origin icon indicating copy to clipboard operation
origin copied to clipboard

WIP OCPBUGS-35231: cert-inspection: parse secret/configmap keys as kubeconfigs

Open vrutkovs opened this issue 1 year ago • 11 comments

Extract CA and certs used in kubeconfigs as TLS artifacts too.

Test for https://github.com/openshift/library-go/pull/1746

vrutkovs avatar Jun 10 '24 08:06 vrutkovs

Skipping CI for Draft Pull Request. If you want CI signal for your change, please convert it to an actual PR. You can still manually trigger a test run with /test all

openshift-ci[bot] avatar Jun 10 '24 08:06 openshift-ci[bot]

/test e2e-agnostic-ovn-cmd

vrutkovs avatar Jun 10 '24 08:06 vrutkovs

/test e2e-agnostic-ovn-cmd

vrutkovs avatar Jun 10 '24 11:06 vrutkovs

/test e2e-agnostic-ovn-cmd

vrutkovs avatar Jun 10 '24 12:06 vrutkovs

/payload-job periodic-ci-openshift-release-master-ci-4.17-e2e-aws-ovn periodic-ci-openshift-release-master-ci-4.17-e2e-azure-ovn periodic-ci-openshift-release-master-ci-4.17-e2e-gcp-ovn periodic-ci-openshift-release-master-nightly-4.17-e2e-metal-ipi-ovn-bm periodic-ci-openshift-release-master-nightly-4.17-e2e-vsphere-ovn-serial periodic-ci-openshift-release-master-nightly-4.17-e2e-aws-ovn-single-node

vrutkovs avatar Jun 10 '24 14:06 vrutkovs

@vrutkovs: trigger 6 job(s) for the /payload-(with-prs|job|aggregate|job-with-prs|aggregate-with-prs) command

  • periodic-ci-openshift-release-master-ci-4.17-e2e-aws-ovn
  • periodic-ci-openshift-release-master-ci-4.17-e2e-azure-ovn
  • periodic-ci-openshift-release-master-ci-4.17-e2e-gcp-ovn
  • periodic-ci-openshift-release-master-nightly-4.17-e2e-metal-ipi-ovn-bm
  • periodic-ci-openshift-release-master-nightly-4.17-e2e-vsphere-ovn-serial
  • periodic-ci-openshift-release-master-nightly-4.17-e2e-aws-ovn-single-node

See details on https://pr-payload-tests.ci.openshift.org/runs/ci/e05758c0-2737-11ef-868f-4c0f750867c0-0

openshift-ci[bot] avatar Jun 10 '24 14:06 openshift-ci[bot]

@vrutkovs: This pull request references Jira Issue OCPBUGS-35231, which is valid.

3 validation(s) were run on this bug
  • bug is open, matching expected state (open)
  • bug target version (4.17.0) matches configured target version for branch (4.17.0)
  • bug is in the state POST, which is one of the valid states (NEW, ASSIGNED, POST)

The bug has been updated to refer to the pull request using the external bug tracker.

In response to this:

Extract CA and certs used in kubeconfigs as TLS artifacts too.

Test for https://github.com/openshift/library-go/pull/1746

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

openshift-ci-robot avatar Jun 10 '24 15:06 openshift-ci-robot

Job Failure Risk Analysis for sha: 31836637c6d3f1a90fd2c365e27f21933827204f

Job Name Failure Risk
pull-ci-openshift-origin-master-e2e-aws-ovn-upgrade High
[sig-apps] job-upgrade
This test has passed 100.00% of 313 runs on jobs ['periodic-ci-openshift-release-master-ci-4.17-e2e-aws-ovn-upgrade'] in the last 14 days.

openshift-trt-bot avatar Jul 10 '24 10:07 openshift-trt-bot

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: vrutkovs Once this PR has been reviewed and has the lgtm label, please assign sosiouxme for approval. For more information see the Kubernetes Code Review Process.

The full list of commands accepted by this bot can be found here.

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment Approvers can cancel approval by writing /approve cancel in a comment

openshift-ci[bot] avatar Aug 13 '24 07:08 openshift-ci[bot]

Job Failure Risk Analysis for sha: 9239d9eedeb1140234a8f24473a5b3b0b573eb16

Job Name Failure Risk
pull-ci-openshift-origin-master-e2e-aws-ovn-single-node-upgrade High
[sig-node][invariant] alert/TargetDown should not be at or above info in ns/kube-system
This test has passed 99.98% of 4831 runs on release 4.18 [Overall] in the last week.

Open Bugs
Kubelet metrics endpoints experiencing prolonged outages
pull-ci-openshift-origin-master-e2e-aws-ovn-serial High
[sig-storage] CSI Mock selinux on mount metrics SELinuxMount metrics [LinuxOnly] [Feature:SELinux] [Serial] error is bumped on two Pods with a different context on RWOP volume [FeatureGate:SELinuxMountReadWriteOncePod] [Beta] [Suite:openshift/conformance/serial] [Suite:k8s]
This test has passed 100.00% of 30 runs on jobs ['periodic-ci-openshift-release-master-ci-4.18-e2e-aws-ovn-serial' 'periodic-ci-openshift-release-master-nightly-4.18-e2e-aws-ovn-serial'] in the last 14 days.
---
[sig-storage] CSI Mock selinux on mount metrics SELinuxMount metrics [LinuxOnly] [Feature:SELinux] [Serial] warning is bumped on two Pods with a different context on RWO volume [FeatureGate:SELinuxMountReadWriteOncePod] [Beta] [Feature:SELinuxMountReadWriteOncePodOnly] [Suite:openshift/conformance/serial] [Suite:k8s]
This test has passed 100.00% of 30 runs on jobs ['periodic-ci-openshift-release-master-ci-4.18-e2e-aws-ovn-serial' 'periodic-ci-openshift-release-master-nightly-4.18-e2e-aws-ovn-serial'] in the last 14 days.

openshift-trt-bot avatar Aug 13 '24 10:08 openshift-trt-bot

Job Failure Risk Analysis for sha: daaf7cc7e309b8dc6248ec7397e911ab37079f7d

Job Name Failure Risk
pull-ci-openshift-origin-master-e2e-aws-ovn-ipsec-serial IncompleteTests
Tests for this run (18) are below the historical average (606): IncompleteTests (not enough tests ran to make a reasonable risk analysis; this could be due to infra, installation, or upgrade problems)
pull-ci-openshift-origin-master-e2e-aws-csi IncompleteTests
Tests for this run (16) are below the historical average (763): IncompleteTests (not enough tests ran to make a reasonable risk analysis; this could be due to infra, installation, or upgrade problems)

openshift-trt-bot avatar Sep 05 '24 13:09 openshift-trt-bot

@vrutkovs: The following tests failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test name Commit Details Required Rerun command
ci/prow/e2e-aws-ovn-upgrade eecb0d34ba2822dc931abd646f3da1815c8f2965 link false /test e2e-aws-ovn-upgrade
ci/prow/e2e-aws-ovn-ipsec-serial eecb0d34ba2822dc931abd646f3da1815c8f2965 link false /test e2e-aws-ovn-ipsec-serial
ci/prow/e2e-metal-ipi-ovn eecb0d34ba2822dc931abd646f3da1815c8f2965 link false /test e2e-metal-ipi-ovn
ci/prow/e2e-aws-ovn-serial eecb0d34ba2822dc931abd646f3da1815c8f2965 link true /test e2e-aws-ovn-serial
ci/prow/e2e-gcp-csi eecb0d34ba2822dc931abd646f3da1815c8f2965 link false /test e2e-gcp-csi

Full PR test history. Your PR dashboard.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

openshift-ci[bot] avatar Sep 05 '24 16:09 openshift-ci[bot]

Job Failure Risk Analysis for sha: eecb0d34ba2822dc931abd646f3da1815c8f2965

Job Name Failure Risk
pull-ci-openshift-origin-master-e2e-aws-ovn-serial High
[sig-node] static pods should start after being created
This test has passed 100.00% of 44 runs on jobs ['periodic-ci-openshift-release-master-ci-4.18-e2e-aws-ovn-serial' 'periodic-ci-openshift-release-master-nightly-4.18-e2e-aws-ovn-serial'] in the last 14 days.

Open Bugs
Static pod controller pods sometimes fail to start
pull-ci-openshift-origin-master-e2e-gcp-csi IncompleteTests
Tests for this run (14) are below the historical average (786): IncompleteTests (not enough tests ran to make a reasonable risk analysis; this could be due to infra, installation, or upgrade problems)

openshift-trt-bot avatar Sep 05 '24 17:09 openshift-trt-bot

@vrutkovs: This pull request references Jira Issue OCPBUGS-35231. The bug has been updated to no longer refer to the pull request using the external bug tracker.

In response to this:

Extract CA and certs used in kubeconfigs as TLS artifacts too.

Test for https://github.com/openshift/library-go/pull/1746

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

openshift-ci-robot avatar Sep 06 '24 07:09 openshift-ci-robot