Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

OTA-925: clusters/hive: Grant cincinnati-ci-admins cluster-reader-extended #37544

Conversation

wking
Copy link
Member

@wking wking commented Mar 22, 2023

Hive is the host-cluster for the release-openshift-origin-installer-launch-hypershift-hosted job, using the hypershift-hosted workflow, and accessible from Cluster Bot via launch 4.13.0-rc.0, etc. Folks developing an operator so it works more closely with HyperShift's HostedClusterController can open parallel pull requests and have Cluster Bot launch a HostedCluster on Hive that mixes the pulls together with:

launch openshift/hypershift#nnn,openshift/cluster-version-operator#nnn

By granting cluster-reader-extended to the folks in the cincinnati-ci-admins Rover group, they can then access the Hive management cluster and check on HostedClusterController state and controller logs and such. Once work on OTA-924 has completed, this access may be revoked.

An alternative we considered was having Cincinnati admins install a Cluster-Bot bot cluster to serve as a management cluster, but there are a number of steps needed to set that up, and it seems easier for this epic's development to temporarily extend access to Hive's existing deployment.

@openshift-ci-robot openshift-ci-robot added the jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. label Mar 22, 2023
@openshift-ci-robot
Copy link
Contributor

openshift-ci-robot commented Mar 22, 2023

@wking: This pull request references OTA-925 which is a valid jira issue.

In response to this:

Hive is the host-cluster for the release-openshift-origin-installer-launch-hypershift-hosted job, using the hypershift-hosted workflow, and accessible from Cluster Bot via launch 4.13.0-rc.0, etc. Folks developing an operator so it works more closely with HyperShift's HostedClusterController can open parallel pull requests and have Cluster Bot launch a HostedCluster on Hive that mixes the pulls together with:

launch openshift/hypershift#nnn,openshift/cluster-version-operator#nnn

By granting cluster-reader-extended to the folks in the cincinnati-ci-admins Rover group, they can then access the Hive management cluster and check on HostedClusterController state and controller logs and such. Once work on OTA-924 has completed, this access may be revoked.

An alternative we considered was having Cincinnati admins install a Cluster-Bot bot cluster to serve as a management cluster, but there are a number of steps needed to set that up, and it seems easier for this epic's development to temporarily extend access to Hive's existing deployment.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

@openshift-ci-robot
Copy link
Contributor

@wking: no rehearsable tests are affected by this change

@openshift-ci-robot openshift-ci-robot added the rehearsals-ack Signifies that rehearsal jobs have been acknowledged label Mar 22, 2023
Hive is the host-cluster for the
release-openshift-origin-installer-launch-hypershift-hosted job, using
the s hypershift-hosted workflow, and accessible from Cluster Bot via
'launch 4.13.0-rc.0', etc.  Folks developing an operator so it works
more closely with HyperShift's HostedClusterController can open
parallel pull requests and have Cluster Bot launch a HostedCluster on
Hive that mixes the pulls together with:

  launch openshift/hypershift#nnn,openshift/cluster-version-operator#nnn

By granting cluster-reader-extended to the folks in the
cincinnati-ci-admins Rover group, they can then access the Hive
management cluster and check on HostedClusterController state and
controller logs and such.  Once work on [1] has completed, this access
may be revoked.

An alternative we considered was having Cincinnati admins install a
Cluster-Bot bot cluster to serve as a management cluster, but there
are a number of steps needed to set that up [2], and it seems easier
for this epic's development to temporarily extend access to Hive's
existing deployment.

[1]: https://issues.redhat.com/browse/OTA-924
[2]: https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.7/html/clusters/cluster_mce_overview#hosting-service-cluster-configure-aws
@wking wking force-pushed the grant-cincinnati-admins-hive-read-access branch from 6380cf8 to 8db57dc Compare March 22, 2023 00:20
@danilo-gemoli
Copy link
Contributor

/lgtm

@openshift-ci openshift-ci bot added the lgtm Indicates that a PR is ready to be merged. label Mar 24, 2023
@openshift-ci
Copy link
Contributor

openshift-ci bot commented Mar 24, 2023

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: danilo-gemoli, wking

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci openshift-ci bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Mar 24, 2023
@openshift-merge-robot openshift-merge-robot merged commit 985c855 into openshift:master Mar 24, 2023
@wking wking deleted the grant-cincinnati-admins-hive-read-access branch March 26, 2023 20:55
bmanzari pushed a commit to bmanzari/release that referenced this pull request Mar 30, 2023
…enshift#37544)

Hive is the host-cluster for the
release-openshift-origin-installer-launch-hypershift-hosted job, using
the s hypershift-hosted workflow, and accessible from Cluster Bot via
'launch 4.13.0-rc.0', etc.  Folks developing an operator so it works
more closely with HyperShift's HostedClusterController can open
parallel pull requests and have Cluster Bot launch a HostedCluster on
Hive that mixes the pulls together with:

  launch openshift/hypershift#nnn,openshift/cluster-version-operator#nnn

By granting cluster-reader-extended to the folks in the
cincinnati-ci-admins Rover group, they can then access the Hive
management cluster and check on HostedClusterController state and
controller logs and such.  Once work on [1] has completed, this access
may be revoked.

An alternative we considered was having Cincinnati admins install a
Cluster-Bot bot cluster to serve as a management cluster, but there
are a number of steps needed to set that up [2], and it seems easier
for this epic's development to temporarily extend access to Hive's
existing deployment.

[1]: https://issues.redhat.com/browse/OTA-924
[2]: https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.7/html/clusters/cluster_mce_overview#hosting-service-cluster-configure-aws
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
approved Indicates a PR has been approved by an approver from all required OWNERS files. jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. lgtm Indicates that a PR is ready to be merged. rehearsals-ack Signifies that rehearsal jobs have been acknowledged
Projects
None yet
4 participants