configuration-anomaly-detection icon indicating copy to clipboard operation
configuration-anomaly-detection copied to clipboard

SREP-11 - Enforce informing mode on new investigations

Open MateSaary opened this issue 8 months ago • 7 comments

This PR adds an informing-only status to investigations' write actions. Informing mode is set to true upon investigation creation from boilerplate. It also adds a script to test the validity of RBAC permissions (i.e write operations are restricted on informing-mode investigations) The PR also removes an unused function in insightsoperatordown.go, and redundant info of the removed deploy directory (see #427).

MateSaary avatar May 02 '25 20:05 MateSaary

Skipping CI for Draft Pull Request. If you want CI signal for your change, please convert it to an actual PR. You can still manually trigger a test run with /test all

openshift-ci[bot] avatar May 02 '25 20:05 openshift-ci[bot]

Codecov Report

Attention: Patch coverage is 12.19512% with 36 lines in your changes missing coverage. Please review.

Project coverage is 31.63%. Comparing base (656441f) to head (0e29f2d).

Files with missing lines Patch % Lines
pkg/ocm/ocm.go 0.00% 8 Missing :warning:
pkg/investigations/cpd/cpd.go 0.00% 5 Missing :warning:
pkg/investigations/chgm/chgm.go 20.00% 4 Missing :warning:
pkg/ocm/mock/ocmmock.go 50.00% 4 Missing :warning:
pkg/investigations/ccam/ccam.go 0.00% 3 Missing :warning:
...rrorbudgetburn/clustermonitoringerrorbudgetburn.go 0.00% 3 Missing :warning:
...tigations/apierrorbudgetburn/apierrorbudgetburn.go 0.00% 2 Missing :warning:
...nnotretrieveupdatessre/cannotretrieveupdatessre.go 0.00% 2 Missing :warning:
...e/machinehealthcheckunterminatedshortcircuitsre.go 0.00% 2 Missing :warning:
...cfailureover4hr/upgradeconfigsyncfailureover4hr.go 0.00% 2 Missing :warning:
... and 1 more
Additional details and impacted files

Impacted file tree graph

@@            Coverage Diff             @@
##             main     #432      +/-   ##
==========================================
- Coverage   31.92%   31.63%   -0.30%     
==========================================
  Files          36       36              
  Lines        2487     2510      +23     
==========================================
  Hits          794      794              
- Misses       1632     1655      +23     
  Partials       61       61              
Files with missing lines Coverage Δ
...tions/insightsoperatordown/insightsoperatordown.go 8.45% <0.00%> (ø)
...tigations/apierrorbudgetburn/apierrorbudgetburn.go 0.00% <0.00%> (ø)
...nnotretrieveupdatessre/cannotretrieveupdatessre.go 26.22% <0.00%> (-0.89%) :arrow_down:
...e/machinehealthcheckunterminatedshortcircuitsre.go 49.71% <0.00%> (-0.59%) :arrow_down:
...cfailureover4hr/upgradeconfigsyncfailureover4hr.go 19.71% <0.00%> (-0.58%) :arrow_down:
pkg/investigations/ccam/ccam.go 36.58% <0.00%> (-1.88%) :arrow_down:
...rrorbudgetburn/clustermonitoringerrorbudgetburn.go 10.86% <0.00%> (-0.50%) :arrow_down:
pkg/investigations/chgm/chgm.go 60.37% <20.00%> (-0.58%) :arrow_down:
pkg/ocm/mock/ocmmock.go 42.66% <50.00%> (ø)
pkg/investigations/cpd/cpd.go 0.00% <0.00%> (ø)
... and 1 more
:rocket: New features to boost your workflow:
  • :snowflake: Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

codecov-commenter avatar May 12 '25 01:05 codecov-commenter

/retest

MateSaary avatar May 12 '25 01:05 MateSaary

/retest

RaphaelBut avatar May 12 '25 09:05 RaphaelBut

@typeid Thanks for the review :slightly_smiling_face: Great points, a lot of this does overlap with reviews. ~~Do we think it's worth looking into implementing guidelines elsewhere (e.g. PR template akin to MR in App-interface)?~~ -> This has now been added in #471 For kube-api, I wrote a short make target script to "lint" investigations and their corresponding RBAC to ensure investigations set to informing cannot conduct write operations. Let me know your thoughts on this/if it's a sufficient solution. Thanks again!

MateSaary avatar May 13 '25 09:05 MateSaary

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: MateSaary

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment Approvers can cancel approval by writing /approve cancel in a comment

openshift-ci[bot] avatar Jun 22 '25 17:06 openshift-ci[bot]

Linting the RBAC for write permissions is great!

RaphaelBut avatar Jun 26 '25 11:06 RaphaelBut

@MateSaary: all tests passed!

Full PR test history. Your PR dashboard.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

openshift-ci[bot] avatar Jun 27 '25 14:06 openshift-ci[bot]

Closing PR following discussion https://redhat-internal.slack.com/archives/C081RTBAPA9/p1751354368278599

MateSaary avatar Jul 01 '25 07:07 MateSaary