Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[release-4.14] OCPBUGS-31360: Remove egressip write permissions from ovn-kubernetes-node #2320

Merged
merged 1 commit into from Mar 28, 2024

Conversation

kyrtapz
Copy link
Contributor

@kyrtapz kyrtapz commented Mar 25, 2024

Backport of #2203

CONFLICT (content): Merge conflict in bindata/network/ovn-kubernetes/common/002-rbac-node.yaml

Signed-off-by: Patryk Diak pdiak@redhat.com
(cherry picked from commit 4019afe)

ovn-kubernetes-node does not write anything to egressip
and cloudprivateipconfigs. This commit removes the unnecessary
permissions.

CONFLICT (content): Merge conflict in bindata/network/ovn-kubernetes/common/002-rbac-node.yaml

Signed-off-by: Patryk Diak <pdiak@redhat.com>
(cherry picked from commit 4019afe)
Signed-off-by: Patryk Diak <pdiak@redhat.com>
@kyrtapz
Copy link
Contributor Author

kyrtapz commented Mar 25, 2024

/jira cherry-pick OCPBUGS-27199

@openshift-ci-robot
Copy link
Contributor

@kyrtapz: Jira Issue OCPBUGS-27199 has been cloned as Jira Issue OCPBUGS-31360. Will retitle bug to link to clone.
/retitle OCPBUGS-31360: Remove egressip write permissions from ovn-kubernetes-node

In response to this:

/jira cherry-pick OCPBUGS-27199

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-ci openshift-ci bot changed the title Remove egressip write permissions from ovn-kubernetes-node OCPBUGS-31360: Remove egressip write permissions from ovn-kubernetes-node Mar 25, 2024
@openshift-ci-robot openshift-ci-robot added jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. jira/valid-bug Indicates that a referenced Jira bug is valid for the branch this PR is targeting. labels Mar 25, 2024
@openshift-ci-robot
Copy link
Contributor

@kyrtapz: This pull request references Jira Issue OCPBUGS-31360, which is valid. The bug has been moved to the POST state.

6 validation(s) were run on this bug
  • bug is open, matching expected state (open)
  • bug target version (4.14.z) matches configured target version for branch (4.14.z)
  • bug is in the state New, which is one of the valid states (NEW, ASSIGNED, POST)
  • dependent bug Jira Issue OCPBUGS-27199 is in the state Closed (Done-Errata), which is one of the valid states (VERIFIED, RELEASE PENDING, CLOSED (ERRATA), CLOSED (CURRENT RELEASE), CLOSED (DONE), CLOSED (DONE-ERRATA))
  • dependent Jira Issue OCPBUGS-27199 targets the "4.15.0" version, which is one of the valid target versions: 4.15.0, 4.15.z
  • bug has dependents

Requesting review from QA contact:
/cc @anuragthehatter

The bug has been updated to refer to the pull request using the external bug tracker.

In response to this:

Backport of #2203

CONFLICT (content): Merge conflict in bindata/network/ovn-kubernetes/common/002-rbac-node.yaml

Signed-off-by: Patryk Diak pdiak@redhat.com
(cherry picked from commit 4019afe)

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-ci openshift-ci bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Mar 25, 2024
@kyrtapz kyrtapz changed the title OCPBUGS-31360: Remove egressip write permissions from ovn-kubernetes-node [release-4.14] OCPBUGS-31360: Remove egressip write permissions from ovn-kubernetes-node Mar 25, 2024
Copy link
Contributor

openshift-ci bot commented Mar 25, 2024

@kyrtapz: The following tests failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test name Commit Details Required Rerun command
ci/prow/e2e-openstack-kuryr b282389 link false /test e2e-openstack-kuryr
ci/prow/e2e-network-mtu-migration-ovn-ipv6 b282389 link false /test e2e-network-mtu-migration-ovn-ipv6
ci/prow/e2e-vsphere-ovn-dualstack-primaryv6 b282389 link false /test e2e-vsphere-ovn-dualstack-primaryv6
ci/prow/security b282389 link false /test security
ci/prow/4.14-upgrade-from-stable-4.13-e2e-gcp-ovn-upgrade b282389 link false /test 4.14-upgrade-from-stable-4.13-e2e-gcp-ovn-upgrade
ci/prow/e2e-vsphere-ovn-dualstack b282389 link false /test e2e-vsphere-ovn-dualstack

Full PR test history. Your PR dashboard.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. I understand the commands that are listed here.

@dougbtv
Copy link
Member

dougbtv commented Mar 26, 2024

/lgtm

@dougbtv
Copy link
Member

dougbtv commented Mar 26, 2024

/label backport-risk-assessed

@openshift-ci openshift-ci bot added the backport-risk-assessed Indicates a PR to a release branch has been evaluated and considered safe to accept. label Mar 26, 2024
@openshift-ci openshift-ci bot added the lgtm Indicates that a PR is ready to be merged. label Mar 26, 2024
Copy link
Contributor

openshift-ci bot commented Mar 26, 2024

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: dougbtv, kyrtapz

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@jechen0648
Copy link

/ocpbugs cc-qa

@jechen0648
Copy link

/label qe-approved

@openshift-ci openshift-ci bot added the qe-approved Signifies that QE has signed off on this PR label Mar 27, 2024
@openshift-ci-robot
Copy link
Contributor

@kyrtapz: This pull request references Jira Issue OCPBUGS-31360, which is valid.

6 validation(s) were run on this bug
  • bug is open, matching expected state (open)
  • bug target version (4.14.z) matches configured target version for branch (4.14.z)
  • bug is in the state POST, which is one of the valid states (NEW, ASSIGNED, POST)
  • dependent bug Jira Issue OCPBUGS-27199 is in the state Closed (Done-Errata), which is one of the valid states (VERIFIED, RELEASE PENDING, CLOSED (ERRATA), CLOSED (CURRENT RELEASE), CLOSED (DONE), CLOSED (DONE-ERRATA))
  • dependent Jira Issue OCPBUGS-27199 targets the "4.15.0" version, which is one of the valid target versions: 4.15.0, 4.15.z
  • bug has dependents

No GitHub users were found matching the public email listed for the QA contact in Jira (jechen@redhat.com), skipping review request.

The bug has been updated to refer to the pull request using the external bug tracker.

In response to this:

Backport of #2203

CONFLICT (content): Merge conflict in bindata/network/ovn-kubernetes/common/002-rbac-node.yaml

Signed-off-by: Patryk Diak pdiak@redhat.com
(cherry picked from commit 4019afe)

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@zhaozhanqi
Copy link

/label cherry-pick-approved

@openshift-ci openshift-ci bot added the cherry-pick-approved Indicates a cherry-pick PR into a release branch has been approved by the release branch manager. label Mar 28, 2024
@openshift-merge-bot openshift-merge-bot bot merged commit bdcd97c into openshift:release-4.14 Mar 28, 2024
34 of 40 checks passed
@openshift-ci-robot
Copy link
Contributor

@kyrtapz: Jira Issue OCPBUGS-31360: All pull requests linked via external trackers have merged:

Jira Issue OCPBUGS-31360 has been moved to the MODIFIED state.

In response to this:

Backport of #2203

CONFLICT (content): Merge conflict in bindata/network/ovn-kubernetes/common/002-rbac-node.yaml

Signed-off-by: Patryk Diak pdiak@redhat.com
(cherry picked from commit 4019afe)

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-bot
Copy link
Contributor

[ART PR BUILD NOTIFIER]

This PR has been included in build cluster-network-operator-container-v4.14.0-202403272210.p0.gbdcd97c.assembly.stream.el8 for distgit cluster-network-operator.
All builds following this will include this PR.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
approved Indicates a PR has been approved by an approver from all required OWNERS files. backport-risk-assessed Indicates a PR to a release branch has been evaluated and considered safe to accept. cherry-pick-approved Indicates a cherry-pick PR into a release branch has been approved by the release branch manager. jira/valid-bug Indicates that a referenced Jira bug is valid for the branch this PR is targeting. jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. lgtm Indicates that a PR is ready to be merged. qe-approved Signifies that QE has signed off on this PR
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet