fix: add CPO and CVO Quay exceptions to image registry VAP for all environments - #7242
Conversation
|
Pipeline controller notification For optional jobs, comment This repository is configured in: automatic mode |
|
Skipping CI for Draft Pull Request. |
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The shared configuration unnecessarily permits direct Quay CPO images on service clusters.
Review effort: Balanced
Findings: 1
What changed in this PR
Restores the dev-cloud CPO Quay exception needed for HyperShift CPO overrides.
Changes:
- Adds the CPO image prefix to dev allowlists.
- Documents the workaround and long-term fix.
- Regenerates six rendered configs and Helm fixtures.
| File | Description |
|---|---|
config/config.yaml |
Adds and documents the exception. |
config/rendered/dev/cspr/westus3.yaml |
Renders CSPR configuration. |
config/rendered/dev/ci00/centralus.yaml |
Renders CI00 configuration. |
config/rendered/dev/ci01/centralus.yaml |
Renders CI01 configuration. |
config/rendered/dev/dev/westus3.yaml |
Renders dev configuration. |
config/rendered/dev/perf/westus3.yaml |
Renders performance configuration. |
config/rendered/dev/pers/westus3.yaml |
Renders personal-dev configuration. |
dev-infrastructure/zz_fixture_TestHelmTemplate_dev_westus3_mgmt_1_image_registry_policy.yaml |
Updates the management-cluster fixture. |
dev-infrastructure/zz_fixture_TestHelmTemplate_dev_westus3_svc_1_image_registry_policy.yaml |
Updates the service-cluster fixture. |
💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| # path before setting the annotation (tracked in AROSLSRE-861). | ||
| imageRegistryPolicy: | ||
| extraAllowedRegistries: docker.io/grafana,docker.io/library/postgres | ||
| extraAllowedRegistries: docker.io/grafana,docker.io/library/postgres,quay.io/redhat-user-workloads/crt-redhat-acm-tenant/control-plane-operator |
|
Scheduling tests matching the |
|
/lgtm |
Manyanda Chitimbo (machi1990)
left a comment
There was a problem hiding this comment.
/lgtm cancel
| # path before setting the annotation (tracked in AROSLSRE-861). | ||
| imageRegistryPolicy: | ||
| extraAllowedRegistries: docker.io/grafana,docker.io/library/postgres | ||
| extraAllowedRegistries: docker.io/grafana,docker.io/library/postgres,quay.io/redhat-user-workloads/crt-redhat-acm-tenant/control-plane-operator |
There was a problem hiding this comment.
Anthony Vollmer (@avollmer-redhat) are you absolute sure that we'd not also want this exception to be in all envs (prod included) until the fix lands in hypershift?
There was a problem hiding this comment.
Yes — the exceptions are in global defaults now, so INT/STG/PROD inherit them. The dev overlay still needs to repeat them because extraAllowedRegistries is a scalar string (not a list), so the dev cloud override completely replaces the defaults value. If we didn't repeat them in the dev overlay, dev would lose the quay.io exceptions and only have the docker.io ones.
1d21c32 to
db3d08e
Compare
| # Image Registry Policy — dev-only extras on top of the base quay.io | ||
| # exceptions (which are inherited from defaults.imageRegistryPolicy). | ||
| imageRegistryPolicy: | ||
| extraAllowedRegistries: docker.io/grafana,docker.io/library/postgres | ||
| extraAllowedRegistries: docker.io/grafana,docker.io/library/postgres,quay.io/redhat-user-workloads/crt-redhat-acm-tenant/control-plane-operator,quay.io/openshift-release-dev/ocp-release |
There was a problem hiding this comment.
With the change above, this isn't needed?
There was a problem hiding this comment.
Still needed — the dev cloud override of extraAllowedRegistries completely replaces the global defaults value (scalar string merge semantics, not append). Without repeating the quay.io entries here, dev environments would only have the docker.io prefixes.
|
Scheduling tests matching the |
Anthony Vollmer (avollmer-redhat)
left a comment
There was a problem hiding this comment.
Addressing the review feedback — pushing an updated commit shortly.
| # fixes merge and propagate. | ||
| imageRegistryPolicy: | ||
| extraAllowedRegistries: "" | ||
| extraAllowedRegistries: quay.io/redhat-user-workloads/crt-redhat-acm-tenant/control-plane-operator,quay.io/openshift-release-dev/ocp-release |
There was a problem hiding this comment.
Good catch — the current prefix control-plane-operator doesn't match the versioned repos (control-plane-operator-4-19, control-plane-operator-4-20) because the CEL only allows /, :, @ as separators, not -.
We're widening to the namespace-level prefix quay.io/redhat-user-workloads/crt-redhat-acm-tenant to match the ACR pull-through cache rule scope (global-acr.bicep line 90) and the HyperShift registryOverrides mapping (hypershiftoperator/values.yaml line 7), which both already operate at this level. This also avoids needing to enumerate and maintain per-OCP-version repos as new versions get CPO overrides.
| # references through ACR pull-through cache before writing them into pod | ||
| # specs, so the VAP must allow them until upstream fixes land. | ||
| # - control-plane-operator: GetControlPlaneOperatorImage() returns raw | ||
| # quay.io URLs from the CPO override table (OCPBUGS-51657). |
There was a problem hiding this comment.
Agreed — trimming the comments down to just reference the upstream bug IDs without describing internal policy behavior.
db3d08e to
261c345
Compare
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The exceptions unnecessarily weaken service-cluster admission policy despite only addressing management-cluster workloads.
Review effort: Balanced
Findings: 1
Open (2)
Resolved since last review (2)
…vironments HyperShift does not rewrite certain Quay image references through ACR pull-through cache before writing them into pod specs. Add temporary VAP exceptions until upstream fixes land: - crt-redhat-acm-tenant: CPO override images use versioned repos (e.g. control-plane-operator-4-19, -4-20). The namespace-level prefix matches the ACR pull-through cache rule and HyperShift registryOverrides scope. (OCPBUGS-128660) - ocp-release: CVO prepare-payload image (OCPBUGS-128661) AROSLSRE-861
261c345 to
136c196
Compare
|
Scheduling tests matching the |
|
/retest-required |
Test Failure AnalysisCodeQL Analysis Failure (Exit Code 143)The CodeQL analysis is failing with exit code 143 (killed/OOM). This is a resource issue in the CI environment, not a problem with the VAP fix code itself. Exit code 143 typically means the process was killed due to:
The Go build step for CodeQL ran for 6m 19s before being killed. This is a CI infrastructure issue, not a code quality problem. Prometheus Rules Test FailureThe This is a pre-existing infrastructure issue unrelated to the VAP fix. The SummaryThe VAP fix itself is correct and ready:
Both test failures are environmental issues unrelated to the code change. |
|
/lgtm |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: avollmer-redhat, hbhushan3 The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
|
/retest-required |
|
/retest-required |



Why
HyperShift does not rewrite two categories of Quay image references through ACR pull-through cache before writing them into pod specs, causing ValidatingAdmissionPolicy violations:
CPO (Control Plane Operator):
GetControlPlaneOperatorImage()returns rawquay.io/redhat-user-workloads/crt-redhat-acm-tenant/control-plane-operator-*URLs from the override table. The versioned repos (e.g.control-plane-operator-4-19,-4-20) require a namespace-level prefix exception. Upstream fix: OCPBUGS-128660.CVO prepare-payload init container: The OCP release image
quay.io/openshift-release-dev/ocp-releaseis resolved with ICSP/IDMS mirrors, but the pod spec still carries the originalquay.ioprefix. Upstream fix: OCPBUGS-128661.What
quay.io/redhat-user-workloads/crt-redhat-acm-tenantto globaldefaults.imageRegistryPolicy.extraAllowedRegistries— namespace-level prefix to match the ACR pull-through cache rule scope (global-acr.bicep) and the HyperShiftregistryOverridesmapping, covering all current and future versioned CPO reposquay.io/openshift-release-dev/ocp-releaseto the same listRollback plan
These exceptions should be rolled back once the upstream HyperShift fixes (OCPBUGS-128660, OCPBUGS-128661) merge and propagate to the OCP versions we deploy.
Related
Checklist
make materializere-run