Skip to content

NO-ISSUE: [Manual] rebase-release-5.0.0-0.nightly-2026-08-03-043516_amd64-2026-08-03_arm64-2026-08-03 - #7147

Open
copejon wants to merge 8 commits into
openshift:mainfrom
copejon:rebase-no-issue-add-asset-service-ca-config-5.0.0-0.nightly-2026-08-03-043516_amd64-2026-08-03_arm64-2026-08-03
Open

NO-ISSUE: [Manual] rebase-release-5.0.0-0.nightly-2026-08-03-043516_amd64-2026-08-03_arm64-2026-08-03#7147
copejon wants to merge 8 commits into
openshift:mainfrom
copejon:rebase-no-issue-add-asset-service-ca-config-5.0.0-0.nightly-2026-08-03-043516_amd64-2026-08-03_arm64-2026-08-03

Conversation

@copejon

@copejon copejon commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

Summary by CodeRabbit

  • New Features

    • Added SELinux conflict status reporting through cluster configuration.
    • Added support for Volume Group Snapshot API version 1.
    • Improved workload placement rules for platform operators.
    • Added service CA controller configuration and network policies for operator catalog and bundle processing.
  • Updates

    • Refreshed platform components, container images, and nightly builds for ARM64 and x86_64.
    • Updated storage test components and CSI health checks.
    • Improved automated rebase and release maintenance workflows.

@openshift-ci-robot openshift-ci-robot added the jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. label Aug 4, 2026
@openshift-ci-robot

Copy link
Copy Markdown

@copejon: This pull request explicitly references no jira issue.

Details

In response to this:

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@coderabbitai

coderabbitai Bot commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: Repository YAML (base), Central YAML (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: 39711ee7-5eb1-4fc8-8600-23a6b13a2d6e

📥 Commits

Reviewing files that changed from the base of the PR and between bec2d1a and 6295fb1.

⛔ Files ignored due to path filters (7)
  • vendor/k8s.io/kubernetes/openshift-kube-apiserver/admission/autoscaling/managementcpusoverride/admission.go is excluded by !**/vendor/**, !vendor/**
  • vendor/k8s.io/kubernetes/openshift-kube-apiserver/admission/scheduler/nodeselectoradjuster/admission.go is excluded by !**/vendor/**, !vendor/**
  • vendor/k8s.io/kubernetes/pkg/controller/volume/selinuxwarning/cache/openshift_patch.go is excluded by !**/vendor/**, !vendor/**
  • vendor/k8s.io/kubernetes/pkg/controller/volume/selinuxwarning/openshift_upgrade_controller.go is excluded by !**/vendor/**, !vendor/**
  • vendor/k8s.io/kubernetes/pkg/controller/volume/selinuxwarning/selinux_warning_controller.go is excluded by !**/vendor/**, !vendor/**
  • vendor/k8s.io/kubernetes/pkg/features/openshift_features.go is excluded by !**/vendor/**, !vendor/**
  • vendor/k8s.io/kubernetes/plugin/pkg/auth/authorizer/rbac/bootstrappolicy/controller_policy.go is excluded by !**/vendor/**, !vendor/**
📒 Files selected for processing (55)
  • Makefile.kube_git.var
  • Makefile.version.aarch64.var
  • Makefile.version.x86_64.var
  • assets/components/multus/kustomization.aarch64.yaml
  • assets/components/multus/kustomization.x86_64.yaml
  • assets/components/multus/release-multus-aarch64.json
  • assets/components/multus/release-multus-x86_64.json
  • assets/components/service-ca/controller-config.yaml
  • assets/components/service-ca/deployment.yaml
  • assets/optional/operator-lifecycle-manager/0000_50_olm_01-networkpolicies.yaml
  • assets/optional/operator-lifecycle-manager/kustomization.aarch64.yaml
  • assets/optional/operator-lifecycle-manager/kustomization.x86_64.yaml
  • assets/optional/operator-lifecycle-manager/release-olm-aarch64.json
  • assets/optional/operator-lifecycle-manager/release-olm-x86_64.json
  • assets/release/release-aarch64.json
  • assets/release/release-x86_64.json
  • deps/github.com/openshift/kubernetes/REBASE.openshift.md
  • deps/github.com/openshift/kubernetes/openshift-hack/cmd/k8s-tests-ext/disabled_tests.go
  • deps/github.com/openshift/kubernetes/openshift-hack/rebase.sh
  • deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/autoscaling/managementcpusoverride/admission.go
  • deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/autoscaling/managementcpusoverride/admission_test.go
  • deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/scheduler/nodeselectoradjuster/admission.go
  • deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/scheduler/nodeselectoradjuster/admission_test.go
  • deps/github.com/openshift/kubernetes/pkg/controller/volume/selinuxwarning/cache/openshift_patch.go
  • deps/github.com/openshift/kubernetes/pkg/controller/volume/selinuxwarning/openshift_upgrade_controller.go
  • deps/github.com/openshift/kubernetes/pkg/controller/volume/selinuxwarning/openshift_upgrade_controller_test.go
  • deps/github.com/openshift/kubernetes/pkg/controller/volume/selinuxwarning/selinux_warning_controller.go
  • deps/github.com/openshift/kubernetes/pkg/features/openshift_features.go
  • deps/github.com/openshift/kubernetes/plugin/pkg/auth/authorizer/rbac/bootstrappolicy/controller_policy.go
  • deps/github.com/openshift/kubernetes/plugin/pkg/auth/authorizer/rbac/bootstrappolicy/testdata/controller-roles.yaml
  • deps/github.com/openshift/kubernetes/test/compatibility_lifecycle/reference/feature_list.md
  • deps/github.com/openshift/kubernetes/test/e2e/storage/testsuites/snapshot-metadata.go
  • deps/github.com/openshift/kubernetes/test/e2e/storage/testsuites/snapshottable.go
  • deps/github.com/openshift/kubernetes/test/e2e/storage/testsuites/snapshottable_stress.go
  • deps/github.com/openshift/kubernetes/test/e2e/storage/utils/volume_group_snapshot.go
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/groupsnapshot.storage.k8s.io_volumegroupsnapshotclasses.yaml
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/groupsnapshot.storage.k8s.io_volumegroupsnapshotcontents.yaml
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/groupsnapshot.storage.k8s.io_volumegroupsnapshots.yaml
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/volume-group-snapshots/csi-hostpath-plugin.yaml
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/volume-group-snapshots/run_group_snapshot_e2e.sh
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/gce-pd/controller_ss.yaml
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/gce-pd/node_ds.yaml
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/hostpath/hostpath/csi-hostpath-plugin.yaml
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-driver-attacher.yaml
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-driver-resizer.yaml
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-driver-snapshotter.yaml
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-driver.yaml
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-proxy.yaml
  • packaging/crio.conf.d/10-microshift_amd64.conf
  • packaging/crio.conf.d/10-microshift_arm64.conf
  • pkg/components/controllers.go
  • scripts/auto-rebase/assets.yaml
  • scripts/auto-rebase/changelog.txt
  • scripts/auto-rebase/commits.txt
  • scripts/auto-rebase/last_rebase.sh

Walkthrough

The pull request advances nightly release assets, updates rebase automation, changes admission rules, adds SELinux conflict reporting, and updates volume group snapshot resources and CSI test components.

Changes

Platform release and manifest updates

Layer / File(s) Summary
Nightly assets and platform manifests
Makefile.*, assets/components/*, assets/optional/operator-lifecycle-manager/*, assets/release/*, packaging/crio.conf.d/*, scripts/auto-rebase/*
Nightly versions, image digests, component commits, release metadata, service CA configuration, OLM policies, and CRI-O pause images are updated.

Kubernetes workflow and controller updates

Layer / File(s) Summary
Rebase automation
deps/github.com/openshift/kubernetes/REBASE.openshift.md, deps/github.com/openshift/kubernetes/openshift-hack/*
The workflow uses Jira identifiers, validates release branches and tags, runs containerized update steps, and can create pull requests through gh.
Admission rules
deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/*
CPU partitioning detection no longer inspects nodes. VPA, CRO, and CMA qualification now checks selectors, namespaces, labels, and tolerations.
SELinux conflict reporting
deps/github.com/openshift/kubernetes/pkg/controller/volume/selinuxwarning/*, deps/github.com/openshift/kubernetes/pkg/features/*, deps/github.com/openshift/kubernetes/plugin/pkg/auth/authorizer/rbac/*
A periodic controller reports conflict status in a ConfigMap. The feature gate and ConfigMap RBAC permissions are added.

Storage snapshot test updates

Layer / File(s) Summary
Volume group snapshot v1 resources
deps/github.com/openshift/kubernetes/test/e2e/storage/utils/*, deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/groupsnapshot.storage.k8s.io_*.yaml
Utilities and CRDs add or select v1 volume group snapshot resources with validation rules.
CSI test manifests and timeouts
deps/github.com/openshift/kubernetes/test/e2e/storage/**/*, deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/**/*
Storage tests use driver-specific timeouts. CSI images and snapshotter versions advance, and registrar health probes are added.

Estimated code review effort: 5 (Critical) | ~120 minutes

Suggested reviewers: eslutsky, pacevedom


Caution

Pre-merge checks failed

Please resolve all errors before merging. Addressing warnings is optional.

  • Ignore

❌ Failed checks (1 error, 1 warning)

Check name Status Explanation Resolution
Container-Privileges ❌ Error Changed CSI test manifests contain multiple privileged: true containers, and the changed GCE controller manifest contains hostNetwork: true. Remove these privileges where possible, or isolate them to required test fixtures and document an approved exception.
Docstring Coverage ⚠️ Warning Docstring coverage is 27.78% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (13 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly identifies this pull request as a manual rebase to the August 3, 2026 nightly amd64 and arm64 releases.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Stable And Deterministic Test Names ✅ Passed All changed Ginkgo titles are static literals and unchanged; added Go subtest names are also static, with no generated names, dates, nodes, namespaces, IPs, or UUIDs.
Test Structure And Quality ✅ Passed The PR changes only Ginkgo framework construction to use driver-specific custom timeouts; It blocks, cleanup, waits, and assertions are unchanged and match existing storage-suite patterns.
Microshift Test Compatibility ✅ Passed The PR adds or changes only standard Go unit tests; diff searches found no new Ginkgo It, Describe, Context, or When e2e tests.
Single Node Openshift (Sno) Test Compatibility ✅ Passed The PR adds no new Ginkgo e2e tests. Its three e2e changes only replace framework constructors with custom timeouts; other added tests are standard Go unit tests.
Topology-Aware Scheduling Compatibility ✅ Passed The new selector logic is registered only when IsStandalone() is true, so it skips HyperShift; control-plane selection excludes arbiter nodes, and manifests add no new topology constraints.
Ote Binary Stdout Contract ✅ Passed PR Go changes add no process-level stdout writes or suite setup; the OTE change only removes a disabled test, and existing klog defaults route logs to stderr.
Ipv6 And Disconnected Network Test Compatibility ✅ Passed The PR adds no new Ginkgo declarations; changed e2e files only update framework timeout constructors, and added unit tests contain no IPv4 or external-connectivity markers.
No-Weak-Crypto ✅ Passed The full origin/main..HEAD diff contains no MD5, SHA1, DES, RC4, Blowfish, or ECB usage, and changed Go code adds no cryptographic APIs or secret comparisons.
No-Sensitive-Data-In-Logs ✅ Passed PR logging is limited to SELinux conflict state/counts and fixed ConfigMap errors; rebase output contains only version, branch, and Jira identifiers, not sensitive data.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@openshift-ci
openshift-ci Bot requested review from eslutsky and pacevedom August 4, 2026 17:20
@openshift-ci

openshift-ci Bot commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: copejon

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci openshift-ci Bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Aug 4, 2026
@copejon

copejon commented Aug 4, 2026

Copy link
Copy Markdown
Contributor Author

/test

@copejon

copejon commented Aug 4, 2026

Copy link
Copy Markdown
Contributor Author

/test e2e-aws-tests-bootc-periodic-arm-el10
/test e2e-aws-tests-bootc-periodic-arm-el9
/test e2e-aws-tests-bootc-periodic-el10
/test e2e-aws-tests-bootc-periodic-el9
/test e2e-aws-tests-periodic
/test e2e-aws-tests-periodic-arm

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 7

🧹 Nitpick comments (1)
deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/autoscaling/managementcpusoverride/admission_test.go (1)

90-90: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Add an empty-node admission case.

The updated fixtures prove that node allocatable capacity no longer controls the result. They do not prove that CPUPartitioningAllNodes admits and mutates a Pod when the node list is empty. Add a nodes: nil case with the expected mutation.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In
`@deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/autoscaling/managementcpusoverride/admission_test.go`
at line 90, Add a test case in the admission test fixtures using nodes: nil,
with CPUPartitioningAllNodes enabled, and assert that the Pod is admitted and
receives the expected mutation. Keep the existing populated-node cases
unchanged.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In
`@assets/optional/operator-lifecycle-manager/0000_50_olm_01-networkpolicies.yaml`:
- Around line 129-151: Restrict the Egress rules in the bundle-unpack
NetworkPolicy selected by the bundle-unpack-ref and olm.managed match
expressions instead of allowing all destinations with an empty rule. Permit only
the registry, DNS, and Kubernetes API destinations and required ports; if
unrestricted access is genuinely required, document that justification in the
manifest.

In `@deps/github.com/openshift/kubernetes/openshift-hack/rebase.sh`:
- Line 131: Update the tag extraction command in rebase.sh to match the
top-level tag: definition at column zero instead of requiring two leading
spaces, ensuring the following Podman commands receive a non-empty release image
tag.
- Around line 96-100: Update rebase.sh to satisfy ShellCheck: remove or use the
unused go_mod_go_ver variable, brace variable expansions in the affected
commands, and replace sed-based character removal with Bash parameter
substitution. Apply these changes throughout the changed sections, including the
commands around the upstream tag check and lines covered by the review.

In
`@deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/scheduler/nodeselectoradjuster/admission.go`:
- Around line 118-138: Update requiresNodeSelectorAdjustment so both CRO and CMA
paths require a toleration covering the node-role.kubernetes.io/control-plane
NoSchedule taint before returning true. Apply the same control-plane toleration
check to CRO and replace CMA’s master-only check, while preserving the existing
label, namespace, and empty-node-selector conditions.

In `@deps/github.com/openshift/kubernetes/REBASE.openshift.md`:
- Around line 415-417: Update the fenced blocks in
deps/github.com/openshift/kubernetes/REBASE.openshift.md:415-417 and 569-571
with the bash language identifier, and mark the blocks at 425-434 and 440-448 as
text so all changed fences satisfy Markdownlint MD040.
- Around line 414-417: Update the tag-listing command in the upstream tag-fetch
instructions so each tag includes its creation timestamp before the awk filter
evaluates $2. Preserve the existing semantic-version filtering and 31-day
cutoff, ensuring recent matching tags are returned.

In `@scripts/auto-rebase/last_rebase.sh`:
- Around line 1-2: Update the script header to use the required /usr/bin/bash
shebang, add set -euo pipefail before the rebase.sh invocation, and remove the
existing -x shebang option while preserving the current command arguments.

---

Nitpick comments:
In
`@deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/autoscaling/managementcpusoverride/admission_test.go`:
- Line 90: Add a test case in the admission test fixtures using nodes: nil, with
CPUPartitioningAllNodes enabled, and assert that the Pod is admitted and
receives the expected mutation. Keep the existing populated-node cases
unchanged.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Central YAML (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: e575b9fd-1c6a-402b-b2fd-f0543ffd58fc

📥 Commits

Reviewing files that changed from the base of the PR and between bec2d1a and c2d654b.

⛔ Files ignored due to path filters (7)
  • vendor/k8s.io/kubernetes/openshift-kube-apiserver/admission/autoscaling/managementcpusoverride/admission.go is excluded by !**/vendor/**, !vendor/**
  • vendor/k8s.io/kubernetes/openshift-kube-apiserver/admission/scheduler/nodeselectoradjuster/admission.go is excluded by !**/vendor/**, !vendor/**
  • vendor/k8s.io/kubernetes/pkg/controller/volume/selinuxwarning/cache/openshift_patch.go is excluded by !**/vendor/**, !vendor/**
  • vendor/k8s.io/kubernetes/pkg/controller/volume/selinuxwarning/openshift_upgrade_controller.go is excluded by !**/vendor/**, !vendor/**
  • vendor/k8s.io/kubernetes/pkg/controller/volume/selinuxwarning/selinux_warning_controller.go is excluded by !**/vendor/**, !vendor/**
  • vendor/k8s.io/kubernetes/pkg/features/openshift_features.go is excluded by !**/vendor/**, !vendor/**
  • vendor/k8s.io/kubernetes/plugin/pkg/auth/authorizer/rbac/bootstrappolicy/controller_policy.go is excluded by !**/vendor/**, !vendor/**
📒 Files selected for processing (54)
  • Makefile.kube_git.var
  • Makefile.version.aarch64.var
  • Makefile.version.x86_64.var
  • assets/components/multus/kustomization.aarch64.yaml
  • assets/components/multus/kustomization.x86_64.yaml
  • assets/components/multus/release-multus-aarch64.json
  • assets/components/multus/release-multus-x86_64.json
  • assets/components/service-ca/controller-config.yaml
  • assets/components/service-ca/deployment.yaml
  • assets/optional/operator-lifecycle-manager/0000_50_olm_01-networkpolicies.yaml
  • assets/optional/operator-lifecycle-manager/kustomization.aarch64.yaml
  • assets/optional/operator-lifecycle-manager/kustomization.x86_64.yaml
  • assets/optional/operator-lifecycle-manager/release-olm-aarch64.json
  • assets/optional/operator-lifecycle-manager/release-olm-x86_64.json
  • assets/release/release-aarch64.json
  • assets/release/release-x86_64.json
  • deps/github.com/openshift/kubernetes/REBASE.openshift.md
  • deps/github.com/openshift/kubernetes/openshift-hack/cmd/k8s-tests-ext/disabled_tests.go
  • deps/github.com/openshift/kubernetes/openshift-hack/rebase.sh
  • deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/autoscaling/managementcpusoverride/admission.go
  • deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/autoscaling/managementcpusoverride/admission_test.go
  • deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/scheduler/nodeselectoradjuster/admission.go
  • deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/scheduler/nodeselectoradjuster/admission_test.go
  • deps/github.com/openshift/kubernetes/pkg/controller/volume/selinuxwarning/cache/openshift_patch.go
  • deps/github.com/openshift/kubernetes/pkg/controller/volume/selinuxwarning/openshift_upgrade_controller.go
  • deps/github.com/openshift/kubernetes/pkg/controller/volume/selinuxwarning/openshift_upgrade_controller_test.go
  • deps/github.com/openshift/kubernetes/pkg/controller/volume/selinuxwarning/selinux_warning_controller.go
  • deps/github.com/openshift/kubernetes/pkg/features/openshift_features.go
  • deps/github.com/openshift/kubernetes/plugin/pkg/auth/authorizer/rbac/bootstrappolicy/controller_policy.go
  • deps/github.com/openshift/kubernetes/plugin/pkg/auth/authorizer/rbac/bootstrappolicy/testdata/controller-roles.yaml
  • deps/github.com/openshift/kubernetes/test/compatibility_lifecycle/reference/feature_list.md
  • deps/github.com/openshift/kubernetes/test/e2e/storage/testsuites/snapshot-metadata.go
  • deps/github.com/openshift/kubernetes/test/e2e/storage/testsuites/snapshottable.go
  • deps/github.com/openshift/kubernetes/test/e2e/storage/testsuites/snapshottable_stress.go
  • deps/github.com/openshift/kubernetes/test/e2e/storage/utils/volume_group_snapshot.go
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/groupsnapshot.storage.k8s.io_volumegroupsnapshotclasses.yaml
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/groupsnapshot.storage.k8s.io_volumegroupsnapshotcontents.yaml
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/groupsnapshot.storage.k8s.io_volumegroupsnapshots.yaml
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/volume-group-snapshots/csi-hostpath-plugin.yaml
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/volume-group-snapshots/run_group_snapshot_e2e.sh
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/gce-pd/controller_ss.yaml
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/gce-pd/node_ds.yaml
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/hostpath/hostpath/csi-hostpath-plugin.yaml
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-driver-attacher.yaml
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-driver-resizer.yaml
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-driver-snapshotter.yaml
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-driver.yaml
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-proxy.yaml
  • packaging/crio.conf.d/10-microshift_amd64.conf
  • packaging/crio.conf.d/10-microshift_arm64.conf
  • scripts/auto-rebase/assets.yaml
  • scripts/auto-rebase/changelog.txt
  • scripts/auto-rebase/commits.txt
  • scripts/auto-rebase/last_rebase.sh
💤 Files with no reviewable changes (1)
  • deps/github.com/openshift/kubernetes/openshift-hack/cmd/k8s-tests-ext/disabled_tests.go

Comment thread deps/github.com/openshift/kubernetes/openshift-hack/rebase.sh
Comment thread deps/github.com/openshift/kubernetes/openshift-hack/rebase.sh
Comment thread deps/github.com/openshift/kubernetes/REBASE.openshift.md
Comment thread deps/github.com/openshift/kubernetes/REBASE.openshift.md
Comment thread scripts/auto-rebase/last_rebase.sh
@copejon

copejon commented Aug 4, 2026

Copy link
Copy Markdown
Contributor Author

/coderabbit help

@copejon
copejon force-pushed the rebase-no-issue-add-asset-service-ca-config-5.0.0-0.nightly-2026-08-03-043516_amd64-2026-08-03_arm64-2026-08-03 branch from c2d654b to a19f7c3 Compare August 5, 2026 00:02
@coderabbitai

coderabbitai Bot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Note

GitHub couldn't provide a complete incremental comparison for this pull request, so CodeRabbit is performing a full review instead. This review may take a little longer.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🧹 Nitpick comments (1)
deps/github.com/openshift/kubernetes/openshift-hack/rebase.sh (1)

127-129: 🔒 Security & Privacy | 🔵 Trivial | ⚡ Quick win

Security Misconfiguration (CWE-494): Download of Code Without Integrity Check

Reachability: External

Pin the Alpine image to an immutable digest.

deps/github.com/openshift/kubernetes/openshift-hack/rebase.sh:127 uses docker.io/library/alpine:latest with sed -i inside a container that mounts the checkout. If the mutable tag is retagged or compromised, unreviewed image content can alter Dockerfile.rhel or other mounted files. Pin an approved digest in the rebase source; do not edit deps/ directly.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@deps/github.com/openshift/kubernetes/openshift-hack/rebase.sh` around lines
127 - 129, Update the Alpine image reference in the rebase script’s podman
command to use the approved immutable digest instead of the mutable latest tag.
Make this change in the rebase source that generates the vendored deps content,
not directly under deps/, while preserving the existing mounted-workspace and
sed behavior.

Source: Path instructions

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@deps/github.com/openshift/kubernetes/openshift-hack/rebase.sh`:
- Around line 134-143: The rebase script’s post-command $? checks are
unreachable under set -e. Add set -euo pipefail and wrap each podman invocation
in the affected vendor-update blocks with if ! podman run ...; then, preserving
the existing failure messages and exits while removing the separate status
checks.
- Around line 99-101: Update the Kubernetes tag validation in the rebase source
to use an exact tag reference check, such as verifying refs/tags/${k8s_tag},
instead of git tag -l pattern matching. Preserve the existing error message and
exit behavior, and ensure the generated vendored script reflects the source
change rather than editing it directly.

In `@deps/github.com/openshift/kubernetes/REBASE.openshift.md`:
- Around line 410-411: Correct the procedure wording in the rebase source that
generates REBASE.openshift.md: update the sentence around the ship-help-bot
description to use “is an internal tool that has been given instructions,” and
revise the patch-release check to say “whether any patch releases have
occurred.” Do not edit the generated file under deps/ directly.

---

Nitpick comments:
In `@deps/github.com/openshift/kubernetes/openshift-hack/rebase.sh`:
- Around line 127-129: Update the Alpine image reference in the rebase script’s
podman command to use the approved immutable digest instead of the mutable
latest tag. Make this change in the rebase source that generates the vendored
deps content, not directly under deps/, while preserving the existing
mounted-workspace and sed behavior.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Central YAML (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: 4514a0d5-d405-417e-afd7-d39cf716156f

📥 Commits

Reviewing files that changed from the base of the PR and between bec2d1a and a19f7c3.

⛔ Files ignored due to path filters (7)
  • vendor/k8s.io/kubernetes/openshift-kube-apiserver/admission/autoscaling/managementcpusoverride/admission.go is excluded by !**/vendor/**, !vendor/**
  • vendor/k8s.io/kubernetes/openshift-kube-apiserver/admission/scheduler/nodeselectoradjuster/admission.go is excluded by !**/vendor/**, !vendor/**
  • vendor/k8s.io/kubernetes/pkg/controller/volume/selinuxwarning/cache/openshift_patch.go is excluded by !**/vendor/**, !vendor/**
  • vendor/k8s.io/kubernetes/pkg/controller/volume/selinuxwarning/openshift_upgrade_controller.go is excluded by !**/vendor/**, !vendor/**
  • vendor/k8s.io/kubernetes/pkg/controller/volume/selinuxwarning/selinux_warning_controller.go is excluded by !**/vendor/**, !vendor/**
  • vendor/k8s.io/kubernetes/pkg/features/openshift_features.go is excluded by !**/vendor/**, !vendor/**
  • vendor/k8s.io/kubernetes/plugin/pkg/auth/authorizer/rbac/bootstrappolicy/controller_policy.go is excluded by !**/vendor/**, !vendor/**
📒 Files selected for processing (54)
  • Makefile.kube_git.var
  • Makefile.version.aarch64.var
  • Makefile.version.x86_64.var
  • assets/components/multus/kustomization.aarch64.yaml
  • assets/components/multus/kustomization.x86_64.yaml
  • assets/components/multus/release-multus-aarch64.json
  • assets/components/multus/release-multus-x86_64.json
  • assets/components/service-ca/controller-config.yaml
  • assets/components/service-ca/deployment.yaml
  • assets/optional/operator-lifecycle-manager/0000_50_olm_01-networkpolicies.yaml
  • assets/optional/operator-lifecycle-manager/kustomization.aarch64.yaml
  • assets/optional/operator-lifecycle-manager/kustomization.x86_64.yaml
  • assets/optional/operator-lifecycle-manager/release-olm-aarch64.json
  • assets/optional/operator-lifecycle-manager/release-olm-x86_64.json
  • assets/release/release-aarch64.json
  • assets/release/release-x86_64.json
  • deps/github.com/openshift/kubernetes/REBASE.openshift.md
  • deps/github.com/openshift/kubernetes/openshift-hack/cmd/k8s-tests-ext/disabled_tests.go
  • deps/github.com/openshift/kubernetes/openshift-hack/rebase.sh
  • deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/autoscaling/managementcpusoverride/admission.go
  • deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/autoscaling/managementcpusoverride/admission_test.go
  • deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/scheduler/nodeselectoradjuster/admission.go
  • deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/scheduler/nodeselectoradjuster/admission_test.go
  • deps/github.com/openshift/kubernetes/pkg/controller/volume/selinuxwarning/cache/openshift_patch.go
  • deps/github.com/openshift/kubernetes/pkg/controller/volume/selinuxwarning/openshift_upgrade_controller.go
  • deps/github.com/openshift/kubernetes/pkg/controller/volume/selinuxwarning/openshift_upgrade_controller_test.go
  • deps/github.com/openshift/kubernetes/pkg/controller/volume/selinuxwarning/selinux_warning_controller.go
  • deps/github.com/openshift/kubernetes/pkg/features/openshift_features.go
  • deps/github.com/openshift/kubernetes/plugin/pkg/auth/authorizer/rbac/bootstrappolicy/controller_policy.go
  • deps/github.com/openshift/kubernetes/plugin/pkg/auth/authorizer/rbac/bootstrappolicy/testdata/controller-roles.yaml
  • deps/github.com/openshift/kubernetes/test/compatibility_lifecycle/reference/feature_list.md
  • deps/github.com/openshift/kubernetes/test/e2e/storage/testsuites/snapshot-metadata.go
  • deps/github.com/openshift/kubernetes/test/e2e/storage/testsuites/snapshottable.go
  • deps/github.com/openshift/kubernetes/test/e2e/storage/testsuites/snapshottable_stress.go
  • deps/github.com/openshift/kubernetes/test/e2e/storage/utils/volume_group_snapshot.go
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/groupsnapshot.storage.k8s.io_volumegroupsnapshotclasses.yaml
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/groupsnapshot.storage.k8s.io_volumegroupsnapshotcontents.yaml
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/groupsnapshot.storage.k8s.io_volumegroupsnapshots.yaml
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/volume-group-snapshots/csi-hostpath-plugin.yaml
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/volume-group-snapshots/run_group_snapshot_e2e.sh
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/gce-pd/controller_ss.yaml
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/gce-pd/node_ds.yaml
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/hostpath/hostpath/csi-hostpath-plugin.yaml
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-driver-attacher.yaml
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-driver-resizer.yaml
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-driver-snapshotter.yaml
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-driver.yaml
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-proxy.yaml
  • packaging/crio.conf.d/10-microshift_amd64.conf
  • packaging/crio.conf.d/10-microshift_arm64.conf
  • scripts/auto-rebase/assets.yaml
  • scripts/auto-rebase/changelog.txt
  • scripts/auto-rebase/commits.txt
  • scripts/auto-rebase/last_rebase.sh
💤 Files with no reviewable changes (1)
  • deps/github.com/openshift/kubernetes/openshift-hack/cmd/k8s-tests-ext/disabled_tests.go
🚧 Files skipped from review as they are similar to previous changes (50)
  • scripts/auto-rebase/assets.yaml
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-driver-resizer.yaml
  • deps/github.com/openshift/kubernetes/plugin/pkg/auth/authorizer/rbac/bootstrappolicy/testdata/controller-roles.yaml
  • deps/github.com/openshift/kubernetes/plugin/pkg/auth/authorizer/rbac/bootstrappolicy/controller_policy.go
  • deps/github.com/openshift/kubernetes/test/compatibility_lifecycle/reference/feature_list.md
  • assets/optional/operator-lifecycle-manager/0000_50_olm_01-networkpolicies.yaml
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-proxy.yaml
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-driver-attacher.yaml
  • scripts/auto-rebase/last_rebase.sh
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-driver-snapshotter.yaml
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-driver.yaml
  • Makefile.version.x86_64.var
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/gce-pd/controller_ss.yaml
  • scripts/auto-rebase/changelog.txt
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/gce-pd/node_ds.yaml
  • assets/optional/operator-lifecycle-manager/kustomization.x86_64.yaml
  • deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/scheduler/nodeselectoradjuster/admission_test.go
  • deps/github.com/openshift/kubernetes/pkg/controller/volume/selinuxwarning/selinux_warning_controller.go
  • deps/github.com/openshift/kubernetes/test/e2e/storage/testsuites/snapshottable_stress.go
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/volume-group-snapshots/run_group_snapshot_e2e.sh
  • deps/github.com/openshift/kubernetes/pkg/features/openshift_features.go
  • assets/components/service-ca/controller-config.yaml
  • packaging/crio.conf.d/10-microshift_amd64.conf
  • assets/components/service-ca/deployment.yaml
  • assets/optional/operator-lifecycle-manager/kustomization.aarch64.yaml
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/groupsnapshot.storage.k8s.io_volumegroupsnapshots.yaml
  • assets/optional/operator-lifecycle-manager/release-olm-x86_64.json
  • deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/scheduler/nodeselectoradjuster/admission.go
  • deps/github.com/openshift/kubernetes/test/e2e/storage/testsuites/snapshot-metadata.go
  • packaging/crio.conf.d/10-microshift_arm64.conf
  • deps/github.com/openshift/kubernetes/pkg/controller/volume/selinuxwarning/cache/openshift_patch.go
  • Makefile.version.aarch64.var
  • assets/components/multus/release-multus-x86_64.json
  • deps/github.com/openshift/kubernetes/test/e2e/storage/utils/volume_group_snapshot.go
  • assets/release/release-aarch64.json
  • assets/release/release-x86_64.json
  • assets/components/multus/kustomization.aarch64.yaml
  • assets/components/multus/kustomization.x86_64.yaml
  • assets/optional/operator-lifecycle-manager/release-olm-aarch64.json
  • assets/components/multus/release-multus-aarch64.json
  • scripts/auto-rebase/commits.txt
  • deps/github.com/openshift/kubernetes/pkg/controller/volume/selinuxwarning/openshift_upgrade_controller_test.go
  • deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/autoscaling/managementcpusoverride/admission.go
  • deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/autoscaling/managementcpusoverride/admission_test.go
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/groupsnapshot.storage.k8s.io_volumegroupsnapshotclasses.yaml
  • deps/github.com/openshift/kubernetes/pkg/controller/volume/selinuxwarning/openshift_upgrade_controller.go
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/hostpath/hostpath/csi-hostpath-plugin.yaml
  • deps/github.com/openshift/kubernetes/test/e2e/storage/testsuites/snapshottable.go
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/volume-group-snapshots/csi-hostpath-plugin.yaml
  • Makefile.kube_git.var

Comment on lines +99 to +101
if [ -z "$(git tag -l "$k8s_tag")" ]; then
echo "No such tag exists in upstream for: $k8s_tag"
exit 1

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/usr/bin/bash
set -euo pipefail

echo "== locate file =="
fd -a 'rebase\.sh$' . | sed 's#^\./##'

echo "== relevant file excerpt =="
if [ -f deps/github.com/openshift/kubernetes/openshift-hack/rebase.sh ]; then
  sed -n '1,180p' deps/github.com/openshift/kubernetes/openshift-hack/rebase.sh | cat -n
fi

echo "== k8s_tag usages =="
rg -n "k8s_tag|git tag -l|git show-ref|Branch|CHANGE|Dockerfile|dockerfile" deps/github.com/openshift/kubernetes/openshift-hack/rebase.sh || true

echo "== git check behavior for glob vs exact refs =="
tmp="$(mktemp -d)"
cd "$tmp"
git init -q
git config user.email test@example.com
git config user.name test
git commit --allow-empty -m init -q
git tag -a v1.35.0 -m msg
git tag -a v1.35.0-beta.1 -m msg
git tag -a v1.35.1 -m msg
git tag -a v1.35.* -m msg
for pattern in "$tmp/repo" "v1.35.*" "v1.35.3" "v1.35.0"; do
  printf 'pattern=%s git tag -l count=%s refs=%s\n' "$pattern" "$(git -C "$tmp/repo" tag -l "$pattern" | wc -l)" "$(git -C "$tmp/repo" tag -l "$pattern" | tr '\n' ' ')"
done
git -C "$tmp/repo" show-ref --verify --quiet "refs/tags/v1.35.*" && echo show-ref=v1.35.*=true || echo show-ref=v1.35.*=false
git -C "$tmp/repo" show-ref --verify --quiet "refs/tags/v1.35.3" && echo show-ref=v1.35.3=3=true || echo show-ref=v1.35.3=3=false
git -C "$tmp/repo" show-ref --verify --quiet "refs/tags/v1.35.0" && echo show-ref=v1.35.0=0=true || echo show-ref=v1.35.0=0=false
rm -rf "$tmp"

Repository: openshift/microshift

Length of output: 8394


🏁 Script executed:

#!/usr/bin/bash
set -euo pipefail

tmp="$(mktemp -d)"
cd "$tmp"
git init -q
cat >/tmp/test-tag.sh <<'EOF'
#!/usr/bin/env bash
set -euo pipefail
for pattern in v1.35.* v1.35.3 v1.35.0; do
  git tag -l "$pattern" >/tmp/tag-l-output
  printf '%s\n' "${pattern}: git tag -l output: [$(< /tmp/tag-l-output)] count=$(git tag -l "$pattern" | wc -l)"
done
git show-ref --verify --quiet "refs/tags/v1.35.*" && echo show-ref:v1.35.*=true || echo show-ref:v1.35.*=false
git show-ref --verify --quiet "refs/tags/v1.35.3" && echo show-ref:v1.35.3=3=true || echo show-ref:v1.35.3=3=false
git show-ref --verify --quiet "refs/tags/v1.35.0" && echo show-ref:v1.35.0=0=true || echo show-ref:v1.35.0=0=false
EOF
git config user.email test@example.com
git config user.name test
git commit --allow-empty -m init -q
git tag -a v1.35.0 -m msg
git tag -a v1.35.1 -m msg
chmod +x /tmp/test-tag.sh
/tmp/test-tag.sh
rm -rf "$tmp"

Repository: openshift/microshift

Length of output: 369


Require an exact Kubernetes tag match.

git tag -l "$k8s_tag" accepts glob patterns, so values like v1.35.* can pass the check without naming a single tag. That pattern later flows into git merge, the branch name, and the changelog link. Switch the validation to an exact ref check such as git show-ref --verify --quiet "refs/tags/${k8s_tag}".

As per deps/** instructions, carry this fix through the rebase source instead of editing the vendored script.

🧰 Tools
🪛 Shellcheck (0.11.0)

[style] 99-99: Prefer putting braces around variable references even when not strictly required.

(SC2250)


[style] 100-100: Prefer putting braces around variable references even when not strictly required.

(SC2250)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@deps/github.com/openshift/kubernetes/openshift-hack/rebase.sh` around lines
99 - 101, Update the Kubernetes tag validation in the rebase source to use an
exact tag reference check, such as verifying refs/tags/${k8s_tag}, instead of
git tag -l pattern matching. Preserve the existing error message and exit
behavior, and ensure the generated vendored script reflects the source change
rather than editing it directly.

Source: Path instructions

Comment on lines +134 to 143
podman run --rm -v "$(pwd):/go/k8s.io/kubernetes:Z" \
--workdir=/go/k8s.io/kubernetes \
"registry.ci.openshift.org/openshift/release:$tag" \
go mod tidy && hack/update-vendor.sh
/bin/bash -c "go mod tidy && hack/update-vendor.sh"

# shellcheck disable=SC2181
if [ $? -ne 0 ]; then
echo "updating the vendor folder failed, is any dependency missing?"
exit 1
fi

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win

Make the failure handlers reachable with set -e.

With the required set -e, a failed podman run exits before the following $? test. The custom error messages never run. Use if ! podman run ...; then ... fi for each invocation instead of checking $? afterward.

As per coding guidelines, shell scripts must use set -euo pipefail.

Also applies to: 145-154, 156-164

🧰 Tools
🪛 Shellcheck (0.11.0)

[style] 136-136: Prefer putting braces around variable references even when not strictly required.

(SC2250)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@deps/github.com/openshift/kubernetes/openshift-hack/rebase.sh` around lines
134 - 143, The rebase script’s post-command $? checks are unreachable under set
-e. Add set -euo pipefail and wrap each podman invocation in the affected
vendor-update blocks with if ! podman run ...; then, preserving the existing
failure messages and exits while removing the separate status checks.

Source: Coding guidelines

Comment on lines +410 to +411
[chai-bot](slack://app?team=T027F3GAJ&id=A0AJUKWDUR1&tab=messages) (ship-help-bot) is an internal tool has been given instructions to
periodically check for upstream patch releases and complete the rebase autonomously. The steps taken are outlined below:

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win

Fix the grammar in the new procedure text.

Line 410 should say is an internal tool that has been given instructions. Line 420 should say whether any patch releases have occurred.

As per path instructions, do not manually edit files under deps/; apply the wording change in the rebase source.

Also applies to: 420-421

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@deps/github.com/openshift/kubernetes/REBASE.openshift.md` around lines 410 -
411, Correct the procedure wording in the rebase source that generates
REBASE.openshift.md: update the sentence around the ship-help-bot description to
use “is an internal tool that has been given instructions,” and revise the
patch-release check to say “whether any patch releases have occurred.” Do not
edit the generated file under deps/ directly.

Source: Path instructions

@copejon

copejon commented Aug 5, 2026

Copy link
Copy Markdown
Contributor Author

/test e2e-aws-tests-bootc-periodic-arm-el9
/test e2e-aws-tests-bootc-periodic-el9
/test e2e-aws-tests-periodic
/test e2e-aws-tests-periodic-arm

@copejon
copejon force-pushed the rebase-no-issue-add-asset-service-ca-config-5.0.0-0.nightly-2026-08-03-043516_amd64-2026-08-03_arm64-2026-08-03 branch from a19f7c3 to 6295fb1 Compare August 5, 2026 02:49
@coderabbitai

coderabbitai Bot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Note

GitHub couldn't provide a complete incremental comparison for this pull request, so CodeRabbit is performing a full review instead. This review may take a little longer.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@deps/github.com/openshift/kubernetes/REBASE.openshift.md`:
- Line 579: The rebase documentation incorrectly states that a pull request is
always created. Update the corresponding wording in the rebase source, not under
deps/, to state that creation requires the gh CLI and to document the manual
fallback when gh is unavailable.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Central YAML (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: 39711ee7-5eb1-4fc8-8600-23a6b13a2d6e

📥 Commits

Reviewing files that changed from the base of the PR and between bec2d1a and 6295fb1.

⛔ Files ignored due to path filters (7)
  • vendor/k8s.io/kubernetes/openshift-kube-apiserver/admission/autoscaling/managementcpusoverride/admission.go is excluded by !**/vendor/**, !vendor/**
  • vendor/k8s.io/kubernetes/openshift-kube-apiserver/admission/scheduler/nodeselectoradjuster/admission.go is excluded by !**/vendor/**, !vendor/**
  • vendor/k8s.io/kubernetes/pkg/controller/volume/selinuxwarning/cache/openshift_patch.go is excluded by !**/vendor/**, !vendor/**
  • vendor/k8s.io/kubernetes/pkg/controller/volume/selinuxwarning/openshift_upgrade_controller.go is excluded by !**/vendor/**, !vendor/**
  • vendor/k8s.io/kubernetes/pkg/controller/volume/selinuxwarning/selinux_warning_controller.go is excluded by !**/vendor/**, !vendor/**
  • vendor/k8s.io/kubernetes/pkg/features/openshift_features.go is excluded by !**/vendor/**, !vendor/**
  • vendor/k8s.io/kubernetes/plugin/pkg/auth/authorizer/rbac/bootstrappolicy/controller_policy.go is excluded by !**/vendor/**, !vendor/**
📒 Files selected for processing (55)
  • Makefile.kube_git.var
  • Makefile.version.aarch64.var
  • Makefile.version.x86_64.var
  • assets/components/multus/kustomization.aarch64.yaml
  • assets/components/multus/kustomization.x86_64.yaml
  • assets/components/multus/release-multus-aarch64.json
  • assets/components/multus/release-multus-x86_64.json
  • assets/components/service-ca/controller-config.yaml
  • assets/components/service-ca/deployment.yaml
  • assets/optional/operator-lifecycle-manager/0000_50_olm_01-networkpolicies.yaml
  • assets/optional/operator-lifecycle-manager/kustomization.aarch64.yaml
  • assets/optional/operator-lifecycle-manager/kustomization.x86_64.yaml
  • assets/optional/operator-lifecycle-manager/release-olm-aarch64.json
  • assets/optional/operator-lifecycle-manager/release-olm-x86_64.json
  • assets/release/release-aarch64.json
  • assets/release/release-x86_64.json
  • deps/github.com/openshift/kubernetes/REBASE.openshift.md
  • deps/github.com/openshift/kubernetes/openshift-hack/cmd/k8s-tests-ext/disabled_tests.go
  • deps/github.com/openshift/kubernetes/openshift-hack/rebase.sh
  • deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/autoscaling/managementcpusoverride/admission.go
  • deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/autoscaling/managementcpusoverride/admission_test.go
  • deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/scheduler/nodeselectoradjuster/admission.go
  • deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/scheduler/nodeselectoradjuster/admission_test.go
  • deps/github.com/openshift/kubernetes/pkg/controller/volume/selinuxwarning/cache/openshift_patch.go
  • deps/github.com/openshift/kubernetes/pkg/controller/volume/selinuxwarning/openshift_upgrade_controller.go
  • deps/github.com/openshift/kubernetes/pkg/controller/volume/selinuxwarning/openshift_upgrade_controller_test.go
  • deps/github.com/openshift/kubernetes/pkg/controller/volume/selinuxwarning/selinux_warning_controller.go
  • deps/github.com/openshift/kubernetes/pkg/features/openshift_features.go
  • deps/github.com/openshift/kubernetes/plugin/pkg/auth/authorizer/rbac/bootstrappolicy/controller_policy.go
  • deps/github.com/openshift/kubernetes/plugin/pkg/auth/authorizer/rbac/bootstrappolicy/testdata/controller-roles.yaml
  • deps/github.com/openshift/kubernetes/test/compatibility_lifecycle/reference/feature_list.md
  • deps/github.com/openshift/kubernetes/test/e2e/storage/testsuites/snapshot-metadata.go
  • deps/github.com/openshift/kubernetes/test/e2e/storage/testsuites/snapshottable.go
  • deps/github.com/openshift/kubernetes/test/e2e/storage/testsuites/snapshottable_stress.go
  • deps/github.com/openshift/kubernetes/test/e2e/storage/utils/volume_group_snapshot.go
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/groupsnapshot.storage.k8s.io_volumegroupsnapshotclasses.yaml
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/groupsnapshot.storage.k8s.io_volumegroupsnapshotcontents.yaml
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/groupsnapshot.storage.k8s.io_volumegroupsnapshots.yaml
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/volume-group-snapshots/csi-hostpath-plugin.yaml
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/volume-group-snapshots/run_group_snapshot_e2e.sh
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/gce-pd/controller_ss.yaml
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/gce-pd/node_ds.yaml
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/hostpath/hostpath/csi-hostpath-plugin.yaml
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-driver-attacher.yaml
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-driver-resizer.yaml
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-driver-snapshotter.yaml
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-driver.yaml
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-proxy.yaml
  • packaging/crio.conf.d/10-microshift_amd64.conf
  • packaging/crio.conf.d/10-microshift_arm64.conf
  • pkg/components/controllers.go
  • scripts/auto-rebase/assets.yaml
  • scripts/auto-rebase/changelog.txt
  • scripts/auto-rebase/commits.txt
  • scripts/auto-rebase/last_rebase.sh
💤 Files with no reviewable changes (1)
  • deps/github.com/openshift/kubernetes/openshift-hack/cmd/k8s-tests-ext/disabled_tests.go
🚧 Files skipped from review as they are similar to previous changes (50)
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/gce-pd/node_ds.yaml
  • packaging/crio.conf.d/10-microshift_arm64.conf
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-driver-snapshotter.yaml
  • assets/optional/operator-lifecycle-manager/release-olm-x86_64.json
  • assets/components/service-ca/deployment.yaml
  • Makefile.version.aarch64.var
  • Makefile.version.x86_64.var
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-driver.yaml
  • assets/components/multus/kustomization.aarch64.yaml
  • assets/optional/operator-lifecycle-manager/release-olm-aarch64.json
  • deps/github.com/openshift/kubernetes/plugin/pkg/auth/authorizer/rbac/bootstrappolicy/controller_policy.go
  • deps/github.com/openshift/kubernetes/pkg/controller/volume/selinuxwarning/cache/openshift_patch.go
  • assets/optional/operator-lifecycle-manager/0000_50_olm_01-networkpolicies.yaml
  • deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/scheduler/nodeselectoradjuster/admission.go
  • assets/components/multus/kustomization.x86_64.yaml
  • deps/github.com/openshift/kubernetes/test/e2e/storage/testsuites/snapshottable_stress.go
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/volume-group-snapshots/run_group_snapshot_e2e.sh
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/gce-pd/controller_ss.yaml
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-driver-resizer.yaml
  • deps/github.com/openshift/kubernetes/pkg/controller/volume/selinuxwarning/selinux_warning_controller.go
  • assets/optional/operator-lifecycle-manager/kustomization.aarch64.yaml
  • assets/components/multus/release-multus-x86_64.json
  • deps/github.com/openshift/kubernetes/plugin/pkg/auth/authorizer/rbac/bootstrappolicy/testdata/controller-roles.yaml
  • assets/optional/operator-lifecycle-manager/kustomization.x86_64.yaml
  • scripts/auto-rebase/assets.yaml
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-driver-attacher.yaml
  • assets/components/service-ca/controller-config.yaml
  • deps/github.com/openshift/kubernetes/test/e2e/storage/testsuites/snapshot-metadata.go
  • packaging/crio.conf.d/10-microshift_amd64.conf
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/volume-group-snapshots/csi-hostpath-plugin.yaml
  • deps/github.com/openshift/kubernetes/test/e2e/storage/testsuites/snapshottable.go
  • scripts/auto-rebase/last_rebase.sh
  • deps/github.com/openshift/kubernetes/test/e2e/storage/utils/volume_group_snapshot.go
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-proxy.yaml
  • deps/github.com/openshift/kubernetes/pkg/features/openshift_features.go
  • assets/release/release-aarch64.json
  • deps/github.com/openshift/kubernetes/pkg/controller/volume/selinuxwarning/openshift_upgrade_controller_test.go
  • deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/autoscaling/managementcpusoverride/admission_test.go
  • deps/github.com/openshift/kubernetes/test/compatibility_lifecycle/reference/feature_list.md
  • Makefile.kube_git.var
  • scripts/auto-rebase/commits.txt
  • assets/release/release-x86_64.json
  • deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/scheduler/nodeselectoradjuster/admission_test.go
  • deps/github.com/openshift/kubernetes/pkg/controller/volume/selinuxwarning/openshift_upgrade_controller.go
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/groupsnapshot.storage.k8s.io_volumegroupsnapshots.yaml
  • assets/components/multus/release-multus-aarch64.json
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/groupsnapshot.storage.k8s.io_volumegroupsnapshotcontents.yaml
  • deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/autoscaling/managementcpusoverride/admission.go
  • deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/hostpath/hostpath/csi-hostpath-plugin.yaml
  • scripts/auto-rebase/changelog.txt

5. In case of conflicts, it will ask you to step into another shell to resolve those. The script will continue by committing the resolution with `UPSTREAM: <drop>`.
6. At the end, there will be a "rebase-$VERSION" branch pushed to your fork.
7. If you have `gh` installed and are logged in, it will attempt to create a PR for you by opening a web browser.
7. A pull request will be created with the title `$jira_id: Rebase $k8s_tag in $openshift_release` against the corresponding openshift branch.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win

Document the conditional pull-request creation.

deps/github.com/openshift/kubernetes/openshift-hack/rebase.sh runs gh pr create only when gh is installed. Line 579 says that a pull request will always be created. State the gh requirement and document the manual fallback.

As per path instructions, do not manually edit files under deps/; apply the wording change in the rebase source.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@deps/github.com/openshift/kubernetes/REBASE.openshift.md` at line 579, The
rebase documentation incorrectly states that a pull request is always created.
Update the corresponding wording in the rebase source, not under deps/, to state
that creation requires the gh CLI and to document the manual fallback when gh is
unavailable.

Source: Path instructions

@openshift-ci

openshift-ci Bot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

@copejon: The following tests failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test name Commit Details Required Rerun command
ci/prow/ocp-full-conformance-serial-rhel-eus 6295fb1 link true /test ocp-full-conformance-serial-rhel-eus
ci/prow/ocp-full-conformance-rhel-eus 6295fb1 link true /test ocp-full-conformance-rhel-eus
ci/prow/e2e-aws-tests-bootc-el10 6295fb1 link true /test e2e-aws-tests-bootc-el10
ci/prow/e2e-aws-tests-bootc-arm-el10 6295fb1 link true /test e2e-aws-tests-bootc-arm-el10
ci/prow/e2e-aws-tests-bootc-el9 6295fb1 link true /test e2e-aws-tests-bootc-el9
ci/prow/e2e-aws-tests-arm 6295fb1 link true /test e2e-aws-tests-arm
ci/prow/e2e-aws-tests 6295fb1 link true /test e2e-aws-tests
ci/prow/e2e-aws-tests-bootc-periodic-arm-el10 c2d654b link true /test e2e-aws-tests-bootc-periodic-arm-el10
ci/prow/e2e-aws-tests-bootc-periodic-el10 c2d654b link true /test e2e-aws-tests-bootc-periodic-el10
ci/prow/e2e-aws-tests-bootc-arm-el9 6295fb1 link true /test e2e-aws-tests-bootc-arm-el9

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

@copejon

copejon commented Aug 5, 2026

Copy link
Copy Markdown
Contributor Author

Includes fix for USHIFT-7434

/jira refresh

@copejon

copejon commented Aug 6, 2026

Copy link
Copy Markdown
Contributor Author

This is blocked until the network interface truncation bug is resolved in upstream ovn-k

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. jira/valid-reference Indicates that this PR references a valid Jira ticket of any type.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants