Skip to content

CNTRLPLANE-3603: Migrate clients from CAPI v1beta1 to v1beta2 - #8717

Merged
openshift-merge-bot[bot] merged 4 commits into
openshift:mainfrom
clebs:v1beta2-clients
Sep 9, 2026
Merged

openshift-merge-bot[bot] merged 4 commits into
openshift:mainfrom
clebs:v1beta2-clients

Conversation

@clebs

@clebs clebs commented Jun 11, 2026 •

Copy link
Copy Markdown
Member

What this PR does / why we need it:

As a the next step after bumping CAPI to 1.11 in CNTRLPLANE-2207, we are updating all clients from v1beta1 to v1beta2.

Provider specific code can not be updated yet since all providers are still using v1beta1 in their types.

Which issue(s) this PR fixes:

Fixes CNTRLPLANE-3603

Special notes for your reviewer:

The fix for MachineDeployment completeness relates to the upstream issue kubernetes-sigs/cluster-api#13738

Checklist:

  • Subject and description added to both, commit and PR.
  • Relevant issues have been referenced.
  • This change includes docs.
  • This change includes unit tests.

Summary by CodeRabbit

  • New Features

    • Expose control-plane initialization status to surface provider initialization progress.
  • Refactor

    • Migrate Cluster API usage from v1beta1 to v1beta2 across controllers, operators, tests and manifests.
    • Update machine, health, condition, and timeout handling to v1beta2 shapes.
  • Behavior

    • Controllers now mark control-plane and infrastructure initialization during reconciliation.
    • Removed legacy API-version conversion webhook support.

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

Pipeline controller notification
This repo is configured to use the pipeline controller. Second-stage tests will be triggered either automatically or after lgtm label is added, depending on the repository configuration. The pipeline controller will automatically detect which contexts are required and will utilize /test Prow commands to trigger the second stage.

For optional jobs, comment /test ? to see a list of all defined jobs. To trigger manually all jobs from second stage use /pipeline required command.

This repository is configured in: LGTM mode

@openshift-ci-robot openshift-ci-robot added the jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. label Jun 11, 2026
@openshift-ci-robot

openshift-ci-robot commented Jun 11, 2026 •

Copy link
Copy Markdown

@clebs: This pull request references CNTRLPLANE-3603 which is a valid jira issue.

Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the story to target the "5.0.0" version, but no target version was set.

Details

In response to this:

What this PR does / why we need it:

As a the next step after bumping CAPI to 1.11 in CNTRLPLANE-2207, we are updating all clients from v1beta1 to v1beta2.

Provider specific code can not be updated yet since all providers are still using v1beta1 in their types.

Which issue(s) this PR fixes:

Fixes CNTRLPLANE-3603

Special notes for your reviewer:

Checklist:

  • Subject and description added to both, commit and PR.
  • Relevant issues have been referenced.
  • This change includes docs.
  • This change includes unit tests.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-ci openshift-ci Bot added the do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. label Jun 11, 2026
@openshift-ci

openshift-ci Bot commented Jun 11, 2026

Copy link
Copy Markdown
Contributor

Skipping CI for Draft Pull Request.
If you want CI signal for your change, please convert it to an actual PR.
You can still manually trigger a test run with /test all

@coderabbitai

coderabbitai Bot commented Jun 11, 2026 •

Copy link
Copy Markdown
Contributor

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

This PR migrates code and tests from Cluster API v1beta1 to v1beta2 across APIs, controllers, platform integrations, schemes, manifests, and utilities. It adds HostedControlPlane.Status.Initialization and HostedControlPlaneInitializationStatus, sets Initialization.ControlPlaneInitialized in HostedControlPlane reconciliation, patches CAPI Cluster Status.Initialization.InfrastructureProvisioned, replaces several CAPI spec/status shapes (ContractVersionedObjectReference, pointer Spec.Paused, seconds-based timeout fields), removes CAPI conversion webhook plumbing, and updates golangci lint exclusions.

Sequence Diagram(s)

sequenceDiagram
  participant HostedControlPlane
  participant HostedControlPlaneController
  participant HostedClusterController
  participant ClusterAPI
  participant Tests
  HostedControlPlane->>HostedControlPlaneController: expose Status.Initialization.ControlPlaneInitialized
  HostedControlPlaneController->>HostedClusterController: reconciliation observes InfrastructureReady
  HostedClusterController->>ClusterAPI: patch status.initialization.infrastructureProvisioned=true
  ClusterAPI->>Tests: tests updated to use v1beta2 types and condition shapes
Loading

Possibly related PRs

  • openshift/hypershift#8594: Related changes touching CAPI webhook conversion wiring and MachineDeployment completion logic during v1beta2 migration.

Suggested reviewers

  • muraee
  • Nirshal

Important

Pre-merge checks failed

Please resolve all errors before merging. Addressing warnings is optional.

❌ Failed checks (1 error)

Check name Status Explanation Resolution
No-Weak-Crypto ❌ Error Changed code uses non-constant-time secret comparisons: bytes.Equal on ServiceSignerPrivateKey/PublicKey secret bytes in hostedcluster_controller.go (and bytes.Equal on global pull secret data in u... Replace bytes.Equal secret/token comparisons with crypto/subtle.ConstantTimeCompare (and handle length differences safely) or avoid comparing secret material directly.
✅ Passed checks (10 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and specifically summarizes the main change: migrating Cluster API client usage from v1beta1 to v1beta2 across the codebase, which is the primary objective of this PR.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Stable And Deterministic Test Names ✅ Passed Verified all PR-mentioned test files (test/e2e/* and test/e2e/v2/backuprestore/cleanup.go) contain no Ginkgo It/Describe/Context/When titles; no dynamic Ginkgo test names found.
Test Structure And Quality ✅ Passed Scanned PR-touched test files (e2e + unit): none import github.com/onsi/ginkgo or use Describe/It/BeforeEach/AfterEach, so the Ginkgo-specific structure/timeout rules are not applicable.
Topology-Aware Scheduling Compatibility ✅ Passed PR is CAPI v1beta1→v1beta2 client/status migration; web.find found no occurrences of affinity/anti-affinity/PDB/topologySpread/maxUnavailable or control-plane node selectors—no new topology-insensi...
Ipv6 And Disconnected Network Test Compatibility ✅ Passed Scanned modified e2e files between commits c6f0d7c and 4183f2c: no added ginkgo It/Describe/Context/When blocks and no newly added IPv4/external-connectivity markers (no hardcoded IPv4/CIDRs, Parse...
Container-Privileges ✅ Passed PR #8717 diff hunks contain no matches for privileged, hostPID, hostNetwork, hostIPC, allowPrivilegeEscalation, or SYS_ADMIN (searches on the GitHub “Files changed” page returned none).
No-Sensitive-Data-In-Logs ✅ Passed Scanned PR-touched files for log calls containing sensitive keywords; only safe messages like “Reconciling kubeadmin password secret” / kubeconfig wait/no secret contents found.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Comment @coderabbitai help to get the list of available commands.

@openshift-ci openshift-ci Bot added area/api Indicates the PR includes changes for the API area/cli Indicates the PR includes changes for CLI area/control-plane-operator Indicates the PR includes changes for the control plane operator - in an OCP release area/hypershift-operator Indicates the PR includes changes for the hypershift operator and API - outside an OCP release area/karpenter-operator Indicates the PR includes changes related to the Karpenter operator area/platform/aws PR/issue for AWS (AWSPlatform) platform area/platform/azure PR/issue for Azure (AzurePlatform) platform area/platform/gcp PR/issue for GCP (GCPPlatform) platform area/platform/ibmcloud PR/issue for IBMCloud (IBMCloudPlatform) platform area/platform/kubevirt PR/issue for KubeVirt (KubevirtPlatform) platform area/platform/openstack PR/issue for OpenStack (OpenStackPlatform) platform area/platform/powervs PR/issue for PowerVS (PowerVSPlatform) platform area/testing Indicates the PR includes changes for e2e testing and removed do-not-merge/needs-area labels Jun 11, 2026
@codecov

codecov Bot commented Jun 11, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 86.03352% with 25 lines in your changes missing coverage. Please review.
✅ Project coverage is 47.33%. Comparing base (e1e98a5) to head (2b10bf7).
⚠️ Report is 24 commits behind head on main.

Files with missing lines Patch % Lines
hypershift-operator/controllers/nodepool/capi.go 88.57% 9 Missing and 3 partials ⚠️
...hostedcluster/internal/platform/powervs/powervs.go 28.57% 5 Missing ⚠️
...rollers/hostedcluster/internal/platform/aws/aws.go 33.33% 2 Missing ⚠️
...stedcluster/internal/platform/ibmcloud/ibmcloud.go 50.00% 2 Missing ⚠️
...trollers/hostedcluster/hostedcluster_controller.go 90.90% 1 Missing ⚠️
...ers/hostedcluster/internal/platform/agent/agent.go 80.00% 1 Missing ⚠️
...ers/hostedcluster/internal/platform/azure/azure.go 0.00% 1 Missing ⚠️
...edcluster/internal/platform/openstack/openstack.go 80.00% 1 Missing ⚠️
Additional details and impacted files
@@            Coverage Diff             @@
##             main    #8717      +/-   ##
==========================================
+ Coverage   47.32%   47.33%   +0.01%     
==========================================
  Files         792      793       +1     
  Lines       99678    99717      +39     
==========================================
+ Hits        47169    47201      +32     
- Misses      49347    49352       +5     
- Partials     3162     3164       +2     
Files with missing lines Coverage Δ
cmd/cluster/core/dump.go 15.73% <ø> (ø)
...ostedcontrolplane/hostedcontrolplane_controller.go 51.83% <100.00%> (+0.07%) ⬆️
...ontrollers/hostedcontrolplane/v2/kas/kubeconfig.go 26.53% <ø> (ø)
...operator/hostedclusterconfigoperator/api/scheme.go 0.00% <ø> (ø)
...tor/controllers/inplaceupgrader/inplaceupgrader.go 68.71% <100.00%> (ø)
...onfigoperator/controllers/inplaceupgrader/setup.go 0.00% <ø> (ø)
...usterconfigoperator/controllers/machine/machine.go 67.48% <ø> (ø)
...clusterconfigoperator/controllers/machine/setup.go 0.00% <ø> (ø)
...stedclusterconfigoperator/controllers/node/node.go 38.70% <ø> (ø)
...tor/controllers/spotremediation/spotremediation.go 65.71% <ø> (ø)
... and 23 more
Flag Coverage Δ
cmd-support 40.96% <100.00%> (+0.01%) ⬆️
cpo-hostedcontrolplane 50.36% <100.00%> (+0.01%) ⬆️
cpo-other 48.32% <100.00%> (ø)
hypershift-operator 57.51% <84.84%> (+0.01%) ⬆️
other 34.70% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 4

🧹 Nitpick comments (1)
api/hypershift/v1beta1/hosted_controlplane.go (1)

440-440: ⚡ Quick win

Use consistent marker syntax for default value.

This file uses +kubebuilder:default= on lines 322, 331, and 338. For consistency, change +default=false to +kubebuilder:default=false.

📝 Suggested change
-	// +default=false
+	// +kubebuilder:default=false
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@api/hypershift/v1beta1/hosted_controlplane.go` at line 440, Change the marker
annotation for the boolean default to use the same kubebuilder syntax as the
other fields: replace the comment line `+default=false` with
`+kubebuilder:default=false` on the corresponding boolean field in the
HostedControlPlane spec (the same block that contains the other
`+kubebuilder:default=` annotations around lines where the spec fields are
defined), ensuring consistency with the markers used on the other fields.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In
`@control-plane-operator/controllers/hostedcontrolplane/hostedcontrolplane_controller.go`:
- Around line 681-685: Don't set
hostedControlPlane.Status.Initialization.ControlPlaneInitialized
unconditionally; instead gate it on the availability checks already computed by
reconcileAvailabilityStatus. Replace the unconditional assignment of
hostedControlPlane.Status.Initialization.ControlPlaneInitialized = ptr.To(true)
with logic that sets it to true only when the reconciler determines
hyperv1.HostedControlPlaneAvailable is true (and specifically
KubeAPIServerAvailable is true / kubeconfig exists and LB health/component
checks passed); otherwise leave it false or nil. Locate the assignment and use
the results/conditions produced by reconcileAvailabilityStatus (or the same
booleans it computes) to decide the value.

In
`@control-plane-operator/hostedclusterconfigoperator/controllers/machine/machine_test.go`:
- Around line 467-468: The test case title "With Failing machine with internal
addresses and passthrow service should mark endpointslices as not ready/not
serving" does not match the setup which uses
pairOfDualStackMachines(capiv1.MachinePhaseRunning,
capiv1.MachinePhaseDeleting); either rename the test title to refer to a
"Deleting machine" to match the current setup, or change the second machine
phase to capiv1.MachinePhaseFailed so the scenario truly models a failing
machine; update the test case entry (the name string and/or the machines call)
accordingly, keeping the rest of the assertions intact.

In `@hypershift-operator/controllers/hostedcluster/hostedcluster_controller.go`:
- Around line 3043-3044: The ClusterRole that includes Verbs:
[]string{"get","list","patch","watch"} is granting the capi-provider subject
cluster-wide patch (write) access to CRDs which contradicts the later code that
assumes a read-only binding for capi-provider; either remove "patch" from that
ClusterRole's Verbs so capi-provider only gets get/list/watch, or create a
separate ClusterRole (e.g., "capi-provider-crd-reader") with Verbs:
[]string{"get","list","watch"} and bind capi-provider to that instead, leaving
the original ClusterRole with "patch" bound only to trusted controller
subjects—update the RoleBinding/ClusterRoleBinding creation for the
capi-provider subject accordingly so the access model matches the assumptions in
the subsequent code paths (lines around where capi-provider is referenced).

In `@hypershift-operator/controllers/nodepool/capi.go`:
- Around line 249-253: The cleanupMachineTemplates function currently uses
api.Scheme.VersionsForGroupKind(...)[0] to build a single apiVersion and only
lists MachineTemplates for that version; change it to iterate over all versions
returned by api.Scheme.VersionsForGroupKind(schema.GroupKind{Group:
ref.APIGroup, Kind: ref.Kind}) and for each version construct
schema.GroupVersion{Group: ref.APIGroup, Version: ver.Version}.String(), then
list and delete MachineTemplates for each apiVersion (rather than only
versions[0]). Keep using the existing capiv1.ContractVersionedObjectReference
writers (no change needed to the reference type).

---

Nitpick comments:
In `@api/hypershift/v1beta1/hosted_controlplane.go`:
- Line 440: Change the marker annotation for the boolean default to use the same
kubebuilder syntax as the other fields: replace the comment line
`+default=false` with `+kubebuilder:default=false` on the corresponding boolean
field in the HostedControlPlane spec (the same block that contains the other
`+kubebuilder:default=` annotations around lines where the spec fields are
defined), ensuring consistency with the markers used on the other fields.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Central YAML (inherited)

Review profile: CHILL

Plan: Enterprise

Run ID: 5cdbc23e-aa7c-4f55-a404-d1a9a463f044

📥 Commits

Reviewing files that changed from the base of the PR and between 76b27ab and bcb4fda.

⛔ Files ignored due to path filters (1)
  • vendor/github.com/openshift/hypershift/api/hypershift/v1beta1/hosted_controlplane.go is excluded by !vendor/**, !**/vendor/**
📒 Files selected for processing (63)
  • api/.golangci.yml
  • api/hypershift/v1beta1/hosted_controlplane.go
  • cmd/cluster/core/dump.go
  • control-plane-operator/controllers/hostedcontrolplane/hostedcontrolplane_controller.go
  • control-plane-operator/controllers/hostedcontrolplane/v2/kas/kubeconfig.go
  • control-plane-operator/hostedclusterconfigoperator/api/scheme.go
  • control-plane-operator/hostedclusterconfigoperator/controllers/globalps/globalps_test.go
  • control-plane-operator/hostedclusterconfigoperator/controllers/inplaceupgrader/inplaceupgrader.go
  • control-plane-operator/hostedclusterconfigoperator/controllers/inplaceupgrader/inplaceupgrader_test.go
  • control-plane-operator/hostedclusterconfigoperator/controllers/inplaceupgrader/setup.go
  • control-plane-operator/hostedclusterconfigoperator/controllers/machine/machine.go
  • control-plane-operator/hostedclusterconfigoperator/controllers/machine/machine_test.go
  • control-plane-operator/hostedclusterconfigoperator/controllers/machine/setup.go
  • control-plane-operator/hostedclusterconfigoperator/controllers/node/node.go
  • control-plane-operator/hostedclusterconfigoperator/controllers/node/node_test.go
  • control-plane-operator/hostedclusterconfigoperator/controllers/spotremediation/spotremediation.go
  • control-plane-operator/hostedclusterconfigoperator/controllers/spotremediation/spotremediation_test.go
  • hypershift-operator/controllers/hostedcluster/hostedcluster_controller.go
  • hypershift-operator/controllers/hostedcluster/hostedcluster_controller_test.go
  • hypershift-operator/controllers/hostedcluster/hostedcluster_webhook.go
  • hypershift-operator/controllers/hostedcluster/internal/platform/agent/agent.go
  • hypershift-operator/controllers/hostedcluster/internal/platform/agent/agent_test.go
  • hypershift-operator/controllers/hostedcluster/internal/platform/aws/aws.go
  • hypershift-operator/controllers/hostedcluster/internal/platform/azure/azure.go
  • hypershift-operator/controllers/hostedcluster/internal/platform/gcp/gcp.go
  • hypershift-operator/controllers/hostedcluster/internal/platform/ibmcloud/ibmcloud.go
  • hypershift-operator/controllers/hostedcluster/internal/platform/ibmcloud/ibmcloud_test.go
  • hypershift-operator/controllers/hostedcluster/internal/platform/kubevirt/kubevirt.go
  • hypershift-operator/controllers/hostedcluster/internal/platform/kubevirt/kubevirt_test.go
  • hypershift-operator/controllers/hostedcluster/internal/platform/openstack/openstack.go
  • hypershift-operator/controllers/hostedcluster/internal/platform/openstack/openstack_test.go
  • hypershift-operator/controllers/hostedcluster/internal/platform/powervs/powervs.go
  • hypershift-operator/controllers/manifests/controlplaneoperator/manifests.go
  • hypershift-operator/controllers/nodepool/aws.go
  • hypershift-operator/controllers/nodepool/aws_test.go
  • hypershift-operator/controllers/nodepool/azure_test.go
  • hypershift-operator/controllers/nodepool/capi.go
  • hypershift-operator/controllers/nodepool/capi_test.go
  • hypershift-operator/controllers/nodepool/conditions.go
  • hypershift-operator/controllers/nodepool/conditions_test.go
  • hypershift-operator/controllers/nodepool/gcp.go
  • hypershift-operator/controllers/nodepool/metrics/metrics.go
  • hypershift-operator/controllers/nodepool/nodepool_controller.go
  • hypershift-operator/controllers/nodepool/nodepool_controller_test.go
  • hypershift-operator/controllers/nodepool/powervs.go
  • hypershift-operator/controllers/nodepool/scale_from_zero_test.go
  • hypershift-operator/controllers/nodepool/version.go
  • hypershift-operator/controllers/nodepool/version_test.go
  • karpenter-operator/controllers/karpenter/karpenter_controller.go
  • karpenter-operator/controllers/karpenter/karpenter_controller_test.go
  • support/api/capi_types.go
  • support/api/scheme.go
  • support/k8sutil/resources.go
  • support/upsert/upsert.go
  • test/e2e/autoscaling_test.go
  • test/e2e/nodepool_day2_tags_test.go
  • test/e2e/nodepool_kv_advanced_multinet_test.go
  • test/e2e/nodepool_osp_advanced_test.go
  • test/e2e/nodepool_rolling_upgrade_test.go
  • test/e2e/nodepool_spot_termination_handler_test.go
  • test/e2e/upgrade_hypershift_operator_test.go
  • test/e2e/util/util.go
  • test/e2e/v2/backuprestore/cleanup.go
💤 Files with no reviewable changes (2)
  • hypershift-operator/controllers/hostedcluster/hostedcluster_webhook.go
  • support/api/scheme.go

Comment thread hypershift-operator/controllers/hostedcluster/hostedcluster_controller.go Outdated
Comment thread hypershift-operator/controllers/nodepool/capi.go
@clebs clebs mentioned this pull request Jun 11, 2026
4 tasks
@clebs
clebs force-pushed the v1beta2-clients branch from c595b6b to 17b8504 Compare June 11, 2026 14:20
@openshift-ci openshift-ci Bot added the area/documentation Indicates the PR includes changes for documentation label Jun 11, 2026
@github-actions
github-actions Bot temporarily deployed to docs-preview/pr-8717 June 11, 2026 14:26 Inactive
@openshift-ci openshift-ci Bot added the needs-rebase Indicates a PR cannot be merged because it has merge conflicts with HEAD. label Jun 11, 2026
@clebs
clebs force-pushed the v1beta2-clients branch from 17b8504 to 80d79fb Compare June 11, 2026 17:31
@openshift-ci openshift-ci Bot added the needs-rebase Indicates a PR cannot be merged because it has merge conflicts with HEAD. label Aug 1, 2026
@openshift-ci

openshift-ci Bot commented Aug 15, 2026

Copy link
Copy Markdown
Contributor

Stale PRs rot after 14d of inactivity.

Mark the PR as fresh by commenting /remove-lifecycle rotten.
Rotten PRs close after an additional 7d of inactivity.

If this PR is safe to close now please do so with /close.

/lifecycle rotten
/remove-lifecycle stale

@openshift-ci openshift-ci Bot added lifecycle/rotten Denotes an issue or PR that has aged beyond stale and will be auto-closed. and removed lifecycle/stale Denotes an issue or PR has remained open with no activity and has become stale. labels Aug 15, 2026
@clebs

clebs commented Aug 15, 2026

Copy link
Copy Markdown
Member Author

/remove-lifecycle rotten

@clebs

clebs commented Aug 24, 2026

Copy link
Copy Markdown
Member Author

/test e2e-aws

3 similar comments
@clebs

clebs commented Aug 25, 2026

Copy link
Copy Markdown
Member Author

/test e2e-aws

@clebs

clebs commented Aug 25, 2026

Copy link
Copy Markdown
Member Author

/test e2e-aws

@clebs

clebs commented Aug 25, 2026

Copy link
Copy Markdown
Member Author

/test e2e-aws

@clebs

clebs commented Aug 25, 2026

Copy link
Copy Markdown
Member Author

/test e2e-aks

@clebs

clebs commented Aug 26, 2026

Copy link
Copy Markdown
Member Author

/test e2e-aws
/test e2e-aks

@clebs

clebs commented Aug 27, 2026

Copy link
Copy Markdown
Member Author

/assign @csrwng

@openshift-ci-robot

openshift-ci-robot commented Aug 27, 2026 •

Copy link
Copy Markdown

@clebs: This pull request references CNTRLPLANE-3603 which is a valid jira issue.

Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the story to target the "5.1.0" version, but no target version was set.

Details

In response to this:

What this PR does / why we need it:

As a the next step after bumping CAPI to 1.11 in CNTRLPLANE-2207, we are updating all clients from v1beta1 to v1beta2.

Provider specific code can not be updated yet since all providers are still using v1beta1 in their types.

Which issue(s) this PR fixes:

Fixes CNTRLPLANE-3603

Special notes for your reviewer:

The fix for MachineDeployment completeness relates to the upstream issue kubernetes-sigs/cluster-api#13738

Checklist:

  • Subject and description added to both, commit and PR.
  • Relevant issues have been referenced.
  • This change includes docs.
  • This change includes unit tests.

Summary by CodeRabbit

  • New Features

  • Expose control-plane initialization status to surface provider initialization progress.

  • Refactor

  • Migrate Cluster API usage from v1beta1 to v1beta2 across controllers, operators, tests and manifests.

  • Update machine, health, condition, and timeout handling to v1beta2 shapes.

  • Behavior

  • Controllers now mark control-plane and infrastructure initialization during reconciliation.

  • Removed legacy API-version conversion webhook support.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-ci

openshift-ci Bot commented Aug 31, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

Approval requirements bypassed by manually added approval.

This pull-request has been approved by: clebs

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@clebs

clebs commented Sep 1, 2026

Copy link
Copy Markdown
Member Author

/test e2e-aws

Comment thread api/hypershift/v1beta1/hosted_controlplane.go
Comment thread api/hypershift/v1beta1/hosted_controlplane.go Outdated
@clebs

clebs commented Sep 1, 2026

Copy link
Copy Markdown
Member Author

/test images

// +kubebuilder:validation:MinProperties=1
type HostedControlPlaneInitializationStatus struct {
// controlPlaneInitialized is true when the control plane is functional enough to accept requests.
// Once this condition is marked true, its value is never changed. See the Ready condition for an

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What enforces that this value is never changed? What would happen if this value does get changed somehow?

@clebs clebs Sep 7, 2026 •

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

HI @everettraven!
that is a good question. There is nothing mechanically enforcing this (other than the controller setting it and making sure it stays that way), it is a property that mirrors what CAPI sets, which has the same comment: https://github.com/kubernetes-sigs/cluster-api/blob/75072e39a4977fec5cbb0223869d26c89b609653/api/core/v1beta2/cluster_types.go#L182

It was working the same way before. The old status.initialized was also unconditionally set to true at the same point, with the same "once true, never reverted" convention and no mechanical enforcement.

The new status.initialization.controlPlaneInitialized is just the v1beta2 contract equivalent of the existing status.initialized field, placed at the exact same location with the same semantics.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Should we add some validation to enforce this semantic and prevent accidental changes to this field once it has been set to true?

What would happen if this was set to true and somehow got modified?

  Bump Cluster API core imports from v1beta1 to v1beta2 across all
  consumers. Provider imports (Azure, GCP, OpenStack, AWS, IBM Cloud)
  remain on v1beta1 as their ControlPlaneEndpoint field still references
  core v1beta1.APIEndpoint — no provider has migrated this yet.

  Key type changes:
  - corev1.ObjectReference → capiv1.ContractVersionedObjectReference
  - Machine.Status.NodeRef: pointer → MachineNodeReference (use .IsDefined())
  - Cluster.Spec.Paused: bool → *bool
  - Version/FailureDomain: *string → string
  - Status replica fields: int32 → *int32 (access via ptr.Deref)
  - Strategy → Rollout.Strategy
  - NodeDrainTimeout → Deletion.NodeDrainTimeoutSeconds
  - MHC: UnhealthyConditions → Checks.UnhealthyNodeConditions,
    MaxUnhealthy → Remediation.TriggerIf.UnhealthyLessThanOrEqualTo
  - Conditions: capiv1.Condition → metav1.Condition
  - ReadyCondition → MachinesReadyCondition (on MachineDeployment/MachineSet)
  - machineConditionResult.Status: corev1.ConditionStatus → metav1.ConditionStatus
  - MachineDeploymentComplete: use UpToDateReplicas + ReadyReplicas
  - Constants renamed with V1Beta1 suffix (e.g. WaitingForNodeRefReason)

  Control plane changes:
  - Add HCP Status.Initialization.ControlPlaneInitialized
  - Add patchInfrastructureInitializationProvisioned for CAPI v1beta2 contract
  - Remove conversion webhook (no longer needed with single API version)
  - Remove v1beta1 scheme registration (core, addons, ipam)

Signed-off-by: Borja Clemente <bclement@redhat.com>
  - ContractVersionedObjectReference (APIGroup instead of APIVersion, no Namespace)
  - FailureDomain: *string nil → empty string
  - Version: *string → string
  - Status replica fields: int32 → *int32 via ptr.To
  - Conditions: []capiv1.Condition → []metav1.Condition
  - MHC: restructured Checks/Remediation fields
  - MachineDeploymentComplete rewritten for v1beta2 native fields
  - MachinePhaseFailed (deprecated) → MachinePhaseDeleting
  - machineConditionResult expectations: corev1 → metav1 ConditionStatus
  - Constants renamed with V1Beta1 suffix
  - Fix bare v1beta2 import and misleading alias in e2e tests

Signed-off-by: Borja Clemente <bclement@redhat.com>
Update vendored dependencies after updating clients.

Signed-off-by: Borja Clemente <bclement@redhat.com>
The MD complete check was wrongly assuming that when ObservedGeneration
is up to date, replica counters are always correct, which is not true,
as is confirmed in
kubernetes-sigs/cluster-api#13738.

To guard against old Machines producing false positives a check is added
to make sure that old MachineSets have no replicas.

Signed-off-by: Borja Clemente <bclement@redhat.com>
@csrwng

csrwng commented Sep 8, 2026

Copy link
Copy Markdown
Contributor

/lgtm

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

Scheduling tests matching the pipeline_run_if_changed or not excluded by pipeline_skip_if_only_changed parameters:
/test e2e-aks-5-0
/test e2e-aws-5-0
/test e2e-aks
/test e2e-aws
/test e2e-aws-upgrade-hypershift-operator
/test e2e-kubevirt-aws-ovn-reduced
/test e2e-v2-aws
/test e2e-v2-azure-self-managed
/test e2e-v2-gke

@csrwng

csrwng commented Sep 8, 2026

Copy link
Copy Markdown
Contributor

/retest

@clebs

clebs commented Sep 9, 2026

Copy link
Copy Markdown
Member Author

/verified by @clebs and e2e tests.

All Cluster, Machine and Node creation/upgrade behaviors unchanged.

@openshift-ci-robot

Copy link
Copy Markdown

@clebs: This PR has been marked as verified by @clebs and e2e tests..

Details

In response to this:

/verified by @clebs and e2e tests.

All Cluster, Machine and Node creation/upgrade behaviors unchanged.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@clebs

clebs commented Sep 9, 2026

Copy link
Copy Markdown
Member Author

/retest

@openshift-ci

openshift-ci Bot commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

@clebs: all tests passed!

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

This branch was successfully deployed

1 active deployment
docs-preview/pr-8717 — 2b10bf74 Deployed Sep 8, 2026 by github-actions[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. area/api Indicates the PR includes changes for the API area/cli Indicates the PR includes changes for CLI area/control-plane-operator Indicates the PR includes changes for the control plane operator - in an OCP release area/documentation Indicates the PR includes changes for documentation area/hypershift-operator Indicates the PR includes changes for the hypershift operator and API - outside an OCP release area/karpenter-operator Indicates the PR includes changes related to the Karpenter operator area/platform/aws PR/issue for AWS (AWSPlatform) platform area/platform/azure PR/issue for Azure (AzurePlatform) platform area/platform/gcp PR/issue for GCP (GCPPlatform) platform area/platform/ibmcloud PR/issue for IBMCloud (IBMCloudPlatform) platform area/platform/kubevirt PR/issue for KubeVirt (KubevirtPlatform) platform area/platform/openstack PR/issue for OpenStack (OpenStackPlatform) platform area/platform/powervs PR/issue for PowerVS (PowerVSPlatform) platform area/testing Indicates the PR includes changes for e2e testing jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. lgtm Indicates that a PR is ready to be merged. verified Signifies that the PR passed pre-merge verification criteria

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants