[release-4.22] OCPBUGS-94518: add ACR pull identity to worker cloud.conf and VMSS - #8865
Conversation
|
Pipeline controller notification For optional jobs, comment This repository is configured in: LGTM mode |
|
Skipping CI for Draft Pull Request. |
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Repository YAML (base), Central YAML (inherited) Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
e4513ac to
68f3b24
Compare
|
/jira cherry-pick OCPBUGS-86616 |
|
@celebdor: Jira Issue OCPBUGS-86616 has been cloned as Jira Issue OCPBUGS-94518. Will retitle bug to link to clone. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
@twolff-gh: This pull request references Jira Issue OCPBUGS-94518, which is invalid:
Comment The bug has been updated to refer to the pull request using the external bug tracker. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
/jira refresh |
|
@celebdor: This pull request references Jira Issue OCPBUGS-94518, which is valid. The bug has been moved to the POST state. 7 validation(s) were run on this bug
The bug has been updated to refer to the pull request using the external bug tracker. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
Are both things the vm attachment and the cloud config propagated as a file for the payload generation needed for kubelet ACR pull to work? If the premise above is true, current implementation doesn't guarantee the latter. Changes to the cloud config do not result in new payload generation and propagation to nodes disk. This might be a good candidate for https://redhat.atlassian.net/browse/OCPSTRAT-3299. With current code you'd get what you want for:
You don't get cloud config day2 changes alone propagated to the nodes disk |
00ba333 to
c180cce
Compare
|
/test e2e-aks-4-21 |
|
/test e2e-aks-4-21 |
|
@jparrill Whenever you get a chance to approve, its ready for another review
|
|
Thanks for addressing the One observation from comparing against the originals on main (#8472, #8840, #8946): The However,
These tests exist in the original PR and cover the hash-gating logic added in Not a blocker — the rest looks clean. |
…o prevent serving stale content Backport of PR openshift#8946 (946d0f9, 077d180) from main, adapted for release-4.22. Hashing uses existing HashSimple inlined at call sites instead of adding HashConfigMapData to support/util. No osStream parameter (CNTRLPLANE-3553 not on this branch). Extracts writeCloudProviderConfig from GetPayload for testability and adds TestWriteCloudProviderConfig covering hash match, mismatch, missing configmap, and non-cloud provider paths. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
c180cce to
b7af8eb
Compare
|
/approve |
|
/label acknowledge-critical-fixes-only |
bryan-cox
left a comment
There was a problem hiding this comment.
Several files are here that are not in the PR this backport was created from :
- hypershift-operator/controllers/hostedcluster/metrics/metrics.go
- hypershift-operator/controllers/hostedcluster/metrics/metrics_test.go
- hypershift-operator/controllers/nodepool/config.go
- hypershift-operator/controllers/nodepool/config_test.go
- hypershift-operator/controllers/nodepool/nodepool_controller.go
- hypershift-operator/controllers/nodepool/nodepool_controller_test.go
- hypershift-operator/controllers/nodepool/token.go
- hypershift-operator/controllers/nodepool/token_test.go
- ignition-server/cmd/run_local_ignitionprovider.go
- ignition-server/controllers/cache.go
- ignition-server/controllers/local_ignitionprovider.go
- ignition-server/controllers/local_ignitionprovider_test.go
- ignition-server/controllers/tokensecret_controller.go
- ignition-server/controllers/tokensecret_controller_test.go
|
/lgtm |
|
Scheduling tests matching the |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: bryan-cox, JoelSpeed, jparrill, twolff-gh The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
|
/test e2e-aws |
|
/verified by @machi1990 Verified using the CPO image: quay.io/redhat-user-workloads/crt-redhat-acm-tenant/control-plane-operator-4-22:b7af8ebd065698241c44da905e3f17c09915e81c The openshift-config cloud provider config, looks good to as expected The worker.conf lgtm And the VM has the identity attached |
|
@machi1990: This PR has been marked as verified by DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
@twolff-gh: all tests passed! Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
41cbcdf
into
openshift:release-4.22
|
@twolff-gh: Jira Issue Verification Checks: Jira Issue OCPBUGS-94518 Jira Issue OCPBUGS-94518 has been moved to the MODIFIED state and will move to the VERIFIED state when the change is available in an accepted nightly payload. 🕓 DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
Fix included in release 4.22.0-0.nightly-2026-08-05-022950 |
Update azure CPO image overrides to include recent backports: - 4.20.0-4.20.32: PR #9055 (cherry-pick to release-4.20) Supersedes OCPBUGS-86567 image; extends range from 4.20.24 to 4.20.32. - 4.21.0-4.21.27: PR #9054 (cherry-pick to release-4.21) Supersedes OCPBUGS-86416 image; extends range from 4.21.18 to 4.21.27. - 4.22.0-4.22.8: PR #8865 (cherry-pick to release-4.22) Supersedes CNTRLPLANE-3619/3656/OCPBUGS-98627/98220 image; extends range from 4.22.6 to 4.22.8. All new images are verified to contain the previously overridden fixes. Next z-streams (4.20.33, 4.21.28, 4.22.9) do not need overrides: all PRs merged before their development cutoffs (2026-08-05). Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
What this PR does / why we need it:
Backports #8472 to release-4.22. Adds ACR pull identity support to worker cloud.conf and VMSS so kubelet's ACR credential provider can authenticate to Azure Container Registry using a managed identity instead of image pull secrets.
Also backports #8840 (ACR pull identity configured metric) and #8946 (gate cloud config on hash to prevent serving stale content).
Backports #8946 to release-4.22. Gates ignition server cloud config serving on a content hash so kubelet only re-fetches when the config actually changes, preventing stale credential provider configuration.
Backports #8840 to release-4.22. Adds a metric to report whether ACR pull identity is configured on hosted clusters, enabling alerting and dashboard visibility for the feature rollout.
Which issue(s) this PR fixes:
Fixes https://redhat.atlassian.net/browse/OCPBUGS-86616
Fixes https://redhat.atlassian.net/browse/OCPBUGS-94518
Special notes for your reviewer:
Not a clean cherry-pick. Two conflicts resolved:
Two additional commits added per reviewer guidance:
Collect()— main has decomposed per-cluster helpers.osStreamparameter omitted (CNTRLPLANE-3553 not on 4.22),k8sutil→supportutil, hashing inlined with existingHashSimpleinstead of addingHashConfigMapDatatosupport/util.Checklist: