origin icon indicating copy to clipboard operation
origin copied to clipboard

AUTH-539: Expose image to unauthenticated test

Open ShazaAldawamneh opened this issue 1 year ago • 42 comments
trafficstars

Create a test that exposes an internal image in OpenShift to unauthenticated users.

ShazaAldawamneh avatar Sep 10 '24 09:09 ShazaAldawamneh

Job Failure Risk Analysis for sha: f5a0b7afcd61dfff2f5db95ac1b8d81a76ad8c8c

Job Name Failure Risk
pull-ci-openshift-origin-master-e2e-openstack-ovn IncompleteTests
Tests for this run (15) are below the historical average (1649): IncompleteTests (not enough tests ran to make a reasonable risk analysis; this could be due to infra, installation, or upgrade problems)
pull-ci-openshift-origin-master-e2e-metal-ipi-ovn-kube-apiserver-rollout IncompleteTests
Tests for this run (13) are below the historical average (858): IncompleteTests (not enough tests ran to make a reasonable risk analysis; this could be due to infra, installation, or upgrade problems)
pull-ci-openshift-origin-master-e2e-metal-ipi-ovn-ipv6 IncompleteTests
Tests for this run (13) are below the historical average (2024): IncompleteTests (not enough tests ran to make a reasonable risk analysis; this could be due to infra, installation, or upgrade problems)
pull-ci-openshift-origin-master-e2e-metal-ipi-ovn IncompleteTests
Tests for this run (13) are below the historical average (1959): IncompleteTests (not enough tests ran to make a reasonable risk analysis; this could be due to infra, installation, or upgrade problems)
pull-ci-openshift-origin-master-e2e-gcp-ovn-upgrade IncompleteTests
Tests for this run (17) are below the historical average (807): IncompleteTests (not enough tests ran to make a reasonable risk analysis; this could be due to infra, installation, or upgrade problems)
pull-ci-openshift-origin-master-e2e-gcp-ovn-rt-upgrade IncompleteTests
Tests for this run (17) are below the historical average (702): IncompleteTests (not enough tests ran to make a reasonable risk analysis; this could be due to infra, installation, or upgrade problems)
pull-ci-openshift-origin-master-e2e-gcp-ovn-builds IncompleteTests
Tests for this run (17) are below the historical average (776): IncompleteTests (not enough tests ran to make a reasonable risk analysis; this could be due to infra, installation, or upgrade problems)
pull-ci-openshift-origin-master-e2e-gcp-ovn IncompleteTests
Tests for this run (17) are below the historical average (1706): IncompleteTests (not enough tests ran to make a reasonable risk analysis; this could be due to infra, installation, or upgrade problems)
pull-ci-openshift-origin-master-e2e-gcp-csi IncompleteTests
Tests for this run (17) are below the historical average (722): IncompleteTests (not enough tests ran to make a reasonable risk analysis; this could be due to infra, installation, or upgrade problems)
pull-ci-openshift-origin-master-e2e-aws-ovn-upgrade IncompleteTests
Tests for this run (18) are below the historical average (646): IncompleteTests (not enough tests ran to make a reasonable risk analysis; this could be due to infra, installation, or upgrade problems)
pull-ci-openshift-origin-master-e2e-aws-ovn-single-node-upgrade IncompleteTests
Tests for this run (17) are below the historical average (2037): IncompleteTests (not enough tests ran to make a reasonable risk analysis; this could be due to infra, installation, or upgrade problems)
pull-ci-openshift-origin-master-e2e-aws-ovn-single-node-serial IncompleteTests
Tests for this run (16) are below the historical average (720): IncompleteTests (not enough tests ran to make a reasonable risk analysis; this could be due to infra, installation, or upgrade problems)
pull-ci-openshift-origin-master-e2e-aws-ovn-single-node IncompleteTests
Tests for this run (16) are below the historical average (1561): IncompleteTests (not enough tests ran to make a reasonable risk analysis; this could be due to infra, installation, or upgrade problems)
pull-ci-openshift-origin-master-e2e-aws-ovn-serial IncompleteTests
Tests for this run (16) are below the historical average (710): IncompleteTests (not enough tests ran to make a reasonable risk analysis; this could be due to infra, installation, or upgrade problems)
pull-ci-openshift-origin-master-e2e-aws-ovn-microshift-serial IncompleteTests
Tests for this run (15) are below the historical average (494): IncompleteTests (not enough tests ran to make a reasonable risk analysis; this could be due to infra, installation, or upgrade problems)
pull-ci-openshift-origin-master-e2e-aws-ovn-microshift IncompleteTests
Tests for this run (15) are below the historical average (1319): IncompleteTests (not enough tests ran to make a reasonable risk analysis; this could be due to infra, installation, or upgrade problems)
pull-ci-openshift-origin-master-e2e-aws-ovn-kube-apiserver-rollout IncompleteTests
Tests for this run (16) are below the historical average (671): IncompleteTests (not enough tests ran to make a reasonable risk analysis; this could be due to infra, installation, or upgrade problems)
pull-ci-openshift-origin-master-e2e-aws-ovn-ipsec-serial IncompleteTests
Tests for this run (18) are below the historical average (571): IncompleteTests (not enough tests ran to make a reasonable risk analysis; this could be due to infra, installation, or upgrade problems)
pull-ci-openshift-origin-master-e2e-aws-ovn-fips IncompleteTests
Tests for this run (16) are below the historical average (1780): IncompleteTests (not enough tests ran to make a reasonable risk analysis; this could be due to infra, installation, or upgrade problems)
pull-ci-openshift-origin-master-e2e-aws-ovn-edge-zones IncompleteTests
Tests for this run (17) are below the historical average (1748): IncompleteTests (not enough tests ran to make a reasonable risk analysis; this could be due to infra, installation, or upgrade problems)

Showing 20 of 23 jobs analysis

openshift-trt-bot avatar Sep 10 '24 13:09 openshift-trt-bot

Job Failure Risk Analysis for sha: 6ef72a6a2bab933d3a383d2bcc95226eb6f73e6f

Job Name Failure Risk
pull-ci-openshift-origin-master-e2e-metal-ipi-ovn-ipv6 IncompleteTests
Tests for this run (100) are below the historical average (2004): IncompleteTests (not enough tests ran to make a reasonable risk analysis; this could be due to infra, installation, or upgrade problems)

openshift-trt-bot avatar Sep 11 '24 16:09 openshift-trt-bot

Job Failure Risk Analysis for sha: e798f165cb8023621c2d6986f63c39b3247bd492

Job Name Failure Risk
pull-ci-openshift-origin-master-e2e-aws-ovn-upgrade High
[sig-apps] job-upgrade
This test has passed 100.00% of 441 runs on jobs ['periodic-ci-openshift-release-master-ci-4.18-e2e-aws-ovn-upgrade'] in the last 14 days.
pull-ci-openshift-origin-master-e2e-aws-ovn-kube-apiserver-rollout Low
[Conformance][Suite:openshift/kube-apiserver/rollout][Jira:"kube-apiserver"][sig-kube-apiserver] kube-apiserver should roll out new revisions without disruption [apigroup:config.openshift.io][apigroup:operator.openshift.io]
This test has passed 78.57% of 14 runs on jobs ['periodic-ci-openshift-release-master-nightly-4.18-e2e-aws-ovn-kube-apiserver-rollout'] in the last 14 days.

openshift-trt-bot avatar Sep 17 '24 11:09 openshift-trt-bot

/retest-required

ShazaAldawamneh avatar Sep 18 '24 07:09 ShazaAldawamneh

Job Failure Risk Analysis for sha: 6f37657f36c3f0362216bb8f379b317a9fed7217

Job Name Failure Risk
pull-ci-openshift-origin-master-e2e-aws-ovn-single-node Medium
[sig-network] pods should successfully create sandboxes by getting pod
This test has passed 96.15% of 52 runs on jobs ['periodic-ci-openshift-release-master-nightly-4.18-e2e-aws-ovn-single-node'] in the last 14 days.

openshift-trt-bot avatar Sep 18 '24 12:09 openshift-trt-bot

/jira refresh

ShazaAldawamneh avatar Sep 18 '24 13:09 ShazaAldawamneh

@ShazaAldawamneh: No Jira issue is referenced in the title of this pull request. To reference a jira issue, add 'XYZ-NNN:' to the title of this pull request and request another refresh with /jira refresh.

In response to this:

/jira refresh

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

openshift-ci-robot avatar Sep 18 '24 13:09 openshift-ci-robot

@ShazaAldawamneh: This pull request references AUTH-539 which is a valid jira issue.

Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the story to target the "4.18.0" version, but no target version was set.

In response to this:

Create a test that exposes an internal image in OpenShift to unauthenticated users.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

openshift-ci-robot avatar Sep 18 '24 14:09 openshift-ci-robot

/retest-required

ShazaAldawamneh avatar Sep 20 '24 09:09 ShazaAldawamneh

/lgtm

vrutkovs avatar Sep 26 '24 13:09 vrutkovs

/retest-required

ShazaAldawamneh avatar Oct 02 '24 09:10 ShazaAldawamneh

/retest-required

ShazaAldawamneh avatar Oct 07 '24 08:10 ShazaAldawamneh

Job Failure Risk Analysis for sha: 88537a86c3e3f45ec5a410587217f01ca2941874

Job Name Failure Risk
pull-ci-openshift-origin-master-e2e-aws-ovn-single-node-upgrade High
[sig-api-machinery] disruption/oauth-api connection/reused should be available throughout the test
This test has passed 99.92% of 6624 runs on release 4.18 [Overall] in the last week.
---
[sig-api-machinery] disruption/kube-api connection/reused should be available throughout the test
This test has passed 99.89% of 6624 runs on release 4.18 [Overall] in the last week.
---
[sig-api-machinery] disruption/oauth-api connection/new should be available throughout the test
This test has passed 99.94% of 6624 runs on release 4.18 [Overall] in the last week.
---
[sig-api-machinery] disruption/kube-api connection/new should be available throughout the test
This test has passed 99.74% of 6623 runs on release 4.18 [Overall] in the last week.

openshift-trt-bot avatar Oct 07 '24 12:10 openshift-trt-bot

Job Failure Risk Analysis for sha: 1f7388bdd8f5ec226da8cbe6a31439e0698f7784

Job Name Failure Risk
pull-ci-openshift-origin-master-e2e-aws-ovn-single-node-upgrade Medium
[sig-node] static pods should start after being created
This test has passed 83.24% of 185 runs on release 4.18 [Architecture:amd64 FeatureSet:default Installer:ipi Network:ovn NetworkStack:ipv4 Platform:aws SecurityMode:default Topology:single Upgrade:micro] in the last week.

Open Bugs
Static pod controller pods sometimes fail to start
---
[sig-node] static pods should start after being created
This test has passed 83.24% of 185 runs on release 4.18 [Architecture:amd64 FeatureSet:default Installer:ipi Network:ovn NetworkStack:ipv4 Platform:aws SecurityMode:default Topology:single Upgrade:micro] in the last week.

Open Bugs
Static pod controller pods sometimes fail to start

openshift-trt-bot avatar Oct 14 '24 13:10 openshift-trt-bot

/lgtm

ibihim avatar Oct 16 '24 13:10 ibihim

We should consider to make it dynamic, to not rely on host+"/openshift/tools:latest", but pick something dynamically from the openshift namespace.

ibihim avatar Oct 16 '24 13:10 ibihim

/test e2e-aws-ovn-single-node-upgrade

neisw avatar Nov 07 '24 12:11 neisw

Noticed failures in single-node-e2e-test/build-log.txt

  Summarizing 1 Failure:
    [FAIL] [sig-auth][Feature:OpenShiftAuthorization] ImageRegistry access  PublicImageAccessWithBasicAuthShouldSucceed [It] should succeed [apigroup:image.openshift.io] [Suite:openshift/conformance/parallel]
    github.com/openshift/origin/test/extended/authorization/authorization.go:1270

neisw avatar Nov 07 '24 12:11 neisw

/retest-required

ibihim avatar Nov 21 '24 15:11 ibihim

New changes are detected. LGTM label has been removed.

openshift-ci[bot] avatar Nov 25 '24 14:11 openshift-ci[bot]

Job Failure Risk Analysis for sha: 027b9059579558cc3eeee5f7cc6a6b557deaa665

Job Name Failure Risk
pull-ci-openshift-origin-master-e2e-aws-ovn-kube-apiserver-rollout Medium
[Conformance][Suite:openshift/kube-apiserver/rollout][Jira:"kube-apiserver"][sig-kube-apiserver] kube-apiserver should roll out new revisions without disruption [apigroup:config.openshift.io][apigroup:operator.openshift.io]
This test has passed 84.21% of 19 runs on jobs ['periodic-ci-openshift-release-master-nightly-4.19-e2e-aws-ovn-kube-apiserver-rollout' 'periodic-ci-openshift-release-master-nightly-4.18-e2e-aws-ovn-kube-apiserver-rollout'] in the last 14 days.

openshift-trt[bot] avatar Nov 25 '24 18:11 openshift-trt[bot]

Job Failure Risk Analysis for sha: 98ef102dcec3db8fb2713b6ee32ce5071c8da071

Job Name Failure Risk
pull-ci-openshift-origin-master-e2e-aws-ovn-kube-apiserver-rollout Low
[Conformance][Suite:openshift/kube-apiserver/rollout][Jira:"kube-apiserver"][sig-kube-apiserver] kube-apiserver should roll out new revisions without disruption [apigroup:config.openshift.io][apigroup:operator.openshift.io]
This test has passed 66.67% of 6 runs on release 4.19 [Architecture:amd64 FeatureSet:default Installer:ipi Network:ovn NetworkStack:ipv4 Platform:aws SecurityMode:default Topology:ha Upgrade:none] in the last week.

openshift-trt[bot] avatar Nov 26 '24 15:11 openshift-trt[bot]

Job Failure Risk Analysis for sha: f2afd8234a1aec2ad96b4eaa3ef47cdf35391415

Job Name Failure Risk
pull-ci-openshift-origin-master-e2e-aws-ovn-kube-apiserver-rollout Low
[Conformance][Suite:openshift/kube-apiserver/rollout][Jira:"kube-apiserver"][sig-kube-apiserver] kube-apiserver should roll out new revisions without disruption [apigroup:config.openshift.io][apigroup:operator.openshift.io]
This test has passed 73.91% of 23 runs on jobs ['periodic-ci-openshift-release-master-nightly-4.19-e2e-aws-ovn-kube-apiserver-rollout' 'periodic-ci-openshift-release-master-nightly-4.18-e2e-aws-ovn-kube-apiserver-rollout'] in the last 14 days.

openshift-trt[bot] avatar Nov 28 '24 16:11 openshift-trt[bot]

/retest-required

ShazaAldawamneh avatar Dec 02 '24 10:12 ShazaAldawamneh

Job Failure Risk Analysis for sha: 7dc46a4b562676685557e342f6e22b5e4850870b

Job Name Failure Risk
pull-ci-openshift-origin-master-okd-scos-e2e-aws-ovn High
[sig-arch] Only known images used by tests
This test has passed 100.00% of 32 runs on jobs ['periodic-ci-openshift-release-master-ci-4.19-e2e-aws-ovn'] in the last 14 days.
pull-ci-openshift-origin-master-e2e-aws-ovn-single-node IncompleteTests
Tests for this run (17) are below the historical average (1554): IncompleteTests (not enough tests ran to make a reasonable risk analysis; this could be due to infra, installation, or upgrade problems)
pull-ci-openshift-origin-master-e2e-aws-ovn-microshift-serial IncompleteTests
Tests for this run (15) are below the historical average (409): IncompleteTests (not enough tests ran to make a reasonable risk analysis; this could be due to infra, installation, or upgrade problems)
pull-ci-openshift-origin-master-e2e-aws-ovn-microshift IncompleteTests
Tests for this run (15) are below the historical average (907): IncompleteTests (not enough tests ran to make a reasonable risk analysis; this could be due to infra, installation, or upgrade problems)
pull-ci-openshift-origin-master-e2e-aws-ovn-fips IncompleteTests
Tests for this run (17) are below the historical average (1795): IncompleteTests (not enough tests ran to make a reasonable risk analysis; this could be due to infra, installation, or upgrade problems)
pull-ci-openshift-origin-master-e2e-aws-ovn-edge-zones IncompleteTests
Tests for this run (18) are below the historical average (2215): IncompleteTests (not enough tests ran to make a reasonable risk analysis; this could be due to infra, installation, or upgrade problems)
pull-ci-openshift-origin-master-e2e-agnostic-ovn-cmd IncompleteTests
Tests for this run (18) are below the historical average (1083): IncompleteTests (not enough tests ran to make a reasonable risk analysis; this could be due to infra, installation, or upgrade problems)

openshift-trt[bot] avatar Dec 02 '24 21:12 openshift-trt[bot]

Job Failure Risk Analysis for sha: f344ee141284b6b60c126280512b83edc02bec29

Job Name Failure Risk
pull-ci-openshift-origin-master-e2e-aws-ovn-single-node-upgrade IncompleteTests
Tests for this run (26) are below the historical average (2509): IncompleteTests (not enough tests ran to make a reasonable risk analysis; this could be due to infra, installation, or upgrade problems)
pull-ci-openshift-origin-master-e2e-aws-ovn-kube-apiserver-rollout Low
[Conformance][Suite:openshift/kube-apiserver/rollout][Jira:"kube-apiserver"][sig-kube-apiserver] kube-apiserver should roll out new revisions without disruption [apigroup:config.openshift.io][apigroup:operator.openshift.io]
This test has passed 69.23% of 26 runs on jobs ['periodic-ci-openshift-release-master-nightly-4.19-e2e-aws-ovn-kube-apiserver-rollout' 'periodic-ci-openshift-release-master-nightly-4.18-e2e-aws-ovn-kube-apiserver-rollout'] in the last 14 days.

openshift-trt[bot] avatar Dec 03 '24 16:12 openshift-trt[bot]

/retest-required

ShazaAldawamneh avatar Dec 20 '24 10:12 ShazaAldawamneh

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: ibihim, ShazaAldawamneh, vrutkovs Once this PR has been reviewed and has the lgtm label, please assign neisw for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment Approvers can cancel approval by writing /approve cancel in a comment

openshift-ci[bot] avatar Jan 08 '25 12:01 openshift-ci[bot]

/retest-required

ShazaAldawamneh avatar Jan 08 '25 13:01 ShazaAldawamneh

Job Failure Risk Analysis for sha: e01ff31e5307d97d04a95fd9df77f2b841e6a274

Job Name Failure Risk
pull-ci-openshift-origin-master-e2e-metal-ipi-ovn-ipv6 IncompleteTests
Tests for this run (14) are below the historical average (2900): IncompleteTests (not enough tests ran to make a reasonable risk analysis; this could be due to infra, installation, or upgrade problems)
pull-ci-openshift-origin-master-e2e-gcp-ovn-upgrade IncompleteTests
Tests for this run (18) are below the historical average (1922): IncompleteTests (not enough tests ran to make a reasonable risk analysis; this could be due to infra, installation, or upgrade problems)
pull-ci-openshift-origin-master-e2e-gcp-ovn IncompleteTests
Tests for this run (18) are below the historical average (3066): IncompleteTests (not enough tests ran to make a reasonable risk analysis; this could be due to infra, installation, or upgrade problems)
pull-ci-openshift-origin-master-e2e-aws-ovn-single-node-upgrade IncompleteTests
Tests for this run (18) are below the historical average (4520): IncompleteTests (not enough tests ran to make a reasonable risk analysis; this could be due to infra, installation, or upgrade problems)
pull-ci-openshift-origin-master-e2e-aws-ovn-serial IncompleteTests
Tests for this run (17) are below the historical average (1969): IncompleteTests (not enough tests ran to make a reasonable risk analysis; this could be due to infra, installation, or upgrade problems)
pull-ci-openshift-origin-master-e2e-aws-ovn-microshift-serial IncompleteTests
Tests for this run (15) are below the historical average (622): IncompleteTests (not enough tests ran to make a reasonable risk analysis; this could be due to infra, installation, or upgrade problems)
pull-ci-openshift-origin-master-e2e-aws-ovn-microshift IncompleteTests
Tests for this run (15) are below the historical average (1375): IncompleteTests (not enough tests ran to make a reasonable risk analysis; this could be due to infra, installation, or upgrade problems)
pull-ci-openshift-origin-master-e2e-aws-ovn-fips IncompleteTests
Tests for this run (17) are below the historical average (3117): IncompleteTests (not enough tests ran to make a reasonable risk analysis; this could be due to infra, installation, or upgrade problems)
pull-ci-openshift-origin-master-e2e-aws-ovn-edge-zones IncompleteTests
Tests for this run (18) are below the historical average (3196): IncompleteTests (not enough tests ran to make a reasonable risk analysis; this could be due to infra, installation, or upgrade problems)

openshift-trt[bot] avatar Jan 08 '25 14:01 openshift-trt[bot]