Migrate sa-claude-openshift-ci jobs to openshift-ci-prow-agents GCP project - #82801
Conversation
…roject Update all step-registry refs that mount the sa-claude-openshift-ci secret to use the new GCP project (openshift-ci-prow-agents) and new token key (google-token) in that secret. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
WalkthroughCI step configurations now use the ChangesVertex AI credential configuration
Estimated code review effort: 2 (Simple) | ~10 minutes Possibly related PRs
Suggested reviewers: 🚥 Pre-merge checks | ✅ 15✅ Passed checks (15 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Hi @not-stbenjam. Thanks for your PR. I'm waiting for a openshift member to verify that this patch is reasonable to test. If it is, they should reply with Tip We noticed you've done this a few times! Consider joining the org to skip this step and gain Once the patch is verified, the new status will be reflected by the I understand the commands that are listed here. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
|
Should we include also |
|
It is using a different secret: I am working on getting access to that one so I can update it as well. It will be updated here or another PR |
…GCP project Update all step-registry refs that mount the hypershift-team-claude-prow secret to use the new GCP project (openshift-ci-prow-agents) and new token key (google-token) replacing the old claude-prow key. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
…laude-openshift-ci
These steps only consume the google token for Vertex AI authentication
and get their GitHub/Jira/Slack credentials from separate secrets.
Moving them to sa-claude-openshift-ci narrows the scope of the
hypershift-team-claude-prow secret to actual hypershift jobs and
the jira-agent chain steps that need its additional keys.
Steps moved: openshift-edge-tooling-ci-monitor, openshift-api-review-run,
openshift-api-eval-run, openshift-api-eval-setup,
openshift-agentic-trt-{review-responder,jira-solver,eval-solve,init},
jira-agent-setup, jira-agent-claude-helpers.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
|
@not-stbenjam: |
|
[REHEARSALNOTIFIER]
A total of 53 jobs have been affected by this change. The above listing is non-exhaustive and limited to 25 jobs. A full list of affected jobs can be found here Interacting with pj-rehearseComment: Once you are satisfied with the results of the rehearsals, comment: |
|
/ok-to-test Extending self-approval rights to the bot: /hold |
|
/pj-rehearse periodic-ci-openshift-release-main-payload-agent-analyze pull-ci-openshift-eng-edge-tooling-main-eval-all periodic-ci-openshift-hypershift-main-dependabot-triage pull-ci-openshift-eng-ai-helpers-main-eval-payload-analysis-minimal AI-generated. Review for accuracy. |
|
@redhat-chai-bot: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
|
@not-stbenjam: all tests passed! Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
✅ GCP Project Migration VerifiedAll 4 rehearsal jobs passed with the new
Zero authentication errors across all jobs. The migration from Tracked by: HPNEX-22 AI-generated. Review for accuracy. |
|
/hold cancel AI-generated. Review for accuracy. |
|
/pj-rehearse ack |
|
@stbenjam: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
…roject (openshift#82801) * Migrate sa-claude-openshift-ci jobs to openshift-ci-prow-agents GCP project Update all step-registry refs that mount the sa-claude-openshift-ci secret to use the new GCP project (openshift-ci-prow-agents) and new token key (google-token) in that secret. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * Migrate hypershift-team-claude-prow jobs to openshift-ci-prow-agents GCP project Update all step-registry refs that mount the hypershift-team-claude-prow secret to use the new GCP project (openshift-ci-prow-agents) and new token key (google-token) replacing the old claude-prow key. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * Move 10 non-hypershift steps from hypershift-team-claude-prow to sa-claude-openshift-ci These steps only consume the google token for Vertex AI authentication and get their GitHub/Jira/Slack credentials from separate secrets. Moving them to sa-claude-openshift-ci narrows the scope of the hypershift-team-claude-prow secret to actual hypershift jobs and the jira-agent chain steps that need its additional keys. Steps moved: openshift-edge-tooling-ci-monitor, openshift-api-review-run, openshift-api-eval-run, openshift-api-eval-setup, openshift-agentic-trt-{review-responder,jira-solver,eval-solve,init}, jira-agent-setup, jira-agent-claude-helpers. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Summary
Migrates all Claude AI step-registry refs from the old GCP project
itpc-gcp-hybrid-pe-eng-claudeto the new projectopenshift-ci-prow-agents, updates credential token keys, and moves non-hypershift steps that only need the google token tosa-claude-openshift-ci.Commit 1 — 5 refs using
sa-claude-openshift-cisecret:ANTHROPIC_VERTEX_PROJECT_ID:itpc-gcp-hybrid-pe-eng-claude→openshift-ci-prow-agentsGOOGLE_APPLICATION_CREDENTIALStoken key:token→google-tokenopenshift-claude-payload-agent,openshift-claude-agent-eval,openshift-edge-tooling-agent-eval,openshift-edge-tooling-lvms-ci-doctor,openshift-edge-tooling-microshift-ci-doctorCommit 2 — 15 refs using
hypershift-team-claude-prowsecret:ANTHROPIC_VERTEX_PROJECT_ID:itpc-gcp-hybrid-pe-eng-claude→openshift-ci-prow-agentsGOOGLE_APPLICATION_CREDENTIALStoken key:claude-prow→google-tokenCommit 3 — Move 10 non-hypershift steps from
hypershift-team-claude-prow→sa-claude-openshift-ci:These steps only consume the google token for Vertex AI auth; their GitHub/Jira/Slack credentials come from separate secrets. Verified by auditing each step's command script for references to the mount path.
openshift-edge-tooling-ci-monitorpr-creds,claude-payload-agent-jira-tokenopenshift-api-review-runapi-review-bot-github-appopenshift-api-eval-runopenshift-api-eval-setupopenshift-agentic-trt-review-respondertrt-agent-gh-appopenshift-agentic-trt-jira-solvertrt-agent-gh-appopenshift-agentic-trt-eval-solvetrt-agent-gh-appopenshift-agentic-trt-initjira-agent-setupjira-agent-claude-helpersSteps remaining on
hypershift-team-claude-prow(use additional keys likeapp-id,private-key,jira-pat,gangway-token, etc.):review-agent-process,jira-agent-process,jira-agent-github-app-auth,jira-agent-git-helpers,jira-agent-jira-helpers,jira-agent-slack-pr-notify,installer-review-agent-triggerhypershift/*stepsNot in scope
openshift-observability-qe-agent— uses a different project (itpc-gcp-hcm-pe-eng-claude) and different secret (dt-secrets)Test plan
sa-claude-openshift-ciruns successfully (e.g. payload-agent or api-review)hypershift-team-claude-prowruns successfully (e.g. hypershift-jira-agent)🤖 Generated with Claude Code
Summary by CodeRabbit
Migrates OpenShift CI Claude workflows to the
openshift-ci-prow-agentsGCP project.Updates Vertex AI project defaults and changes credential paths to use
google-token. Several non-Hypershift workflows also switch fromhypershift-team-claude-prowtosa-claude-openshift-ci.Affected workflows include Claude, OpenShift API, Edge Tooling, TRT, Jira, Review Agent, and HyperShift steps.