Skip to content

OCPBUGS-42107: Allow the control plane operator to finish deleting VPC endpoint for PrivateLink clusters - #4740

Merged
openshift-merge-bot[bot] merged 1 commit into
openshift:mainfrom
csrwng:fix_vpce_deletion
Sep 18, 2024
Merged

openshift-merge-bot[bot] merged 1 commit into
openshift:mainfrom
csrwng:fix_vpce_deletion

Conversation

@csrwng

@csrwng csrwng commented Sep 17, 2024

Copy link
Copy Markdown
Contributor

What this PR does / why we need it:
Before this commit, the HostedCluster controller would only preserve the status of the ValidAWSIdentityProvider condition if its value was false when the hostedcontrolplane was no longer available. This resulted in the following sequence of events:

  • The hosted cluster is deleted
  • The CAPI cluster is deleted causing the hosted control plane to be deleted
  • The ValidAWSIdentityProvider condition was set to Unknown because there is no longer a hosted control plane to get a value from.
  • The AWSEndpointService resource control-plane-operator-finalizer is removed because there is no longer a ValidAWSIdentityProvider
  • The control plane namespace is deleted along with the control plane operator pod in it.
  • The control plane operator does not get a chance to completely cleanup the VPC endpoint in the customer's account.

This commit fixes the sequence by preserving the state of the ValidAWSIdentityProvider condition regardless of it being true or false. This results in the HostedCluster controller waiting for the control plane operator to cleanup and eventually remove the finalizer of the AWSEndpointService resource. It also introduces a grace period for the AWSEndpointService to be cleaned up, after which deletion proceeds as before.

Which issue(s) this PR fixes (optional, use fixes #<issue_number>(, fixes #<issue_number>, ...) format, where issue_number might be a GitHub issue, or a Jira story:
Fixes #OCPBUGS-42107

Checklist

  • Subject and description added to both, commit and PR.
  • Relevant issues have been referenced.
  • This change includes docs.
  • This change includes unit tests.

…PrivateLink clusters

Before this commit, the HostedCluster controller would only preserve the
status of the ValidAWSIdentityProvider condition if its value was false
when the hostedcontrolplane was no longer available. This resulted in
the following sequence of events:
- The hosted cluster is deleted
- The CAPI cluster is deleted causing the hosted control plane to be
  deleted
- The ValidAWSIdentityProvider condition was set to Unknown because
  there is no longer a hosted control plane to get a value from.
- The AWSEndpointService resource control-plane-operator-finalizer is
  removed because there is no longer a ValidAWSIdentityProvider
- The control plane namespace is deleted along with the control plane
  operator pod in it.
- The control plane operator does not get a chance to completely cleanup
  the VPC endpoint in the customer's account.

This commit fixes the sequence by preserving the state of the
ValidAWSIdentityProvider condition regardless of it being true or false.
This results in the HostedCluster controller waiting for the control
plane operator to cleanup and eventually remove the finalizer of the
AWSEndpointService resource. It also introduces a grace period for the
AWSEndpointService to be cleaned up, after which deletion proceeds as
before.
@csrwng csrwng changed the title Allow the control plane operator to finish deleting VPC endpoint for PrivateLink clusters OCPBUGS-42107: Allow the control plane operator to finish deleting VPC endpoint for PrivateLink clusters Sep 17, 2024
@openshift-ci-robot openshift-ci-robot added jira/severity-moderate Referenced Jira bug's severity is moderate for the branch this PR is targeting. jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. labels Sep 17, 2024
@openshift-ci-robot

Copy link
Copy Markdown

@csrwng: This pull request references Jira Issue OCPBUGS-42107, which is valid. The bug has been moved to the POST state.

3 validation(s) were run on this bug
  • bug is open, matching expected state (open)
  • bug target version (4.18.0) matches configured target version for branch (4.18.0)
  • bug is in the state ASSIGNED, which is one of the valid states (NEW, ASSIGNED, POST)

No GitHub users were found matching the public email listed for the QA contact in Jira (jiezhao@redhat.com), skipping review request.

The bug has been updated to refer to the pull request using the external bug tracker.

Details

In response to this:

What this PR does / why we need it:
Before this commit, the HostedCluster controller would only preserve the status of the ValidAWSIdentityProvider condition if its value was false when the hostedcontrolplane was no longer available. This resulted in the following sequence of events:

  • The hosted cluster is deleted
  • The CAPI cluster is deleted causing the hosted control plane to be deleted
  • The ValidAWSIdentityProvider condition was set to Unknown because there is no longer a hosted control plane to get a value from.
  • The AWSEndpointService resource control-plane-operator-finalizer is removed because there is no longer a ValidAWSIdentityProvider
  • The control plane namespace is deleted along with the control plane operator pod in it.
  • The control plane operator does not get a chance to completely cleanup the VPC endpoint in the customer's account.

This commit fixes the sequence by preserving the state of the ValidAWSIdentityProvider condition regardless of it being true or false. This results in the HostedCluster controller waiting for the control plane operator to cleanup and eventually remove the finalizer of the AWSEndpointService resource. It also introduces a grace period for the AWSEndpointService to be cleaned up, after which deletion proceeds as before.

Which issue(s) this PR fixes (optional, use fixes #<issue_number>(, fixes #<issue_number>, ...) format, where issue_number might be a GitHub issue, or a Jira story:
Fixes #OCPBUGS-42107

Checklist

  • Subject and description added to both, commit and PR.
  • Relevant issues have been referenced.
  • This change includes docs.
  • This change includes unit tests.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-ci-robot openshift-ci-robot added the jira/valid-bug Indicates that a referenced Jira bug is valid for the branch this PR is targeting. label Sep 17, 2024
@openshift-ci openshift-ci Bot added the area/hypershift-operator Indicates the PR includes changes for the hypershift operator and API - outside an OCP release label Sep 17, 2024
@openshift-ci

openshift-ci Bot commented Sep 17, 2024

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: csrwng

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci openshift-ci Bot added approved Indicates a PR has been approved by an approver from all required OWNERS files. and removed do-not-merge/needs-area labels Sep 17, 2024
@sjenning

Copy link
Copy Markdown
Contributor

/lgtm

@openshift-ci openshift-ci Bot added the lgtm Indicates that a PR is ready to be merged. label Sep 17, 2024
@openshift-ci

openshift-ci Bot commented Sep 18, 2024

Copy link
Copy Markdown
Contributor

@csrwng: all tests passed!

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

@openshift-merge-bot
openshift-merge-bot Bot merged commit 2ff9ec1 into openshift:main Sep 18, 2024
@openshift-ci-robot

Copy link
Copy Markdown

@csrwng: Jira Issue OCPBUGS-42107: All pull requests linked via external trackers have merged:

Jira Issue OCPBUGS-42107 has been moved to the MODIFIED state.

Details

In response to this:

What this PR does / why we need it:
Before this commit, the HostedCluster controller would only preserve the status of the ValidAWSIdentityProvider condition if its value was false when the hostedcontrolplane was no longer available. This resulted in the following sequence of events:

  • The hosted cluster is deleted
  • The CAPI cluster is deleted causing the hosted control plane to be deleted
  • The ValidAWSIdentityProvider condition was set to Unknown because there is no longer a hosted control plane to get a value from.
  • The AWSEndpointService resource control-plane-operator-finalizer is removed because there is no longer a ValidAWSIdentityProvider
  • The control plane namespace is deleted along with the control plane operator pod in it.
  • The control plane operator does not get a chance to completely cleanup the VPC endpoint in the customer's account.

This commit fixes the sequence by preserving the state of the ValidAWSIdentityProvider condition regardless of it being true or false. This results in the HostedCluster controller waiting for the control plane operator to cleanup and eventually remove the finalizer of the AWSEndpointService resource. It also introduces a grace period for the AWSEndpointService to be cleaned up, after which deletion proceeds as before.

Which issue(s) this PR fixes (optional, use fixes #<issue_number>(, fixes #<issue_number>, ...) format, where issue_number might be a GitHub issue, or a Jira story:
Fixes #OCPBUGS-42107

Checklist

  • Subject and description added to both, commit and PR.
  • Relevant issues have been referenced.
  • This change includes docs.
  • This change includes unit tests.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-bot

Copy link
Copy Markdown

[ART PR BUILD NOTIFIER]

Distgit: hypershift
This PR has been included in build ose-hypershift-container-v4.18.0-202409180310.p0.g2ff9ec1.assembly.stream.el9.
All builds following this will include this PR.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. area/hypershift-operator Indicates the PR includes changes for the hypershift operator and API - outside an OCP release jira/severity-moderate Referenced Jira bug's severity is moderate for the branch this PR is targeting. jira/valid-bug Indicates that a referenced Jira bug is valid for the branch this PR is targeting. jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. lgtm Indicates that a PR is ready to be merged.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants