Repository navigation
CNTRLPLANE-3434: hypershift-install: add OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE parameter - #81877
Conversation
…meter OVERRIDE_IMAGE_HYPERSHIFT_OPERATOR (ci-operator's env var mechanism) has a race condition: both the override and the base_images step write to the same pipeline ImageStream tag concurrently. Since IST Create is an upsert, the base_images step consistently wins because it finishes last (resolveOfficialImport makes API calls, the override does not). The override is silently discarded. --dependency-override-param would work, but Gangway only supports env vars in the payload, not CLI arguments. This commit adds OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE as a step parameter that bypasses the pipeline ImageStream entirely. When set, the script overrides both the operator image (--hypershift-image) and the hcp CLI binary, extracting it from the same image to avoid version skew. Also refactors the existing HO_MULTI and INSTALL_FROM_LATEST branches into a shared extract_hcp_cli() function and adds WARNING log lines to all override paths for better observability. Ref: CNTRLPLANE-3434 Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
|
@Nirshal: This pull request references CNTRLPLANE-3434 which is a valid jira issue. Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the epic to target the "5.0.0" version, but no target version was set. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
WalkthroughHyperShift installation centralizes CLI extraction in a helper and adds precedence-aware selection for an optional operator image override. The step registry declares the override and its multistage transport variable. ChangesHyperShift installation image selection
Estimated code review effort: 3 (Moderate) | ~20 minutes Sequence Diagram(s)sequenceDiagram
participant InstallConfig
participant InstallScript
participant OperatorImage
InstallConfig->>InstallScript: provide image override or install mode
InstallScript->>InstallScript: resolve effective operator image
InstallScript->>OperatorImage: extract pull-secret and linux/amd64 hypershift
OperatorImage-->>InstallScript: return hypershift binary
InstallScript->>InstallScript: set HCP_CLI
Suggested reviewers: Important Pre-merge checks failedPlease resolve all errors before merging. Addressing warnings is optional. ❌ Failed checks (1 error)
✅ Passed checks (14 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
There was a problem hiding this comment.
Actionable comments posted: 2
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@ci-operator/step-registry/hypershift/install/hypershift-install-commands.sh`:
- Around line 18-23: Update the override warning in the hypershift install
command flow to report the effective baseline image selected by the same
HO_MULTI rules as the no-override path, rather than always labeling
HYPERSHIFT_RELEASE_LATEST as the default. Keep the override assignment and
extract_hcp_cli behavior unchanged.
- Around line 11-15: Update the installation flow around the oc extract, oc
image extract, chmod, and HCP_CLI assignments to create a private unpredictable
temporary directory with mktemp -d, use it for both pull-secret extraction and
the hypershift CLI extraction, and reference the resulting paths instead of /tmp
locations. Add cleanup of the temporary directory after installation while
preserving HCP_CLI usability.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Repository YAML (base), Central YAML (inherited)
Review profile: CHILL
Plan: Enterprise
Run ID: fe60077d-1eed-45e2-a779-4a5e9c5e97c9
📒 Files selected for processing (2)
ci-operator/step-registry/hypershift/install/hypershift-install-commands.shci-operator/step-registry/hypershift/install/hypershift-install-ref.yaml
…nflicting overrides Address CodeRabbit review feedback: 1. Replace hardcoded /tmp/hs-cli with mktemp -d to avoid predictable temporary paths in the extract_hcp_cli function (CWE-377). 2. Add precedence warning when multiple image override flags are set simultaneously (OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE, HO_MULTI, INSTALL_FROM_LATEST). Logs the priority order so operators can understand which override takes effect without inspecting the script. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
|
/pj-rehearse pull-ci-openshift-hypershift-main-e2e-aks pull-ci-openshift-hypershift-main-e2e-aws pull-ci-openshift-hypershift-main-e2e-azure-v2-self-managed periodic-ci-openshift-hypershift-release-5.0-periodics-e2e-aks-multi-x-ax pull-ci-openshift-hypershift-main-e2e-aws-upgrade-hypershift-operator |
|
@Nirshal: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
…ERRIDE_COUNT The previous `[[ ]] && ((OVERRIDE_COUNT++))` pattern caused the script to exit under `set -eux` on bash 4.x/5.x (RHEL CI containers). `((expr))` returns exit code 1 when the expression evaluates to 0. With post-increment (`OVERRIDE_COUNT++`), the first increment from 0 evaluates to 0 (pre-increment value), triggering `set -e` termination. Replace with explicit `if/then/fi` blocks (exempt from `set -e`) and `OVERRIDE_COUNT=$((OVERRIDE_COUNT + 1))` (assignment, always exit 0). Confirmed failure in rehearsal job: rehearse-81877-pull-ci-openshift-hypershift-main-e2e-aws-upgrade-hypershift-operator Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
|
/pj-rehearse pull-ci-openshift-hypershift-main-e2e-aks pull-ci-openshift-hypershift-main-e2e-aws pull-ci-openshift-hypershift-main-e2e-azure-v2-self-managed periodic-ci-openshift-hypershift-release-5.0-periodics-e2e-aks-multi-x-ax pull-ci-openshift-hypershift-main-e2e-aws-upgrade-hypershift-operator |
|
@Nirshal: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
…_hcp_cli The mktemp-based temp directory (introduced for CWE-377) is no longer empty when oc image extract runs, because oc extract already wrote .dockerconfigjson to it. Without --confirm, oc image extract refuses to write to a non-empty directory. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
|
/pj-rehearse pull-ci-openshift-hypershift-main-e2e-aks pull-ci-openshift-hypershift-main-e2e-aws pull-ci-openshift-hypershift-main-e2e-azure-v2-self-managed periodic-ci-openshift-hypershift-release-5.0-periodics-e2e-aks-multi-x-ax pull-ci-openshift-hypershift-main-e2e-aws-upgrade-hypershift-operator |
|
@Nirshal: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
|
/pj-rehearse pull-ci-openshift-hypershift-main-e2e-aws pull-ci-openshift-hypershift-main-e2e-aks |
|
@Nirshal: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
|
/pj-rehearse pull-ci-openshift-hypershift-main-e2e-aks |
|
@Nirshal: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
|
/pj-rehearse ack |
|
@bryan-cox: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
…se controller Gangway does not strip the MULTISTAGE_PARAM_OVERRIDE_ prefix when injecting env vars into step pods. Add the prefixed parameter MULTISTAGE_PARAM_OVERRIDE_OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE to the ref YAML and copy its value into OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE at runtime, following the same pattern used by hypershift-mce-install. This enables the HO release controller to override the operator image via Gangway without hitting the ci-operator ImageStream race condition (OVERRIDE_IMAGE_* mechanism). Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
|
[REHEARSALNOTIFIER]
A total of 605 jobs have been affected by this change. The above listing is non-exhaustive and limited to 25 jobs. A full list of affected jobs can be found here Interacting with pj-rehearseComment: Once you are satisfied with the results of the rehearsals, comment: |
|
/lgtm |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: bryan-cox, Nirshal The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
|
/pj-rehearse ack We verified several tests before Alessandro's latest push that just changes the gangway override |
|
@bryan-cox: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
Switch from OVERRIDE_IMAGE_HYPERSHIFT_OPERATOR (ci-operator ImageStream mechanism, broken by race condition) to the MULTISTAGE_PARAM_OVERRIDE_ transport variable that passes the image directly to the hypershift-install step parameter. Requires openshift/release#81877 to be merged first. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
|
@Nirshal: all tests passed! Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
…_IMAGE parameter (openshift#81877) * feat(hypershift-install): add OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE parameter OVERRIDE_IMAGE_HYPERSHIFT_OPERATOR (ci-operator's env var mechanism) has a race condition: both the override and the base_images step write to the same pipeline ImageStream tag concurrently. Since IST Create is an upsert, the base_images step consistently wins because it finishes last (resolveOfficialImport makes API calls, the override does not). The override is silently discarded. --dependency-override-param would work, but Gangway only supports env vars in the payload, not CLI arguments. This commit adds OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE as a step parameter that bypasses the pipeline ImageStream entirely. When set, the script overrides both the operator image (--hypershift-image) and the hcp CLI binary, extracting it from the same image to avoid version skew. Also refactors the existing HO_MULTI and INSTALL_FROM_LATEST branches into a shared extract_hcp_cli() function and adds WARNING log lines to all override paths for better observability. Ref: CNTRLPLANE-3434 Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(hypershift-install): use mktemp for CLI extraction and warn on conflicting overrides Address CodeRabbit review feedback: 1. Replace hardcoded /tmp/hs-cli with mktemp -d to avoid predictable temporary paths in the extract_hcp_cli function (CWE-377). 2. Add precedence warning when multiple image override flags are set simultaneously (OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE, HO_MULTI, INSTALL_FROM_LATEST). Logs the priority order so operators can understand which override takes effect without inspecting the script. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(hypershift-install): use if/then and arithmetic assignment for OVERRIDE_COUNT The previous `[[ ]] && ((OVERRIDE_COUNT++))` pattern caused the script to exit under `set -eux` on bash 4.x/5.x (RHEL CI containers). `((expr))` returns exit code 1 when the expression evaluates to 0. With post-increment (`OVERRIDE_COUNT++`), the first increment from 0 evaluates to 0 (pre-increment value), triggering `set -e` termination. Replace with explicit `if/then/fi` blocks (exempt from `set -e`) and `OVERRIDE_COUNT=$((OVERRIDE_COUNT + 1))` (assignment, always exit 0). Confirmed failure in rehearsal job: rehearse-81877-pull-ci-openshift-hypershift-main-e2e-aws-upgrade-hypershift-operator Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(hypershift-install): add --confirm to oc image extract in extract_hcp_cli The mktemp-based temp directory (introduced for CWE-377) is no longer empty when oc image extract runs, because oc extract already wrote .dockerconfigjson to it. Without --confirm, oc image extract refuses to write to a non-empty directory. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * feat(hypershift-install): add Gangway transport variable for HO release controller Gangway does not strip the MULTISTAGE_PARAM_OVERRIDE_ prefix when injecting env vars into step pods. Add the prefixed parameter MULTISTAGE_PARAM_OVERRIDE_OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE to the ref YAML and copy its value into OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE at runtime, following the same pattern used by hypershift-mce-install. This enables the HO release controller to override the operator image via Gangway without hitting the ci-operator ImageStream race condition (OVERRIDE_IMAGE_* mechanism). Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
…tract_hcp_cli (#82061) * fix(hypershift-install): use mounted CI pull secret in extract_hcp_cli Follow-up fix for PR #81877 which introduced extract_hcp_cli. The function used oc extract secret/pull-secret from the openshift-config namespace to authenticate with container registries. This fails on AKS clusters where openshift-config does not exist. Switch to the mounted CI pull secret at /etc/ci-pull-credentials/.dockerconfigjson, which is already used by the hypershift install command itself for Azure, GCP, and default cloud providers in the same script. Signed-off-by: Alessandro Rossi <alesross@redhat.com> * docs(hypershift-install): add HO release controller note to env doc Trivial documentation update to trigger pj-rehearse detection. pj-rehearse does not detect isolated script-only changes without a corresponding ref YAML modification. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> --------- Signed-off-by: Alessandro Rossi <alesross@redhat.com> Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
…_IMAGE parameter (openshift#81877) * feat(hypershift-install): add OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE parameter OVERRIDE_IMAGE_HYPERSHIFT_OPERATOR (ci-operator's env var mechanism) has a race condition: both the override and the base_images step write to the same pipeline ImageStream tag concurrently. Since IST Create is an upsert, the base_images step consistently wins because it finishes last (resolveOfficialImport makes API calls, the override does not). The override is silently discarded. --dependency-override-param would work, but Gangway only supports env vars in the payload, not CLI arguments. This commit adds OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE as a step parameter that bypasses the pipeline ImageStream entirely. When set, the script overrides both the operator image (--hypershift-image) and the hcp CLI binary, extracting it from the same image to avoid version skew. Also refactors the existing HO_MULTI and INSTALL_FROM_LATEST branches into a shared extract_hcp_cli() function and adds WARNING log lines to all override paths for better observability. Ref: CNTRLPLANE-3434 Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(hypershift-install): use mktemp for CLI extraction and warn on conflicting overrides Address CodeRabbit review feedback: 1. Replace hardcoded /tmp/hs-cli with mktemp -d to avoid predictable temporary paths in the extract_hcp_cli function (CWE-377). 2. Add precedence warning when multiple image override flags are set simultaneously (OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE, HO_MULTI, INSTALL_FROM_LATEST). Logs the priority order so operators can understand which override takes effect without inspecting the script. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(hypershift-install): use if/then and arithmetic assignment for OVERRIDE_COUNT The previous `[[ ]] && ((OVERRIDE_COUNT++))` pattern caused the script to exit under `set -eux` on bash 4.x/5.x (RHEL CI containers). `((expr))` returns exit code 1 when the expression evaluates to 0. With post-increment (`OVERRIDE_COUNT++`), the first increment from 0 evaluates to 0 (pre-increment value), triggering `set -e` termination. Replace with explicit `if/then/fi` blocks (exempt from `set -e`) and `OVERRIDE_COUNT=$((OVERRIDE_COUNT + 1))` (assignment, always exit 0). Confirmed failure in rehearsal job: rehearse-81877-pull-ci-openshift-hypershift-main-e2e-aws-upgrade-hypershift-operator Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(hypershift-install): add --confirm to oc image extract in extract_hcp_cli The mktemp-based temp directory (introduced for CWE-377) is no longer empty when oc image extract runs, because oc extract already wrote .dockerconfigjson to it. Without --confirm, oc image extract refuses to write to a non-empty directory. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * feat(hypershift-install): add Gangway transport variable for HO release controller Gangway does not strip the MULTISTAGE_PARAM_OVERRIDE_ prefix when injecting env vars into step pods. Add the prefixed parameter MULTISTAGE_PARAM_OVERRIDE_OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE to the ref YAML and copy its value into OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE at runtime, following the same pattern used by hypershift-mce-install. This enables the HO release controller to override the operator image via Gangway without hitting the ci-operator ImageStream race condition (OVERRIDE_IMAGE_* mechanism). Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
…tract_hcp_cli (openshift#82061) * fix(hypershift-install): use mounted CI pull secret in extract_hcp_cli Follow-up fix for PR openshift#81877 which introduced extract_hcp_cli. The function used oc extract secret/pull-secret from the openshift-config namespace to authenticate with container registries. This fails on AKS clusters where openshift-config does not exist. Switch to the mounted CI pull secret at /etc/ci-pull-credentials/.dockerconfigjson, which is already used by the hypershift install command itself for Azure, GCP, and default cloud providers in the same script. Signed-off-by: Alessandro Rossi <alesross@redhat.com> * docs(hypershift-install): add HO release controller note to env doc Trivial documentation update to trigger pj-rehearse detection. pj-rehearse does not detect isolated script-only changes without a corresponding ref YAML modification. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> --------- Signed-off-by: Alessandro Rossi <alesross@redhat.com> Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
…_IMAGE parameter (openshift#81877) * feat(hypershift-install): add OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE parameter OVERRIDE_IMAGE_HYPERSHIFT_OPERATOR (ci-operator's env var mechanism) has a race condition: both the override and the base_images step write to the same pipeline ImageStream tag concurrently. Since IST Create is an upsert, the base_images step consistently wins because it finishes last (resolveOfficialImport makes API calls, the override does not). The override is silently discarded. --dependency-override-param would work, but Gangway only supports env vars in the payload, not CLI arguments. This commit adds OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE as a step parameter that bypasses the pipeline ImageStream entirely. When set, the script overrides both the operator image (--hypershift-image) and the hcp CLI binary, extracting it from the same image to avoid version skew. Also refactors the existing HO_MULTI and INSTALL_FROM_LATEST branches into a shared extract_hcp_cli() function and adds WARNING log lines to all override paths for better observability. Ref: CNTRLPLANE-3434 Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(hypershift-install): use mktemp for CLI extraction and warn on conflicting overrides Address CodeRabbit review feedback: 1. Replace hardcoded /tmp/hs-cli with mktemp -d to avoid predictable temporary paths in the extract_hcp_cli function (CWE-377). 2. Add precedence warning when multiple image override flags are set simultaneously (OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE, HO_MULTI, INSTALL_FROM_LATEST). Logs the priority order so operators can understand which override takes effect without inspecting the script. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(hypershift-install): use if/then and arithmetic assignment for OVERRIDE_COUNT The previous `[[ ]] && ((OVERRIDE_COUNT++))` pattern caused the script to exit under `set -eux` on bash 4.x/5.x (RHEL CI containers). `((expr))` returns exit code 1 when the expression evaluates to 0. With post-increment (`OVERRIDE_COUNT++`), the first increment from 0 evaluates to 0 (pre-increment value), triggering `set -e` termination. Replace with explicit `if/then/fi` blocks (exempt from `set -e`) and `OVERRIDE_COUNT=$((OVERRIDE_COUNT + 1))` (assignment, always exit 0). Confirmed failure in rehearsal job: rehearse-81877-pull-ci-openshift-hypershift-main-e2e-aws-upgrade-hypershift-operator Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(hypershift-install): add --confirm to oc image extract in extract_hcp_cli The mktemp-based temp directory (introduced for CWE-377) is no longer empty when oc image extract runs, because oc extract already wrote .dockerconfigjson to it. Without --confirm, oc image extract refuses to write to a non-empty directory. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * feat(hypershift-install): add Gangway transport variable for HO release controller Gangway does not strip the MULTISTAGE_PARAM_OVERRIDE_ prefix when injecting env vars into step pods. Add the prefixed parameter MULTISTAGE_PARAM_OVERRIDE_OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE to the ref YAML and copy its value into OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE at runtime, following the same pattern used by hypershift-mce-install. This enables the HO release controller to override the operator image via Gangway without hitting the ci-operator ImageStream race condition (OVERRIDE_IMAGE_* mechanism). Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
…tract_hcp_cli (openshift#82061) * fix(hypershift-install): use mounted CI pull secret in extract_hcp_cli Follow-up fix for PR openshift#81877 which introduced extract_hcp_cli. The function used oc extract secret/pull-secret from the openshift-config namespace to authenticate with container registries. This fails on AKS clusters where openshift-config does not exist. Switch to the mounted CI pull secret at /etc/ci-pull-credentials/.dockerconfigjson, which is already used by the hypershift install command itself for Azure, GCP, and default cloud providers in the same script. Signed-off-by: Alessandro Rossi <alesross@redhat.com> * docs(hypershift-install): add HO release controller note to env doc Trivial documentation update to trigger pj-rehearse detection. pj-rehearse does not detect isolated script-only changes without a corresponding ref YAML modification. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> --------- Signed-off-by: Alessandro Rossi <alesross@redhat.com> Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Switch from OVERRIDE_IMAGE_HYPERSHIFT_OPERATOR (ci-operator ImageStream mechanism, broken by race condition) to the MULTISTAGE_PARAM_OVERRIDE_ transport variable that passes the image directly to the hypershift-install step parameter. Requires openshift/release#81877 to be merged first. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Switch from OVERRIDE_IMAGE_HYPERSHIFT_OPERATOR (ci-operator ImageStream mechanism, broken by race condition) to the MULTISTAGE_PARAM_OVERRIDE_ transport variable that passes the image directly to the hypershift-install step parameter. Requires openshift/release#81877 to be merged first. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
…_IMAGE parameter (openshift#81877) * feat(hypershift-install): add OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE parameter OVERRIDE_IMAGE_HYPERSHIFT_OPERATOR (ci-operator's env var mechanism) has a race condition: both the override and the base_images step write to the same pipeline ImageStream tag concurrently. Since IST Create is an upsert, the base_images step consistently wins because it finishes last (resolveOfficialImport makes API calls, the override does not). The override is silently discarded. --dependency-override-param would work, but Gangway only supports env vars in the payload, not CLI arguments. This commit adds OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE as a step parameter that bypasses the pipeline ImageStream entirely. When set, the script overrides both the operator image (--hypershift-image) and the hcp CLI binary, extracting it from the same image to avoid version skew. Also refactors the existing HO_MULTI and INSTALL_FROM_LATEST branches into a shared extract_hcp_cli() function and adds WARNING log lines to all override paths for better observability. Ref: CNTRLPLANE-3434 Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(hypershift-install): use mktemp for CLI extraction and warn on conflicting overrides Address CodeRabbit review feedback: 1. Replace hardcoded /tmp/hs-cli with mktemp -d to avoid predictable temporary paths in the extract_hcp_cli function (CWE-377). 2. Add precedence warning when multiple image override flags are set simultaneously (OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE, HO_MULTI, INSTALL_FROM_LATEST). Logs the priority order so operators can understand which override takes effect without inspecting the script. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(hypershift-install): use if/then and arithmetic assignment for OVERRIDE_COUNT The previous `[[ ]] && ((OVERRIDE_COUNT++))` pattern caused the script to exit under `set -eux` on bash 4.x/5.x (RHEL CI containers). `((expr))` returns exit code 1 when the expression evaluates to 0. With post-increment (`OVERRIDE_COUNT++`), the first increment from 0 evaluates to 0 (pre-increment value), triggering `set -e` termination. Replace with explicit `if/then/fi` blocks (exempt from `set -e`) and `OVERRIDE_COUNT=$((OVERRIDE_COUNT + 1))` (assignment, always exit 0). Confirmed failure in rehearsal job: rehearse-81877-pull-ci-openshift-hypershift-main-e2e-aws-upgrade-hypershift-operator Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(hypershift-install): add --confirm to oc image extract in extract_hcp_cli The mktemp-based temp directory (introduced for CWE-377) is no longer empty when oc image extract runs, because oc extract already wrote .dockerconfigjson to it. Without --confirm, oc image extract refuses to write to a non-empty directory. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * feat(hypershift-install): add Gangway transport variable for HO release controller Gangway does not strip the MULTISTAGE_PARAM_OVERRIDE_ prefix when injecting env vars into step pods. Add the prefixed parameter MULTISTAGE_PARAM_OVERRIDE_OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE to the ref YAML and copy its value into OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE at runtime, following the same pattern used by hypershift-mce-install. This enables the HO release controller to override the operator image via Gangway without hitting the ci-operator ImageStream race condition (OVERRIDE_IMAGE_* mechanism). Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
…tract_hcp_cli (openshift#82061) * fix(hypershift-install): use mounted CI pull secret in extract_hcp_cli Follow-up fix for PR openshift#81877 which introduced extract_hcp_cli. The function used oc extract secret/pull-secret from the openshift-config namespace to authenticate with container registries. This fails on AKS clusters where openshift-config does not exist. Switch to the mounted CI pull secret at /etc/ci-pull-credentials/.dockerconfigjson, which is already used by the hypershift install command itself for Azure, GCP, and default cloud providers in the same script. Signed-off-by: Alessandro Rossi <alesross@redhat.com> * docs(hypershift-install): add HO release controller note to env doc Trivial documentation update to trigger pj-rehearse detection. pj-rehearse does not detect isolated script-only changes without a corresponding ref YAML modification. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> --------- Signed-off-by: Alessandro Rossi <alesross@redhat.com> Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
What
Adds a new
OVERRIDE_HYPERSHIFT_OPERATOR_IMAGEstep parameter to thehypershift-installref that allows callers to override both the HyperShift Operator image and thehcpCLI binary used during installation.Why
ci-operator's
OVERRIDE_IMAGE_*env var mechanism has a race condition when the same tag exists inbase_images: both the override and thebase_imagesimport create concurrentInputImageTagStepnodes targeting the same pipeline ImageStream tag. SinceImageStreamTagcreate is an upsert and thebase_imagesstep finishes last (it callsresolveOfficialImportwhich makes API calls, while the override has the pullspec ready), the override is silently discarded. The--dependency-override-paramCLI flag would work, but Gangway only supports env vars in the payload, not CLI arguments.This new parameter bypasses the pipeline ImageStream entirely: the image pullspec is passed directly from the Gangway payload to the install script, avoiding the race condition.
Gangway transport workaround
ci-operator does not strip the
MULTISTAGE_PARAM_OVERRIDE_prefix when injecting env vars into step pods. The step receives the full variable name as-is. This is the same behavior used byhypershift-mce-install(seeMULTISTAGE_PARAM_OVERRIDE_OVERRIDE_HO_IMAGE/MULTISTAGE_PARAM_OVERRIDE_MCE_VERSIONin that step).To support Gangway callers (e.g. the HO release controller), the ref YAML declares both:
OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE(for direct use in job configs)MULTISTAGE_PARAM_OVERRIDE_OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE(Gangway transport)The script copies the prefixed variable into the unprefixed one at startup, before any override logic runs.
What changed
hypershift-install-ref.yaml:OVERRIDE_HYPERSHIFT_OPERATOR_IMAGEparameter (default: empty)MULTISTAGE_PARAM_OVERRIDE_OVERRIDE_HYPERSHIFT_OPERATOR_IMAGEtransport parameter (default: empty)hypershift-install-commands.sh:extract_hcp_cli()function usingmktemp -d(CWE-377)MULTISTAGE_PARAM_OVERRIDE_OVERRIDE_HYPERSHIFT_OPERATOR_IMAGEintoOVERRIDE_HYPERSHIFT_OPERATOR_IMAGEat startupOVERRIDE_HYPERSHIFT_OPERATOR_IMAGEas the highest-priority branch in the existingif/elifchain (beforeHO_MULTIandINSTALL_FROM_LATEST)OPERATOR_IMAGEand extracts thehcpCLI from the same image to avoid version skewWARNINGlog lines to all override paths for better observabilityset -ecompatibility: replaced[[ ]] && ((COUNT++))withif/then/fiand arithmetic assignment (the((0++))expression returns exit code 1 under bash 4.x/5.x, killing the script)--confirmtooc image extract(temp dir is non-empty after pull-secret extraction)How to use
In a Gangway payload:
{ "job_name": "periodic-ci-openshift-hypershift-release-5.0-periodics-e2e-aks", "pod_spec_options": { "envs": { "MULTISTAGE_PARAM_OVERRIDE_OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE": "quay.io/my-repo/hypershift-operator@sha256:abc123..." } } }Or in a job config:
Impact
ifbranch is skippedHO_MULTIandINSTALL_FROM_LATESTbehavior is preserved (refactored, not changed)WARNINGlog lines are informational onlySummary by CodeRabbit
hypershift-installstep registry (ci-operator/step-registry/hypershift/install) to add a newOVERRIDE_HYPERSHIFT_OPERATOR_IMAGEparameter (default empty) that lets job authors provide an Operator image pullspec directly, bypassing pipeline ImageStream dependency resolution and avoiding anOVERRIDE_IMAGE_*race withbase_images.MULTISTAGE_PARAM_OVERRIDE_OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE; at runtime the step copies it intoOVERRIDE_HYPERSHIFT_OPERATOR_IMAGEso Gangway-styleMULTISTAGE_PARAM_OVERRIDE_wiring works as intended.OVERRIDE_HYPERSHIFT_OPERATOR_IMAGEis set, it’s used for both the HyperShift Operator and thehcpCLI by extractinglinux/amd64hypershiftfrom that image and settingHCP_CLIto the extracted binary path.OVERRIDE_HYPERSHIFT_OPERATOR_IMAGE,HO_MULTI, andINSTALL_FROM_LATEST, including warning logs when multiple are enabled (override image >HO_MULTI>INSTALL_FROM_LATEST), while preserving the prior behavior when no override is specified.