Repository navigation
ROSAENG-61837: Add gangway-bridge template for Prow e2e #508
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change | ||||
|---|---|---|---|---|---|---|
| @@ -0,0 +1,99 @@ | ||||||
| # THIS FILE IS GENERATED BY BOILERPLATE. DO NOT EDIT. | ||||||
| apiVersion: template.openshift.io/v1 | ||||||
| kind: Template | ||||||
| metadata: | ||||||
| name: gangway-bridge-e2e | ||||||
| parameters: | ||||||
| - name: JOB_NAME | ||||||
| required: true | ||||||
| description: Prow periodic job name to trigger via Gangway | ||||||
| - name: POLL_INTERVAL | ||||||
| value: "60" | ||||||
| description: Seconds between status polls | ||||||
| - name: TIMEOUT | ||||||
| value: "7200" | ||||||
| description: Maximum seconds to wait for job completion | ||||||
| - name: JOB_ENVS | ||||||
| value: "" | ||||||
| description: Comma-separated KEY=VALUE pairs passed to the Prow job | ||||||
| - name: JOBID | ||||||
| generate: expression | ||||||
| from: "[0-9a-z]{7}" | ||||||
| - name: IMAGE_TAG | ||||||
| value: '' | ||||||
| required: true | ||||||
| objects: | ||||||
| - apiVersion: batch/v1 | ||||||
| kind: Job | ||||||
| metadata: | ||||||
| name: gangway-bridge-${IMAGE_TAG}-${JOBID} | ||||||
| spec: | ||||||
| backoffLimit: 0 | ||||||
| activeDeadlineSeconds: ${{TIMEOUT}} | ||||||
| template: | ||||||
| spec: | ||||||
| automountServiceAccountToken: false | ||||||
| restartPolicy: Never | ||||||
| containers: | ||||||
| - name: gangway-bridge | ||||||
| image: quay.io/openshift/origin-tools:latest | ||||||
| command: | ||||||
| - /bin/bash | ||||||
| - -ceu | ||||||
| - | | ||||||
| GW="https://gangway-ci.apps.ci.l2s4.p1.openshiftapps.com/v1/executions" | ||||||
| log() { echo "$(date +%H:%M:%S) $*" >&2; } | ||||||
|
|
||||||
| [[ "${TIMEOUT}" =~ ^[1-9][0-9]*$ ]] || { log "ERROR: TIMEOUT must be a positive integer"; exit 1; } | ||||||
| [[ "${POLL_INTERVAL}" =~ ^[1-9][0-9]*$ ]] || { log "ERROR: POLL_INTERVAL must be a positive integer"; exit 1; } | ||||||
|
|
||||||
| BODY='{"job_execution_type":"1"}' | ||||||
| if [[ -n "${JOB_ENVS:-}" ]]; then | ||||||
| ENVS=$(echo "${JOB_ENVS}" | jq -Rn '[inputs // input | split(",")[] | split("=") | {(.[0]): .[1:] | join("=")}] | add' <<< "${JOB_ENVS}") | ||||||
| BODY=$(jq -cn --argjson e "$ENVS" '{"job_execution_type":"1","pod_spec_options":{"envs":$e}}') | ||||||
| fi | ||||||
|
|
||||||
| RESP=$(curl -sfSL --retry 3 --retry-delay 10 -X POST -H "Authorization: Bearer ${GANGWAY_TOKEN}" -H "Content-Type: application/json" -d "${BODY}" "${GW}/${JOB_NAME}") | ||||||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win 🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -euo pipefail
# Verify whether repository documentation or clients define Gangway idempotency.
rg -n -i -C 3 --glob '*.{go,md,yaml,yml,json}' \
'idempotency|idempotency-key|/v1/executions' .Repository: openshift/certman-operator Length of output: 799 🏁 Script executed: #!/bin/bash
set -euo pipefail
printf '%s\n' '--- template context ---'
sed -n '35,65p' test/e2e/gangway-bridge-template.yml
printf '%s\n' '--- Gangway-related repository references ---'
rg -n -i -C 3 --glob '*.{go,md,yaml,yml,json,sh}' \
'gangway|executions|JOB_NAME|GANGWAY_TOKEN' . | head -240Repository: openshift/certman-operator Length of output: 10250 🌐 Web query:
💡 Result: The Gangway CI API Citations:
🌐 Web query:
💡 Result: I couldn’t verify this in A current OpenShift CI usage example confirms: POST /v1/executions
GET /v1/executions/{execution-id}The POST body includes I found no authoritative evidence that Gangway supports an Citations: 🏁 Script executed: #!/bin/bash
set -euo pipefail
printf '%s\n' '--- curl retry semantics available in this environment ---'
curl --manual 2>/dev/null | rg -n -A12 -B3 \
-- '--retry( |$)|retry-all-errors|retry-max-time|POST' | head -160 || true
printf '%s\n' '--- repository configuration for the bridge Job ---'
sed -n '1,115p' test/e2e/gangway-bridge-template.ymlRepository: openshift/certman-operator Length of output: 4243 🏁 Script executed: #!/bin/bash
set -euo pipefail
curl --version
printf '%s\n' '--- retry options ---'
curl --help all 2>&1 | rg -n -A3 -B2 \
-- '--retry([ =]|$)|retry-all-errors|retry-connrefused|retry-delay|retry-max-time'Repository: openshift/certman-operator Length of output: 1263 Prevent duplicate Prow executions on submission retry. The Gangway request has no idempotency key or documented duplicate suppression. If Gangway accepts the POST but the response is lost, Proposed fix- RESP=$(curl -sfSL --retry 3 --retry-delay 10 -X POST -H "Authorization: Bearer ${GANGWAY_TOKEN}" -H "Content-Type: application/json" -d "${BODY}" "${GW}/${JOB_NAME}")
+ RESP=$(curl -sfSL -X POST -H "Authorization: Bearer ${GANGWAY_TOKEN}" -H "Content-Type: application/json" -d "${BODY}" "${GW}/${JOB_NAME}")📝 Committable suggestion
Suggested change
🤖 Prompt for AI Agents |
||||||
| ID=$(echo "$RESP" | jq -re .id) | ||||||
| PROW_URL="https://prow.ci.openshift.org/view/gs/test-platform-results/logs/${JOB_NAME}/${ID}" | ||||||
| log "Triggered ${JOB_NAME} -> ${ID}" | ||||||
| log "Prow logs: ${PROW_URL}" | ||||||
|
|
||||||
| END=$((SECONDS + ${TIMEOUT})) | ||||||
| while [[ $SECONDS -lt $END ]]; do | ||||||
| sleep "${POLL_INTERVAL}" | ||||||
| S=$(curl -sfSL -H "Authorization: Bearer ${GANGWAY_TOKEN}" "${GW}/${ID}" | jq -r .job_status) || S=UNKNOWN | ||||||
| log "${S} ($((SECONDS))s)" | ||||||
| case $S in SUCCESS) log "Prow logs: ${PROW_URL}"; exit 0;; FAILURE|ABORTED|ERROR) log "Prow logs: ${PROW_URL}"; exit 1;; esac | ||||||
| done | ||||||
| log "Prow logs: ${PROW_URL}" | ||||||
| log "Timeout"; exit 1 | ||||||
| env: | ||||||
| - name: JOB_NAME | ||||||
| value: ${JOB_NAME} | ||||||
| - name: GANGWAY_TOKEN | ||||||
| valueFrom: | ||||||
| secretKeyRef: | ||||||
| name: gangway-api-token | ||||||
| key: token | ||||||
| - name: POLL_INTERVAL | ||||||
| value: ${POLL_INTERVAL} | ||||||
| - name: TIMEOUT | ||||||
| value: ${TIMEOUT} | ||||||
| - name: JOB_ENVS | ||||||
| value: ${JOB_ENVS} | ||||||
| resources: | ||||||
| requests: | ||||||
| cpu: "50m" | ||||||
| memory: "64Mi" | ||||||
| limits: | ||||||
| cpu: "100m" | ||||||
| memory: "128Mi" | ||||||
| securityContext: | ||||||
| runAsNonRoot: true | ||||||
| readOnlyRootFilesystem: true | ||||||
| allowPrivilegeEscalation: false | ||||||
| capabilities: | ||||||
| drop: ["ALL"] | ||||||
| seccompProfile: | ||||||
| type: RuntimeDefault | ||||||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🔒 Security & Privacy | 🟠 Major | 🏗️ Heavy lift
Add a NetworkPolicy for the bridge Pod.
This template creates a Pod that uses
GANGWAY_TOKENand calls an external API, but it emits no NetworkPolicy. Add a Pod label and a NetworkPolicy that selects this Job's Pod. Permit only DNS and the required Gangway egress path.As per path instructions, “NetworkPolicy defined for the namespace.”
🤖 Prompt for AI Agents
Source: Path instructions