-tenant agent registration races. Node pools within the same cluster share this single `InfraEnv`. The `InfraEnv` is created immediately during initial cluster bootstrap (prior to any worker node provisioning) and is deleted only during the final cluster decommissioning phase, after all associated nodes have been successfully deprovisioned and cleaned up. This guarantees that exactly one `InfraEnv` instance exists per cluster lifecycle scope.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

InfraEnv per cluster is design details

Comment thread enhancements/OSAC-2135/prd.md Outdated

### Cloud Infrastructure Admin

- As a Cloud Infrastructure Admin, I want every deprovisioned bare-metal host to undergo a guaranteed, blocking cleanup (including deep disk wipe and network reset) by the BMaaS layer before being returned to the general inventory pool, so that I can prevent security leaks and configuration drift between different tenants.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Tenant boundaries are the cloud provider admin's responsibility

Comment thread enhancements/OSAC-2135/prd.md Outdated

- As a Cloud Infrastructure Admin, I want every deprovisioned bare-metal host to undergo a guaranteed, blocking cleanup (including deep disk wipe and network reset) by the BMaaS layer before being returned to the general inventory pool, so that I can prevent security leaks and configuration drift between different tenants.

- As a Cloud Infrastructure Admin, I want to ensure that no Assisted Installer, agent, or cluster-specific terminology is exposed within the BMaaS private APIs, so that the BMaaS service remains a clean, generic bare-metal-as-a-service provider.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This isn't exposed to users and therefore isn't a user story

Comment thread enhancements/OSAC-2135/prd.md Outdated

## Dependencies

- **MAC Address Status Exposure:** BMaaS must expose all physical MAC addresses of the host's interfaces as a structured list in the `BareMetalInstance` status subresource, clearly identifying the primary/boot interface MAC address as the canonical reference, to support the CaaS MAC normalization and matching contract `[Jira: OSAC-2308]`.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Leave to design doc

Comment thread enhancements/OSAC-2135/prd.md Outdated
- **BareMetalInstanceType Definition:** The `BareMetalInstanceType` specifications and schema definitions must be finalized and available `[PR #59]`.
- **User Data Pass-through:** BMaaS private API must support the ingestion and pass-through of ignition configurations in the `BareMetalInstance` spec.

## Risks & Mitigations

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Mitigations contain design details

@eranco74 eranco74 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good problem framing and persona coverage. Three things to fix:

  1. In Scope has design leakage

Issue: MAC normalization format, exponential backoff, AwaitingHardwareDiscovery/BareMetalInstanceReady conditions, and InfraEnv lifecycle are implementation details.

Action: Reframe as user-observable outcomes: "CaaS correlates provisioned hosts to cluster agents", "hosts are cleaned up on decommission." Move the mechanics to the design doc.

  1. Remove the Risks section

Issue: prd_template.md has 6 sections (Problem Statement, In Scope, Out of Scope, User Stories, Assumptions, Dependencies).

Action: Remove this section. Risks belongs in the design doc.

  1. Assumptions contains API contracts

Issue: The BareMetalInstanceReady condition spec and failure-ownership breakdown are design-level interface contracts, not product assumptions.

Action: Remove this section.

@forgeSmith-bot

Copy link
Copy Markdown
Author

PRD has been revised based on feedback. Please review the updated version.

@openshift-ci

openshift-ci Bot commented Aug 2, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: forgeSmith-bot
Once this PR has been reviewed and has the lgtm label, please ask for approval from avishayt. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@forgeSmith-bot

Copy link
Copy Markdown
Author

PRD has been revised based on feedback. Please review the updated version.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@enhancements/OSAC-2135/prd.md`:
- Line 28: The PRD’s ClusterOrder resourceClass definition lacks a deterministic
BMaaS mapping and rejection behavior. Update the Resource Definition section to
specify that each nodeRequests[].resourceClass maps to the corresponding
BareMetalInstanceSpec.instance_type.name, whose host_label_selector/match_labels
are passed to BMaaS; explicitly require unsupported or unavailable resourceClass
values to be rejected rather than mapped to another hardware class.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository: osac-project/coderabbit/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 283e32cd-fff6-4f4a-86ca-3cd74f60387a

📥 Commits

Reviewing files that changed from the base of the PR and between 2a2f868 and 5e0d55a.

📒 Files selected for processing (1)
  • enhancements/OSAC-2135/prd.md

Comment thread enhancements/OSAC-2135/prd.md Outdated
@forgeSmith-bot

Copy link
Copy Markdown
Author

PRD has been revised based on feedback. Please review the updated version.

@avishayt
avishayt requested a review from carbonin August 3, 2026 06:08
Comment thread enhancements/OSAC-2135/prd.md Outdated

### Cloud Infrastructure Admin

- As a Cloud Infrastructure Admin, I want every deprovisioned bare-metal host to undergo a guaranteed, blocking cleanup (including deep disk wipe and network reset) by the BMaaS layer before being returned to the general inventory pool, so that I can prevent security leaks and configuration drift between different tenants.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Tenant boundaries are the cloud provider admin's responsibility

Comment thread enhancements/OSAC-2135/prd.md Outdated

- As a Cloud Infrastructure Admin, I want every deprovisioned bare-metal host to undergo a guaranteed, blocking cleanup (including deep disk wipe and network reset) by the BMaaS layer before being returned to the general inventory pool, so that I can prevent security leaks and configuration drift between different tenants.

- As a Cloud Infrastructure Admin, I want to ensure that no Assisted Installer, agent, or cluster-specific terminology is exposed within the BMaaS private APIs, so that the BMaaS service remains a clean, generic bare-metal-as-a-service provider.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This isn't exposed to users and therefore isn't a user story

@openshift-ci

openshift-ci Bot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

@eshulman2: changing LGTM is restricted to collaborators

Details

In response to this:

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@forgeSmith-bot

Copy link
Copy Markdown
Author

PRD has been revised based on feedback. Please review the updated version.

@openshift-ci

openshift-ci Bot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

@eshulman2: changing LGTM is restricted to collaborators

Details

In response to this:

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@forgeSmith-bot

Copy link
Copy Markdown
Author

PRD has been revised based on feedback. Please review the updated version.

@openshift-ci

openshift-ci Bot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

@eshulman2: changing LGTM is restricted to collaborators

Details

In response to this:

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@tchughesiv tchughesiv left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@eranco74 any idea why we're not seeing provenance details at the end of the file?

@forgeSmith-bot

Copy link
Copy Markdown
Author

PRD has been revised based on feedback. Please review the updated version.

|-------------|-------|
| Author(s) | CaaS and BMaaS Product Teams |
| Jira | OSAC-2135 |
| Date | 2026-08-02 |

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

add a field called test with the value true

@openshift-ci

openshift-ci Bot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

@eshulman2: changing LGTM is restricted to collaborators

Details

In response to this:

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@forgeSmith-bot

Copy link
Copy Markdown
Author

PRD has been revised based on feedback. Please review the updated version.

@eshulman2

Copy link
Copy Markdown

@avishayt @eranco74 sorry for the stale test field wanted to be 100% the beta fix works

@mhrivnak mhrivnak left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm not sure this PRD should exist. The jira issue describes work that looks like a change of internal implementation details. That explains why this PRD in its current form is fairly confusing. I read it twice trying to find a narrative or cohesive theme, then went to jira and found that it's really a refactor. I think we should probably skip the PRD and not try to force this change to be describes in terms of user stories, and just go straight to design.

@forgeSmith-bot

Copy link
Copy Markdown
Author

Forge reviewed the feedback but the regenerated PRD was unchanged. The feedback may require manual revision, or it may have already been addressed in a previous revision.

@carbonin

Copy link
Copy Markdown

Closing in favor of #185

@carbonin carbonin closed this Aug 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants