feat: add OCI artifact support for testworkflows - #6767
dhimanAbhi wants to merge 3 commits into
Conversation
|
hey, @dhimanAbhi thank you for your contribution. Looks like a good work, but there is no api spec changes there, that is sued to generate models |
vsukhin
left a comment
There was a problem hiding this comment.
add api spec changes used for mode generation
|
Thanks @vsukhin , I updated api spec and some minor improvements. Let me know if you have any other thoughts or suggestions for further changes! |
|
I have one questions,are CRD installed without kubectl apply --server-side having thier size was increased? |
|
Also, don't you mind to prepare PR for https://github.com/kubeshop/testkube-docs with updated Content spec? |
@vsukhin , I generated CRDs and api spec using Makefile commands |
Definetly. I will soon make a PR for the documentation update. |
It's fine. It's just about testing, because for large CRDs we can have a warning from Kubernetes about thier size |
Sounds Great. Let me know if anything else is required from my end! 🙌 |
Greptile SummaryThis PR adds OCI (Open Container Initiative) registry support as a new content source for TestWorkflows, enabling users to fetch test artifacts from OCI-compliant registries like Docker Hub, GHCR, or private registries. This is particularly valuable for air-gapped environments where Git access may be restricted. Key Changes
Issues Found
Missing Test Coverage
Security Considerations
Confidence Score: 3/5
Important Files Changed
Sequence DiagramsequenceDiagram
participant User
participant API
participant Processor
participant K8s
participant Toolkit
participant Registry
User->>API: Submit TestWorkflow with content.oci
API->>Processor: Process workflow spec
Processor->>Processor: ProcessContentOci()
Processor->>K8s: Create Job with toolkit container
K8s->>Toolkit: Execute /toolkit oci command
Toolkit->>Registry: Authenticate (username/token)
Registry-->>Toolkit: Auth successful
Toolkit->>Registry: Fetch manifest & layers
Registry-->>Toolkit: Return artifact layers
Toolkit->>Toolkit: Extract layers to temp directory
Toolkit->>Toolkit: Copy content from path to mountPath
Toolkit->>Toolkit: Adjust file permissions
Toolkit-->>K8s: Artifact fetched to volume
K8s->>K8s: Execute test steps with artifact content
Last reviewed commit: f8a4362 |
vsukhin
left a comment
There was a problem hiding this comment.
hey @dhimanAbhi one more great contribution! please my and greptile. did you test it well in kubernetes cluster?
| @@ -671,6 +671,174 @@ spec: | |||
| x-kubernetes-map-type: atomic | |||
| type: object | |||
| type: object | |||
There was a problem hiding this comment.
did you test CRD size? Any warnings from Kubernetes
There was a problem hiding this comment.
Do we need these changes in helm/testkube-operator?
|
@dhimanAbhi also back merge main branch |
|
@dhimanAbhi please let us know if you plan to update |
|
Hi @olensmar, yes, I’ll be fixing the issues mentioned above. I’ll push an update by the end of this week. |
Signed-off-by: Abhishek Dhiman <abhi2002dhiman@gmail.com>
Signed-off-by: Abhishek Dhiman <abhi2002dhiman@gmail.com>
Signed-off-by: Abhishek Dhiman <abhi2002dhiman@gmail.com>
f8a4362 to
f3869d9
Compare
|
Thanks for the review @vsukhin ! I tested the changes in a local kind cluster by building the Testkube images and applying the updated CRDs from I also regenerated and synchronized the corresponding Helm CRDs, so the updated definitions are now reflected in Please let me know if there’s anything else I should verify or improve. |
|
thank you @dhimanAbhi let me recheck it |
|
@greptile are these CRD changes will not be over CRD size used on client side? |
Pull request description
This PR introduces support for OCI registry sources in the container executor. It enables fetching test assets directly from OCI-compliant registries (such as Docker Hub, GHCR, or self-hosted registries) as an alternative to Git-based sources. This addition provides a secure and reliable way to distribute test content, especially for air-gapped or restricted network environments, here access to public Git repositories may not be feasible.
It solves issue #4849
Proof Manifests
These are logs of testworkflow execution where I had pushed cypress test defined in testkube/test/cypress/cypress-12 to my dockerhub private repo as an artifact using ORAS. This PR fetches the content just like fetching from Git Source.
Testworkflow Definition
Users can define an OCI registry source specifying:
Template -
Example
Checklist (choose whats happened)
Breaking changes
Changes
Fixes