Skip to content
This repository was archived by the owner on Sep 9, 2026. It is now read-only.

OSAC-1550: read sshPublicKey from template parameters - #368

Merged
openshift-merge-bot[bot] merged 2 commits into
osac-project:mainfrom
mennyaboush:feat/OSAC-1550-aap-rename
Jun 24, 2026
Merged

openshift-merge-bot[bot] merged 2 commits into
osac-project:mainfrom
mennyaboush:feat/OSAC-1550-aap-rename

Conversation

@mennyaboush

@mennyaboush mennyaboush commented Jun 23, 2026 •

Copy link
Copy Markdown

Summary

  • Update bm_host_metal3_provisioning role to read template_params.sshPublicKey instead of template_params.sshKey

Required by the fulfillment-service parameter key rename in osac-project/fulfillment-service#744. Both PRs should merge together.

Test plan

  • Verify with fulfillment-service PR #744 that SSH keys are passed correctly through the template parameters

Summary by CodeRabbit

Bug Fixes

  • Fixed SSH public key parameter recognition during bare metal host provisioning.

@openshift-ci-robot

openshift-ci-robot commented Jun 23, 2026 •

Copy link
Copy Markdown

@mennyaboush: This pull request references OSAC-1550 which is a valid jira issue.

Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the task to target the "5.0.0" version, but no target version was set.

Details

In response to this:

Summary

  • Update bm_host_metal3_provisioning role to read template_params.sshPublicKey instead of template_params.sshKey

Required by the fulfillment-service parameter key rename in osac-project/fulfillment-service#744. Both PRs should merge together.

Test plan

  • Verify with fulfillment-service PR #744 that SSH keys are passed correctly through the template parameters

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-ci
openshift-ci Bot requested review from adriengentil and eliorerz June 23, 2026 14:50
@coderabbitai

coderabbitai Bot commented Jun 23, 2026 •

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

@mennyaboush, we couldn't start this review because you've reached your PR review rate limit.

More reviews will be available in 58 minutes and 22 seconds. Learn how PR review limits work.

Your organization has used up its prepaid credits, and credit purchases are no longer available. Enable the review add-on in the billing tab to keep reviews running — you're only billed for reviews past your plan's rate limits ($0.25/file).

⌛ How to resolve this issue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based credits.

🚦 How do rate limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please see our Fair Usage Limits Policy for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository: osac-project/coderabbit/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Enterprise

Run ID: 77e73186-67f3-422f-adcd-3c4eb0e876ed

📥 Commits

Reviewing files that changed from the base of the PR and between a2554eb and 9bd591d.

📒 Files selected for processing (1)
  • collections/ansible_collections/osac/templates/roles/bm_host_metal3_provisioning/tasks/create.yaml

Walkthrough

A single field name is corrected in the bm_host_metal3_provisioning create task: the ssh_key fact is now sourced from template_params.sshPublicKey instead of template_params.sshKey, aligning the extracted key with the actual template parameter contract.

Changes

SSH Key Field Rename

Layer / File(s) Summary
SSH key template param field rename
collections/ansible_collections/osac/templates/roles/bm_host_metal3_provisioning/tasks/create.yaml
ssh_key fact reads from template_params.sshPublicKey instead of template_params.sshKey; default empty-string fallback is unchanged.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~2 minutes

Possibly related PRs

  • osac-project/osac-aap#358: Directly touches the same templateParameters parsing block in bm_host_metal3_provisioning/tasks/create.yaml for SSH key injection and cloud-init merge logic.

Suggested labels

lgtm, approved

Suggested reviewers

  • danmanor
  • adriengentil

Poem

A key by another name still opens the door,
sshKey stepped aside, sshPublicKey takes the floor.
One field, one fix, one line set right—
Cloud-init breathes easy, auth works tonight. 🔑

🚥 Pre-merge checks | ✅ 11
✅ Passed checks (11 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately reflects the main change: updating the role to read sshPublicKey instead of sshKey from template parameters, which is the core modification in the changeset.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
No-Hardcoded-Secrets ✅ Passed No hardcoded secrets found. The PR changes a template parameter field name reference from sshKey to sshPublicKey. All secret values come from runtime sources (template_params, Kubernetes secrets),...
No-Weak-Crypto ✅ Passed PR changes only read an SSH public key parameter name (sshKey→sshPublicKey). No weak cryptographic algorithms, custom crypto implementations, or secret comparison issues detected in the modified file.
No-Injection-Vectors ✅ Passed PR does not introduce injection vectors. Change only swaps template parameter field access; no new SQL, shell, eval, pickle, yaml.load, os.system, or HTML injection patterns created.
Container-Privileges ✅ Passed PR modifies only an Ansible role task file (not a K8s/container manifest); contains no privileged mode, hostNetwork, hostPID, hostIPC, SYS_ADMIN, allowPrivilegeEscalation, or root-running configura...
No-Sensitive-Data-In-Logs ✅ Passed The PR parameter rename from sshKey to sshPublicKey does not introduce logging of sensitive data; SSH keys are embedded in cloud-init secrets, not exposed via debug statements.
Ai-Attribution ✅ Passed AI tool (Claude Code) was properly credited with Assisted-by trailer in commit message, following Red Hat attribution conventions. No improper Co-Authored-By trailer for AI was detected.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In
`@collections/ansible_collections/osac/templates/roles/bm_host_metal3_provisioning/tasks/create.yaml`:
- Line 25: The ssh_key assignment on line 25 uses only the new sshPublicKey
parameter name without a fallback to the old sshKey parameter, which causes
silent failures when the fulfillment-service hasn't been updated yet. Modify the
default filter chain for template_params.sshPublicKey to include a secondary
fallback that checks template_params.sshKey before falling back to an empty
string, ensuring backward compatibility during staggered deployments.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository: osac-project/coderabbit/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Enterprise

Run ID: 55572dcc-990a-4d0d-a4e8-e907016cb04a

📥 Commits

Reviewing files that changed from the base of the PR and between f130cf4 and a2554eb.

📒 Files selected for processing (1)
  • collections/ansible_collections/osac/templates/roles/bm_host_metal3_provisioning/tasks/create.yaml

@mennyaboush
mennyaboush force-pushed the feat/OSAC-1550-aap-rename branch from a2554eb to e2d99f9 Compare June 23, 2026 15:00
The fulfillment-service renamed the AAP template parameter key
from sshKey to sshPublicKey. Update the reader to match.

Assisted-by: Claude Code <noreply@anthropic.com>
Signed-off-by: MENNY ABOUSH <maboush@maboush-thinkpadt14gen5.raanaii.csb>
@mennyaboush
mennyaboush force-pushed the feat/OSAC-1550-aap-rename branch from e2d99f9 to cd03f76 Compare June 23, 2026 15:07
@adriengentil

Copy link
Copy Markdown
Contributor

/retest

@omer-vishlitzky

Copy link
Copy Markdown
Contributor

infra flake
/retest

Remove the sshKey fallback from template parameter extraction per
reviewer feedback — both PRs will merge together so backward
compatibility is unnecessary.

Assisted-by: Claude Code <noreply@anthropic.com>
Signed-off-by: MENNY ABOUSH <maboush@maboush-thinkpadt14gen5.raanaii.csb>
@omer-vishlitzky

Copy link
Copy Markdown
Contributor

💀 CI Triage: broken_main | Category: BOOT

Root cause: The publish-templates AAP job failed with a 403 Forbidden because fulfillment-service PR #742 removed template-publisher from the default emergency service accounts, and the corresponding osac-installer PR #322 had not yet been merged.

Explanation: During the refresh phase of the boot step, the publish-templates AAP job is launched to sync templates to the fulfillment service. This job runs as the template-publisher service account. fulfillment-service PR #742 (merged at 13:43Z) made the emergency service accounts configurable and defaulted to only ["admin"], removing template-publisher's admin access. This caused the job to fail with a 403 Forbidden when calling /api/private/v1/cluster_templates. The fix, osac-installer PR #322, which adds template-publisher to auth.emergencyServiceAccounts in the Helm values, was merged later at 23:03Z. Since this job ran at 16:19Z, it caught the window where main was broken.

Evidence:

build-log.txt:

[ERROR]: Task failed: Module failed: Status code was 403 and not [200]: HTTP Error 403: Forbidden

build-log.txt:

fatal: [localhost]: FAILED! => {"changed": false, "connection": "close", "content_length": "40", "content_type": "application/json", "date": "Tue, 23 Jun 2026 17:18:30 GMT", "elapsed": 0, "json": {"code": 7, "message": "permission denied"}, "msg": "Status code was 403 and not [200]: HTTP Error 403: Forbidden", "redirected": false, "server": "envoy", "status": 403, "url": "https://fulfillment-internal-api:8001/api/private/v1/cluster_templates", "x_envoy_upstream_service_time": "17"}

Suggestion: Retrigger the job. The fix has already been merged in osac-installer PR #322, so a new run will pick up the updated Helm values and pass.


Prow job | Build 2069455367569412096 | 🤖 triagent

For deeper investigation, use the /osac-debug-e2e skill with this build ID.

@mennyaboush
mennyaboush requested a review from adriengentil June 24, 2026 09:43
@openshift-ci

openshift-ci Bot commented Jun 24, 2026

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: adriengentil, mennyaboush

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-merge-bot
openshift-merge-bot Bot merged commit 89f41e7 into osac-project:main Jun 24, 2026
8 checks passed
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants