Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
79 commits
Select commit Hold shift + click to select a range
878d275
test(envtest): add onUpdate immutability tests for HC fields
cblecker May 22, 2026
e2566f7
test: add unit tests for toleration propagation, HCP status, and gues…
cblecker May 22, 2026
0c9fb46
test(e2e/v2): port 14 v1 validations to v2 Ginkgo specs
cblecker May 22, 2026
7796707
test(e2e/v2): promote registry validation tests to blocking
cblecker May 22, 2026
7404e1d
test(e2e/v2): address review feedback on test patterns
cblecker May 22, 2026
607cd50
test(e2e/v2): move custom labels and tolerations tests to workloads p…
cblecker May 22, 2026
9cfea0f
test: address review findings across e2e/v2 and unit tests
cblecker May 22, 2026
388f477
refactor(e2e/v2): align PR #8527 lifecycle tests with branch helpers
cblecker May 24, 2026
772867f
docs: add PR #8511 learnings to v2 e2e AGENTS.md
cblecker May 25, 2026
42b7b2d
ci: disable inapplicable CodeRabbit pre-merge checks
cblecker May 25, 2026
598e69d
test(e2e/v2): address CodeRabbit pre-merge check findings
cblecker May 25, 2026
0f631d8
chore(deps): update root module dependencies
May 22, 2026
bf06447
chore(deps): update vendored dependencies
May 22, 2026
e6f3061
chore: update remaining generated files
May 22, 2026
65182c6
test(nodepool): add regression tests for CAS pause/unpause replica cl…
jparrill Apr 16, 2026
8800962
ci(deps): bump codecov/codecov-action from 6.0.0 to 6.0.1
dependabot[bot] May 22, 2026
256a90b
feat(webhook): bootstrap serving certs at operator startup
clebs May 19, 2026
6adefb5
test(unit): Add unit test for cert secret bootstrapping
clebs May 20, 2026
8de4d73
refactor(cli): Remove the cert secret bootstrapping from the CLI
clebs May 20, 2026
313783a
Revert "Merge pull request #8480 from bryan-cox/azure-external-dns-va…
Nirshal May 26, 2026
dc7bb3b
fix(cpo): add --tls-cipher-suites to oauth-apiserver deployment
vsolanki12 May 20, 2026
38493cf
fix(konnectivity): propagate mgmt cluster proxy env vars to sidecar
csrwng May 21, 2026
b339635
ci: add Claude Code WIF auth test workflow
bryan-cox May 26, 2026
f36ebed
fix(ci): fix Claude WIF test workflow for ARC runners
bryan-cox May 27, 2026
2cce366
fix(ci): fix Claude WIF test workflow for ARC runners
bryan-cox May 27, 2026
815be12
fix(ci): fix Claude WIF test workflow for ARC runners
bryan-cox May 27, 2026
046ec48
fix(ci): replace container image with workflow-step plugin setup
bryan-cox May 27, 2026
ef0746a
ci(runner): use GOCACHEPROG for zero-copy EFS build cache
celebdor May 22, 2026
04cbe18
ci(gocacheprog): address review feedback and add unit tests
celebdor May 27, 2026
8112733
ci(runner): allow gocacheprog through .dockerignore
celebdor May 27, 2026
24d9750
fix(ci): replace container image with workflow-step plugin setup
bryan-cox May 27, 2026
39c1891
fix(ci): replace container image with workflow-step plugin setup
bryan-cox May 27, 2026
614883c
fix(ci): replace container image with workflow-step plugin setup
bryan-cox May 27, 2026
0cc9996
fix(api): OCPBUGS-84303: add IPv6 OVN join subnet config to prevent d…
orenc1 May 5, 2026
1646589
fix(CPO): compare password with stored hash before regenerating
dhruv-gautam Apr 28, 2026
c4dc4bb
test(CPO): add unit tests for kubeadmin password hash reconciliation
dhruv-gautam May 4, 2026
c2283e5
fix(aws): set aws-load-balancer-scheme on public HCP router service
typeid May 7, 2026
b64f010
fix(hcco): re-enable serviceaccount-pull-secrets controller when regi…
vsolanki12 May 14, 2026
4913947
fix(karpenter-operator): start node cleanup when CAPI Cluster is deleted
maxcao13 May 26, 2026
d4d0663
ci(gocacheprog): use atomic writes to prevent cache corruption
celebdor May 28, 2026
ec2d557
ci(gocacheprog): add unit test workflow
celebdor May 28, 2026
fbf5685
ci(runner): rebuild image on gocacheprog and pipeline changes
celebdor May 29, 2026
12a03a5
ci(runner): remove EFS-backed Go build cache
celebdor May 29, 2026
8a2f54f
docs: de-duplicate Azure self-managed documentation
bryan-cox May 21, 2026
fbcb881
docs: regenerate aggregated-docs.md
bryan-cox May 21, 2026
8ecd002
fix(ci): replace container image with workflow-step plugin setup
bryan-cox May 27, 2026
dafe37e
fix(hostedcluster): requeue when AutoNodeEnabled is progressing
maxcao13 May 12, 2026
8c62fa6
fix(e2e): deep-copy hostedCluster in parallel karpenter subtests
maxcao13 May 12, 2026
42a08a4
fix(hypershift-operator): add CPO overrides for ARO swift-nic resourc…
celebdor May 27, 2026
931a83a
chore(contrib): add Konflux PDS definitions for CPO 4.21 and 4.22
celebdor May 27, 2026
57128f6
ci: add --allowedTools to address-review-comments workflow
bryan-cox May 29, 2026
d5606db
docs(cpo): fix HCCO deployment location in AGENTS.md
enxebre May 29, 2026
9b4f245
ci(deps): bump actions/checkout from 4.3.1 to 6.0.2
dependabot[bot] May 29, 2026
0e27e85
ci(deps): bump google-github-actions/auth from 2.1.13 to 3.0.0
dependabot[bot] May 29, 2026
b68ad2c
fix(ci): pin azure-cli to 2.72.0 in e2e Dockerfile
bryan-cox May 29, 2026
4d00dd6
ci: add Dockerfiles to codecov ignore list
bryan-cox May 29, 2026
788d908
ci(runner): update base image to actions-runner v2.334.0
bryan-cox May 30, 2026
4ca2352
fix: remove stale api.openshift.com labels from HostedControlPlane
dustman9000 May 13, 2026
2dd493c
feat(ci): add skopeo and gh CLI to ARC runner image
enxebre May 28, 2026
83823c1
fix(cpo): increase NTH default workers from 10 to 20
enxebre May 13, 2026
b3370dd
fix(cpo): update NTH test fixtures for workers=20
enxebre May 20, 2026
add63d9
ci(codecov): add carryforward flags to stabilize project coverage checks
bryan-cox May 29, 2026
d04375f
fix(karpenter): Stop controllers fighting over HCP status
jkyros May 20, 2026
468f40f
feat(karpenter): make e2e verify vcpus don't flap
jkyros May 29, 2026
abf747d
fixup! fix(karpenter): Stop controllers fighting over HCP status
jkyros May 30, 2026
1e6a7c7
chore: enable additional golangci-lint linters
bryan-cox May 21, 2026
e50f4c2
fix: resolve all errorlint violations across the codebase
bryan-cox May 21, 2026
604d336
fix: suppress intentional nilerr violations with nolint directives
bryan-cox May 21, 2026
15d02c0
fix: resolve all noctx violations across the codebase
bryan-cox May 21, 2026
244fb77
fix: resolve all usestdlibvars violations across the codebase
bryan-cox May 21, 2026
ae19942
fix: resolve all dupword violations across the codebase
bryan-cox May 21, 2026
b957b57
test: add unit tests for linter fix error paths
bryan-cox May 27, 2026
c0c1d09
fix(cpo): allow kubevirt-csi storageclass default to be changed by user
orenc1 May 27, 2026
c7520f5
docs: add Spot instances documentation
enxebre May 12, 2026
01f1bc1
docs: introduce NTH abbreviation at first mention
enxebre May 21, 2026
0256bfb
docs: reword spot max price description
enxebre May 21, 2026
c829541
docs: regenerate aggregated-docs.md
enxebre Jun 2, 2026
5c1692f
ci(overrides): add GH Action to validate CPO override images from PR …
enxebre Jun 3, 2026
ad0fef1
fix(hcco): guard KubeletConfig CM deletion against transient source a…
vsolanki12 Jun 4, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
38 changes: 38 additions & 0 deletions .claude/skills/validate-pr-override-images/SKILL.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,38 @@
---
description: Validates that CPO override images in a PR actually contain the PRs they claim to include
argument-hint: "<PR-URL-or-number>"
---

## Name
validate-pr-override-images

## Synopsis
```text
/validate-pr-override-images <PR-URL-or-number>
```

## Description
Validates that CPO override images in a PR actually contain the claimed fix PRs.

The PR description must include a structured contract:
```
branch: 4.20 wants: https://github.com/openshift/hypershift/pull/8593
branch: 4.21 wants: https://github.com/openshift/hypershift/pull/8593, https://github.com/openshift/hypershift/pull/8565
```

Prerequisites:
- `skopeo` must be installed (`brew install skopeo` on macOS)
- The local git repo must have the relevant release branches fetched
- Images must be accessible from quay.io

## Implementation

Extract the PR number from the argument, then run:
```bash
.claude/skills/validate-pr-override-images/validate-overrides.sh <pr-number>
```

Report the output to the user.

## Arguments
- `$1`: PR URL (e.g., `https://github.com/openshift/hypershift/pull/8610`) or PR number (e.g., `8610`)
179 changes: 179 additions & 0 deletions .claude/skills/validate-pr-override-images/validate-overrides.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,179 @@
#!/bin/bash
# validate-overrides.sh
# Parses a PR description for the override contract (branch: X.Y wants: PR-links),
# extracts override images from the diff, and validates each image contains the claimed PRs.
# Usage: ./validate-overrides.sh <pr-number> [repo]

set -euo pipefail

SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
REPO_ROOT="$(cd "$SCRIPT_DIR/../../.." && pwd)"

if [[ $# -lt 1 || $# -gt 2 ]]; then
echo "Usage: $0 <pr-number> [repo]" >&2
exit 2
fi

PR="$1"
GH_REPO="${2:-openshift/hypershift}"

echo "=== Validating CPO override images for PR #${PR} ==="
echo ""

# Step 1: Parse PR description for the contract
echo "--- Step 1: Parsing PR description ---"
BODY=$(gh pr view "$PR" --repo "$GH_REPO" --json body -q .body | tr -d '\r')

BRANCH_LIST=""
FOUND_LINES=0
in_code_block=false

while IFS= read -r line; do
if [[ "$line" == '```'* ]]; then
if $in_code_block; then
in_code_block=false
else
in_code_block=true
fi
continue
fi
if $in_code_block; then
continue
fi

lower_line=$(echo "$line" | tr '[:upper:]' '[:lower:]')
if [[ ! "$lower_line" == *branch:*wants:* ]]; then
continue
fi

branch=$(echo "$line" | sed -n 's/^[[:space:]]*[bB][rR][aA][nN][cC][hH]:[[:space:]]*\([0-9]*\.[0-9]*\)[[:space:]]*[wW][aA][nN][tT][sS]:[[:space:]]*\(.*\)$/\1/p')
wants=$(echo "$line" | sed -n 's/^[[:space:]]*[bB][rR][aA][nN][cC][hH]:[[:space:]]*[0-9]*\.[0-9]*[[:space:]]*[wW][aA][nN][tT][sS]:[[:space:]]*\(.*\)$/\1/p')

if [[ -n "$branch" && -n "$wants" ]]; then
FOUND_LINES=$((FOUND_LINES + 1))
pr_numbers=""
for url in $(echo "$wants" | tr ',' ' '); do
url=$(echo "$url" | xargs)
num=$(echo "$url" | grep -oE '[0-9]+$' || true)
if [[ -n "$num" ]]; then
if [[ -n "$pr_numbers" ]]; then
pr_numbers="$pr_numbers $num"
else
pr_numbers="$num"
fi
fi
done
if [[ -z "$pr_numbers" ]]; then
echo "ERROR: branch $branch has 'wants:' but no valid PR numbers could be parsed"
exit 1
fi
BRANCH_LIST="${BRANCH_LIST}${branch}=${pr_numbers}
"
echo " branch $branch wants PRs: $pr_numbers"
fi
done <<< "$BODY"

if [[ $FOUND_LINES -eq 0 ]]; then
echo ""
echo "ERROR: No 'branch: X.Y wants: <PR-links>' lines found in PR description."
echo ""
echo "The PR description must include lines like:"
echo " branch: 4.19 wants: https://github.com/openshift/hypershift/pull/1234"
echo " branch: 4.20 wants: https://github.com/openshift/hypershift/pull/1234, https://github.com/openshift/hypershift/pull/5678"
exit 1
fi

echo ""

# Step 2: Extract images per branch from the diff
echo "--- Step 2: Extracting override images from diff ---"
DIFF=$(gh pr diff "$PR" --repo "$GH_REPO")

IMAGE_LIST=""
current_version=""

while IFS= read -r line; do
version_match=$(echo "$line" | sed -n 's/^[+ ].*version:[[:space:]]*\([0-9]*\.[0-9]*\)\.[0-9]*.*/\1/p')
if [[ -n "$version_match" ]]; then
current_version="$version_match"
fi

image_match=$(echo "$line" | sed -n 's/^+.*cpoImage:[[:space:]]*\(.*\)/\1/p')
image_match="${image_match#"${image_match%%[![:space:]]*}"}"
image_match="${image_match%"${image_match##*[![:space:]]}"}"
if [[ -n "$image_match" && -n "$current_version" ]]; then
entry="${current_version}=${image_match}"
if [[ "$IMAGE_LIST" != *"$entry"* ]]; then
IMAGE_LIST="${IMAGE_LIST}${entry}
"
fi
fi
done <<< "$DIFF"

echo "$IMAGE_LIST" | while IFS= read -r entry; do
if [[ -n "$entry" ]]; then
branch="${entry%%=*}"
image="${entry#*=}"
echo " branch $branch image: $image"
fi
done

echo ""

# Step 3: Validate each (branch, image, PR) tuple
echo "--- Step 3: Validating images contain claimed PRs ---"
echo ""

echo "$BRANCH_LIST" | while IFS= read -r branch_entry; do
if [[ -z "$branch_entry" ]]; then
continue
fi
branch="${branch_entry%%=*}"
prs="${branch_entry#*=}"

branch_images=$(echo "$IMAGE_LIST" | grep "^${branch}=" | sed "s/^${branch}=//" | sort -u)

if [[ -z "$branch_images" ]]; then
echo "WARNING: branch $branch declared in description but no override images found in diff"
echo "FAILURE_COUNT:1"
continue
fi

echo "$branch_images" | while IFS= read -r image; do
if [[ -z "$image" ]]; then
continue
fi
echo "Image: $image (branch $branch)"
for pr_num in $prs; do
verify_output=$("$SCRIPT_DIR/verify-pr-in-image.sh" "$image" "$pr_num" "$REPO_ROOT" 2>&1) && verify_rc=0 || verify_rc=$?
echo "$verify_output" | sed 's/^/ /'
if echo "$verify_output" | tail -1 | grep -q "PASS"; then
echo " PR #${pr_num}: PASS"
echo "PASS_COUNT:1"
else
echo " PR #${pr_num}: FAIL"
echo "FAILURE_COUNT:1"
fi
done
echo ""
done
done > /tmp/validate-overrides-output.$$

grep -v "COUNT:" /tmp/validate-overrides-output.$$
PASSES=$(grep -c "PASS_COUNT:" /tmp/validate-overrides-output.$$ || true)
FAILURES=$(grep -c "FAILURE_COUNT:" /tmp/validate-overrides-output.$$ || true)
rm -f /tmp/validate-overrides-output.$$

# Summary
echo "=== Summary ==="
echo "Passed: $PASSES"
echo "Failed: $FAILURES"

if [[ $FAILURES -gt 0 ]]; then
echo ""
echo "OVERALL: FAIL"
exit 1
else
echo ""
echo "OVERALL: PASS"
fi
69 changes: 69 additions & 0 deletions .claude/skills/validate-pr-override-images/verify-pr-in-image.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,69 @@
#!/bin/bash
# verify-pr-in-image.sh
# Verifies that a container image contains a specific PR in its git history.
# Usage: ./verify-pr-in-image.sh <image> <pr-number> [repo-path]

set -euo pipefail

if [[ $# -lt 2 || $# -gt 3 ]]; then
echo "Usage: $0 <image> <pr-number> [repo-path]" >&2
exit 2
fi

IMAGE="$1"
PR="$2"
REPO="${3:-.}"

if ! command -v skopeo &>/dev/null; then
echo "ERROR: skopeo is not installed. Install it with: brew install skopeo (macOS) or dnf install skopeo (RHEL/Fedora)"
exit 1
fi

echo "Inspecting image..."
INSPECT=$(skopeo inspect --override-os linux --override-arch amd64 "docker://$IMAGE") || {
echo "ERROR: Could not inspect image $IMAGE"
exit 1
}

COMMIT=$(echo "$INSPECT" | grep -o '"vcs-ref"[[:space:]]*:[[:space:]]*"[^"]*"' | head -1 | sed 's/.*"vcs-ref"[[:space:]]*:[[:space:]]*"\([^"]*\)".*/\1/')

if [[ -z "$COMMIT" ]]; then
echo "ERROR: Could not find vcs-ref label in image $IMAGE"
exit 1
fi

echo "Image commit: $COMMIT"

if ! git -C "$REPO" cat-file -e "$COMMIT" 2>/dev/null; then
echo "Commit not found locally, fetching..."
git -C "$REPO" fetch --all --quiet
if ! git -C "$REPO" cat-file -e "$COMMIT" 2>/dev/null; then
echo "ERROR: Commit $COMMIT not found in any remote"
exit 1
fi
fi

PR_MERGE_COMMIT=$(gh pr view "$PR" --repo openshift/hypershift --json mergeCommit --jq '.mergeCommit.oid // empty')

if [[ -z "$PR_MERGE_COMMIT" ]]; then
echo "FAIL: PR #${PR} has no merge commit (not merged yet?)"
exit 1
fi

echo "PR #${PR} merge commit: $PR_MERGE_COMMIT"

if ! git -C "$REPO" cat-file -e "$PR_MERGE_COMMIT" 2>/dev/null; then
echo "Merge commit not found locally, fetching..."
git -C "$REPO" fetch --all --quiet
if ! git -C "$REPO" cat-file -e "$PR_MERGE_COMMIT" 2>/dev/null; then
echo "ERROR: PR #${PR} merge commit $PR_MERGE_COMMIT not found in any remote"
exit 1
fi
fi

if git -C "$REPO" merge-base --is-ancestor "$PR_MERGE_COMMIT" "$COMMIT" 2>/dev/null; then
echo "PASS: PR #${PR} is included in image $IMAGE"
else
echo "FAIL: PR #${PR} is NOT included in image $IMAGE"
exit 1
fi
10 changes: 10 additions & 0 deletions .coderabbit.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,16 @@ language: en-US
reviews:
auto_review:
drafts: true
pre_merge_checks:
docstrings:
mode: "off"
custom_checks:
- name: "MicroShift Test Compatibility"
mode: "off"
- name: "Single Node OpenShift (SNO) Test Compatibility"
mode: "off"
- name: "OTE Binary Stdout Contract"
mode: "off"
profile: chill
high_level_summary: true
collapse_walkthrough: true
Expand Down
1 change: 1 addition & 0 deletions .dockerignore
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
bin/
hack/tools/bin/
contrib/
!contrib/ci/gocacheprog/
.github/
.tekton/
.ci-operator.yaml
Expand Down
22 changes: 0 additions & 22 deletions .github/actions/warm-go-cache/action.yaml

This file was deleted.

Loading