chore: update boilerplate - #504
Conversation
WalkthroughThe pull request adds Tekton automation for pull-request checks, introduces a Gangway bridge Job for e2e Prow execution, updates the e2e builder image and instructions, and revises repository ownership aliases. ChangesPipeline automation
End-to-end execution
Ownership updates
Estimated code review effort: 3 (Moderate) | ~25 minutes Sequence Diagram(s)sequenceDiagram
participant BridgeJob as gangway-bridge-e2e Job
participant GangwayAPI as Gangway API
participant Prow
BridgeJob->>GangwayAPI: Submit Prow job with parameters
GangwayAPI-->>BridgeJob: Return execution ID
BridgeJob->>Prow: Poll execution status
Prow-->>BridgeJob: Return terminal status
``
<!-- walkthrough_end -->
<!-- pre_merge_checks_walkthrough_start -->
<details>
<summary>🚥 Pre-merge checks | ✅ 14 | ❌ 1</summary>
### ❌ Failed checks (1 warning)
| Check name | Status | Explanation | Resolution |
| :----------------------------------------------: | :--------- | :------------------------------------------------------------------------------------------------------------------------------------------------------- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Ipv6 And Disconnected Network Test Compatibility | ⚠️ Warning | The new e2e bridge Job pulls quay.io/openshift/origin-tools and calls external Gangway and Prow endpoints with curl, so it requires public connectivity. | IPv6 and disconnected network compatibility notice: verify with the required IPv6 CI job, or use internal mirrors/services; add [Skipped:Disconnected] if external access cannot be removed. |
<details>
<summary>✅ Passed checks (14 passed)</summary>
| Check name | Status | Explanation |
| :--------------------------------------------: | :------- | :-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Description Check | ✅ Passed | Check skipped - CodeRabbit’s high-level summary is enabled. |
| Title check | ✅ Passed | The title accurately identifies the pull request as a boilerplate update and matches the stated maintenance objective. |
| Docstring Coverage | ✅ Passed | No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. |
| Linked Issues check | ✅ Passed | Check skipped because no linked issues were found for this pull request. |
| Out of Scope Changes check | ✅ Passed | Check skipped because no linked issues were found for this pull request. |
| Stable And Deterministic Test Names | ✅ Passed | The PR adds no Go test changes or Ginkgo title lines; existing test and step titles use static text, and the unchanged template placeholder resolves during generation. |
| Test Structure And Quality | ✅ Passed | The PR changes no Ginkgo test source; it updates configuration, ownership, build/docs files, and a YAML Job template, so these test-quality requirements are not applicable. |
| Microshift Test Compatibility | ✅ Passed | The commit adds no Go files or Ginkgo declarations; it changes boilerplate, Tekton YAML, ownership files, Dockerfiles, README text, and a generated Job template only. |
| Single Node Openshift (Sno) Test Compatibility | ✅ Passed | The patch adds no Go or Ginkgo e2e tests; test/e2e changes are limited to a Dockerfile, README formatting, and a Gangway Job template. |
| Topology-Aware Scheduling Compatibility | ✅ Passed | The added PipelineRun and Gangway Job templates define no affinity, topology spread, replica, PDB, node selector, node affinity, or toleration constraints; no operator or controller code changed. |
| Ote Binary Stdout Contract | ✅ Passed | The PR changes no Go or OTE entry-point source; RunSpecs has no stdout writes, fmt writes are inside It blocks, and standard log writes use stderr. Operator main/fips stdout is a separate binary. |
| No-Weak-Crypto | ✅ Passed | Added-line and changed-file scans found no MD5, SHA1, DES, RC4, Blowfish, ECB, or custom crypto; token use only sends a bearer secret and does not compare it. |
| Container-Privileges | ✅ Passed | Changed manifests add no privileged, host PID/network/IPC, SYS_ADMIN, or true allowPrivilegeEscalation settings; the Job runs non-root, drops all capabilities, and uses RuntimeDefault seccomp. |
| No-Sensitive-Data-In-Logs | ✅ Passed | Changed logging emits job metadata, execution status, timing, and a Prow URL; it does not emit the Gangway token, JOB_ENVS values, passwords, API keys, or PII. |
</details>
</details>
<!-- pre_merge_checks_walkthrough_end -->
<!-- finishing_touch_checkbox_start -->
<details>
<summary>✨ Finishing Touches</summary>
<details>
<summary>🧪 Generate unit tests (beta)</summary>
- [ ] <!-- {"checkboxId": "f47ac10b-58cc-4372-a567-0e02b2c3d479", "radioGroupId": "utg-output-choice-group-unknown_comment_id"} --> Create PR with unit tests
</details>
</details>
<!-- finishing_touch_checkbox_end -->
<!-- tips_start -->
---
Thanks for using [CodeRabbit](https://coderabbit.ai?utm_source=oss&utm_medium=github&utm_campaign=openshift/certman-operator&utm_content=504)! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.
<details>
<summary>❤️ Share</summary>
- [X](https://twitter.com/intent/tweet?text=I%20just%20used%20%40coderabbitai%20for%20my%20code%20review%2C%20and%20it%27s%20fantastic%21%20It%27s%20free%20for%20OSS%20and%20offers%20a%20free%20trial%20for%20the%20proprietary%20code.%20Check%20it%20out%3A&url=https%3A//coderabbit.ai)
- [Mastodon](https://mastodon.social/share?text=I%20just%20used%20%40coderabbitai%20for%20my%20code%20review%2C%20and%20it%27s%20fantastic%21%20It%27s%20free%20for%20OSS%20and%20offers%20a%20free%20trial%20for%20the%20proprietary%20code.%20Check%20it%20out%3A%20https%3A%2F%2Fcoderabbit.ai)
- [Reddit](https://www.reddit.com/submit?title=Great%20tool%20for%20code%20review%20-%20CodeRabbit&text=I%20just%20used%20CodeRabbit%20for%20my%20code%20review%2C%20and%20it%27s%20fantastic%21%20It%27s%20free%20for%20OSS%20and%20offers%20a%20free%20trial%20for%20proprietary%20code.%20Check%20it%20out%3A%20https%3A//coderabbit.ai)
- [LinkedIn](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fcoderabbit.ai&mini=true&title=Great%20tool%20for%20code%20review%20-%20CodeRabbit&summary=I%20just%20used%20CodeRabbit%20for%20my%20code%20review%2C%20and%20it%27s%20fantastic%21%20It%27s%20free%20for%20OSS%20and%20offers%20a%20free%20trial%20for%20proprietary%20code)
</details>
<sub>Comment `@coderabbitai help` to get the list of available commands.</sub>
<!-- tips_end -->
<!-- internal state start -->
<!-- N4IgzgxgFgpgtgQwGowE5gJYHsB2IBcAjADTgAuqArhGZajACYDKZCZMBoYF1t9K6bHiKkADqgDyAIwBWMGhgBuMMARABidQAIACgCUtYSnESoAngB0cVgCpQMYLYgw52OBDggxdByqIZsKlpksFriWHI0WlJYGAA2aKJxgVoIjqIIqGRaWABmWgBSGKgIWg5G3noSTACCAKIAcgDiALQAbAAsABwADIQAdCCkJQDuTMamZgCyCKKcIP3sANZkuAD0XlmIOC1YomhsWKgtCADmMK4YEC1gDHHX0PJLLaKUcXEt9ACOlCpk/WYEHA4mpNFoagBJFrnHAHdgMQwTTJmHL5aAec5gKxWGoMBiOUo2GArXBaAAGOgw+ziLhgekoODJWlyRzCbw+31+3FSMLIVy0TAAIgAZADCWkeECWYGIZU8cUoDBcpy09FEWEwq3MThgrACrFlEA8XnebCEa3obj5pPVNIgGBUstEVJgNNhYUyQN1aBlhjQiiu3gQEAgWAZZFlIyO0oyXl9CEoIQufKN1pwfogltlHgRpSaGDInxUWDiygRzuptNVMFyaAuXn62JwYJqcXYJTTjlWwVCDHkyQ7QkceS0MAAHuqsowcqg2VI7aPLnyVE2GrgYE3hbTHOicOcGPgtABqDoATjWLR6Tbq3AwiHhEqwferAZgI1HuRZWUPU0YGGMQwgBIADqDR1HoTCgtokLQhccLTkYJjIqiEpQBiK7WDgACq/iBAiSbkrM4TKOgTI0tyUgomqyT2nu5JgGqLS5AyCi4AgHwJAg+JMjm9GMewQItJx3FaCMBZQOSqAaggNysJ+LQXKctI+mSjaYS2bZwkOwRYD23h9hAA5mrgw75OOk4PqyrzzvyyYFg6WKYWusKbtuqHoQex6EBeABM163ve06hs+9Cvu+NZfmQh7ClgIyASBYEQQA+jUwoQjUTB1JB+AaNBUIwvBCKIZMKG7piTZ6PAWBluSMzsEwCDIkyuRSXAfEwKITEsWm7EtAJcC7CUe4wDxOAIvQcDVdOBFkgxHVdZ4PUfP1NzyHQBZmDxNJpFopxSX4/Tgni05klJYAydwCDyYpymkbKp3SS02xnCp2ZjeSUCdZk0AFvIZBgFtGA7XtYaiI4YkhHpxRaORD5wPAUg+oddjeOIMABmGYBxCifa5LSCIuC1aQ8DQdAwLKzGLUIvXCbKK207t+2dQzvFMHodQ6KkqA/ewUTsUDYBBCMdbVkkwbTpRemC1osLviDfhgGpVgae2xk4F2ukEQZRmdih5lHJZs7WQudnLo5VgtOC22OPDcCI7OE1TZ5ZJ1TADVNcyrXtZ1lOse4y0wIJRzoUyLjkgl4FMClaUZVlZIW1bAuM6D1aTWWh6zYxvtLX1gcDYLEDrWQm1yuHoGR9H6WZUw8c7InwNMwSx3O2dF1ybkCl7rdAP3a3T0eC9d2pO9ZKfSc3P2Lz/2h+mZIR8lqVV3HCetkn8tg6nTsZ3NnWEyULT2hADBkvdO8LX7NOB9xp/8XnQlXz37XQkz99cY/vGZ/N32T39AOl3P5cF4x2rrXKwW5YQ7jQsNTyR4ADMPRfIAHZ/J8kCgiYK3hQoOnCp+A2P4/wAVIOwbgawYA+RgGsQUWApRoDxgkKC4J8pwQ7AhJE2oRxlQwrYUIUhKDxD7LOO8L1RI7U4QiFqWA2oEQAEL0HfBIfYOAmD2FyNkJoJYMTRD4XEAROk9JaAURcZRGBVHVk4tLPQAAJOowotCni0OorQAwfJtC0fwtAZREDnCVs2aCmlBwmT0VrfsnpdYjn1lOBEVlKA2QgIuPkZtVzrlchA9y0DDxHm8i0QgKChEPgwS+bBH5IrRVioBYhZBSHkLWOzGogoph1H6HABgDCYIFRYUVNhKIOFQPKphHC+ppqhDId4Cpyo5TcCoH7RwX4JQDg2sPcRRx7x8joiMewCQwj0EFqgAMdECLnXhsyJQMBZIdVEtGXIcRYqLMfEhMaismwqy0oE7swTDKhO0uEicBtpzRNifE+yXCcDOQ3JhcBQQxEZIAKwXjaLktBj4QroyKRFPBWgYpxSIX8KpFDTgYhGAgMwLQpCoAwAwc4uc4Bi3YACYErSmGwg6YiJC7C0S9OBbiPsuZdrMLwgYxRxjTFEmpckdgWhcYuHGXmAlRLohkopd4C4DA+pYE7giAoWApCHQhNkYMXhRD/S0DILVToSxulOHTO8MAwwRkXAGKSOB4auDegTLxqNPTw3bGAAA3HKRQWAlhBCaLKlEEMJIeByIa6mcQPToGnBcB1uBnXZEQKIP1to4iOB0FJcKY41ppkMKwWgvqYZYFONm3NWgsJ6GFKW3i44CyOCkGkP56YjAhhUL6XICB4hk1lGgKS6BZSslQTaxMyNQiaqkHKQyiogiKH5vqIQspLRksdNWMAYZubeBpHAJtsoC6WhJa23MiZYCXFTCu252yKBXD5MoDMRcUSCzIKsitPjnkBPVkE3sITv2mVHD8yJM45wmyXA5JslsRU0qDM3DO+K9yEuJaS8llKRkz3JBU3FaxEOnGQyShVlL2CisCHSuIJ9RLiTjV6b15ICgSGkUlBoNQGmUYpBIYUwokoQgaDYcCSBUrsZsBCBpEgsI2HYwxpjjQkA13utJiEgpKMf1EzUJodQko2HU6pFJkKOUwNPOeS8CL+UFKwW+Yp6LfxKgAgAX1IH2Vg8RGCiifDAaR1ypTjFZWYPQ6FVD4AANqgCGucCELScphZgElNoDBTwhkIF0DohAegMEQYBDIIQ1CLGJKsHAGw0BkG2LsfYHYjgnF5FcG4dwHiwClC8dkRYfh/ABECEEpBLpZAhQQEgIBlU9fwGeTrXS1Bcq7KEUMorvTkk2MVjwpW4QVZepemr9wD71aWEyIkJJZ6UkrLCekjJDS4DxqcMmSyjZNc5H8UcyhXBdkyOcd95JEDcDQJR8NqQnEOIwNIi5qAYzi1lPmPV567JXtJEe3UspeH8L9LswMqQQxhhdaLDUBYjhURRZgG0nrvTDtuQRZ0OBYQIhiC51AsGwgujdB6kIgxSAYM89QpYbnptjg2moeGtm4AgAc6F9CEW1DRaSj5BAZ4ehdAQF0GAPRTxSEy2wKAah56QU66wbrtJeunlIAN7XRBdfgFGzlFGqRRDEQ8evRwn8fbdRja/ESH8z70wfkyYW9BN41V4tRcWCIvsPXOrJK6HcbqwhUozkAzOvNs8kUkRtxc1DXLigLkA0XhdRfQklU8PQYAdFyIg6FHQeg+VgV0JX2Wcpq8rrHdX5BMhkEGylvXY0m99eKsiNQlU04nVdu7cwzUvYzTPtnB3K1g7DSZLbe2YB7CiBhg4f4gFo+s/Z/HzniecrJ/58QQXw0M9p6z20XIhBYE+VPG0GAbRoUBAryrqvgCo6L1r4BLrjeDfQp8i3hgg3P8jd813lVDVMPlnPbmxAHIJAXM+oDA3CnLxOxLGiOE2jqHbEjMvu5izlKGvgkBvmYEnmUqnunpFofsNElLkF0F0BAGXtCqeIQFdBlmIMrqro/jXtXK/pru/rCAQG0D0N/oNqeF/sbgATlFykMt4IHm3CHp3EpOHkPBIf3O4OcEPB/GPN/L9DQH/PzLAQrFRpDEmNDNsvsAoI+tPh4rDL6L7rRCqMTlgpjNjBKjWPjAKOzJzHvMTFMnwOTDDFfD6HPrKOvI7q6lzDzH9KkNbMnArJHivlgXHjgVzjlDzv+HzoQULsQaLrAjLjfjAIglIAwD0NCrAnfmoNhiMpQqzrQi5uwQ3oNoIfrlwfgIIR3uYGoGblQjQqgHQt4HDjoh4i2tLEIucDLDcpQILDbvQEpJMmYP0PaP0HsBcLPiYv8EcKcGsHMerCopUvQOYjAPgKgLAB8KeEWNsdCBonuNkv0C4otusYsS0B0BcT5DPO9lxChGSKSm+P0OMYvuYB8YwGhP8NgBaFALsGAFIGAKsYogsaoicckGcd0QIrsfsdnklM4m0KpOgX2JgbHhzvESANvikfvmkVntCl0LkLnm0LArAm0DkYQEUTlCUdUrUvUo0s0lUVrvUbUa3gboQI0SbiAJVFGKgNyvoi4BQE+LwFjrtHwgEJ4EGO9PQF+CsmIcco+vQFNs6kKSMsELdu9mDJGOJLamkjIdYb2NQsYMmEFJItsPiKBgKUsFcrFFERgTHtgQnngVvgQbviQeFoSaQQgNCoghALLgwF0NClID5C0owZXiAPSXiqGoRmhqciRrBuRqyZwRwCIP1pyeyR0P/pMGNs3PooYkohsVoDBmKt4F6lxGwKULxBkCUF6j6MyKyILAkAoPsqEDmjcialIGau8OMiKf6OxFavDLaiOtGuAcalqvasUMmsmFoIumSggPOBuu0vyt2VoEpkEZyMUNOAMaMmcI6Ric6bEa6dzgQskZ6UQSLlnj5IgogrngrklqeHkbSdGTiqUXhgRqhoqlSsmWYPShrtUQbj5NCnwQbrAkbk0W6SAKITyq8WwNAGsIoIQEyNOqJFABqN4KuQ+O4EclNlIG5ARHucEGcLcuuZuboRGloAAF5oC6QtpSh5D5B7oFgnY4BnZ0BLmbLBgPr6RXx06yg4C4BFhv7jLqgMBBEhpIZyrfmDGhiuC9pMqHkebHnYmb4gCJH2aXmpHXmkHQowDQqEAdBtCEBSBdBmXl6Rn35vkkIflxmyWJnwB/kAX15snpnF5gX1H3m5md4iEFkEQOWGCZhUh2ouBzpKj7LWoGm1nmrjKLo0jLq4BjlLT0aMZJSyY1xxqYB0Qim6QFBMASANDZjg6Xr8pSX4ZypGBSD7pgC47phfZroOQDr5qFyFpKZAYUA8XXqdnvg1q2LXKnBGmHrFojFhCxV7h0xoD7r+zB7ioJ5aBQJ3DKhBFjoGk9p9qe6LUWrKWYkum4FqD2CnAq74nem6XnBJQMBxaIKECBwwBGZS6vkxm4b2VEaOWka0r/kdauVpkEDXWeXpnJY+XNF+VCnyXOZMrTmOoppUZkp0SzIERJnlk0YNnoC3KlCrBBrpjXJcTTgSJSKhBkiflEonDOiqqY1MhMDyCWg7WqXr44maUXl76nWZ6kF54BAQA34QUIAuKPXvnVJE0oavW/nlkpmAVuUEAhn/UEBGZA3QWwVaCig6BYS3K2wSk3bcBgksVGo+5/BkrGHeBg2KUeJQFkrFx+hvrKi+hhUKgRUqhCU7BSRYDZDjgFrXqlD0BcS7A4D2GdFgBmDvZwCyhKjnTLnlhkoBgJCDEqBGhirXoMBSQW5BSzBLnxBArxjvTBI9pvDZAFxTbz7hCdE02r4nn7UJHnn84AC6wwKKb4rmlpBYEWgWQWIAXQsCBeqWbQbQAhN1UghAl+LiHQVBJep43NrdNYEAHQk9UgbQPkRoHAVdIAaMv4qA5woom2gWoADg+gmJddJgyYOgGo8IBAPaWa5MIADgEgJECqfYwgJ9gsjm1CkyyobmJEL0EIrgaA/sLAgQnADmUe7m/mUgBFZAwEUk7AOaNgBY9C+Ad9Z9s+YYOimJ+gx97E99IASoDAR2bRLAsNFaa9TwBAPAZ9GDR2kDZACQ+DUohDVAxD5KWD0dZK45OAlDSwKDp9pAboQaDAEItVXIODaggEyQ3ALDlURgbYTdoAkoSwDQXoaggoDDIVQgCtm2VRJa1DvweuE4MJasagLDhgSwVI+wCIlsbmfYgDwDgAmASOCHVAkJDKCxpQVlCOAXBcWMCR6TR9hqCEqoA4DKiARHAYAyHsQsMyPwxqB9iQCMNpg76SObahPpkgBkObJSOqMjHqNn3mTaPROm6hAJLcUhicXsD2Hkp2R4xBDE7sjVgtbcg7SlAU4JBU5I1+CDIq0IWwATbeCXRwyKVuDGjeBaqRC8WR7bIliJhCAEA4DsikAeMJPeO+N7iASqmnaBNkxsNoMBNBNxAhOyN0lQMcCp5SPxNyOP13p0Qv0HDnCpOBZEOaNizuDZMgBrjMhgE/osgMgEzpgERiLHIJAax3bsSUApAMAnO4OPiv3eICgGMW7jLAsQBP10ShjgsG2bbDPFgKgPOgO/QSoguW1NmzgESj6BI1XZXGnwB6LnR8hgC5AohfNTQlCDEhDbIYU6LuPuZeOZDzOnD+NkqbPbNhM5SwvwsVoxNR5xM7MgDgJcMbm8P6YEOAVqP4A3P9ZaMDwPN6NgBQtGPRDyAJjSxCUL44BSvlBciiQixvPvTw32DpCVPq1L7TNss5RzN+OkAbMuDBNiv8u4kuBcM8MVBgA1C1VdopoiuHPisSCJgoRMChj7DKMBaoRyv14KtKuZOqvjM5TquasSw6sjHeD6ucO7kyvgxmuo6XY9gOBsjvBVNch2saUOsgBOsLMus8tutbMesJO2oSC5BRtzFr0BYBujFgDBsHNttqDf3LngjvTyPtjTWL78hEjcjxOqDytpOKs0PV3yUcX0BrMZMqv3NpuJMdkGBcTWn6uOIVKGlBCsj5iGunCax7MGsqB+qNq3j7K3a8Q6nBB7OOA5tFpmhxLsBjh2q8QEQsQGZanvWow0QwDMu6IjOlhBAMDrR0TYVCCotbrotpuTPvD2ueM5SDpHDcuBMtt8sJOFzcCSIhsjum63Y4O8BkwTsIgACKgLNIiey71za7ae8gyz52W7MDqDO7dzOjOT3g+gF7jgp73rt7Wp3IW6dAXgfqBYWgzTgQO4PHhT16sUTKCxogsO2iDAawgrPzG68BWgAAmqxrYmhYjYEIeprO06Mn8C0D8PzGbduRNMmASJ7kJXqhbnaK42h6M9k1h3EDh7Mxy86yAK6/7CR2oGR6sIzaK08EczlFMFcGdCWfO9kGvmaARax3gex+k+u+p3x7A7c1k/u2bmqUp8exJ7pI4r7aBte0sNJ9rJ8iZIp9kJws2rEA07BrKDtvluZ5ZyOiMNp3PsZ76G0UGh0S5r6IyQ0lqYB0EaUNhdONZ05UjbgNjIFxh7gBM1M7W7h/WxF421F82zF1R1HiMQl5R8l+K0wMqJsmuM+EWZCdkAABRMBCUACUpZt2OXfIeXXOhXq7GjXHG7KzpXAn5Xqb+3InHoZA0AqQeIdXDiukV7UnukmpFSpaMZ4nXMu6d4v0+EukpQ03FRCQsoC3dQeLKyy1aNDioahQU5NntKizaLYz8PIXYX7LPjkX0X7r93nr8XFHw7wvCTNgewJY5axKNQ3j3gUbsAiHFqCtceuXqdbHibK7SrSz7FUP6ZZXyrQnDzZux704+2rotIR2ty5VyGLPM6bPCHjh7o+rIeUqxcdM0vA1L6aMXEq6HU/nsoOggo0igl7mforZWo4fz47vvjnvoGqwDTasj46snVIppa+rcx5Ws4rIYNUk7wHiBSYiu3XPwgPPR34X/PZ3gvrbEvcXN3YvnpobnrEg4q0ibr2oLAwLEbbmrgJQNAVzRXEPJXhvMPxvFX8PB7onBg3XQx6PoGEg/G8S5gLwsQrghg26CnWgR2TARh1jO0+r3APf2QIwptG6uQcAp/5/Xn3gLgmAz4uq0QMe6dRUrAY0mQCIA1okN/yn0sx/g6Q6IYhz5OBFKawPGBvGP4Gly2pQQWHWRSAEV3A3xDnuhzL4HdsOlfNQPh1QCEdeWV3UXolxb4JMIQogRQK4hqCTsHA8lWEDQGnANBdQtpf7tyEB4YBgeWvLpiuyN569N2Y/dhhPzh7CBp+MsSzJqUCpoVXg7wRwC5ymIAk1i73VYhd1VQlgCQ70GOlmg6qf12ITPaSiiF4g9VFwDAdUBn0ooSg6AoXTfmUGyDucggxsfkNQL+hKANopfB5hCB0BkDbkwdewbQIRCwgyAjAvOhr3y5DEUwOxecmgBMRhpqMBEawQiFcHuDRQEIScj2VAw/sByPjLQfulQBDowSOyAMHGD9THstAQWJgJmwPCCgqBuAGgfCArplAzIgHTQbGn1RdoJQHgHztqy9xuNAIMzPnpy1wHEd8BjfQgVdzXAtBgIgcZ4KKHMCGosAQ/MHmfW4EG9t2sPPdlP1gpCQqwvEMRExBcxBUPAMyEtvPymCChQKAoSxDUBIBaBBQWUanqKBzJaAWcIwPGLPllB1BRQYfUDAQIlBTDVgfqDGhcD/79NvaL6ZVASG1aZBjaVNXUB4KwBBA2hAQz3AWGcGYdDu3QvDlkII5NsiOl3evjlAIF3cpQKXEAH33BpoAWgOaRwZHRUCzDde3HfXrx14FoMU2KwwQb22gSgDfGtYDWijx8G6RxAFImAPuFlAYVuQOgJTGsF8G2k1grg0ULKCYBmcn89SXjCOnxY0MwiyeckRHQFEwAbwMdFPq+nfR48p0U5KgD+ntqfAsATtIOgnQJCVsjQGQNgU1VuQ5tHAR2MdPIyzptgMwedJEdzxRF1tsBfQ7EQSPFZ4jxewYz1iMMprqx7IygFoIKGrItB36LQGKMK1B40jIe9IpYfwOZG6MwOA1I0qOH3RGp1ylZfUAgGaqu0ocI1X0KggZ6md9BfVTrti1hFO1CxSnAiHbzlR/CcAsoaTOlQaByZ5yALDdBkFqoCl8QsoGoKKK0BBp/ayo3QBCAhA+jy+fo47gGMxF4CcR13cjskQXpCMyA+geRpE0UZT8AAVKeOAh/F8A54iwKgG4TlsYBoAgcu4BlI+AewbAMILQmWTRBeuiQJprhFpS3jsQd4nAOeKKAlBzxh4ILFUFqCNBWgnQXoIQArofcoAb6MGPgDWAWhfibAfoGwCEaYAPA/QXwWsFJSxRBYNSaoPUGaDtBugfQH7k2GgmUS4JNExCRXUPCoSyA6EzCfQAYB/FcJ5DNIARJwBETdQJE3NORJglUT4JtEwgAAH48JEgC7gAF4YAZgAoKIAhAmoMADQYCHoGkY2A4gMgBoNRTM5jgGgMgJAHAAaCCgzOsCI4XECgBHCsI0KMzj5AABaUAMztRRqAuSbAektyTICwgYAxQBQEYJpNiBuSfIcQHoAgEsRIBgpoERQFICYCEAAA0lhEID2hcgjHQRsTH0BJNSOGFegIeBU7ip6mf4n+n/QTCrAdAurN2MWnTKgB9xtUnNgwBqBkBKoYUXekWLczhgCAPQP+lgjqrzAz+v0A/H0FPC1gT8hAFoAwFyLQoWgiCM8NcAoI+QegLQU8IggQAwBYEUgM/AgEIC5AfI/OOzHZiAA== -->
<!-- internal state end -->
|
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: TheUndeadKing The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
There was a problem hiding this comment.
Actionable comments posted: 2
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@test/e2e/gangway-bridge-template.yml`:
- Line 25: Add a NetworkPolicy manifest to the template’s objects alongside the
bridge Job, label the Job pod so the policy selects it, and restrict egress to
only DNS and the required Gangway destination. Ensure the namespace has a
NetworkPolicy defined and preserve the existing Job behavior.
- Line 56: Update the curl invocation in the gangway POST execution flow to
remove automatic retries, or explicitly reconcile the request outcome before
retrying; do not use --retry for this state-changing endpoint without
idempotency or deduplication support.
🪄 Autofix
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Repository YAML (base), Central YAML (inherited)
Review profile: CHILL
Plan: Pro Plus
Run ID: 38ba384d-9e7c-44c6-bb52-22b29dae799b
⛔ Files ignored due to path filters (12)
boilerplate/_data/last-boilerplate-commitis excluded by!boilerplate/**boilerplate/openshift/golang-osd-e2e/OWNERSis excluded by!boilerplate/**boilerplate/openshift/golang-osd-e2e/README.mdis excluded by!boilerplate/**boilerplate/openshift/golang-osd-e2e/gangway-bridge-template.ymlis excluded by!boilerplate/**boilerplate/openshift/golang-osd-e2e/standard.mkis excluded by!boilerplate/**boilerplate/openshift/golang-osd-e2e/updateis excluded by!boilerplate/**boilerplate/openshift/golang-osd-operator/OWNERS_ALIASESis excluded by!boilerplate/**boilerplate/openshift/golang-osd-operator/agentic-sdlc-check-pull-request.yaml.tmplis excluded by!boilerplate/**boilerplate/openshift/golang-osd-operator/updateis excluded by!boilerplate/**boilerplate/updateis excluded by!boilerplate/**build/Dockerfileis excluded by!build/**build/Dockerfile.olm-registryis excluded by!build/**
📒 Files selected for processing (6)
.tekton/certman-operator-agentic-sdlc-check-pull-request.yamlOWNERSOWNERS_ALIASEStest/e2e/Dockerfiletest/e2e/README.mdtest/e2e/gangway-bridge-template.yml
| - name: IMAGE_TAG | ||
| value: '' | ||
| required: true | ||
| objects: |
There was a problem hiding this comment.
🔒 Security & Privacy | 🟠 Major | 🏗️ Heavy lift
Add a NetworkPolicy for the bridge Job.
The template creates a token-bearing Job but does not define a NetworkPolicy. Add pod labels and an egress policy that permits only required DNS and Gangway access.
As per path instructions, a Kubernetes/OpenShift manifest requires a NetworkPolicy defined for the namespace.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@test/e2e/gangway-bridge-template.yml` at line 25, Add a NetworkPolicy
manifest to the template’s objects alongside the bridge Job, label the Job pod
so the policy selects it, and restrict egress to only DNS and the required
Gangway destination. Ensure the namespace has a NetworkPolicy defined and
preserve the existing Job behavior.
Source: Path instructions
| BODY=$(jq -cn --argjson e "$ENVS" '{"job_execution_type":"1","pod_spec_options":{"envs":$e}}') | ||
| fi | ||
|
|
||
| RESP=$(curl -sfSL --retry 3 --retry-delay 10 -X POST -H "Authorization: Bearer ${GANGWAY_TOKEN}" -H "Content-Type: application/json" -d "${BODY}" "${GW}/${JOB_NAME}") |
There was a problem hiding this comment.
🗄️ Data Integrity & Integration | 🟠 Major | 🏗️ Heavy lift
🧩 Analysis chain
🏁 Script executed:
#!/bin/bash
set -eu
file=$(git ls-files 'test/e2e/gangway-bridge-template.yml')
printf '%s\n' "$file"
wc -l "$file"
cat -n "$file" | sed -n '1,120p'
printf '\nGangway and retry references:\n'
rg -n -i 'gangway|idempot|retry|JOB_NAME|Prow' --glob '!vendor/**' --glob '!node_modules/**' .Repository: openshift/certman-operator
Length of output: 16313
🌐 Web query:
Gangway OpenShift POST job execution API idempotency duplicate request retry
💡 Result:
The Gangway API, used in OpenShift/Prow for triggering jobs, does not natively implement idempotency keys or request deduplication for the CreateJobExecution POST endpoint [1][2][3]. As a result, if a client performs a retry on a POST request to /v1/executions due to a network error or timeout, there is a risk that the API will trigger multiple, distinct job executions [1][2]. The API treats each successful POST request as a command to create a new job instance [2][3]. Key technical considerations regarding this behavior include: 1. Absence of Idempotency Tokens: The Gangway proto definition for CreateJobExecution does not include a field for a client-provided idempotency key [2][4]. 2. Execution IDs: Gangway assigns a unique ID to each execution [3]. When a job is triggered, the response returns the details of that specific, newly created execution [2][3]. 3. Client-Side Mitigation: Because the server-side logic does not provide native de-duplication, clients are responsible for handling retries safely. If a request appears to time out but the job may have been created, a common pattern is to query the status of recently triggered jobs or check if a job with identical parameters already exists [5][6]. 4. API Transcoding: While Gangway uses gRPC internally, it is often exposed via a REST API (typically through transcoding proxies like ESPv2) [1]. Standard HTTP POST semantics apply, where retrying without logic to verify the previous request's outcome can lead to duplicate side effects [2][5]. If you are developing a client for Gangway, it is recommended to design your application logic to handle potential job duplication or verify the job state before blindly retrying requests [5].
Citations:
- 1: https://docs.prow.k8s.io/docs/components/optional/gangway/
- 2: https://github.com/kubernetes-sigs/prow/blob/main/pkg/gangway/gangway.proto
- 3: https://github.com/kubernetes-sigs/prow/blob/main/pkg/gangway/gangway.go
- 4: https://github.com/kubernetes-sigs/prow/blob/main/pkg/gangway/gangway.pb.go
- 5: https://hypershift.pages.dev/how-to/ci/triggering-jobs-on-demand/
- 6: https://github.com/kubernetes-sigs/prow/blob/main/pkg/examples/gangway/main.go
🏁 Script executed:
#!/bin/bash
set -eu
tmp=$(mktemp -d)
trap 'rm -rf "$tmp"' EXIT
curl -fsSL https://raw.githubusercontent.com/kubernetes-sigs/prow/main/pkg/gangway/gangway.proto \
-o "$tmp/gangway.proto"
curl -fsSL https://raw.githubusercontent.com/kubernetes-sigs/prow/main/pkg/gangway/gangway.go \
-o "$tmp/gangway.go"
printf '%s\n' 'CreateJobExecution definition:'
rg -n -A18 -B4 'CreateJobExecution|JobExecution' "$tmp/gangway.proto" | head -120
printf '%s\n' 'CreateJobExecution implementation and execution creation:'
rg -n -A35 -B8 'CreateJobExecution|create.*execution|JobExecution' "$tmp/gangway.go" | head -220
printf '%s\n' 'curl retry documentation for POST and transient failures:'
curl --manual 2>/dev/null | rg -n -A12 -B4 -- '--retry( |$)|POST' | head -160Repository: openshift/certman-operator
Length of output: 13202
Prevent duplicate Prow executions on POST retry.
curl --retry can resend this state-changing POST after a transient failure. Gangway does not provide an idempotency key or request deduplication for this endpoint. Reconcile the request outcome before retrying, or remove automatic retries for this POST.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@test/e2e/gangway-bridge-template.yml` at line 56, Update the curl invocation
in the gangway POST execution flow to remove automatic retries, or explicitly
reconcile the request outcome before retrying; do not use --retry for this
state-changing endpoint without idempotency or deduplication support.
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## master #504 +/- ##
=======================================
Coverage 57.14% 57.14%
=======================================
Files 29 29
Lines 2170 2170
=======================================
Hits 1240 1240
Misses 812 812
Partials 118 118 🚀 New features to boost your workflow:
|
Boilerplate validation expects brew.registry.redhat.io/rh-osbs/openshift-golang-builder:rhel_9_1.26
|
@TheUndeadKing: The following test failed, say
Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
What:
This is a maintenance PR that perform boilerplate update.
Jira: ROSAENG-64801
Summary by CodeRabbit
New Features
Documentation
Chores