Repository navigation
OSAC-1550: read sshPublicKey from template parameters - #368
openshift-merge-bot[bot] merged 2 commits into
Conversation
|
@mennyaboush: This pull request references OSAC-1550 which is a valid jira issue. Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the task to target the "5.0.0" version, but no target version was set. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
Warning Review limit reached
More reviews will be available in 58 minutes and 22 seconds. Learn how PR review limits work. Your organization has used up its prepaid credits, and credit purchases are no longer available. Enable the review add-on in the billing tab to keep reviews running — you're only billed for reviews past your plan's rate limits ($0.25/file). ⌛ How to resolve this issue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based credits. 🚦 How do rate limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please see our Fair Usage Limits Policy for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: Repository: osac-project/coderabbit/.coderabbit.yaml Review profile: ASSERTIVE Plan: Enterprise Run ID: 📒 Files selected for processing (1)
WalkthroughA single field name is corrected in the ChangesSSH Key Field Rename
Estimated code review effort🎯 1 (Trivial) | ⏱️ ~2 minutes Possibly related PRs
Suggested labels
Suggested reviewers
Poem
🚥 Pre-merge checks | ✅ 11✅ Passed checks (11 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In
`@collections/ansible_collections/osac/templates/roles/bm_host_metal3_provisioning/tasks/create.yaml`:
- Line 25: The ssh_key assignment on line 25 uses only the new sshPublicKey
parameter name without a fallback to the old sshKey parameter, which causes
silent failures when the fulfillment-service hasn't been updated yet. Modify the
default filter chain for template_params.sshPublicKey to include a secondary
fallback that checks template_params.sshKey before falling back to an empty
string, ensuring backward compatibility during staggered deployments.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Repository: osac-project/coderabbit/.coderabbit.yaml
Review profile: ASSERTIVE
Plan: Enterprise
Run ID: 55572dcc-990a-4d0d-a4e8-e907016cb04a
📒 Files selected for processing (1)
collections/ansible_collections/osac/templates/roles/bm_host_metal3_provisioning/tasks/create.yaml
a2554eb to
e2d99f9
Compare
The fulfillment-service renamed the AAP template parameter key from sshKey to sshPublicKey. Update the reader to match. Assisted-by: Claude Code <noreply@anthropic.com> Signed-off-by: MENNY ABOUSH <maboush@maboush-thinkpadt14gen5.raanaii.csb>
e2d99f9 to
cd03f76
Compare
|
/retest |
|
infra flake |
Remove the sshKey fallback from template parameter extraction per reviewer feedback — both PRs will merge together so backward compatibility is unnecessary. Assisted-by: Claude Code <noreply@anthropic.com> Signed-off-by: MENNY ABOUSH <maboush@maboush-thinkpadt14gen5.raanaii.csb>
|
💀 CI Triage: Root cause: The publish-templates AAP job failed with a 403 Forbidden because fulfillment-service PR #742 removed template-publisher from the default emergency service accounts, and the corresponding osac-installer PR #322 had not yet been merged. Explanation: During the refresh phase of the boot step, the publish-templates AAP job is launched to sync templates to the fulfillment service. This job runs as the template-publisher service account. fulfillment-service PR #742 (merged at 13:43Z) made the emergency service accounts configurable and defaulted to only ["admin"], removing template-publisher's admin access. This caused the job to fail with a 403 Forbidden when calling /api/private/v1/cluster_templates. The fix, osac-installer PR #322, which adds template-publisher to auth.emergencyServiceAccounts in the Helm values, was merged later at 23:03Z. Since this job ran at 16:19Z, it caught the window where main was broken. Evidence: Suggestion: Retrigger the job. The fix has already been merged in osac-installer PR #322, so a new run will pick up the updated Helm values and pass. Prow job | Build For deeper investigation, use the |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: adriengentil, mennyaboush The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
Summary
bm_host_metal3_provisioningrole to readtemplate_params.sshPublicKeyinstead oftemplate_params.sshKeyRequired by the fulfillment-service parameter key rename in osac-project/fulfillment-service#744. Both PRs should merge together.
Test plan
Summary by CodeRabbit
Bug Fixes