[OCPNODE-553] Add CRD ImageDigestMirrorSet,ImageTagMirrorSet - #3037
Conversation
|
Skipping CI for Draft Pull Request. |
9186155 to
7a3a7d7
Compare
mtrmac
left a comment
There was a problem hiding this comment.
Just an initial pass (I didn’t actually read the added tests).
f2890e4 to
c59bf15
Compare
|
/retest |
|
@yuqi-zhang @mtrmac This PR and dependent PR: openshift/runtime-utils#15 will update the registry.conf. And the runtime-utils PR replaced machine-config-operator/pkg/daemon/drain.go Lines 178 to 187 in be77042 Not sure how the safe conditions are defined, but looking at https://bugzilla.redhat.com/show_bug.cgi?id=1943315#c1, we could propose the following as safe? // Currently, we consider following container registry config changes as safe to skip node drain:
// 1. A new mirror is added to an existing registry that has per-mirror setting `pull-from-mirror=digest-only` or registry level setting `mirror-by-digest-only=true`
// 2. A new registry has been added that has `mirror-by-digest-only=true` or per-mirror setting `pull-from-mirror=digest-only` for all of its mirrors |
|
@QiWang19: PR needs rebase. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
mtrmac
left a comment
There was a problem hiding this comment.
LGTM overall. (FWIW the PR doesn’t currently compile).
|
/lgtm again , at least based on the relevant parts of the diff being the same… |
|
/lgtm |
|
/lgtm |
|
@yuqi-zhang could the MCO team review and approve this PR? It is ready to get in. |
yuqi-zhang
left a comment
There was a problem hiding this comment.
Did a first pass with some question/comments below
Also, the MCO team is doing pre-merge QE testing for 4.13. Is node team doing pre-merge QE testing? Would someone from node QE be able to verify this new feature and apply QE approval?
There was a problem hiding this comment.
To be clear, this doesn't actually test any pulling, it just checks if ICSP sets up the correct conf?
Would we want to instead test IDSM/ITMS since that's (I assume) the preferred way?
There was a problem hiding this comment.
This is just to test the ICSP can still work with the addition of new CRDs, before we deprecate the ICSP.
yes, we can add some tests for IDSM/ITMS.
There was a problem hiding this comment.
would we want to keep the old conditionals? It is possible that someone with a hand-crafted registries.conf could be still using the old method
Or, are we saying that we don't support that, and there isn't any way for ICSP to generate the old style mirror flags anymore?
There was a problem hiding this comment.
Add some unit test cases with mirror-by-digest-only for the old style. ICSP will no longer generate this old style, but it is still supported when there are hand-crafted registries.conf.
yuqi-zhang
left a comment
There was a problem hiding this comment.
I think this generally makes sense to me, approving, thanks for working on this!
Also going to add a
/hold
for QE pre-merge testing and QE approval.
Doesn't have to be part of this PR, but could you provide some docs on how to use IDMS/ITMS? Or maybe some links to other docs are fine as well, thanks!
There was a problem hiding this comment.
Hmm, does this actually change anything? Just curious
There was a problem hiding this comment.
These files are also used in the e2e test. To fix the error I saw in the ci e2e test that is image repository name must be lowercase.
|
/retest-required |
|
/lgtm @QiWang19 Please remove the hold when ready. |
|
/label qe-approved |
@yuqi-zhang This passed the QE approval label. Could you merge this? |
|
/hold cancel |
|
/retest-required Remaining retests: 0 against base HEAD fc27a2b and 2 for PR HEAD 73e22c3cc054f6a89f55ac48704ebc7cc523e35f in total |
|
gcp-op may require a rebase to master which has some e2e test fixes |
Signed-off-by: Qi Wang <qiwan@redhat.com>
Signed-off-by: Qi Wang <qiwan@redhat.com>
https://storage.googleapis.com/origin-ci-test/pr-logs/pull/openshift_machine-config-operator/3037/pull-ci-openshift-machine-config-operator-master-e2e-gcp-op/1615814135679815680/build-log.txt the |
|
/retest-required |
|
@yuqi-zhang could you retag lgtm? |
|
/lgtm |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: mtrmac, QiWang19, rphillips, yuqi-zhang The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
|
/retest-required |
|
@QiWang19: The following tests failed, say
Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. I understand the commands that are listed here. |
|
@yuqi-zhang can we skip the tests? |
|
Only Or did you mean you wanted me to override e2e-aws-ovn? |
|
Yes, override e2e-aws-ovn. The e2e-aws-ovn was retested several times and failed. Can we override it? |
|
The latest commit did have a passing run: https://prow.ci.openshift.org/pr-history/?org=openshift&repo=machine-config-operator&pr=3037 So I think it's most likely ok. Still, I am uncomfortable overriding a required job unless the fix is urgent or directly attributed to it. Let's wait until the end of today, and, if there are no passes, I can look to override |
- What I did
Close card: https://issues.redhat.com/browse/OCPNODE-553
Epic: https://issues.redhat.com/browse/OCPNODE-521
Dependent PR: openshift/runtime-utils#15
- How to verify it
Apply following CR, check the /etc/containers/registries.conf
/etc/containers/registries.conf
- Description for the changelog
Add support for ImageDigestMirrorSet,ImageDigestMirrorSet CRDs