Add TLS PQC compliance and TLS 1.3 adherence tests for OADP operator - #79196
Conversation
|
Important Review skippedReview was skipped due to path filters ⛔ Files ignored due to path filters (6)
CodeRabbit blocks several paths by default. You can override this behavior by explicitly including those paths in the path filters. For example, including ⚙️ Run configurationConfiguration used: Repository YAML (base), Central YAML (inherited) Review profile: CHILL Plan: Enterprise Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
WalkthroughAdds a ChangesTLS scanning CI additions
Estimated code review effort🎯 3 (Moderate) | ⏱️ ~20 minutes Suggested labels
🚥 Pre-merge checks | ✅ 12✅ Passed checks (12 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Tip 💬 Introducing Slack Agent: The best way for teams to turn conversations into code.Slack Agent is built on CodeRabbit's deep understanding of your code, so your team can collaborate across the entire SDLC without losing context.
Built for teams:
One agent for your entire SDLC. Right inside Slack. Comment |
|
/pj-rehearse |
|
@Joeavaikath: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
|
/pj-rehearse pull-ci-openshift-oadp-operator-oadp-1.6-4.22-tls-pqc-readiness |
|
@Joeavaikath: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
|
/pj-rehearse periodic-ci-openshift-oadp-operator-oadp-dev-4.22-tls13-adherence-periodic |
|
@Joeavaikath: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
|
/pj-rehearse |
|
@Joeavaikath: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
|
keep in mind #79152 in the middle of migrating away from optional-operators-ci-aws |
0c39701 to
9772e0c
Compare
|
/pj-rehearse |
|
@Joeavaikath: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
|
@Joeavaikath, Interacting with pj-rehearseComment: Once you are satisfied with the results of the rehearsals, comment: |
Adds tls-pqc-readiness and tls13-adherence tests to oadp-dev and oadp-1.6 branch CI on the 4.22 OCP variant. Each test installs OADP via OLM, configures the TLS 1.3 Modern profile, then runs the tls-scanner scoped to the openshift-adp namespace. Available as optional PR tests and weekly periodic jobs (Mondays 06:00 UTC). Signed-off-by: Joseph <jvaikath@redhat.com>
Signed-off-by: Joseph <jvaikath@redhat.com>
|
@Joeavaikath: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
|
/pj-rehearse pull-ci-openshift-oadp-operator-oadp-1.6-4.22-tls-pqc-readiness pull-ci-openshift-oadp-operator-oadp-1.6-4.22-tls13-adherence pull-ci-openshift-oadp-operator-oadp-1.6-4.22-ci-index pull-ci-openshift-oadp-operator-oadp-1.6-4.22-e2e-test-aws pull-ci-openshift-oadp-operator-oadp-1.6-4.22-e2e-test-cli-aws pull-ci-openshift-oadp-operator-oadp-1.6-4.22-e2e-test-hcp-aws pull-ci-openshift-oadp-operator-oadp-1.6-4.22-e2e-test-kubevirt-aws pull-ci-openshift-oadp-operator-oadp-1.6-4.22-images periodic-ci-openshift-oadp-operator-oadp-1.6-4.22-e2e-test-kubevirt-aws-periodic periodic-ci-openshift-oadp-operator-oadp-1.6-4.22-e2e-test-hcp-aws-periodic periodic-ci-openshift-oadp-operator-oadp-1.6-4.22-tls-pqc-readiness-periodic periodic-ci-openshift-oadp-operator-oadp-1.6-4.22-tls13-adherence-periodic periodic-ci-openshift-oadp-operator-oadp-1.6-4.22-e2e-test-aws-periodic periodic-ci-openshift-oadp-operator-oadp-1.6-4.22-e2e-test-cli-aws-periodic |
|
@kaovilai: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
|
/pj-rehearse periodic-ci-openshift-oadp-operator-oadp-dev-4.22-tls13-adherence-periodic periodic-ci-openshift-oadp-operator-oadp-1.6-4.22-e2e-test-aws-periodic periodic-ci-openshift-oadp-operator-oadp-1.6-4.22-e2e-test-cli-aws-periodic |
|
@Joeavaikath: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
|
/lgtm |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: Joeavaikath, kaovilai, shubham-pampattiwar, weshayutin The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
|
/pj-rehearse ack |
|
@kaovilai: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
…penshift#79196) * Add TLS PQC compliance and TLS 1.3 adherence tests for OADP operator Adds tls-pqc-readiness and tls13-adherence tests to oadp-dev and oadp-1.6 branch CI on the 4.22 OCP variant. Each test installs OADP via OLM, configures the TLS 1.3 Modern profile, then runs the tls-scanner scoped to the openshift-adp namespace. Available as optional PR tests and weekly periodic jobs (Mondays 06:00 UTC). Signed-off-by: Joseph <jvaikath@redhat.com> * CPU count to 2 Signed-off-by: Joseph <jvaikath@redhat.com> * Regenerate Prow jobs for oadp-dev and oadp-1.6 4.22 variants Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> Signed-off-by: Joseph <jvaikath@redhat.com> --------- Signed-off-by: Joseph <jvaikath@redhat.com> Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
…penshift#79196) * Add TLS PQC compliance and TLS 1.3 adherence tests for OADP operator Adds tls-pqc-readiness and tls13-adherence tests to oadp-dev and oadp-1.6 branch CI on the 4.22 OCP variant. Each test installs OADP via OLM, configures the TLS 1.3 Modern profile, then runs the tls-scanner scoped to the openshift-adp namespace. Available as optional PR tests and weekly periodic jobs (Mondays 06:00 UTC). Signed-off-by: Joseph <jvaikath@redhat.com> * CPU count to 2 Signed-off-by: Joseph <jvaikath@redhat.com> * Regenerate Prow jobs for oadp-dev and oadp-1.6 4.22 variants Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> Signed-off-by: Joseph <jvaikath@redhat.com> --------- Signed-off-by: Joseph <jvaikath@redhat.com> Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
…penshift#79196) * Add TLS PQC compliance and TLS 1.3 adherence tests for OADP operator Adds tls-pqc-readiness and tls13-adherence tests to oadp-dev and oadp-1.6 branch CI on the 4.22 OCP variant. Each test installs OADP via OLM, configures the TLS 1.3 Modern profile, then runs the tls-scanner scoped to the openshift-adp namespace. Available as optional PR tests and weekly periodic jobs (Mondays 06:00 UTC). Signed-off-by: Joseph <jvaikath@redhat.com> * CPU count to 2 Signed-off-by: Joseph <jvaikath@redhat.com> * Regenerate Prow jobs for oadp-dev and oadp-1.6 4.22 variants Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> Signed-off-by: Joseph <jvaikath@redhat.com> --------- Signed-off-by: Joseph <jvaikath@redhat.com> Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
…penshift#79196) * Add TLS PQC compliance and TLS 1.3 adherence tests for OADP operator Adds tls-pqc-readiness and tls13-adherence tests to oadp-dev and oadp-1.6 branch CI on the 4.22 OCP variant. Each test installs OADP via OLM, configures the TLS 1.3 Modern profile, then runs the tls-scanner scoped to the openshift-adp namespace. Available as optional PR tests and weekly periodic jobs (Mondays 06:00 UTC). Signed-off-by: Joseph <jvaikath@redhat.com> * CPU count to 2 Signed-off-by: Joseph <jvaikath@redhat.com> * Regenerate Prow jobs for oadp-dev and oadp-1.6 4.22 variants Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> Signed-off-by: Joseph <jvaikath@redhat.com> --------- Signed-off-by: Joseph <jvaikath@redhat.com> Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Add TLS compliance scanning to PTP operator CI per OCPSTRAT-2611, following the patterns from OADP (PR openshift#79196) and gcp-filestore (PR openshift#81917). For each branch (release-4.22, release-4.23), add: Presubmit (on-demand, optional, non-blocking): - tls-pqc-readiness: deploys PTP operator via OLM (ci-index), runs tls-13 step then tls-scanner-run with PQC check enabled - tls13-adherence: same flow with TLS 1.3 StrictAllComponents adherence policy Periodic (weekly Monday 6am UTC): - tls-pqc-readiness-periodic: same as presubmit PQC test - tls13-adherence-periodic: same as presubmit adherence test All tests: - Use optional-operators-ci-aws workflow (deploys PTP from ci-index) - Scoped to openshift-ptp namespace via SCAN_NAMESPACE - Use tls-scanner-tool from the tls-scanner namespace (official image) Branches 5.0/5.1/main are skipped because the PTP operator CSV is not yet available in the standard catalog for those versions. linuxptp-daemon is skipped because it has no operator bundle config. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> Signed-off-by: Jack Ding <jackding@gmail.com>
Add TLS compliance scanning to PTP operator CI per OCPSTRAT-2611, following the patterns from OADP (PR openshift#79196) and gcp-filestore (PR openshift#81917). For each branch (4.22, 4.23, 5.0, 5.1, main), add a combined tls-scan test that covers both TLS 1.3 adherence (StrictAllComponents) and PQC readiness in a single cluster deploy: Presubmit (on-demand): - tls-scan: always_run false, optional true. Deploys PTP operator via ci-index, runs tls-13 then tls-scanner-run with PQC check and TLS 1.3 StrictAllComponents adherence enabled. Periodic (weekly, staggered): - tls-scan-periodic: 4.22 Saturday, 4.23 Monday, 5.0 Tuesday, 5.1 Wednesday, main Thursday (all 6am UTC). All tests use optional-operators-ci-aws workflow, scoped to openshift-ptp namespace, SCANNER_CPU=2, tls-scanner-tool from the official tls-scanner namespace. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> Signed-off-by: Jack Ding <jackding@gmail.com>
Add TLS compliance scanning to PTP operator CI per OCPSTRAT-2611, following the patterns from OADP (PR openshift#79196) and gcp-filestore (PR openshift#81917). For each branch (4.22, 4.23, 5.0, 5.1, main), add a combined tls-scan test that covers both TLS 1.3 adherence (StrictAllComponents) and PQC readiness in a single cluster deploy: Presubmit (on-demand): - tls-scan: always_run false, optional true. Deploys PTP operator via ci-index, runs tls-13 then tls-scanner-run with PQC check and TLS 1.3 StrictAllComponents adherence enabled. Periodic (weekly Saturday, staggered 3 hours): - 4.22 at 00:00 UTC, 4.23 at 03:00, 5.0 at 06:00, 5.1 at 09:00, main at 12:00. All tests use optional-operators-ci-aws workflow, scoped to openshift-ptp namespace, SCANNER_CPU=2, tls-scanner-tool from the official tls-scanner namespace. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> Signed-off-by: Jack Ding <jackding@gmail.com>
Add TLS compliance scanning to PTP operator CI per OCPSTRAT-2611, following the patterns from OADP (PR openshift#79196) and gcp-filestore (PR openshift#81917). For each branch (4.22, 4.23, 5.0, 5.1, main), add a combined tls-scan test that covers both TLS 1.3 adherence (StrictAllComponents) and PQC readiness in a single cluster deploy: Presubmit (on-demand): - tls-scan: always_run false, optional true. Deploys PTP operator via ci-index, runs tls-13 then tls-scanner-run with PQC check and TLS 1.3 StrictAllComponents adherence enabled. Periodic (weekly Saturday, staggered 3 hours): - 4.22 at 00:00 UTC, 4.23 at 03:00, 5.0 at 06:00, 5.1 at 09:00, main at 12:00. All tests use optional-operators-ci-aws workflow, scoped to openshift-ptp namespace, SCANNER_CPU=2, tls-scanner-tool from the official tls-scanner namespace. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> Signed-off-by: Jack Ding <jackding@gmail.com>
Add TLS compliance scanning to PTP operator CI per OCPSTRAT-2611, following the patterns from OADP (PR openshift#79196) and gcp-filestore (PR openshift#81917). For each branch (4.22, 4.23, 5.0, 5.1, main), add a combined tls-scan test that covers both TLS 1.3 adherence (StrictAllComponents) and PQC readiness in a single cluster deploy: Presubmit (on-demand): - tls-scan: always_run false, optional true. Deploys PTP operator via ci-index, runs tls-13, waits for PTP operator to restart with the new TLS profile, then runs tls-scanner-run. The wait-ptp-tls-restart step is needed because the PTP operator's SecurityProfileWatcher detects the TLS profile change from the tls-13 step and self-terminates for OLM to restart it. The reconciler then re-renders the kube-rbac-proxy daemonset template with the new TLS min version and cipher suites. Without the wait, the scanner would scan endpoints still running with the old TLS configuration. Periodic (weekly Saturday, staggered 3 hours): - 4.22 at 00:00 UTC, 4.23 at 03:00, 5.0 at 06:00, 5.1 at 09:00, main at 12:00. All tests use optional-operators-ci-aws workflow, scoped to openshift-ptp namespace, SCANNER_CPU=2, tls-scanner-tool from the official tls-scanner namespace. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> Signed-off-by: Jack Ding <jackding@gmail.com>
Add TLS compliance scanning to PTP operator CI per OCPSTRAT-2611, following the patterns from OADP (PR openshift#79196) and gcp-filestore (PR openshift#81917). For each branch (4.22, 4.23, 5.0, 5.1, main), add a combined tls-scan test that covers both TLS 1.3 adherence (StrictAllComponents) and PQC readiness in a single cluster deploy: Presubmit (on-demand): - tls-scan: always_run false, optional true. Deploys PTP operator via ci-index, runs tls-13, waits for PTP operator to restart with the new TLS profile, then runs tls-scanner-run. The wait-ptp-tls-restart step is needed because the PTP operator's SecurityProfileWatcher detects the TLS profile change from the tls-13 step and self-terminates for OLM to restart it. The reconciler then re-renders the kube-rbac-proxy daemonset template with the new TLS min version and cipher suites. Without the wait, the scanner would scan endpoints still running with the old TLS configuration. Periodic (weekly Saturday, staggered 3 hours): - 4.22 at 00:00 UTC, 4.23 at 03:00, 5.0 at 06:00, 5.1 at 09:00, main at 12:00. All tests use optional-operators-ci-aws workflow, scoped to openshift-ptp namespace, SCANNER_CPU=2, tls-scanner-tool from the official tls-scanner namespace. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> Signed-off-by: Jack Ding <jackding@gmail.com>
Add TLS compliance scanning to PTP operator CI per OCPSTRAT-2611, following the patterns from OADP (PR openshift#79196) and gcp-filestore (PR openshift#81917). For each branch (4.22, 4.23, 5.0, 5.1, main), add a combined tls-scan test that covers both TLS 1.3 adherence (StrictAllComponents) and PQC readiness in a single cluster deploy: Presubmit (on-demand): - tls-scan: always_run false, optional true. Deploys PTP operator via ci-index, runs tls-13, waits for PTP operator to restart with the new TLS profile, then runs tls-scanner-run. The wait-ptp-tls-restart step is needed because the PTP operator's SecurityProfileWatcher detects the TLS profile change from the tls-13 step and self-terminates for OLM to restart it. The reconciler then re-renders the kube-rbac-proxy daemonset template with the new TLS min version and cipher suites. Without the wait, the scanner would scan endpoints still running with the old TLS configuration. Periodic (weekly Saturday, staggered 3 hours): - 4.22 at 00:00 UTC, 4.23 at 03:00, 5.0 at 06:00, 5.1 at 09:00, main at 12:00. All tests use optional-operators-ci-aws workflow, scoped to openshift-ptp namespace, SCANNER_CPU=2, tls-scanner-tool from the official tls-scanner namespace. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> Signed-off-by: Jack Ding <jackding@gmail.com>
Add TLS compliance scanning to PTP operator CI per OCPSTRAT-2611, following the patterns from OADP (PR openshift#79196) and gcp-filestore (PR openshift#81917). For each branch (4.22, 4.23, 5.0, 5.1, main), add a combined tls-scan test that covers both TLS 1.3 adherence (StrictAllComponents) and PQC readiness in a single cluster deploy: Presubmit (on-demand): - tls-scan: always_run false, optional true. Deploys PTP operator via ci-index, runs tls-13, waits for PTP operator to restart with the new TLS profile, then runs tls-scanner-run. The wait-ptp-tls-restart step is needed because the PTP operator's SecurityProfileWatcher detects the TLS profile change from the tls-13 step and self-terminates for OLM to restart it. The reconciler then re-renders the kube-rbac-proxy daemonset template with the new TLS min version and cipher suites. Without the wait, the scanner would scan endpoints still running with the old TLS configuration. Periodic (weekly Saturday, staggered 3 hours): - 4.22 at 00:00 UTC, 4.23 at 03:00, 5.0 at 06:00, 5.1 at 09:00, main at 12:00. All tests use optional-operators-ci-aws workflow, scoped to openshift-ptp namespace, SCANNER_CPU=2, tls-scanner-tool from the official tls-scanner namespace. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> Signed-off-by: Jack Ding <jackding@gmail.com>
Summary
oadp-devandoadp-1.6branches (4.22 OCP variant)optional-operators-ci-awsworkflow to provision a cluster and install OADP via OLM, then configures the TLS 1.3 Modern profile (tls-13step) and runs thetls-scanner-runstep scoped to theopenshift-adpnamespace/test 4.22-tls-pqc-readiness,/test 4.22-tls13-adherence) and weekly periodic jobs (Mondays 06:00 UTC)Test plan
/test 4.22-tls-pqc-readinesson the PR to validate the PQC readiness scan/test 4.22-tls13-adherenceon the PR to validate the TLS 1.3 adherence scanThis PR updates OpenShift CI configuration for the OADP operator (oadp-dev and oadp-1.6 branches, 4.22 variant) to add automated TLS compliance testing using the tls-scanner-tool.
What changed (practical impact)
Test plan / verification
Files affected
Notes and reviewer context