Skip to content

Conversation

sslocket
Copy link
Contributor

@sslocket sslocket commented Apr 16, 2025

@openshift-ci openshift-ci bot added the size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. label Apr 16, 2025
@ocpdocs-previewbot
Copy link

ocpdocs-previewbot commented Apr 16, 2025

🤖 Wed May 14 17:02:55 - Prow CI generated the docs preview:

https://92298--ocpdocs-pr.netlify.app/openshift-enterprise/latest/release_notes/ocp-4-19-release-notes.html

@sslocket
Copy link
Contributor Author

@jianping-shu PTAL when you can.

=== Pods deploy with readOnlyRootFilesystem set to true

From {product-title} {product-version}, pods deploy with the `readOnlyRootFilesystem` security context setting set to `true`. This enhances security by ensuring that the container root file system is mounted as read-only.

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

If this is the RN for CCO-385, I think it should be like "Cloud Credential Operator pods deploy with the..." more precisely.

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Agree.

@jianping-shu
Copy link

  • @huangmingxia to review too since she is the QE for this feature.

@huangmingxia
Copy link

The rest LGTM.

@sslocket
Copy link
Contributor Author

@jianping-shu and @huangmingxia I have updated with your suggestion. @jstuever I'd also like to get your signoff on this.

@jstuever
Copy link

/cc

@openshift-ci openshift-ci bot requested a review from jstuever May 12, 2025 19:09
@jstuever
Copy link

lgtm

@sslocket
Copy link
Contributor Author

/label peer-review-needed

@openshift-ci openshift-ci bot added the peer-review-needed Signifies that the peer review team needs to review this PR label May 14, 2025
@skopacz1 skopacz1 added peer-review-in-progress Signifies that the peer review team is reviewing this PR branch/enterprise-4.19 labels May 14, 2025
@skopacz1 skopacz1 added this to the Planned for 4.19 GA milestone May 14, 2025
Copy link
Contributor

@skopacz1 skopacz1 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Just one suggestion for your consideration, but otherwise LGTM. Nice work!

[id="ocp-4-19-notable-technical-changes-readonlyrootfilesystem_{context}"]
=== Pods deploy with readOnlyRootFilesystem set to true

From {product-title} {product-version}, Cloud Credential Operator pods deploy with the `readOnlyRootFilesystem` security context setting set to `true`. This enhances security by ensuring that the container root file system is mounted as read-only.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nothing you need to change, but just for your consideration - since this is a release note that will only appear in one version of the docs, for these notes you can also use language such as "With this release", because it will be implied that the change is occurring in this-version+.

Suggested change
From {product-title} {product-version}, Cloud Credential Operator pods deploy with the `readOnlyRootFilesystem` security context setting set to `true`. This enhances security by ensuring that the container root file system is mounted as read-only.
With this release, Cloud Credential Operator pods now deploy with the `readOnlyRootFilesystem` security context setting set to `true`. This enhances security by ensuring that the container root file system is mounted as read-only.

But it's up to you, feel free to choose whichever option sounds better to you.

@skopacz1 skopacz1 added peer-review-done Signifies that the peer review team has reviewed this PR and removed peer-review-in-progress Signifies that the peer review team is reviewing this PR peer-review-needed Signifies that the peer review team needs to review this PR labels May 14, 2025
@sslocket
Copy link
Contributor Author

Updated with peer edits.

Copy link

openshift-ci bot commented May 14, 2025

@sslocket: all tests passed!

Full PR test history. Your PR dashboard.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

@sslocket
Copy link
Contributor Author

/label merge-review-needed

@openshift-ci openshift-ci bot added the merge-review-needed Signifies that the merge review team needs to review this PR label May 14, 2025
@jeana-redhat jeana-redhat added the merge-review-in-progress Signifies that the merge review team is reviewing this PR label May 14, 2025
Copy link
Contributor

@jeana-redhat jeana-redhat left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM :shipit:

/remove-label merge-review-in-progress
/remove-label merge-review-needed

@openshift-ci openshift-ci bot removed merge-review-in-progress Signifies that the merge review team is reviewing this PR merge-review-needed Signifies that the merge review team needs to review this PR labels May 14, 2025
@jeana-redhat jeana-redhat merged commit 7295479 into openshift:enterprise-4.19 May 14, 2025
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
branch/enterprise-4.19 peer-review-done Signifies that the peer review team has reviewed this PR size/XS Denotes a PR that changes 0-9 lines, ignoring generated files.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

7 participants