Skip to content
This repository was archived by the owner on Sep 9, 2026. It is now read-only.

NO-ISSUE: add is_windows field to ComputeInstanceTemplate and CatalogItem support - #750

Merged
openshift-merge-bot[bot] merged 1 commit into
osac-project:mainfrom
ygalblum:feat/template-add-is-windows
Jun 29, 2026
Merged

openshift-merge-bot[bot] merged 1 commit into
osac-project:mainfrom
ygalblum:feat/template-add-is-windows

Conversation

@ygalblum

@ygalblum ygalblum commented Jun 23, 2026 •

Copy link
Copy Markdown
Contributor

Add is_windows optional boolean field to ComputeInstanceTemplateSpecDefaults in both public and private proto APIs, with template default application and CatalogItem field definition support.

Windows VM provisioning requires templates to carry a guest OS indicator so that downstream provisioning (osac-aap) can apply Windows-specific configuration. This extends the template defaults mechanism to propagate is_windows through the same path as other spec fields like cores, memory, and run_strategy.

  • Added optional bool is_windows field (number 6) to ComputeInstanceTemplateSpecDefaults in both public and private proto definitions

  • Regenerated protobuf Go code for the new field

  • Extended ApplySpecDefaults to propagate the is_windows template default when the user has not set it

  • Added is_windows as a recognized path in CatalogItem field definition application (applyFieldDefinitions)

  • Added unit tests for template default application: applies default, preserves user-provided value, handles missing default

  • Added unit tests for CatalogItem field definitions: applies editable default, forces non-editable value

Assisted-by: Claude Code noreply@anthropic.com

Summary by CodeRabbit

  • New Features
    • Template defaults now include an optional is_windows setting to choose the VM operating system (Windows when true, Linux when false or omitted). New instances inherit this value automatically unless explicitly overridden.
  • Bug Fixes
    • Improved defaulting behavior to ensure is_windows is applied correctly from template defaults when the user does not set it.
  • Tests
    • Added coverage for defaulting, preservation when the user provides a value, and override behavior based on field editability.

@openshift-ci
openshift-ci Bot requested review from trewest and tzvatot June 23, 2026 19:08
@openshift-ci

openshift-ci Bot commented Jun 23, 2026

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: ygalblum

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@coderabbitai

coderabbitai Bot commented Jun 23, 2026 •

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: osac-project/coderabbit/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Enterprise

Run ID: f753f872-e132-4a88-a9e9-4dfb4c3407d9

📥 Commits

Reviewing files that changed from the base of the PR and between 979d866 and 3158f36.

⛔ Files ignored due to path filters (4)
  • internal/api/osac/private/v1/compute_instance_template_type.pb.go is excluded by !**/*.pb.go
  • internal/api/osac/private/v1/compute_instance_template_type_protoopaque.pb.go is excluded by !**/*.pb.go
  • internal/api/osac/public/v1/compute_instance_template_type.pb.go is excluded by !**/*.pb.go
  • internal/api/osac/public/v1/compute_instance_template_type_protoopaque.pb.go is excluded by !**/*.pb.go
📒 Files selected for processing (5)
  • internal/servers/catalog_item_validation_test.go
  • internal/utils/spec_defaults.go
  • internal/utils/spec_defaults_test.go
  • proto/private/osac/private/v1/compute_instance_template_type.proto
  • proto/public/osac/public/v1/compute_instance_template_type.proto

Walkthrough

Adds an optional is_windows field to both proto definitions, defaults it into ComputeInstanceSpec, and extends tests for defaulting and field-definition handling.

Changes

is_windows default field end-to-end

Layer / File(s) Summary
Proto contract: is_windows in ComputeInstanceTemplateSpecDefaults
proto/private/osac/private/v1/compute_instance_template_type.proto, proto/public/osac/public/v1/compute_instance_template_type.proto
Adds optional bool is_windows to ComputeInstanceTemplateSpecDefaults in both proto files with documentation describing Windows and Linux behavior.
ApplySpecDefaults: propagate is_windows from template defaults
internal/utils/spec_defaults.go
ApplySpecDefaults sets spec.is_windows from template defaults when the spec field is unset, alongside the existing defaulting sequence.
Tests for is_windows defaulting and field application
internal/utils/spec_defaults_test.go, internal/servers/catalog_item_validation_test.go
New tests cover ApplySpecDefaults when defaults include or omit is_windows, and applyFieldDefinitions when the field is editable or non-editable.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

Possibly related PRs

Suggested reviewers

  • rgolangh
  • jhernand
  • adriengentil

Poem

A little flag now finds its home,
In proto fields where defaults roam.
Linux or Windows, set or not,
The tests confirm the path is caught.
🪟

🚥 Pre-merge checks | ✅ 11
✅ Passed checks (11 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately summarizes the main change: adding is_windows support to template defaults and CatalogItem handling.
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
No-Hardcoded-Secrets ✅ Passed PASS: changes only add is_windows defaults/tests and proto field; no API keys, tokens, passwords, private keys, or credentialed URLs found.
No-Weak-Crypto ✅ Passed No weak-crypto primitives, custom crypto, or non-constant-time secret comparisons were added; the patch only adds boolean default plumbing and tests.
No-Injection-Vectors ✅ Passed No new SQL/shell/eval/pickle/yaml/dangerous-HTML sinks were introduced; the only eval hit is dev/setup.py's commands.eval with argv list, not user input.
Container-Privileges ✅ Passed PASS: The PR only touches proto/test/defaulting code; no privileged/hostPID/hostNetwork/hostIPC/SYS_ADMIN/allowPrivilegeEscalation:true or root settings were added.
No-Sensitive-Data-In-Logs ✅ Passed No new logging statements or logger usage were added; the patch only adds an is_windows field, defaulting, and tests/comments.
Ai-Attribution ✅ Passed Commit message includes an Assisted-by trailer for Claude Code and no Co-Authored-By AI attribution was found.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@omer-vishlitzky

Copy link
Copy Markdown
Contributor

💀 CI Triage: broken_main | Category: BOOT

Root cause: The main branch is broken due to a database migration sequence number collision between PR 706 and PR 740, which both added a migration with sequence number 60.

Explanation: The boot step failed because the fulfillment-console-proxy deployment timed out during rollout. The proxy depends on the fulfillment-grpc-server, which was crashing at startup. The grpc-server pod logs show it failed to initialize the database with the error 'failed to init driver with path migrations: duplicate migration file: 60_create_external_ip_tables.up.sql'. A search of recently merged PRs reveals that PR 706 added '60_add_projects_immutable_trigger.up.sql' and PR 740 added '60_create_external_ip_tables.up.sql'. Because PR 740 was merged after PR 706 without rebasing, the main branch now contains two migrations with the '60_' prefix, causing the golang-migrate library to fail. This PR (750) does not touch migrations and is failing because it was tested against the broken main branch.

Evidence:

[e2e-vmaas-osac-project-cluster-tool-boot build-log.txt](https://gcsweb-ci.apps.ci.l2s4.p1.openshiftapps.com/gcs/test-platform-results/pr-logs/pull/osac-project_fulfillment-service/750/pull-ci-osac-project-fulfillment-service-main-e2e-vmaas/2069563846242078720/artifacts/e2e-vmaas/osac-project-gather/artifacts/osac-logs/e2e-vmaas-osac-project-cluster-tool-boot build-log.txt):

ERROR: command failed (exit 1): oc rollout status deploy/fulfillment-console-proxy -n osac-e2e-ci --timeout=360s

pod-fulfillment-grpc-server-59dfff497b-ksfrl-grpc-server.log:

failed to init driver with path migrations: duplicate migration file: 60_create_external_ip_tables.up.sql

Suggestion: Create a PR to fix the main branch by renaming the migration files from '60_create_external_ip_tables' to '61_create_external_ip_tables'. Once merged, rebase this PR and retrigger the tests.


Prow job | Build 2069563846242078720 | 🤖 triagent

For deeper investigation, use the /osac-debug-e2e skill with this build ID.

@ygalblum
ygalblum force-pushed the feat/template-add-is-windows branch from e6fb3d1 to 979d866 Compare June 24, 2026 12:59
@ygalblum ygalblum changed the title feat: add is_windows field to ComputeInstanceTemplate and CatalogItem support NO-ISSUE: add is_windows field to ComputeInstanceTemplate and CatalogItem support Jun 24, 2026
@openshift-ci-robot

Copy link
Copy Markdown

@ygalblum: This pull request explicitly references no jira issue.

Details

In response to this:

Add is_windows optional boolean field to ComputeInstanceTemplateSpecDefaults in both public and private proto APIs, with template default application and CatalogItem field definition support.

Windows VM provisioning requires templates to carry a guest OS indicator so that downstream provisioning (osac-aap) can apply Windows-specific configuration. This extends the template defaults mechanism to propagate is_windows through the same path as other spec fields like cores, memory, and run_strategy.

  • Added optional bool is_windows field (number 6) to ComputeInstanceTemplateSpecDefaults in both public and private proto definitions

  • Regenerated protobuf Go code for the new field

  • Extended ApplySpecDefaults to propagate the is_windows template default when the user has not set it

  • Added is_windows as a recognized path in CatalogItem field definition application (applyFieldDefinitions)

  • Added unit tests for template default application: applies default, preserves user-provided value, handles missing default

  • Added unit tests for CatalogItem field definitions: applies editable default, forces non-editable value

Assisted-by: Claude Code noreply@anthropic.com

Summary by CodeRabbit

  • New Features
  • Template defaults now support specifying the operating system (Windows or Linux) for compute instances via is_windows. When set on a template, new instances inherit it automatically unless explicitly overridden.
  • Tests
  • Added test coverage to verify defaulting behavior for is_windows when omitted, preservation when explicitly provided, and override rules based on field editability.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

… support

Add `is_windows` optional boolean field to `ComputeInstanceTemplateSpecDefaults` in both public and private proto APIs, with template default application and CatalogItem field definition support.

Windows VM provisioning requires templates to carry a guest OS indicator so that downstream provisioning (osac-aap) can apply Windows-specific configuration. This extends the template defaults mechanism to propagate `is_windows` through the same path as other spec fields like cores, memory, and run_strategy.

- Added `optional bool is_windows` field (number 6) to `ComputeInstanceTemplateSpecDefaults` in both public and private proto definitions
- Regenerated protobuf Go code for the new field
- Extended `ApplySpecDefaults` to propagate the `is_windows` template default when the user has not set it
- Added `is_windows` as a recognized path in CatalogItem field definition application (`applyFieldDefinitions`)

- Added unit tests for template default application: applies default, preserves user-provided value, handles missing default
- Added unit tests for CatalogItem field definitions: applies editable default, forces non-editable value

Assisted-by: Claude Code <noreply@anthropic.com>
Signed-off-by: Ygal Blum <ygal.blum@gmail.com>
@ygalblum
ygalblum force-pushed the feat/template-add-is-windows branch from 979d866 to 3158f36 Compare June 24, 2026 18:15
@omer-vishlitzky

Copy link
Copy Markdown
Contributor

💀 CI Triage: broken_main | Category: BOOT

Root cause: Helm upgrade fails during the boot step because osac-installer PR 328 changed the OSAC_AAP_TOKEN env var from value to valueFrom, causing a strategic merge patch conflict with the existing snapshot deployment.

Explanation: The CI boot step uses a pre-built snapshot flavor (vmaas-helm) which contains an older version of the osac-operator deployment where OSAC_AAP_TOKEN is set as a literal value. Recently, osac-installer PR 328 updated the CI Helm values to use aap.tokenSecret, which renders valueFrom instead of value. When refresh-after-snapshot.py runs helm upgrade to apply the new configuration, Helm generates a strategic merge patch that adds valueFrom but does not explicitly remove value. Kubernetes rejects the patch because a container environment variable cannot have both value and valueFrom. This breaks the boot step for all PRs across all repos.

Evidence:

build-log.txt:

Error: UPGRADE FAILED: cannot patch "osac-operator" with kind Deployment: Deployment.apps "osac-operator" is invalid: spec.template.spec.containers[0].env[1].valueFrom: Invalid value: "": may not be specified when `value` is not empty

build-log.txt:

ERROR: command failed (exit 1): helm upgrade osac charts/osac/ --namespace osac-e2e-ci --values values/vmaas-ci/values.yaml --set service.externalHostname=fulfillment-api-osac-e2e-ci.apps.test-infra-cluster-vmaas-helm.redhat.com --set service.internalHostname=fulfillment-internal-api-osac-e2e-ci.apps.test-infra-cluster-vmaas-helm.redhat.com --set aap.bootstrap.enabled=false --set clusterFulfillment.config.HOSTED_CLUSTER_BASE_DOMAIN=hosted.test-infra-cluster-vmaas-helm.redhat.com --timeout 15m

Suggestion: Update the osac-operator Helm chart (charts/operator/templates/deployment.yaml) to explicitly set value: null when valueFrom is used for OSAC_AAP_TOKEN. This will force Helm to generate a patch that removes the old value field during upgrades.


Prow job | Build 2069846868132630528 | 🤖 triagent

For deeper investigation, use the /osac-debug-e2e skill with this build ID.

@omer-vishlitzky

Copy link
Copy Markdown
Contributor

/retest

@tzvatot tzvatot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The implementation mechanics (default propagation, field definitions, tests) are well done and follow the existing patterns. But the field type is a fundamental API design issue that should be fixed before merge.

Category Count
🔴 Critical 1
💡 Suggestion 1

💡 Suggestion: Even setting the type aside, the field name is_windows bakes a specific value into the schema. A name like guest_os or os_family describes the dimension, not one point on it. guest_os: "windows" reads as a choice; is_windows: true reads as an assertion about one specific OS.

Comment thread proto/public/osac/public/v1/compute_instance_template_type.proto
Comment thread proto/private/osac/private/v1/compute_instance_template_type.proto
@tzvatot

tzvatot commented Jun 29, 2026

Copy link
Copy Markdown
Contributor

/lgtm
/approved

@openshift-ci openshift-ci Bot added the lgtm label Jun 29, 2026
@openshift-merge-bot
openshift-merge-bot Bot merged commit b0c0208 into osac-project:main Jun 29, 2026
14 checks passed
@ygalblum
ygalblum deleted the feat/template-add-is-windows branch June 29, 2026 17:20
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants