From d8b1bb45acff04b5411d9ac32968dc492a20146b Mon Sep 17 00:00:00 2001 From: Vincent Link Date: Mon, 17 Aug 2026 15:49:06 +0200 Subject: [PATCH] AUTOSCALE-543: Add lint, unit, verify-history, and e2e tests for kedacore-http-add-on Adds CI config for kedacore-http-add-on: a golangci-lint presubmit, a unit test running gotestsum for real JUnit reporting, a verify-history test, and an AWS e2e test. The e2e test runs against a claimed pre-installed OCP 5.0 cluster (cluster_claim) rather than a freshly IPI-installed one, since it only needs KEDA, Jaeger, and OTel installed via Helm plus a few namespaces, not full cluster provisioning. It uses the generic-claim workflow to grant the claimed cluster pull access to the CI build farm's ephemeral image registry, without which the operator/interceptor/scaler pods hit ImagePullBackOff. --- .../openshift-kedacore-http-add-on-main.yaml | 102 +++-- ...kedacore-http-add-on-main-postsubmits.yaml | 1 + ...-kedacore-http-add-on-main-presubmits.yaml | 388 ++++++++++++++++++ 3 files changed, 468 insertions(+), 23 deletions(-) diff --git a/ci-operator/config/openshift/kedacore-http-add-on/openshift-kedacore-http-add-on-main.yaml b/ci-operator/config/openshift/kedacore-http-add-on/openshift-kedacore-http-add-on-main.yaml index b4088591b2e56..77a190a0fe4e7 100644 --- a/ci-operator/config/openshift/kedacore-http-add-on/openshift-kedacore-http-add-on-main.yaml +++ b/ci-operator/config/openshift/kedacore-http-add-on/openshift-kedacore-http-add-on-main.yaml @@ -1,34 +1,20 @@ -base_images: - base: - name: "5.1" - namespace: ocp - tag: base -binary_build_commands: make build build_root: from_repository: true images: items: - - build_args: - - name: GIT_COMMIT - value: dummy-ci-commit-value - dockerfile_path: openshift/Containerfile.operator.rhel - from: base + - dockerfile_path: openshift/Containerfile.operator.rhel to: custom-metrics-autoscaler-http-add-on-operator - - build_args: - - name: GIT_COMMIT - value: dummy-ci-commit-value - dockerfile_path: openshift/Containerfile.interceptor.rhel - from: base + - dockerfile_path: openshift/Containerfile.interceptor.rhel to: custom-metrics-autoscaler-http-add-on-interceptor - - build_args: - - name: GIT_COMMIT - value: dummy-ci-commit-value - dockerfile_path: openshift/Containerfile.scaler.rhel - from: base + - dockerfile_path: openshift/Containerfile.scaler.rhel to: custom-metrics-autoscaler-http-add-on-scaler + - dockerfile_path: openshift/Containerfile.grpc-echo.rhel + to: custom-metrics-autoscaler-http-add-on-grpc-echo promotion: to: - - name: "5.1" + - excluded_images: + - custom-metrics-autoscaler-http-add-on-grpc-echo + name: "5.1" namespace: ocp releases: initial: @@ -47,7 +33,77 @@ resources: requests: cpu: 100m memory: 200Mi -test_binary_build_commands: make test +tests: +- as: lint + commands: GOFLAGS="" GOLANGCI_LINT_CACHE=/tmp/golangci-lint-cache make lint + container: + from: src + skip_if_only_changed: ^docs/|^\.github|\.md$|^(?:.*/)?(?:\.gitignore|OWNERS|OWNERS_ALIASES|PROJECT|LICENSE)$ +- as: unit + commands: go tool gotestsum --junitfile="${ARTIFACT_DIR}/junit_unit.xml" -- ./... + container: + from: src + skip_if_only_changed: ^docs/|^\.github|\.md$|^(?:.*/)?(?:\.gitignore|OWNERS|OWNERS_ALIASES|PROJECT|LICENSE)$ +- as: verify-history + commands: hack/verify-history.sh + container: + from: src + skip_if_only_changed: ^docs/|\.md$|^(?:.*/)?(?:\.gitignore|OWNERS|PROJECT|LICENSE)$ +- as: http-addon-e2e-aws + cluster_claim: + architecture: amd64 + as: unused + cloud: aws + owner: openshift-ci + product: ocp + timeout: 1h0m0s + version: "5.0" + skip_if_only_changed: ^docs/|^\.github|\.md$|^(?:.*/)?(?:\.gitignore|OWNERS|OWNERS_ALIASES|PROJECT|LICENSE)$ + steps: + post: + - as: e2e-clean + cli: latest + commands: GOFLAGS="" make e2e-test-openshift-clean + from: src + resources: + requests: + cpu: 100m + - chain: gather + test: + - as: e2e-setup + cli: latest + commands: | + GOFLAGS="" make e2e-test-openshift-setup + dependencies: + - env: IMAGE_HTTP_ADDON_OPERATOR + name: custom-metrics-autoscaler-http-add-on-operator + - env: IMAGE_HTTP_ADDON_INTERCEPTOR + name: custom-metrics-autoscaler-http-add-on-interceptor + - env: IMAGE_HTTP_ADDON_SCALER + name: custom-metrics-autoscaler-http-add-on-scaler + from: src + resources: + requests: + cpu: 100m + - as: e2e-run + cli: latest + commands: | + GOFLAGS="" make e2e-test-openshift-ci + dependencies: + - env: IMAGE_GRPC_ECHO + name: custom-metrics-autoscaler-http-add-on-grpc-echo + from: src + resources: + requests: + cpu: 100m + workflow: generic-claim +- as: security + optional: true + skip_if_only_changed: ^docs/|^\.github|\.md$|^(?:.*/)?(?:\.gitignore|OWNERS|OWNERS_ALIASES|PROJECT|LICENSE)$ + steps: + env: + PROJECT_NAME: kedacore-http-add-on + workflow: openshift-ci-security zz_generated_metadata: branch: main org: openshift diff --git a/ci-operator/jobs/openshift/kedacore-http-add-on/openshift-kedacore-http-add-on-main-postsubmits.yaml b/ci-operator/jobs/openshift/kedacore-http-add-on/openshift-kedacore-http-add-on-main-postsubmits.yaml index 07f3e6f4a55a4..bd898276a44f6 100644 --- a/ci-operator/jobs/openshift/kedacore-http-add-on/openshift-kedacore-http-add-on-main-postsubmits.yaml +++ b/ci-operator/jobs/openshift/kedacore-http-add-on/openshift-kedacore-http-add-on-main-postsubmits.yaml @@ -9,6 +9,7 @@ postsubmits: decoration_config: sparse_checkout_files: - .ci-operator.yaml + - openshift/Containerfile.grpc-echo.rhel - openshift/Containerfile.interceptor.rhel - openshift/Containerfile.operator.rhel - openshift/Containerfile.scaler.rhel diff --git a/ci-operator/jobs/openshift/kedacore-http-add-on/openshift-kedacore-http-add-on-main-presubmits.yaml b/ci-operator/jobs/openshift/kedacore-http-add-on/openshift-kedacore-http-add-on-main-presubmits.yaml index aca87c3f687c3..52dec741e9ff5 100644 --- a/ci-operator/jobs/openshift/kedacore-http-add-on/openshift-kedacore-http-add-on-main-presubmits.yaml +++ b/ci-operator/jobs/openshift/kedacore-http-add-on/openshift-kedacore-http-add-on-main-presubmits.yaml @@ -1,5 +1,98 @@ presubmits: openshift/kedacore-http-add-on: + - agent: kubernetes + always_run: false + branches: + - ^main$ + - ^main- + cluster: build06 + context: ci/prow/http-addon-e2e-aws + decorate: true + decoration_config: + sparse_checkout_files: + - .ci-operator.yaml + - openshift/Containerfile.grpc-echo.rhel + - openshift/Containerfile.interceptor.rhel + - openshift/Containerfile.operator.rhel + - openshift/Containerfile.scaler.rhel + labels: + ci.openshift.io/generator: prowgen + pj-rehearse.openshift.io/can-be-rehearsed: "true" + name: pull-ci-openshift-kedacore-http-add-on-main-http-addon-e2e-aws + rerun_command: /test http-addon-e2e-aws + skip_if_only_changed: ^docs/|^\.github|\.md$|^(?:.*/)?(?:\.gitignore|OWNERS|OWNERS_ALIASES|PROJECT|LICENSE)$ + spec: + containers: + - args: + - --gcs-upload-secret=/secrets/gcs/service-account.json + - --hive-kubeconfig=/secrets/hive-hive-credentials/kubeconfig + - --image-import-pull-secret=/etc/pull-secret/.dockerconfigjson + - --lease-server-credentials-file=/etc/boskos/credentials + - --report-credentials-file=/etc/report/credentials + - --secret-dir=/secrets/ci-pull-credentials + - --target=http-addon-e2e-aws + command: + - ci-operator + env: + - name: HTTP_SERVER_IP + valueFrom: + fieldRef: + fieldPath: status.podIP + image: quay-proxy.ci.openshift.org/openshift/ci:ci_ci-operator_latest + imagePullPolicy: Always + name: "" + ports: + - containerPort: 8080 + name: http + resources: + requests: + cpu: 10m + volumeMounts: + - mountPath: /etc/boskos + name: boskos + readOnly: true + - mountPath: /secrets/ci-pull-credentials + name: ci-pull-credentials + readOnly: true + - mountPath: /secrets/gcs + name: gcs-credentials + readOnly: true + - mountPath: /secrets/hive-hive-credentials + name: hive-hive-credentials + readOnly: true + - mountPath: /secrets/manifest-tool + name: manifest-tool-local-pusher + readOnly: true + - mountPath: /etc/pull-secret + name: pull-secret + readOnly: true + - mountPath: /etc/report + name: result-aggregator + readOnly: true + serviceAccountName: ci-operator + volumes: + - name: boskos + secret: + items: + - key: credentials + path: credentials + secretName: boskos-credentials + - name: ci-pull-credentials + secret: + secretName: ci-pull-credentials + - name: hive-hive-credentials + secret: + secretName: hive-hive-credentials + - name: manifest-tool-local-pusher + secret: + secretName: manifest-tool-local-pusher + - name: pull-secret + secret: + secretName: registry-pull-credentials + - name: result-aggregator + secret: + secretName: result-aggregator + trigger: (?m)^/test( | .* )http-addon-e2e-aws,?($|\s.*) - agent: kubernetes always_run: true branches: @@ -11,6 +104,7 @@ presubmits: decoration_config: sparse_checkout_files: - .ci-operator.yaml + - openshift/Containerfile.grpc-echo.rhel - openshift/Containerfile.interceptor.rhel - openshift/Containerfile.operator.rhel - openshift/Containerfile.scaler.rhel @@ -60,3 +154,297 @@ presubmits: secret: secretName: result-aggregator trigger: (?m)^/test( | .* )images,?($|\s.*) + - agent: kubernetes + always_run: false + branches: + - ^main$ + - ^main- + cluster: build04 + context: ci/prow/lint + decorate: true + decoration_config: + sparse_checkout_files: + - .ci-operator.yaml + - openshift/Containerfile.grpc-echo.rhel + - openshift/Containerfile.interceptor.rhel + - openshift/Containerfile.operator.rhel + - openshift/Containerfile.scaler.rhel + labels: + ci.openshift.io/generator: prowgen + pj-rehearse.openshift.io/can-be-rehearsed: "true" + name: pull-ci-openshift-kedacore-http-add-on-main-lint + rerun_command: /test lint + skip_if_only_changed: ^docs/|^\.github|\.md$|^(?:.*/)?(?:\.gitignore|OWNERS|OWNERS_ALIASES|PROJECT|LICENSE)$ + spec: + containers: + - args: + - --gcs-upload-secret=/secrets/gcs/service-account.json + - --image-import-pull-secret=/etc/pull-secret/.dockerconfigjson + - --report-credentials-file=/etc/report/credentials + - --target=lint + command: + - ci-operator + env: + - name: HTTP_SERVER_IP + valueFrom: + fieldRef: + fieldPath: status.podIP + image: quay-proxy.ci.openshift.org/openshift/ci:ci_ci-operator_latest + imagePullPolicy: Always + name: "" + ports: + - containerPort: 8080 + name: http + resources: + requests: + cpu: 10m + volumeMounts: + - mountPath: /secrets/gcs + name: gcs-credentials + readOnly: true + - mountPath: /secrets/manifest-tool + name: manifest-tool-local-pusher + readOnly: true + - mountPath: /etc/pull-secret + name: pull-secret + readOnly: true + - mountPath: /etc/report + name: result-aggregator + readOnly: true + serviceAccountName: ci-operator + volumes: + - name: manifest-tool-local-pusher + secret: + secretName: manifest-tool-local-pusher + - name: pull-secret + secret: + secretName: registry-pull-credentials + - name: result-aggregator + secret: + secretName: result-aggregator + trigger: (?m)^/test( | .* )lint,?($|\s.*) + - agent: kubernetes + always_run: false + branches: + - ^main$ + - ^main- + cluster: build13 + context: ci/prow/security + decorate: true + decoration_config: + sparse_checkout_files: + - .ci-operator.yaml + - openshift/Containerfile.grpc-echo.rhel + - openshift/Containerfile.interceptor.rhel + - openshift/Containerfile.operator.rhel + - openshift/Containerfile.scaler.rhel + labels: + ci.openshift.io/generator: prowgen + pj-rehearse.openshift.io/can-be-rehearsed: "true" + name: pull-ci-openshift-kedacore-http-add-on-main-security + optional: true + rerun_command: /test security + skip_if_only_changed: ^docs/|^\.github|\.md$|^(?:.*/)?(?:\.gitignore|OWNERS|OWNERS_ALIASES|PROJECT|LICENSE)$ + spec: + containers: + - args: + - --gcs-upload-secret=/secrets/gcs/service-account.json + - --image-import-pull-secret=/etc/pull-secret/.dockerconfigjson + - --lease-server-credentials-file=/etc/boskos/credentials + - --report-credentials-file=/etc/report/credentials + - --secret-dir=/secrets/ci-pull-credentials + - --target=security + command: + - ci-operator + env: + - name: HTTP_SERVER_IP + valueFrom: + fieldRef: + fieldPath: status.podIP + image: quay-proxy.ci.openshift.org/openshift/ci:ci_ci-operator_latest + imagePullPolicy: Always + name: "" + ports: + - containerPort: 8080 + name: http + resources: + requests: + cpu: 10m + volumeMounts: + - mountPath: /etc/boskos + name: boskos + readOnly: true + - mountPath: /secrets/ci-pull-credentials + name: ci-pull-credentials + readOnly: true + - mountPath: /secrets/gcs + name: gcs-credentials + readOnly: true + - mountPath: /secrets/manifest-tool + name: manifest-tool-local-pusher + readOnly: true + - mountPath: /etc/pull-secret + name: pull-secret + readOnly: true + - mountPath: /etc/report + name: result-aggregator + readOnly: true + serviceAccountName: ci-operator + volumes: + - name: boskos + secret: + items: + - key: credentials + path: credentials + secretName: boskos-credentials + - name: ci-pull-credentials + secret: + secretName: ci-pull-credentials + - name: manifest-tool-local-pusher + secret: + secretName: manifest-tool-local-pusher + - name: pull-secret + secret: + secretName: registry-pull-credentials + - name: result-aggregator + secret: + secretName: result-aggregator + trigger: (?m)^/test( | .* )security,?($|\s.*) + - agent: kubernetes + always_run: false + branches: + - ^main$ + - ^main- + cluster: build13 + context: ci/prow/unit + decorate: true + decoration_config: + sparse_checkout_files: + - .ci-operator.yaml + - openshift/Containerfile.grpc-echo.rhel + - openshift/Containerfile.interceptor.rhel + - openshift/Containerfile.operator.rhel + - openshift/Containerfile.scaler.rhel + labels: + ci.openshift.io/generator: prowgen + pj-rehearse.openshift.io/can-be-rehearsed: "true" + name: pull-ci-openshift-kedacore-http-add-on-main-unit + rerun_command: /test unit + skip_if_only_changed: ^docs/|^\.github|\.md$|^(?:.*/)?(?:\.gitignore|OWNERS|OWNERS_ALIASES|PROJECT|LICENSE)$ + spec: + containers: + - args: + - --gcs-upload-secret=/secrets/gcs/service-account.json + - --image-import-pull-secret=/etc/pull-secret/.dockerconfigjson + - --report-credentials-file=/etc/report/credentials + - --target=unit + command: + - ci-operator + env: + - name: HTTP_SERVER_IP + valueFrom: + fieldRef: + fieldPath: status.podIP + image: quay-proxy.ci.openshift.org/openshift/ci:ci_ci-operator_latest + imagePullPolicy: Always + name: "" + ports: + - containerPort: 8080 + name: http + resources: + requests: + cpu: 10m + volumeMounts: + - mountPath: /secrets/gcs + name: gcs-credentials + readOnly: true + - mountPath: /secrets/manifest-tool + name: manifest-tool-local-pusher + readOnly: true + - mountPath: /etc/pull-secret + name: pull-secret + readOnly: true + - mountPath: /etc/report + name: result-aggregator + readOnly: true + serviceAccountName: ci-operator + volumes: + - name: manifest-tool-local-pusher + secret: + secretName: manifest-tool-local-pusher + - name: pull-secret + secret: + secretName: registry-pull-credentials + - name: result-aggregator + secret: + secretName: result-aggregator + trigger: (?m)^/test( | .* )unit,?($|\s.*) + - agent: kubernetes + always_run: false + branches: + - ^main$ + - ^main- + cluster: build13 + context: ci/prow/verify-history + decorate: true + decoration_config: + sparse_checkout_files: + - .ci-operator.yaml + - openshift/Containerfile.grpc-echo.rhel + - openshift/Containerfile.interceptor.rhel + - openshift/Containerfile.operator.rhel + - openshift/Containerfile.scaler.rhel + labels: + ci.openshift.io/generator: prowgen + pj-rehearse.openshift.io/can-be-rehearsed: "true" + name: pull-ci-openshift-kedacore-http-add-on-main-verify-history + rerun_command: /test verify-history + skip_if_only_changed: ^docs/|\.md$|^(?:.*/)?(?:\.gitignore|OWNERS|PROJECT|LICENSE)$ + spec: + containers: + - args: + - --gcs-upload-secret=/secrets/gcs/service-account.json + - --image-import-pull-secret=/etc/pull-secret/.dockerconfigjson + - --report-credentials-file=/etc/report/credentials + - --target=verify-history + command: + - ci-operator + env: + - name: HTTP_SERVER_IP + valueFrom: + fieldRef: + fieldPath: status.podIP + image: quay-proxy.ci.openshift.org/openshift/ci:ci_ci-operator_latest + imagePullPolicy: Always + name: "" + ports: + - containerPort: 8080 + name: http + resources: + requests: + cpu: 10m + volumeMounts: + - mountPath: /secrets/gcs + name: gcs-credentials + readOnly: true + - mountPath: /secrets/manifest-tool + name: manifest-tool-local-pusher + readOnly: true + - mountPath: /etc/pull-secret + name: pull-secret + readOnly: true + - mountPath: /etc/report + name: result-aggregator + readOnly: true + serviceAccountName: ci-operator + volumes: + - name: manifest-tool-local-pusher + secret: + secretName: manifest-tool-local-pusher + - name: pull-secret + secret: + secretName: registry-pull-credentials + - name: result-aggregator + secret: + secretName: result-aggregator + trigger: (?m)^/test( | .* )verify-history,?($|\s.*)