Update Konflux references - #218
red-hat-konflux[bot] wants to merge 1 commit into
Conversation
c05f6a6 to
6763ea9
Compare
41b2ea2 to
8e8e1f6
Compare
8e8e1f6 to
c1083c5
Compare
c1083c5 to
d4dad2b
Compare
6e52db3 to
d3e0337
Compare
543eafc to
32536b2
Compare
dcb0be4 to
689bc2b
Compare
c176789 to
0e5992c
Compare
0e5992c to
1b7c37a
Compare
1b7c37a to
66392a3
Compare
20e0bc2 to
e312148
Compare
e312148 to
43a0651
Compare
43a0651 to
44e9e0f
Compare
44e9e0f to
a6937d8
Compare
a6937d8 to
f74a82a
Compare
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (2)
Included review availability: This review used your included allowance. Your plan provides up to 12 included reviews per hour; 11 remain after this review. 📝 SummarySummary by CodeRabbit
WalkthroughBoth Tekton pipelines add build parameters for reproducibility and package-registry proxy use. They update task bundles, replace Clair scanning with Roxctl scanning, remove two final tasks, and remove obsolete image-index parameters. ChangesTekton pipelines
Priority: ➖ Normal Estimated code review effort: 2 (Simple) | ~15 minutes Change: Feature Merge Risk: ⚪ Minimal · up to This is a routine update of Konflux task references with no identified problems. Pipeline runs should be watched after merge, as with any task bundle update. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
Comment |
f74a82a to
143e702
Compare
143e702 to
ec891ba
Compare
Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
ec891ba to
d022107
Compare
This PR contains the following updates:
0.3→0.3.10.2→0.40.8→0.12.30.3→0.4.10.3→0.3.4e3a55cc→0ccc68840bc4bc→43901410.1→0.2.60.3→0.4.30.2→0.10.30.1→0.3.10.4→0.50.1→0.30.3→0.3.20.2→0.4Release Notes
konflux-ci/container-build-catalog (quay.io/konflux-ci/tekton-catalog/task-apply-tags)
v0.3.1Changed
konflux-ci/container-build-catalog (quay.io/konflux-ci/tekton-catalog/task-build-image-index)
v0.4Added
IMAGE_PLATFORM_MAPparameter: optional per-image platform mapping(
imageRef=os/archentries) passed tokonflux-build-clias--image-platform-map. This sets the platform on each index entry explicitly,which is required for OCI artifacts whose empty config carries no platform
information (e.g. disk images), where the platform would otherwise be null.
When empty (the default), behaviour is unchanged.
v0.3.1Fixed
SBOM_SKIP_VALIDATIONinto the step environment so the create-sbom step honors the parameter.The parameter did nothing before. Now it works as expected.
v0.3Fixed
SBOM_SKIP_VALIDATIONinto the step environment so the create-sbom step honors the parameter.The parameter did nothing before. Now it works as expected.
konflux-ci/container-build-catalog (quay.io/konflux-ci/tekton-catalog/task-buildah)
v0.12.3Version 0.12.3 only has relevant changes for the remote variants of this task.
v0.12.2Changed
v0.12.1Changed
prepare-sbomsstep memory from 256Mi to 512Mi (requests = limits) to prevent OOM kills on large container images (GPU/ML, bootc, driver-toolkit).prepare-sbomsCPU limit (was 100m) to allow burst CPU and prevent throttling. CPU requests remain at 100m.v0.12.0Changed
CONTEXTUALIZE_SBOMis now set tofalseby default. The SBOMcontextualization received an overhaul, enabling the support for builder
content contextualization in SBOMs. To get involved in UAT, set this value
to
trueand report issuesto Mobster maintainers.
CONTEXTUALIZE_SBOMis set totrue, the built image will containnew labels,
io.buildah.stage.nameandio.buildah.stage.base.v0.11.2Fixed
include the
x86_64RPMs (and no other arches) from the prefetch SBOM,even for images built on other arches.
v0.11.1Version 0.11.1 only has relevant changes for the remote variants of this task.
v0.11.0Changed
a directory instead of scanning the the image as an OCI archive. This improves
the scanning time, disk usage and may improve memory usage. More details in
konflux-build-cli/docs/design/syft-image-scanning.md.
from the build VM instead of rsyncing the image back to the cluster first.
For large images, this significantly reduces the time spent on network transfers.
Removed
sbom-syft-generatestep, SBOM generation now happensin the
buildstep.pushstep, the push now happens in thebuildstep.the pipeline will fail with
invalid StepOverride. See the migration guidance below.Migration guidance
Buildah v0.11.0 comes with a migration script that will attempt to automatically
fix the step overrides in your PipelineRuns. In most cases, no manual action will
be needed. But there are cases that the script cannot handle:
script will never get a chance to run on the PipelineRun.
than the build itself and the remote VMs do not have sufficient resources.
If the migration script doesn't solve the problem, please follow the procedure below.
Manual procedure
If you have
sbom-syft-generateorpushstep overrides in the.spec.taskRunSpecssection in your PipelineRun, please remove them. In most cases, this should be all.
However, if you were previously requesting more resources for SBOM generation
than for the build step itself, there is a chance that the build will fail.
In this case, move the relevant overrides to the build step. The same technically
applies for the push step, but it's highly unlikely that pushing would require
more resources than the build.
For example:
spec: taskRunSpecs: - pipelineTaskName: build-container stepSpecs: - - name: sbom-syft-generate + - name: build computeResources: requests: memory: 16Gi limits: memory: 16GiThis will work for build steps that run in-cluster - single-platform builds
and typically also the amd64 builds in a multi-platform build setup.
For build steps that run on remote VMs, the overrides have no effect. In case
the build fails, please switch to a larger VM flavor (consult the documentation
of your particular Konflux deployment to see what's available).
For example:
spec: params: - name: build-platforms value: - localhost - - linux/arm64 + - linux-mxlarge/arm64v0.10.7Fixed
ignore files, same as buildah itself.
.containerignoreand.dockerignorefilesin the root of the context directory, but not the
<containerfile>.containerignoreand
<containerfile>.dockerignorefiles.v0.10.6Fixed
versions 0.10.4 and 0.10.5, when the upload-sbom step upgraded cosign to v3.
service URLs directly as CLI flags. The konflux-ci/konflux-ci deployment
of Konflux doesn't provide the config file in the TUF mirror. Fixed
by setting
--use-signing-config=falseto still allow direct URLs.Changed
Previously, if keyless signing was enabled, the task would sign the image
in the push step and then the SBOM in upload-sbom step. Now, it will sign both
in the upload-sbom step. This has no practical impact, but enables a larger
rework of the push step in the future.
v0.10.5Added
--rhsm-mount-ca-certsoption.v0.10Fixed
ignore files, same as buildah itself.
.containerignoreand.dockerignorefilesin the root of the context directory, but not the
<containerfile>.containerignoreand
<containerfile>.dockerignorefiles.v0.9Fixed
doesn't match the host architecture, preventing silent emulation builds.
konflux-ci/konflux-test-tasks (quay.io/konflux-ci/tekton-catalog/task-clair-scan)
v0.4.1Changed
Allign script and task version.
v0.3.2Changed
quay.io/konflux-ci/oras:latestimage withquay.io/konflux-ci/task-runner:1.5.0in the oci-attach-report step.Added
v0.3.1Added
konflux-ci/konflux-test-tasks (quay.io/konflux-ci/tekton-catalog/task-clamav-scan)
v0.3.4Added
clamd scans each file directly instead of recursing through nested archive
layers. This makes scanning of deeply nested archives faster. Extraction uses
bsdtar, which detects archives (zip/jar/war/ear/tarand tar.gz/tar.bz2/tar.xz) by content rather than extension — important because
the OCI
dir:payload is an extension-less blob — and unpacks themunconditionally with no size/count/depth limits. It is defensive: a corrupt or
partial archive is left in place for clamd rather than aborting the scan. No new
parameters are introduced. Requires the
clamav-dbimage to shipbsdtar(added in konflux-clamav).
v0.3.3Changed
model-weight files (
.safetensors,.gguf,.ggml,.pt,.pth,.onnx,.onnx_data/.onnx_data_*), usingorg.opencontainers.image.titleandolot.layer.content.inlayerpath. Any other annotated layer is skipped whenthe OCI descriptor
sizeis at least 2000MiB (slightly under ClamAV's ~2GiBMaxFileSize), regardless of extension. Layers without those annotations are
still listed with
--dry-runas in 0.3.2. The--dry-runskip uses thesame name list.
v0.3.2Added
(
.safetensors,.gguf,.ggml). Other layers are still extracted andscanned. If layer listing fails, the task falls back to extracting the
full image.
konflux-ci/container-build-catalog (quay.io/konflux-ci/tekton-catalog/task-prefetch-dependencies)
v0.10.3v0.10.2v0.10.1Changed
inputis empty, skip theprefetch-dependenciesstepv0.10.0v0.9.0Added
pip-index-urlparameter to passPIP_INDEX_URLto Hermeto for pip dependency prefetch.When set, this URL is used as a fallback package index when
requirements.txtdoes not specify--index-url.To use this parameter, add
pip-index-url(type: string, default:"") to your pipeline paramsand pass it to the prefetch-dependencies task.
v0.8.0v0.7.1v0.7.0.repofile for RPM dependencies is now namedhermeto.repoinstead ofcachi2.repov0.6.0v0.5.0v0.4.1Version 0.4.1 only changes the
-oci-tavariant of this task.Nothing changed in the base task (the one you're looking at).
v0.4.0v0.3.2enable-package-registry-proxyparameter to enable use of the package registry proxy when prefetching dependencies.SERVICE_CA_TRUST_CONFIG_MAP_NAMEandSERVICE_CA_TRUST_CONFIG_MAP_KEYparameters to mount the OpenShift service CA for verifying TLS connections to in-cluster services such as the package registry proxy.v0.3konflux-ci/konflux-sast-tasks (quay.io/konflux-ci/tekton-catalog/task-sast-snyk-check)
v0.5Added
konflux-ci/container-build-catalog (quay.io/konflux-ci/tekton-catalog/task-source-build)
v0.3.2Fixed
vendored as unpacked source trees rather than archives, so previously they
were missed by the archive-type filter and left out of the source image.
v0.3.1Changed
Configuration
📅 Schedule: (UTC)
* * * * 6)🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
To execute skipped test pipelines write comment
/ok-to-test.Documentation
Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.