Repository navigation
[devscripts] Add opt-in token-free deploy (OPENSHIFT_CI, ephemeral registry) - #4236
pinikomarov wants to merge 1 commit into
Conversation
|
Skipping CI for Draft Pull Request. |
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
|
Build succeeded (check pipeline). ✔️ openstack-k8s-operators-content-provider SUCCESS in 3h 20m 50s |
…gistry) dev-scripts hard-requires a valid app.ci `CI_TOKEN` for every non-okd release, GA included: `validation.sh` aborts on an empty token, and `utils.sh` (`write_pull_secret`, called from `03_build_installer`) logs in to app.ci to fetch registry credentials for the pull-secret. For a GA cluster the token is not needed to pull images -- they come from the `pull-secret` (quay.io / registry.redhat.io), not from app.ci. dev-scripts already ships a documented token-free mode, `OPENSHIFT_CI=true` (see `config_example.sh`), which bypasses both the token validation and the app.ci pull-secret login in one switch. Use it instead of patching each token gate individually (the previous approach missed `write_pull_secret`). `OPENSHIFT_CI=true` has one side effect unsuitable for a single-host reproducer: it forces an NFS-backed persistent image registry that is not provisioned here, stalling the deploy on `wait-for-stable-cluster`. Add `cifmw_devscripts_skip_persistent_imageregistry` (default `false`): when enabled, `135_patch_src.yml` rewrites the single `PERSISTENT_IMAGEREG=true` line in `common.sh` to `=false`, keeping the in-cluster registry on `emptyDir`. An `assert` fails early if that line is not found, so a future dev-scripts bump cannot silently drop the patch. Enable token-free GA deploys by setting `openshift_ci: "true"` in the config overrides, passing an empty `cifmw_manage_secrets_citoken_content`, and setting `cifmw_devscripts_skip_persistent_imageregistry: true`. Related-Issue: #OSPRH-38514 Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Signed-off-by: pkomarov <pkomarov@redhat.com>
1310e4a to
c96410d
Compare
|
Build succeeded (check pipeline). ✔️ openstack-k8s-operators-content-provider SUCCESS in 2h 21m 51s |
What
Add an opt-in token-free GA deploy path to the
devscriptsrole, usingdev-scripts' own documented
OPENSHIFT_CI=truemode, and neutralize its oneunwanted side effect (a persistent NFS image registry) so a single-host
reproducer stays green.
Why
dev-scripts hard-requires a valid
app.ciCI_TOKENfor every non-okd release,GA included — there are three touchpoints:
validation.shaborts on an empty token;validation.shruns a liveoc loginto app.ci when the token is non-empty;utils.shwrite_pull_secret(from03_build_installer) logs in to app.ci tofetch registry creds for the pull-secret.
For a GA cluster the token is not needed to pull images — they come from the
pull-secret(quay.io / registry.redhat.io), not app.ci.How
OPENSHIFT_CI=true(see dev-scriptsconfig_example.sh) bypasses both thetoken validation and the app.ci pull-secret login in a single documented switch.
Patching each gate individually was a dead end — the previous revision of this PR
missed
write_pull_secret.OPENSHIFT_CI=truealso forces an NFS-backed persistent image registry that asingle-host reproducer does not provision (the deploy then stalls on
wait-for-stable-cluster). New opt-in defaultcifmw_devscripts_skip_persistent_imageregistry(defaultfalse) rewrites thesingle
PERSISTENT_IMAGEREG=trueline incommon.shto=false, keeping thein-cluster registry on
emptyDir. Anassertfails early if that line isabsent, so a future dev-scripts bump cannot silently drop the patch.
Enable token-free deploy
Test
Proven green on a clean single host (m37-09, 2026-10-08): token-free
make allreached "Install complete!"; 34/34 cluster operators Available=True / 0 Degraded;
oc adm wait-for-stable-clusterpassed (no NFS hang); all pod images sourcedfrom quay.io + registry.redhat.io, zero from registry.ci/app.ci.
Related-Issue: #OSPRH-38514
🤖 Generated with Claude Code