STOR-3001: Add TLS jobs for storage components under cluster storage operator - #83039
STOR-3001: Add TLS jobs for storage components under cluster storage operator#83039dfajmon wants to merge 1 commit into
Conversation
|
@dfajmon: This pull request references STOR-3001 which is a valid jira issue. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository YAML (base), Central YAML (inherited) Review profile: CHILL Plan: Enterprise Run ID: ⛔ Files ignored due to path filters (4)
📒 Files selected for processing (4)
WalkthroughThe change adds optional TLS 1.3 scanner jobs for storage providers and VolumeDataSourceValidator across four cluster-storage-operator CI configurations. It also removes the vSphere problem-detector scanner. ChangesStorage operator TLS scanner coverage
Estimated code review effort: 3 (Moderate) | ~20 minutes Merge Risk: ⚪ Minimal · up to The PR adds TLS jobs for storage components, and no actionable merge-blocking risk remains after normal checks and review. Suggested reviewers: Important Pre-merge checks failedPlease resolve all errors before merging. Addressing warnings is optional. ❌ Failed checks (1 error)
✅ Passed checks (14 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In
`@ci-operator/config/openshift/cluster-storage-operator/openshift-cluster-storage-operator-main.yaml`:
- Around line 225-348: Run make update to generate and commit the required
zz_generated_metadata and Prow job outputs for the structural CI jobs in
ci-operator/config/openshift/cluster-storage-operator/openshift-cluster-storage-operator-main.yaml:225-348,
openshift-cluster-storage-operator-release-4.23.yaml:225-348,
openshift-cluster-storage-operator-release-5.0.yaml:226-349, and
openshift-cluster-storage-operator-release-5.1.yaml:225-348; do not hand-edit
generated files.
🪄 Autofix
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Repository YAML (base), Central YAML (inherited)
Review profile: CHILL
Plan: Enterprise
Run ID: 2810462d-da08-4646-b14f-d0d43505c688
⛔ Files ignored due to path filters (4)
ci-operator/jobs/openshift/cluster-storage-operator/openshift-cluster-storage-operator-main-presubmits.yamlis excluded by!ci-operator/jobs/**ci-operator/jobs/openshift/cluster-storage-operator/openshift-cluster-storage-operator-release-4.23-presubmits.yamlis excluded by!ci-operator/jobs/**ci-operator/jobs/openshift/cluster-storage-operator/openshift-cluster-storage-operator-release-5.0-presubmits.yamlis excluded by!ci-operator/jobs/**ci-operator/jobs/openshift/cluster-storage-operator/openshift-cluster-storage-operator-release-5.1-presubmits.yamlis excluded by!ci-operator/jobs/**
📒 Files selected for processing (4)
ci-operator/config/openshift/cluster-storage-operator/openshift-cluster-storage-operator-main.yamlci-operator/config/openshift/cluster-storage-operator/openshift-cluster-storage-operator-release-4.23.yamlci-operator/config/openshift/cluster-storage-operator/openshift-cluster-storage-operator-release-5.0.yamlci-operator/config/openshift/cluster-storage-operator/openshift-cluster-storage-operator-release-5.1.yaml
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: dfajmon The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
|
/pj-rehearse pull-ci-openshift-cluster-storage-operator-main-tls-scanner-aws-ebs pull-ci-openshift-cluster-storage-operator-main-tls-scanner-azure-disk-azure-file pull-ci-openshift-cluster-storage-operator-main-tls-scanner-gcp-pd pull-ci-openshift-cluster-storage-operator-main-tls-scanner-ibm-vpc-block pull-ci-openshift-cluster-storage-operator-main-tls-scanner-openstack-cinder-manila pull-ci-openshift-cluster-storage-operator-main-tls-scanner-powervs-block pull-ci-openshift-cluster-storage-operator-main-tls-scanner-volumedatasourcevalidator pull-ci-openshift-cluster-storage-operator-main-tls-scanner-vsphere |
|
@dfajmon: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
|
/pj-rehearse pull-ci-openshift-cluster-storage-operator-main-tls-scanner-openstack-cinder-manila pull-ci-openshift-cluster-storage-operator-main-tls-scanner-powervs-block pull-ci-openshift-cluster-storage-operator-main-tls-scanner-vsphere |
|
@dfajmon: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
|
/pj-rehearse pull-ci-openshift-cluster-storage-operator-main-tls-scanner-openstack-cinder-manila pull-ci-openshift-cluster-storage-operator-main-tls-scanner-powervs-block pull-ci-openshift-cluster-storage-operator-main-tls-scanner-vsphere |
|
@dfajmon: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
|
Note GitHub couldn't provide a complete incremental comparison for this pull request, so CodeRabbit is performing a full review instead. This review may take a little longer. |
|
Note GitHub couldn't provide a complete incremental comparison for this pull request, so CodeRabbit is performing a full review instead. This review may take a little longer. |
|
/pj-rehearse pull-ci-openshift-cluster-storage-operator-main-tls-scanner-powervs-block |
|
@dfajmon: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
|
@dfajmon: The following tests failed, say
Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
|
Note GitHub couldn't provide a complete incremental comparison for this pull request, so CodeRabbit is performing a full review instead. This review may take a little longer. |
|
Removed OpenStack and PowerVS because they are failing due to other problems Azure - success but fails on gather, tracker https://redhat.atlassian.net/browse/ART-21815 Everything else passed 👍 |
|
/pj-rehearse pull-ci-openshift-cluster-storage-operator-main-tls-scanner-vsphere |
|
@dfajmon: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
|
/pj-rehearse ack |
|
/verified by CI |
|
@dfajmon: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
|
@dfajmon: This PR has been marked as verified by DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
| @@ -236,6 +311,21 @@ tests: | |||
| test: | |||
| - ref: tls-13 | |||
| - ref: tls-scanner-run | |||
| workflow: ipi-aws | |||
| - always_run: false | |||
| as: tls-scanner-vsphere-problem-detector | |||
There was a problem hiding this comment.
Can it be part of tls-scanner-vsphere? It needs the same cluster, just scan another namespace. In other words, does SCAN_NAMESPACE allow multiple values?
Code says that --namespace-filter accepts comma-separated items
If so, then IMO all jobs should scan both openshift-cluster-storage-operator and openshift-cluster-csi-drivers
There was a problem hiding this comment.
good catch, lets try it
|
Note GitHub couldn't provide a complete incremental comparison for this pull request, so CodeRabbit is performing a full review instead. This review may take a little longer. |
|
@dfajmon: This pull request references STOR-3001 which is a valid jira issue. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
/pj-rehearse pull-ci-openshift-cluster-storage-operator-main-tls-scanner-vsphere |
|
@dfajmon: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
…operator AWS EBS AZURE DISK AZURE FILE GCP PD IBM VPC BLOCK CINDER MANILA POWERVS BLOCK VSPHERE VOLUME DATA SOURCE VALIDATOR
|
/pj-rehearse pull-ci-openshift-cluster-storage-operator-main-tls-scanner-vsphere |
|
@dfajmon: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
|
[REHEARSALNOTIFIER]
Interacting with pj-rehearseComment: Once you are satisfied with the results of the rehearsals, comment: |
Added TLS scanners for:
AWS EBS
AZURE FILE + DISK - success on port scanning but fails on gather, tracker redhat.atlassian.net/browse/ART-21815
GCP PD
IBM VPC BLOCK
VSPHERE - rehearse job was failing with 1 CPU and 1GiB, increasing the limit worked
VOLUME DATA SOURCE VALIDATOR
Not added because:
PowerVS block - failing on creation of cluster due to credentials, tracker issues.redhat.com/browse/DPTP-5139
OpenStack Cinder + Manila - failing on supposedly changing TLS, asked in OpenStack slack
Summary by CodeRabbit
This PR updates OpenShift CI configuration for the Cluster Storage Operator in releases 4.23, 5.0, 5.1, and
main.It adds optional TLS 1.3 scanner jobs for AWS EBS, Azure Disk and File, GCP PD, IBM VPC Block, vSphere, and
VolumeDataSourceValidator.Each job defines provider-specific workflows, storage namespaces, strict TLS settings, and
tls-13/tls-scanner-runtests. The vSphere jobs use increased resource allocations. The previous vSphere problem-detector job is removed.