api icon indicating copy to clipboard operation
api copied to clipboard

API-1843: FeatureGate KMSv2

Open swghosh opened this issue 1 year ago • 4 comments

This feature is primarily targeted for SelfManagedHA OpenShift TechPreview.

swghosh avatar Sep 20 '24 08:09 swghosh

Skipping CI for Draft Pull Request. If you want CI signal for your change, please convert it to an actual PR. You can still manually trigger a test run with /test all

openshift-ci[bot] avatar Sep 20 '24 08:09 openshift-ci[bot]

Hello @swghosh! Some important instructions when contributing to openshift/api: API design plays an important part in the user experience of OpenShift and as such API PRs are subject to a high level of scrutiny to ensure they follow our best practices. If you haven't already done so, please review the OpenShift API Conventions and ensure that your proposed changes are compliant. Following these conventions will help expedite the api review process for your PR.

openshift-ci[bot] avatar Sep 20 '24 08:09 openshift-ci[bot]

@swghosh: This pull request references API-1843 which is a valid jira issue.

Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the task to target the "4.18.0" version, but no target version was set.

In response to this:

This feature is primarily targeted for SelfManagedHA OpenShift TechPreview.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

openshift-ci-robot avatar Sep 23 '24 08:09 openshift-ci-robot

/cc @dgrisonnet @tkashem

swghosh avatar Sep 26 '24 12:09 swghosh

/hold per https://github.com/openshift/api/pull/2071#issuecomment-2431322266

JoelSpeed avatar Oct 23 '24 08:10 JoelSpeed

/remove-hold @JoelSpeed feel free to re-review, thanks!

swghosh avatar Oct 24 '24 15:10 swghosh

The EP for this feature doesn't yet have any review, lets get some initial review going on the EP first before we get too much into perfecting the API (else it may change massively based on EP feedback from other stakeholders)

JoelSpeed avatar Oct 24 '24 16:10 JoelSpeed

@swghosh: This pull request references API-1843 which is a valid jira issue.

Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the task to target the "4.18.0" version, but no target version was set.

In response to this:

This feature is primarily targeted for SelfManagedHA OpenShift TechPreview.

Feature Gate PR: https://github.com/openshift/api/pull/2071

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

openshift-ci-robot avatar Oct 25 '24 10:10 openshift-ci-robot

/retest

dgrisonnet avatar Nov 21 '24 05:11 dgrisonnet

this looks good to me for techpreview

/lgtm

tkashem avatar Nov 21 '24 14:11 tkashem

/retest

swghosh avatar Nov 22 '24 07:11 swghosh

updated the integration test suite to be more verbose and specific about the error checks.

swghosh avatar Nov 27 '24 12:11 swghosh

/retest

swghosh avatar Dec 03 '24 06:12 swghosh

API is looking good, need to get the gate merged and go from there

Are the team happy with the shape of this API? How has feedback on the EP been?

JoelSpeed avatar Dec 10 '24 14:12 JoelSpeed

/payload 4.18 ci blocking /payload 4.18 nightly blocking /payload 4.19 ci blocking /payload 4.19 nightly blocking

swghosh avatar Dec 19 '24 14:12 swghosh

@swghosh: trigger 4 job(s) of type blocking for the ci release of OCP 4.18

  • periodic-ci-openshift-release-master-ci-4.18-upgrade-from-stable-4.17-e2e-aws-ovn-upgrade
  • periodic-ci-openshift-release-master-ci-4.18-upgrade-from-stable-4.17-e2e-azure-ovn-upgrade
  • periodic-ci-openshift-release-master-ci-4.18-e2e-gcp-ovn-upgrade
  • periodic-ci-openshift-hypershift-release-4.18-periodics-e2e-aws-ovn

See details on https://pr-payload-tests.ci.openshift.org/runs/ci/9dbe3bb0-be17-11ef-999e-1bab93b98ddb-0

trigger 13 job(s) of type blocking for the nightly release of OCP 4.18

  • periodic-ci-openshift-release-master-ci-4.18-e2e-aws-upgrade-ovn-single-node
  • periodic-ci-openshift-release-master-ci-4.18-e2e-aws-ovn-upgrade
  • periodic-ci-openshift-release-master-ci-4.18-e2e-azure-ovn-upgrade
  • periodic-ci-openshift-release-master-ci-4.18-upgrade-from-stable-4.17-e2e-gcp-ovn-rt-upgrade
  • periodic-ci-openshift-hypershift-release-4.18-periodics-e2e-aws-ovn-conformance
  • periodic-ci-openshift-release-master-nightly-4.18-e2e-aws-ovn-serial
  • periodic-ci-openshift-release-master-ci-4.18-e2e-aws-ovn-techpreview
  • periodic-ci-openshift-release-master-ci-4.18-e2e-aws-ovn-techpreview-serial
  • periodic-ci-openshift-release-master-nightly-4.18-fips-payload-scan
  • periodic-ci-openshift-release-master-nightly-4.18-e2e-metal-ipi-ovn-bm
  • periodic-ci-openshift-release-master-nightly-4.18-e2e-metal-ipi-ovn-ipv6
  • periodic-ci-openshift-microshift-release-4.18-periodics-e2e-aws-ovn-ocp-conformance
  • periodic-ci-openshift-microshift-release-4.18-periodics-e2e-aws-ovn-ocp-conformance-serial

See details on https://pr-payload-tests.ci.openshift.org/runs/ci/9dbe3bb0-be17-11ef-999e-1bab93b98ddb-1

trigger 4 job(s) of type blocking for the ci release of OCP 4.19

  • periodic-ci-openshift-release-master-ci-4.19-upgrade-from-stable-4.18-e2e-aws-ovn-upgrade
  • periodic-ci-openshift-release-master-ci-4.19-upgrade-from-stable-4.18-e2e-azure-ovn-upgrade
  • periodic-ci-openshift-release-master-ci-4.19-e2e-gcp-ovn-upgrade
  • periodic-ci-openshift-hypershift-release-4.19-periodics-e2e-aws-ovn

See details on https://pr-payload-tests.ci.openshift.org/runs/ci/9dbe3bb0-be17-11ef-999e-1bab93b98ddb-2

trigger 13 job(s) of type blocking for the nightly release of OCP 4.19

  • periodic-ci-openshift-release-master-ci-4.19-e2e-aws-upgrade-ovn-single-node
  • periodic-ci-openshift-release-master-ci-4.19-e2e-aws-ovn-upgrade
  • periodic-ci-openshift-release-master-ci-4.19-e2e-azure-ovn-upgrade
  • periodic-ci-openshift-release-master-ci-4.19-upgrade-from-stable-4.18-e2e-gcp-ovn-rt-upgrade
  • periodic-ci-openshift-hypershift-release-4.19-periodics-e2e-aws-ovn-conformance
  • periodic-ci-openshift-release-master-nightly-4.19-e2e-aws-ovn-serial
  • periodic-ci-openshift-release-master-ci-4.19-e2e-aws-ovn-techpreview
  • periodic-ci-openshift-release-master-ci-4.19-e2e-aws-ovn-techpreview-serial
  • periodic-ci-openshift-release-master-nightly-4.19-fips-payload-scan
  • periodic-ci-openshift-release-master-nightly-4.19-e2e-metal-ipi-ovn-bm
  • periodic-ci-openshift-release-master-nightly-4.19-e2e-metal-ipi-ovn-ipv6
  • periodic-ci-openshift-microshift-release-4.19-periodics-e2e-aws-ovn-ocp-conformance
  • periodic-ci-openshift-microshift-release-4.19-periodics-e2e-aws-ovn-ocp-conformance-serial

See details on https://pr-payload-tests.ci.openshift.org/runs/ci/9dbe3bb0-be17-11ef-999e-1bab93b98ddb-3

openshift-ci[bot] avatar Dec 19 '24 14:12 openshift-ci[bot]

@swghosh: This pull request references API-1843 which is a valid jira issue.

Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the task to target the "4.19.0" version, but no target version was set.

In response to this:

Adds API fields for KMS based encryption enablement via configv1.APIServer through it's spec.encryptionType, AWS KMS config added as the initial KMS encryption provider.

This feature is primarily targeted for SelfManagedHA OpenShift and is considered for TechPreview.

  • [x] Feature Gate: openshift/api#2071
  • [ ] Enhancement: https://github.com/openshift/enhancements/pull/1682

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

openshift-ci-robot avatar Feb 24 '25 14:02 openshift-ci-robot

/test all

swghosh avatar Feb 24 '25 14:02 swghosh

/retest

swghosh avatar Feb 24 '25 19:02 swghosh

/retest

swghosh avatar Feb 25 '25 07:02 swghosh

/retest

swghosh avatar Mar 12 '25 16:03 swghosh

/retest

swghosh avatar Mar 12 '25 20:03 swghosh

/retest

swghosh avatar Mar 21 '25 10:03 swghosh

/lgtm

JoelSpeed avatar Mar 21 '25 11:03 JoelSpeed

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: dgrisonnet, JoelSpeed, swghosh, tkashem

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment Approvers can cancel approval by writing /approve cancel in a comment

openshift-ci[bot] avatar Mar 21 '25 11:03 openshift-ci[bot]

/test all

swghosh avatar Mar 21 '25 12:03 swghosh

/label acknowledge-critical-fixes-only (requirement added for the next week: Shift Week) This is a low risk change and API fields are well gated behind TechPreview. It should not affect our OpenShift payload.

swghosh avatar Mar 21 '25 13:03 swghosh

/retest-required

Remaining retests: 0 against base HEAD 75d64d71980b0e5f126c9a8b0c9423a808adc3e2 and 2 for PR HEAD 8ada9f6298816a2157234eebfdeecba60aff2626 in total

openshift-ci-robot avatar Mar 21 '25 14:03 openshift-ci-robot

/retest-required

swghosh avatar Mar 21 '25 17:03 swghosh

/test e2e-aws-ovn-hypershift

swghosh avatar Mar 21 '25 21:03 swghosh