Skip to content

Bug 1972009: Implementing CredentialStoreFactory - #1109

Merged
openshift-merge-robot merged 3 commits into
openshift:masterfrom
ricardomaraschini:credential-store-factory
Aug 26, 2021
Merged

openshift-merge-robot merged 3 commits into
openshift:masterfrom
ricardomaraschini:credential-store-factory

Conversation

@ricardomaraschini

@ricardomaraschini ricardomaraschini commented Jun 14, 2021 •

Copy link
Copy Markdown
Contributor

Registry client supports Alternates (mirrors) since #1084. As mirrors most likely use different credentials to authenticate we need a way of getting these mirror credentials based in the image path.

@openshift-ci openshift-ci Bot added the do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. label Jun 14, 2021
@openshift-ci
openshift-ci Bot requested review from deads2k and sttts June 14, 2021 09:03
When fetching an image we may need to use different authentications as,
in some cases, we are accessing mirrors instead of the original repo.
@ricardomaraschini

Copy link
Copy Markdown
Contributor Author

/assign @dmage

Could you please take an initial look into this one?

@ricardomaraschini ricardomaraschini changed the title WIP - Implementing CredentialStoreFactory Implementing CredentialStoreFactory Jun 15, 2021
@openshift-ci openshift-ci Bot removed the do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. label Jun 15, 2021
creds := c.Credentials
if c.CredentialsFactory != nil {
creds = c.CredentialsFactory.CredentialStoreFor(ref.AsRepository().String())
}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

you need to rework cachedTransports so that it respects new credentials

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I don't think I need to refactor it. Scopes (repository and operation) and the registry host are taken into account when evaluating if we are going to reuse or not a transport. In any case I have developed an unit test where I assure we are trying the right authentications even when mirror from one repository into another inside the same registry. Is there any corner case you see this failing? ptal.

Assure we are not reusing the same transport when fetching two distinct
repositories inside the same registry.
@ricardomaraschini ricardomaraschini changed the title Implementing CredentialStoreFactory Bug 1972009: Implementing CredentialStoreFactory Jun 18, 2021
@openshift-ci openshift-ci Bot added the bugzilla/severity-medium Referenced Bugzilla bug's severity is medium for the branch this PR is targeting. label Jun 18, 2021
@openshift-ci

openshift-ci Bot commented Jun 18, 2021

Copy link
Copy Markdown
Contributor

@ricardomaraschini: This pull request references Bugzilla bug 1972009, which is valid. The bug has been moved to the POST state. The bug has been updated to refer to the pull request using the external bug tracker.

3 validation(s) were run on this bug
  • bug is open, matching expected state (open)
  • bug target release (4.9.0) matches configured target release for branch (4.9.0)
  • bug is in the state NEW, which is one of the valid states (NEW, ASSIGNED, ON_DEV, POST, POST)

Requesting review from QA contact:
/cc @wzheng1

Details

In response to this:

Bug 1972009: Implementing CredentialStoreFactory

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

@openshift-ci openshift-ci Bot added the bugzilla/valid-bug Indicates that a referenced Bugzilla bug is valid for the branch this PR is targeting. label Jun 18, 2021
@openshift-ci
openshift-ci Bot requested a review from wzheng1 June 18, 2021 08:31
@dmage

dmage commented Aug 26, 2021

Copy link
Copy Markdown
Contributor

/lgtm
/assign @sttts

@openshift-ci openshift-ci Bot added the lgtm Indicates that a PR is ready to be merged. label Aug 26, 2021
@sttts

sttts commented Aug 26, 2021

Copy link
Copy Markdown
Contributor

/approved

@dmage

dmage commented Aug 26, 2021

Copy link
Copy Markdown
Contributor

@sttts you have a typo in the command

@sttts

sttts commented Aug 26, 2021

Copy link
Copy Markdown
Contributor

/approve

@openshift-ci

openshift-ci Bot commented Aug 26, 2021

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: dmage, ricardomaraschini, sttts

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci openshift-ci Bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Aug 26, 2021
@openshift-merge-robot
openshift-merge-robot merged commit cc316ba into openshift:master Aug 26, 2021
@openshift-ci

openshift-ci Bot commented Aug 26, 2021

Copy link
Copy Markdown
Contributor

@ricardomaraschini: Some pull requests linked via external trackers have merged:

The following pull requests linked via external trackers have not merged:

These pull request must merge or be unlinked from the Bugzilla bug in order for it to move to the next state. Once unlinked, request a bug refresh with /bugzilla refresh.

Bugzilla bug 1972009 has not been moved to the MODIFIED state.

Details

In response to this:

Bug 1972009: Implementing CredentialStoreFactory

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

@dmage

dmage commented Oct 8, 2021

Copy link
Copy Markdown
Contributor

/cherrypick release-4.8

@openshift-cherrypick-robot

Copy link
Copy Markdown

@dmage: new pull request created: #1225

Details

In response to this:

/cherrypick release-4.8

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. bugzilla/severity-medium Referenced Bugzilla bug's severity is medium for the branch this PR is targeting. bugzilla/valid-bug Indicates that a referenced Bugzilla bug is valid for the branch this PR is targeting. lgtm Indicates that a PR is ready to be merged.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants