Skip to content

HPCASE-362: Promote TLSAdherence feature gate to GA - #2883

Merged
openshift-merge-bot[bot] merged 1 commit into
openshift:masterfrom
joelanford:promote-tlsadherence-ga
Sep 22, 2026
Merged

openshift-merge-bot[bot] merged 1 commit into
openshift:masterfrom
joelanford:promote-tlsadherence-ga

Conversation

@joelanford

Copy link
Copy Markdown
Member

Summary

Promotes the TLSAdherence feature gate to GA by enabling it in the Default and OKD feature sets (in addition to the existing TechPreviewNoUpgrade and DevPreviewNoUpgrade).

This enables the tlsAdherence field on the apiserver.config.openshift.io/v1 APIServer resource for all clusters, allowing administrators to control how strictly components honor the centralized TLS security profile.

References

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

Pipeline controller notification
This repo is configured to use the pipeline controller. Second-stage tests will be triggered either automatically or after lgtm label is added, depending on the repository configuration. The pipeline controller will automatically detect which contexts are required and will utilize /test Prow commands to trigger the second stage.

For optional jobs, comment /test ? to see a list of all defined jobs. To trigger manually all jobs from second stage use /pipeline required command.

This repository is configured in: LGTM mode

@openshift-ci

openshift-ci Bot commented Jun 9, 2026

Copy link
Copy Markdown
Contributor

Hello @joelanford! Some important instructions when contributing to openshift/api:
API design plays an important part in the user experience of OpenShift and as such API PRs are subject to a high level of scrutiny to ensure they follow our best practices. If you haven't already done so, please review the OpenShift API Conventions and ensure that your proposed changes are compliant. Following these conventions will help expedite the api review process for your PR.

@coderabbitai

coderabbitai Bot commented Jun 9, 2026 •

Copy link
Copy Markdown

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Central YAML (inherited)

Review profile: CHILL

Plan: Enterprise

Run ID: fc5bd3b0-bdb3-43b6-a823-ea7ec777bad2

📥 Commits

Reviewing files that changed from the base of the PR and between 88d8373 and 559b4c5.

📒 Files selected for processing (4)
  • features.md
  • features/features.go
  • payload-manifests/featuregates/featureGate-4-10-Hypershift-Default.yaml
  • payload-manifests/featuregates/featureGate-4-10-SelfManagedHA-Default.yaml

Included review availability: Your plan provides up to 12 included reviews per hour; 11 remain after this review.


📝 Walkthrough

Walkthrough

The change adds the optional spec.tlsAdherence field and prevents its removal after assignment. It adds, removes, and updates feature-gate declarations and profile enablement. It enables TLSAdherence across deployment environments and in the Hypershift and SelfManagedHA default manifests.

Priority: ➖ Normal

Merge Risk: ⚪ Minimal · up to 559b4

TLSAdherence is consistently enabled for GA feature sets and exposes the expected validated API contract, with no remaining actionable merge risk identified.

🚥 Pre-merge checks | ✅ 15
✅ Passed checks (15 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely describes the primary change: promoting the TLSAdherence feature gate to GA.
Description check ✅ Passed The description directly explains the TLSAdherence GA promotion, the affected feature sets, and the enabled APIServer field.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 1…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Stable And Deterministic Test Names ✅ Passed PASS: The pull request changes only feature-gate declarations, manifests, CRDs, and documentation. The authoritative diff adds no test files, Ginkgo declarations, or test-title construction. Therefore…
Test Structure And Quality ✅ Passed PASS: The pull request changes one feature declaration, feature-gate manifests, documentation, and generated CRDs. It does not change any Ginkgo test file or add Ginkgo constructs such as It, `Befor…
Microshift Test Compatibility ✅ Passed The check is not applicable. The authoritative PR diff changes only CRD YAML, feature-gate metadata, and feature-gate manifests. It adds no Ginkgo tests or test constructs such as It(), Describe(), Co…
Single Node Openshift (Sno) Test Compatibility ✅ Passed PASS: The pull request adds no Ginkgo e2e tests. The authoritative diff changes feature metadata, feature-gate manifests, and APIServer CRD manifests only. No added lines contain It(), Describe(), Con…
Topology-Aware Scheduling Compatibility ✅ Passed PASS: The pull request changes only feature-gate metadata, feature-gate manifests, and the APIServer CRD (including its generated copy). The diff adds no Deployment or controller scheduling logic and …
Ote Binary Stdout Contract ✅ Passed PASS: The pull request changes six files: four YAML manifests, one Markdown table, and features/features.go. The only Go change adds inDefault() to the TLSAdherence feature-gate declaration. The…
Ipv6 And Disconnected Network Test Compatibility ✅ Passed PASS: The pull request adds no Ginkgo e2e tests. The authoritative diff changes one feature declaration, Markdown, and YAML manifests/CRDs; the only changed Go file is features/features.go, and no a…
No-Weak-Crypto ✅ Passed PASS. The PR changes feature-gate enablement, manifests, and APIServer schema documentation. It adds no MD5, SHA1, DES, 3DES, RC4, Blowfish, or ECB usage, custom crypto, or secret/token comparisons. T…
Container-Privileges ✅ Passed The pull request changes only feature-gate definitions, feature-gate lists, and APIServer CRD schemas. The added YAML contains no container or pod security settings. The added-line scan found no `priv…
No-Sensitive-Data-In-Logs ✅ Passed PASS. The authoritative diff changes feature-gate enablement, feature documentation, and generated APIServer CRD schemas. It adds no logging implementation or log payload. The only added logging text …
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Create a new PR

Warning

Some tools did not complete. Review the errors below.

🔧 golangci-lint (2.13.2)

Error: build linters: unable to load custom analyzer "kubeapilinter": tools/_output/bin/kube-api-linter.so, plugin: not implemented
The command is terminated due to an error: build linters: unable to load custom analyzer "kubeapilinter": tools/_output/bin/kube-api-linter.so, plugin: not implemented


Comment @coderabbitai help to get the list of available commands.

@openshift-ci openshift-ci Bot added the size/S Denotes a PR that changes 10-29 lines, ignoring generated files. label Jun 9, 2026
@openshift-ci
openshift-ci Bot requested review from JoelSpeed and everettraven June 9, 2026 16:52
@joelanford

Copy link
Copy Markdown
Member Author

This is speculative to see what gating criteria need to be added to https://redhat.atlassian.net/browse/HPCASE-362

@joelanford

Copy link
Copy Markdown
Member Author

/test ?

@joelanford joelanford changed the title Promote TLSAdherence feature gate to GA HPCASE-362: Promote TLSAdherence feature gate to GA Jun 9, 2026
@openshift-ci-robot

openshift-ci-robot commented Jun 9, 2026 •

Copy link
Copy Markdown

@joelanford: This pull request references HPCASE-362 which is a valid jira issue.

Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the epic to target the "5.0.0" version, but no target version was set.

Details

In response to this:

Summary

Promotes the TLSAdherence feature gate to GA by enabling it in the Default and OKD feature sets (in addition to the existing TechPreviewNoUpgrade and DevPreviewNoUpgrade).

This enables the tlsAdherence field on the apiserver.config.openshift.io/v1 APIServer resource for all clusters, allowing administrators to control how strictly components honor the centralized TLS security profile.

References

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-ci-robot openshift-ci-robot added the jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. label Jun 9, 2026
@everettraven

Copy link
Copy Markdown
Contributor

@joelanford Is there on-going work to add tests for this feature?

@richardsonnick

Copy link
Copy Markdown
Contributor

@everettraven We have a PR here openshift/origin#31309 that should be gtg. The current CI failures seem to be due to flakiness

@joelanford

Copy link
Copy Markdown
Member Author

/test verify-feature-promotion

@joelanford
joelanford force-pushed the promote-tlsadherence-ga branch from 9fce402 to 88d8373 Compare August 18, 2026 21:17
@coderabbitai

coderabbitai Bot commented Aug 18, 2026

Copy link
Copy Markdown

Note

GitHub couldn't provide a complete incremental comparison for this pull request, so CodeRabbit is performing a full review instead. This review may take a little longer.

@openshift-ci openshift-ci Bot added size/L Denotes a PR that changes 100-499 lines, ignoring generated files. and removed size/S Denotes a PR that changes 10-29 lines, ignoring generated files. labels Aug 18, 2026
@neisw

neisw commented Aug 20, 2026

Copy link
Copy Markdown
Contributor

/test verify-feature-promotion

@jsafrane

Copy link
Copy Markdown
Contributor

/test verify-feature-promotion
just curious :-)

@JoelSpeed

Copy link
Copy Markdown
Contributor

just curious :-)

You can now get an instantaneous view of the feature gate promotion through sippy, e.g. https://sippy.dptools.openshift.org/sippy-ng/feature_gates/5.0/TLSAdherence

@joelanford
joelanford force-pushed the promote-tlsadherence-ga branch from 88d8373 to 559b4c5 Compare September 17, 2026 19:40
@openshift-ci openshift-ci Bot added size/M Denotes a PR that changes 30-99 lines, ignoring generated files. and removed size/L Denotes a PR that changes 100-499 lines, ignoring generated files. labels Sep 17, 2026
@joelanford

Copy link
Copy Markdown
Member Author

/retest

1 similar comment
@joelanford

Copy link
Copy Markdown
Member Author

/retest

@redhat-chai-bot

Copy link
Copy Markdown
Contributor

/test verify-feature-promotion


AI-generated. Review for accuracy.

@candita

candita commented Sep 18, 2026

Copy link
Copy Markdown
Contributor

@joelanford I think the only feature gate testing for TLSAdherence is in openshift/origin#31309, but that was closed before it merged. Was that intentional?

I'm seeing this in the results for the job verify-feature-promotion, which seems to imply the feature is not being tested?

INSUFFICIENT CI testing for "TLSAdherence".
F0917 21:29:26.222145 10323 root.go:64] Error running codegen: error: only 0 tests found, need at least 5 for "TLSAdherence" on {aws amd64 external false}
error: only 0 tests found, need at least 5 for "TLSAdherence" on {aws amd64 ha false}

@JoelSpeed

Copy link
Copy Markdown
Contributor

/pipeline required

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

Scheduling tests matching the pipeline_run_if_changed or not excluded by pipeline_skip_if_only_changed parameters:
/test e2e-aws-ovn
/test e2e-aws-ovn-hypershift
/test e2e-aws-ovn-hypershift-conformance
/test e2e-aws-ovn-techpreview
/test e2e-aws-serial-1of2
/test e2e-aws-serial-2of2
/test e2e-aws-serial-techpreview-1of2
/test e2e-aws-serial-techpreview-2of2
/test e2e-azure
/test e2e-gcp
/test e2e-upgrade
/test e2e-upgrade-out-of-change
/test minor-e2e-upgrade-minor

@redhat-chai-bot

Copy link
Copy Markdown
Contributor

/override-sticky ci/prow/e2e-azure

Automated triage: This failure appears unrelated to the PR changes.

Job classification: Eligible long-running presubmit e2e/integration job. The Prow definition is pull-ci-openshift-api-master-e2e-azure with the Azure cluster profile, openshift-e2e-azure workflow, and openshift-e2e-test as its test step.

Revision check: Run SHA 559b4c50d9291ad7fc1df3a2a72be539d326e621; current PR HEAD 559b4c50d9291ad7fc1df3a2a72be539d326e621; match.

Execution status: Tests executed. The openshift-tests run openshift/conformance/parallel --retry-strategy=aggressive --provider azure suite ran for 1h50m45s, with 4,372 e2e tests and the monitor suite completed. The root failure was [Monitor:etcd-log-analyzer][sig-etcd] cluster should not be without a leader for too long; the Azure cluster had no etcd leader for approximately 11m58s, with leadership moving from master-0 to master-2.

Completed supporting jobs: ci/prow/build, ci/prow/unit, ci/prow/integration, ci/prow/verify, ci/prow/verify-client-go, ci/prow/verify-crd-schema, ci/prow/verify-crdify, ci/prow/verify-deps, ci/prow/verify-hypershift-integration, ci/prow/e2e-aws-ovn-hypershift, ci/prow/e2e-aws-ovn-hypershift-conformance, and ci/prow/e2e-upgrade-out-of-change passed. Pending checks: ci/prow/e2e-aws-ovn-techpreview, ci/prow/e2e-aws-serial-1of2, ci/prow/e2e-aws-serial-techpreview-1of2, ci/prow/e2e-aws-serial-techpreview-2of2, ci/prow/e2e-gcp, ci/prow/minor-e2e-upgrade-minor, and tide.

Fleet-wide failure rate: This job passed 11/20 runs (55.0%) over the last 14 days. The root test had an 86.3% global pass rate with 473 flakes in 3,450 runs, and a 79.1% Azure pass rate with 152 flakes in 729 runs over the last 7 days.

Open regressions: None found for [Monitor:etcd-log-analyzer][sig-etcd] cluster should not be without a leader for too long; Component Readiness reported no current hard failures.

Linked bugs: None linked to the root etcd leader-loss test. OCPBUGS-6586 is currently Closed with resolution Done and is linked to the secondary test [sig-cli] oc idle [apigroup:apps.openshift.io][apigroup:route.openshift.io][apigroup:project.openshift.io][apigroup:image.openshift.io] by checking previous scale [Suite:openshift/conformance/parallel]; it does not track the root etcd failure.

Overlap assessment: PR #2883 changes API/CRD and feature-gate manifests for promoting TLSAdherence; it does not change etcd, cluster infrastructure, or the tested Azure platform. The baseline e2e-azure workflow runs the common e2e suite and does not explicitly opt into TLSAdherence. No plausible direct or indirect overlap with the observed etcd leader-stability failure was found.

Missing-coverage risk: Low for this failure. The job completed its long-running Azure e2e coverage and failed only because of the known Azure etcd leader-loss condition. Accepting the override does not substitute this job for TLSAdherence-specific coverage, which is a separate signal.

Prior bot activity on this SHA: /test e2e-azure was already issued on the current SHA by openshift-merge-bot; no additional retest will be triggered.

Rationale: The current-HEAD run executed tests, the failure is a known high-rate Azure etcd flake, the failure cascaded into etcd timeout errors in other tests, and the PR has no plausible overlap with etcd leader stability.

Prow run: https://prow.ci.openshift.org/view/gs/test-platform-results-public/pr-logs/pull/openshift_api/2883/pull-ci-openshift-api-master-e2e-azure/2102073761246220288

If you disagree with this assessment, rerun the current job with /test e2e-azure.


AI-generated. Review for accuracy.

@openshift-ci

openshift-ci Bot commented Sep 21, 2026

Copy link
Copy Markdown
Contributor

@redhat-chai-bot: Overrode contexts on behalf of redhat-chai-bot: ci/prow/e2e-azure

These overrides will persist across retests on the current HEAD SHA. Pushing a new commit will clear them. Use /override-cancel to remove them.

Details

In response to this:

/override-sticky ci/prow/e2e-azure

Automated triage: This failure appears unrelated to the PR changes.

Job classification: Eligible long-running presubmit e2e/integration job. The Prow definition is pull-ci-openshift-api-master-e2e-azure with the Azure cluster profile, openshift-e2e-azure workflow, and openshift-e2e-test as its test step.

Revision check: Run SHA 559b4c50d9291ad7fc1df3a2a72be539d326e621; current PR HEAD 559b4c50d9291ad7fc1df3a2a72be539d326e621; match.

Execution status: Tests executed. The openshift-tests run openshift/conformance/parallel --retry-strategy=aggressive --provider azure suite ran for 1h50m45s, with 4,372 e2e tests and the monitor suite completed. The root failure was [Monitor:etcd-log-analyzer][sig-etcd] cluster should not be without a leader for too long; the Azure cluster had no etcd leader for approximately 11m58s, with leadership moving from master-0 to master-2.

Completed supporting jobs: ci/prow/build, ci/prow/unit, ci/prow/integration, ci/prow/verify, ci/prow/verify-client-go, ci/prow/verify-crd-schema, ci/prow/verify-crdify, ci/prow/verify-deps, ci/prow/verify-hypershift-integration, ci/prow/e2e-aws-ovn-hypershift, ci/prow/e2e-aws-ovn-hypershift-conformance, and ci/prow/e2e-upgrade-out-of-change passed. Pending checks: ci/prow/e2e-aws-ovn-techpreview, ci/prow/e2e-aws-serial-1of2, ci/prow/e2e-aws-serial-techpreview-1of2, ci/prow/e2e-aws-serial-techpreview-2of2, ci/prow/e2e-gcp, ci/prow/minor-e2e-upgrade-minor, and tide.

Fleet-wide failure rate: This job passed 11/20 runs (55.0%) over the last 14 days. The root test had an 86.3% global pass rate with 473 flakes in 3,450 runs, and a 79.1% Azure pass rate with 152 flakes in 729 runs over the last 7 days.

Open regressions: None found for [Monitor:etcd-log-analyzer][sig-etcd] cluster should not be without a leader for too long; Component Readiness reported no current hard failures.

Linked bugs: None linked to the root etcd leader-loss test. OCPBUGS-6586 is currently Closed with resolution Done and is linked to the secondary test [sig-cli] oc idle [apigroup:apps.openshift.io][apigroup:route.openshift.io][apigroup:project.openshift.io][apigroup:image.openshift.io] by checking previous scale [Suite:openshift/conformance/parallel]; it does not track the root etcd failure.

Overlap assessment: PR #2883 changes API/CRD and feature-gate manifests for promoting TLSAdherence; it does not change etcd, cluster infrastructure, or the tested Azure platform. The baseline e2e-azure workflow runs the common e2e suite and does not explicitly opt into TLSAdherence. No plausible direct or indirect overlap with the observed etcd leader-stability failure was found.

Missing-coverage risk: Low for this failure. The job completed its long-running Azure e2e coverage and failed only because of the known Azure etcd leader-loss condition. Accepting the override does not substitute this job for TLSAdherence-specific coverage, which is a separate signal.

Prior bot activity on this SHA: /test e2e-azure was already issued on the current SHA by openshift-merge-bot; no additional retest will be triggered.

Rationale: The current-HEAD run executed tests, the failure is a known high-rate Azure etcd flake, the failure cascaded into etcd timeout errors in other tests, and the PR has no plausible overlap with etcd leader stability.

Prow run: https://prow.ci.openshift.org/view/gs/test-platform-results-public/pr-logs/pull/openshift_api/2883/pull-ci-openshift-api-master-e2e-azure/2102073761246220288

If you disagree with this assessment, rerun the current job with /test e2e-azure.


AI-generated. Review for accuracy.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@joelanford

Copy link
Copy Markdown
Member Author

/pipeline required

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

Scheduling tests matching the pipeline_run_if_changed or not excluded by pipeline_skip_if_only_changed parameters:
/test e2e-aws-ovn
/test e2e-aws-ovn-hypershift
/test e2e-aws-ovn-hypershift-conformance
/test e2e-aws-ovn-techpreview
/test e2e-aws-serial-1of2
/test e2e-aws-serial-2of2
/test e2e-aws-serial-techpreview-1of2
/test e2e-aws-serial-techpreview-2of2
/test e2e-azure
/test e2e-gcp
/test e2e-upgrade
/test e2e-upgrade-out-of-change
/test minor-e2e-upgrade-minor

@redhat-chai-bot

Copy link
Copy Markdown
Contributor

/override-sticky ci/prow/e2e-aws-ovn-hypershift-conformance

Automated triage: This failure appears unrelated to the PR changes.

Job classification: Eligible long-running presubmit e2e/integration job. The Prow definition uses the hypershift-aws cluster profile and hypershift-aws-conformance workflow; the run lasted 2h48m and executed the conformance test phase.

Revision check: Run SHA 559b4c50d9291ad7fc1df3a2a72be539d326e621; current PR HEAD 559b4c50d9291ad7fc1df3a2a72be539d326e621; match.

Execution status: Tests executed. The final summary recorded six blocking failures, all in AWS load-balancer/router/Gateway API coverage. The observed signatures were ELB reachability timeout, DNS/route resolution timeout, h2spec condition timeout, and interruption after the timeout cascade. The same job passed on the same SHA in earlier run 2102079596043177984, including all six blocking tests.

Completed supporting jobs: ci/prow/build, ci/prow/unit, ci/prow/integration, ci/prow/verify, ci/prow/verify-client-go, ci/prow/verify-crd-schema, ci/prow/verify-crdify, ci/prow/verify-deps, ci/prow/verify-hypershift-integration, ci/prow/e2e-aws-ovn-hypershift, ci/prow/e2e-upgrade, ci/prow/e2e-upgrade-out-of-change, and ci/prow/minor-e2e-upgrade-minor passed. Pending checks: ci/prow/e2e-aws-ovn, ci/prow/e2e-aws-ovn-techpreview, ci/prow/e2e-aws-serial-1of2, ci/prow/e2e-aws-serial-2of2, ci/prow/e2e-aws-serial-techpreview-1of2, ci/prow/e2e-aws-serial-techpreview-2of2, ci/prow/e2e-azure, ci/prow/e2e-gcp, and tide.

Fleet-wide failure rate: The job pass rate is 72.4% over the last 30 days. Exact failing-test rates were: [cloud-provider-aws-e2e] loadbalancer CLB internal should be reachable with hairpinning traffic [Suite:openshift/conformance/parallel] — 99.0% global, 95.4% HyperShift; [cloud-provider-aws-e2e] loadbalancer CLB should be reachable with default configurations [Suite:openshift/conformance/parallel] — 99.0% global, 95.4% HyperShift; [sig-network-edge][Conformance][Area:Networking][Feature:Router] The HAProxy router should pass the gRPC interoperability tests [apigroup:route.openshift.io][apigroup:operator.openshift.io] [Suite:openshift/conformance/parallel/minimal] — 99.1% global, 98.2% HyperShift; [sig-network-edge][Conformance][Area:Networking][Feature:Router][apigroup:route.openshift.io] The HAProxy router should pass the h2spec conformance tests [apigroup:authorization.openshift.io][apigroup:user.openshift.io][apigroup:security.openshift.io][apigroup:operator.openshift.io] [Suite:openshift/conformance/parallel/minimal] — 99.1% global, 98.4% HyperShift; [sig-network-edge][Conformance][Area:Networking][Feature:Router][apigroup:route.openshift.io][apigroup:config.openshift.io] The HAProxy router should pass the http2 tests [apigroup:image.openshift.io][apigroup:operator.openshift.io] [Suite:openshift/conformance/parallel/minimal] — 96.4% global, 96.8% HyperShift with 20 HyperShift flakes; [sig-network-edge][OCPFeatureGate:GatewayAPIController][Feature:Router][apigroup:gateway.networking.k8s.io] Ensure HTTPRoute object is created [Suite:openshift/conformance/parallel] — 98.3% global, 97.9% HyperShift.

Open regressions: None found for the six failing tests in the relevant Component Readiness view.

Linked bugs: Internal CI analysis found existing linked tracking for the observed AWS load-balancer/router failures. Jira identifiers and statuses are intentionally omitted from this public PR comment.

Overlap assessment: The PR changes TLSAdherence feature-gate/API schema and generated manifests only. It does not change AWS load-balancer behavior, router/HAProxy, Gateway API, DNS, HyperShift provisioning, or test infrastructure. No plausible direct or indirect overlap with the observed failures was found.

Missing-coverage risk: Low for this failure. The same PR revision passed the complete job earlier, all six failed tests passed in that run, and relevant build/unit/integration/verification and HyperShift/upgrade jobs completed successfully. Pending checks are not used as positive signal; they remain pending separately.

Prior bot activity on this SHA: /test e2e-aws-ovn-hypershift-conformance was already issued by openshift-merge-bot for this SHA; no additional retest will be triggered. No override was previously applied for this context.

Rationale: The current-HEAD run executed tests, but the failures formed a correlated AWS/HyperShift networking timeout pattern and all six passed on the same SHA in the earlier run. The failure is unrelated to the PR's API/feature-gate changes.

Prow run: https://prow.ci.openshift.org/view/gs/test-platform-results-public/pr-logs/pull/openshift_api/2883/pull-ci-openshift-api-master-e2e-aws-ovn-hypershift-conformance/2102141670903517184

If you disagree with this assessment, rerun the current job with /test e2e-aws-ovn-hypershift-conformance.


AI-generated. Review for accuracy.


AI-generated. Review for accuracy.

@openshift-ci

openshift-ci Bot commented Sep 22, 2026

Copy link
Copy Markdown
Contributor

@redhat-chai-bot: Overrode contexts on behalf of redhat-chai-bot: ci/prow/e2e-aws-ovn-hypershift-conformance

These overrides will persist across retests on the current HEAD SHA. Pushing a new commit will clear them. Use /override-cancel to remove them.

Details

In response to this:

/override-sticky ci/prow/e2e-aws-ovn-hypershift-conformance

Automated triage: This failure appears unrelated to the PR changes.

Job classification: Eligible long-running presubmit e2e/integration job. The Prow definition uses the hypershift-aws cluster profile and hypershift-aws-conformance workflow; the run lasted 2h48m and executed the conformance test phase.

Revision check: Run SHA 559b4c50d9291ad7fc1df3a2a72be539d326e621; current PR HEAD 559b4c50d9291ad7fc1df3a2a72be539d326e621; match.

Execution status: Tests executed. The final summary recorded six blocking failures, all in AWS load-balancer/router/Gateway API coverage. The observed signatures were ELB reachability timeout, DNS/route resolution timeout, h2spec condition timeout, and interruption after the timeout cascade. The same job passed on the same SHA in earlier run 2102079596043177984, including all six blocking tests.

Completed supporting jobs: ci/prow/build, ci/prow/unit, ci/prow/integration, ci/prow/verify, ci/prow/verify-client-go, ci/prow/verify-crd-schema, ci/prow/verify-crdify, ci/prow/verify-deps, ci/prow/verify-hypershift-integration, ci/prow/e2e-aws-ovn-hypershift, ci/prow/e2e-upgrade, ci/prow/e2e-upgrade-out-of-change, and ci/prow/minor-e2e-upgrade-minor passed. Pending checks: ci/prow/e2e-aws-ovn, ci/prow/e2e-aws-ovn-techpreview, ci/prow/e2e-aws-serial-1of2, ci/prow/e2e-aws-serial-2of2, ci/prow/e2e-aws-serial-techpreview-1of2, ci/prow/e2e-aws-serial-techpreview-2of2, ci/prow/e2e-azure, ci/prow/e2e-gcp, and tide.

Fleet-wide failure rate: The job pass rate is 72.4% over the last 30 days. Exact failing-test rates were: [cloud-provider-aws-e2e] loadbalancer CLB internal should be reachable with hairpinning traffic [Suite:openshift/conformance/parallel] — 99.0% global, 95.4% HyperShift; [cloud-provider-aws-e2e] loadbalancer CLB should be reachable with default configurations [Suite:openshift/conformance/parallel] — 99.0% global, 95.4% HyperShift; [sig-network-edge][Conformance][Area:Networking][Feature:Router] The HAProxy router should pass the gRPC interoperability tests [apigroup:route.openshift.io][apigroup:operator.openshift.io] [Suite:openshift/conformance/parallel/minimal] — 99.1% global, 98.2% HyperShift; [sig-network-edge][Conformance][Area:Networking][Feature:Router][apigroup:route.openshift.io] The HAProxy router should pass the h2spec conformance tests [apigroup:authorization.openshift.io][apigroup:user.openshift.io][apigroup:security.openshift.io][apigroup:operator.openshift.io] [Suite:openshift/conformance/parallel/minimal] — 99.1% global, 98.4% HyperShift; [sig-network-edge][Conformance][Area:Networking][Feature:Router][apigroup:route.openshift.io][apigroup:config.openshift.io] The HAProxy router should pass the http2 tests [apigroup:image.openshift.io][apigroup:operator.openshift.io] [Suite:openshift/conformance/parallel/minimal] — 96.4% global, 96.8% HyperShift with 20 HyperShift flakes; [sig-network-edge][OCPFeatureGate:GatewayAPIController][Feature:Router][apigroup:gateway.networking.k8s.io] Ensure HTTPRoute object is created [Suite:openshift/conformance/parallel] — 98.3% global, 97.9% HyperShift.

Open regressions: None found for the six failing tests in the relevant Component Readiness view.

Linked bugs: Internal CI analysis found existing linked tracking for the observed AWS load-balancer/router failures. Jira identifiers and statuses are intentionally omitted from this public PR comment.

Overlap assessment: The PR changes TLSAdherence feature-gate/API schema and generated manifests only. It does not change AWS load-balancer behavior, router/HAProxy, Gateway API, DNS, HyperShift provisioning, or test infrastructure. No plausible direct or indirect overlap with the observed failures was found.

Missing-coverage risk: Low for this failure. The same PR revision passed the complete job earlier, all six failed tests passed in that run, and relevant build/unit/integration/verification and HyperShift/upgrade jobs completed successfully. Pending checks are not used as positive signal; they remain pending separately.

Prior bot activity on this SHA: /test e2e-aws-ovn-hypershift-conformance was already issued by openshift-merge-bot for this SHA; no additional retest will be triggered. No override was previously applied for this context.

Rationale: The current-HEAD run executed tests, but the failures formed a correlated AWS/HyperShift networking timeout pattern and all six passed on the same SHA in the earlier run. The failure is unrelated to the PR's API/feature-gate changes.

Prow run: https://prow.ci.openshift.org/view/gs/test-platform-results-public/pr-logs/pull/openshift_api/2883/pull-ci-openshift-api-master-e2e-aws-ovn-hypershift-conformance/2102141670903517184

If you disagree with this assessment, rerun the current job with /test e2e-aws-ovn-hypershift-conformance.


AI-generated. Review for accuracy.


AI-generated. Review for accuracy.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@redhat-chai-bot

Copy link
Copy Markdown
Contributor

/override-sticky ci/prow/e2e-aws-ovn

Automated triage: This failure appears unrelated to the PR changes.

Job classification: Eligible long-running AWS OVN end-to-end presubmit. The definition uses the openshift-e2e-aws workflow with AWS IPI provisioning and the openshift-e2e-test step; the run lasted 3h1m31s.

Revision check: event SHA 559b4c50d9291ad7fc1df3a2a72be539d326e621; Prow run SHA 559b4c50d9291ad7fc1df3a2a72be539d326e621; current PR HEAD 559b4c50d9291ad7fc1df3a2a72be539d326e621; match.

Execution status: Tests executed. The live Prow log reports 2231 passed, 7 blocking failures, 1 informing failure, 0 flakes, and 2119 skipped. The failed tests were:

  • [cloud-provider-aws-e2e] loadbalancer CLB internal should be reachable with hairpinning traffic [Suite:openshift/conformance/parallel]
  • [sig-builds][Feature:Builds] oc new-app should succeed with a --name of 58 characters [apigroup:build.openshift.io] [Suite:openshift/conformance/parallel]
  • [sig-network-edge][Conformance][Area:Networking][Feature:Router] The HAProxy router should pass the gRPC interoperability tests [apigroup:route.openshift.io][apigroup:operator.openshift.io] [Suite:openshift/conformance/parallel/minimal]
  • [sig-network-edge][Conformance][Area:Networking][Feature:Router][apigroup:route.openshift.io] The HAProxy router should pass the h2spec conformance tests [apigroup:authorization.openshift.io][apigroup:user.openshift.io][apigroup:security.internal.openshift.io][apigroup:operator.openshift.io] [Suite:openshift/conformance/parallel/minimal]
  • [sig-network-edge][Conformance][Area:Networking][Feature:Router][apigroup:route.openshift.io][apigroup:config.openshift.io] The HAProxy router should pass the http2 tests [apigroup:image.openshift.io][apigroup:operator.openshift.io] [Suite:openshift/conformance/parallel/minimal]
  • [sig-network-edge][OCPFeatureGate:GatewayAPIController][Feature:Router][apigroup:gateway.networking.k8s.io] Ensure HTTPRoute object is created [Suite:openshift/conformance/parallel]
  • [sig-network][OCPFeatureGate:RouteExternalCertificate][Feature:Router][apigroup:route.openshift.io] with valid setup the router should support external certificate and the secret is updated then also routes are reachable [Suite:openshift/conformance/parallel]
  • [sig-cli] Workloads client test ROSA-OSD_CCS-ARO-ConnectedOnly-Author:yinzhou-Medium-71273-Medium-71275-Validate user is able to extract rhel8 and rhel9 oc from the ocp payload

The dominant signatures are DNS/route resolution timeouts, condition timeouts, and Interrupted by User cascade failures; the CLB hairpinning and oc new-app failures are also unrelated to the changed API/feature-gate files.

Completed supporting jobs: ci/prow/e2e-aws-ovn-hypershift, ci/prow/e2e-aws-serial-1of2, ci/prow/e2e-aws-serial-techpreview-1of2, ci/prow/e2e-azure, ci/prow/e2e-gcp, ci/prow/e2e-upgrade, ci/prow/e2e-upgrade-out-of-change, and ci/prow/minor-e2e-upgrade-minor passed. The separate ci/prow/verify-feature-promotion check is failed and is not waived by this override.

Pending jobs: ci/prow/e2e-aws-ovn-techpreview, ci/prow/e2e-aws-serial-2of2, ci/prow/e2e-aws-serial-techpreview-2of2, and tide. Pending jobs are not used as positive signal.

Fleet-wide failure rate: The exact presubmit job passed 2/8 runs over the last 7 days (25.0%); all eight runs were openshift/api PR runs. Release 5.1 test reports show: CLB hairpinning 98.69% pass (10 failures/761 runs); oc new-app 98.22% pass with 3 flakes (28 failures/1740 runs); gRPC 98.34% pass (27 failures/1630 runs); h2spec exact report unavailable, with 45 global failures in the last 7 days; http2 87.81% raw pass / 98.39% working with 171 flakes; GatewayAPI HTTPRoute 98.31% pass (30 failures/1777 runs); RouteExternalCertificate 98.24% pass (33 failures/1872 runs). Exact platform-filtered rates for this presubmit job are unavailable.

Open regressions: Component Readiness regression 49126 is open for the exact RouteExternalCertificate test, with variants including FeatureSet:default, Network:ovn, Platform:aws, and Topology:external (the regression record also includes Installer:hypershift). No matching regression was returned for the other exact failed test names.

Linked bugs: None. The explicit Sippy bugs/bug_tests lookup returned no open Jira bug associations for the failed tests.

Overlap assessment: The PR changes six API/feature-gate/CRD-manifest files to promote TLSAdherence; it does not change router, Gateway API, Build, cloud-provider AWS, or e2e implementation. There is a shared feature-gate/configuration surface, but the observed failures are DNS/ingress timeouts, CLB hairpinning, build timeout, and an unrelated RouteExternalCertificate regression; no failure signature implicates TLSAdherence.

Missing-coverage risk: Low for the failed coverage. The job ran the full e2e suite and the failures are established outside-PR failures, while multiple independent e2e, upgrade, build, unit, and verification checks passed. The separate feature-promotion verification failure still requires its own resolution.

Prior bot activity on this SHA: /test e2e-aws-ovn was already issued by openshift-merge-bot at 2026-09-21T16:29:14Z and 2026-09-21T21:03:05Z; no prior override for this context. No further retest is issued.

Rationale: The current revision is verified, the job is an eligible long-running e2e job, and tests ran. The exact job is only 25% successful across the recent PR fleet, five router failures have elevated global failure counts, the exact RouteExternalCertificate test has an open AWS/OVN/external Component Readiness regression, and the PR does not modify the tested implementations. These gates support overriding this one e2e context; the separate failed feature-promotion verification check remains blocking.

If you disagree with this assessment, rerun the current job with /test e2e-aws-ovn.


AI-generated. Review for accuracy.

@openshift-ci

openshift-ci Bot commented Sep 22, 2026

Copy link
Copy Markdown
Contributor

@redhat-chai-bot: Overrode contexts on behalf of redhat-chai-bot: ci/prow/e2e-aws-ovn

These overrides will persist across retests on the current HEAD SHA. Pushing a new commit will clear them. Use /override-cancel to remove them.

Details

In response to this:

/override-sticky ci/prow/e2e-aws-ovn

Automated triage: This failure appears unrelated to the PR changes.

Job classification: Eligible long-running AWS OVN end-to-end presubmit. The definition uses the openshift-e2e-aws workflow with AWS IPI provisioning and the openshift-e2e-test step; the run lasted 3h1m31s.

Revision check: event SHA 559b4c50d9291ad7fc1df3a2a72be539d326e621; Prow run SHA 559b4c50d9291ad7fc1df3a2a72be539d326e621; current PR HEAD 559b4c50d9291ad7fc1df3a2a72be539d326e621; match.

Execution status: Tests executed. The live Prow log reports 2231 passed, 7 blocking failures, 1 informing failure, 0 flakes, and 2119 skipped. The failed tests were:

  • [cloud-provider-aws-e2e] loadbalancer CLB internal should be reachable with hairpinning traffic [Suite:openshift/conformance/parallel]
  • [sig-builds][Feature:Builds] oc new-app should succeed with a --name of 58 characters [apigroup:build.openshift.io] [Suite:openshift/conformance/parallel]
  • [sig-network-edge][Conformance][Area:Networking][Feature:Router] The HAProxy router should pass the gRPC interoperability tests [apigroup:route.openshift.io][apigroup:operator.openshift.io] [Suite:openshift/conformance/parallel/minimal]
  • [sig-network-edge][Conformance][Area:Networking][Feature:Router][apigroup:route.openshift.io] The HAProxy router should pass the h2spec conformance tests [apigroup:authorization.openshift.io][apigroup:user.openshift.io][apigroup:security.internal.openshift.io][apigroup:operator.openshift.io] [Suite:openshift/conformance/parallel/minimal]
  • [sig-network-edge][Conformance][Area:Networking][Feature:Router][apigroup:route.openshift.io][apigroup:config.openshift.io] The HAProxy router should pass the http2 tests [apigroup:image.openshift.io][apigroup:operator.openshift.io] [Suite:openshift/conformance/parallel/minimal]
  • [sig-network-edge][OCPFeatureGate:GatewayAPIController][Feature:Router][apigroup:gateway.networking.k8s.io] Ensure HTTPRoute object is created [Suite:openshift/conformance/parallel]
  • [sig-network][OCPFeatureGate:RouteExternalCertificate][Feature:Router][apigroup:route.openshift.io] with valid setup the router should support external certificate and the secret is updated then also routes are reachable [Suite:openshift/conformance/parallel]
  • [sig-cli] Workloads client test ROSA-OSD_CCS-ARO-ConnectedOnly-Author:yinzhou-Medium-71273-Medium-71275-Validate user is able to extract rhel8 and rhel9 oc from the ocp payload

The dominant signatures are DNS/route resolution timeouts, condition timeouts, and Interrupted by User cascade failures; the CLB hairpinning and oc new-app failures are also unrelated to the changed API/feature-gate files.

Completed supporting jobs: ci/prow/e2e-aws-ovn-hypershift, ci/prow/e2e-aws-serial-1of2, ci/prow/e2e-aws-serial-techpreview-1of2, ci/prow/e2e-azure, ci/prow/e2e-gcp, ci/prow/e2e-upgrade, ci/prow/e2e-upgrade-out-of-change, and ci/prow/minor-e2e-upgrade-minor passed. The separate ci/prow/verify-feature-promotion check is failed and is not waived by this override.

Pending jobs: ci/prow/e2e-aws-ovn-techpreview, ci/prow/e2e-aws-serial-2of2, ci/prow/e2e-aws-serial-techpreview-2of2, and tide. Pending jobs are not used as positive signal.

Fleet-wide failure rate: The exact presubmit job passed 2/8 runs over the last 7 days (25.0%); all eight runs were openshift/api PR runs. Release 5.1 test reports show: CLB hairpinning 98.69% pass (10 failures/761 runs); oc new-app 98.22% pass with 3 flakes (28 failures/1740 runs); gRPC 98.34% pass (27 failures/1630 runs); h2spec exact report unavailable, with 45 global failures in the last 7 days; http2 87.81% raw pass / 98.39% working with 171 flakes; GatewayAPI HTTPRoute 98.31% pass (30 failures/1777 runs); RouteExternalCertificate 98.24% pass (33 failures/1872 runs). Exact platform-filtered rates for this presubmit job are unavailable.

Open regressions: Component Readiness regression 49126 is open for the exact RouteExternalCertificate test, with variants including FeatureSet:default, Network:ovn, Platform:aws, and Topology:external (the regression record also includes Installer:hypershift). No matching regression was returned for the other exact failed test names.

Linked bugs: None. The explicit Sippy bugs/bug_tests lookup returned no open Jira bug associations for the failed tests.

Overlap assessment: The PR changes six API/feature-gate/CRD-manifest files to promote TLSAdherence; it does not change router, Gateway API, Build, cloud-provider AWS, or e2e implementation. There is a shared feature-gate/configuration surface, but the observed failures are DNS/ingress timeouts, CLB hairpinning, build timeout, and an unrelated RouteExternalCertificate regression; no failure signature implicates TLSAdherence.

Missing-coverage risk: Low for the failed coverage. The job ran the full e2e suite and the failures are established outside-PR failures, while multiple independent e2e, upgrade, build, unit, and verification checks passed. The separate feature-promotion verification failure still requires its own resolution.

Prior bot activity on this SHA: /test e2e-aws-ovn was already issued by openshift-merge-bot at 2026-09-21T16:29:14Z and 2026-09-21T21:03:05Z; no prior override for this context. No further retest is issued.

Rationale: The current revision is verified, the job is an eligible long-running e2e job, and tests ran. The exact job is only 25% successful across the recent PR fleet, five router failures have elevated global failure counts, the exact RouteExternalCertificate test has an open AWS/OVN/external Component Readiness regression, and the PR does not modify the tested implementations. These gates support overriding this one e2e context; the separate failed feature-promotion verification check remains blocking.

If you disagree with this assessment, rerun the current job with /test e2e-aws-ovn.


AI-generated. Review for accuracy.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@JoelSpeed

Copy link
Copy Markdown
Contributor

/override ci/prow/verify-feature-promotion

We agreed that these tests are pretty binary in their nature, components are either compliant or they are not. There's not enough data typically but all of the tests that have run, do pass.

/lgtm
/verified by E2E testing and feature promotion metrics

@openshift-ci-robot openshift-ci-robot added the verified Signifies that the PR passed pre-merge verification criteria label Sep 22, 2026
@openshift-ci-robot

Copy link
Copy Markdown

@JoelSpeed: This PR has been marked as verified by E2E testing and feature promotion metrics.

Details

In response to this:

/override ci/prow/verify-feature-promotion

We agreed that these tests are pretty binary in their nature, components are either compliant or they are not. There's not enough data typically but all of the tests that have run, do pass.

/lgtm
/verified by E2E testing and feature promotion metrics

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-ci

openshift-ci Bot commented Sep 22, 2026

Copy link
Copy Markdown
Contributor

@JoelSpeed: Overrode contexts on behalf of JoelSpeed: ci/prow/verify-feature-promotion

Details

In response to this:

/override ci/prow/verify-feature-promotion

We agreed that these tests are pretty binary in their nature, components are either compliant or they are not. There's not enough data typically but all of the tests that have run, do pass.

/lgtm
/verified by E2E testing and feature promotion metrics

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@openshift-ci openshift-ci Bot added the lgtm Indicates that a PR is ready to be merged. label Sep 22, 2026
@openshift-ci

openshift-ci Bot commented Sep 22, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: JoelSpeed

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci openshift-ci Bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Sep 22, 2026
@openshift-ci

openshift-ci Bot commented Sep 22, 2026

Copy link
Copy Markdown
Contributor

@joelanford: all tests passed!

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

@openshift-merge-bot
openshift-merge-bot Bot merged commit 3a6e03c into openshift:master Sep 22, 2026
29 checks passed
@joelanford
joelanford deleted the promote-tlsadherence-ga branch September 22, 2026 12:56
@joelanford

Copy link
Copy Markdown
Member Author

/jira backport release-5.0

@openshift-ci-robot

Copy link
Copy Markdown

@joelanford: The following backport issues have been created:

Queuing cherrypicks to the requested branches to be created after this PR merges:
/cherrypick release-5.0

Details

In response to this:

/jira backport release-5.0

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-cherrypick-robot

Copy link
Copy Markdown

@openshift-ci-robot: #2883 failed to apply on top of branch "release-5.0":

Applying: Promote TLSAdherence feature gate to GA
Using index info to reconstruct a base tree...
M	features.md
M	features/features.go
M	payload-manifests/featuregates/featureGate-4-10-Hypershift-Default.yaml
M	payload-manifests/featuregates/featureGate-4-10-SelfManagedHA-Default.yaml
Falling back to patching base and 3-way merge...
Auto-merging features.md
CONFLICT (content): Merge conflict in features.md
Auto-merging features/features.go
CONFLICT (content): Merge conflict in features/features.go
Auto-merging payload-manifests/featuregates/featureGate-4-10-Hypershift-Default.yaml
Auto-merging payload-manifests/featuregates/featureGate-4-10-SelfManagedHA-Default.yaml
error: Failed to merge in the changes.
hint: Use 'git am --show-current-patch=diff' to see the failed patch
hint: When you have resolved this problem, run "git am --continue".
hint: If you prefer to skip this patch, run "git am --skip" instead.
hint: To restore the original branch and stop patching, run "git am --abort".
hint: Disable this message with "git config set advice.mergeConflict false"
Patch failed at 0001 Promote TLSAdherence feature gate to GA

Details

In response to this:

@joelanford: The following backport issues have been created:

Queuing cherrypicks to the requested branches to be created after this PR merges:
/cherrypick release-5.0

In response to this:

/jira backport release-5.0

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. lgtm Indicates that a PR is ready to be merged. size/M Denotes a PR that changes 30-99 lines, ignoring generated files. verified Signifies that the PR passed pre-merge verification criteria

Projects

None yet

Development

Successfully merging this pull request may close these issues.

10 participants