ROSAENG-65876: Add OSDFM stage-canary gating Prow job with backplane Hive access - #84039
Conversation
|
@anfranci14: This pull request references ROSAENG-65876 which is a valid jira issue. Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the sub-task to target the "5.1.0" version, but no target version was set. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository YAML (base), Central YAML (inherited) Review profile: CHILL Plan: Pro Plus Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (1)
Included review availability: Your plan provides up to 2 included reviews per hour; 1 remains after this review. WalkthroughThe ROSA E2E configuration adds a scheduled OCM FVT staging canary job. The job enables nested Podman and intranet access, configures credentials and reporting, sets canary soak options, selects the stage environment, and applies a four-hour timeout. ChangesOCM FVT staging canary
Estimated code review effort: 3 (Moderate) | ~15–30 minutes Merge Risk: ⚪ Minimal · up to This localized change adds the requested stage-canary gating configuration, and no actionable merge-blocking risk remains beyond normal checks and review. Suggested reviewers: Important Pre-merge checks failedPlease resolve all errors before merging. Addressing warnings is optional. ❌ Failed checks (1 error)
✅ Passed checks (14 passed)
Full details: Docstring CoverageExplanation No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0 files. (1 skipped: 1 unsupported.) Full details: Stable And Deterministic Test NamesExplanation PASS: The pull request changes only CI YAML and generated Prow job metadata. It adds the static job/test identifier Full details: Test Structure And QualityExplanation PASS — The pull request changes only two YAML files: the staging Prow configuration and its generated periodic-job definition. It adds no Ginkgo source, Full details: Microshift Test CompatibilityExplanation The check is not applicable. The pull request changes only two YAML files: the OCM FVT staging job configuration and its generated Prow job. The diff adds no Ginkgo test declarations or test source, and it introduces no MicroShift-incompatible API or feature reference. Full details: Single Node Openshift (Sno) Test CompatibilityExplanation PASS — The pull request changes only Prow YAML and generated job configuration. The diff adds no Ginkgo tests or test declarations such as Full details: Topology-Aware Scheduling CompatibilityExplanation PASS: The pull request changes only ci-operator configuration and a generated Prow periodic-job definition. The diff adds no deployment manifest, operator code, or controller code. It also adds none of the listed topology-sensitive scheduling constraints, such as affinity, topology spread, replica, node-role, toleration, or PDB settings. The Full details: Ote Binary Stdout ContractExplanation PASS: The pull request changes only two YAML files: the staging job configuration and generated Prow metadata. It adds a job that uses the existing Full details: Ipv6 And Disconnected Network Test CompatibilityExplanation PASS: The pull request changes only CI YAML and generated Prow job configuration. It adds no Ginkgo test declarations or test implementation files. The referenced Full details: No-Weak-CryptoExplanation PASS. The PR changes only two YAML files: one staging job definition and its generated Prow job. Added lines contain no MD5, SHA-1, DES, 3DES, RC4, Blowfish, ECB, crypto implementation, or secret/token comparison. The job references the existing Full details: Container-PrivilegesExplanation The pull request adds a Prow job and its generated ProwJob, but neither changed manifest declares Full details: No-Sensitive-Data-In-LogsExplanation The new job enables an existing logging path. Its Resolution Before enabling this job, update the shared OCM FVT command to log only generic status, HTTP codes, and retry counts. Remove raw Prometheus response bodies, the internal Prometheus FQDN, cluster names and cluster IDs from log messages, and raw port-forward log output. Keep credential and kubeconfig contents out of stdout and stderr. Then regenerate the Prow job configuration. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
[REHEARSALNOTIFIER] Note: If this PR includes changes to step registry files (
|
|
/pj-rehearse network-access-allowed |
|
@dustman9000: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
|
/pj-rehearse periodic-ci-openshift-online-rosa-e2e-main-ocm-fvt-osdfm-staging-ocm-fvt-gating-osdfm-stage-canary |
|
@anfranci14: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
|
@anfranci14: job(s): periodic-ci-openshift-online-rosa-e2e-main-ocm-fvt-osdfm-staging-ocm-fvt-gating-osdfm-stage-canary either don't exist or were not found to be affected, and cannot be rehearsed |
|
/pj-rehearse periodic-ci-openshift-online-rosa-e2e-main-ocm-fvt-osdfm-staging-ocm-fvt-gating-osdfm-stage-canary |
|
@anfranci14: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
|
@anfranci14: job(s): periodic-ci-openshift-online-rosa-e2e-main-ocm-fvt-osdfm-staging-ocm-fvt-gating-osdfm-stage-canary either don't exist or were not found to be affected, and cannot be rehearsed |
|
/approve |
|
/pj-rehearse periodic-ci-openshift-online-rosa-e2e-main-ocm-fvt-osdfm-staging-ocm-fvt-gating-osdfm-stage-canary |
|
@anfranci14: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
|
/pj-rehearse periodic-ci-openshift-online-rosa-e2e-main-ocm-fvt-osdfm-staging-ocm-fvt-gating-osdfm-stage-canary |
|
@anfranci14: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
|
Rehearsals passed two times. |
|
/pj-rehearse periodic-ci-openshift-online-rosa-e2e-main-ocm-fvt-osdfm-integration-ocm-fvt-gating-osdfm-integration-canary |
|
@anfranci14: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
|
@anfranci14: job(s): periodic-ci-openshift-online-rosa-e2e-main-ocm-fvt-osdfm-integration-ocm-fvt-gating-osdfm-integration-canary either don't exist or were not found to be affected, and cannot be rehearsed |
|
/lgtm |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: anfranci14, dustman9000 The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
|
@anfranci14: all tests passed! Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
Summary
Adds a never-cron Prow gating job for OSDFM stage-canary, following the same pattern as INT gating (#82743 / #62722).
New job ocm-fvt-gating-osdfm-stage-canary in the ocm-fvt-osdfm-staging variant
Runs osdfm-basic-stage via rosa-e2e-ocm-fvt-longrunning with SECTOR=canary, SOAK_TIME=15
Enables backplane for Hive AAO access and AppSRE Prometheus port-forward (shared step-registry from INT migration — no new step changes)
Stage Hive override: hives02ue1 (1farlonnersks14ohfp155uoonupr9id) — matches pre-Prow Tekton kubeconfig in app-interface stage AAO secret
AppSRE Prom: app-sre-stage-01 (19mjrthsfn66bm22m574v2v1gt9a8r4q) — same cluster INT gating uses
Out of scope (follow-up):
stage-main gating job (separate PR after canary is validated)
app-interface Gangway bridge in gating-tests-qe-fvt-prow-e2e.yaml to wire SAPM deploy → Prow
Test plan
make update (done locally)
Prow rehearsal: periodic-ci-openshift-online-rosa-e2e-main-ocm-fvt-osdfm-staging-ocm-fvt-gating-osdfm-stage-canary
After merge: app-interface MR to add stage-canary-prow-e2e Gangway target subscribing to ocm-osdfm-deployed-stage-canary
Retire Tekton stage-canary target from gating-tests-qe-fvt.yaml once Prow path is verified
Summary by CodeRabbit
ocm-fvt-gating-osdfm-stage-canaryProw job to theocm-fvt-osdfm-stagingvariant.osdfm-basic-stagewith canary settings throughrosa-e2e-ocm-fvt-longrunning.