Skip to content

chore: update boilerplate - #504

Open
TheUndeadKing wants to merge 2 commits into
openshift:masterfrom
TheUndeadKing:ROSAENG-64801
Open

chore: update boilerplate#504
TheUndeadKing wants to merge 2 commits into
openshift:masterfrom
TheUndeadKing:ROSAENG-64801

Conversation

@TheUndeadKing

@TheUndeadKing TheUndeadKing commented Aug 11, 2026

Copy link
Copy Markdown
Member

What:
This is a maintenance PR that perform boilerplate update.

Jira: ROSAENG-64801

Summary by CodeRabbit

  • New Features

    • Added automated pull-request SDLC checks through the CI pipeline.
    • Added an end-to-end Gangway bridge template that launches jobs, monitors progress, reports status, and handles timeouts or failures.
    • Updated end-to-end testing to use the latest Go-based build environment.
  • Documentation

    • Clarified and reformatted end-to-end testing instructions.
  • Chores

    • Updated repository approval and ownership groups to reflect current responsibilities.

@coderabbitai

coderabbitai Bot commented Aug 11, 2026

Copy link
Copy Markdown

Walkthrough

The pull request adds Tekton automation for pull-request checks, introduces a Gangway bridge Job for e2e Prow execution, updates the e2e builder image and instructions, and revises repository ownership aliases.

Changes

Pipeline automation

Layer / File(s) Summary
Pull-request PipelineRun configuration
.tekton/certman-operator-agentic-sdlc-check-pull-request.yaml
Adds a Tekton PipelineRun for pull requests targeting master. It configures repository parameters, a 1 GiB workspace, Git authentication, the build service account, retention settings, and the pinned pipeline reference.

End-to-end execution

Layer / File(s) Summary
Gangway bridge Job flow
test/e2e/gangway-bridge-template.yml
Adds an OpenShift Template and batch/v1 Job. The bridge validates inputs, submits jobs to Gangway, polls Prow status, logs execution URLs, handles terminal states and timeouts, and applies authentication, resource, and security settings.
E2E image and usage updates
test/e2e/Dockerfile, test/e2e/README.md
Changes the builder image to the OpenShift RHEL 9 Go 1.26 image. Reformats the five-step e2e instructions without changing their commands.

Ownership updates

Layer / File(s) Summary
Approver and alias group changes
OWNERS, OWNERS_ALIASES
Replaces the listed approver groups with rosa-staff-engineers. Removes obsolete aliases and membership, and adds rosa-staff-engineers, rosa-managers, and hp-architects groups.

Estimated code review effort: 3 (Moderate) | ~25 minutes

Sequence Diagram(s)

sequenceDiagram
  participant BridgeJob as gangway-bridge-e2e Job
  participant GangwayAPI as Gangway API
  participant Prow
  BridgeJob->>GangwayAPI: Submit Prow job with parameters
  GangwayAPI-->>BridgeJob: Return execution ID
  BridgeJob->>Prow: Poll execution status
  Prow-->>BridgeJob: Return terminal status
``

<!-- walkthrough_end -->
<!-- pre_merge_checks_walkthrough_start -->

<details>
<summary>🚥 Pre-merge checks | ✅ 14 | ❌ 1</summary>

### ❌ Failed checks (1 warning)

|                    Check name                    | Status     | Explanation                                                                                                                                              | Resolution                                                                                                                                                                                   |
| :----------------------------------------------: | :--------- | :------------------------------------------------------------------------------------------------------------------------------------------------------- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Ipv6 And Disconnected Network Test Compatibility | ⚠️ Warning | The new e2e bridge Job pulls quay.io/openshift/origin-tools and calls external Gangway and Prow endpoints with curl, so it requires public connectivity. | IPv6 and disconnected network compatibility notice: verify with the required IPv6 CI job, or use internal mirrors/services; add [Skipped:Disconnected] if external access cannot be removed. |

<details>
<summary>✅ Passed checks (14 passed)</summary>

|                   Check name                   | Status   | Explanation                                                                                                                                                                                         |
| :--------------------------------------------: | :------- | :-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|                Description Check               | ✅ Passed | Check skipped - CodeRabbit’s high-level summary is enabled.                                                                                                                                         |
|                   Title check                  | ✅ Passed | The title accurately identifies the pull request as a boilerplate update and matches the stated maintenance objective.                                                                              |
|               Docstring Coverage               | ✅ Passed | No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.                                                                                          |
|               Linked Issues check              | ✅ Passed | Check skipped because no linked issues were found for this pull request.                                                                                                                            |
|           Out of Scope Changes check           | ✅ Passed | Check skipped because no linked issues were found for this pull request.                                                                                                                            |
|       Stable And Deterministic Test Names      | ✅ Passed | The PR adds no Go test changes or Ginkgo title lines; existing test and step titles use static text, and the unchanged template placeholder resolves during generation.                             |
|           Test Structure And Quality           | ✅ Passed | The PR changes no Ginkgo test source; it updates configuration, ownership, build/docs files, and a YAML Job template, so these test-quality requirements are not applicable.                        |
|          Microshift Test Compatibility         | ✅ Passed | The commit adds no Go files or Ginkgo declarations; it changes boilerplate, Tekton YAML, ownership files, Dockerfiles, README text, and a generated Job template only.                              |
| Single Node Openshift (Sno) Test Compatibility | ✅ Passed | The patch adds no Go or Ginkgo e2e tests; test/e2e changes are limited to a Dockerfile, README formatting, and a Gangway Job template.                                                              |
|     Topology-Aware Scheduling Compatibility    | ✅ Passed | The added PipelineRun and Gangway Job templates define no affinity, topology spread, replica, PDB, node selector, node affinity, or toleration constraints; no operator or controller code changed. |
|           Ote Binary Stdout Contract           | ✅ Passed | The PR changes no Go or OTE entry-point source; RunSpecs has no stdout writes, fmt writes are inside It blocks, and standard log writes use stderr. Operator main/fips stdout is a separate binary. |
|                 No-Weak-Crypto                 | ✅ Passed | Added-line and changed-file scans found no MD5, SHA1, DES, RC4, Blowfish, ECB, or custom crypto; token use only sends a bearer secret and does not compare it.                                      |
|              Container-Privileges              | ✅ Passed | Changed manifests add no privileged, host PID/network/IPC, SYS_ADMIN, or true allowPrivilegeEscalation settings; the Job runs non-root, drops all capabilities, and uses RuntimeDefault seccomp.    |
|            No-Sensitive-Data-In-Logs           | ✅ Passed | Changed logging emits job metadata, execution status, timing, and a Prow URL; it does not emit the Gangway token, JOB_ENVS values, passwords, API keys, or PII.                                     |

</details>

</details>

<!-- pre_merge_checks_walkthrough_end -->
<!-- finishing_touch_checkbox_start -->

<details>
<summary>✨ Finishing Touches</summary>

<details>
<summary>🧪 Generate unit tests (beta)</summary>

- [ ] <!-- {"checkboxId": "f47ac10b-58cc-4372-a567-0e02b2c3d479", "radioGroupId": "utg-output-choice-group-unknown_comment_id"} -->   Create PR with unit tests

</details>

</details>

<!-- finishing_touch_checkbox_end -->
<!-- tips_start -->

---

Thanks for using [CodeRabbit](https://coderabbit.ai?utm_source=oss&utm_medium=github&utm_campaign=openshift/certman-operator&utm_content=504)! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

<details>
<summary>❤️ Share</summary>

- [X](https://twitter.com/intent/tweet?text=I%20just%20used%20%40coderabbitai%20for%20my%20code%20review%2C%20and%20it%27s%20fantastic%21%20It%27s%20free%20for%20OSS%20and%20offers%20a%20free%20trial%20for%20the%20proprietary%20code.%20Check%20it%20out%3A&url=https%3A//coderabbit.ai)
- [Mastodon](https://mastodon.social/share?text=I%20just%20used%20%40coderabbitai%20for%20my%20code%20review%2C%20and%20it%27s%20fantastic%21%20It%27s%20free%20for%20OSS%20and%20offers%20a%20free%20trial%20for%20the%20proprietary%20code.%20Check%20it%20out%3A%20https%3A%2F%2Fcoderabbit.ai)
- [Reddit](https://www.reddit.com/submit?title=Great%20tool%20for%20code%20review%20-%20CodeRabbit&text=I%20just%20used%20CodeRabbit%20for%20my%20code%20review%2C%20and%20it%27s%20fantastic%21%20It%27s%20free%20for%20OSS%20and%20offers%20a%20free%20trial%20for%20proprietary%20code.%20Check%20it%20out%3A%20https%3A//coderabbit.ai)
- [LinkedIn](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fcoderabbit.ai&mini=true&title=Great%20tool%20for%20code%20review%20-%20CodeRabbit&summary=I%20just%20used%20CodeRabbit%20for%20my%20code%20review%2C%20and%20it%27s%20fantastic%21%20It%27s%20free%20for%20OSS%20and%20offers%20a%20free%20trial%20for%20proprietary%20code)

</details>


<sub>Comment `@coderabbitai help` to get the list of available commands.</sub>

<!-- tips_end -->
<!-- internal state start -->


<!-- N4IgzgxgFgpgtgQwGowE5gJYHsB2IBcAjADTgAuqArhGZajACYDKZCZMBoYF1t9K6bHiKkADqgDyAIwBWMGhgBuMMARABidQAIACgCUtYSnESoAngB0cVgCpQMYLYgw52OBDggxdByqIZsKlpksFriWHI0WlJYGAA2aKJxgVoIjqIIqGRaWABmWgBSGKgIWg5G3noSTACCAKIAcgDiALQAbAAsABwADIQAdCCkJQDuTMamZgCyCKKcIP3sANZkuAD0XlmIOC1YomhsWKgtCADmMK4YEC1gDHHX0PJLLaKUcXEt9ACOlCpk/WYEHA4mpNFoagBJFrnHAHdgMQwTTJmHL5aAec5gKxWGoMBiOUo2GArXBaAAGOgw+ziLhgekoODJWlyRzCbw+31+3FSMLIVy0TAAIgAZADCWkeECWYGIZU8cUoDBcpy09FEWEwq3MThgrACrFlEA8XnebCEa3obj5pPVNIgGBUstEVJgNNhYUyQN1aBlhjQiiu3gQEAgWAZZFlIyO0oyXl9CEoIQufKN1pwfogltlHgRpSaGDInxUWDiygRzuptNVMFyaAuXn62JwYJqcXYJTTjlWwVCDHkyQ7QkceS0MAAHuqsowcqg2VI7aPLnyVE2GrgYE3hbTHOicOcGPgtABqDoATjWLR6Tbq3AwiHhEqwferAZgI1HuRZWUPU0YGGMQwgBIADqDR1HoTCgtokLQhccLTkYJjIqiEpQBiK7WDgACq/iBAiSbkrM4TKOgTI0tyUgomqyT2nu5JgGqLS5AyCi4AgHwJAg+JMjm9GMewQItJx3FaCMBZQOSqAaggNysJ+LQXKctI+mSjaYS2bZwkOwRYD23h9hAA5mrgw75OOk4PqyrzzvyyYFg6WKYWusKbtuqHoQex6EBeABM163ve06hs+9Cvu+NZfmQh7ClgIyASBYEQQA+jUwoQjUTB1JB+AaNBUIwvBCKIZMKG7piTZ6PAWBluSMzsEwCDIkyuRSXAfEwKITEsWm7EtAJcC7CUe4wDxOAIvQcDVdOBFkgxHVdZ4PUfP1NzyHQBZmDxNJpFopxSX4/Tgni05klJYAydwCDyYpymkbKp3SS02xnCp2ZjeSUCdZk0AFvIZBgFtGA7XtYaiI4YkhHpxRaORD5wPAUg+oddjeOIMABmGYBxCifa5LSCIuC1aQ8DQdAwLKzGLUIvXCbKK207t+2dQzvFMHodQ6KkqA/ewUTsUDYBBCMdbVkkwbTpRemC1osLviDfhgGpVgae2xk4F2ukEQZRmdih5lHJZs7WQudnLo5VgtOC22OPDcCI7OE1TZ5ZJ1TADVNcyrXtZ1lOse4y0wIJRzoUyLjkgl4FMClaUZVlZIW1bAuM6D1aTWWh6zYxvtLX1gcDYLEDrWQm1yuHoGR9H6WZUw8c7InwNMwSx3O2dF1ybkCl7rdAP3a3T0eC9d2pO9ZKfSc3P2Lz/2h+mZIR8lqVV3HCetkn8tg6nTsZ3NnWEyULT2hADBkvdO8LX7NOB9xp/8XnQlXz37XQkz99cY/vGZ/N32T39AOl3P5cF4x2rrXKwW5YQ7jQsNTyR4ADMPRfIAHZ/J8kCgiYK3hQoOnCp+A2P4/wAVIOwbgawYA+RgGsQUWApRoDxgkKC4J8pwQ7AhJE2oRxlQwrYUIUhKDxD7LOO8L1RI7U4QiFqWA2oEQAEL0HfBIfYOAmD2FyNkJoJYMTRD4XEAROk9JaAURcZRGBVHVk4tLPQAAJOowotCni0OorQAwfJtC0fwtAZREDnCVs2aCmlBwmT0VrfsnpdYjn1lOBEVlKA2QgIuPkZtVzrlchA9y0DDxHm8i0QgKChEPgwS+bBH5IrRVioBYhZBSHkLWOzGogoph1H6HABgDCYIFRYUVNhKIOFQPKphHC+ppqhDId4Cpyo5TcCoH7RwX4JQDg2sPcRRx7x8joiMewCQwj0EFqgAMdECLnXhsyJQMBZIdVEtGXIcRYqLMfEhMaismwqy0oE7swTDKhO0uEicBtpzRNifE+yXCcDOQ3JhcBQQxEZIAKwXjaLktBj4QroyKRFPBWgYpxSIX8KpFDTgYhGAgMwLQpCoAwAwc4uc4Bi3YACYErSmGwg6YiJC7C0S9OBbiPsuZdrMLwgYxRxjTFEmpckdgWhcYuHGXmAlRLohkopd4C4DA+pYE7giAoWApCHQhNkYMXhRD/S0DILVToSxulOHTO8MAwwRkXAGKSOB4auDegTLxqNPTw3bGAAA3HKRQWAlhBCaLKlEEMJIeByIa6mcQPToGnBcB1uBnXZEQKIP1to4iOB0FJcKY41ppkMKwWgvqYZYFONm3NWgsJ6GFKW3i44CyOCkGkP56YjAhhUL6XICB4hk1lGgKS6BZSslQTaxMyNQiaqkHKQyiogiKH5vqIQspLRksdNWMAYZubeBpHAJtsoC6WhJa23MiZYCXFTCu252yKBXD5MoDMRcUSCzIKsitPjnkBPVkE3sITv2mVHD8yJM45wmyXA5JslsRU0qDM3DO+K9yEuJaS8llKRkz3JBU3FaxEOnGQyShVlL2CisCHSuIJ9RLiTjV6b15ICgSGkUlBoNQGmUYpBIYUwokoQgaDYcCSBUrsZsBCBpEgsI2HYwxpjjQkA13utJiEgpKMf1EzUJodQko2HU6pFJkKOUwNPOeS8CL+UFKwW+Yp6LfxKgAgAX1IH2Vg8RGCiifDAaR1ypTjFZWYPQ6FVD4AANqgCGucCELScphZgElNoDBTwhkIF0DohAegMEQYBDIIQ1CLGJKsHAGw0BkG2LsfYHYjgnF5FcG4dwHiwClC8dkRYfh/ABECEEpBLpZAhQQEgIBlU9fwGeTrXS1Bcq7KEUMorvTkk2MVjwpW4QVZepemr9wD71aWEyIkJJZ6UkrLCekjJDS4DxqcMmSyjZNc5H8UcyhXBdkyOcd95JEDcDQJR8NqQnEOIwNIi5qAYzi1lPmPV567JXtJEe3UspeH8L9LswMqQQxhhdaLDUBYjhURRZgG0nrvTDtuQRZ0OBYQIhiC51AsGwgujdB6kIgxSAYM89QpYbnptjg2moeGtm4AgAc6F9CEW1DRaSj5BAZ4ehdAQF0GAPRTxSEy2wKAah56QU66wbrtJeunlIAN7XRBdfgFGzlFGqRRDEQ8evRwn8fbdRja/ESH8z70wfkyYW9BN41V4tRcWCIvsPXOrJK6HcbqwhUozkAzOvNs8kUkRtxc1DXLigLkA0XhdRfQklU8PQYAdFyIg6FHQeg+VgV0JX2Wcpq8rrHdX5BMhkEGylvXY0m99eKsiNQlU04nVdu7cwzUvYzTPtnB3K1g7DSZLbe2YB7CiBhg4f4gFo+s/Z/HzniecrJ/58QQXw0M9p6z20XIhBYE+VPG0GAbRoUBAryrqvgCo6L1r4BLrjeDfQp8i3hgg3P8jd813lVDVMPlnPbmxAHIJAXM+oDA3CnLxOxLGiOE2jqHbEjMvu5izlKGvgkBvmYEnmUqnunpFofsNElLkF0F0BAGXtCqeIQFdBlmIMrqro/jXtXK/pru/rCAQG0D0N/oNqeF/sbgATlFykMt4IHm3CHp3EpOHkPBIf3O4OcEPB/GPN/L9DQH/PzLAQrFRpDEmNDNsvsAoI+tPh4rDL6L7rRCqMTlgpjNjBKjWPjAKOzJzHvMTFMnwOTDDFfD6HPrKOvI7q6lzDzH9KkNbMnArJHivlgXHjgVzjlDzv+HzoQULsQaLrAjLjfjAIglIAwD0NCrAnfmoNhiMpQqzrQi5uwQ3oNoIfrlwfgIIR3uYGoGblQjQqgHQt4HDjoh4i2tLEIucDLDcpQILDbvQEpJMmYP0PaP0HsBcLPiYv8EcKcGsHMerCopUvQOYjAPgKgLAB8KeEWNsdCBonuNkv0C4otusYsS0B0BcT5DPO9lxChGSKSm+P0OMYvuYB8YwGhP8NgBaFALsGAFIGAKsYogsaoicckGcd0QIrsfsdnklM4m0KpOgX2JgbHhzvESANvikfvmkVntCl0LkLnm0LArAm0DkYQEUTlCUdUrUvUo0s0lUVrvUbUa3gboQI0SbiAJVFGKgNyvoi4BQE+LwFjrtHwgEJ4EGO9PQF+CsmIcco+vQFNs6kKSMsELdu9mDJGOJLamkjIdYb2NQsYMmEFJItsPiKBgKUsFcrFFERgTHtgQnngVvgQbviQeFoSaQQgNCoghALLgwF0NClID5C0owZXiAPSXiqGoRmhqciRrBuRqyZwRwCIP1pyeyR0P/pMGNs3PooYkohsVoDBmKt4F6lxGwKULxBkCUF6j6MyKyILAkAoPsqEDmjcialIGau8OMiKf6OxFavDLaiOtGuAcalqvasUMmsmFoIumSggPOBuu0vyt2VoEpkEZyMUNOAMaMmcI6Ric6bEa6dzgQskZ6UQSLlnj5IgogrngrklqeHkbSdGTiqUXhgRqhoqlSsmWYPShrtUQbj5NCnwQbrAkbk0W6SAKITyq8WwNAGsIoIQEyNOqJFABqN4KuQ+O4EclNlIG5ARHucEGcLcuuZuboRGloAAF5oC6QtpSh5D5B7oFgnY4BnZ0BLmbLBgPr6RXx06yg4C4BFhv7jLqgMBBEhpIZyrfmDGhiuC9pMqHkebHnYmb4gCJH2aXmpHXmkHQowDQqEAdBtCEBSBdBmXl6Rn35vkkIflxmyWJnwB/kAX15snpnF5gX1H3m5md4iEFkEQOWGCZhUh2ouBzpKj7LWoGm1nmrjKLo0jLq4BjlLT0aMZJSyY1xxqYB0Qim6QFBMASANDZjg6Xr8pSX4ZypGBSD7pgC47phfZroOQDr5qFyFpKZAYUA8XXqdnvg1q2LXKnBGmHrFojFhCxV7h0xoD7r+zB7ioJ5aBQJ3DKhBFjoGk9p9qe6LUWrKWYkum4FqD2CnAq74nem6XnBJQMBxaIKECBwwBGZS6vkxm4b2VEaOWka0r/kdauVpkEDXWeXpnJY+XNF+VCnyXOZMrTmOoppUZkp0SzIERJnlk0YNnoC3KlCrBBrpjXJcTTgSJSKhBkiflEonDOiqqY1MhMDyCWg7WqXr44maUXl76nWZ6kF54BAQA34QUIAuKPXvnVJE0oavW/nlkpmAVuUEAhn/UEBGZA3QWwVaCig6BYS3K2wSk3bcBgksVGo+5/BkrGHeBg2KUeJQFkrFx+hvrKi+hhUKgRUqhCU7BSRYDZDjgFrXqlD0BcS7A4D2GdFgBmDvZwCyhKjnTLnlhkoBgJCDEqBGhirXoMBSQW5BSzBLnxBArxjvTBI9pvDZAFxTbz7hCdE02r4nn7UJHnn84AC6wwKKb4rmlpBYEWgWQWIAXQsCBeqWbQbQAhN1UghAl+LiHQVBJep43NrdNYEAHQk9UgbQPkRoHAVdIAaMv4qA5woom2gWoADg+gmJddJgyYOgGo8IBAPaWa5MIADgEgJECqfYwgJ9gsjm1CkyyobmJEL0EIrgaA/sLAgQnADmUe7m/mUgBFZAwEUk7AOaNgBY9C+Ad9Z9s+YYOimJ+gx97E99IASoDAR2bRLAsNFaa9TwBAPAZ9GDR2kDZACQ+DUohDVAxD5KWD0dZK45OAlDSwKDp9pAboQaDAEItVXIODaggEyQ3ALDlURgbYTdoAkoSwDQXoaggoDDIVQgCtm2VRJa1DvweuE4MJasagLDhgSwVI+wCIlsbmfYgDwDgAmASOCHVAkJDKCxpQVlCOAXBcWMCR6TR9hqCEqoA4DKiARHAYAyHsQsMyPwxqB9iQCMNpg76SObahPpkgBkObJSOqMjHqNn3mTaPROm6hAJLcUhicXsD2Hkp2R4xBDE7sjVgtbcg7SlAU4JBU5I1+CDIq0IWwATbeCXRwyKVuDGjeBaqRC8WR7bIliJhCAEA4DsikAeMJPeO+N7iASqmnaBNkxsNoMBNBNxAhOyN0lQMcCp5SPxNyOP13p0Qv0HDnCpOBZEOaNizuDZMgBrjMhgE/osgMgEzpgERiLHIJAax3bsSUApAMAnO4OPiv3eICgGMW7jLAsQBP10ShjgsG2bbDPFgKgPOgO/QSoguW1NmzgESj6BI1XZXGnwB6LnR8hgC5AohfNTQlCDEhDbIYU6LuPuZeOZDzOnD+NkqbPbNhM5SwvwsVoxNR5xM7MgDgJcMbm8P6YEOAVqP4A3P9ZaMDwPN6NgBQtGPRDyAJjSxCUL44BSvlBciiQixvPvTw32DpCVPq1L7TNss5RzN+OkAbMuDBNiv8u4kuBcM8MVBgA1C1VdopoiuHPisSCJgoRMChj7DKMBaoRyv14KtKuZOqvjM5TquasSw6sjHeD6ucO7kyvgxmuo6XY9gOBsjvBVNch2saUOsgBOsLMus8tutbMesJO2oSC5BRtzFr0BYBujFgDBsHNttqDf3LngjvTyPtjTWL78hEjcjxOqDytpOKs0PV3yUcX0BrMZMqv3NpuJMdkGBcTWn6uOIVKGlBCsj5iGunCax7MGsqB+qNq3j7K3a8Q6nBB7OOA5tFpmhxLsBjh2q8QEQsQGZanvWow0QwDMu6IjOlhBAMDrR0TYVCCotbrotpuTPvD2ueM5SDpHDcuBMtt8sJOFzcCSIhsjum63Y4O8BkwTsIgACKgLNIiey71za7ae8gyz52W7MDqDO7dzOjOT3g+gF7jgp73rt7Wp3IW6dAXgfqBYWgzTgQO4PHhT16sUTKCxogsO2iDAawgrPzG68BWgAAmqxrYmhYjYEIeprO06Mn8C0D8PzGbduRNMmASJ7kJXqhbnaK42h6M9k1h3EDh7Mxy86yAK6/7CR2oGR6sIzaK08EczlFMFcGdCWfO9kGvmaARax3gex+k+u+p3x7A7c1k/u2bmqUp8exJ7pI4r7aBte0sNJ9rJ8iZIp9kJws2rEA07BrKDtvluZ5ZyOiMNp3PsZ76G0UGh0S5r6IyQ0lqYB0EaUNhdONZ05UjbgNjIFxh7gBM1M7W7h/WxF421F82zF1R1HiMQl5R8l+K0wMqJsmuM+EWZCdkAABRMBCUACUpZt2OXfIeXXOhXq7GjXHG7KzpXAn5Xqb+3InHoZA0AqQeIdXDiukV7UnukmpFSpaMZ4nXMu6d4v0+EukpQ03FRCQsoC3dQeLKyy1aNDioahQU5NntKizaLYz8PIXYX7LPjkX0X7r93nr8XFHw7wvCTNgewJY5axKNQ3j3gUbsAiHFqCtceuXqdbHibK7SrSz7FUP6ZZXyrQnDzZux704+2rotIR2ty5VyGLPM6bPCHjh7o+rIeUqxcdM0vA1L6aMXEq6HU/nsoOggo0igl7mforZWo4fz47vvjnvoGqwDTasj46snVIppa+rcx5Ws4rIYNUk7wHiBSYiu3XPwgPPR34X/PZ3gvrbEvcXN3YvnpobnrEg4q0ibr2oLAwLEbbmrgJQNAVzRXEPJXhvMPxvFX8PB7onBg3XQx6PoGEg/G8S5gLwsQrghg26CnWgR2TARh1jO0+r3APf2QIwptG6uQcAp/5/Xn3gLgmAz4uq0QMe6dRUrAY0mQCIA1okN/yn0sx/g6Q6IYhz5OBFKawPGBvGP4Gly2pQQWHWRSAEV3A3xDnuhzL4HdsOlfNQPh1QCEdeWV3UXolxb4JMIQogRQK4hqCTsHA8lWEDQGnANBdQtpf7tyEB4YBgeWvLpiuyN569N2Y/dhhPzh7CBp+MsSzJqUCpoVXg7wRwC5ymIAk1i73VYhd1VQlgCQ70GOlmg6qf12ITPaSiiF4g9VFwDAdUBn0ooSg6AoXTfmUGyDucggxsfkNQL+hKANopfB5hCB0BkDbkwdewbQIRCwgyAjAvOhr3y5DEUwOxecmgBMRhpqMBEawQiFcHuDRQEIScj2VAw/sByPjLQfulQBDowSOyAMHGD9THstAQWJgJmwPCCgqBuAGgfCArplAzIgHTQbGn1RdoJQHgHztqy9xuNAIMzPnpy1wHEd8BjfQgVdzXAtBgIgcZ4KKHMCGosAQ/MHmfW4EG9t2sPPdlP1gpCQqwvEMRExBcxBUPAMyEtvPymCChQKAoSxDUBIBaBBQWUanqKBzJaAWcIwPGLPllB1BRQYfUDAQIlBTDVgfqDGhcD/79NvaL6ZVASG1aZBjaVNXUB4KwBBA2hAQz3AWGcGYdDu3QvDlkII5NsiOl3evjlAIF3cpQKXEAH33BpoAWgOaRwZHRUCzDde3HfXrx14FoMU2KwwQb22gSgDfGtYDWijx8G6RxAFImAPuFlAYVuQOgJTGsF8G2k1grg0ULKCYBmcn89SXjCOnxY0MwiyeckRHQFEwAbwMdFPq+nfR48p0U5KgD+ntqfAsATtIOgnQJCVsjQGQNgU1VuQ5tHAR2MdPIyzptgMwedJEdzxRF1tsBfQ7EQSPFZ4jxewYz1iMMprqx7IygFoIKGrItB36LQGKMK1B40jIe9IpYfwOZG6MwOA1I0qOH3RGp1ylZfUAgGaqu0ocI1X0KggZ6md9BfVTrti1hFO1CxSnAiHbzlR/CcAsoaTOlQaByZ5yALDdBkFqoCl8QsoGoKKK0BBp/ayo3QBCAhA+jy+fo47gGMxF4CcR13cjskQXpCMyA+geRpE0UZT8AAVKeOAh/F8A54iwKgG4TlsYBoAgcu4BlI+AewbAMILQmWTRBeuiQJprhFpS3jsQd4nAOeKKAlBzxh4ILFUFqCNBWgnQXoIQArofcoAb6MGPgDWAWhfibAfoGwCEaYAPA/QXwWsFJSxRBYNSaoPUGaDtBugfQH7k2GgmUS4JNExCRXUPCoSyA6EzCfQAYB/FcJ5DNIARJwBETdQJE3NORJglUT4JtEwgAAH48JEgC7gAF4YAZgAoKIAhAmoMADQYCHoGkY2A4gMgBoNRTM5jgGgMgJAHAAaCCgzOsCI4XECgBHCsI0KMzj5AABaUAMztRRqAuSbAektyTICwgYAxQBQEYJpNiBuSfIcQHoAgEsRIBgpoERQFICYCEAAA0lhEID2hcgjHQRsTH0BJNSOGFegIeBU7ip6mf4n+n/QTCrAdAurN2MWnTKgB9xtUnNgwBqBkBKoYUXekWLczhgCAPQP+lgjqrzAz+v0A/H0FPC1gT8hAFoAwFyLQoWgiCM8NcAoI+QegLQU8IggQAwBYEUgM/AgEIC5AfI/OOzHZiAA== -->

<!-- internal state end -->
Loading

@openshift-ci

openshift-ci Bot commented Aug 11, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: TheUndeadKing

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci openshift-ci Bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Aug 11, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@test/e2e/gangway-bridge-template.yml`:
- Line 25: Add a NetworkPolicy manifest to the template’s objects alongside the
bridge Job, label the Job pod so the policy selects it, and restrict egress to
only DNS and the required Gangway destination. Ensure the namespace has a
NetworkPolicy defined and preserve the existing Job behavior.
- Line 56: Update the curl invocation in the gangway POST execution flow to
remove automatic retries, or explicitly reconcile the request outcome before
retrying; do not use --retry for this state-changing endpoint without
idempotency or deduplication support.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Central YAML (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: 38ba384d-9e7c-44c6-bb52-22b29dae799b

📥 Commits

Reviewing files that changed from the base of the PR and between ca5b1b7 and 83f7106.

⛔ Files ignored due to path filters (12)
  • boilerplate/_data/last-boilerplate-commit is excluded by !boilerplate/**
  • boilerplate/openshift/golang-osd-e2e/OWNERS is excluded by !boilerplate/**
  • boilerplate/openshift/golang-osd-e2e/README.md is excluded by !boilerplate/**
  • boilerplate/openshift/golang-osd-e2e/gangway-bridge-template.yml is excluded by !boilerplate/**
  • boilerplate/openshift/golang-osd-e2e/standard.mk is excluded by !boilerplate/**
  • boilerplate/openshift/golang-osd-e2e/update is excluded by !boilerplate/**
  • boilerplate/openshift/golang-osd-operator/OWNERS_ALIASES is excluded by !boilerplate/**
  • boilerplate/openshift/golang-osd-operator/agentic-sdlc-check-pull-request.yaml.tmpl is excluded by !boilerplate/**
  • boilerplate/openshift/golang-osd-operator/update is excluded by !boilerplate/**
  • boilerplate/update is excluded by !boilerplate/**
  • build/Dockerfile is excluded by !build/**
  • build/Dockerfile.olm-registry is excluded by !build/**
📒 Files selected for processing (6)
  • .tekton/certman-operator-agentic-sdlc-check-pull-request.yaml
  • OWNERS
  • OWNERS_ALIASES
  • test/e2e/Dockerfile
  • test/e2e/README.md
  • test/e2e/gangway-bridge-template.yml

- name: IMAGE_TAG
value: ''
required: true
objects:

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟠 Major | 🏗️ Heavy lift

Add a NetworkPolicy for the bridge Job.

The template creates a token-bearing Job but does not define a NetworkPolicy. Add pod labels and an egress policy that permits only required DNS and Gangway access.

As per path instructions, a Kubernetes/OpenShift manifest requires a NetworkPolicy defined for the namespace.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@test/e2e/gangway-bridge-template.yml` at line 25, Add a NetworkPolicy
manifest to the template’s objects alongside the bridge Job, label the Job pod
so the policy selects it, and restrict egress to only DNS and the required
Gangway destination. Ensure the namespace has a NetworkPolicy defined and
preserve the existing Job behavior.

Source: Path instructions

BODY=$(jq -cn --argjson e "$ENVS" '{"job_execution_type":"1","pod_spec_options":{"envs":$e}}')
fi

RESP=$(curl -sfSL --retry 3 --retry-delay 10 -X POST -H "Authorization: Bearer ${GANGWAY_TOKEN}" -H "Content-Type: application/json" -d "${BODY}" "${GW}/${JOB_NAME}")

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🗄️ Data Integrity & Integration | 🟠 Major | 🏗️ Heavy lift

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -eu
file=$(git ls-files 'test/e2e/gangway-bridge-template.yml')
printf '%s\n' "$file"
wc -l "$file"
cat -n "$file" | sed -n '1,120p'
printf '\nGangway and retry references:\n'
rg -n -i 'gangway|idempot|retry|JOB_NAME|Prow' --glob '!vendor/**' --glob '!node_modules/**' .

Repository: openshift/certman-operator

Length of output: 16313


🌐 Web query:

Gangway OpenShift POST job execution API idempotency duplicate request retry

💡 Result:

The Gangway API, used in OpenShift/Prow for triggering jobs, does not natively implement idempotency keys or request deduplication for the CreateJobExecution POST endpoint [1][2][3]. As a result, if a client performs a retry on a POST request to /v1/executions due to a network error or timeout, there is a risk that the API will trigger multiple, distinct job executions [1][2]. The API treats each successful POST request as a command to create a new job instance [2][3]. Key technical considerations regarding this behavior include: 1. Absence of Idempotency Tokens: The Gangway proto definition for CreateJobExecution does not include a field for a client-provided idempotency key [2][4]. 2. Execution IDs: Gangway assigns a unique ID to each execution [3]. When a job is triggered, the response returns the details of that specific, newly created execution [2][3]. 3. Client-Side Mitigation: Because the server-side logic does not provide native de-duplication, clients are responsible for handling retries safely. If a request appears to time out but the job may have been created, a common pattern is to query the status of recently triggered jobs or check if a job with identical parameters already exists [5][6]. 4. API Transcoding: While Gangway uses gRPC internally, it is often exposed via a REST API (typically through transcoding proxies like ESPv2) [1]. Standard HTTP POST semantics apply, where retrying without logic to verify the previous request's outcome can lead to duplicate side effects [2][5]. If you are developing a client for Gangway, it is recommended to design your application logic to handle potential job duplication or verify the job state before blindly retrying requests [5].

Citations:


🏁 Script executed:

#!/bin/bash
set -eu
tmp=$(mktemp -d)
trap 'rm -rf "$tmp"' EXIT

curl -fsSL https://raw.githubusercontent.com/kubernetes-sigs/prow/main/pkg/gangway/gangway.proto \
  -o "$tmp/gangway.proto"
curl -fsSL https://raw.githubusercontent.com/kubernetes-sigs/prow/main/pkg/gangway/gangway.go \
  -o "$tmp/gangway.go"

printf '%s\n' 'CreateJobExecution definition:'
rg -n -A18 -B4 'CreateJobExecution|JobExecution' "$tmp/gangway.proto" | head -120
printf '%s\n' 'CreateJobExecution implementation and execution creation:'
rg -n -A35 -B8 'CreateJobExecution|create.*execution|JobExecution' "$tmp/gangway.go" | head -220

printf '%s\n' 'curl retry documentation for POST and transient failures:'
curl --manual 2>/dev/null | rg -n -A12 -B4 -- '--retry( |$)|POST' | head -160

Repository: openshift/certman-operator

Length of output: 13202


Prevent duplicate Prow executions on POST retry.

curl --retry can resend this state-changing POST after a transient failure. Gangway does not provide an idempotency key or request deduplication for this endpoint. Reconcile the request outcome before retrying, or remove automatic retries for this POST.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@test/e2e/gangway-bridge-template.yml` at line 56, Update the curl invocation
in the gangway POST execution flow to remove automatic retries, or explicitly
reconcile the request outcome before retrying; do not use --retry for this
state-changing endpoint without idempotency or deduplication support.

@codecov

codecov Bot commented Aug 11, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 57.14%. Comparing base (ca5b1b7) to head (65cdfdd).

Additional details and impacted files

Impacted file tree graph

@@           Coverage Diff           @@
##           master     #504   +/-   ##
=======================================
  Coverage   57.14%   57.14%           
=======================================
  Files          29       29           
  Lines        2170     2170           
=======================================
  Hits         1240     1240           
  Misses        812      812           
  Partials      118      118           
🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

Boilerplate validation expects brew.registry.redhat.io/rh-osbs/openshift-golang-builder:rhel_9_1.26
@openshift-ci

openshift-ci Bot commented Aug 11, 2026

Copy link
Copy Markdown
Contributor

@TheUndeadKing: The following test failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test name Commit Details Required Rerun command
ci/prow/lint 65cdfdd link true /test lint

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant