Skip to content

CNTRLPLANE-3434: hypershift-install: add OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE parameter - #81877

Merged
openshift-merge-bot[bot] merged 5 commits into
openshift:mainfrom
Nirshal:hypershift-install-override-image
Jul 16, 2026
Merged

openshift-merge-bot[bot] merged 5 commits into
openshift:mainfrom
Nirshal:hypershift-install-override-image

Conversation

@Nirshal

@Nirshal Nirshal commented Jul 14, 2026 •

Copy link
Copy Markdown
Contributor

What

Adds a new OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE step parameter to the hypershift-install ref that allows callers to override both the HyperShift Operator image and the hcp CLI binary used during installation.

Why

ci-operator's OVERRIDE_IMAGE_* env var mechanism has a race condition when the same tag exists in base_images: both the override and the base_images import create concurrent InputImageTagStep nodes targeting the same pipeline ImageStream tag. Since ImageStreamTag create is an upsert and the base_images step finishes last (it calls resolveOfficialImport which makes API calls, while the override has the pullspec ready), the override is silently discarded. The --dependency-override-param CLI flag would work, but Gangway only supports env vars in the payload, not CLI arguments.

This new parameter bypasses the pipeline ImageStream entirely: the image pullspec is passed directly from the Gangway payload to the install script, avoiding the race condition.

Gangway transport workaround

ci-operator does not strip the MULTISTAGE_PARAM_OVERRIDE_ prefix when injecting env vars into step pods. The step receives the full variable name as-is. This is the same behavior used by hypershift-mce-install (see MULTISTAGE_PARAM_OVERRIDE_OVERRIDE_HO_IMAGE / MULTISTAGE_PARAM_OVERRIDE_MCE_VERSION in that step).

To support Gangway callers (e.g. the HO release controller), the ref YAML declares both:

  • OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE (for direct use in job configs)
  • MULTISTAGE_PARAM_OVERRIDE_OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE (Gangway transport)

The script copies the prefixed variable into the unprefixed one at startup, before any override logic runs.

What changed

hypershift-install-ref.yaml:

  • Added OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE parameter (default: empty)
  • Added MULTISTAGE_PARAM_OVERRIDE_OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE transport parameter (default: empty)

hypershift-install-commands.sh:

  • Extracted duplicated CLI extraction logic into extract_hcp_cli() function using mktemp -d (CWE-377)
  • Added Gangway transport: copies MULTISTAGE_PARAM_OVERRIDE_OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE into OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE at startup
  • Added OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE as the highest-priority branch in the existing if/elif chain (before HO_MULTI and INSTALL_FROM_LATEST)
  • When set, overrides both OPERATOR_IMAGE and extracts the hcp CLI from the same image to avoid version skew
  • Added WARNING log lines to all override paths for better observability
  • Added precedence warning when multiple override flags are set simultaneously
  • Fixed set -e compatibility: replaced [[ ]] && ((COUNT++)) with if/then/fi and arithmetic assignment (the ((0++)) expression returns exit code 1 under bash 4.x/5.x, killing the script)
  • Added --confirm to oc image extract (temp dir is non-empty after pull-secret extraction)

How to use

In a Gangway payload:

{
  "job_name": "periodic-ci-openshift-hypershift-release-5.0-periodics-e2e-aks",
  "pod_spec_options": {
    "envs": {
      "MULTISTAGE_PARAM_OVERRIDE_OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE": "quay.io/my-repo/hypershift-operator@sha256:abc123..."
    }
  }
}

Or in a job config:

env:
  OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE: "quay.io/my-repo/hypershift-operator@sha256:abc123..."

Impact

  • No behavioral change for existing jobs: the parameter defaults to empty and the if branch is skipped
  • HO_MULTI and INSTALL_FROM_LATEST behavior is preserved (refactored, not changed)
  • New WARNING log lines are informational only

Summary by CodeRabbit

  • Updates the hypershift-install step registry (ci-operator/step-registry/hypershift/install) to add a new OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE parameter (default empty) that lets job authors provide an Operator image pullspec directly, bypassing pipeline ImageStream dependency resolution and avoiding an OVERRIDE_IMAGE_* race with base_images.
  • Adds a companion transport parameter MULTISTAGE_PARAM_OVERRIDE_OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE; at runtime the step copies it into OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE so Gangway-style MULTISTAGE_PARAM_OVERRIDE_ wiring works as intended.
  • Refactors the install script to use the effective image override consistently: when OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE is set, it’s used for both the HyperShift Operator and the hcp CLI by extracting linux/amd64 hypershift from that image and setting HCP_CLI to the extracted binary path.
  • Introduces precedence-aware operator-image selection across OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE, HO_MULTI, and INSTALL_FROM_LATEST, including warning logs when multiple are enabled (override image > HO_MULTI > INSTALL_FROM_LATEST), while preserving the prior behavior when no override is specified.

…meter

OVERRIDE_IMAGE_HYPERSHIFT_OPERATOR (ci-operator's env var mechanism) has
a race condition: both the override and the base_images step write to
the same pipeline ImageStream tag concurrently. Since IST Create is an
upsert, the base_images step consistently wins because it finishes last
(resolveOfficialImport makes API calls, the override does not). The
override is silently discarded.

--dependency-override-param would work, but Gangway only supports env
vars in the payload, not CLI arguments.

This commit adds OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE as a step parameter
that bypasses the pipeline ImageStream entirely. When set, the script
overrides both the operator image (--hypershift-image) and the hcp CLI
binary, extracting it from the same image to avoid version skew.

Also refactors the existing HO_MULTI and INSTALL_FROM_LATEST branches
into a shared extract_hcp_cli() function and adds WARNING log lines to
all override paths for better observability.

Ref: CNTRLPLANE-3434

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@openshift-ci-robot openshift-ci-robot added the jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. label Jul 14, 2026
@openshift-ci-robot

openshift-ci-robot commented Jul 14, 2026 •

Copy link
Copy Markdown
Contributor

@Nirshal: This pull request references CNTRLPLANE-3434 which is a valid jira issue.

Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the epic to target the "5.0.0" version, but no target version was set.

Details

In response to this:

What

Adds a new OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE step parameter to the hypershift-install ref that allows callers to override both the HyperShift Operator image and the hcp CLI binary used during installation.

Why

ci-operator's OVERRIDE_IMAGE_* env var mechanism has a race condition when the same tag exists in base_images: both the override and the base_images import create concurrent InputImageTagStep nodes targeting the same pipeline ImageStream tag. Since ImageStreamTag create is an upsert and the base_images step finishes last (it calls resolveOfficialImport which makes API calls, while the override has the pullspec ready), the override is silently discarded. The --dependency-override-param CLI flag would work, but Gangway only supports env vars in the payload, not CLI arguments.

This new parameter bypasses the pipeline ImageStream entirely: the image pullspec is passed directly from the Gangway payload to the install script via MULTISTAGE_PARAM_OVERRIDE_OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE, avoiding the race condition.

What changed

hypershift-install-ref.yaml:

  • Added OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE parameter (default: empty)

hypershift-install-commands.sh:

  • Extracted duplicated CLI extraction logic into extract_hcp_cli() function
  • Added OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE as the highest-priority branch in the existing if/elif chain (before HO_MULTI and INSTALL_FROM_LATEST)
  • When set, overrides both OPERATOR_IMAGE and extracts the hcp CLI from the same image to avoid version skew
  • Added WARNING log lines to all override paths (OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE, HO_MULTI, INSTALL_FROM_LATEST) for better observability in build logs

How to use

In a Gangway payload:

{
 "job_name": "periodic-ci-openshift-hypershift-release-5.0-periodics-e2e-aks",
 "pod_spec_options": {
   "envs": {
     "MULTISTAGE_PARAM_OVERRIDE_OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE": "quay.io/my-repo/hypershift-operator@sha256:abc123..."
   }
 }
}

Or in a job config:

env:
 OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE: "quay.io/my-repo/hypershift-operator@sha256:abc123..."

Impact

  • No behavioral change for existing jobs: the parameter defaults to empty and the if branch is skipped
  • HO_MULTI and INSTALL_FROM_LATEST behavior is preserved (refactored, not changed)
  • New WARNING log lines are informational only

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@coderabbitai

coderabbitai Bot commented Jul 14, 2026 •

Copy link
Copy Markdown
Contributor

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

Walkthrough

HyperShift installation centralizes CLI extraction in a helper and adds precedence-aware selection for an optional operator image override. The step registry declares the override and its multistage transport variable.

Changes

HyperShift installation image selection

Layer / File(s) Summary
Override configuration and precedence
ci-operator/step-registry/hypershift/install/hypershift-install-ref.yaml, ci-operator/step-registry/hypershift/install/hypershift-install-commands.sh
Declares the operator image override, forwards its multistage value, counts active installation modes, and applies override > HO_MULTI > install-from-latest precedence.
CLI extraction and install wiring
ci-operator/step-registry/hypershift/install/hypershift-install-commands.sh
Extracts the pull-secret and linux/amd64 HyperShift binary from the selected image, makes it executable, and assigns its path to HCP_CLI.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Sequence Diagram(s)

sequenceDiagram
  participant InstallConfig
  participant InstallScript
  participant OperatorImage
  InstallConfig->>InstallScript: provide image override or install mode
  InstallScript->>InstallScript: resolve effective operator image
  InstallScript->>OperatorImage: extract pull-secret and linux/amd64 hypershift
  OperatorImage-->>InstallScript: return hypershift binary
  InstallScript->>InstallScript: set HCP_CLI
Loading

Suggested reviewers: mgencur, enxebre


Important

Pre-merge checks failed

Please resolve all errors before merging. Addressing warnings is optional.

❌ Failed checks (1 error)

Check name Status Explanation Resolution
No-Sensitive-Data-In-Logs ❌ Error New WARNING logs print raw image pullspecs, including OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE, which can expose private registry hostnames or repo paths. Avoid logging full pullspecs; use generic warnings or redact registry/repo values, and suppress shell xtrace around sensitive args if needed.
✅ Passed checks (14 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Stable And Deterministic Test Names ✅ Passed PR only changes a shell script and YAML; no Ginkgo test titles (It/Describe/Context/When) were added or modified.
Test Structure And Quality ✅ Passed PR only touches hypershift-install shell/YAML; no Ginkgo test files were modified, so the test-quality checklist is not applicable.
Microshift Test Compatibility ✅ Passed No new Ginkgo e2e tests were added; the PR only changes a shell script and step YAML, with no MicroShift-incompatible APIs or resources introduced.
Single Node Openshift (Sno) Test Compatibility ✅ Passed No Ginkgo e2e tests were added; the PR only changes a shell step and YAML parameters, so SNO test compatibility is not implicated.
Topology-Aware Scheduling Compatibility ✅ Passed Only a CI step script and ref YAML changed; no manifests/controllers, no node selectors, affinity, spread, replica, or topology-dependent scheduling logic.
Ote Binary Stdout Contract ✅ Passed Only a shell step script and YAML changed; no OTE binary main/init/TestMain code or stdout contract issue is present.
Ipv6 And Disconnected Network Test Compatibility ✅ Passed No new Ginkgo e2e tests were added; the diff only changes install script/YAML and contains no IPv4-only assertions or test connectivity logic.
No-Weak-Crypto ✅ Passed The changed shell/YAML only add image-override logic and pull-secret handling; no weak algorithms, custom crypto, or secret/token comparisons appear.
Container-Privileges ✅ Passed Changed files only add env/ref and shell logic; no privileged, host* or allowPrivilegeEscalation settings were introduced.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly describes the main change: adding the OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE parameter to hypershift-install.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Comment @coderabbitai help to get the list of available commands.

@openshift-ci
openshift-ci Bot requested review from enxebre and mgencur July 14, 2026 15:03

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@ci-operator/step-registry/hypershift/install/hypershift-install-commands.sh`:
- Around line 18-23: Update the override warning in the hypershift install
command flow to report the effective baseline image selected by the same
HO_MULTI rules as the no-override path, rather than always labeling
HYPERSHIFT_RELEASE_LATEST as the default. Keep the override assignment and
extract_hcp_cli behavior unchanged.
- Around line 11-15: Update the installation flow around the oc extract, oc
image extract, chmod, and HCP_CLI assignments to create a private unpredictable
temporary directory with mktemp -d, use it for both pull-secret extraction and
the hypershift CLI extraction, and reference the resulting paths instead of /tmp
locations. Add cleanup of the temporary directory after installation while
preserving HCP_CLI usability.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Central YAML (inherited)

Review profile: CHILL

Plan: Enterprise

Run ID: fe60077d-1eed-45e2-a779-4a5e9c5e97c9

📥 Commits

Reviewing files that changed from the base of the PR and between 334c674 and 1f0b907.

📒 Files selected for processing (2)
  • ci-operator/step-registry/hypershift/install/hypershift-install-commands.sh
  • ci-operator/step-registry/hypershift/install/hypershift-install-ref.yaml

Comment thread ci-operator/step-registry/hypershift/install/hypershift-install-commands.sh Outdated
…nflicting overrides

Address CodeRabbit review feedback:

1. Replace hardcoded /tmp/hs-cli with mktemp -d to avoid predictable
   temporary paths in the extract_hcp_cli function (CWE-377).

2. Add precedence warning when multiple image override flags are set
   simultaneously (OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE, HO_MULTI,
   INSTALL_FROM_LATEST). Logs the priority order so operators can
   understand which override takes effect without inspecting the script.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@Nirshal

Nirshal commented Jul 14, 2026

Copy link
Copy Markdown
Contributor Author

/pj-rehearse pull-ci-openshift-hypershift-main-e2e-aks pull-ci-openshift-hypershift-main-e2e-aws pull-ci-openshift-hypershift-main-e2e-azure-v2-self-managed periodic-ci-openshift-hypershift-release-5.0-periodics-e2e-aks-multi-x-ax pull-ci-openshift-hypershift-main-e2e-aws-upgrade-hypershift-operator

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

@Nirshal: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel.

…ERRIDE_COUNT

The previous `[[ ]] && ((OVERRIDE_COUNT++))` pattern caused the script
to exit under `set -eux` on bash 4.x/5.x (RHEL CI containers).

`((expr))` returns exit code 1 when the expression evaluates to 0.
With post-increment (`OVERRIDE_COUNT++`), the first increment from 0
evaluates to 0 (pre-increment value), triggering `set -e` termination.

Replace with explicit `if/then/fi` blocks (exempt from `set -e`) and
`OVERRIDE_COUNT=$((OVERRIDE_COUNT + 1))` (assignment, always exit 0).

Confirmed failure in rehearsal job:
  rehearse-81877-pull-ci-openshift-hypershift-main-e2e-aws-upgrade-hypershift-operator

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@Nirshal

Nirshal commented Jul 15, 2026

Copy link
Copy Markdown
Contributor Author

/pj-rehearse pull-ci-openshift-hypershift-main-e2e-aks pull-ci-openshift-hypershift-main-e2e-aws pull-ci-openshift-hypershift-main-e2e-azure-v2-self-managed periodic-ci-openshift-hypershift-release-5.0-periodics-e2e-aks-multi-x-ax pull-ci-openshift-hypershift-main-e2e-aws-upgrade-hypershift-operator

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

@Nirshal: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel.

…_hcp_cli

The mktemp-based temp directory (introduced for CWE-377) is no longer
empty when oc image extract runs, because oc extract already wrote
.dockerconfigjson to it. Without --confirm, oc image extract refuses
to write to a non-empty directory.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@Nirshal

Nirshal commented Jul 15, 2026

Copy link
Copy Markdown
Contributor Author

/pj-rehearse pull-ci-openshift-hypershift-main-e2e-aks pull-ci-openshift-hypershift-main-e2e-aws pull-ci-openshift-hypershift-main-e2e-azure-v2-self-managed periodic-ci-openshift-hypershift-release-5.0-periodics-e2e-aks-multi-x-ax pull-ci-openshift-hypershift-main-e2e-aws-upgrade-hypershift-operator

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

@Nirshal: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel.

@Nirshal

Nirshal commented Jul 15, 2026

Copy link
Copy Markdown
Contributor Author

/pj-rehearse pull-ci-openshift-hypershift-main-e2e-aws pull-ci-openshift-hypershift-main-e2e-aks

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

@Nirshal: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel.

@Nirshal

Nirshal commented Jul 16, 2026

Copy link
Copy Markdown
Contributor Author

/pj-rehearse pull-ci-openshift-hypershift-main-e2e-aks

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

@Nirshal: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel.

@bryan-cox

Copy link
Copy Markdown
Member

/pj-rehearse ack

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

@bryan-cox: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel.

@openshift-merge-bot openshift-merge-bot Bot added the rehearsals-ack Signifies that rehearsal jobs have been acknowledged label Jul 16, 2026
@openshift-ci openshift-ci Bot added lgtm Indicates that a PR is ready to be merged. approved Indicates a PR has been approved by an approver from all required OWNERS files. labels Jul 16, 2026
…se controller

Gangway does not strip the MULTISTAGE_PARAM_OVERRIDE_ prefix when
injecting env vars into step pods. Add the prefixed parameter
MULTISTAGE_PARAM_OVERRIDE_OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE to the
ref YAML and copy its value into OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE
at runtime, following the same pattern used by hypershift-mce-install.

This enables the HO release controller to override the operator image
via Gangway without hitting the ci-operator ImageStream race condition
(OVERRIDE_IMAGE_* mechanism).

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@openshift-ci openshift-ci Bot removed the lgtm Indicates that a PR is ready to be merged. label Jul 16, 2026
@openshift-merge-bot openshift-merge-bot Bot removed the rehearsals-ack Signifies that rehearsal jobs have been acknowledged label Jul 16, 2026
@openshift-merge-bot

Copy link
Copy Markdown
Contributor

[REHEARSALNOTIFIER]
@Nirshal: the pj-rehearse plugin accommodates running rehearsal tests for the changes in this PR. Expand 'Interacting with pj-rehearse' for usage details. The following rehearsable tests have been affected by this change:

Test name Repo Type Reason
pull-ci-openshift-openstack-resource-controller-main-e2e-hypershift openshift/openstack-resource-controller presubmit Registry content changed
pull-ci-openshift-openstack-resource-controller-release-5.1-e2e-hypershift openshift/openstack-resource-controller presubmit Registry content changed
pull-ci-openshift-openstack-resource-controller-release-5.0-e2e-hypershift openshift/openstack-resource-controller presubmit Registry content changed
pull-ci-openshift-openstack-resource-controller-release-4.23-e2e-hypershift openshift/openstack-resource-controller presubmit Registry content changed
pull-ci-openshift-openstack-resource-controller-release-4.22-e2e-hypershift openshift/openstack-resource-controller presubmit Registry content changed
pull-ci-openshift-openstack-resource-controller-release-4.21-e2e-hypershift openshift/openstack-resource-controller presubmit Registry content changed
pull-ci-openshift-openstack-resource-controller-release-4.20-e2e-hypershift openshift/openstack-resource-controller presubmit Registry content changed
pull-ci-openshift-openstack-resource-controller-release-4.19-e2e-hypershift openshift/openstack-resource-controller presubmit Registry content changed
pull-ci-openshift-cluster-api-provider-azure-main-hypershift-e2e-aks openshift/cluster-api-provider-azure presubmit Registry content changed
pull-ci-openshift-cluster-api-provider-azure-release-5.1-hypershift-e2e-aks openshift/cluster-api-provider-azure presubmit Registry content changed
pull-ci-openshift-cluster-api-provider-azure-release-5.0-hypershift-e2e-aks openshift/cluster-api-provider-azure presubmit Registry content changed
pull-ci-openshift-cluster-api-provider-azure-release-4.23-hypershift-e2e-aks openshift/cluster-api-provider-azure presubmit Registry content changed
pull-ci-openshift-cluster-api-provider-azure-release-4.22-hypershift-e2e-aks openshift/cluster-api-provider-azure presubmit Registry content changed
pull-ci-openshift-cluster-api-provider-azure-release-4.21-hypershift-e2e-aks openshift/cluster-api-provider-azure presubmit Registry content changed
pull-ci-openshift-cluster-api-provider-azure-release-4.20-hypershift-e2e-aks openshift/cluster-api-provider-azure presubmit Registry content changed
pull-ci-openshift-cluster-api-provider-azure-release-4.19-hypershift-e2e-aks openshift/cluster-api-provider-azure presubmit Registry content changed
pull-ci-openshift-cluster-machine-approver-main-e2e-hypershift-aks openshift/cluster-machine-approver presubmit Registry content changed
pull-ci-openshift-cluster-machine-approver-release-5.1-e2e-hypershift-aks openshift/cluster-machine-approver presubmit Registry content changed
pull-ci-openshift-cluster-machine-approver-release-5.0-e2e-hypershift-aks openshift/cluster-machine-approver presubmit Registry content changed
pull-ci-openshift-cluster-machine-approver-release-4.23-e2e-hypershift-aks openshift/cluster-machine-approver presubmit Registry content changed
pull-ci-openshift-cluster-machine-approver-release-4.22-e2e-hypershift-aks openshift/cluster-machine-approver presubmit Registry content changed
pull-ci-openshift-cluster-api-provider-kubevirt-main-e2e-hypershift-kubevirt openshift/cluster-api-provider-kubevirt presubmit Registry content changed
pull-ci-openshift-cluster-api-provider-kubevirt-release-5.1-e2e-hypershift-kubevirt openshift/cluster-api-provider-kubevirt presubmit Registry content changed
pull-ci-openshift-cluster-api-provider-kubevirt-release-5.0-e2e-hypershift-kubevirt openshift/cluster-api-provider-kubevirt presubmit Registry content changed
pull-ci-openshift-cluster-api-provider-kubevirt-release-4.23-e2e-hypershift-kubevirt openshift/cluster-api-provider-kubevirt presubmit Registry content changed

A total of 605 jobs have been affected by this change. The above listing is non-exhaustive and limited to 25 jobs.

A full list of affected jobs can be found here

Interacting with pj-rehearse

Comment: /pj-rehearse to run up to 5 rehearsals
Comment: /pj-rehearse skip to opt-out of rehearsals
Comment: /pj-rehearse {test-name}, with each test separated by a space, to run one or more specific rehearsals
Comment: /pj-rehearse more to run up to 10 rehearsals
Comment: /pj-rehearse max to run up to 25 rehearsals
Comment: /pj-rehearse auto-ack to run up to 5 rehearsals, and add the rehearsals-ack label on success
Comment: /pj-rehearse list to get an up-to-date list of affected jobs
Comment: /pj-rehearse abort to abort all active rehearsals
Comment: /pj-rehearse network-access-allowed to allow rehearsals of tests that have the restrict_network_access field set to false. This must be executed by an openshift org member who is not the PR author

Once you are satisfied with the results of the rehearsals, comment: /pj-rehearse ack to unblock merge. When the rehearsals-ack label is present on your PR, merge will no longer be blocked by rehearsals.
If you would like the rehearsals-ack label removed, comment: /pj-rehearse reject to re-block merging.

@bryan-cox

Copy link
Copy Markdown
Member

/lgtm

@openshift-ci

openshift-ci Bot commented Jul 16, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: bryan-cox, Nirshal

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci openshift-ci Bot added the lgtm Indicates that a PR is ready to be merged. label Jul 16, 2026
@bryan-cox

Copy link
Copy Markdown
Member

/pj-rehearse ack

We verified several tests before Alessandro's latest push that just changes the gangway override

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

@bryan-cox: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel.

@openshift-merge-bot openshift-merge-bot Bot added the rehearsals-ack Signifies that rehearsal jobs have been acknowledged label Jul 16, 2026
Nirshal added a commit to Nirshal/hypershift that referenced this pull request Jul 16, 2026
Switch from OVERRIDE_IMAGE_HYPERSHIFT_OPERATOR (ci-operator ImageStream
mechanism, broken by race condition) to the MULTISTAGE_PARAM_OVERRIDE_
transport variable that passes the image directly to the hypershift-install
step parameter.

Requires openshift/release#81877 to be merged first.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@openshift-ci

openshift-ci Bot commented Jul 16, 2026

Copy link
Copy Markdown
Contributor

@Nirshal: all tests passed!

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

@openshift-merge-bot
openshift-merge-bot Bot merged commit 98c017b into openshift:main Jul 16, 2026
11 checks passed
SachinNinganure pushed a commit to SachinNinganure/release that referenced this pull request Jul 20, 2026
…_IMAGE parameter (openshift#81877)

* feat(hypershift-install): add OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE parameter

OVERRIDE_IMAGE_HYPERSHIFT_OPERATOR (ci-operator's env var mechanism) has
a race condition: both the override and the base_images step write to
the same pipeline ImageStream tag concurrently. Since IST Create is an
upsert, the base_images step consistently wins because it finishes last
(resolveOfficialImport makes API calls, the override does not). The
override is silently discarded.

--dependency-override-param would work, but Gangway only supports env
vars in the payload, not CLI arguments.

This commit adds OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE as a step parameter
that bypasses the pipeline ImageStream entirely. When set, the script
overrides both the operator image (--hypershift-image) and the hcp CLI
binary, extracting it from the same image to avoid version skew.

Also refactors the existing HO_MULTI and INSTALL_FROM_LATEST branches
into a shared extract_hcp_cli() function and adds WARNING log lines to
all override paths for better observability.

Ref: CNTRLPLANE-3434

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(hypershift-install): use mktemp for CLI extraction and warn on conflicting overrides

Address CodeRabbit review feedback:

1. Replace hardcoded /tmp/hs-cli with mktemp -d to avoid predictable
   temporary paths in the extract_hcp_cli function (CWE-377).

2. Add precedence warning when multiple image override flags are set
   simultaneously (OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE, HO_MULTI,
   INSTALL_FROM_LATEST). Logs the priority order so operators can
   understand which override takes effect without inspecting the script.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(hypershift-install): use if/then and arithmetic assignment for OVERRIDE_COUNT

The previous `[[ ]] && ((OVERRIDE_COUNT++))` pattern caused the script
to exit under `set -eux` on bash 4.x/5.x (RHEL CI containers).

`((expr))` returns exit code 1 when the expression evaluates to 0.
With post-increment (`OVERRIDE_COUNT++`), the first increment from 0
evaluates to 0 (pre-increment value), triggering `set -e` termination.

Replace with explicit `if/then/fi` blocks (exempt from `set -e`) and
`OVERRIDE_COUNT=$((OVERRIDE_COUNT + 1))` (assignment, always exit 0).

Confirmed failure in rehearsal job:
  rehearse-81877-pull-ci-openshift-hypershift-main-e2e-aws-upgrade-hypershift-operator

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(hypershift-install): add --confirm to oc image extract in extract_hcp_cli

The mktemp-based temp directory (introduced for CWE-377) is no longer
empty when oc image extract runs, because oc extract already wrote
.dockerconfigjson to it. Without --confirm, oc image extract refuses
to write to a non-empty directory.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* feat(hypershift-install): add Gangway transport variable for HO release controller

Gangway does not strip the MULTISTAGE_PARAM_OVERRIDE_ prefix when
injecting env vars into step pods. Add the prefixed parameter
MULTISTAGE_PARAM_OVERRIDE_OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE to the
ref YAML and copy its value into OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE
at runtime, following the same pattern used by hypershift-mce-install.

This enables the HO release controller to override the operator image
via Gangway without hitting the ci-operator ImageStream race condition
(OVERRIDE_IMAGE_* mechanism).

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
openshift-merge-bot Bot pushed a commit that referenced this pull request Jul 21, 2026
…tract_hcp_cli (#82061)

* fix(hypershift-install): use mounted CI pull secret in extract_hcp_cli

Follow-up fix for PR #81877 which introduced extract_hcp_cli.

The function used oc extract secret/pull-secret from the
openshift-config namespace to authenticate with container registries.
This fails on AKS clusters where openshift-config does not exist.

Switch to the mounted CI pull secret at
/etc/ci-pull-credentials/.dockerconfigjson, which is already used by
the hypershift install command itself for Azure, GCP, and default
cloud providers in the same script.

Signed-off-by: Alessandro Rossi <alesross@redhat.com>

* docs(hypershift-install): add HO release controller note to env doc

Trivial documentation update to trigger pj-rehearse detection.
pj-rehearse does not detect isolated script-only changes without
a corresponding ref YAML modification.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Signed-off-by: Alessandro Rossi <alesross@redhat.com>
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
fracappa pushed a commit to fracappa/release that referenced this pull request Jul 22, 2026
…_IMAGE parameter (openshift#81877)

* feat(hypershift-install): add OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE parameter

OVERRIDE_IMAGE_HYPERSHIFT_OPERATOR (ci-operator's env var mechanism) has
a race condition: both the override and the base_images step write to
the same pipeline ImageStream tag concurrently. Since IST Create is an
upsert, the base_images step consistently wins because it finishes last
(resolveOfficialImport makes API calls, the override does not). The
override is silently discarded.

--dependency-override-param would work, but Gangway only supports env
vars in the payload, not CLI arguments.

This commit adds OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE as a step parameter
that bypasses the pipeline ImageStream entirely. When set, the script
overrides both the operator image (--hypershift-image) and the hcp CLI
binary, extracting it from the same image to avoid version skew.

Also refactors the existing HO_MULTI and INSTALL_FROM_LATEST branches
into a shared extract_hcp_cli() function and adds WARNING log lines to
all override paths for better observability.

Ref: CNTRLPLANE-3434

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(hypershift-install): use mktemp for CLI extraction and warn on conflicting overrides

Address CodeRabbit review feedback:

1. Replace hardcoded /tmp/hs-cli with mktemp -d to avoid predictable
   temporary paths in the extract_hcp_cli function (CWE-377).

2. Add precedence warning when multiple image override flags are set
   simultaneously (OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE, HO_MULTI,
   INSTALL_FROM_LATEST). Logs the priority order so operators can
   understand which override takes effect without inspecting the script.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(hypershift-install): use if/then and arithmetic assignment for OVERRIDE_COUNT

The previous `[[ ]] && ((OVERRIDE_COUNT++))` pattern caused the script
to exit under `set -eux` on bash 4.x/5.x (RHEL CI containers).

`((expr))` returns exit code 1 when the expression evaluates to 0.
With post-increment (`OVERRIDE_COUNT++`), the first increment from 0
evaluates to 0 (pre-increment value), triggering `set -e` termination.

Replace with explicit `if/then/fi` blocks (exempt from `set -e`) and
`OVERRIDE_COUNT=$((OVERRIDE_COUNT + 1))` (assignment, always exit 0).

Confirmed failure in rehearsal job:
  rehearse-81877-pull-ci-openshift-hypershift-main-e2e-aws-upgrade-hypershift-operator

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(hypershift-install): add --confirm to oc image extract in extract_hcp_cli

The mktemp-based temp directory (introduced for CWE-377) is no longer
empty when oc image extract runs, because oc extract already wrote
.dockerconfigjson to it. Without --confirm, oc image extract refuses
to write to a non-empty directory.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* feat(hypershift-install): add Gangway transport variable for HO release controller

Gangway does not strip the MULTISTAGE_PARAM_OVERRIDE_ prefix when
injecting env vars into step pods. Add the prefixed parameter
MULTISTAGE_PARAM_OVERRIDE_OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE to the
ref YAML and copy its value into OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE
at runtime, following the same pattern used by hypershift-mce-install.

This enables the HO release controller to override the operator image
via Gangway without hitting the ci-operator ImageStream race condition
(OVERRIDE_IMAGE_* mechanism).

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
fracappa pushed a commit to fracappa/release that referenced this pull request Jul 22, 2026
…tract_hcp_cli (openshift#82061)

* fix(hypershift-install): use mounted CI pull secret in extract_hcp_cli

Follow-up fix for PR openshift#81877 which introduced extract_hcp_cli.

The function used oc extract secret/pull-secret from the
openshift-config namespace to authenticate with container registries.
This fails on AKS clusters where openshift-config does not exist.

Switch to the mounted CI pull secret at
/etc/ci-pull-credentials/.dockerconfigjson, which is already used by
the hypershift install command itself for Azure, GCP, and default
cloud providers in the same script.

Signed-off-by: Alessandro Rossi <alesross@redhat.com>

* docs(hypershift-install): add HO release controller note to env doc

Trivial documentation update to trigger pj-rehearse detection.
pj-rehearse does not detect isolated script-only changes without
a corresponding ref YAML modification.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Signed-off-by: Alessandro Rossi <alesross@redhat.com>
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
amogh-redhat pushed a commit to amogh-redhat/release that referenced this pull request Aug 5, 2026
…_IMAGE parameter (openshift#81877)

* feat(hypershift-install): add OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE parameter

OVERRIDE_IMAGE_HYPERSHIFT_OPERATOR (ci-operator's env var mechanism) has
a race condition: both the override and the base_images step write to
the same pipeline ImageStream tag concurrently. Since IST Create is an
upsert, the base_images step consistently wins because it finishes last
(resolveOfficialImport makes API calls, the override does not). The
override is silently discarded.

--dependency-override-param would work, but Gangway only supports env
vars in the payload, not CLI arguments.

This commit adds OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE as a step parameter
that bypasses the pipeline ImageStream entirely. When set, the script
overrides both the operator image (--hypershift-image) and the hcp CLI
binary, extracting it from the same image to avoid version skew.

Also refactors the existing HO_MULTI and INSTALL_FROM_LATEST branches
into a shared extract_hcp_cli() function and adds WARNING log lines to
all override paths for better observability.

Ref: CNTRLPLANE-3434

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(hypershift-install): use mktemp for CLI extraction and warn on conflicting overrides

Address CodeRabbit review feedback:

1. Replace hardcoded /tmp/hs-cli with mktemp -d to avoid predictable
   temporary paths in the extract_hcp_cli function (CWE-377).

2. Add precedence warning when multiple image override flags are set
   simultaneously (OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE, HO_MULTI,
   INSTALL_FROM_LATEST). Logs the priority order so operators can
   understand which override takes effect without inspecting the script.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(hypershift-install): use if/then and arithmetic assignment for OVERRIDE_COUNT

The previous `[[ ]] && ((OVERRIDE_COUNT++))` pattern caused the script
to exit under `set -eux` on bash 4.x/5.x (RHEL CI containers).

`((expr))` returns exit code 1 when the expression evaluates to 0.
With post-increment (`OVERRIDE_COUNT++`), the first increment from 0
evaluates to 0 (pre-increment value), triggering `set -e` termination.

Replace with explicit `if/then/fi` blocks (exempt from `set -e`) and
`OVERRIDE_COUNT=$((OVERRIDE_COUNT + 1))` (assignment, always exit 0).

Confirmed failure in rehearsal job:
  rehearse-81877-pull-ci-openshift-hypershift-main-e2e-aws-upgrade-hypershift-operator

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(hypershift-install): add --confirm to oc image extract in extract_hcp_cli

The mktemp-based temp directory (introduced for CWE-377) is no longer
empty when oc image extract runs, because oc extract already wrote
.dockerconfigjson to it. Without --confirm, oc image extract refuses
to write to a non-empty directory.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* feat(hypershift-install): add Gangway transport variable for HO release controller

Gangway does not strip the MULTISTAGE_PARAM_OVERRIDE_ prefix when
injecting env vars into step pods. Add the prefixed parameter
MULTISTAGE_PARAM_OVERRIDE_OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE to the
ref YAML and copy its value into OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE
at runtime, following the same pattern used by hypershift-mce-install.

This enables the HO release controller to override the operator image
via Gangway without hitting the ci-operator ImageStream race condition
(OVERRIDE_IMAGE_* mechanism).

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
amogh-redhat pushed a commit to amogh-redhat/release that referenced this pull request Aug 5, 2026
…tract_hcp_cli (openshift#82061)

* fix(hypershift-install): use mounted CI pull secret in extract_hcp_cli

Follow-up fix for PR openshift#81877 which introduced extract_hcp_cli.

The function used oc extract secret/pull-secret from the
openshift-config namespace to authenticate with container registries.
This fails on AKS clusters where openshift-config does not exist.

Switch to the mounted CI pull secret at
/etc/ci-pull-credentials/.dockerconfigjson, which is already used by
the hypershift install command itself for Azure, GCP, and default
cloud providers in the same script.

Signed-off-by: Alessandro Rossi <alesross@redhat.com>

* docs(hypershift-install): add HO release controller note to env doc

Trivial documentation update to trigger pj-rehearse detection.
pj-rehearse does not detect isolated script-only changes without
a corresponding ref YAML modification.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Signed-off-by: Alessandro Rossi <alesross@redhat.com>
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
vsolanki12 pushed a commit to vsolanki12/hypershift that referenced this pull request Aug 25, 2026
Switch from OVERRIDE_IMAGE_HYPERSHIFT_OPERATOR (ci-operator ImageStream
mechanism, broken by race condition) to the MULTISTAGE_PARAM_OVERRIDE_
transport variable that passes the image directly to the hypershift-install
step parameter.

Requires openshift/release#81877 to be merged first.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
rutvik23 pushed a commit to rutvik23/hypershift that referenced this pull request Aug 26, 2026
Switch from OVERRIDE_IMAGE_HYPERSHIFT_OPERATOR (ci-operator ImageStream
mechanism, broken by race condition) to the MULTISTAGE_PARAM_OVERRIDE_
transport variable that passes the image directly to the hypershift-install
step parameter.

Requires openshift/release#81877 to be merged first.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
TimurMP pushed a commit to TimurMP/release that referenced this pull request Sep 5, 2026
…_IMAGE parameter (openshift#81877)

* feat(hypershift-install): add OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE parameter

OVERRIDE_IMAGE_HYPERSHIFT_OPERATOR (ci-operator's env var mechanism) has
a race condition: both the override and the base_images step write to
the same pipeline ImageStream tag concurrently. Since IST Create is an
upsert, the base_images step consistently wins because it finishes last
(resolveOfficialImport makes API calls, the override does not). The
override is silently discarded.

--dependency-override-param would work, but Gangway only supports env
vars in the payload, not CLI arguments.

This commit adds OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE as a step parameter
that bypasses the pipeline ImageStream entirely. When set, the script
overrides both the operator image (--hypershift-image) and the hcp CLI
binary, extracting it from the same image to avoid version skew.

Also refactors the existing HO_MULTI and INSTALL_FROM_LATEST branches
into a shared extract_hcp_cli() function and adds WARNING log lines to
all override paths for better observability.

Ref: CNTRLPLANE-3434

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(hypershift-install): use mktemp for CLI extraction and warn on conflicting overrides

Address CodeRabbit review feedback:

1. Replace hardcoded /tmp/hs-cli with mktemp -d to avoid predictable
   temporary paths in the extract_hcp_cli function (CWE-377).

2. Add precedence warning when multiple image override flags are set
   simultaneously (OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE, HO_MULTI,
   INSTALL_FROM_LATEST). Logs the priority order so operators can
   understand which override takes effect without inspecting the script.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(hypershift-install): use if/then and arithmetic assignment for OVERRIDE_COUNT

The previous `[[ ]] && ((OVERRIDE_COUNT++))` pattern caused the script
to exit under `set -eux` on bash 4.x/5.x (RHEL CI containers).

`((expr))` returns exit code 1 when the expression evaluates to 0.
With post-increment (`OVERRIDE_COUNT++`), the first increment from 0
evaluates to 0 (pre-increment value), triggering `set -e` termination.

Replace with explicit `if/then/fi` blocks (exempt from `set -e`) and
`OVERRIDE_COUNT=$((OVERRIDE_COUNT + 1))` (assignment, always exit 0).

Confirmed failure in rehearsal job:
  rehearse-81877-pull-ci-openshift-hypershift-main-e2e-aws-upgrade-hypershift-operator

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(hypershift-install): add --confirm to oc image extract in extract_hcp_cli

The mktemp-based temp directory (introduced for CWE-377) is no longer
empty when oc image extract runs, because oc extract already wrote
.dockerconfigjson to it. Without --confirm, oc image extract refuses
to write to a non-empty directory.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* feat(hypershift-install): add Gangway transport variable for HO release controller

Gangway does not strip the MULTISTAGE_PARAM_OVERRIDE_ prefix when
injecting env vars into step pods. Add the prefixed parameter
MULTISTAGE_PARAM_OVERRIDE_OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE to the
ref YAML and copy its value into OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE
at runtime, following the same pattern used by hypershift-mce-install.

This enables the HO release controller to override the operator image
via Gangway without hitting the ci-operator ImageStream race condition
(OVERRIDE_IMAGE_* mechanism).

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
TimurMP pushed a commit to TimurMP/release that referenced this pull request Sep 5, 2026
…tract_hcp_cli (openshift#82061)

* fix(hypershift-install): use mounted CI pull secret in extract_hcp_cli

Follow-up fix for PR openshift#81877 which introduced extract_hcp_cli.

The function used oc extract secret/pull-secret from the
openshift-config namespace to authenticate with container registries.
This fails on AKS clusters where openshift-config does not exist.

Switch to the mounted CI pull secret at
/etc/ci-pull-credentials/.dockerconfigjson, which is already used by
the hypershift install command itself for Azure, GCP, and default
cloud providers in the same script.

Signed-off-by: Alessandro Rossi <alesross@redhat.com>

* docs(hypershift-install): add HO release controller note to env doc

Trivial documentation update to trigger pj-rehearse detection.
pj-rehearse does not detect isolated script-only changes without
a corresponding ref YAML modification.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Signed-off-by: Alessandro Rossi <alesross@redhat.com>
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. lgtm Indicates that a PR is ready to be merged. rehearsals-ack Signifies that rehearsal jobs have been acknowledged

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants