Skip to content

OPCT-453: merge main into release-0.6 for v0.6.7 release - #97

Merged
openshift-merge-bot[bot] merged 8 commits into
release-0.6from
release/v0.6.7
Aug 25, 2026
Merged

openshift-merge-bot[bot] merged 8 commits into
release-0.6from
release/v0.6.7

Conversation

@bshaw7

@bshaw7 bshaw7 commented Aug 25, 2026 •

Copy link
Copy Markdown
Collaborator

Merge main into release-0.6 to include fixes for v0.6.7 release.

Changes since v0.6.6

Jira: https://redhat.atlassian.net/browse/OPCT-453

bshaw7 and others added 8 commits July 7, 2026 14:12
…data cleaning (#88)

## Summary

- Embed
[must-gather-clean](https://github.com/openshift/must-gather-clean)
v0.0.5 in the artifacts-collector plugin image
- Run it against must-gather directory (omit Secrets/MachineConfig,
redact sha256~ tokens and JWTs) before packing
- Run it against e2e metadata tar.gz archives (redact sha256~ tokens and
JWTs) before final packing
- Falls back to existing sed-based cleaning if must-gather-clean fails

This prevents leaktk-gcs-filter from removing OPCT CI archives from GCS.
The bulk of findings (3070 of 3157) are sha256~ OAuth tokens inside
`artifacts_e2e-metadata-*.tar.gz` from openshift-tests output.

Verified locally: must-gather-clean with regex config reduces sha256~
findings in e2e metadata from 1212 to 0.

Related: redhat-openshift-ecosystem/opct#223 (non-nested scanner
improvements, defense in depth)

## Test plan
- [ ] Build artifacts-collector image with changes
- [ ] Run must-gather-clean against extracted e2e metadata, confirm
sha256~ count drops to 0
- [ ] Run must-gather-clean against extracted must-gather, confirm
Secrets/MachineConfig omitted
- [ ] Run leaktk scan against cleaned archive, confirm 0 findings
- [ ] Full OPCT run on a cluster to verify no regressions

/cc @mtulio

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
…her (#89)

## Summary

- Add mco-sanitize to the artifacts-collector plugin to redact pull
secrets and JWTs from machineconfig ignition configs in must-gather
- Same tool CI gather-must-gather step uses

## Root Cause

leaktk-gcs-filter was redacting the entire OPCT archive (76 bytes)
because machineconfigs (00-master.yaml, 00-worker.yaml) inside the OPCT
must-gather contained real pull secrets and JWTs in the ignition config.

CI standalone must-gather.tar in the same job was NOT redacted because
the gather-must-gather step runs mco-sanitize after collection. OPCT
artifacts-collector was missing this step.

Evidence from same CI job (2076734326464057344):
- Standalone must-gather 00-master.yaml (17 KB): _REDACTED: This field
has been redacted
- OPCT must-gather 00-master.yaml (151 KB): real auths with base64
registry credentials

leaktk self-service form confirmed 25 findings, 6 from machineconfigs
(the trigger).

## Changes

### artifacts-collector/Containerfile
- New build stage to download mco-sanitize binary (16 MB) from CI mirror
- COPY into main image at /usr/bin/mco-sanitize

### artifacts-collector/collector.sh
- Run mco-sanitize on must-gather directory after sed and before
must-gather-clean
- Fallback to manual REDACTED if mco-sanitize fails (same pattern as CI)

## Verification

Needs integration test: run OPCT with this image, retrieve archive, run
leaktk scan - machineconfig findings should be 0.

Jira: https://redhat.atlassian.net/browse/OPCT-428

---------

Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
## Summary

- Bump tools image from v0.5.0 to v0.6.0 (includes mco-sanitize from PR
#89)
- Bump Fedora base from 41 to 42 to fix security vulnerabilities (per
Marco request)
- Bump tools/VERSION to v0.6.0

Tools image v0.6.0 already built and pushed to quay.io/opct/tools:v0.6.0

Fixes CI build failure from PR #89 merge:
https://github.com/redhat-openshift-ecosystem/provider-certification-plugins/actions/runs/29445777176

---------

Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Fix CI release-latest build failure on arm64. The tools:v0.6.0 arm64
image does not have mco-sanitize (not published for aarch64). Use
wildcard glob so COPY succeeds silently on arm64. collector.sh already
handles the missing binary with manual redaction fallback.

Fixes:
https://github.com/redhat-openshift-ecosystem/provider-certification-plugins/actions/runs/29516430669

Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
## Summary
- Remove the `--file` workaround for kube-conformance plugin (plugin 10)
added in PR #84/#86
- Suite name resolution now works correctly after upstream fixes landed
and were backported (origin#31261, k8s#2694, and backports to 4.21/4.22)
- Fixes upgrade jobs failing with 0/414 tests since June 2026 due to
version skew between pre/post-upgrade binaries

## Context
- Tracked under [OPCT-401](https://redhat.atlassian.net/browse/OPCT-401)
- Slack thread:
https://redhat-internal.slack.com/archives/C04HTQ7A7EX/p1785951340628179
- The `--file` flag was a temporary workaround while
`kubernetes/conformance` suite was unavailable on OCP 4.20+. Now that
upstream backports are merged across 4.21/4.22/5.0, the suite name
drives test selection correctly and `--file` is unnecessary

## Test plan
- [ ] CI periodic upgrade job passes (4.21-upgrade-from-4.20,
4.22-upgrade-from-4.21)
- [ ] Non-upgrade jobs remain unaffected (4.20, 4.21, 4.22, 5.0 aws-ccm)
- [ ] kube-conformance test count matches expected (~419-436 tests)

Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
## Summary

Fix x509 certificate verification failures when running openshift-tests
in-cluster via OPCT/Sonobuoy.

## Problem

The plugin entrypoint scripts run `oc login
--certificate-authority="$SA_CA_PATH"`, which stores the CA as a **file
reference** in the kubeconfig. Some openshift-tests only check
`restConfig.TLSClientConfig.CAData` (not `CAFile`) and fall back to the
system CA pool when it's empty, causing `x509: certificate signed by
unknown authority` failures.

CI/ci-operator embeds the CA **inline** (`certificate-authority-data:
base64`), so these tests pass there.

## Fix

After every `oc login --certificate-authority=...`, add:
```bash
CLUSTER_NAME=$(oc config view --minify -o jsonpath='{.clusters[0].name}')
oc config set-cluster "${CLUSTER_NAME}" \
    --certificate-authority="${SA_CA_PATH}" \
    --embed-certs=true
```

This converts the kubeconfig from file-reference to inline CA data,
matching CI/ci-operator behavior.

## Files modified

- `openshift-tests-plugin/plugin/entrypoint-tests.sh`
- `artifacts-collector/entrypoint-collector.sh` (preserves existing `||
true` error tolerance)

## Related

- Jira: [OPCT-457](https://redhat.atlassian.net/browse/OPCT-457)
- Companion PR for opct (same fix for YAML plugin templates)
- Long-term fix: individual issues against openshift/origin for each
test's CAData-only bug

---
*AI-generated. Review for accuracy.*

@mtulio requested in [Slack
thread](https://redhat-internal.slack.com/archives/C04HTQ7A7EX/p1787104610932349)

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
## Summary
- In upgrade mode, OPCT CLI sets `PLUGIN_BLOCKED_BY` to empty
(conformance plugins skipped)
- `wait-updater` ignored the `--blocker` flag and used hardcoded
`BlockerPlugins` from `NewPlugin()`
  - Collector polled indefinitely for non-existent plugin 80 pod

  ## Changes
  - `wait-updater.go`: early return when `--blocker` is empty
- `entrypoint-collector.sh`: skip `wait-updater` call when
`PLUGIN_BLOCKED_BY` is empty

  ## Test plan
  - [ ] Build image, run `opct run --mode upgrade` on cluster
- [ ] Verify collector starts artifact collection immediately (no
polling loop)
  - [ ] Verify non-upgrade mode still waits for plugin 80 as before

  🤖 Generated with [Claude Code](https://claude.com/claude-code)
  EOF

---------

Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@openshift-ci
openshift-ci Bot requested review from mtulio and rvanderp3 August 25, 2026 11:30
@coderabbitai

coderabbitai Bot commented Aug 25, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: acf87580-69a6-46b3-9c93-979502560316

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@openshift-ci openshift-ci Bot added the lgtm Indicates that a PR is ready to be merged. label Aug 25, 2026
@openshift-ci

openshift-ci Bot commented Aug 25, 2026

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: mtulio

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci openshift-ci Bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Aug 25, 2026
@openshift-merge-bot
openshift-merge-bot Bot merged commit 7d21128 into release-0.6 Aug 25, 2026
15 checks passed
@mtulio
mtulio deleted the release/v0.6.7 branch August 25, 2026 12:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. kind/release lgtm Indicates that a PR is ready to be merged.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants