diff --git a/ci-operator/config/openshift/openshift-tests-private/openshift-openshift-tests-private-release-4.18__amd64-nightly.yaml b/ci-operator/config/openshift/openshift-tests-private/openshift-openshift-tests-private-release-4.18__amd64-nightly.yaml index 030c612fef42e..dbb4a5a207f96 100644 --- a/ci-operator/config/openshift/openshift-tests-private/openshift-openshift-tests-private-release-4.18__amd64-nightly.yaml +++ b/ci-operator/config/openshift/openshift-tests-private/openshift-openshift-tests-private-release-4.18__amd64-nightly.yaml @@ -3909,6 +3909,21 @@ tests: test: - chain: openshift-e2e-test-qe workflow: baremetal-lab-sno +- as: metal-sno-ipv6-http-proxy-f60 + capabilities: + - intranet + cron: 19 22 18 1,3,5,7,9,11 * + steps: + cluster_profile: equinix-ocp-metal-qe + env: + AUX_HOST: openshift-qe-metal-ci.arm.eng.rdu2.redhat.com + RESERVE_BOOTSTRAP: "false" + architecture: amd64 + masters: "1" + workers: "0" + test: + - chain: openshift-e2e-test-qe + workflow: baremetal-lab-sno-ipv6-static - as: metal-upi-ipv6-static-disk-etcd-encryption-f999 capabilities: - intranet diff --git a/ci-operator/config/openshift/openshift-tests-private/openshift-openshift-tests-private-release-4.19__arm64-nightly.yaml b/ci-operator/config/openshift/openshift-tests-private/openshift-openshift-tests-private-release-4.19__arm64-nightly.yaml index bf9746281124f..b2514e7c09df5 100644 --- a/ci-operator/config/openshift/openshift-tests-private/openshift-openshift-tests-private-release-4.19__arm64-nightly.yaml +++ b/ci-operator/config/openshift/openshift-tests-private/openshift-openshift-tests-private-release-4.19__arm64-nightly.yaml @@ -626,6 +626,23 @@ tests: test: - chain: openshift-e2e-test-qe workflow: baremetal-lab-sno +- as: metal-sno-ipv6-http-proxy-f28 + capabilities: + - intranet + cron: 29 4 9,23 * * + steps: + cluster_profile: equinix-ocp-metal-qe + dependencies: + OPENSHIFT_INSTALL_RELEASE_IMAGE_OVERRIDE: release:arm64-latest + env: + AUX_HOST: openshift-qe-metal-ci.arm.eng.rdu2.redhat.com + RESERVE_BOOTSTRAP: "false" + architecture: arm64 + masters: "1" + workers: "0" + test: + - chain: openshift-e2e-test-qe + workflow: baremetal-lab-sno-ipv6-static - as: metal-upi-ipv6-static-disk-etcd-encryption-f999 capabilities: - intranet diff --git a/ci-operator/config/openshift/openshift-tests-private/openshift-openshift-tests-private-release-4.20__amd64-nightly.yaml b/ci-operator/config/openshift/openshift-tests-private/openshift-openshift-tests-private-release-4.20__amd64-nightly.yaml index d4b3f9899bcfa..2421889c89754 100644 --- a/ci-operator/config/openshift/openshift-tests-private/openshift-openshift-tests-private-release-4.20__amd64-nightly.yaml +++ b/ci-operator/config/openshift/openshift-tests-private/openshift-openshift-tests-private-release-4.20__amd64-nightly.yaml @@ -4609,6 +4609,21 @@ tests: test: - chain: openshift-e2e-test-qe workflow: baremetal-lab-sno +- as: metal-sno-ipv6-http-proxy-f28 + capabilities: + - intranet + cron: 9 23 7,21 * * + steps: + cluster_profile: equinix-ocp-metal-qe + env: + AUX_HOST: openshift-qe-metal-ci.arm.eng.rdu2.redhat.com + RESERVE_BOOTSTRAP: "false" + architecture: amd64 + masters: "1" + workers: "0" + test: + - chain: openshift-e2e-test-qe + workflow: baremetal-lab-sno-ipv6-static - as: metal-upi-ipv6-static-disk-etcd-encryption-f28 capabilities: - intranet diff --git a/ci-operator/config/openshift/openshift-tests-private/openshift-openshift-tests-private-release-4.21__arm64-nightly.yaml b/ci-operator/config/openshift/openshift-tests-private/openshift-openshift-tests-private-release-4.21__arm64-nightly.yaml index 6414143a81963..3903834c7ae69 100644 --- a/ci-operator/config/openshift/openshift-tests-private/openshift-openshift-tests-private-release-4.21__arm64-nightly.yaml +++ b/ci-operator/config/openshift/openshift-tests-private/openshift-openshift-tests-private-release-4.21__arm64-nightly.yaml @@ -656,6 +656,23 @@ tests: test: - chain: openshift-e2e-test-qe workflow: baremetal-lab-sno +- as: metal-sno-ipv6-http-proxy-f28 + capabilities: + - intranet + cron: 29 22 7,21 * * + steps: + cluster_profile: equinix-ocp-metal-qe + dependencies: + OPENSHIFT_INSTALL_RELEASE_IMAGE_OVERRIDE: release:arm64-latest + env: + AUX_HOST: openshift-qe-metal-ci.arm.eng.rdu2.redhat.com + RESERVE_BOOTSTRAP: "false" + architecture: arm64 + masters: "1" + workers: "0" + test: + - chain: openshift-e2e-test-qe + workflow: baremetal-lab-sno-ipv6-static - as: metal-ipi-ovn-vmedia-bmc-verify-ca-f28 capabilities: - intranet diff --git a/ci-operator/config/openshift/openshift-tests-private/openshift-openshift-tests-private-release-4.22__amd64-nightly.yaml b/ci-operator/config/openshift/openshift-tests-private/openshift-openshift-tests-private-release-4.22__amd64-nightly.yaml index 7fa51650f3874..445890c0b874c 100644 --- a/ci-operator/config/openshift/openshift-tests-private/openshift-openshift-tests-private-release-4.22__amd64-nightly.yaml +++ b/ci-operator/config/openshift/openshift-tests-private/openshift-openshift-tests-private-release-4.22__amd64-nightly.yaml @@ -4952,6 +4952,21 @@ tests: test: - chain: openshift-e2e-test-qe workflow: baremetal-lab-sno +- as: metal-sno-ipv6-http-proxy-f7 + capabilities: + - intranet + cron: 29 0 5,12,19,26 * * + steps: + cluster_profile: equinix-ocp-metal-qe + env: + AUX_HOST: openshift-qe-metal-ci.arm.eng.rdu2.redhat.com + RESERVE_BOOTSTRAP: "false" + architecture: amd64 + masters: "1" + workers: "0" + test: + - chain: openshift-e2e-test-qe + workflow: baremetal-lab-sno-ipv6-static - as: metal-upi-ovn-ipsec-dualstack-fips-f7 capabilities: - intranet diff --git a/ci-operator/config/openshift/openshift-tests-private/openshift-openshift-tests-private-release-5.0__amd64-nightly.yaml b/ci-operator/config/openshift/openshift-tests-private/openshift-openshift-tests-private-release-5.0__amd64-nightly.yaml index 21a2611ff6b52..fee3d87555e1a 100644 --- a/ci-operator/config/openshift/openshift-tests-private/openshift-openshift-tests-private-release-5.0__amd64-nightly.yaml +++ b/ci-operator/config/openshift/openshift-tests-private/openshift-openshift-tests-private-release-5.0__amd64-nightly.yaml @@ -4374,6 +4374,21 @@ tests: test: - chain: openshift-e2e-test-qe workflow: baremetal-lab-sno +- as: metal-sno-ipv6-http-proxy-f7 + capabilities: + - intranet + cron: 19 16 2,9,16,23,30 * * + steps: + cluster_profile: equinix-ocp-metal-qe + env: + AUX_HOST: openshift-qe-metal-ci.arm.eng.rdu2.redhat.com + RESERVE_BOOTSTRAP: "false" + architecture: amd64 + masters: "1" + workers: "0" + test: + - chain: openshift-e2e-test-qe + workflow: baremetal-lab-sno-ipv6-static - as: metal-sno-ipv4-etcd-encryption-rt-kernel-basecap-f7 capabilities: - intranet diff --git a/ci-operator/jobs/openshift/openshift-tests-private/openshift-openshift-tests-private-release-4.18-periodics.yaml b/ci-operator/jobs/openshift/openshift-tests-private/openshift-openshift-tests-private-release-4.18-periodics.yaml index 5049e8f20a168..8f9a868b5a35a 100644 --- a/ci-operator/jobs/openshift/openshift-tests-private/openshift-openshift-tests-private-release-4.18-periodics.yaml +++ b/ci-operator/jobs/openshift/openshift-tests-private/openshift-openshift-tests-private-release-4.18-periodics.yaml @@ -38058,6 +38058,116 @@ periodics: - name: result-aggregator secret: secretName: result-aggregator +- agent: kubernetes + cluster: build10 + cron: 19 22 18 1,3,5,7,9,11 * + decorate: true + decoration_config: + skip_cloning: true + extra_refs: + - base_ref: release-4.18 + org: openshift + repo: openshift-tests-private + labels: + capability/intranet: intranet + ci-operator.openshift.io/cloud: equinix-ocp-metal + ci-operator.openshift.io/cloud-cluster-profile: equinix-ocp-metal-qe + ci-operator.openshift.io/variant: amd64-nightly + ci.openshift.io/generator: prowgen + job-release: "4.18" + pj-rehearse.openshift.io/can-be-rehearsed: "true" + name: periodic-ci-openshift-openshift-tests-private-release-4.18-amd64-nightly-metal-sno-ipv6-http-proxy-f60 + spec: + containers: + - args: + - --enable-secrets-store-csi-driver=true + - --gcs-upload-secret=/secrets/gcs/service-account.json + - --gsm-config=/etc/gsm-config/gsm-config.yaml + - --gsm-credentials-file=/etc/gsm-credentials/key.json + - --gsm-project-config=/etc/gsm-config/gsm-project-config.yaml + - --image-import-pull-secret=/etc/pull-secret/.dockerconfigjson + - --lease-server-credentials-file=/etc/boskos/credentials + - --oauth-token-path=/usr/local/github-credentials/oauth + - --report-credentials-file=/etc/report/credentials + - --secret-dir=/secrets/ci-pull-credentials + - --target=metal-sno-ipv6-http-proxy-f60 + - --variant=amd64-nightly + command: + - ci-operator + env: + - name: HTTP_SERVER_IP + valueFrom: + fieldRef: + fieldPath: status.podIP + image: quay-proxy.ci.openshift.org/openshift/ci:ci_ci-operator_latest + imagePullPolicy: Always + name: "" + ports: + - containerPort: 8080 + name: http + resources: + requests: + cpu: 10m + volumeMounts: + - mountPath: /etc/boskos + name: boskos + readOnly: true + - mountPath: /secrets/ci-pull-credentials + name: ci-pull-credentials + readOnly: true + - mountPath: /secrets/gcs + name: gcs-credentials + readOnly: true + - mountPath: /usr/local/github-credentials + name: github-credentials-openshift-ci-robot-private-git-cloner + readOnly: true + - mountPath: /etc/gsm-config + name: gsm-config + readOnly: true + - mountPath: /etc/gsm-credentials + name: gsm-sa-key + readOnly: true + - mountPath: /secrets/manifest-tool + name: manifest-tool-local-pusher + readOnly: true + - mountPath: /etc/pull-secret + name: pull-secret + readOnly: true + - mountPath: /etc/report + name: result-aggregator + readOnly: true + serviceAccountName: ci-operator + volumes: + - name: boskos + secret: + items: + - key: credentials + path: credentials + secretName: boskos-credentials + - name: ci-pull-credentials + secret: + secretName: ci-pull-credentials + - name: github-credentials-openshift-ci-robot-private-git-cloner + secret: + secretName: github-credentials-openshift-ci-robot-private-git-cloner + - configMap: + name: gsm-config + name: gsm-config + - csi: + driver: secrets-store.csi.k8s.io + readOnly: true + volumeAttributes: + secretProviderClass: ci-operator-sa-key-spc + name: gsm-sa-key + - name: manifest-tool-local-pusher + secret: + secretName: manifest-tool-local-pusher + - name: pull-secret + secret: + secretName: registry-pull-credentials + - name: result-aggregator + secret: + secretName: result-aggregator - agent: kubernetes cluster: build10 cron: 0 0 31 2 * diff --git a/ci-operator/jobs/openshift/openshift-tests-private/openshift-openshift-tests-private-release-4.19-periodics.yaml b/ci-operator/jobs/openshift/openshift-tests-private/openshift-openshift-tests-private-release-4.19-periodics.yaml index 81357e3e664c3..e3fabeac8efd2 100644 --- a/ci-operator/jobs/openshift/openshift-tests-private/openshift-openshift-tests-private-release-4.19-periodics.yaml +++ b/ci-operator/jobs/openshift/openshift-tests-private/openshift-openshift-tests-private-release-4.19-periodics.yaml @@ -55021,6 +55021,116 @@ periodics: - name: result-aggregator secret: secretName: result-aggregator +- agent: kubernetes + cluster: build10 + cron: 29 4 9,23 * * + decorate: true + decoration_config: + skip_cloning: true + extra_refs: + - base_ref: release-4.19 + org: openshift + repo: openshift-tests-private + labels: + capability/intranet: intranet + ci-operator.openshift.io/cloud: equinix-ocp-metal + ci-operator.openshift.io/cloud-cluster-profile: equinix-ocp-metal-qe + ci-operator.openshift.io/variant: arm64-nightly + ci.openshift.io/generator: prowgen + job-release: "4.19" + pj-rehearse.openshift.io/can-be-rehearsed: "true" + name: periodic-ci-openshift-openshift-tests-private-release-4.19-arm64-nightly-metal-sno-ipv6-http-proxy-f28 + spec: + containers: + - args: + - --enable-secrets-store-csi-driver=true + - --gcs-upload-secret=/secrets/gcs/service-account.json + - --gsm-config=/etc/gsm-config/gsm-config.yaml + - --gsm-credentials-file=/etc/gsm-credentials/key.json + - --gsm-project-config=/etc/gsm-config/gsm-project-config.yaml + - --image-import-pull-secret=/etc/pull-secret/.dockerconfigjson + - --lease-server-credentials-file=/etc/boskos/credentials + - --oauth-token-path=/usr/local/github-credentials/oauth + - --report-credentials-file=/etc/report/credentials + - --secret-dir=/secrets/ci-pull-credentials + - --target=metal-sno-ipv6-http-proxy-f28 + - --variant=arm64-nightly + command: + - ci-operator + env: + - name: HTTP_SERVER_IP + valueFrom: + fieldRef: + fieldPath: status.podIP + image: quay-proxy.ci.openshift.org/openshift/ci:ci_ci-operator_latest + imagePullPolicy: Always + name: "" + ports: + - containerPort: 8080 + name: http + resources: + requests: + cpu: 10m + volumeMounts: + - mountPath: /etc/boskos + name: boskos + readOnly: true + - mountPath: /secrets/ci-pull-credentials + name: ci-pull-credentials + readOnly: true + - mountPath: /secrets/gcs + name: gcs-credentials + readOnly: true + - mountPath: /usr/local/github-credentials + name: github-credentials-openshift-ci-robot-private-git-cloner + readOnly: true + - mountPath: /etc/gsm-config + name: gsm-config + readOnly: true + - mountPath: /etc/gsm-credentials + name: gsm-sa-key + readOnly: true + - mountPath: /secrets/manifest-tool + name: manifest-tool-local-pusher + readOnly: true + - mountPath: /etc/pull-secret + name: pull-secret + readOnly: true + - mountPath: /etc/report + name: result-aggregator + readOnly: true + serviceAccountName: ci-operator + volumes: + - name: boskos + secret: + items: + - key: credentials + path: credentials + secretName: boskos-credentials + - name: ci-pull-credentials + secret: + secretName: ci-pull-credentials + - name: github-credentials-openshift-ci-robot-private-git-cloner + secret: + secretName: github-credentials-openshift-ci-robot-private-git-cloner + - configMap: + name: gsm-config + name: gsm-config + - csi: + driver: secrets-store.csi.k8s.io + readOnly: true + volumeAttributes: + secretProviderClass: ci-operator-sa-key-spc + name: gsm-sa-key + - name: manifest-tool-local-pusher + secret: + secretName: manifest-tool-local-pusher + - name: pull-secret + secret: + secretName: registry-pull-credentials + - name: result-aggregator + secret: + secretName: result-aggregator - agent: kubernetes cluster: build10 cron: 0 0 31 2 * diff --git a/ci-operator/jobs/openshift/openshift-tests-private/openshift-openshift-tests-private-release-4.20-periodics.yaml b/ci-operator/jobs/openshift/openshift-tests-private/openshift-openshift-tests-private-release-4.20-periodics.yaml index be4f7d763155c..4f208cbeeb61f 100644 --- a/ci-operator/jobs/openshift/openshift-tests-private/openshift-openshift-tests-private-release-4.20-periodics.yaml +++ b/ci-operator/jobs/openshift/openshift-tests-private/openshift-openshift-tests-private-release-4.20-periodics.yaml @@ -41492,6 +41492,116 @@ periodics: - name: result-aggregator secret: secretName: result-aggregator +- agent: kubernetes + cluster: build10 + cron: 9 23 7,21 * * + decorate: true + decoration_config: + skip_cloning: true + extra_refs: + - base_ref: release-4.20 + org: openshift + repo: openshift-tests-private + labels: + capability/intranet: intranet + ci-operator.openshift.io/cloud: equinix-ocp-metal + ci-operator.openshift.io/cloud-cluster-profile: equinix-ocp-metal-qe + ci-operator.openshift.io/variant: amd64-nightly + ci.openshift.io/generator: prowgen + job-release: "4.20" + pj-rehearse.openshift.io/can-be-rehearsed: "true" + name: periodic-ci-openshift-openshift-tests-private-release-4.20-amd64-nightly-metal-sno-ipv6-http-proxy-f28 + spec: + containers: + - args: + - --enable-secrets-store-csi-driver=true + - --gcs-upload-secret=/secrets/gcs/service-account.json + - --gsm-config=/etc/gsm-config/gsm-config.yaml + - --gsm-credentials-file=/etc/gsm-credentials/key.json + - --gsm-project-config=/etc/gsm-config/gsm-project-config.yaml + - --image-import-pull-secret=/etc/pull-secret/.dockerconfigjson + - --lease-server-credentials-file=/etc/boskos/credentials + - --oauth-token-path=/usr/local/github-credentials/oauth + - --report-credentials-file=/etc/report/credentials + - --secret-dir=/secrets/ci-pull-credentials + - --target=metal-sno-ipv6-http-proxy-f28 + - --variant=amd64-nightly + command: + - ci-operator + env: + - name: HTTP_SERVER_IP + valueFrom: + fieldRef: + fieldPath: status.podIP + image: quay-proxy.ci.openshift.org/openshift/ci:ci_ci-operator_latest + imagePullPolicy: Always + name: "" + ports: + - containerPort: 8080 + name: http + resources: + requests: + cpu: 10m + volumeMounts: + - mountPath: /etc/boskos + name: boskos + readOnly: true + - mountPath: /secrets/ci-pull-credentials + name: ci-pull-credentials + readOnly: true + - mountPath: /secrets/gcs + name: gcs-credentials + readOnly: true + - mountPath: /usr/local/github-credentials + name: github-credentials-openshift-ci-robot-private-git-cloner + readOnly: true + - mountPath: /etc/gsm-config + name: gsm-config + readOnly: true + - mountPath: /etc/gsm-credentials + name: gsm-sa-key + readOnly: true + - mountPath: /secrets/manifest-tool + name: manifest-tool-local-pusher + readOnly: true + - mountPath: /etc/pull-secret + name: pull-secret + readOnly: true + - mountPath: /etc/report + name: result-aggregator + readOnly: true + serviceAccountName: ci-operator + volumes: + - name: boskos + secret: + items: + - key: credentials + path: credentials + secretName: boskos-credentials + - name: ci-pull-credentials + secret: + secretName: ci-pull-credentials + - name: github-credentials-openshift-ci-robot-private-git-cloner + secret: + secretName: github-credentials-openshift-ci-robot-private-git-cloner + - configMap: + name: gsm-config + name: gsm-config + - csi: + driver: secrets-store.csi.k8s.io + readOnly: true + volumeAttributes: + secretProviderClass: ci-operator-sa-key-spc + name: gsm-sa-key + - name: manifest-tool-local-pusher + secret: + secretName: manifest-tool-local-pusher + - name: pull-secret + secret: + secretName: registry-pull-credentials + - name: result-aggregator + secret: + secretName: result-aggregator - agent: kubernetes cluster: build10 cron: 9 5 4 * * diff --git a/ci-operator/jobs/openshift/openshift-tests-private/openshift-openshift-tests-private-release-4.21-periodics.yaml b/ci-operator/jobs/openshift/openshift-tests-private/openshift-openshift-tests-private-release-4.21-periodics.yaml index be1b6b65066dd..e32db8516e3fd 100644 --- a/ci-operator/jobs/openshift/openshift-tests-private/openshift-openshift-tests-private-release-4.21-periodics.yaml +++ b/ci-operator/jobs/openshift/openshift-tests-private/openshift-openshift-tests-private-release-4.21-periodics.yaml @@ -61545,6 +61545,116 @@ periodics: - name: result-aggregator secret: secretName: result-aggregator +- agent: kubernetes + cluster: build10 + cron: 29 22 7,21 * * + decorate: true + decoration_config: + skip_cloning: true + extra_refs: + - base_ref: release-4.21 + org: openshift + repo: openshift-tests-private + labels: + capability/intranet: intranet + ci-operator.openshift.io/cloud: equinix-ocp-metal + ci-operator.openshift.io/cloud-cluster-profile: equinix-ocp-metal-qe + ci-operator.openshift.io/variant: arm64-nightly + ci.openshift.io/generator: prowgen + job-release: "4.21" + pj-rehearse.openshift.io/can-be-rehearsed: "true" + name: periodic-ci-openshift-openshift-tests-private-release-4.21-arm64-nightly-metal-sno-ipv6-http-proxy-f28 + spec: + containers: + - args: + - --enable-secrets-store-csi-driver=true + - --gcs-upload-secret=/secrets/gcs/service-account.json + - --gsm-config=/etc/gsm-config/gsm-config.yaml + - --gsm-credentials-file=/etc/gsm-credentials/key.json + - --gsm-project-config=/etc/gsm-config/gsm-project-config.yaml + - --image-import-pull-secret=/etc/pull-secret/.dockerconfigjson + - --lease-server-credentials-file=/etc/boskos/credentials + - --oauth-token-path=/usr/local/github-credentials/oauth + - --report-credentials-file=/etc/report/credentials + - --secret-dir=/secrets/ci-pull-credentials + - --target=metal-sno-ipv6-http-proxy-f28 + - --variant=arm64-nightly + command: + - ci-operator + env: + - name: HTTP_SERVER_IP + valueFrom: + fieldRef: + fieldPath: status.podIP + image: quay-proxy.ci.openshift.org/openshift/ci:ci_ci-operator_latest + imagePullPolicy: Always + name: "" + ports: + - containerPort: 8080 + name: http + resources: + requests: + cpu: 10m + volumeMounts: + - mountPath: /etc/boskos + name: boskos + readOnly: true + - mountPath: /secrets/ci-pull-credentials + name: ci-pull-credentials + readOnly: true + - mountPath: /secrets/gcs + name: gcs-credentials + readOnly: true + - mountPath: /usr/local/github-credentials + name: github-credentials-openshift-ci-robot-private-git-cloner + readOnly: true + - mountPath: /etc/gsm-config + name: gsm-config + readOnly: true + - mountPath: /etc/gsm-credentials + name: gsm-sa-key + readOnly: true + - mountPath: /secrets/manifest-tool + name: manifest-tool-local-pusher + readOnly: true + - mountPath: /etc/pull-secret + name: pull-secret + readOnly: true + - mountPath: /etc/report + name: result-aggregator + readOnly: true + serviceAccountName: ci-operator + volumes: + - name: boskos + secret: + items: + - key: credentials + path: credentials + secretName: boskos-credentials + - name: ci-pull-credentials + secret: + secretName: ci-pull-credentials + - name: github-credentials-openshift-ci-robot-private-git-cloner + secret: + secretName: github-credentials-openshift-ci-robot-private-git-cloner + - configMap: + name: gsm-config + name: gsm-config + - csi: + driver: secrets-store.csi.k8s.io + readOnly: true + volumeAttributes: + secretProviderClass: ci-operator-sa-key-spc + name: gsm-sa-key + - name: manifest-tool-local-pusher + secret: + secretName: manifest-tool-local-pusher + - name: pull-secret + secret: + secretName: registry-pull-credentials + - name: result-aggregator + secret: + secretName: result-aggregator - agent: kubernetes cluster: build10 cron: 19 4 7 * * diff --git a/ci-operator/jobs/openshift/openshift-tests-private/openshift-openshift-tests-private-release-4.22-periodics.yaml b/ci-operator/jobs/openshift/openshift-tests-private/openshift-openshift-tests-private-release-4.22-periodics.yaml index 737576d862a9e..931285c28bc22 100644 --- a/ci-operator/jobs/openshift/openshift-tests-private/openshift-openshift-tests-private-release-4.22-periodics.yaml +++ b/ci-operator/jobs/openshift/openshift-tests-private/openshift-openshift-tests-private-release-4.22-periodics.yaml @@ -46569,6 +46569,116 @@ periodics: - name: result-aggregator secret: secretName: result-aggregator +- agent: kubernetes + cluster: build10 + cron: 29 0 5,12,19,26 * * + decorate: true + decoration_config: + skip_cloning: true + extra_refs: + - base_ref: release-4.22 + org: openshift + repo: openshift-tests-private + labels: + capability/intranet: intranet + ci-operator.openshift.io/cloud: equinix-ocp-metal + ci-operator.openshift.io/cloud-cluster-profile: equinix-ocp-metal-qe + ci-operator.openshift.io/variant: amd64-nightly + ci.openshift.io/generator: prowgen + job-release: "4.22" + pj-rehearse.openshift.io/can-be-rehearsed: "true" + name: periodic-ci-openshift-openshift-tests-private-release-4.22-amd64-nightly-metal-sno-ipv6-http-proxy-f7 + spec: + containers: + - args: + - --enable-secrets-store-csi-driver=true + - --gcs-upload-secret=/secrets/gcs/service-account.json + - --gsm-config=/etc/gsm-config/gsm-config.yaml + - --gsm-credentials-file=/etc/gsm-credentials/key.json + - --gsm-project-config=/etc/gsm-config/gsm-project-config.yaml + - --image-import-pull-secret=/etc/pull-secret/.dockerconfigjson + - --lease-server-credentials-file=/etc/boskos/credentials + - --oauth-token-path=/usr/local/github-credentials/oauth + - --report-credentials-file=/etc/report/credentials + - --secret-dir=/secrets/ci-pull-credentials + - --target=metal-sno-ipv6-http-proxy-f7 + - --variant=amd64-nightly + command: + - ci-operator + env: + - name: HTTP_SERVER_IP + valueFrom: + fieldRef: + fieldPath: status.podIP + image: quay-proxy.ci.openshift.org/openshift/ci:ci_ci-operator_latest + imagePullPolicy: Always + name: "" + ports: + - containerPort: 8080 + name: http + resources: + requests: + cpu: 10m + volumeMounts: + - mountPath: /etc/boskos + name: boskos + readOnly: true + - mountPath: /secrets/ci-pull-credentials + name: ci-pull-credentials + readOnly: true + - mountPath: /secrets/gcs + name: gcs-credentials + readOnly: true + - mountPath: /usr/local/github-credentials + name: github-credentials-openshift-ci-robot-private-git-cloner + readOnly: true + - mountPath: /etc/gsm-config + name: gsm-config + readOnly: true + - mountPath: /etc/gsm-credentials + name: gsm-sa-key + readOnly: true + - mountPath: /secrets/manifest-tool + name: manifest-tool-local-pusher + readOnly: true + - mountPath: /etc/pull-secret + name: pull-secret + readOnly: true + - mountPath: /etc/report + name: result-aggregator + readOnly: true + serviceAccountName: ci-operator + volumes: + - name: boskos + secret: + items: + - key: credentials + path: credentials + secretName: boskos-credentials + - name: ci-pull-credentials + secret: + secretName: ci-pull-credentials + - name: github-credentials-openshift-ci-robot-private-git-cloner + secret: + secretName: github-credentials-openshift-ci-robot-private-git-cloner + - configMap: + name: gsm-config + name: gsm-config + - csi: + driver: secrets-store.csi.k8s.io + readOnly: true + volumeAttributes: + secretProviderClass: ci-operator-sa-key-spc + name: gsm-sa-key + - name: manifest-tool-local-pusher + secret: + secretName: manifest-tool-local-pusher + - name: pull-secret + secret: + secretName: registry-pull-credentials + - name: result-aggregator + secret: + secretName: result-aggregator - agent: kubernetes cluster: build10 cron: 39 0 3,10,17,24 * * diff --git a/ci-operator/jobs/openshift/openshift-tests-private/openshift-openshift-tests-private-release-5.0-periodics.yaml b/ci-operator/jobs/openshift/openshift-tests-private/openshift-openshift-tests-private-release-5.0-periodics.yaml index 7a7b791249263..ab0c2483c4f55 100644 --- a/ci-operator/jobs/openshift/openshift-tests-private/openshift-openshift-tests-private-release-5.0-periodics.yaml +++ b/ci-operator/jobs/openshift/openshift-tests-private/openshift-openshift-tests-private-release-5.0-periodics.yaml @@ -41897,6 +41897,116 @@ periodics: - name: result-aggregator secret: secretName: result-aggregator +- agent: kubernetes + cluster: build09 + cron: 19 16 2,9,16,23,30 * * + decorate: true + decoration_config: + skip_cloning: true + extra_refs: + - base_ref: release-5.0 + org: openshift + repo: openshift-tests-private + labels: + capability/intranet: intranet + ci-operator.openshift.io/cloud: equinix-ocp-metal + ci-operator.openshift.io/cloud-cluster-profile: equinix-ocp-metal-qe + ci-operator.openshift.io/variant: amd64-nightly + ci.openshift.io/generator: prowgen + job-release: "5.0" + pj-rehearse.openshift.io/can-be-rehearsed: "true" + name: periodic-ci-openshift-openshift-tests-private-release-5.0-amd64-nightly-metal-sno-ipv6-http-proxy-f7 + spec: + containers: + - args: + - --enable-secrets-store-csi-driver=true + - --gcs-upload-secret=/secrets/gcs/service-account.json + - --gsm-config=/etc/gsm-config/gsm-config.yaml + - --gsm-credentials-file=/etc/gsm-credentials/key.json + - --gsm-project-config=/etc/gsm-config/gsm-project-config.yaml + - --image-import-pull-secret=/etc/pull-secret/.dockerconfigjson + - --lease-server-credentials-file=/etc/boskos/credentials + - --oauth-token-path=/usr/local/github-credentials/oauth + - --report-credentials-file=/etc/report/credentials + - --secret-dir=/secrets/ci-pull-credentials + - --target=metal-sno-ipv6-http-proxy-f7 + - --variant=amd64-nightly + command: + - ci-operator + env: + - name: HTTP_SERVER_IP + valueFrom: + fieldRef: + fieldPath: status.podIP + image: quay-proxy.ci.openshift.org/openshift/ci:ci_ci-operator_latest + imagePullPolicy: Always + name: "" + ports: + - containerPort: 8080 + name: http + resources: + requests: + cpu: 10m + volumeMounts: + - mountPath: /etc/boskos + name: boskos + readOnly: true + - mountPath: /secrets/ci-pull-credentials + name: ci-pull-credentials + readOnly: true + - mountPath: /secrets/gcs + name: gcs-credentials + readOnly: true + - mountPath: /usr/local/github-credentials + name: github-credentials-openshift-ci-robot-private-git-cloner + readOnly: true + - mountPath: /etc/gsm-config + name: gsm-config + readOnly: true + - mountPath: /etc/gsm-credentials + name: gsm-sa-key + readOnly: true + - mountPath: /secrets/manifest-tool + name: manifest-tool-local-pusher + readOnly: true + - mountPath: /etc/pull-secret + name: pull-secret + readOnly: true + - mountPath: /etc/report + name: result-aggregator + readOnly: true + serviceAccountName: ci-operator + volumes: + - name: boskos + secret: + items: + - key: credentials + path: credentials + secretName: boskos-credentials + - name: ci-pull-credentials + secret: + secretName: ci-pull-credentials + - name: github-credentials-openshift-ci-robot-private-git-cloner + secret: + secretName: github-credentials-openshift-ci-robot-private-git-cloner + - configMap: + name: gsm-config + name: gsm-config + - csi: + driver: secrets-store.csi.k8s.io + readOnly: true + volumeAttributes: + secretProviderClass: ci-operator-sa-key-spc + name: gsm-sa-key + - name: manifest-tool-local-pusher + secret: + secretName: manifest-tool-local-pusher + - name: pull-secret + secret: + secretName: registry-pull-credentials + - name: result-aggregator + secret: + secretName: result-aggregator - agent: kubernetes cluster: build09 cron: 39 6 3,10,17,24 * * diff --git a/ci-operator/step-registry/baremetal/lab/pre/firewall/baremetal-lab-pre-firewall-commands.sh b/ci-operator/step-registry/baremetal/lab/pre/firewall/baremetal-lab-pre-firewall-commands.sh index 39c41dbf8ab3a..c826f4395efdf 100644 --- a/ci-operator/step-registry/baremetal/lab/pre/firewall/baremetal-lab-pre-firewall-commands.sh +++ b/ci-operator/step-registry/baremetal/lab/pre/firewall/baremetal-lab-pre-firewall-commands.sh @@ -14,16 +14,37 @@ SSHOPTS=(-o 'ConnectTimeout=5' -i "${CLUSTER_PROFILE_DIR}/ssh-key") if [ "$CLUSTER_WIDE_PROXY" == "true" ] || [ "$DISCONNECTED" == "true" ]; then + # Build NO_PROXY for CI scripts using dynamic values only + NO_PROXY_SHELL="localhost,127.0.0.1,::1" + + # Add auxiliary host (CI scripts SSH to it) + if [ -n "${AUX_HOST:-}" ]; then + NO_PROXY_SHELL="${NO_PROXY_SHELL},${AUX_HOST}" + fi + + # Add internal lab networks (where aux host and BMC live) + if [ -n "${INTERNAL_NET_CIDR:-}" ]; then + NO_PROXY_SHELL="${NO_PROXY_SHELL},${INTERNAL_NET_CIDR}" + fi + + if [ -n "${INTERNAL_NET_V6_CIDR:-}" ]; then + NO_PROXY_SHELL="${NO_PROXY_SHELL},${INTERNAL_NET_V6_CIDR}" + fi + + # Add CI infrastructure (don't proxy CI registries and services) + NO_PROXY_SHELL="${NO_PROXY_SHELL},.ci.openshift.org" + proxy="$(<"${CLUSTER_PROFILE_DIR}/proxy")" cat < "${SHARED_DIR}/proxy-conf.sh" export HTTP_PROXY=${proxy} export HTTPS_PROXY=${proxy} - export NO_PROXY="localhost,127.0.0.1" + export NO_PROXY="${NO_PROXY_SHELL}" export http_proxy=${proxy} export https_proxy=${proxy} - export no_proxy="localhost,127.0.0.1" + export no_proxy="${NO_PROXY_SHELL}" EOF + echo "Created ${SHARED_DIR}/proxy-conf.sh with NO_PROXY=${NO_PROXY_SHELL}" fi if [ "${CLUSTER_WIDE_PROXY}" == "true" ]; then diff --git a/ci-operator/step-registry/baremetal/lab/pre/load-balancer/run/baremetal-lab-pre-load-balancer-run-commands.sh b/ci-operator/step-registry/baremetal/lab/pre/load-balancer/run/baremetal-lab-pre-load-balancer-run-commands.sh index 3c0b4c5a621a4..3afd11222a0ae 100644 --- a/ci-operator/step-registry/baremetal/lab/pre/load-balancer/run/baremetal-lab-pre-load-balancer-run-commands.sh +++ b/ci-operator/step-registry/baremetal/lab/pre/load-balancer/run/baremetal-lab-pre-load-balancer-run-commands.sh @@ -252,6 +252,12 @@ if [ "${ipv4_enabled:-false}" == "true" ]; then api_ip=$(nsenter -t "$CONTAINER_PID" -n /sbin/ip -o -4 a list ${api_ip_interface} | sed 's/.*inet \(.*\)\/[0-9]* brd.*$/\1/') fi api_int_ip="$api_ip" + if [ "${DISCONNECTED}" != "true" ] && \ + { [ "${LOAD_BALANCER_TYPE}" == "user-managed" ] || [ "${AGENT_PLATFORM_TYPE}" == "none" ]; }; then + # Connected user-managed LBs use the reserved ingress VIP on eth2 for + # both API and ingress listeners. Keep node-to-API traffic on that network. + api_int_ip="$INTERNAL_INGRESS_IPV4" + fi ingress_vip="$INTERNAL_INGRESS_IPV4" if [ "${#api_ip}" -eq 0 ]; then @@ -267,6 +273,12 @@ if [ "${ipv6_enabled:-false}" == "true" ]; then api_ip_v6=$(nsenter -t "$CONTAINER_PID" -n /sbin/ip -o -6 a list ${api_ip_interface} | grep global | sed 's/.*inet6 \(.*\)\/[0-9]* scope global.*/\1/') fi api_int_ip_v6="$api_ip_v6" + if [ "${DISCONNECTED}" != "true" ] && \ + { [ "${LOAD_BALANCER_TYPE}" == "user-managed" ] || [ "${AGENT_PLATFORM_TYPE}" == "none" ]; }; then + # Using eth1 here makes internal IPv6 clients traverse AUX on the way out, + # while HAProxy replies directly over eth2, bypassing AUX's connection tracking. + api_int_ip_v6="$INTERNAL_INGRESS_IPV6" + fi ingress_vip_v6="$INTERNAL_INGRESS_IPV6" if [ "${#api_ip_v6}" -eq 0 ]; then diff --git a/ci-operator/step-registry/baremetal/lab/sno/bip/OWNERS b/ci-operator/step-registry/baremetal/lab/sno/bip/OWNERS new file mode 100644 index 0000000000000..c3bd2ab0b5294 --- /dev/null +++ b/ci-operator/step-registry/baremetal/lab/sno/bip/OWNERS @@ -0,0 +1,12 @@ +approvers: +- aleskandro +- jadhaj +- mhanss +- pamoedom +- sgoveas +reviewers: +- aleskandro +- jadhaj +- mhanss +- pamoedom +- sgoveas diff --git a/ci-operator/step-registry/baremetal/lab/sno/bip/gather/OWNERS b/ci-operator/step-registry/baremetal/lab/sno/bip/gather/OWNERS new file mode 100644 index 0000000000000..c3bd2ab0b5294 --- /dev/null +++ b/ci-operator/step-registry/baremetal/lab/sno/bip/gather/OWNERS @@ -0,0 +1,12 @@ +approvers: +- aleskandro +- jadhaj +- mhanss +- pamoedom +- sgoveas +reviewers: +- aleskandro +- jadhaj +- mhanss +- pamoedom +- sgoveas diff --git a/ci-operator/step-registry/baremetal/lab/sno/bip/gather/baremetal-lab-sno-bip-gather-commands.sh b/ci-operator/step-registry/baremetal/lab/sno/bip/gather/baremetal-lab-sno-bip-gather-commands.sh new file mode 100644 index 0000000000000..03390b592fcbf --- /dev/null +++ b/ci-operator/step-registry/baremetal/lab/sno/bip/gather/baremetal-lab-sno-bip-gather-commands.sh @@ -0,0 +1,190 @@ +#!/bin/bash + +set -o nounset +set -o pipefail +# Intentionally best effort: an unavailable API, node or previous boot journal +# must not prevent collection from other sources or subsequent lab cleanup. + +if [[ "${BOOTSTRAP_IN_PLACE:-false}" != "true" ]]; then + echo "Skipping diagnostics for a non-BIP installation." + exit 0 +fi + +for required_file in "${SHARED_DIR}/cluster_name" "${SHARED_DIR}/hosts.yaml" \ + "${CLUSTER_PROFILE_DIR}/base_domain" "${CLUSTER_PROFILE_DIR}/ssh-key"; do + if [[ ! -s "${required_file}" ]]; then + echo "Skipping BIP diagnostics: missing ${required_file}." + exit 0 + fi +done + +CLUSTER_NAME=$(<"${SHARED_DIR}/cluster_name") +BASE_DOMAIN=$(<"${CLUSTER_PROFILE_DIR}/base_domain") +API_INT="api-int.${CLUSTER_NAME}.${BASE_DOMAIN}" +ADDRESS_FIELD=ipv6 +if [[ "${ipv4_enabled:-false}" == "true" ]]; then + ADDRESS_FIELD=ip +fi +NODE_IP=$(yq -r "[.[] | select(.name == \"master-00\")][0].${ADDRESS_FIELD}" "${SHARED_DIR}/hosts.yaml") + +# These values cross an SSH command boundary. Accept only namespace, DNS and +# address characters, never shell syntax from a missing or malformed input. +if [[ -z "${AUX_HOST:-}" || ! "${CLUSTER_NAME}" =~ ^[a-z0-9-]+$ || \ + ! "${BASE_DOMAIN}" =~ ^[a-zA-Z0-9.-]+$ || ! "${NODE_IP}" =~ ^[a-fA-F0-9:.]+$ ]]; then + echo "Skipping BIP diagnostics: invalid auxiliary host, cluster name, domain or node address." + exit 0 +fi + +mkdir -p "${ARTIFACT_DIR}" +SSHOPTS=(-o BatchMode=yes -o ConnectTimeout=10 -o ConnectionAttempts=1 + -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null + -o ServerAliveInterval=10 -o ServerAliveCountMax=2 -o LogLevel=ERROR + -i "${CLUSTER_PROFILE_DIR}/ssh-key") + +# CI also elides cluster-profile secrets. Avoid copying secret-bearing files and +# additionally strip URL credentials and authorization headers from text logs. +redact() { + sed -E \ + -e 's#(https?://)[^/@[:space:]]+@#\1[REDACTED]@#g' \ + -e 's#(Authorization:[[:space:]]*(Bearer|Basic)[[:space:]]+)[^[:space:]"]+#\1[REDACTED]#Ig' +} + +collect_api() { + if [[ ! -s "${SHARED_DIR}/kubeconfig" ]]; then + echo "No kubeconfig was saved; collecting SSH diagnostics only." + return + fi + export KUBECONFIG="${SHARED_DIR}/kubeconfig" + if [[ -f "${SHARED_DIR}/proxy-conf.sh" ]]; then + # shellcheck source=/dev/null + source "${SHARED_DIR}/proxy-conf.sh" + fi + echo "Proxy exclusions (not proxy credentials):" + oc --request-timeout=15s get proxy cluster \ + -o 'jsonpath=spec.noProxy={.spec.noProxy}{"\n"}status.noProxy={.status.noProxy}{"\n"}' + echo "Nodes:" + oc --request-timeout=15s get nodes -o wide + echo "Certificate requests (no request or certificate contents):" + oc --request-timeout=15s get csr + echo "Etcd operator conditions:" + oc --request-timeout=15s get etcds.operator.openshift.io cluster \ + -o 'jsonpath={.status.conditions}{"\n"}' +} + +collect_node() { + timeout --signal=TERM --kill-after=10s 8m ssh "${SSHOPTS[@]}" "root@${AUX_HOST}" \ + bash -s -- "${CLUSTER_NAME}" "${NODE_IP}" "${API_INT}" <<'AUX' +set -o nounset +set -o pipefail + +cluster_name=$1 +node_ip=$2 +api_int=$3 +container_name="haproxy-${cluster_name}" +ignition="/var/mnt/data-storage/html/${cluster_name}/bootstrap.ign" + +echo "Generated BIP ignition proxy exclusions:" +if [[ -r "${ignition}" ]]; then + # Read only the profile script's exclusion line, never publish the ignition. + proxy_source=$(jq -r '.storage.files[]? | select(.path == "/etc/profile.d/proxy.sh") | .contents.source // empty' "${ignition}") + case "${proxy_source}" in + data:*';base64,'*) + printf '%s' "${proxy_source#*,}" | base64 --decode | + sed -n -E '/^[[:space:]]*(export[[:space:]]+)?(NO_PROXY|no_proxy)=/p' + ;; + *) echo "Proxy script is absent or does not use the expected base64 data URL." ;; + esac +else + echo "BIP ignition is unavailable." +fi + +container_pid=$(podman inspect -f '{{ .State.Pid }}' "${container_name}") +if [[ ! "${container_pid}" =~ ^[1-9][0-9]*$ ]]; then + echo "The job's HAProxy network namespace is unavailable." + exit 1 +fi + +echo "Load-balancer network state:" +timeout 15s nsenter -n -t "${container_pid}" ip -brief address +timeout 15s nsenter -n -t "${container_pid}" ip -6 route +echo "API-int connectivity from the load-balancer namespace (TLS validation disabled for this probe only):" +timeout 20s nsenter -n -t "${container_pid}" curl --noproxy '*' -k -sS \ + --connect-timeout 5 --max-time 10 -o /dev/null \ + -w 'HTTP %{http_code}; remote %{remote_ip}\n' "https://${api_int}:6443/readyz" + +echo "Connecting to the reserved SNO node ${node_ip}:" +timeout --signal=TERM --kill-after=10s 5m nsenter -n -t "${container_pid}" \ + ssh -o BatchMode=yes -o ConnectTimeout=10 -o ConnectionAttempts=1 \ + -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null \ + -o ServerAliveInterval=10 -o ServerAliveCountMax=2 -o LogLevel=ERROR \ + "core@${node_ip}" sudo -n bash -s -- "${api_int}" <<'NODE' +set -o nounset +set -o pipefail +api_int=$1 + +echo "Boot and disk state:" +date --utc +uname -a +cat /proc/sys/kernel/random/boot_id /proc/cmdline +findmnt -no SOURCE,FSTYPE / +lsblk -o NAME,TYPE,FSTYPE,MOUNTPOINTS + +echo "Systemd unit state:" +timeout 15s systemctl show kubelet crio bootkube install-to-disk \ + -p ActiveState -p SubState -p Result -p ExecMainStatus -p MainPID \ + -p FragmentPath -p DropInPaths -p EnvironmentFiles + +echo "Configured proxy exclusions:" +for proxy_file in /etc/mco/proxy.env /etc/profile.d/proxy.sh; do + if [[ -r "${proxy_file}" ]]; then + echo "${proxy_file}:" + sed -n -E '/^[[:space:]]*(export[[:space:]]+)?(NO_PROXY|no_proxy)=/p' "${proxy_file}" + fi +done +for unit in kubelet crio; do + echo "${unit} process proxy exclusions:" + unit_pid=$(timeout 10s systemctl show "${unit}" -p MainPID --value) + if [[ "${unit_pid}" =~ ^[1-9][0-9]*$ && -r "/proc/${unit_pid}/environ" ]]; then + while IFS= read -r -d '' entry; do + case "${entry}" in + NO_PROXY=*|no_proxy=*) printf '%s\n' "${entry}" ;; + esac + done < "/proc/${unit_pid}/environ" + else + echo "No readable environment for a running ${unit} process." + fi +done + +echo "Node network state:" +ip -brief address +ip -6 route +timeout 15s nmcli -f NAME,UUID,TYPE,DEVICE connection show +timeout 15s nmcli -f GENERAL.DEVICE,GENERAL.STATE,IP6.ADDRESS,IP6.GATEWAY,IP6.DNS device show +timeout 10s getent ahosts "${api_int}" +echo "Direct API probes (TLS validation disabled for these probes only):" +for endpoint in "https://${api_int}:6443/readyz" "https://localhost:6443/readyz"; do + echo "${endpoint}" + curl --noproxy '*' -k -sS --connect-timeout 5 --max-time 10 \ + -o /dev/null -w 'HTTP %{http_code}; remote %{remote_ip}\n' "${endpoint}" +done + +echo "CRI-O containers:" +timeout 20s crictl --runtime-endpoint unix:///var/run/crio/crio.sock ps -a +for boot in 0 -1; do + echo "Relevant journal entries from boot ${boot}:" + timeout 30s journalctl -b "${boot}" --utc --no-pager -n 3000 \ + -u kubelet -u crio -u bootkube -u install-to-disk +done +NODE +AUX +} + +echo "Collecting BIP diagnostics before lab cleanup." +collect_api 2>&1 | redact > "${ARTIFACT_DIR}/cluster-state.txt" +if collect_node 2>&1 | redact > "${ARTIFACT_DIR}/bip-node-and-lb.txt"; then + echo "BIP node and load-balancer diagnostics collected." +else + echo "BIP SSH collection was incomplete; see bip-node-and-lb.txt. Continuing cleanup." +fi +echo "Diagnostics saved in ${ARTIFACT_DIR}." +exit 0 diff --git a/ci-operator/step-registry/baremetal/lab/sno/bip/gather/baremetal-lab-sno-bip-gather-ref.metadata.json b/ci-operator/step-registry/baremetal/lab/sno/bip/gather/baremetal-lab-sno-bip-gather-ref.metadata.json new file mode 100644 index 0000000000000..86c3f4f228b13 --- /dev/null +++ b/ci-operator/step-registry/baremetal/lab/sno/bip/gather/baremetal-lab-sno-bip-gather-ref.metadata.json @@ -0,0 +1,19 @@ +{ + "path": "baremetal/lab/sno/bip/gather/baremetal-lab-sno-bip-gather-ref.yaml", + "owners": { + "approvers": [ + "aleskandro", + "jadhaj", + "mhanss", + "pamoedom", + "sgoveas" + ], + "reviewers": [ + "aleskandro", + "jadhaj", + "mhanss", + "pamoedom", + "sgoveas" + ] + } +} \ No newline at end of file diff --git a/ci-operator/step-registry/baremetal/lab/sno/bip/gather/baremetal-lab-sno-bip-gather-ref.yaml b/ci-operator/step-registry/baremetal/lab/sno/bip/gather/baremetal-lab-sno-bip-gather-ref.yaml new file mode 100644 index 0000000000000..84994302b5dfc --- /dev/null +++ b/ci-operator/step-registry/baremetal/lab/sno/bip/gather/baremetal-lab-sno-bip-gather-ref.yaml @@ -0,0 +1,26 @@ +ref: + as: baremetal-lab-sno-bip-gather + best_effort: true + from_image: + namespace: ci + name: baremetal-qe-base + tag: latest + commands: baremetal-lab-sno-bip-gather-commands.sh + timeout: 10m + grace_period: 30s + resources: + requests: + cpu: 100m + memory: 128Mi + env: + - name: AUX_HOST + default: "" + - name: BOOTSTRAP_IN_PLACE + default: "false" + - name: ipv4_enabled + default: "true" + documentation: |- + Collects bounded, read-only BIP node and lab load-balancer diagnostics before + cleanup, including when the node has not registered with the API. Collects + proxy exclusions without copying full ignition files, kubeconfigs or private + keys. Collection failures must not prevent the lab cleanup steps. diff --git a/ci-operator/step-registry/baremetal/lab/sno/ipv6/OWNERS b/ci-operator/step-registry/baremetal/lab/sno/ipv6/OWNERS new file mode 120000 index 0000000000000..ec405d65a79df --- /dev/null +++ b/ci-operator/step-registry/baremetal/lab/sno/ipv6/OWNERS @@ -0,0 +1 @@ +../OWNERS \ No newline at end of file diff --git a/ci-operator/step-registry/baremetal/lab/sno/ipv6/static/OWNERS b/ci-operator/step-registry/baremetal/lab/sno/ipv6/static/OWNERS new file mode 120000 index 0000000000000..8c272259fbba9 --- /dev/null +++ b/ci-operator/step-registry/baremetal/lab/sno/ipv6/static/OWNERS @@ -0,0 +1 @@ +../../OWNERS \ No newline at end of file diff --git a/ci-operator/step-registry/baremetal/lab/sno/ipv6/static/baremetal-lab-sno-ipv6-static-workflow.metadata.json b/ci-operator/step-registry/baremetal/lab/sno/ipv6/static/baremetal-lab-sno-ipv6-static-workflow.metadata.json new file mode 100644 index 0000000000000..2e4b3b11c9954 --- /dev/null +++ b/ci-operator/step-registry/baremetal/lab/sno/ipv6/static/baremetal-lab-sno-ipv6-static-workflow.metadata.json @@ -0,0 +1,21 @@ +{ + "path": "baremetal/lab/sno/ipv6/static/baremetal-lab-sno-ipv6-static-workflow.yaml", + "owners": { + "approvers": [ + "aleskandro", + "jadhaj", + "jhou1", + "mhanss", + "pamoedom", + "sgoveas" + ], + "reviewers": [ + "aleskandro", + "jadhaj", + "jhou1", + "mhanss", + "pamoedom", + "sgoveas" + ] + } +} \ No newline at end of file diff --git a/ci-operator/step-registry/baremetal/lab/sno/ipv6/static/baremetal-lab-sno-ipv6-static-workflow.yaml b/ci-operator/step-registry/baremetal/lab/sno/ipv6/static/baremetal-lab-sno-ipv6-static-workflow.yaml new file mode 100644 index 0000000000000..4d16c58da2a1e --- /dev/null +++ b/ci-operator/step-registry/baremetal/lab/sno/ipv6/static/baremetal-lab-sno-ipv6-static-workflow.yaml @@ -0,0 +1,24 @@ +workflow: + as: baremetal-lab-sno-ipv6-static + steps: + pre: + - chain: baremetal-lab-sno-ipv6-static-conf + - chain: baremetal-lab-upi-install + - ref: upi-install-heterogeneous + - ref: baremetal-lab-etcd-encryption + post: + - ref: baremetal-lab-sno-bip-gather + - chain: baremetal-lab-post + - ref: send-results-to-reportportal + env: + AGENT_PLATFORM_TYPE: none + BOOTSTRAP_IN_PLACE: "true" + ADDITIONAL_WORKERS: "0" + ipv4_enabled: "false" + ipv6_enabled: "true" + CLUSTER_WIDE_PROXY: "true" + DISCONNECTED: "false" + documentation: |- + The baremetal-lab-sno-ipv6-static workflow provides pre- and post- steps that provision and + deprovision an SNO OpenShift cluster with IPv6 single-stack and cluster-wide HTTP proxy + on a Baremetal lab, allowing job authors to inject their own end-to-end test logic. diff --git a/ci-operator/step-registry/baremetal/lab/sno/ipv6/static/conf/OWNERS b/ci-operator/step-registry/baremetal/lab/sno/ipv6/static/conf/OWNERS new file mode 120000 index 0000000000000..ec405d65a79df --- /dev/null +++ b/ci-operator/step-registry/baremetal/lab/sno/ipv6/static/conf/OWNERS @@ -0,0 +1 @@ +../OWNERS \ No newline at end of file diff --git a/ci-operator/step-registry/baremetal/lab/sno/ipv6/static/conf/baremetal-lab-sno-ipv6-static-conf-chain.metadata.json b/ci-operator/step-registry/baremetal/lab/sno/ipv6/static/conf/baremetal-lab-sno-ipv6-static-conf-chain.metadata.json new file mode 100644 index 0000000000000..8a38e9b8fd3eb --- /dev/null +++ b/ci-operator/step-registry/baremetal/lab/sno/ipv6/static/conf/baremetal-lab-sno-ipv6-static-conf-chain.metadata.json @@ -0,0 +1,21 @@ +{ + "path": "baremetal/lab/sno/ipv6/static/conf/baremetal-lab-sno-ipv6-static-conf-chain.yaml", + "owners": { + "approvers": [ + "aleskandro", + "jadhaj", + "jhou1", + "mhanss", + "pamoedom", + "sgoveas" + ], + "reviewers": [ + "aleskandro", + "jadhaj", + "jhou1", + "mhanss", + "pamoedom", + "sgoveas" + ] + } +} \ No newline at end of file diff --git a/ci-operator/step-registry/baremetal/lab/sno/ipv6/static/conf/baremetal-lab-sno-ipv6-static-conf-chain.yaml b/ci-operator/step-registry/baremetal/lab/sno/ipv6/static/conf/baremetal-lab-sno-ipv6-static-conf-chain.yaml new file mode 100644 index 0000000000000..c777111545442 --- /dev/null +++ b/ci-operator/step-registry/baremetal/lab/sno/ipv6/static/conf/baremetal-lab-sno-ipv6-static-conf-chain.yaml @@ -0,0 +1,21 @@ +chain: + as: baremetal-lab-sno-ipv6-static-conf + steps: + - ref: baremetal-lab-pre-reserve-nodes + - ref: baremetal-lab-pre-dhcp-conf + - chain: baremetal-lab-pre-load-balancer + - ref: baremetal-lab-pre-dns + - ref: baremetal-lab-pre-firewall + - ref: baremetal-lab-pre-pull-artifacts + - ref: baremetal-lab-upi-conf-grub2-ipv6-static + - ref: ipi-conf + - ref: ipi-conf-telemetry + - ref: baremetal-lab-upi-conf-network + - ref: baremetal-lab-rt-kernel + - ref: ipi-conf-proxy + - ref: baremetal-lab-sno-bip + - ref: baremetal-lab-kdump + - ref: baremetal-lab-storage + documentation: |- + The baremetal-lab-sno-ipv6-static-conf chain provisions common configuration for + Single Node OpenShift (SNO) on bare-metal lab with IPv6 static networking and HTTP proxy. diff --git a/ci-operator/step-registry/baremetal/lab/upi/conf/grub2/ipv6/static/baremetal-lab-upi-conf-grub2-ipv6-static-commands.sh b/ci-operator/step-registry/baremetal/lab/upi/conf/grub2/ipv6/static/baremetal-lab-upi-conf-grub2-ipv6-static-commands.sh index 4ddcae1b884a6..13ba90842e272 100644 --- a/ci-operator/step-registry/baremetal/lab/upi/conf/grub2/ipv6/static/baremetal-lab-upi-conf-grub2-ipv6-static-commands.sh +++ b/ci-operator/step-registry/baremetal/lab/upi/conf/grub2/ipv6/static/baremetal-lab-upi-conf-grub2-ipv6-static-commands.sh @@ -46,7 +46,15 @@ for bmhost in $(yq e -o=j -I=0 '.[]' "${SHARED_DIR}/hosts.yaml"); do mac_postfix=${mac//:/-} kargs="$(join_by_semicolon "$ipi_disabled_ifaces" "ip=" ":off")" kargs="$kargs$(join_by_semicolon "$console_kargs" "console=" "")" - [ "$USE_CONSOLE_HOOK" == "true" ] && kargs="${kargs} ignition.config.url=http://[${INTERNAL_NET_IPV6}]/${CLUSTER_NAME}/$mac_postfix-console-hook.ign" + + if [[ "$USE_CONSOLE_HOOK" == "true" ]]; then + if [[ "$BOOTSTRAP_IN_PLACE" == "true" ]]; then + kargs="${kargs} ignition.config.url=http://[${INTERNAL_NET_IPV6}]/${CLUSTER_NAME}/bootstrap.ign" + else + kargs="${kargs} ignition.config.url=http://[${INTERNAL_NET_IPV6}]/${CLUSTER_NAME}/$mac_postfix-console-hook.ign" + fi + fi + if [[ "${name}" == *-a-* ]] && [ "${ADDITIONAL_WORKERS_DAY2}" == "true" ]; then cat > "${GRUB_DIR}/grub.cfg-01-${mac_postfix}" <