Skip to content

Use Watcher user for the dbsync job - #407

Merged
openshift-merge-bot[bot] merged 1 commit into
openstack-k8s-operators:mainfrom
amoralej:dbsync-user
Jul 27, 2026
Merged

Use Watcher user for the dbsync job#407
openshift-merge-bot[bot] merged 1 commit into
openstack-k8s-operators:mainfrom
amoralej:dbsync-user

Conversation

@amoralej

@amoralej amoralej commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

Currently, the dbsync job pod is running as root which is not required and against the minimum privilege principle.

This patch switches the dbsync job to use the Watcher user id.

@openshift-ci
openshift-ci Bot requested review from SeanMooney and raukadah July 24, 2026 07:08
@centosinfra-prod-github-app

Copy link
Copy Markdown

Build failed (check pipeline). Post recheck (without leading slash)
to rerun all jobs. Make sure the failure cause has been resolved before
you rerun jobs.

https://gateway-cloud-softwarefactory.apps.ocp.cloud.ci.centos.org/zuul/t/rdoproject.org/buildset/b95bfe8e370747d2b897ad00f4c28c56

✔️ openstack-meta-content-provider-master SUCCESS in 2h 24m 23s
watcher-operator-validation-master FAILURE in 1h 46m 39s
openstack-meta-content-provider-epoxy FAILURE in 15m 39s
⚠️ watcher-operator-validation-epoxy SKIPPED Skipped due to failed job openstack-meta-content-provider-epoxy
⚠️ watcher-operator-validation-epoxy-ocp4-18 SKIPPED Skipped due to failed job openstack-meta-content-provider-epoxy
✔️ noop SUCCESS in 0s
watcher-operator-kuttl FAILURE in 1h 32m 26s

Currently, the dbsync job pod is running as root which is not required
and against the minimum privilege principle.

This patch switches the dbsync job to use the Watcher user id.

Signed-off-by: Alfredo Moralejo <amoralej@redhat.com>
@centosinfra-prod-github-app

Copy link
Copy Markdown

Build failed (check pipeline). Post recheck (without leading slash)
to rerun all jobs. Make sure the failure cause has been resolved before
you rerun jobs.

https://gateway-cloud-softwarefactory.apps.ocp.cloud.ci.centos.org/zuul/t/rdoproject.org/buildset/80109091e2c34f579a5e8e154c4916f0

✔️ openstack-meta-content-provider-master SUCCESS in 2h 53m 41s
✔️ watcher-operator-validation-master SUCCESS in 2h 13m 29s
openstack-meta-content-provider-epoxy FAILURE in 16m 23s
⚠️ watcher-operator-validation-epoxy SKIPPED Skipped due to failed job openstack-meta-content-provider-epoxy
⚠️ watcher-operator-validation-epoxy-ocp4-18 SKIPPED Skipped due to failed job openstack-meta-content-provider-epoxy
✔️ noop SUCCESS in 0s
✔️ watcher-operator-kuttl SUCCESS in 57m 24s

@amoralej

Copy link
Copy Markdown
Contributor Author

check-rdo

1 similar comment
@amoralej

Copy link
Copy Markdown
Contributor Author

check-rdo

@amoralej
amoralej requested a review from stuggi July 27, 2026 07:30

@stuggi stuggi left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm
/approve

@openshift-ci

openshift-ci Bot commented Jul 27, 2026

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: stuggi

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-merge-bot
openshift-merge-bot Bot merged commit 48a2bba into openstack-k8s-operators:main Jul 27, 2026
7 checks passed
@amoralej

Copy link
Copy Markdown
Contributor Author

/cherry-pick 18.0-stable

@openshift-cherrypick-robot

Copy link
Copy Markdown

@amoralej: cannot checkout 18.0-stable: error checking out "18.0-stable": exit status 1 error: pathspec '18.0-stable' did not match any file(s) known to git

Details

In response to this:

/cherry-pick 18.0-stable

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@amoralej

Copy link
Copy Markdown
Contributor Author

/cherry-pick 18-stable

@openshift-cherrypick-robot

Copy link
Copy Markdown

@amoralej: new pull request created: #420

Details

In response to this:

/cherry-pick 18-stable

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants