From 9d7f7b8c8b20f0fdb4400c7eaf0341b6d0b6142c Mon Sep 17 00:00:00 2001 From: "Jonathan H. Cope" Date: Tue, 4 Aug 2026 11:19:55 -0500 Subject: [PATCH 1/8] include the newly-added service-ca-controller configmap in assets --- scripts/auto-rebase/assets.yaml | 1 + 1 file changed, 1 insertion(+) diff --git a/scripts/auto-rebase/assets.yaml b/scripts/auto-rebase/assets.yaml index b4f34d3f6c..91869c5e05 100644 --- a/scripts/auto-rebase/assets.yaml +++ b/scripts/auto-rebase/assets.yaml @@ -93,6 +93,7 @@ assets: files: - file: clusterrole.yaml - file: clusterrolebinding.yaml + - file: controller-config.yaml - file: deployment.yaml - file: ns.yaml - file: role.yaml From a03639ffb8a4b64898d34e581ad263a1fbccebf6 Mon Sep 17 00:00:00 2001 From: "Jonathan H. Cope" Date: Tue, 4 Aug 2026 11:24:37 -0500 Subject: [PATCH 2/8] update last_rebase.sh --- scripts/auto-rebase/last_rebase.sh | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/scripts/auto-rebase/last_rebase.sh b/scripts/auto-rebase/last_rebase.sh index 258fd5c26e..02756c24b8 100755 --- a/scripts/auto-rebase/last_rebase.sh +++ b/scripts/auto-rebase/last_rebase.sh @@ -1,2 +1,2 @@ #!/bin/bash -x -./scripts/auto-rebase/rebase.sh to "registry.ci.openshift.org/ocp/release-5:5.0.0-0.nightly-2026-07-23-224236" "registry.ci.openshift.org/ocp-arm64/release-5-arm64:5.0.0-0.nightly-arm64-2026-07-27-004356" +./scripts/auto-rebase/rebase.sh to "registry.ci.openshift.org/ocp/release-5:5.0.0-0.nightly-2026-08-03-043516" "registry.ci.openshift.org/ocp-arm64/release-5-arm64:5.0.0-0.nightly-arm64-2026-08-03-232352" From 003acf6cb2a39a51fb3edd9967f6b18b48c3acf4 Mon Sep 17 00:00:00 2001 From: "Jonathan H. Cope" Date: Tue, 4 Aug 2026 11:24:38 -0500 Subject: [PATCH 3/8] update changelog --- scripts/auto-rebase/changelog.txt | 419 +++++++++++++++++++++++++++++- scripts/auto-rebase/commits.txt | 46 ++-- 2 files changed, 431 insertions(+), 34 deletions(-) diff --git a/scripts/auto-rebase/changelog.txt b/scripts/auto-rebase/changelog.txt index 00dd54e0f4..cbe91eccb7 100644 --- a/scripts/auto-rebase/changelog.txt +++ b/scripts/auto-rebase/changelog.txt @@ -1,7 +1,243 @@ -- oc image-arm64 994613040335f72809854babcb80b9d11a4e98d5 to a88e785e90aa96ac96da93359bacf3ea5c174733 +- api embedded-component 581cfdf7198613bd325c185eb3eac672670da633 to 05ea89db4588a2f443a2402764a73f3529ab116b + - 716553af 2026-07-27T11:26:57-04:00 Promote AWS DualStack to Default + - bc8cebd3 2026-07-27T13:14:00+02:00 MON-4616: add support for dmmultipath collector + - 217ca8ce 2026-07-27T12:59:02+02:00 Remove NewOLMPreflightPermissionChecks FeatureGate + - 5c06b67f 2026-07-24T07:53:19-04:00 Added vSphere failure domain to vcenter ratcheting tests + - db1ed9c2 2026-07-24T07:53:13-04:00 Added vSphere failure domain to vcenter check + - ffbad1d3 2026-07-24T12:14:11+01:00 Check all hypershift variants when the featuregate is not platform specific + - bb7402c2 2026-07-23T11:59:36-03:00 Promote Multi HAProxy Versions feature to default + - f4a969be 2026-07-23T14:02:51+02:00 make update + - 62822773 2026-07-23T14:02:45+02:00 operator/v1: rename KMSPluginHealthReport fields and remove compatibility marker + - 3199351b 2026-07-22T14:28:51+02:00 machineconfiguration/v1: add BGPVIPPeersJSON to ControllerConfigSpec + - b0927431 2026-07-22T14:28:49+02:00 config/v1: add BGPBasedVIPManagement feature gate and VIPManagement field + - 5bd0b76d 2026-07-21T09:05:02-05:00 NodeUID in status to detect replaced node with same name + - 91ec72c6 2026-07-21T15:06:54+03:00 Align with latest beta API of Vault + - a1e80c1b 2026-07-09T10:56:50+02:00 Promote OLMLifecycleAndCompatibility feature gate to Default + +- cluster-csi-snapshot-controller-operator embedded-component ef7a4c8b7f5c5e6cba4486dcc37f50521e7bc655 to 35ec0224eb0e5219d5eae012fb703223a6f3e1f7 + - ab3ec5d 2026-07-21T15:24:21+02:00 Bump all deps for 5.0.0 + - 2267501 2026-07-09T14:20:58+02:00 Remove v1beta2 group snapshot API + +- cluster-dns-operator embedded-component 4b8ae49940eefc50fa48da5179e735dd6ccd42d9 to c0ed09e329e9001629518604a58205e3fbe8284a + - 1d4d1e8 2026-07-28T18:22:09+02:00 NE-2743: gate operator metrics TLS on tlsAdherence policy + - b2ee3f5 2026-06-23T15:35:36-04:00 OCPBUGS-86009: Add regression test for scale-up without rollout + - ee254fc 2026-05-28T14:02:33-04:00 OCPBUGS-86009: Fix dns operator reporting Progressing=True on scale up + +- cluster-ingress-operator embedded-component b4daff58712de418c51d765a8686069a5f47e764 to 2461c5ceeb1fe16a4c8cfc1d0f82fb9555cbf1d0 + - af69f70f 2026-08-01T13:59:22Z Revert "Merge pull request #1513 from gcs278/listenerset-upgradeable" + - d89d9ac5 2026-07-31T17:00:00-03:00 Bump API to promote Multi HAProxy Versions feature + - 546c7b6f 2026-07-30T22:28:24-04:00 Move ListenerSet field index to ensureDependentControllers + - 7a481282 2026-07-30T22:28:24-04:00 Refactor to per-ListenerSet reconciliation with GaugeVec metric + - 901ca245 2026-07-30T22:28:24-04:00 Address review comments on listenerset-status controller + - 8105ed32 2026-07-30T22:28:24-04:00 Set Accepted=False on ListenerSets targeting OpenShift-managed Gateways + - e003edd7 2026-07-30T13:04:28-04:00 OCPBUGS-63219: Use status instead of old service for desired state during auto-delete + - 460e91cc 2026-07-30T13:04:28-04:00 OCPBUGS-63219: Improve NLB hairpin risk alert description + - 847c0fbf 2026-07-30T13:04:28-04:00 OCPBUGS-63219: Address code review feedback + - 8f942a63 2026-07-30T13:04:28-04:00 OCPBUGS-63219: Use isNewIngressController instead of !alreadyAdmitted for NLB protocol defaulting + - e5ca4df6 2026-07-30T13:04:28-04:00 OCPBUGS-63219: Add NLB hairpin risk alert for existing IngressControllers + - c0cf37d7 2026-07-30T13:04:28-04:00 OCPBUGS-63219: Add E2E tests for NLB protocol and LB type transition safety + - ed2c82e0 2026-07-30T09:22:59-04:00 Clean up ListenerSet ignored e2e test + - 5fc335e9 2026-07-30T08:32:37-04:00 Disable Istio CRL configmap creation + - 87efd8fc 2026-07-30T08:31:58-04:00 Bump GWAPI CRDs to v1.5.1 and Istio y-stream to 1.30 + - 89626b79 2026-07-29T19:35:49-04:00 OCPBUGS-63219: Support NLB protocol for AWS + - be35bbce 2026-07-29T23:40:36+02:00 NE-2818: Gate operator metrics TLS on tlsAdherence + - 81aa343f 2026-07-29T23:40:36+02:00 NE-2742: Replace custom metrics server with controller-runtime built-in metrics and authentication + - de37a611 2026-07-29T23:37:11+02:00 NE-2742: Apply cluster TLS security profile to operator metrics and canary endpoints + - 7304d3c0 2026-07-29T18:11:31-03:00 NE-2796: check if Gateway infrastructure labels are replicated to pods + - 79e04dfe 2026-07-29T18:11:31-03:00 NE-2796: Set APIServer TLS on sail-library options + - 0ff67422 2026-07-29T17:34:17-03:00 Rename network policy in TestContainerLoggingMinLength + - 2ce2bfc6 2026-07-29T20:24:59Z Replace deprecated io/ioutil usage + - e5b605c2 2026-07-27T21:42:36-04:00 GCP: Set Universe Domain + - c781a1be 2026-07-27T21:42:30-04:00 go.mod/vendor: bump google API packages for universe domain support + - bdc58f56 2026-07-27T14:58:03-04:00 Don't publish duplicate DNS records + - 2e5310f5 2026-07-27T14:40:04+01:00 OCPBUGS-85680: Re-fetch infraConfig on every periodic loop iteration + - be257092 2026-07-27T09:44:30+01:00 OCPBUGS-86841: Add BackendTLSPolicy to Gateway API e2e CRD test coverage + - 56b39bf7 2026-07-25T22:58:36Z OCPBUGS-99775: Update TestHTTPHeaderBufferSize for HAProxy 3.2 response code change + - c1d235c5 2026-07-24T17:18:46-03:00 Add upgradeable logic for HAProxy version + - a5c99e25 2026-06-23T14:17:24+01:00 OCPBUGS-90616: Add GRPCRoute to Gateway API e2e CRD test coverage + +- cluster-kube-apiserver-operator embedded-component ea8a9c50203113ca43db98ca925ab7fcdaff7d28 to 1f677d8a71a5d43c17505349fc7c41c97b04fe8d + - 1840df0 2026-07-29T09:32:03+03:00 Update openshift/* + - e4c2c4d 2026-07-28T10:10:34+02:00 encryptionstatusprovider/provider: creates the provider from the operator client. + - 49d6404 2026-07-28T10:10:30+02:00 bump (*) + - 00f607c 2026-07-27T10:29:28+02:00 NO-JIRA: gofmt encryption_kms_2.go + - 16f12e5 2026-07-27T09:05:10+02:00 NO-JIRA: address preflight e2e review feedback + - d5e6d37 2026-07-27T09:05:10+02:00 NO-JIRA: add KMS preflight deploy e2e to encryption-kms-2 + - 09ea0d5 2026-07-24T16:22:19+03:00 Update openshift/* + - 8dfb4f8 2026-07-24T05:27:15-04:00 pkg/operator: add KMS plugin sidecar revision readiness check + - 050afcf 2026-07-23T15:52:02+02:00 NO-JIRA: Automatic agentic rebase: Update library-go to d8f45c2 + - df010b0 2026-07-23T12:17:46+05:30 Add KMS key ID identifier + - a400ab1 2026-02-09T11:18:33+01:00 chore: add permissions on endpointslice to Prometheus Role and use serviceDiscoveryRole: EndpointSlice in ServiceMonitors + +- cluster-network-operator embedded-component 4f6fb6be829a2f6ad3e0df4ab85ecb00ef028343 to 1dcce833f8682c68273f1c47c911baeeb1a741f6 + - 471c79c 2026-07-29T19:07:13-04:00 Use TLS profile to render networking-console-plugin NGINX directives + - d654633 2026-07-29T19:07:13-04:00 Migrate check-endpoints to controller-runtime with TLS CLI args + - ad3dcdb 2026-07-24T10:20:52+02:00 vendor: bump github.com/openshift/api to latest master + - e538c9c 2026-07-23T15:10:03-04:00 Register PKI controller through AddToManager + - e7e9bf0 2026-07-23T14:57:58-04:00 Bound PKI informer cache sync with a timeout + - 60cedaf 2026-07-23T13:48:45-04:00 Use keyutil.ParsePrivateKeyPEM for private key decoding + - 262103b 2026-07-23T13:11:47-04:00 Enable configurable PKI for managed certificate rotation + - dfb8dd5 2026-07-23T15:40:27Z Revert "Merge pull request #2925 from OlivierCazade/day0" + - 17f08a7 2026-07-22T11:44:23-04:00 ovn-kubernetes: Move MNP from ConfigMap to CLI flags + - 9de83fa 2026-07-20T18:36:49+02:00 Fix 'kill: not a pid' error by checking PID file before use + - 40fd88f 2026-07-20T18:36:49+02:00 Remove /usr/libexec mount and avoid GLIBC compatibility issues + - a11c2e4 2026-07-20T18:36:49+02:00 Remove /usr/sbin host directory dependency from ovn-ipsec-host pod + - 3db668e 2026-07-20T18:36:39+02:00 Consume openvswitch-ipsec systemd service for OVN IPsec deployment + - 1117c8e 2026-07-17T11:37:37-04:00 Use TLS profile to render CLI args for network-check-source + - 6ad012f 2026-07-17T08:24:24-04:00 Use TLS profile to render CLI args for HyperShift ovnkube-control-plane + - 78a0e1a 2026-07-17T08:24:24-04:00 Use TLS profile to render CLI args for FRR components + - 6d2e543 2026-07-17T08:24:24-04:00 Use TLS profile to render CLI args for network-metrics kube-rbac-proxy + - 3e6eaf3 2026-07-17T08:24:24-04:00 Use TLS profile to render CLI args for kube-proxy's kube-rbac-proxy + - 46a985c 2026-07-17T08:24:24-04:00 Use TLS profile to render CLI args for kube-rbac-proxy in OVNK + - 6dd6533 2026-07-17T08:24:24-04:00 Use shared start-rbac-proxy function in ovnkube-control-plane + - c4a3db1 2026-07-17T08:24:24-04:00 Use TLS profile to render CLI args in the multus-admission-controller + - a211f70 2026-07-17T08:24:24-04:00 Use TLS profile to render CLI args in the node identity webhook + - c617131 2026-07-17T08:24:24-04:00 Add test utility functions for component rendering tests + - 42a8434 2026-07-17T08:24:24-04:00 Convert OpenSSL cipher names to IANA and filter TLS 1.3 ciphers + - 79bbb49 2026-07-15T09:43:13Z Bump frr-k8s MAX_FDS from 1024 to 65536 + - 9c178ed 2026-04-28T16:16:58+02:00 CORENET-6581: Add transport label to CUDN telemetry recording rule + +- csi-external-snapshotter embedded-component b5e4b73f9a761ff8a59f31b982a63e1cdbb76ed8 to a019d1a9d9e1d26ffd0b2e0d911733180fa608b2 + - b17468a 2026-07-29T11:10:15+02:00 UPSTREAM: 1460: Skip NotFound errors when deleting snapshot content objects + +- kubernetes embedded-component 98b35193b2ac7a23a673325f5e9b830ecd5ba406 to e63ab41237b34f2a457e76900f6162184420cf96 + - 5e858e982 2026-07-28T13:51:08-04:00 UPSTREAM: : Re-enable kubectl kuberc commands e2e tests + - 8d27ef98f 2026-07-27T11:14:23+02:00 UPSTREAM: 137936: csi: update CSI sidecar images in test manifests + - c8aa52947 2026-07-24T13:25:07+02:00 UPSTREAM: 138768: move VolumeGroupSnapshot to V1 + - 0f4503bbf 2026-07-22T11:54:16-04:00 UPSTREAM: : Update openshift-hack/rebase.sh, REBASE.openshift.md + - cc48cfba7 2026-07-20T21:23:37-06:00 UPSTREAM: : Add NodeSelectorAdjuster admission plugin for standalone clusters (part 2) + - 44a83e00e 2026-07-17T15:00:07+02:00 UPSTREAM: : hack/update-featuregates.sh + - 4da08ff19 2026-07-17T08:27:41+02:00 UPSTREAM: : Store SELinuxWarningController upgrade check as a ConfigMap + - de396e993 2026-07-16T15:20:30-06:00 UPSTREAM: 140377: e2e: storage snapshot tests should read custom timeouts from manifest + - 13ace3c70 2026-07-02T02:25:02-04:00 UPSTREAM: : upkeep cpu partitioning admission webhook + +- machine-config-operator embedded-component 067b924f19a64a209796d5be5a0a63665f53b1eb to 215097bef12ac57636668b4732c6ccf288a48a9f + - c6eba28b 2026-08-01T21:29:39Z Revert "Merge pull request #6303 from isabella-janssen/disrutive-suite-stabilization" + - eccb06f8 2026-07-31T08:34:43-04:00 tests: make ImageModeStatusReporting MCP count test more resilient on SNO + - 44cb8f47 2026-07-31T10:13:32Z OCPBUGS-92811: test MCC proxy. Refactor TC 52373 proxy test. + - 6a9d4739 2026-07-30T18:21:21+05:30 Fix TC 43278 failing when release payload has no MCO commit info + - 131f0458 2026-07-30T17:12:38+05:30 Migrate 17 OCB test cases from openshift-tests-private + - 92a24cee 2026-07-30T14:30:20+05:30 Fix setArchitectureAndCheckStatus corrupting multi-label annotations + - 7ddac2a2 2026-07-29T15:54:20+02:00 MCO-2244: Update MCO dependencies to Kubernetes 1.36 + - 58a9a52e 2026-07-29T10:59:57+02:00 MCO-2468: Cache backed OSImageStreams for PIS + - 6b9f78ba 2026-07-28T07:48:30+02:00 NO-ISSUE: Fix incorrect OSImageStreams log + - a5384d66 2026-07-27T19:53:32+02:00 Removed no more useful SkipTestIfWorkersCannotBeScaled(oc) function for scale-up test + - ce872407 2026-07-27T19:32:17+02:00 MCO-2470: Disable scale-up test support for AWS and vSphere + - 7ee7027a 2026-07-27T16:55:35+02:00 NO-ISSUE: Use context instead of discrete signal + - c316b995 2026-07-27T14:56:17+03:00 Add --collect back to systemd-run to prevent stale units + - 0cd0458e 2026-07-27T14:26:01+03:00 Bug: fix fencing_validator ocdebug fence dispatch race condition + - 08f5b4e1 2026-07-24T11:30:29Z Thread context through syncHandler instead of storing it in Controller + - c4fb4794 2026-07-24T11:30:29Z Propagate context to InspectStreamClass for shutdown cancellation + - 92bdeffb 2026-07-24T11:30:29Z Add unit tests for validateNoRuncOnRHEL10FromOSImageURL + - 3c6b0fcd 2026-07-24T11:30:29Z Inline runcBlockedError into its callers + - a0e361e2 2026-07-24T11:30:29Z Move validateNoRuncOnRHEL10FromOSImageStream out of generateRenderedMachineConfig + - cd031001 2026-07-24T11:30:29Z Decouple validateNoRuncOnRHEL10FromOSImageURL from Controller + - 46c64391 2026-07-24T11:30:29Z Rename runc validation functions for clarity + - ec249e54 2026-07-24T11:30:29Z TBD + - b5fe45d5 2026-07-24T08:59:10Z NO-ISSUE: extended tests, restore initial maxUnavailable when modified + - 00d8a31e 2026-07-24T09:55:57+02:00 vendor: bump github.com/openshift/api to latest master + - bd1f9660 2026-07-23T16:08:26+05:30 Add TC 88940: Apply password only if changes exist + - 173915e5 2026-07-23T09:54:18Z NO-ISSUE: add AWS marketplace polarion ID test + - 75e3bbca 2026-07-22T14:46:03-04:00 Surface MOSB build status on paused MCPs, added e2e tests to test the behavior, and refined non-paused pool reporting + - 9278288f 2026-07-22T15:13:16+02:00 CNTRLPLANE-3840: Remove ExternalTopologyMode guard from OSImageStream bootstrap + - 54982a74 2026-07-21T19:36:43+05:30 Add unit tests for osImageStream label skip logic in boot image controller + - 135e4398 2026-07-19T19:45:23-04:00 Add control-plane NoSchedule taint support alongside master taint + - b68a7440 2026-07-17T08:10:43Z MCO-2184: Adapt scale extended tests to support osstreams + - 7788a2e5 2026-07-09T22:27:07-04:00 OCPBUGS-98316: Fix SHA idempotency test in nmstate-configuration.sh + - a50480ed 2026-06-05T13:42:39-04:00 machine-config-daemon-firstboot: disable ostree fsync during bootstrap + +- operator-framework-olm embedded-component 56b3931de4636f7e0d212001f2074b9dddb45a8f to 76870171f4c192e96d450bcfb71dca508a264999 + - 2050b037 2026-07-31T00:04:49Z :seedling: Bump github.com/prometheus/client_golang (#3882) + - 05e37129 2026-07-31T00:03:59Z :seedling: Bump the k8s-dependencies group with 8 updates (#3879) + - 9ac5c409 2026-07-31T00:03:36Z :seedling: Bump github.com/prometheus/common from 0.70.0 to 0.70.1 (#3880) + - abeffeb5 2026-07-31T00:03:18Z :seedling: Bump go.yaml.in/yaml/v3 from 3.0.4 to 3.0.5 (#3881) + - c6c6b0cf 2026-07-24T00:21:36Z Bump actions/setup-go from 6 to 7 (#506) + - 1f40a85d 2026-07-24T00:20:39Z Bump github.com/google/cel-go from 0.29.1 to 0.29.2 (#505) + - 3c189066 2026-07-24T00:20:22Z Bump github.com/google/cel-go from 0.28.1 to 0.29.1 (#504) + - 113c62ae 2026-07-24T00:20:04Z Bump golang.org/x/net from 0.54.0 to 0.55.0 (#503) + - 0e5f254d 2026-07-24T00:19:43Z Bump actions/cache from 5 to 6 (#502) + - 8e3576e0 2026-07-24T00:19:26Z pkg/manifests: fix dropped walk errors (#495) + - 59bced99 2026-07-24T00:19:10Z Bump actions/checkout from 6 to 7 (#501) + - e3d3ba94 2026-07-24T00:18:53Z Bump the k8s-dependencies group with 4 updates (#500) + - 136d055c 2026-07-24T00:18:37Z bump api to 0.45.0 (#2040) + - 46661c32 2026-07-24T00:18:19Z Bump github.com/moby/moby/client from v0.4.1 to v0.5.0 (#2039) + - 653c6c13 2026-07-24T00:18:02Z Reject cyclic substitutesFor chains instead of looping until OOM (#2038) + - 66852bce 2026-07-24T00:17:45Z Bump actions/setup-go from 6 to 7 (#2037) + - 4210cd0f 2026-07-24T00:17:29Z Bump github.com/docker/cli (#2036) + - faa7ac12 2026-07-24T00:17:12Z Bump google.golang.org/grpc from 1.82.0 to 1.82.1 (#2035) + - 2ee84a3a 2026-07-24T00:16:57Z Bump github.com/mattn/go-sqlite3 from 1.14.47 to 1.14.48 (#2033) + - 1f9ef03f 2026-07-24T00:16:38Z Bump oras.land/oras-go/v2 from 2.6.1 to 2.6.2 (#2032) + - 7bb36d4d 2026-07-24T00:16:12Z Bump github.com/containerd/containerd from 1.7.33 to 1.7.34 (#2031) + - c3c1a01e 2026-07-24T00:15:49Z Upgrade gopkg.in/yaml.v2 to go.yaml.in/yaml/v3 (#2023) + - ac622511 2026-07-24T00:15:27Z Bump go.podman.io/common from 0.68.0 to 0.68.1 (#2029) + - 108f9b21 2026-07-24T00:15:09Z Bump github.com/grpc-ecosystem/grpc-health-probe from 0.4.52 to 0.4.53 (#2030) + - aecb2cbc 2026-07-24T00:14:50Z Bump the golang-x-deps group with 4 updates (#2028) + - cf6a7040 2026-07-24T00:14:26Z Bump golang.org/x/text from 0.38.0 to 0.39.0 in the golang-x-deps group (#2027) + - 89a84c40 2026-07-24T00:14:08Z Bump google.golang.org/grpc from 1.81.1 to 1.82.0 (#2026) + - 5def95d3 2026-07-24T00:13:51Z Bump github.com/docker/cli (#2024) + - fd563d4f 2026-07-24T00:13:30Z empty cred check failed to fall back (#2020) + - 3be9d826 2026-07-24T00:13:13Z Bump github.com/onsi/gomega from 1.42.0 to 1.42.1 (#2022) + - a9705c4c 2026-07-24T00:12:56Z Bump github.com/joelanford/ignore from 0.1.1 to 0.1.2 (#2021) + - 94dc8f82 2026-07-24T00:12:38Z Bump github.com/onsi/ginkgo/v2 from 2.31.0 to 2.32.0 (#2019) + - 006c600c 2026-07-24T00:12:21Z Bump go.etcd.io/bbolt from 1.4.3 to 1.5.0 (#2018) + - 8b9e185b 2026-07-24T00:12:04Z Bump github.com/mattn/go-sqlite3 from 1.14.46 to 1.14.47 (#2017) + - 7dd24242 2026-07-24T00:11:46Z Bump github.com/docker/cli (#2016) + - e69eb2f5 2026-07-24T00:11:28Z Bump github.com/containerd/containerd from 1.7.32 to 1.7.33 (#2015) + - f4932e58 2026-07-24T00:11:05Z Bump actions/checkout from 6 to 7 (#2014) + - bad5f896 2026-07-24T00:10:47Z Bump github.com/mattn/go-sqlite3 from 1.14.45 to 1.14.46 (#2013) + - 64421e49 2026-07-24T00:10:26Z Bump github.com/onsi/ginkgo/v2 from 2.30.0 to 2.31.0 (#2012) + - bb561dd7 2026-07-24T00:10:11Z Bump github.com/onsi/gomega from 1.41.0 to 1.42.0 (#2011) + - 71d26236 2026-07-24T00:09:48Z Bump the k8s-dependencies group with 4 updates (#2010) + - 6e325976 2026-07-24T00:09:25Z Bump github.com/onsi/ginkgo/v2 from 2.29.0 to 2.30.0 (#2009) + - 31ebf518 2026-07-24T00:09:02Z chore: bump o-f deps (#3877) + - 2d8c7fe5 2026-07-24T00:08:38Z :seedling: Bump google.golang.org/grpc from 1.82.0 to 1.82.1 (#3875) + - f6bea1b4 2026-07-24T00:08:18Z :seedling: Bump github.com/go-logr/logr from 1.4.3 to 1.4.4 (#3874) + - 6909f0e9 2026-07-24T00:07:56Z Bump actions/setup-go from 6 to 7 (#3873) + - b995490f 2026-07-24T00:07:37Z :seedling: Bump github.com/prometheus/client_golang (#3872) + - 98c63a01 2026-07-24T00:06:58Z Migrate deprecated gopkg.in/yaml.v3 to go.yaml.in/yaml/v3 (#3865) + - bf01ccba 2026-07-24T00:06:37Z deploy/chart: add static NetworkPolicies for CatalogSource gRPC ingress and bundle unpack egress (#3863) + - 21730989 2026-07-24T00:06:12Z :seedling: Bump golang.org/x/net from 0.56.0 to 0.57.0 (#3868) + - d1efd56a 2026-07-24T00:05:36Z :seedling: Bump github.com/prometheus/common from 0.69.0 to 0.70.0 (#3869) + - 90eb2fa8 2026-07-24T00:05:02Z :seedling: Bump golang.org/x/sync from 0.21.0 to 0.22.0 (#3870) + +- service-ca-operator embedded-component 6391e070d2ab026324b032a6fa5fc7d6be0d2cb5 to 4c5aa6cf172006ca0ebc56c06fe0f2eebc23ec2d + - 9ad2f83 2026-07-24T17:31:07-04:00 Bump github.com/openshift/build-machinery-go + - 11a6d83 2026-07-23T13:23:29+02:00 feat: inject centralized TLS into service-ca operand + - 843f71b 2026-07-22T14:39:22+02:00 chore: sync deps + - 195ba0b 2026-06-06T22:21:50Z Updating ose-service-ca-operator-container image to be consistent with ART for 5.0 Reconciling with https://github.com/openshift-eng/ocp-build-data/tree/7691ed4dc0b6585b358f9e73fb736ace9a48a286/images/ose-service-ca-operator.yml + - 2fc2708 2026-02-09T11:24:14+01:00 chore: add permissions on endpointslice to Prometheus Role and use serviceDiscoveryRole: EndpointSlice in ServiceMonitors + +- oc image-amd64 994613040335f72809854babcb80b9d11a4e98d5 to 86ceecf68afd2f20839edd7f0821766879b5572a + - 7884f37a 2026-07-31T19:05:40-04:00 Handle accept risks with different commands + - 68ed2c1a 2026-07-31T09:01:24-04:00 OCPBUGS-99757: Set oauth2 AuthStyle to AuthStyleInParams for OIDC token endpoint + - 51c19217 2026-07-27T09:55:07-04:00 OCPBUGS-99757: Include extra scopes in OIDC token cache key - a88e785e 2026-07-23T20:40:27Z RFE-8595: must-gather: add client-side keep-alive to prevent accessTokenInactivityTimeout failures (#2288) + - 324c04c3 2026-07-22T19:10:46-04:00 Revert "TRT-2817: Revert "Merge pull request #2279 from nbottari9/1814-duplicate-warning"" + +- csi-external-snapshotter image-amd64 b5e4b73f9a761ff8a59f31b982a63e1cdbb76ed8 to a019d1a9d9e1d26ffd0b2e0d911733180fa608b2 + - b17468a 2026-07-29T11:10:15+02:00 UPSTREAM: 1460: Skip NotFound errors when deleting snapshot content objects -- router image-arm64 0c4063da30da6091765e2576efc684d0f020918d to 682319a1bb432f0203951c33336d0f55947e1099 +- router image-amd64 f5b67ebd12089170bfc47da7745fe4efb1477eb7 to 6248720623dd7f49226e2333fcaf7cde3b9492a3 + - 5c27a38 2026-07-29T15:24:08Z Revert "Merge pull request #825 from bentito/OCPBUGS-77056-async-sar-resurrect-v2" + - 64e3cbf 2026-07-28T14:19:34-04:00 OCPBUGS-77056: Check error returns in race condition tests + - 941eaf6 2026-07-27T12:43:29-04:00 OCPBUGS-77056: Update test comments to describe post-fix behavior + - fd296c1 2026-07-27T11:47:39-04:00 OCPBUGS-77056: Reduce writerlease workers and fix gofmt + - e3418f0 2026-07-27T11:47:39-04:00 OCPBUGS-77056: Fix race conditions causing x509 ECDSA verification failure + - 3926e45 2026-07-27T11:47:39-04:00 OCPBUGS-77056: Add tests exposing race conditions in async external cert validation + - bff072d 2026-07-27T11:47:39-04:00 OCPBUGS-77056: Use a short, unique prefix for fake-haproxy test sockets + - 34cbff2 2026-07-27T11:47:39-04:00 OCPBUGS-77056: Update vendor to remove unused authorizationutil reference + - 1dcc235 2026-07-27T11:47:39-04:00 OCPBUGS-77056: Refine secret deletion message for semantic consistency + - 2d4cf93 2026-07-27T11:47:39-04:00 OCPBUGS-77056: Use t.Setenv for WatchListClient override in factory tests + - bc5619a 2026-07-27T11:47:39-04:00 OCPBUGS-77056: Include standard SA groups in SubjectAccessReview specs + - cfc2726 2026-07-27T11:47:39-04:00 OCPBUGS-77056: Fail-closed to ValidationFailed on secret deletion + - fff8566 2026-07-27T11:47:39-04:00 Addressing coderabbit PR comments + - 5a52884 2026-07-27T11:47:39-04:00 Addressed several refactor needs from PR comments + - 20fe05f 2026-07-27T11:47:39-04:00 address review comment: remove unnecessary lock from StatusAdmitter + - 463265d 2026-07-27T11:47:39-04:00 address review comment: use types.NamespacedName for informer key + - 25ccd95 2026-07-27T11:47:39-04:00 Remove library-go replace directive and update vendor + - 6c010a1 2026-07-27T11:47:39-04:00 OCPBUGS-77056: Retry on write conflicts without dropping writerlease + - 8666c60 2026-07-27T11:47:39-04:00 OCPBUGS-77056: Asynchronous external certificate validation and Hybrid Informer secret monitoring + - b701b2d 2026-07-27T15:37:57Z images/router/f5: Delete F5 router Dockerfile - c15a20a 2026-07-25T20:02:34Z Revert "OCPBUGS-77056: Make external cert validation asynchronous (Resurrection)" - da1c969 2026-07-23T10:29:40-04:00 OCPBUGS-77056: Use a short, unique prefix for fake-haproxy test sockets - 6f2aacc 2026-07-23T10:29:40-04:00 OCPBUGS-77056: Update vendor to remove unused authorizationutil reference @@ -16,26 +252,187 @@ - 7b4b855 2026-07-23T10:29:40-04:00 Remove library-go replace directive and update vendor - 277913c 2026-07-23T10:29:40-04:00 OCPBUGS-77056: Retry on write conflicts without dropping writerlease - bc97dba 2026-07-23T10:29:40-04:00 OCPBUGS-77056: Asynchronous external certificate validation and Hybrid Informer secret monitoring - - 74b6915 2026-07-22T11:50:03-04:00 NE-2741: Align vendored openshift/api with the master branch version - - deb1d50 2026-07-22T11:21:18-04:00 NE-2741: Address PR comments on TLS curve preference parsing - - 7f33917 2026-07-22T11:21:18-04:00 Security: fail-closed on unsupported TLS curves and parse mixed delimiters - - da031dd 2026-07-22T11:21:18-04:00 Fix: shorten fake-haproxy socket path in tests to avoid length limits - - ef67e22 2026-07-22T11:21:18-04:00 NE-2741: Implement TLS Curves Support for Metrics Endpoints - 6ebff4e 2026-07-20T21:03:15-04:00 NE-2223: Bump HAProxy to 3.2.19 in the router image - 400eac8 2026-06-15T16:09:07-03:00 NO-JIRA: Add default coderabbit for the repo -- ovn-kubernetes image-arm64 8e2e1542642847da592268a0ab94a207eb8d3605 to 88e9f0f146784e8525f6304a1f6f7c986eba2319 +- ovn-kubernetes image-amd64 8e2e1542642847da592268a0ab94a207eb8d3605 to 4c92603d97181c0315e16fa9a1e2ad9f5d323344 + - 51047fae 2026-07-17T20:27:56+05:30 sync test annotations with upstream changes + - b05c351c 2026-07-17T20:27:53+05:30 Adapt OTE for E2E L3 CUDN multisubnet backward compatibility fixes + - 70a2009b 2026-07-17T10:23:14+02:00 e2e(kubevirt): deflake "with pre-copy fails" migration test + - fa8e140a 2026-07-16T15:33:44+02:00 Fix traffic leak in egress IP on secondary interface + - 8bce7389 2026-07-16T10:32:40+02:00 node: use libovsdb instead of ovs-vsctl exec in checkPorts + - 7b2e6eb5 2026-07-16T00:32:34+02:00 ci: cover dynamic UDN allocation on a no-overlay shared-gateway lane + - 1b7e0ec0 2026-07-16T00:32:34+02:00 e2e: adapt advertised network isolation tests to dynamic UDN allocation + - 156b75f9 2026-07-16T00:32:34+02:00 e2e: adapt CUDN advertisement tests to dynamic UDN allocation + - 501cc079 2026-07-16T00:32:34+02:00 e2e: cover RouteAdvertisements over a dynamically allocated CUDN + - 8df86599 2026-07-16T00:32:34+02:00 routeadvertisements: advertise dynamic UDNs only from active nodes + - 677d6113 2026-07-15T10:03:52-07:00 clustermanager: rename node allocation controller + - 1fcfb18f 2026-07-14T16:09:34-04:00 no-overlay: host -> pods on other nodes via mp0 + - 4620cb6d 2026-07-14T10:29:15-07:00 licenses: refresh generated third-party licenses + - 8b0dd877 2026-07-14T10:29:15-07:00 cni: fold libovsdb and shell-out ConfigureOVS paths into one + - 0b276e27 2026-07-14T10:29:15-07:00 libovsdb/ops: consolidate ovs helper operations + - 49393a41 2026-07-14T16:52:06+01:00 docs: rename portSecurity to macSecurity in OKEP-3926 + - 7229c04d 2026-07-14T20:27:41+05:30 node: skip configureGlobalForwarding tests in CI without root access + - 40bd24a5 2026-07-13T17:27:35+02:00 zone_interconnect: add unit test for stale IC route cleanup - 3f34530b 2026-07-12T10:36:43+03:00 Update OWNERS file + - 60fcdaf5 2026-07-10T18:56:40+02:00 Use new IPv6 force_forwarding sysctl if available. + - 0e3a4e06 2026-07-10T18:56:40+02:00 Don't change FORWARD table default policy for IPv4 + - 7795aba2 2026-07-10T18:56:40+02:00 Don't override FORWARD default policy when `disable-forwarding` is not set + - 92fc5160 2026-07-10T18:56:40+02:00 Update disable-gateway unit tests + - a90d60b6 2026-07-10T18:56:40+02:00 Clarify/simplify/fix "Disable Forwarding Config" docs + - bdfd82fb 2026-07-10T17:48:35+02:00 Redo the AllocateLoadBalancerNodePorts=false test cases + - dcaf6dba 2026-07-10T12:46:42+02:00 [perf] fix netpol selection for cudn-l2 job + - d447e853 2026-07-10T11:17:19+02:00 Support update of chassis-id without re-creating the node. + - 0c9edf05 2026-07-08T12:59:20-07:00 ovnkube.sh: unify gateway option loading from OVS external_ids + - 945f64d7 2026-07-08T10:33:19-07:00 test: Use proper TLS certificate validation in metrics server tests + - 98e204fe 2026-07-08T13:36:28+02:00 coderabbit: add pre-merge checks and custom validation rules + - e36fbadc 2026-07-07T20:23:30+02:00 Get pod from apiserver on retryable annotation patch failure + - 06f453b7 2026-07-07T08:13:37+02:00 e2e(kubevirt): replace echoserver with iperf3 + - 853a72fa 2026-07-06T15:06:48-07:00 libovsdb/ops: document ovs-vsctl equivalents on read wrappers + - e3e40f10 2026-07-06T15:06:48-07:00 util, libovsdb/ops: migrate NicToBridge to libovsdb + - 497f470f 2026-07-06T15:06:48-07:00 test/e2e: pin docker while importing libovsdb + - c1c5603e 2026-07-06T15:06:48-07:00 util, node: migrate nicstobridge read paths to libovsdb + - 258eb623 2026-07-06T15:06:48-07:00 node/test: migrate DPU and gateway tests to libovsdb harness + - 1a64e7db 2026-07-06T15:06:48-07:00 cni, node: migrate ConfigureOVS and delRepPort to libovsdb + - 3785f7bd 2026-07-06T15:06:48-07:00 node: move ovsClient to BaseNodeNetworkController + - a58ead15 2026-07-06T15:06:47-07:00 libovsdb/ops: add GetOVSInterface and CreateOrUpdatePodPort + - ff6d3a79 2026-07-06T15:06:47-07:00 node, controllermanager: migrate stale-port cleanup to libovsdb + - 65e3926d 2026-07-06T15:06:47-07:00 node, libovsdb/ops: migrate port-to-br shell-outs to libovsdb + - f1a554fd 2026-07-06T15:06:47-07:00 node: migrate br-exists and del-port br-int to libovsdb + - 1e4c92c6 2026-07-06T15:06:47-07:00 util, ovn-kube-util: migrate BridgeToNic to libovsdb + - 79cb19da 2026-07-06T15:06:47-07:00 libovsdb/ops: bridge-scope DeletePortWithInterfaces + - fdc69950 2026-07-06T15:06:47-07:00 node, libovsdb/ops: migrate del-br shell-outs to libovsdb + - 25b05aa5 2026-07-06T20:15:26+02:00 Only create ACCEPT rules for bypassing our own DROP rules + - fe9bd9f8 2026-07-06T20:15:26+02:00 Simplify initLocalGateway iptables/nftables setup + - 7683207e 2026-07-03T10:03:37+02:00 e2e(kubevirt): drop fedora coreos image in favor of fedora + - d9d3e374 2026-07-02T18:14:51+02:00 area-merge: prevent bot comment feedback loop + - 635a3fd7 2026-07-02T15:50:39+01:00 docs: add "future work" section to OKEP-3926 + - 69f3a5e7 2026-07-02T15:50:39+01:00 docs: simplify OKEP-3926 and add per-attachment future section + - 00e2aa81 2026-07-02T15:50:39+01:00 docs: add OKEP-3926 for disabling port security on secondary networks + - 4246d935 2026-07-02T17:56:19+08:00 docs: fix typo in OKEP 5193 CUDN spec + - e9ed7419 2026-07-01T15:50:28-07:00 OKEP-6227: Add DHCP IPAM support for localnet UDNs + - 78e42465 2026-07-01T10:34:35-04:00 config: make routing table ID start configurable + - b19a79d2 2026-06-30T10:59:13-04:00 Revert "Route DPU host no-overlay traffic through OVN" + - 6eac3a2e 2026-06-30T15:35:05+02:00 docs/e2e: clarify E2E backward compatibility requirements in OKEP template + - 585b72c2 2026-06-26T16:33:10+02:00 Allow networks to start while route advertisements settle -- kubernetes image-arm64 0f7d1a1b66af90eece8d46f6f9dc7537bf16d978 to 63ee93dac28329fd9d81e91b21ea8d8c43105d01 +- kubernetes image-amd64 98b35193b2ac7a23a673325f5e9b830ecd5ba406 to e63ab41237b34f2a457e76900f6162184420cf96 + - 5e858e982 2026-07-28T13:51:08-04:00 UPSTREAM: : Re-enable kubectl kuberc commands e2e tests + - 8d27ef98f 2026-07-27T11:14:23+02:00 UPSTREAM: 137936: csi: update CSI sidecar images in test manifests + - c8aa52947 2026-07-24T13:25:07+02:00 UPSTREAM: 138768: move VolumeGroupSnapshot to V1 + - 0f4503bbf 2026-07-22T11:54:16-04:00 UPSTREAM: : Update openshift-hack/rebase.sh, REBASE.openshift.md + - cc48cfba7 2026-07-20T21:23:37-06:00 UPSTREAM: : Add NodeSelectorAdjuster admission plugin for standalone clusters (part 2) - 44a83e00e 2026-07-17T15:00:07+02:00 UPSTREAM: : hack/update-featuregates.sh - 4da08ff19 2026-07-17T08:27:41+02:00 UPSTREAM: : Store SELinuxWarningController upgrade check as a ConfigMap - - d178a1dbb 2026-07-17T00:54:58+05:30 UPSTREAM: 140211: Promote regression-issue-74839 to 1.5 + - de396e993 2026-07-16T15:20:30-06:00 UPSTREAM: 140377: e2e: storage snapshot tests should read custom timeouts from manifest - 13ace3c70 2026-07-02T02:25:02-04:00 UPSTREAM: : upkeep cpu partitioning admission webhook -- service-ca-operator image-arm64 6391e070d2ab026324b032a6fa5fc7d6be0d2cb5 to e260be2b3710137012814ce9ca48f155f24f0b02 +- service-ca-operator image-amd64 6391e070d2ab026324b032a6fa5fc7d6be0d2cb5 to 4c5aa6cf172006ca0ebc56c06fe0f2eebc23ec2d - 9ad2f83 2026-07-24T17:31:07-04:00 Bump github.com/openshift/build-machinery-go - 11a6d83 2026-07-23T13:23:29+02:00 feat: inject centralized TLS into service-ca operand - 843f71b 2026-07-22T14:39:22+02:00 chore: sync deps - 195ba0b 2026-06-06T22:21:50Z Updating ose-service-ca-operator-container image to be consistent with ART for 5.0 Reconciling with https://github.com/openshift-eng/ocp-build-data/tree/7691ed4dc0b6585b358f9e73fb736ace9a48a286/images/ose-service-ca-operator.yml + - 2fc2708 2026-02-09T11:24:14+01:00 chore: add permissions on endpointslice to Prometheus Role and use serviceDiscoveryRole: EndpointSlice in ServiceMonitors + +- oc image-arm64 a88e785e90aa96ac96da93359bacf3ea5c174733 to 86ceecf68afd2f20839edd7f0821766879b5572a + - 7884f37a 2026-07-31T19:05:40-04:00 Handle accept risks with different commands + - 68ed2c1a 2026-07-31T09:01:24-04:00 OCPBUGS-99757: Set oauth2 AuthStyle to AuthStyleInParams for OIDC token endpoint + - 51c19217 2026-07-27T09:55:07-04:00 OCPBUGS-99757: Include extra scopes in OIDC token cache key + - 324c04c3 2026-07-22T19:10:46-04:00 Revert "TRT-2817: Revert "Merge pull request #2279 from nbottari9/1814-duplicate-warning"" + +- csi-external-snapshotter image-arm64 b5e4b73f9a761ff8a59f31b982a63e1cdbb76ed8 to a019d1a9d9e1d26ffd0b2e0d911733180fa608b2 + - b17468a 2026-07-29T11:10:15+02:00 UPSTREAM: 1460: Skip NotFound errors when deleting snapshot content objects + +- router image-arm64 682319a1bb432f0203951c33336d0f55947e1099 to 6248720623dd7f49226e2333fcaf7cde3b9492a3 + - 5c27a38 2026-07-29T15:24:08Z Revert "Merge pull request #825 from bentito/OCPBUGS-77056-async-sar-resurrect-v2" + - 64e3cbf 2026-07-28T14:19:34-04:00 OCPBUGS-77056: Check error returns in race condition tests + - 941eaf6 2026-07-27T12:43:29-04:00 OCPBUGS-77056: Update test comments to describe post-fix behavior + - fd296c1 2026-07-27T11:47:39-04:00 OCPBUGS-77056: Reduce writerlease workers and fix gofmt + - e3418f0 2026-07-27T11:47:39-04:00 OCPBUGS-77056: Fix race conditions causing x509 ECDSA verification failure + - 3926e45 2026-07-27T11:47:39-04:00 OCPBUGS-77056: Add tests exposing race conditions in async external cert validation + - bff072d 2026-07-27T11:47:39-04:00 OCPBUGS-77056: Use a short, unique prefix for fake-haproxy test sockets + - 34cbff2 2026-07-27T11:47:39-04:00 OCPBUGS-77056: Update vendor to remove unused authorizationutil reference + - 1dcc235 2026-07-27T11:47:39-04:00 OCPBUGS-77056: Refine secret deletion message for semantic consistency + - 2d4cf93 2026-07-27T11:47:39-04:00 OCPBUGS-77056: Use t.Setenv for WatchListClient override in factory tests + - bc5619a 2026-07-27T11:47:39-04:00 OCPBUGS-77056: Include standard SA groups in SubjectAccessReview specs + - cfc2726 2026-07-27T11:47:39-04:00 OCPBUGS-77056: Fail-closed to ValidationFailed on secret deletion + - fff8566 2026-07-27T11:47:39-04:00 Addressing coderabbit PR comments + - 5a52884 2026-07-27T11:47:39-04:00 Addressed several refactor needs from PR comments + - 20fe05f 2026-07-27T11:47:39-04:00 address review comment: remove unnecessary lock from StatusAdmitter + - 463265d 2026-07-27T11:47:39-04:00 address review comment: use types.NamespacedName for informer key + - 25ccd95 2026-07-27T11:47:39-04:00 Remove library-go replace directive and update vendor + - 6c010a1 2026-07-27T11:47:39-04:00 OCPBUGS-77056: Retry on write conflicts without dropping writerlease + - 8666c60 2026-07-27T11:47:39-04:00 OCPBUGS-77056: Asynchronous external certificate validation and Hybrid Informer secret monitoring + - b701b2d 2026-07-27T15:37:57Z images/router/f5: Delete F5 router Dockerfile + +- ovn-kubernetes image-arm64 88e9f0f146784e8525f6304a1f6f7c986eba2319 to 4c92603d97181c0315e16fa9a1e2ad9f5d323344 + - 51047fae 2026-07-17T20:27:56+05:30 sync test annotations with upstream changes + - b05c351c 2026-07-17T20:27:53+05:30 Adapt OTE for E2E L3 CUDN multisubnet backward compatibility fixes + - 70a2009b 2026-07-17T10:23:14+02:00 e2e(kubevirt): deflake "with pre-copy fails" migration test + - fa8e140a 2026-07-16T15:33:44+02:00 Fix traffic leak in egress IP on secondary interface + - 8bce7389 2026-07-16T10:32:40+02:00 node: use libovsdb instead of ovs-vsctl exec in checkPorts + - 7b2e6eb5 2026-07-16T00:32:34+02:00 ci: cover dynamic UDN allocation on a no-overlay shared-gateway lane + - 1b7e0ec0 2026-07-16T00:32:34+02:00 e2e: adapt advertised network isolation tests to dynamic UDN allocation + - 156b75f9 2026-07-16T00:32:34+02:00 e2e: adapt CUDN advertisement tests to dynamic UDN allocation + - 501cc079 2026-07-16T00:32:34+02:00 e2e: cover RouteAdvertisements over a dynamically allocated CUDN + - 8df86599 2026-07-16T00:32:34+02:00 routeadvertisements: advertise dynamic UDNs only from active nodes + - 677d6113 2026-07-15T10:03:52-07:00 clustermanager: rename node allocation controller + - 1fcfb18f 2026-07-14T16:09:34-04:00 no-overlay: host -> pods on other nodes via mp0 + - 4620cb6d 2026-07-14T10:29:15-07:00 licenses: refresh generated third-party licenses + - 8b0dd877 2026-07-14T10:29:15-07:00 cni: fold libovsdb and shell-out ConfigureOVS paths into one + - 0b276e27 2026-07-14T10:29:15-07:00 libovsdb/ops: consolidate ovs helper operations + - 49393a41 2026-07-14T16:52:06+01:00 docs: rename portSecurity to macSecurity in OKEP-3926 + - 7229c04d 2026-07-14T20:27:41+05:30 node: skip configureGlobalForwarding tests in CI without root access + - 40bd24a5 2026-07-13T17:27:35+02:00 zone_interconnect: add unit test for stale IC route cleanup + - 60fcdaf5 2026-07-10T18:56:40+02:00 Use new IPv6 force_forwarding sysctl if available. + - 0e3a4e06 2026-07-10T18:56:40+02:00 Don't change FORWARD table default policy for IPv4 + - 7795aba2 2026-07-10T18:56:40+02:00 Don't override FORWARD default policy when `disable-forwarding` is not set + - 92fc5160 2026-07-10T18:56:40+02:00 Update disable-gateway unit tests + - a90d60b6 2026-07-10T18:56:40+02:00 Clarify/simplify/fix "Disable Forwarding Config" docs + - bdfd82fb 2026-07-10T17:48:35+02:00 Redo the AllocateLoadBalancerNodePorts=false test cases + - dcaf6dba 2026-07-10T12:46:42+02:00 [perf] fix netpol selection for cudn-l2 job + - d447e853 2026-07-10T11:17:19+02:00 Support update of chassis-id without re-creating the node. + - 0c9edf05 2026-07-08T12:59:20-07:00 ovnkube.sh: unify gateway option loading from OVS external_ids + - 945f64d7 2026-07-08T10:33:19-07:00 test: Use proper TLS certificate validation in metrics server tests + - 98e204fe 2026-07-08T13:36:28+02:00 coderabbit: add pre-merge checks and custom validation rules + - e36fbadc 2026-07-07T20:23:30+02:00 Get pod from apiserver on retryable annotation patch failure + - 06f453b7 2026-07-07T08:13:37+02:00 e2e(kubevirt): replace echoserver with iperf3 + - 853a72fa 2026-07-06T15:06:48-07:00 libovsdb/ops: document ovs-vsctl equivalents on read wrappers + - e3e40f10 2026-07-06T15:06:48-07:00 util, libovsdb/ops: migrate NicToBridge to libovsdb + - 497f470f 2026-07-06T15:06:48-07:00 test/e2e: pin docker while importing libovsdb + - c1c5603e 2026-07-06T15:06:48-07:00 util, node: migrate nicstobridge read paths to libovsdb + - 258eb623 2026-07-06T15:06:48-07:00 node/test: migrate DPU and gateway tests to libovsdb harness + - 1a64e7db 2026-07-06T15:06:48-07:00 cni, node: migrate ConfigureOVS and delRepPort to libovsdb + - 3785f7bd 2026-07-06T15:06:48-07:00 node: move ovsClient to BaseNodeNetworkController + - a58ead15 2026-07-06T15:06:47-07:00 libovsdb/ops: add GetOVSInterface and CreateOrUpdatePodPort + - ff6d3a79 2026-07-06T15:06:47-07:00 node, controllermanager: migrate stale-port cleanup to libovsdb + - 65e3926d 2026-07-06T15:06:47-07:00 node, libovsdb/ops: migrate port-to-br shell-outs to libovsdb + - f1a554fd 2026-07-06T15:06:47-07:00 node: migrate br-exists and del-port br-int to libovsdb + - 1e4c92c6 2026-07-06T15:06:47-07:00 util, ovn-kube-util: migrate BridgeToNic to libovsdb + - 79cb19da 2026-07-06T15:06:47-07:00 libovsdb/ops: bridge-scope DeletePortWithInterfaces + - fdc69950 2026-07-06T15:06:47-07:00 node, libovsdb/ops: migrate del-br shell-outs to libovsdb + - 25b05aa5 2026-07-06T20:15:26+02:00 Only create ACCEPT rules for bypassing our own DROP rules + - fe9bd9f8 2026-07-06T20:15:26+02:00 Simplify initLocalGateway iptables/nftables setup + - 7683207e 2026-07-03T10:03:37+02:00 e2e(kubevirt): drop fedora coreos image in favor of fedora + - d9d3e374 2026-07-02T18:14:51+02:00 area-merge: prevent bot comment feedback loop + - 635a3fd7 2026-07-02T15:50:39+01:00 docs: add "future work" section to OKEP-3926 + - 69f3a5e7 2026-07-02T15:50:39+01:00 docs: simplify OKEP-3926 and add per-attachment future section + - 00e2aa81 2026-07-02T15:50:39+01:00 docs: add OKEP-3926 for disabling port security on secondary networks + - 4246d935 2026-07-02T17:56:19+08:00 docs: fix typo in OKEP 5193 CUDN spec + - e9ed7419 2026-07-01T15:50:28-07:00 OKEP-6227: Add DHCP IPAM support for localnet UDNs + - 78e42465 2026-07-01T10:34:35-04:00 config: make routing table ID start configurable + - b19a79d2 2026-06-30T10:59:13-04:00 Revert "Route DPU host no-overlay traffic through OVN" + - 6eac3a2e 2026-06-30T15:35:05+02:00 docs/e2e: clarify E2E backward compatibility requirements in OKEP template + - 585b72c2 2026-06-26T16:33:10+02:00 Allow networks to start while route advertisements settle + +- kubernetes image-arm64 63ee93dac28329fd9d81e91b21ea8d8c43105d01 to e63ab41237b34f2a457e76900f6162184420cf96 + - 5e858e982 2026-07-28T13:51:08-04:00 UPSTREAM: : Re-enable kubectl kuberc commands e2e tests + - 8d27ef98f 2026-07-27T11:14:23+02:00 UPSTREAM: 137936: csi: update CSI sidecar images in test manifests + - c8aa52947 2026-07-24T13:25:07+02:00 UPSTREAM: 138768: move VolumeGroupSnapshot to V1 + - 0f4503bbf 2026-07-22T11:54:16-04:00 UPSTREAM: : Update openshift-hack/rebase.sh, REBASE.openshift.md + - cc48cfba7 2026-07-20T21:23:37-06:00 UPSTREAM: : Add NodeSelectorAdjuster admission plugin for standalone clusters (part 2) + - de396e993 2026-07-16T15:20:30-06:00 UPSTREAM: 140377: e2e: storage snapshot tests should read custom timeouts from manifest + +- service-ca-operator image-arm64 e260be2b3710137012814ce9ca48f155f24f0b02 to 4c5aa6cf172006ca0ebc56c06fe0f2eebc23ec2d + - 2fc2708 2026-02-09T11:24:14+01:00 chore: add permissions on endpointslice to Prometheus Role and use serviceDiscoveryRole: EndpointSlice in ServiceMonitors diff --git a/scripts/auto-rebase/commits.txt b/scripts/auto-rebase/commits.txt index d610a4f0c7..90353cb437 100644 --- a/scripts/auto-rebase/commits.txt +++ b/scripts/auto-rebase/commits.txt @@ -1,35 +1,35 @@ -https://github.com/openshift/api embedded-component 581cfdf7198613bd325c185eb3eac672670da633 -https://github.com/openshift/cluster-csi-snapshot-controller-operator embedded-component ef7a4c8b7f5c5e6cba4486dcc37f50521e7bc655 -https://github.com/openshift/cluster-dns-operator embedded-component 4b8ae49940eefc50fa48da5179e735dd6ccd42d9 -https://github.com/openshift/cluster-ingress-operator embedded-component b4daff58712de418c51d765a8686069a5f47e764 -https://github.com/openshift/cluster-kube-apiserver-operator embedded-component ea8a9c50203113ca43db98ca925ab7fcdaff7d28 +https://github.com/openshift/api embedded-component 05ea89db4588a2f443a2402764a73f3529ab116b +https://github.com/openshift/cluster-csi-snapshot-controller-operator embedded-component 35ec0224eb0e5219d5eae012fb703223a6f3e1f7 +https://github.com/openshift/cluster-dns-operator embedded-component c0ed09e329e9001629518604a58205e3fbe8284a +https://github.com/openshift/cluster-ingress-operator embedded-component 2461c5ceeb1fe16a4c8cfc1d0f82fb9555cbf1d0 +https://github.com/openshift/cluster-kube-apiserver-operator embedded-component 1f677d8a71a5d43c17505349fc7c41c97b04fe8d https://github.com/openshift/cluster-kube-controller-manager-operator embedded-component 4e72164b8bc505033ad565ab01d57963e7c9688e https://github.com/openshift/cluster-kube-scheduler-operator embedded-component 56fa325466a1f2a2d41435ba3a58b2bf8fdab2f3 -https://github.com/openshift/cluster-network-operator embedded-component 4f6fb6be829a2f6ad3e0df4ab85ecb00ef028343 +https://github.com/openshift/cluster-network-operator embedded-component 1dcce833f8682c68273f1c47c911baeeb1a741f6 https://github.com/openshift/cluster-openshift-controller-manager-operator embedded-component 34f95b07f4afbc47558e54e4fa2710fd692e615e https://github.com/openshift/cluster-policy-controller embedded-component 01afc4aac71a8e8be26383a0421bed7673391750 -https://github.com/openshift/csi-external-snapshotter embedded-component b5e4b73f9a761ff8a59f31b982a63e1cdbb76ed8 +https://github.com/openshift/csi-external-snapshotter embedded-component a019d1a9d9e1d26ffd0b2e0d911733180fa608b2 https://github.com/openshift/etcd embedded-component 64f8851a001f7e102d47bfe51ca0dac23951879a -https://github.com/openshift/kubernetes embedded-component 98b35193b2ac7a23a673325f5e9b830ecd5ba406 +https://github.com/openshift/kubernetes embedded-component e63ab41237b34f2a457e76900f6162184420cf96 https://github.com/openshift/kubernetes-kube-storage-version-migrator embedded-component 72835e43c7754356645e41031f3a99926b4d42e6 -https://github.com/openshift/machine-config-operator embedded-component 067b924f19a64a209796d5be5a0a63665f53b1eb +https://github.com/openshift/machine-config-operator embedded-component 215097bef12ac57636668b4732c6ccf288a48a9f https://github.com/openshift/openshift-controller-manager embedded-component 5631cf493b006cbc72a8600a7435813272d71940 -https://github.com/openshift/operator-framework-olm embedded-component 56b3931de4636f7e0d212001f2074b9dddb45a8f +https://github.com/openshift/operator-framework-olm embedded-component 76870171f4c192e96d450bcfb71dca508a264999 https://github.com/openshift/route-controller-manager embedded-component 59697cf7af4517dd44e28179a57f7f35b6ea0e22 -https://github.com/openshift/service-ca-operator embedded-component 6391e070d2ab026324b032a6fa5fc7d6be0d2cb5 -https://github.com/openshift/oc image-amd64 994613040335f72809854babcb80b9d11a4e98d5 +https://github.com/openshift/service-ca-operator embedded-component 4c5aa6cf172006ca0ebc56c06fe0f2eebc23ec2d +https://github.com/openshift/oc image-amd64 86ceecf68afd2f20839edd7f0821766879b5572a https://github.com/openshift/coredns image-amd64 37aaba896e97f4b9a091aab6d36f2213b8854474 -https://github.com/openshift/csi-external-snapshotter image-amd64 b5e4b73f9a761ff8a59f31b982a63e1cdbb76ed8 -https://github.com/openshift/router image-amd64 f5b67ebd12089170bfc47da7745fe4efb1477eb7 +https://github.com/openshift/csi-external-snapshotter image-amd64 a019d1a9d9e1d26ffd0b2e0d911733180fa608b2 +https://github.com/openshift/router image-amd64 6248720623dd7f49226e2333fcaf7cde3b9492a3 https://github.com/openshift/kube-rbac-proxy image-amd64 43c114bc124f59e2fc3223dea8e0a8f4cdeed18d -https://github.com/openshift/ovn-kubernetes image-amd64 8e2e1542642847da592268a0ab94a207eb8d3605 -https://github.com/openshift/kubernetes image-amd64 98b35193b2ac7a23a673325f5e9b830ecd5ba406 -https://github.com/openshift/service-ca-operator image-amd64 6391e070d2ab026324b032a6fa5fc7d6be0d2cb5 -https://github.com/openshift/oc image-arm64 a88e785e90aa96ac96da93359bacf3ea5c174733 +https://github.com/openshift/ovn-kubernetes image-amd64 4c92603d97181c0315e16fa9a1e2ad9f5d323344 +https://github.com/openshift/kubernetes image-amd64 e63ab41237b34f2a457e76900f6162184420cf96 +https://github.com/openshift/service-ca-operator image-amd64 4c5aa6cf172006ca0ebc56c06fe0f2eebc23ec2d +https://github.com/openshift/oc image-arm64 86ceecf68afd2f20839edd7f0821766879b5572a https://github.com/openshift/coredns image-arm64 37aaba896e97f4b9a091aab6d36f2213b8854474 -https://github.com/openshift/csi-external-snapshotter image-arm64 b5e4b73f9a761ff8a59f31b982a63e1cdbb76ed8 -https://github.com/openshift/router image-arm64 682319a1bb432f0203951c33336d0f55947e1099 +https://github.com/openshift/csi-external-snapshotter image-arm64 a019d1a9d9e1d26ffd0b2e0d911733180fa608b2 +https://github.com/openshift/router image-arm64 6248720623dd7f49226e2333fcaf7cde3b9492a3 https://github.com/openshift/kube-rbac-proxy image-arm64 43c114bc124f59e2fc3223dea8e0a8f4cdeed18d -https://github.com/openshift/ovn-kubernetes image-arm64 88e9f0f146784e8525f6304a1f6f7c986eba2319 -https://github.com/openshift/kubernetes image-arm64 63ee93dac28329fd9d81e91b21ea8d8c43105d01 -https://github.com/openshift/service-ca-operator image-arm64 e260be2b3710137012814ce9ca48f155f24f0b02 +https://github.com/openshift/ovn-kubernetes image-arm64 4c92603d97181c0315e16fa9a1e2ad9f5d323344 +https://github.com/openshift/kubernetes image-arm64 e63ab41237b34f2a457e76900f6162184420cf96 +https://github.com/openshift/service-ca-operator image-arm64 4c5aa6cf172006ca0ebc56c06fe0f2eebc23ec2d From a3133e061f395a3af6deeb44a8a76c406b8874a5 Mon Sep 17 00:00:00 2001 From: "Jonathan H. Cope" Date: Tue, 4 Aug 2026 11:25:54 -0500 Subject: [PATCH 4/8] update no-issue-add-asset-service-ca-config/deps --- .../openshift/kubernetes/REBASE.openshift.md | 72 +++- .../cmd/k8s-tests-ext/disabled_tests.go | 3 - .../kubernetes/openshift-hack/rebase.sh | 84 +++-- .../managementcpusoverride/admission.go | 26 +- .../managementcpusoverride/admission_test.go | 35 +- .../nodeselectoradjuster/admission.go | 61 +++- .../nodeselectoradjuster/admission_test.go | 253 ++++++++++++- .../selinuxwarning/cache/openshift_patch.go | 18 + .../openshift_upgrade_controller.go | 102 ++++++ .../openshift_upgrade_controller_test.go | 336 ++++++++++++++++++ .../selinux_warning_controller.go | 7 + .../pkg/features/openshift_features.go | 6 + .../rbac/bootstrappolicy/controller_policy.go | 4 + .../testdata/controller-roles.yaml | 14 + .../reference/feature_list.md | 1 + .../storage/testsuites/snapshot-metadata.go | 2 +- .../e2e/storage/testsuites/snapshottable.go | 2 +- .../testsuites/snapshottable_stress.go | 2 +- .../storage/utils/volume_group_snapshot.go | 8 +- ...age.k8s.io_volumegroupsnapshotclasses.yaml | 83 +++++ ...ge.k8s.io_volumegroupsnapshotcontents.yaml | 327 +++++++++++++++++ ...t.storage.k8s.io_volumegroupsnapshots.yaml | 220 ++++++++++++ .../csi-hostpath-plugin.yaml | 27 +- .../run_group_snapshot_e2e.sh | 2 +- .../storage-csi/gce-pd/controller_ss.yaml | 8 +- .../storage-csi/gce-pd/node_ds.yaml | 2 +- .../hostpath/csi-hostpath-plugin.yaml | 29 +- .../mock/csi-mock-driver-attacher.yaml | 2 +- .../mock/csi-mock-driver-resizer.yaml | 2 +- .../mock/csi-mock-driver-snapshotter.yaml | 2 +- .../storage-csi/mock/csi-mock-driver.yaml | 17 +- .../storage-csi/mock/csi-mock-proxy.yaml | 17 +- 32 files changed, 1628 insertions(+), 146 deletions(-) create mode 100644 deps/github.com/openshift/kubernetes/pkg/controller/volume/selinuxwarning/cache/openshift_patch.go create mode 100644 deps/github.com/openshift/kubernetes/pkg/controller/volume/selinuxwarning/openshift_upgrade_controller.go create mode 100644 deps/github.com/openshift/kubernetes/pkg/controller/volume/selinuxwarning/openshift_upgrade_controller_test.go diff --git a/deps/github.com/openshift/kubernetes/REBASE.openshift.md b/deps/github.com/openshift/kubernetes/REBASE.openshift.md index 1d6d616f8e..a800ceecc4 100644 --- a/deps/github.com/openshift/kubernetes/REBASE.openshift.md +++ b/deps/github.com/openshift/kubernetes/REBASE.openshift.md @@ -360,9 +360,8 @@ The following repositories have been already bumped as well: -Followup work has been assigned to appropriate teams -through bugzillas linked in the code. Please treat -them as the highest priority after landing the bump. +A Jira ticket has been opened for the rebase process. +It has been linked to the pull request. Finally, this means we are blocking ALL PRs to our kubernetes fork. @@ -404,10 +403,55 @@ them as the highest priority and release blockers for your team: 1. Update cluster-kube-apiserver-operator `pre-release-lifecycle` alert's `removed_release` version similarly to https://github.com/openshift/cluster-kube-apiserver-operator/pull/1382. -## Updating with `git merge` +## Updating with `redhat-chai-bot` *This is the preferred way to update to patch releases of kubernetes* +[chai-bot](slack://app?team=T027F3GAJ&id=A0AJUKWDUR1&tab=messages) (ship-help-bot) is an internal tool has been given instructions to +periodically check for upstream patch releases and complete the rebase autonomously. The steps taken are outlined below: + + +1. Fetch upstream tags over the past 31 days: +``` +git fetch --tags upstream && git tag --sort=-creatordate | grep -E 'v[0-9]+\.[0-9]+\.[0-9]+$' | awk -v cutoff="$(date -d '31 days ago' +%s)" '$2 >= cutoff {print $1}' +``` +where `upstream` points at https://github.com/kubernetes/kubernetes/ + +2. Determine whether any patch release have occurred that have not yet been rebased and merged. If such patch releases exist, + the corresponding openshift branches are found and marked to be rebased. Otherwise, chai-bot reports that there is no rebase necessary. + - *Branches tracking master are skipped.* + +3. Output a mapping table of upstream release to openshift version, as well as whether that branch needs to be rebased, to the appropriate team: +``` +*Kubernetes patch rebase check* + +Upstream Release OCP Branch Current k8s Status Notes +───────────────── ────────────── ──────────── ───────── ────────────────────────── +v1.35.6 master 1.35.3 REBASE Patch 3 → 6 +v1.35.6 release-5.1 1.35.3 SKIP Points at openshift/master +v1.35.6 release-4.22 1.35.5 REBASE Patch 5 → 6 +v1.34.9 release-4.21 1.34.8 REBASE Patch 8 → 9 +``` + +4. For each branch requiring a rebase, chai-bot runs [rebase.sh](https://github.com/openshift/kubernetes/blob/master/openshift-hack/rebase.sh) (see usage below) with + the appropriate parameters of `kubernetes_tag` and `openshift_release`. + +5. After each successful rebase, a message is posted to the appropriate team: +``` +*:white_check_mark: Rebase of openshift/kubernetes:{openshift_release} → {kubernetes_tag} complete* + +Branch pushed: :{branch_name} +• Kubernetes version: {old_version} → {kubernetes_tag} +• Merge conflicts: {list of files or "None"} + +_Open a PR against `openshift/kubernetes:{openshift_release}` when ready._ +``` +On rebase failure, a message containing failure details is posted instead and the next branch is rebased. + +6. A final summary is posted and permission to open a pull request for each rebase is requested. + +## Updating with `git merge` + After the initial bump as described above it is possible to update to newer released version using `git merge`. To do that follow these steps: @@ -512,26 +556,24 @@ etcd version 3.5.6 or greater required Grab newer version of etcd from https://github.com/etcd-io/etcd/releases/ and place it in `/usr/local/bin/etcd`. -## Updating with `rebase.sh` (experimental) +## Updating with `rebase.sh` -The above steps are available as a script that will merge and rebase along the happy path without automatic conflict -resolution and at the end will create a PR for you. +In the event that chai-bot fails to rebase, [rebase.sh](https://github.com/openshift/kubernetes/blob/master/openshift-hack/rebase.sh) can also be run manually. Here are the steps: -1. Create a new BugZilla with the respective OpenShift version to rebase (Target Release stays ---), - Prio&Severity to High with a proper description of the change logs. - See [BZ2021468](https://bugzilla.redhat.com/show_bug.cgi?id=2021468) as an example. +1. Create a new Jira ticket under OCPBUGS with the respective OpenShift version to rebase, + Target Backport Version to the previous minor version + .z 2. It's best to start off with a fresh fork of [openshift/kubernetes](https://github.com/openshift/kubernetes/). Stay on the master branch. -3. This script requires `jq`, `git`, `podman` and `bash`, `gh` is optional. +3. This script requires `git`, `podman` and `bash`, and optionally uses `gh` to create a pull request. 4. In the root dir of that fork run: ``` -openshift-hack/rebase.sh --k8s-tag=v1.25.2 --openshift-release=release-4.12 --bugzilla-id=2003027 +openshift-hack/rebase.sh --k8s-tag=v1.25.2 --openshift-release=release-4.12 --jira-id=OCPBUGS-90150 ``` where `k8s-tag` is the [kubernetes/kubernetes](https://github.com/kubernetes/kubernetes/) release tag, the `openshift-release` -is the OpenShift release branch in [openshift/kubernetes](https://github.com/openshift/kubernetes/) and the `bugzilla-id` is the -BugZilla ID created in step (1). +is the OpenShift release branch in [openshift/kubernetes](https://github.com/openshift/kubernetes/) and the `jira-id` is the +Jira ticket number created in step (1). 5. In case of conflicts, it will ask you to step into another shell to resolve those. The script will continue by committing the resolution with `UPSTREAM: `. 6. At the end, there will be a "rebase-$VERSION" branch pushed to your fork. -7. If you have `gh` installed and are logged in, it will attempt to create a PR for you by opening a web browser. +7. A pull request will be created with the title `$jira_id: Rebase $k8s_tag in $openshift_release` against the corresponding openshift branch. diff --git a/deps/github.com/openshift/kubernetes/openshift-hack/cmd/k8s-tests-ext/disabled_tests.go b/deps/github.com/openshift/kubernetes/openshift-hack/cmd/k8s-tests-ext/disabled_tests.go index 14b814010a..922c28647f 100644 --- a/deps/github.com/openshift/kubernetes/openshift-hack/cmd/k8s-tests-ext/disabled_tests.go +++ b/deps/github.com/openshift/kubernetes/openshift-hack/cmd/k8s-tests-ext/disabled_tests.go @@ -177,9 +177,6 @@ func filterOutDisabledSpecs(specs et.ExtensionTestSpecs) et.ExtensionTestSpecs { // https://issues.redhat.com/browse/OCPBUGS-61378 "[sig-network] Conntrack should be able to cleanup conntrack entries when UDP service target port changes for a NodePort service", - // https://redhat.atlassian.net/browse/OCPBUGS-85262 - "[sig-cli] kubectl kuberc commands", - // https://redhat.atlassian.net/browse/OCPBUGS-64847 "[sig-node] [Serial] Pod InPlace Resize Container (deferred-resizes) [FeatureGate:InPlacePodVerticalScaling] pod-resize-retry-deferred-test-2", }, diff --git a/deps/github.com/openshift/kubernetes/openshift-hack/rebase.sh b/deps/github.com/openshift/kubernetes/openshift-hack/rebase.sh index ed2fdbbed5..9db68e2274 100755 --- a/deps/github.com/openshift/kubernetes/openshift-hack/rebase.sh +++ b/deps/github.com/openshift/kubernetes/openshift-hack/rebase.sh @@ -2,7 +2,7 @@ # READ FIRST BEFORE USING THIS SCRIPT # -# This script requires jq, git, podman and bash to work properly (dependencies are checked for you). +# This script requires git, podman and bash to work properly (dependencies are checked for you). # The Github CLI "gh" is optional, but convenient to create a pull request automatically at the end. # # This script generates a git remote structure described in: @@ -11,16 +11,16 @@ # # The usage is described in /Rebase.openshift.md. -# validate input args --k8s-tag=v1.21.2 --openshift-release=release-4.8 --bugzilla-id=2003027 +# validate input args --k8s-tag=v1.21.2 --openshift-release=release-4.8 --jira-id=OCPBUGS-91759 k8s_tag="" openshift_release="" -bugzilla_id="" +jira_id="" usage() { echo "Available arguments:" echo " --k8s-tag (required) Example: --k8s-tag=v1.21.2" echo " --openshift-release (required) Example: --openshift-release=release-4.8" - echo " --bugzilla-id (optional) creates new PR against openshift/kubernetes:${openshift-release}: Example: --bugzilla-id=2003027" + echo " --jira-id (optional) Include Jira ticket in PR title: Example: --jira-id=OCPBUGS-1234" } for i in "$@"; do @@ -33,8 +33,8 @@ for i in "$@"; do openshift_release="${i#*=}" shift ;; - --bugzilla-id=*) - bugzilla_id="${i#*=}" + --jira-id=*) + jira_id="${i#*=}" shift ;; *) @@ -61,7 +61,7 @@ fi echo "Processed arguments are:" echo "--k8s_tag=${k8s_tag}" echo "--openshift_release=${openshift_release}" -echo "--bugzilla_id=${bugzilla_id}" +echo "--jira_id=${jira_id}" # prerequisites (check git, podman, ... is present) if ! command -v git &>/dev/null; then @@ -69,11 +69,6 @@ if ! command -v git &>/dev/null; then exit 1 fi -if ! command -v jq &>/dev/null; then - echo "jq not installed, exiting" - exit 1 -fi - if ! command -v podman &>/dev/null; then echo "podman not installed, exiting" exit 1 @@ -98,9 +93,13 @@ git fetch upstream --tags -f git remote add openshift git@github.com:openshift/kubernetes.git git fetch openshift -#git checkout --track "openshift/$openshift_release" +git checkout --track "openshift/$openshift_release" git pull openshift "$openshift_release" +if [ -z "$(git tag -l "$k8s_tag")" ]; then + echo "No such tag exists in upstream for: $k8s_tag" + exit 1 +fi git merge "$k8s_tag" # shellcheck disable=SC2181 if [ $? -eq 0 ]; then @@ -125,18 +124,17 @@ fi # openshift-hack/images/hyperkube/Dockerfile.rhel still has FROM pointing to old tag # we need to remove the prefix "v" from the $k8s_tag to stay compatible -sed -i -E "s/(io.openshift.build.versions=\"kubernetes=)(1.[1-9]+.[1-9]+)/\1${k8s_tag:1}/" openshift-hack/images/hyperkube/Dockerfile.rhel +podman run --rm -v "$(pwd):/workspace:Z" docker.io/library/alpine:latest \ + sed -i -E "s/(io.openshift.build.versions=\"kubernetes=)(1.[1-9]+.[1-9]+)/\1${k8s_tag:1}/" \ + /workspace/openshift-hack/images/hyperkube/Dockerfile.rhel go_mod_go_ver=$(grep -E 'go 1\.[1-9][0-9]?' go.mod | sed -E 's/go (1\.[1-9][0-9]?)/\1/' | cut -d '.' -f 1,2) # Need to handle mod versions like 1.23 and 1.23.4; our release images only have major.minor -tag="rhel-8-release-golang-${go_mod_go_ver}-openshift-${openshift_release#release-}" - -# update openshift go.mod dependencies -sed -i -E "/=>/! s/(\tgithub.com\/openshift\/[a-z|-]+) (.*)$/\1 $openshift_release/" go.mod +tag=$(grep "^ tag:" .ci-operator.yaml | head -n1 | sed -E 's/.*: (.*)/\1/') echo "> go mod tidy && hack/update-vendor.sh" -podman run -it --rm -v "$(pwd):/go/k8s.io/kubernetes:Z" \ +podman run --rm -v "$(pwd):/go/k8s.io/kubernetes:Z" \ --workdir=/go/k8s.io/kubernetes \ "registry.ci.openshift.org/openshift/release:$tag" \ - go mod tidy && hack/update-vendor.sh + /bin/bash -c "go mod tidy && hack/update-vendor.sh" # shellcheck disable=SC2181 if [ $? -ne 0 ]; then @@ -144,10 +142,26 @@ if [ $? -ne 0 ]; then exit 1 fi -podman run -it --rm -v "$(pwd):/go/k8s.io/kubernetes:Z" \ +echo "> make clean to remove stale _output directory" +podman run --rm -v "$(pwd):/go/k8s.io/kubernetes:Z" \ + --workdir=/go/k8s.io/kubernetes \ + "registry.ci.openshift.org/openshift/release:$tag" \ + make clean +# shellcheck disable=SC2181 +if [ $? -ne 0 ]; then + echo "make clean failed — check filesystem permissions on _output/" + exit 1 +fi + +podman run --rm -v "$(pwd):/go/k8s.io/kubernetes:Z" \ --workdir=/go/k8s.io/kubernetes \ "registry.ci.openshift.org/openshift/release:$tag" \ make update OS_RUN_WITHOUT_DOCKER=yes +# shellcheck disable=SC2181 +if [ $? -ne 0 ]; then + echo "make update failed" + exit 1 +fi git add -A git commit -m "UPSTREAM: : hack/update-vendor.sh, make update and update image" @@ -155,21 +169,19 @@ git commit -m "UPSTREAM: : hack/update-vendor.sh, make update and update i remote_branch="rebase-$k8s_tag" git push origin "$openshift_release:$remote_branch" -XY=$(echo "$k8s_tag" | sed -E "s/v(1\.[0-9]+)\.[0-9]+/\1/") -ver=$(echo "$k8s_tag" | sed "s/\.//g") -link="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-$XY.md#$ver" -if [ -n "${bugzilla_id}" ]; then - if command -v gh &>/dev/null; then - XY=$(echo "$k8s_tag" | sed -E "s/v(1\.[0-9]+)\.[0-9]+/\1/") - ver=$(echo "$k8s_tag" | sed "s/\.//g") - link="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-$XY.md#$ver" - - # opens a web browser, because we can't properly create PRs against remote repositories with the GH CLI (yet): - # https://github.com/cli/cli/issues/2691 - gh pr create \ - --title "Bug $bugzilla_id: Rebase $k8s_tag" \ - --body "CHANGELOG $link" \ - --web +if command -v gh &>/dev/null; then + XY=$(echo "$k8s_tag" | sed -E "s/v(1\.[0-9]+)\.[0-9]+/\1/") + ver=$(echo "$k8s_tag" | sed "s/\.//g") + link="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-$XY.md#$ver" + title="Rebase $k8s_tag in $openshift_release" + if [ -n "${jira_id}" ]; then + title="$jira_id: $title" fi + + gh pr create \ + --title "$title" \ + --body "CHANGELOG $link" \ + --base "$openshift_release" \ + --head "$remote_branch" fi diff --git a/deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/autoscaling/managementcpusoverride/admission.go b/deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/autoscaling/managementcpusoverride/admission.go index 9bf0a1f8a1..530639815a 100644 --- a/deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/autoscaling/managementcpusoverride/admission.go +++ b/deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/autoscaling/managementcpusoverride/admission.go @@ -17,7 +17,6 @@ import ( "k8s.io/apimachinery/pkg/api/errors" "k8s.io/apimachinery/pkg/api/resource" metav1 "k8s.io/apimachinery/pkg/apis/meta/v1" - "k8s.io/apimachinery/pkg/labels" "k8s.io/apimachinery/pkg/util/validation/field" "k8s.io/apiserver/pkg/admission" "k8s.io/apiserver/pkg/admission/initializer" @@ -187,16 +186,6 @@ func (a *managementCPUsOverride) Admit(ctx context.Context, attr admission.Attri return admission.NewForbidden(attr, fmt.Errorf("%s node or namespace or infra config cache not synchronized", PluginName)) } - nodes, err := a.nodeLister.List(labels.Everything()) - if err != nil { - return admission.NewForbidden(attr, err) // can happen due to informer latency - } - - // we still need to have nodes under the cluster to decide if the management resource enabled or not - if len(nodes) == 0 { - return admission.NewForbidden(attr, fmt.Errorf("%s the cluster does not have any nodes", PluginName)) - } - clusterInfra, err := a.infraConfigLister.Get(infraClusterName) if err != nil { return admission.NewForbidden(attr, err) // can happen due to informer latency @@ -215,7 +204,7 @@ func (a *managementCPUsOverride) Admit(ctx context.Context, attr admission.Attri } // Check if we are in CPU Partitioning mode for AllNodes - if !isCPUPartitioning(clusterInfra.Status, nodes, workloadType) { + if !isCPUPartitioning(clusterInfra.Status) { return nil } @@ -284,18 +273,7 @@ func (a *managementCPUsOverride) Admit(ctx context.Context, attr admission.Attri return nil } -func isCPUPartitioning(infraStatus configv1.InfrastructureStatus, nodes []*corev1.Node, workloadType string) bool { - // If status is not for CPU partitioning and we're single node we also check nodes to support upgrade event - // TODO: This should not be needed after 4.13 as all clusters after should have this feature on at install time, or updated by migration in NTO. - if infraStatus.CPUPartitioning != configv1.CPUPartitioningAllNodes && infraStatus.ControlPlaneTopology == configv1.SingleReplicaTopologyMode { - managedResource := fmt.Sprintf("%s.%s", workloadType, containerWorkloadResourceSuffix) - for _, node := range nodes { - // We only expect a single node to exist, so we return on first hit - if _, ok := node.Status.Allocatable[corev1.ResourceName(managedResource)]; ok { - return true - } - } - } +func isCPUPartitioning(infraStatus configv1.InfrastructureStatus) bool { return infraStatus.CPUPartitioning == configv1.CPUPartitioningAllNodes } diff --git a/deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/autoscaling/managementcpusoverride/admission_test.go b/deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/autoscaling/managementcpusoverride/admission_test.go index 9564bffe39..209bea8383 100644 --- a/deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/autoscaling/managementcpusoverride/admission_test.go +++ b/deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/autoscaling/managementcpusoverride/admission_test.go @@ -87,7 +87,7 @@ func TestAdmit(t *testing.T) { pod: testManagedPodWithWorkloadAnnotation("500m", "250m", "500Mi", "250Mi", "non-existent"), expectedCpuRequest: resource.MustParse("250m"), namespace: testManagedNamespace(), - nodes: []*corev1.Node{testNodeWithManagementResource()}, + nodes: []*corev1.Node{testNode()}, infra: testClusterSNOInfra(), expectedError: fmt.Errorf("the pod namespace %q does not allow the workload type non-existent", "managed-namespace"), }, @@ -96,7 +96,7 @@ func TestAdmit(t *testing.T) { pod: testPod("500m", "250m", "500Mi", "250Mi"), expectedCpuRequest: resource.MustParse("250m"), namespace: testManagedNamespace(), - nodes: []*corev1.Node{testNodeWithManagementResource()}, + nodes: []*corev1.Node{testNode()}, }, { name: "should return admission error when the pod has more than one workload annotation", @@ -112,7 +112,7 @@ func TestAdmit(t *testing.T) { ), expectedCpuRequest: resource.MustParse("250m"), namespace: testManagedNamespace(), - nodes: []*corev1.Node{testNodeWithManagementResource()}, + nodes: []*corev1.Node{testNode()}, infra: testClusterSNOInfra(), expectedError: fmt.Errorf("the pod can not have more than one workload annotations"), }, @@ -129,7 +129,7 @@ func TestAdmit(t *testing.T) { ), expectedCpuRequest: resource.MustParse("250m"), namespace: testManagedNamespace(), - nodes: []*corev1.Node{testNodeWithManagementResource()}, + nodes: []*corev1.Node{testNode()}, infra: testClusterSNOInfra(), expectedError: fmt.Errorf("the workload annotation key should have format %s", podWorkloadTargetAnnotationPrefix), }, @@ -146,7 +146,7 @@ func TestAdmit(t *testing.T) { ), expectedCpuRequest: resource.MustParse("250m"), namespace: testManagedNamespace(), - nodes: []*corev1.Node{testNodeWithManagementResource()}, + nodes: []*corev1.Node{testNode()}, infra: testClusterSNOInfra(), expectedError: fmt.Errorf(`failed to get workload annotation effect: failed to parse "{" annotation value: unexpected end of JSON input`), }, @@ -163,7 +163,7 @@ func TestAdmit(t *testing.T) { ), expectedCpuRequest: resource.MustParse("250m"), namespace: testManagedNamespace(), - nodes: []*corev1.Node{testNodeWithManagementResource()}, + nodes: []*corev1.Node{testNode()}, expectedError: fmt.Errorf(`failed to get workload annotation effect: the workload annotation value map["test":"test"] does not have "effect" key`), infra: testClusterSNOInfra(), }, @@ -183,7 +183,7 @@ func TestAdmit(t *testing.T) { workloadAdmissionWarning: "skipping pod CPUs requests modifications because the namespace namespace is not annotated with workload.openshift.io/allowed to allow workload partitioning", }, namespace: testNamespace(), - nodes: []*corev1.Node{testNodeWithManagementResource()}, + nodes: []*corev1.Node{testNode()}, infra: testClusterSNOInfra(), }, { @@ -196,7 +196,7 @@ func TestAdmit(t *testing.T) { fmt.Sprintf("%s%s", containerResourcesAnnotationPrefix, "initTest"): fmt.Sprintf(`{"%s":256}`, containerResourcesAnnotationValueKeyCPUShares), fmt.Sprintf("%s%s", podWorkloadTargetAnnotationPrefix, workloadTypeManagement): fmt.Sprintf(`{"%s":"%s"}`, podWorkloadAnnotationEffect, workloadEffectPreferredDuringScheduling), }, - nodes: []*corev1.Node{testNodeWithManagementResource()}, + nodes: []*corev1.Node{testNode()}, infra: testClusterSNOInfra(), }, { @@ -209,7 +209,7 @@ func TestAdmit(t *testing.T) { fmt.Sprintf("%s%s", containerResourcesAnnotationPrefix, "initTest"): fmt.Sprintf(`{"%s": 2}`, containerResourcesAnnotationValueKeyCPUShares), fmt.Sprintf("%s%s", podWorkloadTargetAnnotationPrefix, workloadTypeManagement): fmt.Sprintf(`{"%s":"%s"}`, podWorkloadAnnotationEffect, workloadEffectPreferredDuringScheduling), }, - nodes: []*corev1.Node{testNodeWithManagementResource()}, + nodes: []*corev1.Node{testNode()}, infra: testClusterSNOInfra(), }, { @@ -221,7 +221,7 @@ func TestAdmit(t *testing.T) { fmt.Sprintf("%s%s", podWorkloadTargetAnnotationPrefix, workloadTypeManagement): fmt.Sprintf(`{"%s":"%s"}`, podWorkloadAnnotationEffect, workloadEffectPreferredDuringScheduling), kubetypes.ConfigSourceAnnotationKey: kubetypes.FileSource, }, - nodes: []*corev1.Node{testNodeWithManagementResource()}, + nodes: []*corev1.Node{testNode()}, infra: testClusterSNOInfra(), }, { @@ -232,7 +232,7 @@ func TestAdmit(t *testing.T) { expectedAnnotations: map[string]string{ workloadAdmissionWarning: "skip pod CPUs requests modifications because it has guaranteed QoS class", }, - nodes: []*corev1.Node{testNodeWithManagementResource()}, + nodes: []*corev1.Node{testNode()}, infra: testClusterSNOInfra(), }, { @@ -245,7 +245,7 @@ func TestAdmit(t *testing.T) { fmt.Sprintf("%s%s", containerResourcesAnnotationPrefix, "initTest"): fmt.Sprintf(`{"%s":256,"cpulimit":500}`, containerResourcesAnnotationValueKeyCPUShares), fmt.Sprintf("%s%s", podWorkloadTargetAnnotationPrefix, workloadTypeManagement): fmt.Sprintf(`{"%s":"%s"}`, podWorkloadAnnotationEffect, workloadEffectPreferredDuringScheduling), }, - nodes: []*corev1.Node{testNodeWithManagementResource()}, + nodes: []*corev1.Node{testNode()}, infra: testClusterSNOInfra(), }, { @@ -256,7 +256,7 @@ func TestAdmit(t *testing.T) { expectedAnnotations: map[string]string{ workloadAdmissionWarning: fmt.Sprintf("skip pod CPUs requests modifications because it will change the pod QoS class from %s to %s", corev1.PodQOSBurstable, corev1.PodQOSBestEffort), }, - nodes: []*corev1.Node{testNodeWithManagementResource()}, + nodes: []*corev1.Node{testNode()}, infra: testClusterSNOInfra(), }, { @@ -267,15 +267,6 @@ func TestAdmit(t *testing.T) { nodes: []*corev1.Node{testNode()}, infra: testClusterInfraWithoutWorkloadPartitioning(), }, - { - name: "should return admission error when the cluster does not have any nodes", - pod: testManagedPod("500m", "250m", "500Mi", "250Mi"), - expectedCpuRequest: resource.MustParse("250m"), - namespace: testManagedNamespace(), - nodes: []*corev1.Node{}, - infra: testClusterSNOInfra(), - expectedError: fmt.Errorf("the cluster does not have any nodes"), - }, } for _, test := range tests { diff --git a/deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/scheduler/nodeselectoradjuster/admission.go b/deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/scheduler/nodeselectoradjuster/admission.go index 9fa7770e9f..06a24fee8e 100644 --- a/deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/scheduler/nodeselectoradjuster/admission.go +++ b/deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/scheduler/nodeselectoradjuster/admission.go @@ -32,6 +32,19 @@ const ( // vpaOperatorNamespace is the namespace the VPA operator is expected to run in. vpaOperatorNamespace = "openshift-vertical-pod-autoscaler" + // croOperatorLabelKey / croOperatorLabelValue identify the CRO operator pod. + croOperatorLabelKey = "clusterresourceoverride.operator" + croOperatorLabelValue = "true" + // croOperatorNamespace is the namespace the CRO operator is expected to run in. + croOperatorNamespace = "openshift-cluster-resource-override" + + // cmaOperatorLabelKey / cmaOperatorLabelValue identify the CMA operator pod. + cmaOperatorLabelKey = "name" + cmaOperatorLabelValue = "custom-metrics-autoscaler-operator" + + // cmaOperatorNamespace is the namespace the CMA operator is expected to run in. + cmaOperatorNamespace = "openshift-keda" + // standaloneEnvVar is the environment variable checked at start-up. // It is injected by the downward API and reflects the namespace the // kube-apiserver pod runs in. @@ -93,16 +106,58 @@ func (p *nodeSelectorAdjuster) ValidateInitialization() error { // requiresNodeSelectorAdjustment returns true when the pod carries a label that // opts it in to control-plane node placement and lives in a namespace where that -// label is expected. Currently the VPA operator pod opts in via its well-known -// label. Future control-plane-adjacent Day 2 operators can be added here. +// label is expected. Control-plane-adjacent Day 2 operators can be added here. func requiresNodeSelectorAdjustment(pod *coreapi.Pod) bool { + // for VPA, we only want to update if the node selector is the default from + // https://github.com/openshift/vertical-pod-autoscaler-operator/blob/main/config/manager/manager.yaml if pod.Labels[vpaOperatorLabelKey] == vpaOperatorLabelValue && - pod.Namespace == vpaOperatorNamespace { + pod.Namespace == vpaOperatorNamespace && len(pod.Spec.NodeSelector) == 1 && + pod.Spec.NodeSelector["kubernetes.io/os"] == "linux" { return true } + // for CRO, we only want to update if the node selector empty + if pod.Labels[croOperatorLabelKey] == croOperatorLabelValue && + pod.Namespace == croOperatorNamespace && len(pod.Spec.NodeSelector) == 0 { + return true + } + // for CMA, we want to update if the node selector is empty + // and if it has a toleration that would tolerate the master NoSchedule taint + if pod.Labels[cmaOperatorLabelKey] == cmaOperatorLabelValue && + pod.Namespace == cmaOperatorNamespace && len(pod.Spec.NodeSelector) == 0 { + masterTaint := coreapi.Taint{ + Key: "node-role.kubernetes.io/master", + Effect: coreapi.TaintEffectNoSchedule, + } + for _, tol := range pod.Spec.Tolerations { + if toleratesTaint(tol, masterTaint) { + return true + } + } + } return false } +// toleratesTaint checks if a toleration tolerates a given taint, following the +// same rules as corev1.Toleration.ToleratesTaint: an empty effect matches all +// effects, the Exists operator matches any value, and an empty key with Exists +// matches all keys. +func toleratesTaint(tol coreapi.Toleration, taint coreapi.Taint) bool { + if len(tol.Effect) > 0 && tol.Effect != taint.Effect { + return false + } + if len(tol.Key) > 0 && tol.Key != taint.Key { + return false + } + switch tol.Operator { + case "", coreapi.TolerationOpEqual: + return tol.Value == taint.Value + case coreapi.TolerationOpExists: + return true + default: + return false + } +} + // addControlPlaneNodeSelector ensures spec.nodeSelector contains the control-plane role key. func addControlPlaneNodeSelector(pod *coreapi.Pod) { if pod.Spec.NodeSelector == nil { diff --git a/deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/scheduler/nodeselectoradjuster/admission_test.go b/deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/scheduler/nodeselectoradjuster/admission_test.go index 630616f343..38d5a1a360 100644 --- a/deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/scheduler/nodeselectoradjuster/admission_test.go +++ b/deps/github.com/openshift/kubernetes/openshift-kube-apiserver/admission/scheduler/nodeselectoradjuster/admission_test.go @@ -20,29 +20,52 @@ func TestAdmit(t *testing.T) { expectedNodeSelector map[string]string }{ { - name: "VPA operator pod: control-plane node selector is added", + name: "VPA operator pod with default node selector: control-plane node selector is added", + pod: makePod( + withNamespace(vpaOperatorNamespace), + withLabels(map[string]string{vpaOperatorLabelKey: vpaOperatorLabelValue}), + withNodeSelector(map[string]string{"kubernetes.io/os": "linux"}), + ), + resource: coreapi.Resource("pods").WithVersion("v1"), + expectedNodeSelector: map[string]string{ + controlPlaneRoleKey: "", + "kubernetes.io/os": "linux", + }, + }, + { + name: "VPA operator pod with no node selector: not modified", pod: makePod( withNamespace(vpaOperatorNamespace), withLabels(map[string]string{vpaOperatorLabelKey: vpaOperatorLabelValue}), ), resource: coreapi.Resource("pods").WithVersion("v1"), - expectedNodeSelector: map[string]string{controlPlaneRoleKey: ""}, + expectedNodeSelector: nil, }, { - name: "VPA operator pod: control-plane node selector added alongside existing selectors", + name: "VPA operator pod with non-default node selector: not modified", pod: makePod( withNamespace(vpaOperatorNamespace), withLabels(map[string]string{vpaOperatorLabelKey: vpaOperatorLabelValue}), withNodeSelector(map[string]string{"topology.kubernetes.io/zone": "us-east-1a"}), ), + resource: coreapi.Resource("pods").WithVersion("v1"), + expectedNodeSelector: map[string]string{"topology.kubernetes.io/zone": "us-east-1a"}, + }, + { + name: "VPA operator pod with extra node selectors: not modified", + pod: makePod( + withNamespace(vpaOperatorNamespace), + withLabels(map[string]string{vpaOperatorLabelKey: vpaOperatorLabelValue}), + withNodeSelector(map[string]string{"kubernetes.io/os": "linux", "topology.kubernetes.io/zone": "us-east-1a"}), + ), resource: coreapi.Resource("pods").WithVersion("v1"), expectedNodeSelector: map[string]string{ - controlPlaneRoleKey: "", + "kubernetes.io/os": "linux", "topology.kubernetes.io/zone": "us-east-1a", }, }, { - name: "VPA operator pod: control-plane node selector already present is left unchanged", + name: "VPA operator pod with control-plane selector already present: not modified", pod: makePod( withNamespace(vpaOperatorNamespace), withLabels(map[string]string{vpaOperatorLabelKey: vpaOperatorLabelValue}), @@ -51,6 +74,125 @@ func TestAdmit(t *testing.T) { resource: coreapi.Resource("pods").WithVersion("v1"), expectedNodeSelector: map[string]string{controlPlaneRoleKey: ""}, }, + { + name: "CRO operator pod with no node selector: control-plane node selector is added", + pod: makePod( + withNamespace(croOperatorNamespace), + withLabels(map[string]string{croOperatorLabelKey: croOperatorLabelValue}), + ), + resource: coreapi.Resource("pods").WithVersion("v1"), + expectedNodeSelector: map[string]string{controlPlaneRoleKey: ""}, + }, + { + name: "CRO operator pod with existing node selector: not modified", + pod: makePod( + withNamespace(croOperatorNamespace), + withLabels(map[string]string{croOperatorLabelKey: croOperatorLabelValue}), + withNodeSelector(map[string]string{"kubernetes.io/os": "linux"}), + ), + resource: coreapi.Resource("pods").WithVersion("v1"), + expectedNodeSelector: map[string]string{"kubernetes.io/os": "linux"}, + }, + { + name: "CRO operator pod in wrong namespace: not modified", + pod: makePod( + withNamespace("other-namespace"), + withLabels(map[string]string{croOperatorLabelKey: croOperatorLabelValue}), + ), + resource: coreapi.Resource("pods").WithVersion("v1"), + expectedNodeSelector: nil, + }, + { + name: "CRO operator label with wrong value: not modified", + pod: makePod( + withNamespace(croOperatorNamespace), + withLabels(map[string]string{croOperatorLabelKey: "false"}), + ), + resource: coreapi.Resource("pods").WithVersion("v1"), + expectedNodeSelector: nil, + }, + { + name: "CMA operator pod with master toleration: control-plane node selector is added", + pod: makePod( + withNamespace(cmaOperatorNamespace), + withLabels(map[string]string{cmaOperatorLabelKey: cmaOperatorLabelValue}), + withTolerations([]coreapi.Toleration{ + {Key: "node-role.kubernetes.io/master", Effect: coreapi.TaintEffectNoSchedule, Operator: coreapi.TolerationOpExists}, + }), + ), + resource: coreapi.Resource("pods").WithVersion("v1"), + expectedNodeSelector: map[string]string{controlPlaneRoleKey: ""}, + }, + { + name: "CMA operator pod with broad tolerate-all toleration: control-plane node selector is added", + pod: makePod( + withNamespace(cmaOperatorNamespace), + withLabels(map[string]string{cmaOperatorLabelKey: cmaOperatorLabelValue}), + withTolerations([]coreapi.Toleration{ + {Operator: coreapi.TolerationOpExists}, + }), + ), + resource: coreapi.Resource("pods").WithVersion("v1"), + expectedNodeSelector: map[string]string{controlPlaneRoleKey: ""}, + }, + { + name: "CMA operator pod without master toleration: not modified", + pod: makePod( + withNamespace(cmaOperatorNamespace), + withLabels(map[string]string{cmaOperatorLabelKey: cmaOperatorLabelValue}), + ), + resource: coreapi.Resource("pods").WithVersion("v1"), + expectedNodeSelector: nil, + }, + { + name: "CMA operator pod with wrong toleration key: not modified", + pod: makePod( + withNamespace(cmaOperatorNamespace), + withLabels(map[string]string{cmaOperatorLabelKey: cmaOperatorLabelValue}), + withTolerations([]coreapi.Toleration{ + {Key: "node-role.kubernetes.io/control-plane", Effect: coreapi.TaintEffectNoSchedule, Operator: coreapi.TolerationOpExists}, + }), + ), + resource: coreapi.Resource("pods").WithVersion("v1"), + expectedNodeSelector: nil, + }, + { + name: "CMA operator pod with existing node selector: not modified", + pod: makePod( + withNamespace(cmaOperatorNamespace), + withLabels(map[string]string{cmaOperatorLabelKey: cmaOperatorLabelValue}), + withNodeSelector(map[string]string{"kubernetes.io/os": "linux"}), + withTolerations([]coreapi.Toleration{ + {Key: "node-role.kubernetes.io/master", Effect: coreapi.TaintEffectNoSchedule, Operator: coreapi.TolerationOpExists}, + }), + ), + resource: coreapi.Resource("pods").WithVersion("v1"), + expectedNodeSelector: map[string]string{"kubernetes.io/os": "linux"}, + }, + { + name: "CMA operator pod in wrong namespace: not modified", + pod: makePod( + withNamespace("other-namespace"), + withLabels(map[string]string{cmaOperatorLabelKey: cmaOperatorLabelValue}), + withTolerations([]coreapi.Toleration{ + {Key: "node-role.kubernetes.io/master", Effect: coreapi.TaintEffectNoSchedule, Operator: coreapi.TolerationOpExists}, + }), + ), + resource: coreapi.Resource("pods").WithVersion("v1"), + expectedNodeSelector: nil, + }, + { + name: "CMA operator label with wrong value: not modified", + pod: makePod( + withNamespace(cmaOperatorNamespace), + withLabels(map[string]string{cmaOperatorLabelKey: "wrong-operator"}), + withTolerations([]coreapi.Toleration{ + {Key: "node-role.kubernetes.io/master", Effect: coreapi.TaintEffectNoSchedule, Operator: coreapi.TolerationOpExists}, + }), + ), + resource: coreapi.Resource("pods").WithVersion("v1"), + expectedNodeSelector: nil, + }, { name: "non-qualifying pod: not modified", pod: makePod( @@ -148,13 +290,102 @@ func TestRequiresNodeSelectorAdjustment(t *testing.T) { expected bool }{ { - name: "VPA operator label in correct namespace: match", + name: "VPA operator with default node selector: match", + pod: makePod(withNamespace(vpaOperatorNamespace), withLabels(map[string]string{vpaOperatorLabelKey: vpaOperatorLabelValue}), withNodeSelector(map[string]string{"kubernetes.io/os": "linux"})), + expected: true, + }, + { + name: "VPA operator with no node selector: no match", pod: makePod(withNamespace(vpaOperatorNamespace), withLabels(map[string]string{vpaOperatorLabelKey: vpaOperatorLabelValue})), + expected: false, + }, + { + name: "VPA operator with non-default node selector: no match", + pod: makePod(withNamespace(vpaOperatorNamespace), withLabels(map[string]string{vpaOperatorLabelKey: vpaOperatorLabelValue}), withNodeSelector(map[string]string{"topology.kubernetes.io/zone": "us-east-1a"})), + expected: false, + }, + { + name: "VPA operator with extra node selectors: no match", + pod: makePod(withNamespace(vpaOperatorNamespace), withLabels(map[string]string{vpaOperatorLabelKey: vpaOperatorLabelValue}), withNodeSelector(map[string]string{"kubernetes.io/os": "linux", "extra": "value"})), + expected: false, + }, + { + name: "VPA operator in wrong namespace: no match", + pod: makePod(withNamespace("other-namespace"), withLabels(map[string]string{vpaOperatorLabelKey: vpaOperatorLabelValue}), withNodeSelector(map[string]string{"kubernetes.io/os": "linux"})), + expected: false, + }, + { + name: "CRO operator with no node selector: match", + pod: makePod(withNamespace(croOperatorNamespace), withLabels(map[string]string{croOperatorLabelKey: croOperatorLabelValue})), + expected: true, + }, + { + name: "CRO operator with existing node selector: no match", + pod: makePod(withNamespace(croOperatorNamespace), withLabels(map[string]string{croOperatorLabelKey: croOperatorLabelValue}), withNodeSelector(map[string]string{"kubernetes.io/os": "linux"})), + expected: false, + }, + { + name: "CRO operator in wrong namespace: no match", + pod: makePod(withNamespace("other-namespace"), withLabels(map[string]string{croOperatorLabelKey: croOperatorLabelValue})), + expected: false, + }, + { + name: "CRO operator label with wrong value: no match", + pod: makePod(withNamespace(croOperatorNamespace), withLabels(map[string]string{croOperatorLabelKey: "false"})), + expected: false, + }, + { + name: "CMA operator with master toleration: match", + pod: makePod(withNamespace(cmaOperatorNamespace), withLabels(map[string]string{cmaOperatorLabelKey: cmaOperatorLabelValue}), + withTolerations([]coreapi.Toleration{ + {Key: "node-role.kubernetes.io/master", Effect: coreapi.TaintEffectNoSchedule, Operator: coreapi.TolerationOpExists}, + })), + expected: true, + }, + { + name: "CMA operator with broad tolerate-all toleration: match", + pod: makePod(withNamespace(cmaOperatorNamespace), withLabels(map[string]string{cmaOperatorLabelKey: cmaOperatorLabelValue}), + withTolerations([]coreapi.Toleration{ + {Operator: coreapi.TolerationOpExists}, + })), expected: true, }, { - name: "VPA operator label in wrong namespace: no match", - pod: makePod(withNamespace("other-namespace"), withLabels(map[string]string{vpaOperatorLabelKey: vpaOperatorLabelValue})), + name: "CMA operator without master toleration: no match", + pod: makePod(withNamespace(cmaOperatorNamespace), withLabels(map[string]string{cmaOperatorLabelKey: cmaOperatorLabelValue})), + expected: false, + }, + { + name: "CMA operator with wrong toleration key: no match", + pod: makePod(withNamespace(cmaOperatorNamespace), withLabels(map[string]string{cmaOperatorLabelKey: cmaOperatorLabelValue}), + withTolerations([]coreapi.Toleration{ + {Key: "node-role.kubernetes.io/control-plane", Effect: coreapi.TaintEffectNoSchedule, Operator: coreapi.TolerationOpExists}, + })), + expected: false, + }, + { + name: "CMA operator with existing node selector: no match", + pod: makePod(withNamespace(cmaOperatorNamespace), withLabels(map[string]string{cmaOperatorLabelKey: cmaOperatorLabelValue}), + withNodeSelector(map[string]string{"kubernetes.io/os": "linux"}), + withTolerations([]coreapi.Toleration{ + {Key: "node-role.kubernetes.io/master", Effect: coreapi.TaintEffectNoSchedule, Operator: coreapi.TolerationOpExists}, + })), + expected: false, + }, + { + name: "CMA operator in wrong namespace: no match", + pod: makePod(withNamespace("other-namespace"), withLabels(map[string]string{cmaOperatorLabelKey: cmaOperatorLabelValue}), + withTolerations([]coreapi.Toleration{ + {Key: "node-role.kubernetes.io/master", Effect: coreapi.TaintEffectNoSchedule, Operator: coreapi.TolerationOpExists}, + })), + expected: false, + }, + { + name: "CMA operator label with wrong value: no match", + pod: makePod(withNamespace(cmaOperatorNamespace), withLabels(map[string]string{cmaOperatorLabelKey: "wrong-operator"}), + withTolerations([]coreapi.Toleration{ + {Key: "node-role.kubernetes.io/master", Effect: coreapi.TaintEffectNoSchedule, Operator: coreapi.TolerationOpExists}, + })), expected: false, }, { @@ -244,6 +475,12 @@ func withLabels(labels map[string]string) func(*coreapi.Pod) { } } +func withTolerations(tolerations []coreapi.Toleration) func(*coreapi.Pod) { + return func(p *coreapi.Pod) { + p.Spec.Tolerations = tolerations + } +} + func withNodeSelector(selector map[string]string) func(*coreapi.Pod) { return func(p *coreapi.Pod) { p.Spec.NodeSelector = selector diff --git a/deps/github.com/openshift/kubernetes/pkg/controller/volume/selinuxwarning/cache/openshift_patch.go b/deps/github.com/openshift/kubernetes/pkg/controller/volume/selinuxwarning/cache/openshift_patch.go new file mode 100644 index 0000000000..d0c66ab8de --- /dev/null +++ b/deps/github.com/openshift/kubernetes/pkg/controller/volume/selinuxwarning/cache/openshift_patch.go @@ -0,0 +1,18 @@ +package cache + +type ConflictCounter interface { + GetConflictCount() int +} + +var _ ConflictCounter = &volumeCache{} + +func (c *volumeCache) GetConflictCount() int { + c.mutex.RLock() + defer c.mutex.RUnlock() + + conflictCount := 0 + for _, conflicts := range c.conflicts { + conflictCount += len(conflicts) + } + return conflictCount +} diff --git a/deps/github.com/openshift/kubernetes/pkg/controller/volume/selinuxwarning/openshift_upgrade_controller.go b/deps/github.com/openshift/kubernetes/pkg/controller/volume/selinuxwarning/openshift_upgrade_controller.go new file mode 100644 index 0000000000..39eeb9853c --- /dev/null +++ b/deps/github.com/openshift/kubernetes/pkg/controller/volume/selinuxwarning/openshift_upgrade_controller.go @@ -0,0 +1,102 @@ +package selinuxwarning + +import ( + "context" + "fmt" + "time" + + metav1 "k8s.io/apimachinery/pkg/apis/meta/v1" + utilfeature "k8s.io/apiserver/pkg/util/feature" + applyconfigurationscorev1 "k8s.io/client-go/applyconfigurations/core/v1" + clientset "k8s.io/client-go/kubernetes" + "k8s.io/klog/v2" + "k8s.io/kubernetes/pkg/controller/volume/selinuxwarning/cache" + "k8s.io/kubernetes/pkg/features" +) + +const ( + checkInterval = 30 * time.Second + configMapNamespace = "openshift-config" + configMapName = "selinux-conflicts" + fieldManager = "selinux-conflicts-reporter" +) + +type SELinuxConflictsReporterController struct { + kubeClient clientset.Interface + conflictCounter cache.ConflictCounter + previousConflicts metav1.ConditionStatus +} + +func NewSELinuxConflictsReporterController(kubeClient clientset.Interface, volumeCache cache.VolumeCache) *SELinuxConflictsReporterController { + return &SELinuxConflictsReporterController{ + kubeClient: kubeClient, + // Ugly retype to avoid more carry patches in Kubernetes code. + // We added ConflictCounter in cache/openshift_patch.go, + // therefore we know that VolumeCache implements it. + conflictCounter: volumeCache.(cache.ConflictCounter), + previousConflicts: metav1.ConditionUnknown, + } +} + +func (c *SELinuxConflictsReporterController) Run(ctx context.Context) { + logger := klog.FromContext(ctx) + if !utilfeature.DefaultFeatureGate.Enabled(features.SELinuxMountGAReadiness) { + logger.V(2).Info("SELinuxMountGAReadiness feature gate is disabled, not starting OpenShift SELinux conflicts reporter") + return + } + logger.V(2).Info("Starting OpenShift SELinux conflicts reporter") + timer := time.NewTimer(checkInterval) + defer timer.Stop() + for { + select { + case <-ctx.Done(): + return + case <-timer.C: + c.reportSELinuxConflicts(ctx) + timer.Reset(checkInterval) + } + } +} + +func (c *SELinuxConflictsReporterController) reportSELinuxConflicts(ctx context.Context) { + logger := klog.FromContext(ctx) + logger.V(4).Info("Checking for SELinux conflicts") + + currentConflicts := c.getConflicts(logger) + if currentConflicts == c.previousConflicts { + logger.V(4).Info("SELinux conflict status did not change since last check") + return + } + logger.V(4).Info("SELinux conflict status changed, updating the config map") + if err := c.applySELinuxConflictsConfigMap(ctx, currentConflicts); err != nil { + logger.Error(err, "Error saving conflicts config map") + // To keep it simple: no exponential backoff try again in the next iteration. + return + } + logger.V(2).Info("SELinux conflict updated", "Conflicts", currentConflicts) + c.previousConflicts = currentConflicts +} + +func (c *SELinuxConflictsReporterController) getConflicts(logger klog.Logger) metav1.ConditionStatus { + conflictsCount := c.conflictCounter.GetConflictCount() + if conflictsCount > 0 { + logger.V(4).Info("Found SELinux-conflicting pods", "conflictsCount", conflictsCount) + return metav1.ConditionTrue + } + logger.V(4).Info("Found no SELinux-conflicting pods") + return metav1.ConditionFalse +} + +func (c *SELinuxConflictsReporterController) applySELinuxConflictsConfigMap(ctx context.Context, conflictsPresent metav1.ConditionStatus) error { + cm := applyconfigurationscorev1.ConfigMap(configMapName, configMapNamespace). + WithData(map[string]string{ + "conflictsPresent": string(conflictsPresent), + }).WithAnnotations(map[string]string{ + "Description": "This config map is used to report presence of SELinux conflicts from kube-controller-manager to storage Upgradeable condition in OpenShift 5.0", + }) + _, err := c.kubeClient.CoreV1().ConfigMaps(configMapNamespace).Apply(ctx, cm, metav1.ApplyOptions{FieldManager: fieldManager, Force: true}) + if err != nil { + return fmt.Errorf("error applying config map %s: %w", configMapName, err) + } + return nil +} diff --git a/deps/github.com/openshift/kubernetes/pkg/controller/volume/selinuxwarning/openshift_upgrade_controller_test.go b/deps/github.com/openshift/kubernetes/pkg/controller/volume/selinuxwarning/openshift_upgrade_controller_test.go new file mode 100644 index 0000000000..c0a78104ac --- /dev/null +++ b/deps/github.com/openshift/kubernetes/pkg/controller/volume/selinuxwarning/openshift_upgrade_controller_test.go @@ -0,0 +1,336 @@ +package selinuxwarning + +import ( + "context" + "testing" + + v1 "k8s.io/api/core/v1" + apierrors "k8s.io/apimachinery/pkg/api/errors" + metav1 "k8s.io/apimachinery/pkg/apis/meta/v1" + "k8s.io/client-go/kubernetes/fake" + "k8s.io/client-go/tools/cache" + "k8s.io/klog/v2/ktesting" + volumecache "k8s.io/kubernetes/pkg/controller/volume/selinuxwarning/cache" +) + +var _ volumecache.ConflictCounter = &fakeVolumeCache{} + +func (f *fakeVolumeCache) GetConflictCount() int { + count := 0 + for _, conflicts := range f.conflictsToSend { + count += len(conflicts) + } + return count +} + +func TestReportSELinuxConflicts(t *testing.T) { + cmTrue := &v1.ConfigMap{ + ObjectMeta: metav1.ObjectMeta{ + Name: configMapName, + Namespace: configMapNamespace, + }, + Data: map[string]string{ + "conflictsPresent": "True", + }, + } + cmFalse := &v1.ConfigMap{ + ObjectMeta: metav1.ObjectMeta{ + Name: configMapName, + Namespace: configMapNamespace, + }, + Data: map[string]string{ + "conflictsPresent": "False", + }, + } + tests := []struct { + name string + conflicts map[cache.ObjectName][]volumecache.Conflict + initialConflict metav1.ConditionStatus + // If set, the ConfigMap already exists before the test runs. + existingConfigMap *v1.ConfigMap + + expectConfigMapData map[string]string + // If true, no ConfigMap write is expected (status didn't change). + expectNoWrite bool + }{ + { + name: "no conflicts, create the config map", + initialConflict: metav1.ConditionUnknown, + conflicts: nil, + expectConfigMapData: map[string]string{ + "conflictsPresent": "False", + }, + }, + { + name: "conflicts present, create the config map", + initialConflict: metav1.ConditionUnknown, + conflicts: map[cache.ObjectName][]volumecache.Conflict{ + {Namespace: "ns1", Name: "pod1"}: { + { + PropertyName: "SELinuxLabel", + EventReason: "SELinuxLabelConflict", + Pod: cache.ObjectName{Namespace: "ns1", Name: "pod1"}, + PropertyValue: ":::s0:c1,c2", + OtherPod: cache.ObjectName{Namespace: "ns1", Name: "pod2"}, + OtherPropertyValue: ":::s0:c98,c99", + }, + }, + }, + expectConfigMapData: map[string]string{ + "conflictsPresent": "True", + }, + }, + { + name: "no conflicts, status was already False", + conflicts: nil, + initialConflict: metav1.ConditionFalse, + existingConfigMap: cmFalse, + expectNoWrite: true, + }, + { + name: "conflicts present, status was already True", + conflicts: map[cache.ObjectName][]volumecache.Conflict{ + {Namespace: "ns1", Name: "pod1"}: { + { + PropertyName: "SELinuxLabel", + EventReason: "SELinuxLabelConflict", + }, + }, + }, + initialConflict: metav1.ConditionTrue, + existingConfigMap: cmTrue, + expectNoWrite: true, + }, + { + name: "no conflicts, status changes from True to False", + conflicts: nil, + initialConflict: metav1.ConditionTrue, + existingConfigMap: cmTrue, + expectConfigMapData: map[string]string{ + "conflictsPresent": "False", + }, + }, + { + name: "conflicts appear, status changes from False to True", + conflicts: map[cache.ObjectName][]volumecache.Conflict{ + {Namespace: "ns1", Name: "pod1"}: { + { + PropertyName: "SELinuxLabel", + EventReason: "SELinuxLabelConflict", + }, + }, + }, + initialConflict: metav1.ConditionFalse, + existingConfigMap: cmFalse, + expectConfigMapData: map[string]string{ + "conflictsPresent": "True", + }, + }, + } + + for _, tt := range tests { + t.Run(tt.name, func(t *testing.T) { + _, ctx := ktesting.NewTestContext(t) + + var fakeClient *fake.Clientset + if tt.existingConfigMap != nil { + fakeClient = fake.NewClientset(tt.existingConfigMap) + } else { + fakeClient = fake.NewClientset() + } + + labelCache := &fakeVolumeCache{ + conflictsToSend: tt.conflicts, + } + + c := &SELinuxConflictsReporterController{ + kubeClient: fakeClient, + conflictCounter: labelCache, + previousConflicts: tt.initialConflict, + } + + c.reportSELinuxConflicts(ctx) + + if tt.expectNoWrite { + cm, err := fakeClient.CoreV1().ConfigMaps(configMapNamespace).Get(ctx, configMapName, metav1.GetOptions{}) + if tt.existingConfigMap != nil { + // The ConfigMap should still exist unchanged. + if err != nil { + t.Fatalf("expected ConfigMap to exist, got error: %v", err) + } + if cm.Data["conflictsPresent"] != tt.existingConfigMap.Data["conflictsPresent"] { + t.Errorf("ConfigMap data changed unexpectedly: got %v, want %v", cm.Data, tt.existingConfigMap.Data) + } + } else { + if err == nil || !apierrors.IsNotFound(err) { + t.Fatalf("expected ConfigMap to not exist, got error: %v", err) + } + } + return + } + + cm, err := fakeClient.CoreV1().ConfigMaps(configMapNamespace).Get(ctx, configMapName, metav1.GetOptions{}) + if err != nil { + t.Fatalf("failed to get ConfigMap: %v", err) + } + for key, expectedValue := range tt.expectConfigMapData { + if cm.Data[key] != expectedValue { + t.Errorf("ConfigMap data[%q] = %q, want %q", key, cm.Data[key], expectedValue) + } + } + }) + } +} + +func TestApplySELinuxConflictsConfigMap(t *testing.T) { + cmTrue := &v1.ConfigMap{ + ObjectMeta: metav1.ObjectMeta{ + Name: configMapName, + Namespace: configMapNamespace, + }, + Data: map[string]string{ + "conflictsPresent": "True", + }, + } + cmFalse := &v1.ConfigMap{ + ObjectMeta: metav1.ObjectMeta{ + Name: configMapName, + Namespace: configMapNamespace, + }, + Data: map[string]string{ + "conflictsPresent": "False", + }, + } + tests := []struct { + name string + existingConfigMap *v1.ConfigMap + conflictsPresent metav1.ConditionStatus + expectData map[string]string + }{ + { + name: "creates ConfigMap when it does not exist", + conflictsPresent: metav1.ConditionTrue, + expectData: map[string]string{ + "conflictsPresent": "True", + }, + }, + { + name: "patches ConfigMap when it already exists", + existingConfigMap: cmFalse, + conflictsPresent: metav1.ConditionTrue, + expectData: map[string]string{ + "conflictsPresent": string(metav1.ConditionTrue), + }, + }, + { + name: "patches ConfigMap from True to False", + existingConfigMap: cmTrue, + conflictsPresent: metav1.ConditionFalse, + expectData: map[string]string{ + "conflictsPresent": "False", + }, + }, + } + + for _, tt := range tests { + t.Run(tt.name, func(t *testing.T) { + ctx := context.Background() + + var fakeClient *fake.Clientset + if tt.existingConfigMap != nil { + fakeClient = fake.NewClientset(tt.existingConfigMap) + } else { + fakeClient = fake.NewClientset() + } + + c := &SELinuxConflictsReporterController{ + kubeClient: fakeClient, + // the rest of the struct is not used in this test + } + + err := c.applySELinuxConflictsConfigMap(ctx, tt.conflictsPresent) + if err != nil { + t.Fatalf("unexpected error: %v", err) + } + + cm, err := fakeClient.CoreV1().ConfigMaps(configMapNamespace).Get(ctx, configMapName, metav1.GetOptions{}) + if err != nil { + t.Fatalf("failed to get ConfigMap: %v", err) + } + for key, expectedValue := range tt.expectData { + if cm.Data[key] != expectedValue { + t.Errorf("ConfigMap data[%q] = %q, want %q", key, cm.Data[key], expectedValue) + } + } + }) + } +} + +func TestGetConflicts(t *testing.T) { + tests := []struct { + name string + conflicts map[cache.ObjectName][]volumecache.Conflict + expected metav1.ConditionStatus + }{ + { + name: "no conflicts returns False", + conflicts: nil, + expected: metav1.ConditionFalse, + }, + { + name: "empty conflicts returns False", + conflicts: map[cache.ObjectName][]volumecache.Conflict{}, + expected: metav1.ConditionFalse, + }, + { + name: "one conflict returns True", + conflicts: map[cache.ObjectName][]volumecache.Conflict{ + {Namespace: "ns1", Name: "pod1"}: { + { + PropertyName: "SELinuxLabel", + EventReason: "SELinuxLabelConflict", + Pod: cache.ObjectName{Namespace: "ns1", Name: "pod1"}, + PropertyValue: ":::s0:c1,c2", + OtherPod: cache.ObjectName{Namespace: "ns1", Name: "pod2"}, + OtherPropertyValue: ":::s0:c98,c99", + }, + }, + }, + expected: metav1.ConditionTrue, + }, + { + name: "multiple conflicts returns True", + conflicts: map[cache.ObjectName][]volumecache.Conflict{ + {Namespace: "ns1", Name: "pod1"}: { + {PropertyName: "SELinuxLabel"}, + }, + {Namespace: "ns1", Name: "pod2"}: { + {PropertyName: "SELinuxLabel"}, + {PropertyName: "SELinuxChangePolicy"}, + }, + }, + expected: metav1.ConditionTrue, + }, + } + + for _, tt := range tests { + t.Run(tt.name, func(t *testing.T) { + _, ctx := ktesting.NewTestContext(t) + logger := ktesting.NewLogger(t, ktesting.NewConfig()) + _ = ctx + + labelCache := &fakeVolumeCache{ + conflictsToSend: tt.conflicts, + } + + c := &SELinuxConflictsReporterController{ + conflictCounter: labelCache, + } + + got := c.getConflicts(logger) + if got != tt.expected { + t.Errorf("getConflicts() = %v, want %v", got, tt.expected) + } + }) + } +} diff --git a/deps/github.com/openshift/kubernetes/pkg/controller/volume/selinuxwarning/selinux_warning_controller.go b/deps/github.com/openshift/kubernetes/pkg/controller/volume/selinuxwarning/selinux_warning_controller.go index 53c08d1f6a..488a19161d 100644 --- a/deps/github.com/openshift/kubernetes/pkg/controller/volume/selinuxwarning/selinux_warning_controller.go +++ b/deps/github.com/openshift/kubernetes/pkg/controller/volume/selinuxwarning/selinux_warning_controller.go @@ -380,6 +380,13 @@ func (c *Controller) Run(ctx context.Context, workers int) { wait.UntilWithContext(ctx, c.runWorker, time.Second) }) } + + seLinuxConflictsReporterController := NewSELinuxConflictsReporterController(c.kubeClient, c.labelCache) + wg.Go(func() { + defer utilruntime.HandleCrash() + seLinuxConflictsReporterController.Run(ctx) + }) + <-ctx.Done() } diff --git a/deps/github.com/openshift/kubernetes/pkg/features/openshift_features.go b/deps/github.com/openshift/kubernetes/pkg/features/openshift_features.go index 434781ba97..b09d7fe484 100644 --- a/deps/github.com/openshift/kubernetes/pkg/features/openshift_features.go +++ b/deps/github.com/openshift/kubernetes/pkg/features/openshift_features.go @@ -9,6 +9,7 @@ var ( RouteExternalCertificate featuregate.Feature = "RouteExternalCertificate" MinimumKubeletVersion featuregate.Feature = "MinimumKubeletVersion" StoragePerformantSecurityPolicy featuregate.Feature = "StoragePerformantSecurityPolicy" + SELinuxMountGAReadiness featuregate.Feature = "SELinuxMountGAReadiness" ) // registerOpenshiftFeatures injects openshift-specific feature gates @@ -25,8 +26,13 @@ func registerOpenshiftFeatures() { defaultVersionedKubernetesFeatureGates[StoragePerformantSecurityPolicy] = featuregate.VersionedSpecs{ {Version: version.MustParse("1.33"), Default: false, PreRelease: featuregate.Alpha}, } + // Introduced in 5.0 + defaultVersionedKubernetesFeatureGates[SELinuxMountGAReadiness] = featuregate.VersionedSpecs{ + {Version: version.MustParse("1.35"), Default: false, PreRelease: featuregate.Alpha}, + } defaultKubernetesFeatureGateDependencies[RouteExternalCertificate] = []featuregate.Feature{} defaultKubernetesFeatureGateDependencies[MinimumKubeletVersion] = []featuregate.Feature{} defaultKubernetesFeatureGateDependencies[StoragePerformantSecurityPolicy] = []featuregate.Feature{} + defaultKubernetesFeatureGateDependencies[SELinuxMountGAReadiness] = []featuregate.Feature{} } diff --git a/deps/github.com/openshift/kubernetes/plugin/pkg/auth/authorizer/rbac/bootstrappolicy/controller_policy.go b/deps/github.com/openshift/kubernetes/plugin/pkg/auth/authorizer/rbac/bootstrappolicy/controller_policy.go index 994e716a28..ddcafd16ae 100644 --- a/deps/github.com/openshift/kubernetes/plugin/pkg/auth/authorizer/rbac/bootstrappolicy/controller_policy.go +++ b/deps/github.com/openshift/kubernetes/plugin/pkg/auth/authorizer/rbac/bootstrappolicy/controller_policy.go @@ -606,6 +606,10 @@ func buildControllerRoles() ([]rbacv1.ClusterRole, []rbacv1.ClusterRoleBinding) rbacv1helpers.NewRule("get", "list", "watch").Groups(legacyGroup).Resources("persistentvolumeclaims").RuleOrDie(), rbacv1helpers.NewRule("get", "list", "watch").Groups(legacyGroup).Resources("pods").RuleOrDie(), rbacv1helpers.NewRule("get", "list", "watch").Groups(storageGroup).Resources("csidrivers").RuleOrDie(), + // RBAC cannot restrict `create` by resourceName, so adding a generic rule to allow creation of any ConfigMap + rbacv1helpers.NewRule("create").Groups(legacyGroup).Resources("configmaps").RuleOrDie(), + // ... and allow patching only of the selinux-conflicts ConfigMap + rbacv1helpers.NewRule("patch").Groups(legacyGroup).Resources("configmaps").Names("selinux-conflicts").RuleOrDie(), }, }) } diff --git a/deps/github.com/openshift/kubernetes/plugin/pkg/auth/authorizer/rbac/bootstrappolicy/testdata/controller-roles.yaml b/deps/github.com/openshift/kubernetes/plugin/pkg/auth/authorizer/rbac/bootstrappolicy/testdata/controller-roles.yaml index 88459b2652..3e90cc424a 100644 --- a/deps/github.com/openshift/kubernetes/plugin/pkg/auth/authorizer/rbac/bootstrappolicy/testdata/controller-roles.yaml +++ b/deps/github.com/openshift/kubernetes/plugin/pkg/auth/authorizer/rbac/bootstrappolicy/testdata/controller-roles.yaml @@ -1465,6 +1465,20 @@ items: - get - list - watch + - apiGroups: + - "" + resources: + - configmaps + verbs: + - create + - apiGroups: + - "" + resourceNames: + - selinux-conflicts + resources: + - configmaps + verbs: + - patch - apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: diff --git a/deps/github.com/openshift/kubernetes/test/compatibility_lifecycle/reference/feature_list.md b/deps/github.com/openshift/kubernetes/test/compatibility_lifecycle/reference/feature_list.md index 73e3761674..2605dbd3dd 100644 --- a/deps/github.com/openshift/kubernetes/test/compatibility_lifecycle/reference/feature_list.md +++ b/deps/github.com/openshift/kubernetes/test/compatibility_lifecycle/reference/feature_list.md @@ -184,6 +184,7 @@ | RuntimeClassInImageCriApi | | | 1.29– | | | | | [code](https://cs.k8s.io/?q=%5CbRuntimeClassInImageCriApi%5Cb&i=nope&files=&excludeFiles=CHANGELOG&repos=kubernetes/kubernetes) [KEPs](https://cs.k8s.io/?q=%5CbRuntimeClassInImageCriApi%5Cb&i=nope&files=&excludeFiles=CHANGELOG&repos=kubernetes/enhancements) | | SELinuxChangePolicy | :ballot_box_with_check: 1.33+ | :closed_lock_with_key: 1.36+ | 1.32 | 1.33–1.35 | 1.36– | | | [code](https://cs.k8s.io/?q=%5CbSELinuxChangePolicy%5Cb&i=nope&files=&excludeFiles=CHANGELOG&repos=kubernetes/kubernetes) [KEPs](https://cs.k8s.io/?q=%5CbSELinuxChangePolicy%5Cb&i=nope&files=&excludeFiles=CHANGELOG&repos=kubernetes/enhancements) | | SELinuxMount | | | 1.30–1.32 | 1.33– | | | | [code](https://cs.k8s.io/?q=%5CbSELinuxMount%5Cb&i=nope&files=&excludeFiles=CHANGELOG&repos=kubernetes/kubernetes) [KEPs](https://cs.k8s.io/?q=%5CbSELinuxMount%5Cb&i=nope&files=&excludeFiles=CHANGELOG&repos=kubernetes/enhancements) | +| SELinuxMountGAReadiness | | | 1.35– | | | | | [code](https://cs.k8s.io/?q=%5CbSELinuxMountGAReadiness%5Cb&i=nope&files=&excludeFiles=CHANGELOG&repos=kubernetes/kubernetes) [KEPs](https://cs.k8s.io/?q=%5CbSELinuxMountGAReadiness%5Cb&i=nope&files=&excludeFiles=CHANGELOG&repos=kubernetes/enhancements) | | SELinuxMountReadWriteOncePod | :ballot_box_with_check: 1.28+ | :closed_lock_with_key: 1.36+ | 1.25–1.26 | 1.27–1.35 | 1.36– | | | [code](https://cs.k8s.io/?q=%5CbSELinuxMountReadWriteOncePod%5Cb&i=nope&files=&excludeFiles=CHANGELOG&repos=kubernetes/kubernetes) [KEPs](https://cs.k8s.io/?q=%5CbSELinuxMountReadWriteOncePod%5Cb&i=nope&files=&excludeFiles=CHANGELOG&repos=kubernetes/enhancements) | | SchedulerAsyncAPICalls | | | | 1.34– | | | | [code](https://cs.k8s.io/?q=%5CbSchedulerAsyncAPICalls%5Cb&i=nope&files=&excludeFiles=CHANGELOG&repos=kubernetes/kubernetes) [KEPs](https://cs.k8s.io/?q=%5CbSchedulerAsyncAPICalls%5Cb&i=nope&files=&excludeFiles=CHANGELOG&repos=kubernetes/enhancements) | | SchedulerAsyncPreemption | :ballot_box_with_check: 1.33+ | | 1.32 | 1.33– | | | | [code](https://cs.k8s.io/?q=%5CbSchedulerAsyncPreemption%5Cb&i=nope&files=&excludeFiles=CHANGELOG&repos=kubernetes/kubernetes) [KEPs](https://cs.k8s.io/?q=%5CbSchedulerAsyncPreemption%5Cb&i=nope&files=&excludeFiles=CHANGELOG&repos=kubernetes/enhancements) | diff --git a/deps/github.com/openshift/kubernetes/test/e2e/storage/testsuites/snapshot-metadata.go b/deps/github.com/openshift/kubernetes/test/e2e/storage/testsuites/snapshot-metadata.go index ca6e0ce7f2..b864ba13dc 100644 --- a/deps/github.com/openshift/kubernetes/test/e2e/storage/testsuites/snapshot-metadata.go +++ b/deps/github.com/openshift/kubernetes/test/e2e/storage/testsuites/snapshot-metadata.go @@ -266,7 +266,7 @@ func (s *snapshotMetadataTestSuite) DefineTests(driver storageframework.TestDriv targetDeviceName string ) - f := framework.NewDefaultFramework("snapshotmetadata") + f := framework.NewFrameworkWithCustomTimeouts("snapshotmetadata", storageframework.GetDriverTimeouts(driver)) f.NamespacePodSecurityLevel = admissionapi.LevelPrivileged createBackupClientPod := func(ctx context.Context, source, target *v1.PersistentVolumeClaim) *v1.Pod { diff --git a/deps/github.com/openshift/kubernetes/test/e2e/storage/testsuites/snapshottable.go b/deps/github.com/openshift/kubernetes/test/e2e/storage/testsuites/snapshottable.go index c8fe3cc585..331adbc02c 100644 --- a/deps/github.com/openshift/kubernetes/test/e2e/storage/testsuites/snapshottable.go +++ b/deps/github.com/openshift/kubernetes/test/e2e/storage/testsuites/snapshottable.go @@ -108,7 +108,7 @@ func (s *snapshottableTestSuite) DefineTests(driver storageframework.TestDriver, // Beware that it also registers an AfterEach which renders f unusable. Any code using // f must run inside an It or Context callback. - f := framework.NewDefaultFramework("snapshotting") + f := framework.NewFrameworkWithCustomTimeouts("snapshotting", storageframework.GetDriverTimeouts(driver)) f.NamespacePodSecurityLevel = admissionapi.LevelPrivileged ginkgo.Describe("volume snapshot controller", func() { diff --git a/deps/github.com/openshift/kubernetes/test/e2e/storage/testsuites/snapshottable_stress.go b/deps/github.com/openshift/kubernetes/test/e2e/storage/testsuites/snapshottable_stress.go index b381e67c48..289c826d18 100644 --- a/deps/github.com/openshift/kubernetes/test/e2e/storage/testsuites/snapshottable_stress.go +++ b/deps/github.com/openshift/kubernetes/test/e2e/storage/testsuites/snapshottable_stress.go @@ -120,7 +120,7 @@ func (t *snapshottableStressTestSuite) DefineTests(driver storageframework.TestD // Beware that it also registers an AfterEach which renders f unusable. Any code using // f must run inside an It or Context callback. - f := framework.NewDefaultFramework("snapshottable-stress") + f := framework.NewFrameworkWithCustomTimeouts("snapshottable-stress", storageframework.GetDriverTimeouts(driver)) f.NamespacePodSecurityLevel = admissionapi.LevelPrivileged init := func(ctx context.Context) { diff --git a/deps/github.com/openshift/kubernetes/test/e2e/storage/utils/volume_group_snapshot.go b/deps/github.com/openshift/kubernetes/test/e2e/storage/utils/volume_group_snapshot.go index a3ed602030..6c464cb382 100644 --- a/deps/github.com/openshift/kubernetes/test/e2e/storage/utils/volume_group_snapshot.go +++ b/deps/github.com/openshift/kubernetes/test/e2e/storage/utils/volume_group_snapshot.go @@ -33,16 +33,16 @@ const ( // VolumeGroupSnapshot is the group snapshot api VolumeGroupSnapshotAPIGroup = "groupsnapshot.storage.k8s.io" // VolumeGroupSnapshotAPIVersion is the group snapshot api version - VolumeGroupSnapshotAPIVersion = "groupsnapshot.storage.k8s.io/v1beta2" + VolumeGroupSnapshotAPIVersion = "groupsnapshot.storage.k8s.io/v1" ) var ( // VolumeGroupSnapshotGVR is GroupVersionResource for volumegroupsnapshots - VolumeGroupSnapshotGVR = schema.GroupVersionResource{Group: VolumeGroupSnapshotAPIGroup, Version: "v1beta2", Resource: "volumegroupsnapshots"} + VolumeGroupSnapshotGVR = schema.GroupVersionResource{Group: VolumeGroupSnapshotAPIGroup, Version: "v1", Resource: "volumegroupsnapshots"} // VolumeGroupSnapshotClassGVR is GroupVersionResource for volumegroupsnapshotsclasses - VolumeGroupSnapshotClassGVR = schema.GroupVersionResource{Group: VolumeGroupSnapshotAPIGroup, Version: "v1beta2", Resource: "volumegroupsnapshotclasses"} - VolumeGroupSnapshotContentGVR = schema.GroupVersionResource{Group: VolumeGroupSnapshotAPIGroup, Version: "v1beta2", Resource: "volumegroupsnapshotcontents"} + VolumeGroupSnapshotClassGVR = schema.GroupVersionResource{Group: VolumeGroupSnapshotAPIGroup, Version: "v1", Resource: "volumegroupsnapshotclasses"} + VolumeGroupSnapshotContentGVR = schema.GroupVersionResource{Group: VolumeGroupSnapshotAPIGroup, Version: "v1", Resource: "volumegroupsnapshotcontents"} ) // WaitForVolumeGroupSnapshotReady waits for a VolumeGroupSnapshot to be ready to use or until timeout occurs, whichever comes first. diff --git a/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/groupsnapshot.storage.k8s.io_volumegroupsnapshotclasses.yaml b/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/groupsnapshot.storage.k8s.io_volumegroupsnapshotclasses.yaml index 81299d5ecf..25ecd53595 100644 --- a/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/groupsnapshot.storage.k8s.io_volumegroupsnapshotclasses.yaml +++ b/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/groupsnapshot.storage.k8s.io_volumegroupsnapshotclasses.yaml @@ -174,5 +174,88 @@ spec: - driver type: object served: true + storage: false + subresources: {} + - additionalPrinterColumns: + - jsonPath: .driver + name: Driver + type: string + - description: Determines whether a VolumeGroupSnapshotContent created through + the VolumeGroupSnapshotClass should be deleted when its bound VolumeGroupSnapshot + is deleted. + jsonPath: .deletionPolicy + name: DeletionPolicy + type: string + - jsonPath: .metadata.creationTimestamp + name: Age + type: date + name: v1 + schema: + openAPIV3Schema: + description: |- + VolumeGroupSnapshotClass specifies parameters that a underlying storage system + uses when creating a volume group snapshot. A specific VolumeGroupSnapshotClass + is used by specifying its name in a VolumeGroupSnapshot object. + VolumeGroupSnapshotClasses are non-namespaced. + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + deletionPolicy: + description: |- + DeletionPolicy determines whether a VolumeGroupSnapshotContent created + through the VolumeGroupSnapshotClass should be deleted when its bound + VolumeGroupSnapshot is deleted. + Supported values are "Retain" and "Delete". + "Retain" means that the VolumeGroupSnapshotContent and its physical group + snapshot on underlying storage system are kept. + "Delete" means that the VolumeGroupSnapshotContent and its physical group + snapshot on underlying storage system are deleted. + Required. + enum: + - Delete + - Retain + type: string + x-kubernetes-validations: + - message: deletionPolicy is immutable once set + rule: self == oldSelf + driver: + description: |- + Driver is the name of the storage driver expected to handle this VolumeGroupSnapshotClass. + Required. + type: string + x-kubernetes-validations: + - message: driver is immutable once set + rule: self == oldSelf + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + parameters: + additionalProperties: + type: string + description: |- + Parameters is a key-value map with storage driver specific parameters for + creating group snapshots. + These values are opaque to Kubernetes and are passed directly to the driver. + type: object + x-kubernetes-validations: + - message: parameters are immutable once set + rule: self == oldSelf + required: + - deletionPolicy + - driver + type: object + served: true storage: true subresources: {} diff --git a/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/groupsnapshot.storage.k8s.io_volumegroupsnapshotcontents.yaml b/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/groupsnapshot.storage.k8s.io_volumegroupsnapshotcontents.yaml index 235198ac49..09b9ffee83 100644 --- a/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/groupsnapshot.storage.k8s.io_volumegroupsnapshotcontents.yaml +++ b/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/groupsnapshot.storage.k8s.io_volumegroupsnapshotcontents.yaml @@ -656,6 +656,333 @@ spec: - spec type: object served: true + storage: false + subresources: + status: {} + - additionalPrinterColumns: + - description: Indicates if all the individual snapshots in the group are ready + to be used to restore a group of volumes. + jsonPath: .status.readyToUse + name: ReadyToUse + type: boolean + - description: Determines whether this VolumeGroupSnapshotContent and its physical + group snapshot on the underlying storage system should be deleted when its + bound VolumeGroupSnapshot is deleted. + jsonPath: .spec.deletionPolicy + name: DeletionPolicy + type: string + - description: Name of the CSI driver used to create the physical group snapshot + on the underlying storage system. + jsonPath: .spec.driver + name: Driver + type: string + - description: Name of the VolumeGroupSnapshotClass from which this group snapshot + was (or will be) created. + jsonPath: .spec.volumeGroupSnapshotClassName + name: VolumeGroupSnapshotClass + type: string + - description: Namespace of the VolumeGroupSnapshot object to which this VolumeGroupSnapshotContent + object is bound. + jsonPath: .spec.volumeGroupSnapshotRef.namespace + name: VolumeGroupSnapshotNamespace + type: string + - description: Name of the VolumeGroupSnapshot object to which this VolumeGroupSnapshotContent + object is bound. + jsonPath: .spec.volumeGroupSnapshotRef.name + name: VolumeGroupSnapshot + type: string + - jsonPath: .metadata.creationTimestamp + name: Age + type: date + name: v1 + schema: + openAPIV3Schema: + description: |- + VolumeGroupSnapshotContent represents the actual "on-disk" group snapshot object + in the underlying storage system + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + description: |- + Spec defines properties of a VolumeGroupSnapshotContent created by the underlying storage system. + Required. + properties: + deletionPolicy: + description: |- + DeletionPolicy determines whether this VolumeGroupSnapshotContent and the + physical group snapshot on the underlying storage system should be deleted + when the bound VolumeGroupSnapshot is deleted. + Supported values are "Retain" and "Delete". + "Retain" means that the VolumeGroupSnapshotContent and its physical group + snapshot on underlying storage system are kept. + "Delete" means that the VolumeGroupSnapshotContent and its physical group + snapshot on underlying storage system are deleted. + For dynamically provisioned group snapshots, this field will automatically + be filled in by the CSI snapshotter sidecar with the "DeletionPolicy" field + defined in the corresponding VolumeGroupSnapshotClass. + For pre-existing snapshots, users MUST specify this field when creating the + VolumeGroupSnapshotContent object. + Required. + enum: + - Delete + - Retain + type: string + driver: + description: |- + Driver is the name of the CSI driver used to create the physical group snapshot on + the underlying storage system. + This MUST be the same as the name returned by the CSI GetPluginName() call for + that driver. + Required. + type: string + x-kubernetes-validations: + - message: driver is immutable once set + rule: self == oldSelf + source: + description: |- + Source specifies whether the snapshot is (or should be) dynamically provisioned + or already exists, and just requires a Kubernetes object representation. + This field is immutable after creation. + Required. + properties: + groupSnapshotHandles: + description: |- + GroupSnapshotHandles specifies the CSI "group_snapshot_id" of a pre-existing + group snapshot and a list of CSI "snapshot_id" of pre-existing snapshots + on the underlying storage system for which a Kubernetes object + representation was (or should be) created. + This field is immutable. + properties: + volumeGroupSnapshotHandle: + description: |- + VolumeGroupSnapshotHandle specifies the CSI "group_snapshot_id" of a pre-existing + group snapshot on the underlying storage system for which a Kubernetes object + representation was (or should be) created. + This field is immutable. + Required. + type: string + volumeSnapshotHandles: + description: |- + VolumeSnapshotHandles is a list of CSI "snapshot_id" of pre-existing + snapshots on the underlying storage system for which Kubernetes objects + representation were (or should be) created. + This field is immutable. + Required. + items: + type: string + type: array + required: + - volumeGroupSnapshotHandle + - volumeSnapshotHandles + type: object + x-kubernetes-validations: + - message: groupSnapshotHandles is immutable + rule: self == oldSelf + volumeHandles: + description: |- + VolumeHandles is a list of volume handles on the backend to be snapshotted + together. It is specified for dynamic provisioning of the VolumeGroupSnapshot. + This field is immutable. + items: + type: string + type: array + x-kubernetes-validations: + - message: volumeHandles is immutable + rule: self == oldSelf + type: object + x-kubernetes-validations: + - message: volumeHandles is required once set + rule: '!has(oldSelf.volumeHandles) || has(self.volumeHandles)' + - message: groupSnapshotHandles is required once set + rule: '!has(oldSelf.groupSnapshotHandles) || has(self.groupSnapshotHandles)' + - message: exactly one of volumeHandles and groupSnapshotHandles must + be set + rule: (has(self.volumeHandles) && !has(self.groupSnapshotHandles)) + || (!has(self.volumeHandles) && has(self.groupSnapshotHandles)) + volumeGroupSnapshotClassName: + description: |- + VolumeGroupSnapshotClassName is the name of the VolumeGroupSnapshotClass from + which this group snapshot was (or will be) created. + Note that after provisioning, the VolumeGroupSnapshotClass may be deleted or + recreated with different set of values, and as such, should not be referenced + post-snapshot creation. + For dynamic provisioning, this field must be set. + This field may be unset for pre-provisioned snapshots. + type: string + x-kubernetes-validations: + - message: volumeGroupSnapshotClassName is immutable once set + rule: self == oldSelf + volumeGroupSnapshotRef: + description: |- + VolumeGroupSnapshotRef specifies the VolumeGroupSnapshot object to which this + VolumeGroupSnapshotContent object is bound. + VolumeGroupSnapshot.Spec.VolumeGroupSnapshotContentName field must reference to + this VolumeGroupSnapshotContent's name for the bidirectional binding to be valid. + For a pre-existing VolumeGroupSnapshotContent object, name and namespace of the + VolumeGroupSnapshot object MUST be provided for binding to happen. + This field is immutable after creation. + Required. + properties: + apiVersion: + description: API version of the referent. + type: string + fieldPath: + description: |- + If referring to a piece of an object instead of an entire object, this string + should contain a valid JSON/Go field access statement, such as desiredState.manifest.containers[2]. + For example, if the object reference is to a container within a pod, this would take on a value like: + "spec.containers{name}" (where "name" refers to the name of the container that triggered + the event) or if no container name is specified "spec.containers[2]" (container with + index 2 in this pod). This syntax is chosen only to have some well-defined way of + referencing a part of an object. + TODO: this design is not final and this field is subject to change in the future. + type: string + kind: + description: |- + Kind of the referent. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + name: + description: |- + Name of the referent. + More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names + type: string + namespace: + description: |- + Namespace of the referent. + More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/namespaces/ + type: string + resourceVersion: + description: |- + Specific resourceVersion to which this reference is made, if any. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#concurrency-control-and-consistency + type: string + uid: + description: |- + UID of the referent. + More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#uids + type: string + type: object + x-kubernetes-map-type: atomic + x-kubernetes-validations: + - message: both volumeGroupSnapshotRef.name and volumeGroupSnapshotRef.namespace + must be set + rule: has(self.name) && has(self.__namespace__) + - message: volumeGroupSnapshotRef.name and volumeGroupSnapshotRef.namespace + are immutable + rule: self.name == oldSelf.name && self.__namespace__ == oldSelf.__namespace__ + - message: volumeGroupSnapshotRef.uid is immutable once set + rule: '!has(oldSelf.uid) || (has(self.uid) && self.uid == oldSelf.uid)' + required: + - deletionPolicy + - driver + - source + - volumeGroupSnapshotRef + type: object + status: + description: status represents the current information of a group snapshot. + properties: + creationTime: + description: |- + CreationTime is the timestamp when the point-in-time group snapshot is taken + by the underlying storage system. + If not specified, it indicates the creation time is unknown. + If not specified, it means the readiness of a group snapshot is unknown. + This field is the source for the CreationTime field in VolumeGroupSnapshotStatus + format: date-time + type: string + error: + description: |- + Error is the last observed error during group snapshot creation, if any. + Upon success after retry, this error field will be cleared. + properties: + message: + description: |- + message is a string detailing the encountered error during snapshot + creation if specified. + NOTE: message may be logged, and it should not contain sensitive + information. + type: string + time: + description: time is the timestamp when the error was encountered. + format: date-time + type: string + type: object + readyToUse: + description: |- + ReadyToUse indicates if all the individual snapshots in the group are ready to be + used to restore a group of volumes. + ReadyToUse becomes true when ReadyToUse of all individual snapshots become true. + type: boolean + volumeGroupSnapshotHandle: + description: |- + VolumeGroupSnapshotHandle is a unique id returned by the CSI driver + to identify the VolumeGroupSnapshot on the storage system. + If a storage system does not provide such an id, the + CSI driver can choose to return the VolumeGroupSnapshot name. + type: string + x-kubernetes-validations: + - message: volumeGroupSnapshotHandle is immutable once set + rule: self == oldSelf + volumeSnapshotInfoList: + description: |- + This field is introduced in v1beta2 + It is replacing VolumeSnapshotHandlePairList + VolumeSnapshotInfoList is a list of snapshot information returned by + by the CSI driver to identify snapshots on the storage system. + items: + description: |- + The VolumeSnapshotInfo struct is added in v1beta2 + VolumeSnapshotInfo contains information for a snapshot + properties: + creationTime: + description: |- + creationTime is the timestamp when the point-in-time snapshot is taken + by the underlying storage system. + format: int64 + type: integer + readyToUse: + description: ReadyToUse indicates if the snapshot is ready to + be used to restore a volume. + type: boolean + restoreSize: + description: |- + RestoreSize represents the minimum size of volume required to create a volume + from this snapshot. + format: int64 + type: integer + snapshotHandle: + description: SnapshotHandle is the CSI "snapshot_id" of this + snapshot on the underlying storage system. + type: string + volumeHandle: + description: |- + VolumeHandle specifies the CSI "volume_id" of the volume from which this snapshot + was taken from. + type: string + type: object + type: array + type: object + required: + - spec + type: object + served: true storage: true subresources: status: {} diff --git a/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/groupsnapshot.storage.k8s.io_volumegroupsnapshots.yaml b/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/groupsnapshot.storage.k8s.io_volumegroupsnapshots.yaml index 3f8c4909aa..9e7315dfde 100644 --- a/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/groupsnapshot.storage.k8s.io_volumegroupsnapshots.yaml +++ b/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/groupsnapshot.storage.k8s.io_volumegroupsnapshots.yaml @@ -455,6 +455,226 @@ spec: - spec type: object served: true + storage: false + subresources: + status: {} + - additionalPrinterColumns: + - description: Indicates if all the individual snapshots in the group are ready + to be used to restore a group of volumes. + jsonPath: .status.readyToUse + name: ReadyToUse + type: boolean + - description: The name of the VolumeGroupSnapshotClass requested by the VolumeGroupSnapshot. + jsonPath: .spec.volumeGroupSnapshotClassName + name: VolumeGroupSnapshotClass + type: string + - description: Name of the VolumeGroupSnapshotContent object to which the VolumeGroupSnapshot + object intends to bind to. Please note that verification of binding actually + requires checking both VolumeGroupSnapshot and VolumeGroupSnapshotContent + to ensure both are pointing at each other. Binding MUST be verified prior + to usage of this object. + jsonPath: .status.boundVolumeGroupSnapshotContentName + name: VolumeGroupSnapshotContent + type: string + - description: Timestamp when the point-in-time group snapshot was taken by the + underlying storage system. + jsonPath: .status.creationTime + name: CreationTime + type: date + - jsonPath: .metadata.creationTimestamp + name: Age + type: date + name: v1 + schema: + openAPIV3Schema: + description: |- + VolumeGroupSnapshot is a user's request for creating either a point-in-time + group snapshot or binding to a pre-existing group snapshot. + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + description: |- + Spec defines the desired characteristics of a group snapshot requested by a user. + Required. + properties: + source: + description: |- + Source specifies where a group snapshot will be created from. + This field is immutable after creation. + Required. + properties: + selector: + description: |- + Selector is a label query over persistent volume claims that are to be + grouped together for snapshotting. + This labelSelector will be used to match the label added to a PVC. + If the label is added or removed to a volume after a group snapshot + is created, the existing group snapshots won't be modified. + Once a VolumeGroupSnapshotContent is created and the sidecar starts to process + it, the volume list will not change with retries. + properties: + matchExpressions: + description: matchExpressions is a list of label selector + requirements. The requirements are ANDed. + items: + description: |- + A label selector requirement is a selector that contains values, a key, and an operator that + relates the key and values. + properties: + key: + description: key is the label key that the selector + applies to. + type: string + operator: + description: |- + operator represents a key's relationship to a set of values. + Valid operators are In, NotIn, Exists and DoesNotExist. + type: string + values: + description: |- + values is an array of string values. If the operator is In or NotIn, + the values array must be non-empty. If the operator is Exists or DoesNotExist, + the values array must be empty. This array is replaced during a strategic + merge patch. + items: + type: string + type: array + x-kubernetes-list-type: atomic + required: + - key + - operator + type: object + type: array + x-kubernetes-list-type: atomic + matchLabels: + additionalProperties: + type: string + description: |- + matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels + map is equivalent to an element of matchExpressions, whose key field is "key", the + operator is "In", and the values array contains only "value". The requirements are ANDed. + type: object + type: object + x-kubernetes-map-type: atomic + x-kubernetes-validations: + - message: selector is immutable + rule: self == oldSelf + volumeGroupSnapshotContentName: + description: |- + VolumeGroupSnapshotContentName specifies the name of a pre-existing VolumeGroupSnapshotContent + object representing an existing volume group snapshot. + This field should be set if the volume group snapshot already exists and + only needs a representation in Kubernetes. + This field is immutable. + type: string + x-kubernetes-validations: + - message: volumeGroupSnapshotContentName is immutable + rule: self == oldSelf + type: object + x-kubernetes-validations: + - message: selector is required once set + rule: '!has(oldSelf.selector) || has(self.selector)' + - message: volumeGroupSnapshotContentName is required once set + rule: '!has(oldSelf.volumeGroupSnapshotContentName) || has(self.volumeGroupSnapshotContentName)' + - message: exactly one of selector and volumeGroupSnapshotContentName + must be set + rule: (has(self.selector) && !has(self.volumeGroupSnapshotContentName)) + || (!has(self.selector) && has(self.volumeGroupSnapshotContentName)) + volumeGroupSnapshotClassName: + description: |- + VolumeGroupSnapshotClassName is the name of the VolumeGroupSnapshotClass + requested by the VolumeGroupSnapshot. + VolumeGroupSnapshotClassName may be left nil to indicate that the default + class will be used. + Empty string is not allowed for this field. + type: string + x-kubernetes-validations: + - message: volumeGroupSnapshotClassName must not be the empty string + when set + rule: size(self) > 0 + required: + - source + type: object + status: + description: |- + Status represents the current information of a group snapshot. + Consumers must verify binding between VolumeGroupSnapshot and + VolumeGroupSnapshotContent objects is successful (by validating that both + VolumeGroupSnapshot and VolumeGroupSnapshotContent point to each other) before + using this object. + properties: + boundVolumeGroupSnapshotContentName: + description: |- + BoundVolumeGroupSnapshotContentName is the name of the VolumeGroupSnapshotContent + object to which this VolumeGroupSnapshot object intends to bind to. + If not specified, it indicates that the VolumeGroupSnapshot object has not + been successfully bound to a VolumeGroupSnapshotContent object yet. + NOTE: To avoid possible security issues, consumers must verify binding between + VolumeGroupSnapshot and VolumeGroupSnapshotContent objects is successful + (by validating that both VolumeGroupSnapshot and VolumeGroupSnapshotContent + point at each other) before using this object. + type: string + x-kubernetes-validations: + - message: boundVolumeGroupSnapshotContentName is immutable once set + rule: self == oldSelf + creationTime: + description: |- + CreationTime is the timestamp when the point-in-time group snapshot is taken + by the underlying storage system. + If not specified, it may indicate that the creation time of the group snapshot + is unknown. + This field is updated based on the CreationTime field in VolumeGroupSnapshotContentStatus + format: date-time + type: string + error: + description: |- + Error is the last observed error during group snapshot creation, if any. + This field could be helpful to upper level controllers (i.e., application + controller) to decide whether they should continue on waiting for the group + snapshot to be created based on the type of error reported. + The snapshot controller will keep retrying when an error occurs during the + group snapshot creation. Upon success, this error field will be cleared. + properties: + message: + description: |- + message is a string detailing the encountered error during snapshot + creation if specified. + NOTE: message may be logged, and it should not contain sensitive + information. + type: string + time: + description: time is the timestamp when the error was encountered. + format: date-time + type: string + type: object + readyToUse: + description: |- + ReadyToUse indicates if all the individual snapshots in the group are ready + to be used to restore a group of volumes. + ReadyToUse becomes true when ReadyToUse of all individual snapshots become true. + If not specified, it means the readiness of a group snapshot is unknown. + type: boolean + type: object + required: + - spec + type: object + served: true storage: true subresources: status: {} diff --git a/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/volume-group-snapshots/csi-hostpath-plugin.yaml b/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/volume-group-snapshots/csi-hostpath-plugin.yaml index 4a50349cd4..c8e54f3a53 100644 --- a/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/volume-group-snapshots/csi-hostpath-plugin.yaml +++ b/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/volume-group-snapshots/csi-hostpath-plugin.yaml @@ -262,7 +262,7 @@ spec: name: dev-dir - name: csi-external-health-monitor-controller - image: registry.k8s.io/sig-storage/csi-external-health-monitor-controller:v0.17.0 + image: registry.k8s.io/sig-storage/csi-external-health-monitor-controller:v0.18.0 args: - "--v=5" - "--csi-address=$(ADDRESS)" @@ -276,11 +276,12 @@ spec: mountPath: /csi - name: node-driver-registrar - image: registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.16.0 + image: registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.17.0 args: - --v=5 - --csi-address=/csi/csi.sock - --kubelet-registration-path=/var/lib/kubelet/plugins/csi-hostpath/csi.sock + - --http-endpoint=:9809 securityContext: # This is necessary only for systems with SELinux, where # non-privileged sidecar containers cannot access unix domain socket @@ -292,6 +293,18 @@ spec: fieldRef: apiVersion: v1 fieldPath: spec.nodeName + ports: + - containerPort: 9809 + name: healthz + protocol: TCP + livenessProbe: + httpGet: + path: /healthz + port: healthz + initialDelaySeconds: 30 + timeoutSeconds: 15 + periodSeconds: 10 + failureThreshold: 3 volumeMounts: - mountPath: /csi name: socket-dir @@ -304,13 +317,13 @@ spec: volumeMounts: - mountPath: /csi name: socket-dir - image: registry.k8s.io/sig-storage/livenessprobe:v2.18.0 + image: registry.k8s.io/sig-storage/livenessprobe:v2.19.0 args: - --csi-address=/csi/csi.sock - --health-port=9898 - name: csi-attacher - image: registry.k8s.io/sig-storage/csi-attacher:v4.11.0 + image: registry.k8s.io/sig-storage/csi-attacher:v4.12.0 args: - --v=5 - --csi-address=/csi/csi.sock @@ -324,7 +337,7 @@ spec: name: socket-dir - name: csi-provisioner - image: registry.k8s.io/sig-storage/csi-provisioner:v6.1.1 + image: registry.k8s.io/sig-storage/csi-provisioner:v6.3.0 args: - -v=5 - --csi-address=/csi/csi.sock @@ -340,7 +353,7 @@ spec: name: socket-dir - name: csi-resizer - image: registry.k8s.io/sig-storage/csi-resizer:v2.1.0 + image: registry.k8s.io/sig-storage/csi-resizer:v2.2.0 args: - -v=5 - -csi-address=/csi/csi.sock @@ -354,7 +367,7 @@ spec: name: socket-dir - name: csi-snapshotter - image: registry.k8s.io/sig-storage/csi-snapshotter:v8.5.0 + image: registry.k8s.io/sig-storage/csi-snapshotter:v8.6.0 args: - -v=5 - --csi-address=/csi/csi.sock diff --git a/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/volume-group-snapshots/run_group_snapshot_e2e.sh b/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/volume-group-snapshots/run_group_snapshot_e2e.sh index 8d39c1ba44..40f0586dc9 100755 --- a/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/volume-group-snapshots/run_group_snapshot_e2e.sh +++ b/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/external-snapshotter/volume-group-snapshots/run_group_snapshot_e2e.sh @@ -244,7 +244,7 @@ run_tests() { export KUBE_CONTAINER_RUNTIME=remote export KUBE_CONTAINER_RUNTIME_ENDPOINT=unix:///run/containerd/containerd.sock export KUBE_CONTAINER_RUNTIME_NAME=containerd - export SNAPSHOTTER_VERSION="${SNAPSHOTTER_VERSION:-v8.4.0}" + export SNAPSHOTTER_VERSION="${SNAPSHOTTER_VERSION:-v8.6.0}" echo "SNAPSHOTTER_VERSION is $SNAPSHOTTER_VERSION" # Enable VolumeGroupSnapshot tests in csi-driver-hostpath diff --git a/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/gce-pd/controller_ss.yaml b/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/gce-pd/controller_ss.yaml index 9f7809b08b..6d7cbbf131 100644 --- a/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/gce-pd/controller_ss.yaml +++ b/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/gce-pd/controller_ss.yaml @@ -21,7 +21,7 @@ spec: serviceAccountName: csi-gce-pd-controller-sa containers: - name: csi-snapshotter - image: registry.k8s.io/sig-storage/csi-snapshotter:v8.5.0 + image: registry.k8s.io/sig-storage/csi-snapshotter:v8.6.0 args: - "--v=5" - "--csi-address=/csi/csi.sock" @@ -39,7 +39,7 @@ spec: - name: socket-dir mountPath: /csi - name: csi-provisioner - image: registry.k8s.io/sig-storage/csi-provisioner:v5.2.0 + image: registry.k8s.io/sig-storage/csi-provisioner:v6.3.0 args: - "--v=5" - "--csi-address=/csi/csi.sock" @@ -73,7 +73,7 @@ spec: - name: socket-dir mountPath: /csi - name: csi-attacher - image: registry.k8s.io/sig-storage/csi-attacher:v4.8.1 + image: registry.k8s.io/sig-storage/csi-attacher:v4.12.0 args: - "--v=5" - "--csi-address=/csi/csi.sock" @@ -102,7 +102,7 @@ spec: - name: socket-dir mountPath: /csi - name: csi-resizer - image: registry.k8s.io/sig-storage/csi-resizer:v1.13.1 + image: registry.k8s.io/sig-storage/csi-resizer:v2.2.0 args: - "--v=5" - "--csi-address=/csi/csi.sock" diff --git a/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/gce-pd/node_ds.yaml b/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/gce-pd/node_ds.yaml index 99d9f9ce2a..36c6e6ef12 100644 --- a/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/gce-pd/node_ds.yaml +++ b/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/gce-pd/node_ds.yaml @@ -13,7 +13,7 @@ spec: spec: containers: - name: csi-driver-registrar - image: registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.16.0 + image: registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.17.0 args: - "--v=5" - "--csi-address=/csi/csi.sock" diff --git a/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/hostpath/hostpath/csi-hostpath-plugin.yaml b/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/hostpath/hostpath/csi-hostpath-plugin.yaml index 2fe67ffb71..1dd8d161b4 100644 --- a/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/hostpath/hostpath/csi-hostpath-plugin.yaml +++ b/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/hostpath/hostpath/csi-hostpath-plugin.yaml @@ -281,7 +281,7 @@ spec: name: dev-dir - name: csi-external-health-monitor-controller - image: registry.k8s.io/sig-storage/csi-external-health-monitor-controller:v0.17.0 + image: registry.k8s.io/sig-storage/csi-external-health-monitor-controller:v0.18.0 args: - "--v=5" - "--csi-address=$(ADDRESS)" @@ -295,11 +295,12 @@ spec: mountPath: /csi - name: node-driver-registrar - image: registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.16.0 + image: registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.17.0 args: - --v=5 - --csi-address=/csi/csi.sock - --kubelet-registration-path=/var/lib/kubelet/plugins/csi-hostpath/csi.sock + - --http-endpoint=:9809 securityContext: # This is necessary only for systems with SELinux, where # non-privileged sidecar containers cannot access unix domain socket @@ -311,6 +312,18 @@ spec: fieldRef: apiVersion: v1 fieldPath: spec.nodeName + ports: + - containerPort: 9809 + name: healthz + protocol: TCP + livenessProbe: + httpGet: + path: /healthz + port: healthz + initialDelaySeconds: 30 + timeoutSeconds: 15 + periodSeconds: 10 + failureThreshold: 3 volumeMounts: - mountPath: /csi name: socket-dir @@ -323,13 +336,13 @@ spec: volumeMounts: - mountPath: /csi name: socket-dir - image: registry.k8s.io/sig-storage/livenessprobe:v2.18.0 + image: registry.k8s.io/sig-storage/livenessprobe:v2.19.0 args: - --csi-address=/csi/csi.sock - --health-port=9898 - name: csi-attacher - image: registry.k8s.io/sig-storage/csi-attacher:v4.11.0 + image: registry.k8s.io/sig-storage/csi-attacher:v4.12.0 args: - --v=5 - --csi-address=/csi/csi.sock @@ -343,7 +356,7 @@ spec: name: socket-dir - name: csi-provisioner - image: registry.k8s.io/sig-storage/csi-provisioner:v6.1.1 + image: registry.k8s.io/sig-storage/csi-provisioner:v6.3.0 args: - -v=5 - --csi-address=/csi/csi.sock @@ -359,7 +372,7 @@ spec: name: socket-dir - name: csi-resizer - image: registry.k8s.io/sig-storage/csi-resizer:v2.1.0 + image: registry.k8s.io/sig-storage/csi-resizer:v2.2.0 args: - -v=5 - -csi-address=/csi/csi.sock @@ -373,7 +386,7 @@ spec: name: socket-dir - name: csi-snapshotter - image: registry.k8s.io/sig-storage/csi-snapshotter:v8.5.0 + image: registry.k8s.io/sig-storage/csi-snapshotter:v8.6.0 args: - -v=5 - --csi-address=/csi/csi.sock @@ -387,7 +400,7 @@ spec: name: socket-dir - name: csi-snapshot-metadata - image: registry.k8s.io/sig-storage/csi-snapshot-metadata:v0.2.0 + image: registry.k8s.io/sig-storage/csi-snapshot-metadata:v1.0.0 imagePullPolicy: IfNotPresent args: - --csi-address=/csi/csi.sock diff --git a/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-driver-attacher.yaml b/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-driver-attacher.yaml index 40a2a58587..84210e1a22 100644 --- a/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-driver-attacher.yaml +++ b/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-driver-attacher.yaml @@ -15,7 +15,7 @@ spec: serviceAccountName: csi-mock containers: - name: csi-attacher - image: registry.k8s.io/sig-storage/csi-attacher:v4.11.0 + image: registry.k8s.io/sig-storage/csi-attacher:v4.12.0 args: - --v=5 - --csi-address=$(ADDRESS) diff --git a/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-driver-resizer.yaml b/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-driver-resizer.yaml index 7415c5eade..b87541894f 100644 --- a/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-driver-resizer.yaml +++ b/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-driver-resizer.yaml @@ -15,7 +15,7 @@ spec: serviceAccountName: csi-mock containers: - name: csi-resizer - image: registry.k8s.io/sig-storage/csi-resizer:v2.1.0 + image: registry.k8s.io/sig-storage/csi-resizer:v2.2.0 args: - "--v=5" - "--csi-address=$(ADDRESS)" diff --git a/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-driver-snapshotter.yaml b/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-driver-snapshotter.yaml index 130721db8d..9bd0a110b3 100644 --- a/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-driver-snapshotter.yaml +++ b/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-driver-snapshotter.yaml @@ -15,7 +15,7 @@ spec: serviceAccountName: csi-mock containers: - name: csi-snapshotter - image: registry.k8s.io/sig-storage/csi-snapshotter:v8.5.0 + image: registry.k8s.io/sig-storage/csi-snapshotter:v8.6.0 args: - "--v=5" - "--csi-address=$(ADDRESS)" diff --git a/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-driver.yaml b/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-driver.yaml index 5f85ae7422..c2c331a552 100644 --- a/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-driver.yaml +++ b/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-driver.yaml @@ -15,7 +15,7 @@ spec: serviceAccountName: csi-mock containers: - name: csi-provisioner - image: registry.k8s.io/sig-storage/csi-provisioner:v6.1.1 + image: registry.k8s.io/sig-storage/csi-provisioner:v6.3.0 args: - "--csi-address=$(ADDRESS)" # Topology support is needed for the pod rescheduling test @@ -34,11 +34,12 @@ spec: - mountPath: /csi name: socket-dir - name: driver-registrar - image: registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.16.0 + image: registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.17.0 args: - --v=5 - --csi-address=/csi/csi.sock - --kubelet-registration-path=/var/lib/kubelet/plugins/csi-mock/csi.sock + - --http-endpoint=:9809 env: - name: KUBE_NODE_NAME valueFrom: @@ -47,6 +48,18 @@ spec: fieldPath: spec.nodeName securityContext: privileged: true + ports: + - containerPort: 9809 + name: healthz + protocol: TCP + livenessProbe: + httpGet: + path: /healthz + port: healthz + initialDelaySeconds: 30 + timeoutSeconds: 15 + periodSeconds: 10 + failureThreshold: 3 volumeMounts: - mountPath: /csi name: socket-dir diff --git a/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-proxy.yaml b/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-proxy.yaml index 956adbf70a..5fad68e0a3 100644 --- a/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-proxy.yaml +++ b/deps/github.com/openshift/kubernetes/test/e2e/testing-manifests/storage-csi/mock/csi-mock-proxy.yaml @@ -15,7 +15,7 @@ spec: serviceAccountName: csi-mock containers: - name: csi-provisioner - image: registry.k8s.io/sig-storage/csi-provisioner:v6.1.1 + image: registry.k8s.io/sig-storage/csi-provisioner:v6.3.0 args: - "--csi-address=$(ADDRESS)" # Topology support is needed for the pod rescheduling test @@ -35,18 +35,31 @@ spec: - mountPath: /csi name: socket-dir - name: driver-registrar - image: registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.16.0 + image: registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.17.0 args: - --v=5 - --csi-address=/csi/csi.sock - --kubelet-registration-path=/var/lib/kubelet/plugins/csi-mock/csi.sock - --timeout=1m + - --http-endpoint=:9809 env: - name: KUBE_NODE_NAME valueFrom: fieldRef: apiVersion: v1 fieldPath: spec.nodeName + ports: + - containerPort: 9809 + name: healthz + protocol: TCP + livenessProbe: + httpGet: + path: /healthz + port: healthz + initialDelaySeconds: 30 + timeoutSeconds: 15 + periodSeconds: 10 + failureThreshold: 3 volumeMounts: - mountPath: /csi name: socket-dir From f220524f8021a4024143c2e898e235529f38e189 Mon Sep 17 00:00:00 2001 From: "Jonathan H. Cope" Date: Tue, 4 Aug 2026 11:26:04 -0500 Subject: [PATCH 5/8] update no-issue-add-asset-service-ca-config/vendor --- .../managementcpusoverride/admission.go | 26 +---- .../nodeselectoradjuster/admission.go | 61 ++++++++++- .../selinuxwarning/cache/openshift_patch.go | 18 ++++ .../openshift_upgrade_controller.go | 102 ++++++++++++++++++ .../selinux_warning_controller.go | 7 ++ .../pkg/features/openshift_features.go | 6 ++ .../rbac/bootstrappolicy/controller_policy.go | 4 + 7 files changed, 197 insertions(+), 27 deletions(-) create mode 100644 vendor/k8s.io/kubernetes/pkg/controller/volume/selinuxwarning/cache/openshift_patch.go create mode 100644 vendor/k8s.io/kubernetes/pkg/controller/volume/selinuxwarning/openshift_upgrade_controller.go diff --git a/vendor/k8s.io/kubernetes/openshift-kube-apiserver/admission/autoscaling/managementcpusoverride/admission.go b/vendor/k8s.io/kubernetes/openshift-kube-apiserver/admission/autoscaling/managementcpusoverride/admission.go index 9bf0a1f8a1..530639815a 100644 --- a/vendor/k8s.io/kubernetes/openshift-kube-apiserver/admission/autoscaling/managementcpusoverride/admission.go +++ b/vendor/k8s.io/kubernetes/openshift-kube-apiserver/admission/autoscaling/managementcpusoverride/admission.go @@ -17,7 +17,6 @@ import ( "k8s.io/apimachinery/pkg/api/errors" "k8s.io/apimachinery/pkg/api/resource" metav1 "k8s.io/apimachinery/pkg/apis/meta/v1" - "k8s.io/apimachinery/pkg/labels" "k8s.io/apimachinery/pkg/util/validation/field" "k8s.io/apiserver/pkg/admission" "k8s.io/apiserver/pkg/admission/initializer" @@ -187,16 +186,6 @@ func (a *managementCPUsOverride) Admit(ctx context.Context, attr admission.Attri return admission.NewForbidden(attr, fmt.Errorf("%s node or namespace or infra config cache not synchronized", PluginName)) } - nodes, err := a.nodeLister.List(labels.Everything()) - if err != nil { - return admission.NewForbidden(attr, err) // can happen due to informer latency - } - - // we still need to have nodes under the cluster to decide if the management resource enabled or not - if len(nodes) == 0 { - return admission.NewForbidden(attr, fmt.Errorf("%s the cluster does not have any nodes", PluginName)) - } - clusterInfra, err := a.infraConfigLister.Get(infraClusterName) if err != nil { return admission.NewForbidden(attr, err) // can happen due to informer latency @@ -215,7 +204,7 @@ func (a *managementCPUsOverride) Admit(ctx context.Context, attr admission.Attri } // Check if we are in CPU Partitioning mode for AllNodes - if !isCPUPartitioning(clusterInfra.Status, nodes, workloadType) { + if !isCPUPartitioning(clusterInfra.Status) { return nil } @@ -284,18 +273,7 @@ func (a *managementCPUsOverride) Admit(ctx context.Context, attr admission.Attri return nil } -func isCPUPartitioning(infraStatus configv1.InfrastructureStatus, nodes []*corev1.Node, workloadType string) bool { - // If status is not for CPU partitioning and we're single node we also check nodes to support upgrade event - // TODO: This should not be needed after 4.13 as all clusters after should have this feature on at install time, or updated by migration in NTO. - if infraStatus.CPUPartitioning != configv1.CPUPartitioningAllNodes && infraStatus.ControlPlaneTopology == configv1.SingleReplicaTopologyMode { - managedResource := fmt.Sprintf("%s.%s", workloadType, containerWorkloadResourceSuffix) - for _, node := range nodes { - // We only expect a single node to exist, so we return on first hit - if _, ok := node.Status.Allocatable[corev1.ResourceName(managedResource)]; ok { - return true - } - } - } +func isCPUPartitioning(infraStatus configv1.InfrastructureStatus) bool { return infraStatus.CPUPartitioning == configv1.CPUPartitioningAllNodes } diff --git a/vendor/k8s.io/kubernetes/openshift-kube-apiserver/admission/scheduler/nodeselectoradjuster/admission.go b/vendor/k8s.io/kubernetes/openshift-kube-apiserver/admission/scheduler/nodeselectoradjuster/admission.go index 9fa7770e9f..06a24fee8e 100644 --- a/vendor/k8s.io/kubernetes/openshift-kube-apiserver/admission/scheduler/nodeselectoradjuster/admission.go +++ b/vendor/k8s.io/kubernetes/openshift-kube-apiserver/admission/scheduler/nodeselectoradjuster/admission.go @@ -32,6 +32,19 @@ const ( // vpaOperatorNamespace is the namespace the VPA operator is expected to run in. vpaOperatorNamespace = "openshift-vertical-pod-autoscaler" + // croOperatorLabelKey / croOperatorLabelValue identify the CRO operator pod. + croOperatorLabelKey = "clusterresourceoverride.operator" + croOperatorLabelValue = "true" + // croOperatorNamespace is the namespace the CRO operator is expected to run in. + croOperatorNamespace = "openshift-cluster-resource-override" + + // cmaOperatorLabelKey / cmaOperatorLabelValue identify the CMA operator pod. + cmaOperatorLabelKey = "name" + cmaOperatorLabelValue = "custom-metrics-autoscaler-operator" + + // cmaOperatorNamespace is the namespace the CMA operator is expected to run in. + cmaOperatorNamespace = "openshift-keda" + // standaloneEnvVar is the environment variable checked at start-up. // It is injected by the downward API and reflects the namespace the // kube-apiserver pod runs in. @@ -93,16 +106,58 @@ func (p *nodeSelectorAdjuster) ValidateInitialization() error { // requiresNodeSelectorAdjustment returns true when the pod carries a label that // opts it in to control-plane node placement and lives in a namespace where that -// label is expected. Currently the VPA operator pod opts in via its well-known -// label. Future control-plane-adjacent Day 2 operators can be added here. +// label is expected. Control-plane-adjacent Day 2 operators can be added here. func requiresNodeSelectorAdjustment(pod *coreapi.Pod) bool { + // for VPA, we only want to update if the node selector is the default from + // https://github.com/openshift/vertical-pod-autoscaler-operator/blob/main/config/manager/manager.yaml if pod.Labels[vpaOperatorLabelKey] == vpaOperatorLabelValue && - pod.Namespace == vpaOperatorNamespace { + pod.Namespace == vpaOperatorNamespace && len(pod.Spec.NodeSelector) == 1 && + pod.Spec.NodeSelector["kubernetes.io/os"] == "linux" { return true } + // for CRO, we only want to update if the node selector empty + if pod.Labels[croOperatorLabelKey] == croOperatorLabelValue && + pod.Namespace == croOperatorNamespace && len(pod.Spec.NodeSelector) == 0 { + return true + } + // for CMA, we want to update if the node selector is empty + // and if it has a toleration that would tolerate the master NoSchedule taint + if pod.Labels[cmaOperatorLabelKey] == cmaOperatorLabelValue && + pod.Namespace == cmaOperatorNamespace && len(pod.Spec.NodeSelector) == 0 { + masterTaint := coreapi.Taint{ + Key: "node-role.kubernetes.io/master", + Effect: coreapi.TaintEffectNoSchedule, + } + for _, tol := range pod.Spec.Tolerations { + if toleratesTaint(tol, masterTaint) { + return true + } + } + } return false } +// toleratesTaint checks if a toleration tolerates a given taint, following the +// same rules as corev1.Toleration.ToleratesTaint: an empty effect matches all +// effects, the Exists operator matches any value, and an empty key with Exists +// matches all keys. +func toleratesTaint(tol coreapi.Toleration, taint coreapi.Taint) bool { + if len(tol.Effect) > 0 && tol.Effect != taint.Effect { + return false + } + if len(tol.Key) > 0 && tol.Key != taint.Key { + return false + } + switch tol.Operator { + case "", coreapi.TolerationOpEqual: + return tol.Value == taint.Value + case coreapi.TolerationOpExists: + return true + default: + return false + } +} + // addControlPlaneNodeSelector ensures spec.nodeSelector contains the control-plane role key. func addControlPlaneNodeSelector(pod *coreapi.Pod) { if pod.Spec.NodeSelector == nil { diff --git a/vendor/k8s.io/kubernetes/pkg/controller/volume/selinuxwarning/cache/openshift_patch.go b/vendor/k8s.io/kubernetes/pkg/controller/volume/selinuxwarning/cache/openshift_patch.go new file mode 100644 index 0000000000..d0c66ab8de --- /dev/null +++ b/vendor/k8s.io/kubernetes/pkg/controller/volume/selinuxwarning/cache/openshift_patch.go @@ -0,0 +1,18 @@ +package cache + +type ConflictCounter interface { + GetConflictCount() int +} + +var _ ConflictCounter = &volumeCache{} + +func (c *volumeCache) GetConflictCount() int { + c.mutex.RLock() + defer c.mutex.RUnlock() + + conflictCount := 0 + for _, conflicts := range c.conflicts { + conflictCount += len(conflicts) + } + return conflictCount +} diff --git a/vendor/k8s.io/kubernetes/pkg/controller/volume/selinuxwarning/openshift_upgrade_controller.go b/vendor/k8s.io/kubernetes/pkg/controller/volume/selinuxwarning/openshift_upgrade_controller.go new file mode 100644 index 0000000000..39eeb9853c --- /dev/null +++ b/vendor/k8s.io/kubernetes/pkg/controller/volume/selinuxwarning/openshift_upgrade_controller.go @@ -0,0 +1,102 @@ +package selinuxwarning + +import ( + "context" + "fmt" + "time" + + metav1 "k8s.io/apimachinery/pkg/apis/meta/v1" + utilfeature "k8s.io/apiserver/pkg/util/feature" + applyconfigurationscorev1 "k8s.io/client-go/applyconfigurations/core/v1" + clientset "k8s.io/client-go/kubernetes" + "k8s.io/klog/v2" + "k8s.io/kubernetes/pkg/controller/volume/selinuxwarning/cache" + "k8s.io/kubernetes/pkg/features" +) + +const ( + checkInterval = 30 * time.Second + configMapNamespace = "openshift-config" + configMapName = "selinux-conflicts" + fieldManager = "selinux-conflicts-reporter" +) + +type SELinuxConflictsReporterController struct { + kubeClient clientset.Interface + conflictCounter cache.ConflictCounter + previousConflicts metav1.ConditionStatus +} + +func NewSELinuxConflictsReporterController(kubeClient clientset.Interface, volumeCache cache.VolumeCache) *SELinuxConflictsReporterController { + return &SELinuxConflictsReporterController{ + kubeClient: kubeClient, + // Ugly retype to avoid more carry patches in Kubernetes code. + // We added ConflictCounter in cache/openshift_patch.go, + // therefore we know that VolumeCache implements it. + conflictCounter: volumeCache.(cache.ConflictCounter), + previousConflicts: metav1.ConditionUnknown, + } +} + +func (c *SELinuxConflictsReporterController) Run(ctx context.Context) { + logger := klog.FromContext(ctx) + if !utilfeature.DefaultFeatureGate.Enabled(features.SELinuxMountGAReadiness) { + logger.V(2).Info("SELinuxMountGAReadiness feature gate is disabled, not starting OpenShift SELinux conflicts reporter") + return + } + logger.V(2).Info("Starting OpenShift SELinux conflicts reporter") + timer := time.NewTimer(checkInterval) + defer timer.Stop() + for { + select { + case <-ctx.Done(): + return + case <-timer.C: + c.reportSELinuxConflicts(ctx) + timer.Reset(checkInterval) + } + } +} + +func (c *SELinuxConflictsReporterController) reportSELinuxConflicts(ctx context.Context) { + logger := klog.FromContext(ctx) + logger.V(4).Info("Checking for SELinux conflicts") + + currentConflicts := c.getConflicts(logger) + if currentConflicts == c.previousConflicts { + logger.V(4).Info("SELinux conflict status did not change since last check") + return + } + logger.V(4).Info("SELinux conflict status changed, updating the config map") + if err := c.applySELinuxConflictsConfigMap(ctx, currentConflicts); err != nil { + logger.Error(err, "Error saving conflicts config map") + // To keep it simple: no exponential backoff try again in the next iteration. + return + } + logger.V(2).Info("SELinux conflict updated", "Conflicts", currentConflicts) + c.previousConflicts = currentConflicts +} + +func (c *SELinuxConflictsReporterController) getConflicts(logger klog.Logger) metav1.ConditionStatus { + conflictsCount := c.conflictCounter.GetConflictCount() + if conflictsCount > 0 { + logger.V(4).Info("Found SELinux-conflicting pods", "conflictsCount", conflictsCount) + return metav1.ConditionTrue + } + logger.V(4).Info("Found no SELinux-conflicting pods") + return metav1.ConditionFalse +} + +func (c *SELinuxConflictsReporterController) applySELinuxConflictsConfigMap(ctx context.Context, conflictsPresent metav1.ConditionStatus) error { + cm := applyconfigurationscorev1.ConfigMap(configMapName, configMapNamespace). + WithData(map[string]string{ + "conflictsPresent": string(conflictsPresent), + }).WithAnnotations(map[string]string{ + "Description": "This config map is used to report presence of SELinux conflicts from kube-controller-manager to storage Upgradeable condition in OpenShift 5.0", + }) + _, err := c.kubeClient.CoreV1().ConfigMaps(configMapNamespace).Apply(ctx, cm, metav1.ApplyOptions{FieldManager: fieldManager, Force: true}) + if err != nil { + return fmt.Errorf("error applying config map %s: %w", configMapName, err) + } + return nil +} diff --git a/vendor/k8s.io/kubernetes/pkg/controller/volume/selinuxwarning/selinux_warning_controller.go b/vendor/k8s.io/kubernetes/pkg/controller/volume/selinuxwarning/selinux_warning_controller.go index 53c08d1f6a..488a19161d 100644 --- a/vendor/k8s.io/kubernetes/pkg/controller/volume/selinuxwarning/selinux_warning_controller.go +++ b/vendor/k8s.io/kubernetes/pkg/controller/volume/selinuxwarning/selinux_warning_controller.go @@ -380,6 +380,13 @@ func (c *Controller) Run(ctx context.Context, workers int) { wait.UntilWithContext(ctx, c.runWorker, time.Second) }) } + + seLinuxConflictsReporterController := NewSELinuxConflictsReporterController(c.kubeClient, c.labelCache) + wg.Go(func() { + defer utilruntime.HandleCrash() + seLinuxConflictsReporterController.Run(ctx) + }) + <-ctx.Done() } diff --git a/vendor/k8s.io/kubernetes/pkg/features/openshift_features.go b/vendor/k8s.io/kubernetes/pkg/features/openshift_features.go index 434781ba97..b09d7fe484 100644 --- a/vendor/k8s.io/kubernetes/pkg/features/openshift_features.go +++ b/vendor/k8s.io/kubernetes/pkg/features/openshift_features.go @@ -9,6 +9,7 @@ var ( RouteExternalCertificate featuregate.Feature = "RouteExternalCertificate" MinimumKubeletVersion featuregate.Feature = "MinimumKubeletVersion" StoragePerformantSecurityPolicy featuregate.Feature = "StoragePerformantSecurityPolicy" + SELinuxMountGAReadiness featuregate.Feature = "SELinuxMountGAReadiness" ) // registerOpenshiftFeatures injects openshift-specific feature gates @@ -25,8 +26,13 @@ func registerOpenshiftFeatures() { defaultVersionedKubernetesFeatureGates[StoragePerformantSecurityPolicy] = featuregate.VersionedSpecs{ {Version: version.MustParse("1.33"), Default: false, PreRelease: featuregate.Alpha}, } + // Introduced in 5.0 + defaultVersionedKubernetesFeatureGates[SELinuxMountGAReadiness] = featuregate.VersionedSpecs{ + {Version: version.MustParse("1.35"), Default: false, PreRelease: featuregate.Alpha}, + } defaultKubernetesFeatureGateDependencies[RouteExternalCertificate] = []featuregate.Feature{} defaultKubernetesFeatureGateDependencies[MinimumKubeletVersion] = []featuregate.Feature{} defaultKubernetesFeatureGateDependencies[StoragePerformantSecurityPolicy] = []featuregate.Feature{} + defaultKubernetesFeatureGateDependencies[SELinuxMountGAReadiness] = []featuregate.Feature{} } diff --git a/vendor/k8s.io/kubernetes/plugin/pkg/auth/authorizer/rbac/bootstrappolicy/controller_policy.go b/vendor/k8s.io/kubernetes/plugin/pkg/auth/authorizer/rbac/bootstrappolicy/controller_policy.go index 994e716a28..ddcafd16ae 100644 --- a/vendor/k8s.io/kubernetes/plugin/pkg/auth/authorizer/rbac/bootstrappolicy/controller_policy.go +++ b/vendor/k8s.io/kubernetes/plugin/pkg/auth/authorizer/rbac/bootstrappolicy/controller_policy.go @@ -606,6 +606,10 @@ func buildControllerRoles() ([]rbacv1.ClusterRole, []rbacv1.ClusterRoleBinding) rbacv1helpers.NewRule("get", "list", "watch").Groups(legacyGroup).Resources("persistentvolumeclaims").RuleOrDie(), rbacv1helpers.NewRule("get", "list", "watch").Groups(legacyGroup).Resources("pods").RuleOrDie(), rbacv1helpers.NewRule("get", "list", "watch").Groups(storageGroup).Resources("csidrivers").RuleOrDie(), + // RBAC cannot restrict `create` by resourceName, so adding a generic rule to allow creation of any ConfigMap + rbacv1helpers.NewRule("create").Groups(legacyGroup).Resources("configmaps").RuleOrDie(), + // ... and allow patching only of the selinux-conflicts ConfigMap + rbacv1helpers.NewRule("patch").Groups(legacyGroup).Resources("configmaps").Names("selinux-conflicts").RuleOrDie(), }, }) } From 0760cfd6d3a18352718a6030b0e2a005fd16c755 Mon Sep 17 00:00:00 2001 From: "Jonathan H. Cope" Date: Tue, 4 Aug 2026 11:26:07 -0500 Subject: [PATCH 6/8] update component images --- packaging/crio.conf.d/10-microshift_amd64.conf | 2 +- packaging/crio.conf.d/10-microshift_arm64.conf | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/packaging/crio.conf.d/10-microshift_amd64.conf b/packaging/crio.conf.d/10-microshift_amd64.conf index ae8b830aa9..7b5ffc6733 100644 --- a/packaging/crio.conf.d/10-microshift_amd64.conf +++ b/packaging/crio.conf.d/10-microshift_amd64.conf @@ -2,6 +2,6 @@ # for community builds on top of OKD, this setting has no effect [crio.image] global_auth_file="/etc/crio/openshift-pull-secret" -pause_image = "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:046dee0e64bb32cdb9d34b43abc4c1b8f2d1700e2243e3812b759e1436677c9b" +pause_image = "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:517544c0297e5cb78c22931aafaf50e370e397873247a5231310f3ca98693e23" pause_image_auth_file = "/etc/crio/openshift-pull-secret" pause_command = "/usr/bin/pod" diff --git a/packaging/crio.conf.d/10-microshift_arm64.conf b/packaging/crio.conf.d/10-microshift_arm64.conf index 22790acdd0..5409b492e2 100644 --- a/packaging/crio.conf.d/10-microshift_arm64.conf +++ b/packaging/crio.conf.d/10-microshift_arm64.conf @@ -2,6 +2,6 @@ # for community builds on top of OKD, this setting has no effect [crio.image] global_auth_file="/etc/crio/openshift-pull-secret" -pause_image = "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:a3aba52ab6f516a28f1423d2f71e9e3320d8486a266ca0e8430e47b77c38de9c" +pause_image = "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:9f0b32aea13d54846f8456797b15ae7802ffacb788c0942ed6d6d85a43152369" pause_image_auth_file = "/etc/crio/openshift-pull-secret" pause_command = "/usr/bin/pod" From 377e7e2e5e9275cbdd514f4054477f74122ffc21 Mon Sep 17 00:00:00 2001 From: "Jonathan H. Cope" Date: Tue, 4 Aug 2026 11:26:11 -0500 Subject: [PATCH 7/8] update manifests --- .../multus/kustomization.aarch64.yaml | 4 +- .../multus/kustomization.x86_64.yaml | 4 +- .../multus/release-multus-aarch64.json | 6 +-- .../multus/release-multus-x86_64.json | 6 +-- .../service-ca/controller-config.yaml | 9 ++++ assets/components/service-ca/deployment.yaml | 9 +++- .../0000_50_olm_01-networkpolicies.yaml | 46 +++++++++++++++++++ .../kustomization.aarch64.yaml | 10 ++-- .../kustomization.x86_64.yaml | 10 ++-- .../release-olm-aarch64.json | 8 ++-- .../release-olm-x86_64.json | 8 ++-- assets/release/release-aarch64.json | 18 ++++---- assets/release/release-x86_64.json | 18 ++++---- 13 files changed, 108 insertions(+), 48 deletions(-) create mode 100644 assets/components/service-ca/controller-config.yaml diff --git a/assets/components/multus/kustomization.aarch64.yaml b/assets/components/multus/kustomization.aarch64.yaml index 2df3672ef8..962a3595fc 100644 --- a/assets/components/multus/kustomization.aarch64.yaml +++ b/assets/components/multus/kustomization.aarch64.yaml @@ -2,7 +2,7 @@ images: - name: multus-cni-microshift newName: quay.io/openshift-release-dev/ocp-v5.0-art-dev - digest: sha256:a0c089dbbd138b47d7467ce50d0ea3eff60bff9674a34d429078118eeabb78a3 + digest: sha256:8345d8ef1ce21f88e4d7b3d2fbd525aae89364441ab252a8554f699faab1f2d0 - name: containernetworking-plugins-microshift newName: quay.io/openshift-release-dev/ocp-v5.0-art-dev - digest: sha256:1557d1200e7c7c8672f9cd9fa145874d43967f61f798f27894f643d5b857b99a + digest: sha256:ddc451bab694022b54bb769e02c43c4371f84e12e701f1b944ed47d54f1f0e0c diff --git a/assets/components/multus/kustomization.x86_64.yaml b/assets/components/multus/kustomization.x86_64.yaml index 234e0862de..7c38bb3886 100644 --- a/assets/components/multus/kustomization.x86_64.yaml +++ b/assets/components/multus/kustomization.x86_64.yaml @@ -2,7 +2,7 @@ images: - name: multus-cni-microshift newName: quay.io/openshift-release-dev/ocp-v5.0-art-dev - digest: sha256:29f31422d6d637e350f99a58001ef8929cb151497ccc4d4f128d3b408812f635 + digest: sha256:6e2d67797d6642e62366d3fe4640e6bd285c9ca8e77e6507779c7f2d039d7999 - name: containernetworking-plugins-microshift newName: quay.io/openshift-release-dev/ocp-v5.0-art-dev - digest: sha256:c63df61df4155fb06d9da879bb7d0e96b5e34161e1ad78e43e87d0690fcae29a + digest: sha256:33688e39cfa0ee183a46d1e796bb3f173690ff81d2d602a03c3dd091e9a42ec9 diff --git a/assets/components/multus/release-multus-aarch64.json b/assets/components/multus/release-multus-aarch64.json index da7ab1020d..59ab83fde7 100644 --- a/assets/components/multus/release-multus-aarch64.json +++ b/assets/components/multus/release-multus-aarch64.json @@ -1,9 +1,9 @@ { "release": { - "base": "5.0.0-0.nightly-arm64-2026-07-27-004356" + "base": "5.0.0-0.nightly-arm64-2026-08-03-232352" }, "images": { - "multus-cni-microshift": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:a0c089dbbd138b47d7467ce50d0ea3eff60bff9674a34d429078118eeabb78a3", - "containernetworking-plugins-microshift": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:1557d1200e7c7c8672f9cd9fa145874d43967f61f798f27894f643d5b857b99a" + "multus-cni-microshift": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:8345d8ef1ce21f88e4d7b3d2fbd525aae89364441ab252a8554f699faab1f2d0", + "containernetworking-plugins-microshift": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:ddc451bab694022b54bb769e02c43c4371f84e12e701f1b944ed47d54f1f0e0c" } } diff --git a/assets/components/multus/release-multus-x86_64.json b/assets/components/multus/release-multus-x86_64.json index eee6612c5f..5ad9b4288e 100644 --- a/assets/components/multus/release-multus-x86_64.json +++ b/assets/components/multus/release-multus-x86_64.json @@ -1,9 +1,9 @@ { "release": { - "base": "5.0.0-0.nightly-2026-07-23-224236" + "base": "5.0.0-0.nightly-2026-08-03-043516" }, "images": { - "multus-cni-microshift": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:29f31422d6d637e350f99a58001ef8929cb151497ccc4d4f128d3b408812f635", - "containernetworking-plugins-microshift": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:c63df61df4155fb06d9da879bb7d0e96b5e34161e1ad78e43e87d0690fcae29a" + "multus-cni-microshift": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:6e2d67797d6642e62366d3fe4640e6bd285c9ca8e77e6507779c7f2d039d7999", + "containernetworking-plugins-microshift": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:33688e39cfa0ee183a46d1e796bb3f173690ff81d2d602a03c3dd091e9a42ec9" } } diff --git a/assets/components/service-ca/controller-config.yaml b/assets/components/service-ca/controller-config.yaml new file mode 100644 index 0000000000..fbd3fd9acc --- /dev/null +++ b/assets/components/service-ca/controller-config.yaml @@ -0,0 +1,9 @@ +apiVersion: v1 +kind: ConfigMap +metadata: + namespace: openshift-service-ca + name: service-ca-controller-config +data: + controller-config.yaml: | + apiVersion: operator.openshift.io/v1alpha1 + kind: GenericOperatorConfig diff --git a/assets/components/service-ca/deployment.yaml b/assets/components/service-ca/deployment.yaml index f51d49b47d..a9dfd43a7a 100644 --- a/assets/components/service-ca/deployment.yaml +++ b/assets/components/service-ca/deployment.yaml @@ -29,6 +29,8 @@ spec: image: '{{ .ReleaseImage.service_ca_operator }}' imagePullPolicy: IfNotPresent command: ["service-ca-operator", "controller"] + args: + - -v=2 ports: - containerPort: 8443 securityContext: @@ -45,8 +47,8 @@ spec: name: signing-key - mountPath: /var/run/configmaps/signing-cabundle name: signing-cabundle - args: - - -v=2 + - mountPath: /var/run/configmaps/config + name: config volumes: - name: signing-key secret: @@ -54,6 +56,9 @@ spec: - name: signing-cabundle configMap: name: '{{.CAConfigMap}}' + - name: config + configMap: + name: service-ca-controller-config nodeSelector: node-role.kubernetes.io/master: "" priorityClassName: "system-cluster-critical" diff --git a/assets/optional/operator-lifecycle-manager/0000_50_olm_01-networkpolicies.yaml b/assets/optional/operator-lifecycle-manager/0000_50_olm_01-networkpolicies.yaml index c991681f8d..fead054ab1 100644 --- a/assets/optional/operator-lifecycle-manager/0000_50_olm_01-networkpolicies.yaml +++ b/assets/optional/operator-lifecycle-manager/0000_50_olm_01-networkpolicies.yaml @@ -103,3 +103,49 @@ spec: - {} egress: - {} +--- +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy +metadata: + name: olm-catalog-grpc-ingress + namespace: openshift-marketplace + annotations: + include.release.openshift.io/ibm-cloud-managed: "true" + include.release.openshift.io/self-managed-high-availability: "true" + capability.openshift.io/name: "OperatorLifecycleManager" + include.release.openshift.io/hypershift: "true" +spec: + podSelector: + matchExpressions: + - key: olm.catalogSource + operator: Exists + policyTypes: + - Ingress + ingress: + - ports: + - protocol: TCP + port: 50051 +--- +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy +metadata: + name: bundle-unpack-egress + namespace: openshift-marketplace + annotations: + include.release.openshift.io/ibm-cloud-managed: "true" + include.release.openshift.io/self-managed-high-availability: "true" + capability.openshift.io/name: "OperatorLifecycleManager" + include.release.openshift.io/hypershift: "true" +spec: + podSelector: + matchExpressions: + - key: operatorframework.io/bundle-unpack-ref + operator: Exists + - key: olm.managed + operator: In + values: + - "true" + policyTypes: + - Egress + egress: + - {} diff --git a/assets/optional/operator-lifecycle-manager/kustomization.aarch64.yaml b/assets/optional/operator-lifecycle-manager/kustomization.aarch64.yaml index cec9490c75..f86d30ed34 100644 --- a/assets/optional/operator-lifecycle-manager/kustomization.aarch64.yaml +++ b/assets/optional/operator-lifecycle-manager/kustomization.aarch64.yaml @@ -2,13 +2,13 @@ images: - name: quay.io/operator-framework/olm newName: quay.io/openshift-release-dev/ocp-v5.0-art-dev - digest: sha256:c8eebdd593891b886d0fb2fc554b2cbcf39c77c57c8582b72c9647cf9e0f8684 + digest: sha256:c4a15a469eece9e8168a337332b7029b0dac2ae3c3c9f1cf9ca1ec357462db7e - name: quay.io/operator-framework/configmap-operator-registry newName: quay.io/openshift-release-dev/ocp-v5.0-art-dev - digest: sha256:823e379c09c3e2c566efe5c95f91134eb4170643fe2ba5633bcd382738cc841c + digest: sha256:7ff48d8916e2b6843e702ac94df2578a51db6d5f9f7e21d7a94f16b0ddcd3b30 - name: quay.io/openshift/origin-kube-rbac-proxy newName: quay.io/openshift-release-dev/ocp-v5.0-art-dev - digest: sha256:fc51b97845de29e7a245f185d31ff8adb2c7b7a5350686876a700104499ae2f5 + digest: sha256:ce1804e33b1da036e9603b1f513e4fadd4649a556661412c559f5f5b6a500ae7 patches: - patch: |- @@ -16,12 +16,12 @@ patches: path: /spec/template/spec/containers/0/env/- value: name: OPERATOR_REGISTRY_IMAGE - value: quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:823e379c09c3e2c566efe5c95f91134eb4170643fe2ba5633bcd382738cc841c + value: quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:7ff48d8916e2b6843e702ac94df2578a51db6d5f9f7e21d7a94f16b0ddcd3b30 - op: add path: /spec/template/spec/containers/0/env/- value: name: OLM_IMAGE - value: quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:c8eebdd593891b886d0fb2fc554b2cbcf39c77c57c8582b72c9647cf9e0f8684 + value: quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:c4a15a469eece9e8168a337332b7029b0dac2ae3c3c9f1cf9ca1ec357462db7e target: kind: Deployment labelSelector: app=catalog-operator diff --git a/assets/optional/operator-lifecycle-manager/kustomization.x86_64.yaml b/assets/optional/operator-lifecycle-manager/kustomization.x86_64.yaml index 139b453dee..f3b91de9d3 100644 --- a/assets/optional/operator-lifecycle-manager/kustomization.x86_64.yaml +++ b/assets/optional/operator-lifecycle-manager/kustomization.x86_64.yaml @@ -2,13 +2,13 @@ images: - name: quay.io/operator-framework/olm newName: quay.io/openshift-release-dev/ocp-v5.0-art-dev - digest: sha256:18957bcdaaa13c8c028b3742805b66d30d82fab2273dbeb71938844c44c5d5c5 + digest: sha256:12473d0a633259fac47965423b1dcb1c3353c3359f5f75ca335e233202c28d3d - name: quay.io/operator-framework/configmap-operator-registry newName: quay.io/openshift-release-dev/ocp-v5.0-art-dev - digest: sha256:714be6db62abadfce860b3ace30d35e63e087d9bf07ac3e667578d91e8659fcd + digest: sha256:3d1b75883c0a9b7592b4b5303be10bb420b1139b57b97d4ee741ee4416019b27 - name: quay.io/openshift/origin-kube-rbac-proxy newName: quay.io/openshift-release-dev/ocp-v5.0-art-dev - digest: sha256:849ba7d8ef4add8ef5841c14276f97cf9920b33bebf26ee021d72f08064e7abb + digest: sha256:ef81059f46c0dc37a53235bcb69decf96fa8ea62c9e4284a26ec674de267a75e patches: - patch: |- @@ -16,12 +16,12 @@ patches: path: /spec/template/spec/containers/0/env/- value: name: OPERATOR_REGISTRY_IMAGE - value: quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:714be6db62abadfce860b3ace30d35e63e087d9bf07ac3e667578d91e8659fcd + value: quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:3d1b75883c0a9b7592b4b5303be10bb420b1139b57b97d4ee741ee4416019b27 - op: add path: /spec/template/spec/containers/0/env/- value: name: OLM_IMAGE - value: quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:18957bcdaaa13c8c028b3742805b66d30d82fab2273dbeb71938844c44c5d5c5 + value: quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:12473d0a633259fac47965423b1dcb1c3353c3359f5f75ca335e233202c28d3d target: kind: Deployment labelSelector: app=catalog-operator diff --git a/assets/optional/operator-lifecycle-manager/release-olm-aarch64.json b/assets/optional/operator-lifecycle-manager/release-olm-aarch64.json index fbad187d45..707e40f368 100644 --- a/assets/optional/operator-lifecycle-manager/release-olm-aarch64.json +++ b/assets/optional/operator-lifecycle-manager/release-olm-aarch64.json @@ -1,10 +1,10 @@ { "release": { - "base": "5.0.0-0.nightly-arm64-2026-07-27-004356" + "base": "5.0.0-0.nightly-arm64-2026-08-03-232352" }, "images": { - "operator-lifecycle-manager": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:c8eebdd593891b886d0fb2fc554b2cbcf39c77c57c8582b72c9647cf9e0f8684", - "operator-registry": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:823e379c09c3e2c566efe5c95f91134eb4170643fe2ba5633bcd382738cc841c", - "kube-rbac-proxy": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:fc51b97845de29e7a245f185d31ff8adb2c7b7a5350686876a700104499ae2f5" + "operator-lifecycle-manager": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:c4a15a469eece9e8168a337332b7029b0dac2ae3c3c9f1cf9ca1ec357462db7e", + "operator-registry": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:7ff48d8916e2b6843e702ac94df2578a51db6d5f9f7e21d7a94f16b0ddcd3b30", + "kube-rbac-proxy": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:ce1804e33b1da036e9603b1f513e4fadd4649a556661412c559f5f5b6a500ae7" } } diff --git a/assets/optional/operator-lifecycle-manager/release-olm-x86_64.json b/assets/optional/operator-lifecycle-manager/release-olm-x86_64.json index 2e22dd7e93..61bcacf19c 100644 --- a/assets/optional/operator-lifecycle-manager/release-olm-x86_64.json +++ b/assets/optional/operator-lifecycle-manager/release-olm-x86_64.json @@ -1,10 +1,10 @@ { "release": { - "base": "5.0.0-0.nightly-2026-07-23-224236" + "base": "5.0.0-0.nightly-2026-08-03-043516" }, "images": { - "operator-lifecycle-manager": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:18957bcdaaa13c8c028b3742805b66d30d82fab2273dbeb71938844c44c5d5c5", - "operator-registry": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:714be6db62abadfce860b3ace30d35e63e087d9bf07ac3e667578d91e8659fcd", - "kube-rbac-proxy": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:849ba7d8ef4add8ef5841c14276f97cf9920b33bebf26ee021d72f08064e7abb" + "operator-lifecycle-manager": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:12473d0a633259fac47965423b1dcb1c3353c3359f5f75ca335e233202c28d3d", + "operator-registry": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:3d1b75883c0a9b7592b4b5303be10bb420b1139b57b97d4ee741ee4416019b27", + "kube-rbac-proxy": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:ef81059f46c0dc37a53235bcb69decf96fa8ea62c9e4284a26ec674de267a75e" } } diff --git a/assets/release/release-aarch64.json b/assets/release/release-aarch64.json index 3c4ef3df31..bcc6eb3edc 100644 --- a/assets/release/release-aarch64.json +++ b/assets/release/release-aarch64.json @@ -1,16 +1,16 @@ { "release": { - "base": "5.0.0-0.nightly-arm64-2026-07-27-004356" + "base": "5.0.0-0.nightly-arm64-2026-08-03-232352" }, "images": { - "cli": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:aa5ae933124990ac8342023e51870cf4d07884243e09afaf62417a0363a9729d", - "coredns": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:3bd36df30411a20a17e54c90ccf9d993832da0ada367da6e0c3f28a83216f879", - "haproxy-router": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:15e8952c1875922024db7b12af4990488d129afb1c25b7c5a653e830e0ec28f3", - "kube-rbac-proxy": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:fc51b97845de29e7a245f185d31ff8adb2c7b7a5350686876a700104499ae2f5", - "ovn-kubernetes-microshift": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:38885d2ed82f8089323768d6afffd298e8779dc440d88e91a97fab1d9310d486", - "pod": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:a3aba52ab6f516a28f1423d2f71e9e3320d8486a266ca0e8430e47b77c38de9c", - "service-ca-operator": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:648ad75c87d184155041dcd9cc76e135aea9050c07779edb473e26bd87342f19", + "cli": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:1136557f467a7856f31e8f109e66971c4d1671edccc1430f8ea65c825d8f425f", + "coredns": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:8e130d9a4f475c7582f30e9cd25273c0b6f2019e0ee70be9b8ba711b65ce0501", + "haproxy-router": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:67a3806c99aa412c4fc96ae443b18640e238a65185bb965ce1d875dfbe5fa673", + "kube-rbac-proxy": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:ce1804e33b1da036e9603b1f513e4fadd4649a556661412c559f5f5b6a500ae7", + "ovn-kubernetes-microshift": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:cf3bb8e85c1394d5818cc6010a2ef294b45d7587ef0539f3c57ba4a49c234ed6", + "pod": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:9f0b32aea13d54846f8456797b15ae7802ffacb788c0942ed6d6d85a43152369", + "service-ca-operator": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:8111f2595c48571edaa61f8abeec4d6548e4eb75dca01e549df24f17b1e26041", "lvms_operator": "registry.redhat.io/lvms4/lvms-rhel9-operator@sha256:e77365e44676fbd8ab9e4ce53f3a406856bbdfef3467c545a7df1197d84477af", - "csi-snapshot-controller": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:94fbbcfffd5a5503f3ea5ab43f13c325c3765c33db2b4e5d040c07ded10f8c6e" + "csi-snapshot-controller": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:b732df6d49a0b6b0092562a4db227759daa26c8b9e7da0b940c103d623724ef5" } } diff --git a/assets/release/release-x86_64.json b/assets/release/release-x86_64.json index f2adf17ca3..136af42a98 100644 --- a/assets/release/release-x86_64.json +++ b/assets/release/release-x86_64.json @@ -1,16 +1,16 @@ { "release": { - "base": "5.0.0-0.nightly-2026-07-23-224236" + "base": "5.0.0-0.nightly-2026-08-03-043516" }, "images": { - "cli": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:45188944bb589e9b3fd88bd175a18b9414a2ba070e2a08a3964e22ceedaf2955", - "coredns": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:f8333c52e3b4ec5d1575a31276b9600f173ddda7d6f1a0cb11f0d364fe5be29a", - "haproxy-router": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:9d40caf7c3a21b802c6632cf968b8c17f5bb756b6ff0564b77ee2dc9898e38f3", - "kube-rbac-proxy": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:849ba7d8ef4add8ef5841c14276f97cf9920b33bebf26ee021d72f08064e7abb", - "ovn-kubernetes-microshift": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:e05f31e81de47bfb323c9015b117bf2dcf34abb56d7effcd43513378ef45aae6", - "pod": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:046dee0e64bb32cdb9d34b43abc4c1b8f2d1700e2243e3812b759e1436677c9b", - "service-ca-operator": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:dcdfe8696ab6c9c7098e3ea2d297af47b68e91eac931364e13e46edd28b2a479", + "cli": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:4884e78ebfe844890f68ab0f53db01aada34a77f35922c2802c0267ddb598758", + "coredns": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:94448fb8bb5c4e0afd40efb42b6660bb60e3c8bb0289bc5a7b8325bd2125b2ac", + "haproxy-router": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:9a4b4222fd8b9abdf05c2f80632ecc81bcbe8083ab2b3326a935166c0f39d3a1", + "kube-rbac-proxy": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:ef81059f46c0dc37a53235bcb69decf96fa8ea62c9e4284a26ec674de267a75e", + "ovn-kubernetes-microshift": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:1364b024af032c81c416b34b67654a402c70682cff84040f3f94ab01419d3bd2", + "pod": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:517544c0297e5cb78c22931aafaf50e370e397873247a5231310f3ca98693e23", + "service-ca-operator": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:128583c5a5d4ce064507bbbf55e1ed7cfed6ddc23662722826ab11ea26bb16f9", "lvms_operator": "registry.redhat.io/lvms4/lvms-rhel9-operator@sha256:10c9ccab4f2857d113b55e12cac29aed0dc97d5a4e29ed2e4ea0f77551ee55f8", - "csi-snapshot-controller": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:f0631a7e1e3aa1cf6ac01df7a7b0b8ce5f5ad333e2efc8f4599b4428a6d54c22" + "csi-snapshot-controller": "quay.io/openshift-release-dev/ocp-v5.0-art-dev@sha256:6f62fdad64584a10b70e8dff9e2960bdb4c53f5fb070fda0d517cf571f639ebc" } } From 6295fb1a38711aff6b7ec4732a6cd3e25fc92fce Mon Sep 17 00:00:00 2001 From: "Jonathan H. Cope" Date: Tue, 4 Aug 2026 11:26:12 -0500 Subject: [PATCH 8/8] update buildfiles --- Makefile.kube_git.var | 2 +- Makefile.version.aarch64.var | 2 +- Makefile.version.x86_64.var | 2 +- pkg/components/controllers.go | 13 ++++++++++--- 4 files changed, 13 insertions(+), 6 deletions(-) diff --git a/Makefile.kube_git.var b/Makefile.kube_git.var index 64a966edca..919e32dc31 100644 --- a/Makefile.kube_git.var +++ b/Makefile.kube_git.var @@ -1,5 +1,5 @@ KUBE_GIT_MAJOR=1 KUBE_GIT_MINOR=36 KUBE_GIT_VERSION=v1.36.2 -KUBE_GIT_COMMIT=98b35193b2ac7a23a673325f5e9b830ecd5ba406 +KUBE_GIT_COMMIT=e63ab41237b34f2a457e76900f6162184420cf96 KUBE_GIT_TREE_STATE=clean diff --git a/Makefile.version.aarch64.var b/Makefile.version.aarch64.var index 1b287e6e86..0c2acbdd4b 100644 --- a/Makefile.version.aarch64.var +++ b/Makefile.version.aarch64.var @@ -1 +1 @@ -OCP_VERSION := 5.0.0-0.nightly-arm64-2026-07-27-004356 +OCP_VERSION := 5.0.0-0.nightly-arm64-2026-08-03-232352 diff --git a/Makefile.version.x86_64.var b/Makefile.version.x86_64.var index cf840335be..b993d3e8e0 100644 --- a/Makefile.version.x86_64.var +++ b/Makefile.version.x86_64.var @@ -1 +1 @@ -OCP_VERSION := 5.0.0-0.nightly-2026-07-23-224236 +OCP_VERSION := 5.0.0-0.nightly-2026-08-03-043516 diff --git a/pkg/components/controllers.go b/pkg/components/controllers.go index 52074bcf87..024f3b9025 100644 --- a/pkg/components/controllers.go +++ b/pkg/components/controllers.go @@ -100,9 +100,12 @@ func startServiceCAController(ctx context.Context, cfg *config.Config, kubeconfi sa = []string{ "components/service-ca/sa.yaml", } + cm = []string{ + "components/service-ca/controller-config.yaml", + } secret = "components/service-ca/signing-secret.yaml" secretName = "signing-key" - cm = "components/service-ca/signing-cabundle.yaml" + cmCaBundle = "components/service-ca/signing-cabundle.yaml" cmName = "signing-cabundle" ) @@ -153,8 +156,12 @@ func startServiceCAController(ctx context.Context, cfg *config.Config, kubeconfi klog.Warningf("Failed to apply secret %v: %v", secret, err) return err } - if err := assets.ApplyConfigMapWithData(ctx, cm, cmData, kubeconfigPath); err != nil { - klog.Warningf("Failed to apply configMap %v: %v", cm, err) + if err := assets.ApplyConfigMapWithData(ctx, cmCaBundle, cmData, kubeconfigPath); err != nil { + klog.Warningf("Failed to apply configMap %v: %v", cmCaBundle, err) + return err + } + if err := assets.ApplyConfigMaps(ctx, cm, nil, nil, kubeconfigPath); err != nil { + klog.Warningf("Failed to apply configMaps %v: %v", cm, err) return err } extraParams := assets.RenderParams{