Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bug 1895053: Verify builds can mount proxy trustedCA #25778

Merged

Conversation

adambkaplan
Copy link
Contributor

Verify builds can mount the cluster's custom PKI trust bundle if one is
set on the cluster proxy configuration. When mountProxyTrustedCA is
set to true, builds should add the container's trust bundle as a
read-only mount. The custom PKI should be readable during the build
execution, but should not be present in the resulting image.

@openshift-ci-robot openshift-ci-robot added do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. bugzilla/severity-urgent Referenced Bugzilla bug's severity is urgent for the branch this PR is targeting. bugzilla/invalid-bug Indicates that a referenced Bugzilla bug is invalid for the branch this PR is targeting. labels Jan 4, 2021
@openshift-ci-robot
Copy link

@adambkaplan: This pull request references Bugzilla bug 1895093, which is invalid:

  • expected the bug to be open, but it isn't
  • expected the bug to target the "4.7.0" release, but it targets "4.6.z" instead
  • expected the bug to be in one of the following states: NEW, ASSIGNED, ON_DEV, POST, POST, but it is CLOSED (ERRATA) instead

Comment /bugzilla refresh to re-evaluate validity if changes to the Bugzilla bug are made, or edit the title of this pull request to link to a different bug.

In response to this:

WIP - Bug 1895093: Verify builds can mount proxy trustedCA

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

@openshift-ci-robot openshift-ci-robot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Jan 4, 2021
@adambkaplan adambkaplan changed the title WIP - Bug 1895093: Verify builds can mount proxy trustedCA WIP - Bug 1895053: Verify builds can mount proxy trustedCA Jan 4, 2021
@openshift-ci-robot openshift-ci-robot added bugzilla/severity-high Referenced Bugzilla bug's severity is high for the branch this PR is targeting. bugzilla/valid-bug Indicates that a referenced Bugzilla bug is valid for the branch this PR is targeting. and removed bugzilla/severity-urgent Referenced Bugzilla bug's severity is urgent for the branch this PR is targeting. bugzilla/invalid-bug Indicates that a referenced Bugzilla bug is invalid for the branch this PR is targeting. labels Jan 4, 2021
@openshift-ci-robot
Copy link

@adambkaplan: This pull request references Bugzilla bug 1895053, which is valid. The bug has been updated to refer to the pull request using the external bug tracker.

3 validation(s) were run on this bug
  • bug is open, matching expected state (open)
  • bug target release (4.7.0) matches configured target release for branch (4.7.0)
  • bug is in the state POST, which is one of the valid states (NEW, ASSIGNED, ON_DEV, POST, POST)

In response to this:

WIP - Bug 1895053: Verify builds can mount proxy trustedCA

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

Verify builds can mount the cluster's custom PKI trust bundle if one is
set on the cluster proxy configuration. When `mountProxyTrustedCA` is
set to `true`, builds should add the container's trust bundle as a
read-only mount. The custom PKI should be readable during the build
execution, but should not be present in the resulting image.
@wewang58
Copy link
Contributor

wewang58 commented Apr 2, 2021

/bugzilla cc-qa

@openshift-ci-robot
Copy link

@wewang58: This pull request references Bugzilla bug 1895053, which is valid.

3 validation(s) were run on this bug
  • bug is open, matching expected state (open)
  • bug target release (4.8.0) matches configured target release for branch (4.8.0)
  • bug is in the state POST, which is one of the valid states (NEW, ASSIGNED, ON_DEV, POST, POST)

Requesting review from QA contact:
/cc @wewang58

In response to this:

/bugzilla cc-qa

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

@wewang58
Copy link
Contributor

wewang58 commented Apr 2, 2021

/lgtm

@openshift-ci-robot
Copy link

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: adambkaplan, wewang58

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci-robot openshift-ci-robot added the lgtm Indicates that a PR is ready to be merged. label Apr 2, 2021
@wewang58
Copy link
Contributor

wewang58 commented Apr 2, 2021

/label qe-approved

@openshift-ci-robot openshift-ci-robot added the qe-approved Signifies that QE has signed off on this PR label Apr 2, 2021
@adambkaplan adambkaplan changed the title WIP - Bug 1895053: Verify builds can mount proxy trustedCA Bug 1895053: Verify builds can mount proxy trustedCA Apr 6, 2021
@openshift-ci-robot openshift-ci-robot removed the do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. label Apr 6, 2021
@adambkaplan
Copy link
Contributor Author

/refresh

@adambkaplan
Copy link
Contributor Author

@bparees something seems to be up with this PR. It is waiting on the status of a job that has never run.

ci/prow/e2e-metal-ipi-ovn-ipv6

@bparees
Copy link
Contributor

bparees commented Apr 9, 2021

/override ci/prow/e2e-metal-ipi-ovn-ipv6

@openshift-ci-robot
Copy link

@bparees: /override requires a failed status context to operate on.
The following unknown contexts were given:

  • ci/prow/e2e-metal-ipi-ovn-ipv6

Only the following contexts were expected:

  • ci/prow/e2e-agnostic-cmd
  • ci/prow/e2e-aws-csi
  • ci/prow/e2e-aws-disruptive
  • ci/prow/e2e-aws-fips
  • ci/prow/e2e-aws-serial
  • ci/prow/e2e-gcp
  • ci/prow/e2e-gcp-builds
  • ci/prow/e2e-gcp-csi
  • ci/prow/e2e-gcp-disruptive
  • ci/prow/e2e-gcp-upgrade
  • ci/prow/images
  • ci/prow/verify
  • ci/prow/verify-deps
  • tide

In response to this:

/override ci/prow/e2e-metal-ipi-ovn-ipv6

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

@bparees
Copy link
Contributor

bparees commented Apr 9, 2021

@openshift/openshift-team-developer-productivity-test-platform can you take a look at why this PR is stuck? it wants a job result for a context that doesn't seem to exist.

we can manually merge it if need be, but i'd rather find a way to properly push it through.

@alvaroaleman
Copy link
Contributor

/test e2e-metal-ipi-ovn-ipv6

@bparees
Copy link
Contributor

bparees commented Apr 9, 2021

/test e2e-metal-ipi-ovn-ipv6

wait....that worked? why didn't the override work then?

@alvaroaleman
Copy link
Contributor

wait....that worked? why didn't the override work then?

Override only works with a status that exists and that status didn't exist

@adambkaplan
Copy link
Contributor Author

/retest

@adambkaplan
Copy link
Contributor Author

@bparees I've submitted a pr to make the metal-ipi-ovn-ipv6 test optional. openshift/release#17679

@adambkaplan
Copy link
Contributor Author

/retest

@bparees
Copy link
Contributor

bparees commented Apr 12, 2021

/override ci/prow/e2e-metal-ipi-ovn-ipv6

@openshift-ci-robot
Copy link

@bparees: Overrode contexts on behalf of bparees: ci/prow/e2e-metal-ipi-ovn-ipv6

In response to this:

/override ci/prow/e2e-metal-ipi-ovn-ipv6

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

@adambkaplan
Copy link
Contributor Author

/retest

@openshift-bot
Copy link
Contributor

/retest

Please review the full test history for this PR and help us cut down flakes.

14 similar comments
@openshift-bot
Copy link
Contributor

/retest

Please review the full test history for this PR and help us cut down flakes.

@openshift-bot
Copy link
Contributor

/retest

Please review the full test history for this PR and help us cut down flakes.

@openshift-bot
Copy link
Contributor

/retest

Please review the full test history for this PR and help us cut down flakes.

@openshift-bot
Copy link
Contributor

/retest

Please review the full test history for this PR and help us cut down flakes.

@openshift-bot
Copy link
Contributor

/retest

Please review the full test history for this PR and help us cut down flakes.

@openshift-bot
Copy link
Contributor

/retest

Please review the full test history for this PR and help us cut down flakes.

@openshift-bot
Copy link
Contributor

/retest

Please review the full test history for this PR and help us cut down flakes.

@openshift-bot
Copy link
Contributor

/retest

Please review the full test history for this PR and help us cut down flakes.

@openshift-bot
Copy link
Contributor

/retest

Please review the full test history for this PR and help us cut down flakes.

@openshift-bot
Copy link
Contributor

/retest

Please review the full test history for this PR and help us cut down flakes.

@openshift-bot
Copy link
Contributor

/retest

Please review the full test history for this PR and help us cut down flakes.

@openshift-bot
Copy link
Contributor

/retest

Please review the full test history for this PR and help us cut down flakes.

@openshift-bot
Copy link
Contributor

/retest

Please review the full test history for this PR and help us cut down flakes.

@openshift-bot
Copy link
Contributor

/retest

Please review the full test history for this PR and help us cut down flakes.

@openshift-merge-robot openshift-merge-robot merged commit 5887a3d into openshift:master Apr 18, 2021
@openshift-ci-robot
Copy link

@adambkaplan: All pull requests linked via external trackers have merged:

Bugzilla bug 1895053 has been moved to the MODIFIED state.

In response to this:

Bug 1895053: Verify builds can mount proxy trustedCA

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
approved Indicates a PR has been approved by an approver from all required OWNERS files. bugzilla/severity-high Referenced Bugzilla bug's severity is high for the branch this PR is targeting. bugzilla/valid-bug Indicates that a referenced Bugzilla bug is valid for the branch this PR is targeting. lgtm Indicates that a PR is ready to be merged. qe-approved Signifies that QE has signed off on this PR
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

7 participants