Skip to content

fix: add CPO and CVO Quay exceptions to image registry VAP for all environments - #7242

Merged
openshift-merge-bot[bot] merged 1 commit into
Azure:mainfrom
avollmer-redhat:fix/aroslsre-861-restore-cpo-vap-exception-dev
Oct 1, 2026
Merged

openshift-merge-bot[bot] merged 1 commit into
Azure:mainfrom
avollmer-redhat:fix/aroslsre-861-restore-cpo-vap-exception-dev

Conversation

@avollmer-redhat

@avollmer-redhat Anthony Vollmer (avollmer-redhat) commented Sep 29, 2026 •

Copy link
Copy Markdown
Collaborator

Why

HyperShift does not rewrite two categories of Quay image references through ACR pull-through cache before writing them into pod specs, causing ValidatingAdmissionPolicy violations:

  1. CPO (Control Plane Operator): GetControlPlaneOperatorImage() returns raw quay.io/redhat-user-workloads/crt-redhat-acm-tenant/control-plane-operator-* URLs from the override table. The versioned repos (e.g. control-plane-operator-4-19, -4-20) require a namespace-level prefix exception. Upstream fix: OCPBUGS-128660.

  2. CVO prepare-payload init container: The OCP release image quay.io/openshift-release-dev/ocp-release is resolved with ICSP/IDMS mirrors, but the pod spec still carries the original quay.io prefix. Upstream fix: OCPBUGS-128661.

What

  • Add quay.io/redhat-user-workloads/crt-redhat-acm-tenant to global defaults.imageRegistryPolicy.extraAllowedRegistries — namespace-level prefix to match the ACR pull-through cache rule scope (global-acr.bicep) and the HyperShift registryOverrides mapping, covering all current and future versioned CPO repos
  • Add quay.io/openshift-release-dev/ocp-release to the same list
  • Re-materialize configs and Helm fixtures

Rollback plan

These exceptions should be rolled back once the upstream HyperShift fixes (OCPBUGS-128660, OCPBUGS-128661) merge and propagate to the OCP versions we deploy.

Related

Checklist

  • Config change with make materialize re-run
  • Rendered configs committed
  • Helm fixtures updated
  • OCPBUGS filed for upstream tracking

Copilot AI balanced review requested due to automatic review settings September 29, 2026 13:03
@openshift-merge-bot

Copy link
Copy Markdown
Contributor

Pipeline controller notification
This repo is configured to use the pipeline controller. Second-stage tests will be triggered either automatically or after lgtm label is added, depending on the repository configuration. The pipeline controller will automatically detect which contexts are required and will utilize /test Prow commands to trigger the second stage.

For optional jobs, comment /test ? to see a list of all defined jobs. To trigger manually all jobs from second stage use /pipeline required command.

This repository is configured in: automatic mode

@openshift-ci openshift-ci Bot added do-not-merge/work-in-progress area/infrastructure Deployment/pipeline infrastructure config approved labels Sep 29, 2026
@openshift-ci

openshift-ci Bot commented Sep 29, 2026

Copy link
Copy Markdown
Contributor

Skipping CI for Draft Pull Request.
If you want CI signal for your change, please convert it to an actual PR.
You can still manually trigger a test run with /test all

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The shared configuration unnecessarily permits direct Quay CPO images on service clusters.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
What changed in this PR

Restores the dev-cloud CPO Quay exception needed for HyperShift CPO overrides.

Changes:

  • Adds the CPO image prefix to dev allowlists.
  • Documents the workaround and long-term fix.
  • Regenerates six rendered configs and Helm fixtures.
File Description
config/​config.yaml Adds and documents the exception.
config/​rendered/​dev/​cspr/​westus3.yaml Renders CSPR configuration.
config/​rendered/​dev/​ci00/​centralus.yaml Renders CI00 configuration.
config/​rendered/​dev/​ci01/​centralus.yaml Renders CI01 configuration.
config/​rendered/​dev/​dev/​westus3.yaml Renders dev configuration.
config/​rendered/​dev/​perf/​westus3.yaml Renders performance configuration.
config/​rendered/​dev/​pers/​westus3.yaml Renders personal-dev configuration.
dev-infrastructure/​zz_fixture_TestHelmTemplate_dev_westus3_mgmt_1_image_registry_policy.yaml Updates the management-cluster fixture.
dev-infrastructure/​zz_fixture_TestHelmTemplate_dev_westus3_svc_1_image_registry_policy.yaml Updates the service-cluster fixture.

💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread config/config.yaml Outdated
# path before setting the annotation (tracked in AROSLSRE-861).
imageRegistryPolicy:
extraAllowedRegistries: docker.io/grafana,docker.io/library/postgres
extraAllowedRegistries: docker.io/grafana,docker.io/library/postgres,quay.io/redhat-user-workloads/crt-redhat-acm-tenant/control-plane-operator
@openshift-merge-bot

Copy link
Copy Markdown
Contributor

Scheduling tests matching the pipeline_run_if_changed or not excluded by pipeline_skip_if_only_changed parameters:
/test e2e-parallel

@machi1990

Copy link
Copy Markdown
Collaborator

/lgtm

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm cancel

@openshift-ci openshift-ci Bot removed the lgtm label Sep 29, 2026
Comment thread config/config.yaml Outdated
# path before setting the annotation (tracked in AROSLSRE-861).
imageRegistryPolicy:
extraAllowedRegistries: docker.io/grafana,docker.io/library/postgres
extraAllowedRegistries: docker.io/grafana,docker.io/library/postgres,quay.io/redhat-user-workloads/crt-redhat-acm-tenant/control-plane-operator

@machi1990 Manyanda Chitimbo (machi1990) Sep 29, 2026 •

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Anthony Vollmer (@avollmer-redhat) are you absolute sure that we'd not also want this exception to be in all envs (prod included) until the fix lands in hypershift?

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yes — the exceptions are in global defaults now, so INT/STG/PROD inherit them. The dev overlay still needs to repeat them because extraAllowedRegistries is a scalar string (not a list), so the dev cloud override completely replaces the defaults value. If we didn't repeat them in the dev overlay, dev would lose the quay.io exceptions and only have the docker.io ones.

@avollmer-redhat
Anthony Vollmer (avollmer-redhat) force-pushed the fix/aroslsre-861-restore-cpo-vap-exception-dev branch from 1d21c32 to db3d08e Compare September 29, 2026 16:07
Copilot AI review requested due to automatic review settings September 29, 2026 16:07
@avollmer-redhat Anthony Vollmer (avollmer-redhat) changed the title fix: restore CPO Quay exception in dev-cloud image registry VAP fix: add CPO and CVO Quay exceptions to image registry VAP for all environments Sep 29, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The CPO entry does not match suffixed repositories, and restricted operational details require removal.

Review effort: Balanced
Findings: 2 Medium severity · 1 Low severity

Open (3)

Comment thread config/config.yaml Outdated
Comment thread config/config.yaml Outdated
Comment thread config/config.yaml Outdated
Comment on lines +1502 to +1505
# Image Registry Policy — dev-only extras on top of the base quay.io
# exceptions (which are inherited from defaults.imageRegistryPolicy).
imageRegistryPolicy:
extraAllowedRegistries: docker.io/grafana,docker.io/library/postgres
extraAllowedRegistries: docker.io/grafana,docker.io/library/postgres,quay.io/redhat-user-workloads/crt-redhat-acm-tenant/control-plane-operator,quay.io/openshift-release-dev/ocp-release

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

With the change above, this isn't needed?

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Still needed — the dev cloud override of extraAllowedRegistries completely replaces the global defaults value (scalar string merge semantics, not append). Without repeating the quay.io entries here, dev environments would only have the docker.io prefixes.

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

Scheduling tests matching the pipeline_run_if_changed or not excluded by pipeline_skip_if_only_changed parameters:
/test e2e-parallel

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Addressing the review feedback — pushing an updated commit shortly.

Comment thread config/config.yaml Outdated
# fixes merge and propagate.
imageRegistryPolicy:
extraAllowedRegistries: ""
extraAllowedRegistries: quay.io/redhat-user-workloads/crt-redhat-acm-tenant/control-plane-operator,quay.io/openshift-release-dev/ocp-release

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good catch — the current prefix control-plane-operator doesn't match the versioned repos (control-plane-operator-4-19, control-plane-operator-4-20) because the CEL only allows /, :, @ as separators, not -.

We're widening to the namespace-level prefix quay.io/redhat-user-workloads/crt-redhat-acm-tenant to match the ACR pull-through cache rule scope (global-acr.bicep line 90) and the HyperShift registryOverrides mapping (hypershiftoperator/values.yaml line 7), which both already operate at this level. This also avoids needing to enumerate and maintain per-OCP-version repos as new versions get CPO overrides.

Comment thread config/config.yaml Outdated
# references through ACR pull-through cache before writing them into pod
# specs, so the VAP must allow them until upstream fixes land.
# - control-plane-operator: GetControlPlaneOperatorImage() returns raw
# quay.io URLs from the CPO override table (OCPBUGS-51657).

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Agreed — trimming the comments down to just reference the upstream bug IDs without describing internal policy behavior.

Copilot AI balanced review requested due to automatic review settings September 29, 2026 17:20
@avollmer-redhat
Anthony Vollmer (avollmer-redhat) force-pushed the fix/aroslsre-861-restore-cpo-vap-exception-dev branch from db3d08e to 261c345 Compare September 29, 2026 17:20

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The exceptions unnecessarily weaken service-cluster admission policy despite only addressing management-cluster workloads.

Review effort: Balanced
Findings: 1 High severity · 1 Medium severity

Open (2)
Resolved since last review (2)

…vironments

HyperShift does not rewrite certain Quay image references through ACR
pull-through cache before writing them into pod specs. Add temporary
VAP exceptions until upstream fixes land:

- crt-redhat-acm-tenant: CPO override images use versioned repos
  (e.g. control-plane-operator-4-19, -4-20). The namespace-level
  prefix matches the ACR pull-through cache rule and HyperShift
  registryOverrides scope. (OCPBUGS-128660)
- ocp-release: CVO prepare-payload image (OCPBUGS-128661)

AROSLSRE-861
Copilot AI balanced review requested due to automatic review settings September 29, 2026 17:55
@avollmer-redhat
Anthony Vollmer (avollmer-redhat) force-pushed the fix/aroslsre-861-restore-cpo-vap-exception-dev branch from 261c345 to 136c196 Compare September 29, 2026 17:55

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The scoped configuration change correctly matches both affected image prefixes and its generated artifacts are consistent.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
Resolved since last review (1)

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

Scheduling tests matching the pipeline_run_if_changed or not excluded by pipeline_skip_if_only_changed parameters:
/test e2e-parallel

@avollmer-ms

Copy link
Copy Markdown

/retest-required

@avollmer-redhat

Copy link
Copy Markdown
Collaborator Author

Test Failure Analysis

CodeQL Analysis Failure (Exit Code 143)

The CodeQL analysis is failing with exit code 143 (killed/OOM). This is a resource issue in the CI environment, not a problem with the VAP fix code itself.

Exit code 143 typically means the process was killed due to:

  • Out of memory (OOM)
  • Timeout
  • Resource limits exceeded

The Go build step for CodeQL ran for 6m 19s before being killed. This is a CI infrastructure issue, not a code quality problem.

Prometheus Rules Test Failure

The TestPrometheusRules tests are failing with:

testing rules failed error running promtool exec: "promtool": executable file not found in $PATH

This is a pre-existing infrastructure issue unrelated to the VAP fix. The promtool binary is not available in the test environment. This failure exists on main branch as well and should be fixed independently.

Summary

The VAP fix itself is correct and ready:

  • ✅ Config changes are minimal and correct (adding Quay registries to allowlist)
  • ✅ All relevant Helm test fixtures properly updated
  • ✅ Unit tests pass
  • ❌ CodeQL: CI infrastructure issue (OOM/timeout)
  • ❌ Prometheus: Pre-existing environment issue (promtool missing)

Both test failures are environmental issues unrelated to the code change.

@hbhushan3

Copy link
Copy Markdown
Collaborator

/lgtm

@openshift-ci

openshift-ci Bot commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: avollmer-redhat, hbhushan3

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@avollmer-ms

Copy link
Copy Markdown

/retest-required

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

/retest-required

Remaining retests: 0 against base HEAD 21717c1 and 2 for PR HEAD 136c196 in total

@sclarkso

Copy link
Copy Markdown
Collaborator

/retest-required

@openshift-merge-bot
openshift-merge-bot Bot merged commit bb2cbe0 into Azure:main Oct 1, 2026
16 of 18 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved area/infrastructure Deployment/pipeline infrastructure config lgtm

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants