feat: add tide query for openshift-ci[bot] PRs to openshift/config - #9
Open
Prucek wants to merge 321 commits into
Open
feat: add tide query for openshift-ci[bot] PRs to openshift/config#9Prucek wants to merge 321 commits into
Prucek wants to merge 321 commits into
Conversation
…t#83145) The split resource variables (SCANNER_CPU_REQUEST, etc.) had non-empty defaults that shadowed the deprecated SCANNER_CPU/SCANNER_MEMORY values. CI configs setting only the old names got the YAML defaults (4/4Gi) instead of their intended values, causing pods to fail scheduling. Clear the defaults so the shell fallback (${SCANNER_CPU_REQUEST:-${SCANNER_CPU}}) actually reaches the deprecated variables when the new ones aren't explicitly set.
Signed-off-by: Brady Pratt <bpratt@redhat.com>
…sdk (openshift#82299) The e2e-using-bundle presubmit job for cluster-logging-operator was using the deprecated index image approach (OO_INDEX + optional-operators-ci-generic-claim) to install the operator via OLM CatalogSource/Subscription. This method is being removed from ci-operator. - Add cli-operator-sdk (v1.39.2) and operator-sdk (4.21) base images - Set skip_building_index: true on the bundle definition - Replace OO_INDEX dependency with OO_BUNDLE - Remove OO_CHANNEL, OO_PACKAGE, OO_TARGET_NAMESPACES env vars (not needed with operator-sdk run bundle) Signed-off-by: Vitalii Parfonov <vparfono@redhat.com>
Signed-off-by: Gabriel Bernal <gbernal@redhat.com>
Signed-off-by: Neha Yadav <neha.yadav3@ibm.com>
…ift#83191) Enable registry.ci push and quay-proxy pull for QCI→app.ci mirrors.
…Saturday (openshift#83054) Signed-off-by: Rajakumar Battula <rbattula@redhat.com>
openshift#83159) * SPLAT-2830: Add CI changes and periodic PROW changes for CI-Cluster Capacity monitoring * fixes * fixes
- jobs fails when there is not default channel set. on PreGA the default channel is not always published Signed-off-by: Eran Ifrach <eifrach@redhat.com>
…enshift#83126) * chore(clo): remove e2e job in favor of one that runs using bundle * chore(vector): update v0.54 for logging 6.6. Remove obs job
Co-authored-by: Cursor <cursoragent@cursor.com>
…penshift#81947) * OCPMCP-108: weekly mcpchecker eval periodic for openshift-mcp-server * OCPMCP-108: add mcpchecker weekly periodic on release-5.0 Define the weekly job on the release-5.0 config so Sippy can attach results to an OCP release, not only the main-branch periodic. Co-authored-by: Cursor <cursoragent@cursor.com> * OCPMCP-108: drop main mcpchecker weekly periodic Keep the weekly only on release-5.0 so Sippy can align the job with an OCP release; avoid a duplicate main-branch weekly. Co-authored-by: Cursor <cursoragent@cursor.com> * OCPMCP-108: move mcpchecker weekly periodic to release-0.5 Product release-0.5 now exists; define the weekly eval job there for Sippy product attribution and drop the interim release-5.0 periodics. Co-authored-by: Cursor <cursoragent@cursor.com> --------- Co-authored-by: Cursor <cursoragent@cursor.com>
…t#82850) Add rosa-operator-mc-e2e workflow that provisions an HCP on a CI sector, fetches the MC kubeconfig, and runs operator e2e tests against the Management Cluster. Add weekly periodics for both RMO (RHOBS Synthetic Monitoring tests) and AVO (CEL validation tests) on the rosa-e2e sector. Reuses existing provision/deprovision chains with a bridge step to copy the MC kubeconfig. No operator install/cleanup since operators are fleet-managed via MCC/PKO.
…hift#83167) Update dockerfile_path references from operator/Dockerfile pattern to openshift/Containerfile.*.rhel. Signed-off-by: Vincent Link <vlink@redhat.com>
…ver (openshift#83208) Signed-off-by: grokspawn <jordan@nimblewidget.com>
* autoscale-tests: enable Tide auto-merge * approve label --------- Co-authored-by: Samuel Sulka <ssulka@redhat.com>
…perf variants (openshift#83065) With the IngressControllerMultipleHAProxyVersions feature gate promoted to GA, drop FEATURE_SET: TechPreviewNoUpgrade from all haproxy28 presubmits in CIO and router repos and rename from *-techpreview to *-haproxy28. This fixes the upgrade presubmits which could never work on TechPreviewNoUpgrade clusters. Add FIPS haproxy28 presubmits to CIO and router since HAProxy 2.8 and 3.2 use different OpenSSL/pcre versions which may behave differently in FIPS mode. Add a perfscale-aws-ingress-perf-haproxy28 presubmit to router for comparing HAProxy 2.8 vs 3.2 performance on the same cluster profile. Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
…shift#83209) * Disable aws-perfscale loaded-upgrade crons for non-5.0 versions Remove cron schedules and set always_run: false for loaded-upgrade-120nodes and loaded-upgrade-252nodes (aws-perfscale profile) in 4.22-from-4.21, 4.23-from-4.22, and 5.1-from-4.22 configs. The aws-perfscale-qe loaded-upgrade-24nodes jobs are unchanged. Only 5.0-from-4.22 loaded-upgrade crons remain active on the aws-perfscale profile. Assisted-by: Claude Signed-off-by: Mohit Sheth <msheth@redhat.com> * Regenerate Prow jobs after disabling non-5.0 loaded-upgrade crons Assisted-by: Claude Signed-off-by: Mohit Sheth <msheth@redhat.com> * Remove 5.1 loaded-upgrade change (covered by separate PR) and regenerate Assisted-by: Claude Signed-off-by: Mohit Sheth <msheth@redhat.com> --------- Signed-off-by: Mohit Sheth <msheth@redhat.com>
* Disable all 5.1 aws-perfscale cron jobs Remove cron schedules and set always_run: false for 7 aws-perfscale profile jobs: control-plane-120nodes, control-plane-252nodes, data-path-9nodes, control-plane-ipsec-120nodes, control-plane-ipsec-252nodes in 5.1 nightly, and loaded-upgrade-120nodes, loaded-upgrade-252nodes in 5.1 loaded-upgrade. All aws-perfscale-qe profile jobs remain unchanged. Assisted-by: Claude Signed-off-by: Mohit Sheth <msheth@redhat.com> * Regenerate Prow jobs after disabling 5.1 aws-perfscale crons Assisted-by: Claude Signed-off-by: Mohit Sheth <msheth@redhat.com> --------- Signed-off-by: Mohit Sheth <msheth@redhat.com>
…bs (openshift#83213) * Reduce 5.0 aws-perfscale cron frequency and disable ipsec jobs - control-plane-120nodes: reduce from 4x/week to 2x/week (Tue, Sat) - control-plane-ipsec-120nodes: disable (set always_run: false) - control-plane-ipsec-252nodes: disable (set always_run: false) Assisted-by: Claude Signed-off-by: Mohit Sheth <msheth@redhat.com> * Reduce 5.0 control-plane-120nodes frequency and disable cudn churn jobs - control-plane-120nodes: reduce from 4x/week to 2x/week (Tue, Sat) - cudn-pod-churn-250-24nodes: disable (set always_run: false) - cudn-churn-250-24nodes: disable (set always_run: false) - Restore ipsec jobs to original crons Assisted-by: Claude Signed-off-by: Mohit Sheth <msheth@redhat.com> --------- Signed-off-by: Mohit Sheth <msheth@redhat.com>
…83138) Register the HCP VPN profile after Boskos leases and secret bootstrap from the companion PR land and cluster-secrets-libvirt-s390x-vpn-hcp exists in ci.
…penshift#83218) This reverts commit 2068cf2.
* MGMT-23162: Adding openshift/conformance/parallel back Because conformance tests could not run and the extensive test suite did not contain any valid tests (test names are changing over time) the conformance tests were disabled. Now that the conformance tests are running fine those tests are added back. And also one test is introduced which runs a full set of openshift/conformance/parallel once a week. A new flow is added witch sets the local in-cluster openshift image registry to managed. Without it the new namespace, one created for most of the tests, will not have the desired secrets, causing the test to fail. * setting the image managed in assisted-ofcir-baremetal Instead of creating a new workflow, image registry is set to managed as part of assisted-ofcir-baremetal when TEST_TYPE is not none. * pin image-registry to master nodes When adding day2 nodes to an SNO cluster, the image-registry deployment without nodeSelector can be rescheduled to the day2 worker nodes since they lack the master taint. For an emptyDir-backed registry, this wipes all previously stored images and breaks conformance tests that need to pull `openshift/tools:latest` and other test images. By pinning the image-registry to `node-role.kubernetes.io/master`, it will stay on the original master node and not lose its ephemeral storage. Co-authored-by: Cursor <cursoragent@cursor.com> * On day 2 host in a multi node env some networking tests are not working the root cause is still being investigated. In the meantime the tests are being removed --------- Co-authored-by: Cursor <cursoragent@cursor.com>
Create a baremetal cluster-network-operator workflow that provisions a secondary interface, injects node-specific OVN_ENCAP_IP overrides, and prints the resolved override mapping before validating OVS state. Signed-off-by: Sebastian Sch <sebassch@gmail.com>
…82846) * establish pass gates Signed-off-by: grokspawn <jordan@nimblewidget.com> * add kubeconfig env to indicate correct SA Signed-off-by: grokspawn <jordan@nimblewidget.com> * correct gemini zone Signed-off-by: grokspawn <jordan@nimblewidget.com> --------- Signed-off-by: grokspawn <jordan@nimblewidget.com>
…nshift#83420) * INTEROP-9202: Add ExitTrap MAP_TESTS support to acm-opp-app step Enable Component Readiness junit suite name remapping for the acm-opp-app step. When MAP_TESTS=true, the step sources ExitTrap--PostProcessPrep to rename the junit suite from raw "acm-opp-app" to the CR-routable format (lp-interop--OPP--acm-opp-app), chained after the existing GenerateJunitXml trap. Also declares DR__RP__CR_COMP_NAME and MAP_TESTS env vars in the ref YAML so they are passed through from the job config. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * INTEROP-9202: Fix ExitTrap output filename for BQ ingestion TestGrid's JUnit scanner requires filenames starting with lowercase 'junit' (strings.HasPrefix(base, "junit")). The ExitTrap default output 'jUnit.xml' (capital U) was being ignored by BQ ingestion, preventing Quay and Observability test data from reaching Sippy. Pass explicit lowercase junit--*.xml filenames to ExitTrap--PostProcessPrep for acm-opp-app, quay-interop-test, and acm-observability steps. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
…diness checks complete (openshift#83470) The EphemeralCluster reconciler watches for the kubeconfig file in SHARED_DIR to determine when the cluster is ready (ClusterReady condition). Creating the symlink before clusteroperators and NodePool readiness checks causes the controller to consider the cluster ready prematurely, leading to DNS resolution failures because tests start before nodes and DNS are actually available. Move the `ln -s nested_kubeconfig kubeconfig` symlink creation to after all readiness checks (clusteroperators, NodePools, feature set) have passed, while keeping the KUBECONFIG export in place for the oc wait commands that need it. Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
…tainer tests on ROSA HCP (openshift#83473) These tests are not supported on ROSA HCP because: - AWSServiceLBNetworkSecurityGroup feature gate is not yet supported on ROSA HCP (SPLAT-2353) - cloud-provider-aws-e2e NLB BYO SG tests require IMDS credentials unavailable in HCP - InPlacePodVerticalScaling is not supported on HyperShift-managed clusters Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Add the rosa-gather-rhobs-logs step reference to the post block of the rosa-e2e-hcp workflow to collect RHOBS logs during cleanup. Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
…penshift#83479) Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
…O log collection (openshift#83482) Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
…or release-2.5, 2.6 (openshift#83488)
…overrides (openshift#83478) Move Monitor:apiserver-incluster-availability, CSI csi-hostpath provisioning, Security seccomp/SELinuxMount, PersistentVolumes-local block, and ntfs/Windows test patterns into the shared workflow. These were only in per-version nightly config overrides and weren't applied consistently across all versions. Prereq for removing TEST_SKIPS overrides from openshift-release-main nightly configs, so ROSA can own skip list management without TRT involvement.
openshift#83492) Add retry_with_backoff function and best_effort flag to the operator-roles delete step, matching the existing account-roles-delete sibling step. This prevents transient ROSA API failures from failing the overall CI job. Changes: - ref.yaml: add best_effort: true and timeout: 10m0s - commands.sh: add retry_with_backoff (3 retries, exponential backoff) wrapping the rosa delete operator-roles call Co-authored-by: redhat-chai-bot <redhat-chai-bot@users.noreply.github.com> Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
) The rosa-gather-rhobs-logs step ref uses `from: rosa-aws-cli`, which requires each consuming ci-operator config to import that image into the `stable` imagestream. Configs that do not import the image (e.g. FVT staging jobs) hit ImagePullBackOff for ~1 hour before the pod is reaped. Because the step is best_effort, the failure is silent. Switch to `from_image` so the step self-resolves the image directly from the ci registry (namespace: ci, name: rosa-aws-cli, tag: latest), matching the pattern used by other ROSA step refs. Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Signed-off-by: Alejandro Brugarolas <abrugaro@redhat.com>
….1 --skip-periodics --future-release 4.23 --future-release 5.2 --confirm
…openshift-priv --only-org openshift --whitelist-file ./core-services/openshift-priv/_whitelist.yaml
…rator/jobs --registry ./ci-operator/step-registry
…865 --github-app-private-key-path /etc/github/cert --github-endpoint http://ghproxy --dry-run=false --whitelist-file ./core-services/openshift-priv/_whitelist.yaml
…/core-services/sanitize-prow-jobs/_config.yaml
…magesets ./clusters/hosted-mgmt/hive/pools
* Add billing account to ROSA HCP cluster provisioning ROSA now requires --billing-account for Hosted Control Plane clusters. Read the value from the cluster profile secret (aws_billing_account) and mask it in all log output. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * Validate billing account format and add temp file cleanup trap - Reject billing account values that aren't exactly 12 digits - Add EXIT trap to clean up mktemp file on early exit - Skip xtrace finding: script never enables set -x Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Automate config brancher by auto-config-brancher job at Mon, 17 Aug 2026 08:09:47 UTC
…nshift-priv fix: add prow trigger plugin config for openshift-priv/dra-driver-sriov
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: Prucek The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
|
The OWNERS file contains untrusted users, which makes it INVALID. The following users are mentioned in OWNERS file(s) but are untrusted for the following reasons. One way to make the user trusted is to add them as members of the Prucek org. You can then trigger verification by writing
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
lgtm(noapprovedlabel required)🤖 Generated with Claude Code