fix(ci): align hermetic build with must-gather improvements - #3668
Conversation
PR Summary by QodoAlign hermetic CI and local builds around a shared Hermeto pin
AI Description
Diagram
High-Level Assessment
Files changed (6)
|
Code Review by Qodo
1.
|
Pin Hermeto once in the Makefile for CI and local builds, include the Hermeto tag in the deps cache key, chmod the prefetch cache for non-root go-builder, and drop USER 0 from the builder stage. Signed-off-by: Fortune-Ndlovu <fndlovu@redhat.com>
|
Important The |
3a8a3ae to
c83d33b
Compare
Chown the Podman-populated cache before chmod (podman unshare, like CI), use /tmp/hermeto-cache/operator for local builds, and restrict the cache parent directory to the invoking user. Signed-off-by: Fortune-Ndlovu <fndlovu@redhat.com>
|
✅ PR images built and pushed successfully! Images are available for testing (expires in 7 days):
|
|
✅ PR images built and pushed successfully! Images are available for testing (expires in 7 days):
|
Map go-builder and rpm-builder Podman UIDs with setfacl (subuid math plus a root probe) so local offline builds work without world-writable cache files. Signed-off-by: Fortune-Ndlovu <fndlovu@redhat.com>
|
✅ PR images built and pushed successfully! Images are available for testing (expires in 7 days):
|
Relocate local Hermeto helper to hack/local-hermeto-build.sh, add CONTAINERFILE and per-image cache dirs under /tmp/hermeto-cache/, and parse multi-stage Dockerfiles for ACL UID mapping. Add dp-installer-hermetic-build for plugin-installer. Signed-off-by: Fortune-Ndlovu <fndlovu@redhat.com>
|
✅ PR images built and pushed successfully! Images are available for testing (expires in 7 days):
|
Use podman unshare chown plus chmod -R a+rwX on the local Hermeto cache, same as rhdh-must-gather redhat-developer#218 and CI. Removes the acl package requirement. Signed-off-by: Fortune-Ndlovu <fndlovu@redhat.com>
|
|
✅ PR images built and pushed successfully! Images are available for testing (expires in 7 days):
|
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #3668 +/- ##
==========================================
+ Coverage 60.09% 60.43% +0.33%
==========================================
Files 51 52 +1
Lines 3614 3672 +58
==========================================
+ Hits 2172 2219 +47
- Misses 1247 1257 +10
- Partials 195 196 +1
Flags with carried forward coverage won't be shown. Click here to find out more. 🚀 New features to boost your workflow:
|
088febb
into
redhat-developer:main



Summary
Follow-up to rhdh-must-gather#218: apply the same hermetic CI hygiene to the operator.
Makefile(Renovate + shared by CI andmake hermetic-build)chmodon the prefetched cache after inject (local script + CI) so the go-builder can stay non-rootUSER 0from the builder stage; setGOCACHE=/tmp/go-build-cacheTest plan
make hermetic-build IMG=localhost/rhdh-operator:hermetic-testpodman run --rm localhost/rhdh-operator:hermetic-test --help