Skip to content

[devscripts] Add opt-in token-free deploy (OPENSHIFT_CI, ephemeral registry) - #4236

Draft
pinikomarov wants to merge 1 commit into
openstack-k8s-operators:mainfrom
pinikomarov:OSPRH-38514-devscripts-tokenless
Draft

pinikomarov wants to merge 1 commit into
openstack-k8s-operators:mainfrom
pinikomarov:OSPRH-38514-devscripts-tokenless

Conversation

@pinikomarov

@pinikomarov pinikomarov commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

What

Add an opt-in token-free GA deploy path to the devscripts role, using
dev-scripts' own documented OPENSHIFT_CI=true mode, and neutralize its one
unwanted side effect (a persistent NFS image registry) so a single-host
reproducer stays green.

Why

dev-scripts hard-requires a valid app.ci CI_TOKEN for every non-okd release,
GA included — there are three touchpoints:

  • validation.sh aborts on an empty token;
  • validation.sh runs a live oc login to app.ci when the token is non-empty;
  • utils.sh write_pull_secret (from 03_build_installer) logs in to app.ci to
    fetch registry creds for the pull-secret.

For a GA cluster the token is not needed to pull images — they come from the
pull-secret (quay.io / registry.redhat.io), not app.ci.

How

OPENSHIFT_CI=true (see dev-scripts config_example.sh) bypasses both the
token validation and the app.ci pull-secret login in a single documented switch.
Patching each gate individually was a dead end — the previous revision of this PR
missed write_pull_secret.

OPENSHIFT_CI=true also forces an NFS-backed persistent image registry that a
single-host reproducer does not provision (the deploy then stalls on
wait-for-stable-cluster). New opt-in default
cifmw_devscripts_skip_persistent_imageregistry (default false) rewrites the
single PERSISTENT_IMAGEREG=true line in common.sh to =false, keeping the
in-cluster registry on emptyDir. An assert fails early if that line is
absent, so a future dev-scripts bump cannot silently drop the patch.

Enable token-free deploy

cifmw_devscripts_config_overrides:
  openshift_ci: "true"
cifmw_manage_secrets_citoken_content: ''
cifmw_devscripts_skip_persistent_imageregistry: true

Test

Proven green on a clean single host (m37-09, 2026-10-08): token-free make all
reached "Install complete!"; 34/34 cluster operators Available=True / 0 Degraded;
oc adm wait-for-stable-cluster passed (no NFS hang); all pod images sourced
from quay.io + registry.redhat.io, zero from registry.ci/app.ci.

Related-Issue: #OSPRH-38514

🤖 Generated with Claude Code

@openshift-ci

openshift-ci Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Skipping CI for Draft Pull Request.
If you want CI signal for your change, please convert it to an actual PR.
You can still manually trigger a test run with /test all

@openshift-ci

openshift-ci Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
Once this PR has been reviewed and has the lgtm label, please assign fultonj for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@centosinfra-prod-github-app

Copy link
Copy Markdown

Build succeeded (check pipeline).
https://gateway-cloud-softwarefactory.apps.ocp.cloud.ci.centos.org/zuul/t/rdoproject.org/buildset/3177e3752fe6451ea74476fa4864b18e

✔️ openstack-k8s-operators-content-provider SUCCESS in 3h 20m 50s
✔️ podified-multinode-edpm-deployment-crc SUCCESS in 1h 19m 14s
✔️ podified-multinode-edpm-deployment-crc-centos-10 SUCCESS in 1h 20m 03s
✔️ cifmw-crc-podified-edpm-baremetal SUCCESS in 1h 37m 03s
✔️ cifmw-pod-zuul-files SUCCESS in 5m 17s
✔️ noop SUCCESS in 0s
✔️ cifmw-pod-ansible-test SUCCESS in 8m 32s
✔️ cifmw-pod-pre-commit SUCCESS in 8m 36s
✔️ cifmw-molecule-devscripts SUCCESS in 10m 11s

…gistry)

dev-scripts hard-requires a valid app.ci `CI_TOKEN` for every non-okd release,
GA included: `validation.sh` aborts on an empty token, and `utils.sh`
(`write_pull_secret`, called from `03_build_installer`) logs in to app.ci to
fetch registry credentials for the pull-secret. For a GA cluster the token is
not needed to pull images -- they come from the `pull-secret` (quay.io /
registry.redhat.io), not from app.ci.

dev-scripts already ships a documented token-free mode, `OPENSHIFT_CI=true`
(see `config_example.sh`), which bypasses both the token validation and the
app.ci pull-secret login in one switch. Use it instead of patching each token
gate individually (the previous approach missed `write_pull_secret`).

`OPENSHIFT_CI=true` has one side effect unsuitable for a single-host reproducer:
it forces an NFS-backed persistent image registry that is not provisioned here,
stalling the deploy on `wait-for-stable-cluster`. Add
`cifmw_devscripts_skip_persistent_imageregistry` (default `false`): when enabled,
`135_patch_src.yml` rewrites the single `PERSISTENT_IMAGEREG=true` line in
`common.sh` to `=false`, keeping the in-cluster registry on `emptyDir`. An
`assert` fails early if that line is not found, so a future dev-scripts bump
cannot silently drop the patch.

Enable token-free GA deploys by setting `openshift_ci: "true"` in the config
overrides, passing an empty `cifmw_manage_secrets_citoken_content`, and setting
`cifmw_devscripts_skip_persistent_imageregistry: true`.

Related-Issue: #OSPRH-38514

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Signed-off-by: pkomarov <pkomarov@redhat.com>
@pinikomarov
pinikomarov force-pushed the OSPRH-38514-devscripts-tokenless branch from 1310e4a to c96410d Compare October 8, 2026 14:43
@pinikomarov pinikomarov changed the title [devscripts] Add opt-in token-free deploy (skip CI_TOKEN validation) [devscripts] Add opt-in token-free deploy (OPENSHIFT_CI, ephemeral registry) Oct 8, 2026
@centosinfra-prod-github-app

Copy link
Copy Markdown

Build succeeded (check pipeline).
https://gateway-cloud-softwarefactory.apps.ocp.cloud.ci.centos.org/zuul/t/rdoproject.org/buildset/1bf67ea7535c4d16abcf401a12c64cfc

✔️ openstack-k8s-operators-content-provider SUCCESS in 2h 21m 51s
✔️ podified-multinode-edpm-deployment-crc SUCCESS in 1h 18m 46s
✔️ podified-multinode-edpm-deployment-crc-centos-10 SUCCESS in 1h 21m 27s
✔️ cifmw-crc-podified-edpm-baremetal SUCCESS in 1h 32m 08s
✔️ cifmw-pod-zuul-files SUCCESS in 4m 29s
✔️ noop SUCCESS in 0s
✔️ cifmw-pod-ansible-test SUCCESS in 8m 40s
✔️ cifmw-pod-pre-commit SUCCESS in 7m 53s
✔️ cifmw-molecule-devscripts SUCCESS in 10m 32s

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant