Skip to content

OSAC-3530: Merge osac-csi-driver into osac mono-repo - #75

Merged
eliorerz merged 39 commits into
osac-project:mainfrom
eliorerz:merge/osac-csi-driver
Aug 2, 2026
Merged

eliorerz merged 39 commits into
osac-project:mainfrom
eliorerz:merge/osac-csi-driver

Conversation

@eliorerz

@eliorerz eliorerz commented Aug 1, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Merges osac-csi-driver into the mono-repo, following the same pattern established for fulfillment-service, osac-operator, osac-aap, and bare-metal-fulfillment-operator.

  • git subtree add --prefix=osac-csi-driver (full history preserved, no --squash) — verified the merge commit's second parent has all 34 commits from the standalone repo, cross-checked against the live repo's commit count via the GitHub API.
  • Standalone repo's main branch locked (branch protection API + durable Terraform change in github-config, so it survives the next auto-apply).
  • Root-file audit: consolidated .pre-commit-config.yaml/.pre-commit-config-ci.yaml/.yamllint.yaml/dependabot.yml into root's, dropped the redundant per-component copies (and the stale "Innabox"-era LICENSE), added an osac-csi-driver matrix entry to helm-lint.yaml, merged OWNERS and .gitignore entries, added a README bullet.
  • Scoped publish-image.yaml's tag trigger to osac-csi-driver/v* and hardcoded IMAGE_NAME up front, to avoid the OSAC-3467/OSAC-3490 image-tag collision that hit the earlier merges. Renamed the workflow to Build osac-csi-driver image (its default name would've collided with fulfillment-service's Container image workflow, which publish-charts.yaml disambiguates on).
  • Added the missing publish-charts.yaml wiring (guard job + publish-csi-driver-chart/publish-csi-backends-chart/release jobs), matching the shared per-component pattern.
  • Repointed osac-installer/charts/osac/Chart.yaml's csi-driver/csi-backends dependencies from the old base/osac-csi-driver submodule path to the mono-repo-local osac-csi-driver/charts/{csi-driver,csi-backends} paths, and removed the now-unused submodule from .gitmodules. Verified with a real helm dependency build + helm template (126 rendered manifests, including the csiDriver/csiBackends resources).
  • Added osac-csi-driver to the root go.work workspace — required, since Go's workspace auto-discovery otherwise breaks go build/go vet/golangci-lint for any module living under a go.work root that isn't listed in it. Verified go build/go vet succeed from within osac-csi-driver afterward.
  • No open GitHub Issues on the standalone repo to transfer.
  • Disabled the standalone repo's pre-commit and Container image CI workflows post-merge (its branch is also lock-protected).

Test plan

  • git subtree add history verified (commit count + merge-commit parentage)
  • pre-commit run clean on all changed files (yamllint, whitespace/EOF checks, osac-csi-driver golangci-lint with binary pre-downloaded)
  • helm lint/helm template clean for both charts/csi-driver and charts/csi-backends, standalone and via the umbrella osac-installer/charts/osac chart
  • go build ./... / go vet ./... clean from within osac-csi-driver, with osac-operator/bare-metal-fulfillment-operator builds unaffected
  • publish-csi-driver-image.yaml and publish-charts.yaml YAML-validated; workflow-name collision with fulfillment-service's Container image avoided
  • Actual tag push (osac-csi-driver/v0.0.1-style) to confirm the end-to-end image-build → chart-publish → release chain, once this merges

🤖 Generated with Claude Code

Summary by CodeRabbit

  • New Features
    • Added the OSAC CSI driver for routing storage operations across vendor backends.
    • Added Helm charts for the CSI driver and Trident, VAST, and Pure Storage integrations.
    • Added container image and chart publishing for component releases.
  • Documentation
    • Added deployment, configuration, build, and security guidance.
  • Tests
    • Added end-to-end CSI sanity testing with a simulated vendor backend.
  • Chores
    • Added automated linting, validation, dependency updates, and release safeguards.

org-config-management Bot and others added 30 commits July 19, 2026 10:04
Scaffold the project infrastructure for the OSAC CSI meta-driver:
- go.mod with Go 1.26.3 and CSI spec, gRPC, klog dependencies
- Makefile with build, test, lint, image targets (podman, UBI10)
- Containerfile for multi-stage container build
- golangci-lint v2.12.1 configuration matching osac-operator
- .gitignore and pre-commit hooks with golangci-lint

Assisted-by: Claude Code <noreply@anthropic.com>
Signed-off-by: Roy Golan <rgolan@redhat.com>
Define the Client interface that the CSI driver uses to communicate with
the OSAC fulfillment service's Volume API. The Resolve method determines
which vendor backend handles a volume request for a given tenant and tier.

Includes a LoggingStub implementation for development before the real
gRPC client is wired to the fulfillment-service.

Assisted-by: Claude Code <noreply@anthropic.com>
Signed-off-by: Roy Golan <rgolan@redhat.com>
Migrate the CSI meta-driver code from the PoC, replacing the stub HTTP
storage API with the fulfillment client interface:

- Controller plugin resolves storage tiers via fulfillment.Client.Resolve
  instead of the storageapi HTTP stub
- Removed CheckPolicy call (policy enforcement moves to fulfillment-service)
- Tenant extracted from CSI request parameters instead of hardcoded
- Deterministic default vendor socket selection (sorted map keys)
- Removed dead proxyError() function
- Version injected via ldflags instead of hardcoded constant
- Node plugin and proxy manager carried over with minimal changes

Not migrated (per design): cmd/osac-storage-api, pkg/storageapi,
deploy/ manifests, Dockerfile.storage-api, Dockerfile.pure-node.

Assisted-by: Claude Code <noreply@anthropic.com>
Signed-off-by: Roy Golan <rgolan@redhat.com>
Replace the template boilerplate with OSAC CSI driver documentation
covering architecture (controller/node plugin modes), build commands,
and CLI flag reference.

Assisted-by: Claude Code <noreply@anthropic.com>
Signed-off-by: Roy Golan <rgolan@redhat.com>
The local golangci-lint pre-commit hook uses language:system which
requires the binary at bin/golangci-lint. In CI this binary is not
available, so follow the osac-operator pattern:

- Add .pre-commit-config-ci.yaml without the golangci-lint hook
- Run golangci-lint as a separate CI job using the official action
- Update checkout action to v7, add paths-ignore for docs

Assisted-by: Claude Code <noreply@anthropic.com>
Signed-off-by: Roy Golan <rgolan@redhat.com>
- Pin google.golang.org/protobuf to stable v1.36.11 instead of
  pseudo-version
- Track volume-to-backend mapping in NodeServer so NodeUnstageVolume
  and NodeUnpublishVolume route to the correct vendor instead of
  blindly using the default socket
- Extract isUnimplemented helper to reduce duplication

Assisted-by: Claude Code <noreply@anthropic.com>
Signed-off-by: Roy Golan <rgolan@redhat.com>
Vendor resolution must be explicit, no surprises. Removed the
defaultVendorSocket fallback that silently routed to an arbitrary
vendor when the backend was unknown.

Controller: DeleteVolume and ControllerUnpublishVolume now read
osac.backend from the secrets map. ValidateVolumeCapabilities reads
it from volume context. ListVolumes removed (cannot determine backend
without volume context per-volume).

Node: resolveVendorSocket fails with InvalidArgument when osac.backend
is missing from volume context. lookupBackendSocket fails with
FailedPrecondition when no backend was recorded for the volume.

Assisted-by: Claude Code <noreply@anthropic.com>
Signed-off-by: Roy Golan <rgolan@redhat.com>
Signed-off-by: Roy Golan <rgolan@redhat.com>
Restrict GITHUB_TOKEN to read-only contents access. SHA pinning
skipped to stay consistent with other osac-project repos.

Assisted-by: Claude Code <noreply@anthropic.com>
Signed-off-by: Roy Golan <rgolan@redhat.com>
NO-ISSUE: Migrate CSI meta-driver from PoC with fulfillment client interface
Bumps [actions/setup-python](https://github.com/actions/setup-python) from 6 to 7.
- [Release notes](https://github.com/actions/setup-python/releases)
- [Commits](actions/setup-python@v6...v7)

---
updated-dependencies:
- dependency-name: actions/setup-python
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/setup-go](https://github.com/actions/setup-go) from 6 to 7.
- [Release notes](https://github.com/actions/setup-go/releases)
- [Commits](actions/setup-go@v6...v7)

---
updated-dependencies:
- dependency-name: actions/setup-go
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Helm chart for the OSAC CSI meta-driver deployment:
- Controller Deployment with csi-provisioner and csi-attacher sidecars
- Node DaemonSet with csi-node-driver-registrar
- CSIDriver resource (csi.osac.openshift.io)
- RBAC (ServiceAccounts, ClusterRoles, ClusterRoleBindings)
- Configurable image refs, resources, vendor sockets, leader election

Also excludes Helm templates from yamllint and adds a helm-lint
pre-commit hook.

Assisted-by: Claude Code <noreply@anthropic.com>
Signed-off-by: Roy Golan <rgolan@redhat.com>
Deploys vendor CSI controller pods (Trident, VAST, Pure) as separate
Deployments + Services in a dedicated namespace. Each vendor is
conditionally enabled via values (disabled by default).

Includes per-vendor: ServiceAccount, Deployment, Service, and for
Pure: ClusterRole + ClusterRoleBinding. Credentials are referenced
as existing Secrets, not created by the chart.

Assisted-by: Claude Code <noreply@anthropic.com>
Signed-off-by: Roy Golan <rgolan@redhat.com>
CSI driver containers need root to bind unix sockets on hostPath
volumes. Add runAsUser: 0 to securityContext on both controller and
node containers (complements existing privileged: true).

Also add -buildvcs=false to Containerfile to fix build when .git
is not available in the container context.

Assisted-by: Claude Code <noreply@anthropic.com>
Signed-off-by: Roy Golan <rgolan@redhat.com>
Add imagePullSecrets to all vendor controller pod specs so that
private registry credentials can be provided via values.

Fix default Trident image tag from 25.02.0 (does not exist) to
25.10.0. Available tags: 25.10.0, 26.02.0, latest.

Assisted-by: Claude Code <noreply@anthropic.com>
Signed-off-by: Roy Golan <rgolan@redhat.com>
Document the secrets and configuration each vendor requires before
chart installation: Trident TLS certs, VAST credentials, Pure config,
and registry pull secrets.

Assisted-by: Claude Code <noreply@anthropic.com>
Signed-off-by: Roy Golan <rgolan@redhat.com>
Pure CSI controller needs the Kubernetes API to function. Enable
automountServiceAccountToken (was disabled from PoC workaround).

Assisted-by: Claude Code <noreply@anthropic.com>
Signed-off-by: Roy Golan <rgolan@redhat.com>
Assisted-by: Claude Code <noreply@anthropic.com>
Signed-off-by: Roy Golan <rgolan@redhat.com>
- Add coordination.k8s.io/leases RBAC for leader election (csi-provisioner/attacher)
- Remove unnecessary hostPID and hostNetwork from node DaemonSet
- Harden controller containers: drop privileged, add restricted securityContext
- Add securityContext to all sidecar containers (provisioner, attacher, registrar)
- Change VAST verifySsl default to true for TLS verification
- Change image tag default from latest to 0.0.0 with pullPolicy Always
- Change backends namespace PSA from privileged to baseline (warn: restricted)
- Scope Pure Secrets RBAC from ClusterRole to namespaced Role (least privilege)
- Add Trident CRD RBAC (ClusterRole/Binding) for --crd_persistence

Assisted-by: Claude Code <noreply@anthropic.com>
Signed-off-by: Roy Golan <rgolan@redhat.com>
Deploy separate DaemonSets for Trident, VAST, and Pure node plugins
alongside the OSAC meta-driver. Each vendor node plugin:
- Writes its CSI socket to a well-known hostPath
- Runs privileged for mount/device operations
- Is conditionally enabled via vendors.<name>.enabled
- Reuses the csi-driver node ServiceAccount

Also fixes runAsNonRoot on sidecar containers (csi-provisioner and
csi-attacher run as root) and reverts backends namespace PSA to
privileged since vendor controllers may need it.

Tested on kind: controller 3/3 Running, all 4 node DaemonSets created.

Assisted-by: Claude Code <noreply@anthropic.com>
Signed-off-by: Roy Golan <rgolan@redhat.com>
…_actions/actions/setup-python-7

NO-ISSUE: Bump actions/setup-python from 6 to 7
…_actions/actions/setup-go-7

NO-ISSUE: Bump actions/setup-go from 6 to 7
OSAC-3052: Add Helm charts for CSI driver and vendor backends
- Add namespace.yaml template so the chart owns its namespace with
  pod-security privileged labels
- Switch all templates from Release.Namespace to Values.namespace for
  uniform deployment
- Remove hardcoded securityContext from controller sidecars
- Use templated privileged flag from Values for all node containers
- Default image tag to 'main' (placeholder, overwritten at release time)

Assisted-by: Claude Code <noreply@anthropic.com>
Signed-off-by: Roy Golan <rgolan@redhat.com>
Build and push container images to ghcr.io on merge to main
(tagged main + sha-<commit>) and on v* tags (semver tags).
Build-only on PRs to validate the Containerfile.

Assisted-by: Claude Code <noreply@anthropic.com>
Signed-off-by: Roy Golan <rgolan@redhat.com>
OSAC-3052: add publish-image GitHub Actions workflow
The Containerfile sets USER 1001 but the CSI node plugin needs root
to bind unix sockets on hostPath volumes under /var/lib/kubelet/plugins/.

Assisted-by: Claude Code <noreply@anthropic.com>
Signed-off-by: Roy Golan <rgolan@redhat.com>
Restore allowPrivilegeEscalation: false, drop ALL capabilities, and
readOnlyRootFilesystem on the controller containers (osac-csi-driver,
csi-provisioner, csi-attacher) and node-driver-registrar. These
containers don't need privileges — only the node driver plugin does.

Assisted-by: Claude Code <noreply@anthropic.com>
Signed-off-by: Roy Golan <rgolan@redhat.com>
# Conflicts:
#	.github/workflows/helm-lint.yaml
@eliorerz

eliorerz commented Aug 1, 2026

Copy link
Copy Markdown
Contributor Author

Triaged all 33 CodeRabbit findings on this PR against the actual diff (not just file location) to separate what this merge's own new content introduced from what's pre-existing in osac-csi-driver's carried-over driver/chart/test code (this is a full-history git subtree add, so every file under osac-csi-driver/ shows as "added" relative to main regardless of which of the 34 original commits actually wrote it).

5 findings are caused by this merge's own new content (the wiring commit's workflow/pre-commit/README changes, not the subtree-added code) -- fixes ready to push to this branch, coordinating with the PR author first since some may already be in progress:

  • publish-charts.yaml: the new csi-driver tag-placeholder sed step had no verification it landed (same class of gap publish-osac-aap-chart's replace_and_verify already guards against).
  • publish-csi-driver-image.yaml: missing !osac-csi-driver/charts/** exclusion (chart-only PRs shouldn't trigger a full image rebuild), plus all 4 actions this new workflow uses were unpinned to mutable tags.
  • .pre-commit-config.yaml: the new osac-csi-driver-golangci-lint entry calls the binary directly, which won't exist on a clean checkout.
  • README.md: the go.work workspace paragraph is missing osac-csi-driver (and, pre-existing, bare-metal-fulfillment-operator).

The remaining 28 findings are real, but in osac-csi-driver's own pre-existing code (Helm charts, Containerfile, Go driver logic, sanity tests) that this PR carries over unchanged from the standalone repo's history -- not something a migration PR should silently rewrite out from under the component's actual owners (zszabo-rh, wgordon17, avishayt, rgolangh per OWNERS). Filed for follow-up, not blocking this merge:

  • OSAC-3532 -- Helm chart / Containerfile security-hardening gaps (namespace-wide privileged PSA that should be scoped to the node DaemonSet only, missing resource limits/probes on several containers, overly-broad Trident ClusterRole, world-writable CSI socket, missing TLS for TCP vendor connections, COPY . ./ + no HEALTHCHECK in the Containerfile, etc.)
  • OSAC-3533 -- driver correctness bugs and test reliability issues, including one critical item: NodeUnstageVolume/NodeUnpublishVolume currently collapse a real routing failure into a false success, which can leave a vendor mount/device attached on the node while Kubernetes believes it's unstaged. Also volume-ID/backend-resolution inconsistencies in controller.go/node.go that need a design decision (not backward-compatible with existing volumes), plus a few lower-severity code-quality/test-flakiness items.

Neither ticket blocks this PR -- they're pre-existing conditions in code that already exists and runs today in the standalone repo, unaffected by whether this merge lands.

…r wiring

Addresses the 5 of 33 CodeRabbit findings on this PR that are caused by
this merge's own new content, as opposed to pre-existing osac-csi-driver
driver/chart/test code carried over verbatim by the subtree merge (those
are tracked separately as OSAC-3532/OSAC-3533, not fixed here -- see PR
comment).

- publish-charts.yaml: the new csi-driver values.yaml tag-placeholder
  sed step had no verification it actually matched, unlike the sibling
  publish-osac-aap-chart job's replace_and_verify pattern. Applied the
  same verify-after-sed guard.
- publish-csi-driver-image.yaml: excluded osac-csi-driver/charts/** from
  the image-rebuild trigger (chart-only changes are already covered by
  helm-lint.yaml's own chart path filter), and SHA-pinned the 4 actions
  this new workflow uses, reusing the exact SHA+comment pairs
  fulfillment-service's own publish-image.yaml already has for the
  identical action+version combos.
- .pre-commit-config.yaml: the new osac-csi-driver-golangci-lint entry
  called bin/golangci-lint directly, which doesn't exist on a clean
  checkout. Changed to `make -C osac-csi-driver lint-fix` so the
  Makefile installs the pinned tool first.
- README.md: the go.work workspace paragraph was missing osac-csi-driver
  (this PR's addition) and bare-metal-fulfillment-operator (a pre-existing
  gap from an earlier merge, fixed in the same pass since it's the same
  sentence).

Assisted-by: Claude Code <noreply@anthropic.com>
Signed-off-by: Elior Erez <eerez@redhat.com>

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (2)
.github/workflows/publish-csi-driver-image.yaml (2)

94-104: 🔒 Security & Privacy | 🟠 Major | 🏗️ Heavy lift

.github/workflows/publish-csi-driver-image.yaml#L94-L104, .github/workflows/publish-charts.yaml#L604-L615, .github/workflows/publish-charts.yaml#L617-L668

Sign every published OCI artifact.

These release paths push images or charts but do not create Sigstore/cosign signatures. Consumers cannot verify artifact provenance. Add keyless signing after each push, sign the immutable digest, and grant each signing job id-token: write.

  • .github/workflows/publish-csi-driver-image.yaml#L94-L104: Sign the pushed image digest after docker/build-push-action.
  • .github/workflows/publish-charts.yaml#L604-L615: Sign the pushed csi-driver chart digest.
  • .github/workflows/publish-charts.yaml#L617-L668: Sign the pushed csi-backends chart digest.

As per path instructions, “Sign artifacts with Sigstore/cosign.”

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/publish-csi-driver-image.yaml around lines 94 - 104, Sign
every published OCI artifact with keyless Sigstore/cosign after its push, using
the immutable digest and granting the relevant jobs id-token: write. Update
.github/workflows/publish-csi-driver-image.yaml lines 94-104 to sign the digest
output from docker/build-push-action; update
.github/workflows/publish-charts.yaml lines 604-615 to sign the csi-driver chart
digest; and update lines 617-668 to sign the csi-backends chart digest.

Source: Path instructions


67-73: 🎯 Functional Correctness | 🟠 Major | ⚡ Quick win

Do not publish prereleases under stable aliases.

Lines 70-73 derive v1.2 and v1 aliases after accepting prerelease versions. Lines 87-88 publish those aliases whenever RELEASE_VERSION exists. A tag such as osac-csi-driver/v1.2.3-rc.1 can overwrite v1.2 and v1 with a prerelease image.

Set major and minor aliases only when version has no prerelease suffix. Enable those metadata entries only when their alias variables are set.

Also applies to: 85-88

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/publish-csi-driver-image.yaml around lines 67 - 73, Update
the release metadata logic around RELEASE_MAJOR_MINOR and RELEASE_MAJOR so
prerelease versions do not populate stable alias variables; only set these
aliases when version has no prerelease suffix. In the publish steps,
conditionally enable the major/minor metadata entries only when their
corresponding alias variables are set, while continuing to publish
RELEASE_VERSION for prereleases.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/helm-lint.yaml:
- Around line 116-123: Add a job-level permissions block to helm-lint-installer
granting only contents: read, keeping the existing checkout and Helm validation
steps unchanged.

---

Outside diff comments:
In @.github/workflows/publish-csi-driver-image.yaml:
- Around line 94-104: Sign every published OCI artifact with keyless
Sigstore/cosign after its push, using the immutable digest and granting the
relevant jobs id-token: write. Update
.github/workflows/publish-csi-driver-image.yaml lines 94-104 to sign the digest
output from docker/build-push-action; update
.github/workflows/publish-charts.yaml lines 604-615 to sign the csi-driver chart
digest; and update lines 617-668 to sign the csi-backends chart digest.
- Around line 67-73: Update the release metadata logic around
RELEASE_MAJOR_MINOR and RELEASE_MAJOR so prerelease versions do not populate
stable alias variables; only set these aliases when version has no prerelease
suffix. In the publish steps, conditionally enable the major/minor metadata
entries only when their corresponding alias variables are set, while continuing
to publish RELEASE_VERSION for prereleases.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository: osac-project/coderabbit/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 40e75231-fc50-49f9-af6a-c334b8bc1fb3

📥 Commits

Reviewing files that changed from the base of the PR and between 524075b and c2dfa91.

📒 Files selected for processing (5)
  • .github/workflows/helm-lint.yaml
  • .github/workflows/publish-charts.yaml
  • .github/workflows/publish-csi-driver-image.yaml
  • .pre-commit-config.yaml
  • README.md

Comment on lines 116 to 123
helm-lint-installer:
name: Lint Helm charts (osac-installer)
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v6
with:
submodules: recursive
persist-credentials: false

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟠 Major | ⚡ Quick win

Restrict the installer lint job token.

This job inherits repository-default GITHUB_TOKEN permissions. It only checks out repository contents and runs local Helm validation. Set permissions: contents: read.

Proposed fix
   helm-lint-installer:
     name: Lint Helm charts (osac-installer)
     runs-on: ubuntu-latest
+    permissions:
+      contents: read
     steps:

As per path instructions, “Least privilege: minimize GITHUB_TOKEN permissions.”

📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
helm-lint-installer:
name: Lint Helm charts (osac-installer)
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v6
with:
submodules: recursive
persist-credentials: false
helm-lint-installer:
name: Lint Helm charts (osac-installer)
runs-on: ubuntu-latest
permissions:
contents: read
steps:
- name: Checkout repository
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v6
with:
persist-credentials: false
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/helm-lint.yaml around lines 116 - 123, Add a job-level
permissions block to helm-lint-installer granting only contents: read, keeping
the existing checkout and Helm validation steps unchanged.

Source: Path instructions

…liases

CodeRabbit follow-up on the previous push: RELEASE_MAJOR_MINOR/RELEASE_MAJOR
were derived from the prerelease-stripped core version but gated only on
RELEASE_VERSION being non-empty, so a prerelease tag (e.g.
osac-csi-driver/v1.2.3-rc.1) would still publish/overwrite the v1.2 and v1
stable alias tags with a prerelease image. Confirmed real: only skip setting
these two env vars when the tag has no prerelease suffix, and gate their
metadata-action entries on their own value instead of RELEASE_VERSION's.

Assisted-by: Claude Code <noreply@anthropic.com>
Signed-off-by: Elior Erez <eerez@redhat.com>
@eliorerz

eliorerz commented Aug 1, 2026

Copy link
Copy Markdown
Contributor Author

Follow-up review pass on CodeRabbit's post-push findings (submitted 21:46:53, after my earlier fixes). Verified each against current code rather than applying diffs blindly, per the same discipline as before.

Fixed: the prerelease/stable-alias overwrite bug in publish-csi-driver-image.yaml. Confirmed real: RELEASE_MAJOR_MINOR/RELEASE_MAJOR were derived from the prerelease-stripped core version, but their metadata-action entries were gated on RELEASE_VERSION != '' rather than their own value -- so a tag like osac-csi-driver/v1.2.3-rc.1 would still publish/overwrite the v1.2 and v1 stable alias tags with a prerelease image. Traced through with test values (v1.2.3 → aliases set; v1.2.3-rc.1/v2.0.0-beta.1.2 → aliases correctly left empty) before pushing. Now only sets those two env vars when the tag has no prerelease suffix, and gates their tag entries on their own non-emptiness instead of RELEASE_VERSION's.

Rejected as a false positive: the helm-lint-installer job "missing permissions" finding. Checked the actual file -- helm-lint.yaml already has a workflow-level permissions: contents: read block (line 24) that every job in the file inherits, including helm-lint-installer. Neither of the other two jobs in this same file (helm-crds-sync, helm-lint) has a job-level override either -- they all correctly rely on the same workflow-level default. Adding a redundant job-level block to only this one job would be a no-op change that also breaks consistency with its siblings. CodeRabbit's diff-scoped view of this PR likely didn't see the top-of-file block since it wasn't part of the diff.

Deferred, not fixed here: the missing Sigstore/cosign signing on published images/charts. Checked first, per instruction, whether this is unique to csi-driver -- it isn't: grepped every workflow in the repo for cosign/sigstore/id-token and found zero signing usage anywhere, across every component's publish-image/publish-charts jobs. This is already tracked epic-wide at OSAC-1148 ("Sign all distributed artifacts... with cosign"), which already covers container images, Helm charts, and binaries -- I added a comment there linking this PR as a concrete current instance rather than filing a duplicate or bolting a one-off fix onto csi-driver alone.

Pushed the one real fix. Will keep watching this PR for further CodeRabbit rounds.

@eliorerz
eliorerz merged commit 186088f into osac-project:main Aug 2, 2026
37 of 40 checks passed
@eliorerz
eliorerz deleted the merge/osac-csi-driver branch August 2, 2026 00:40
ajamias pushed a commit to ajamias/osac that referenced this pull request Aug 3, 2026
…mp-aap-submodule

NO_ISSUE: bump osac-aap submodule to latest
ajamias pushed a commit to ajamias/osac that referenced this pull request Aug 3, 2026
…ue-solver/OSAC-3049

OSAC-3049: E2E gate jobs: bare exit 1 with no diagnostic output
eliorerz pushed a commit that referenced this pull request Sep 18, 2026
…tials

OSAC-1665: add download kubeconfig and view password to cluster details

This branch was previously deployed

1 inactive deployment
e2e-test — 9ff9023a Deployed Aug 1, 2026 by eliorerz via e2e-vmaas-full-install / e2e #166
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants