Repository navigation
Conversation
The backend Deployment's pod template pinned runAsUser: 1000, which no SCC available to the namespace's default ServiceAccount will admit. The fix keeps the pod restricted-compliant (runAsNonRoot, RuntimeDefault seccomp) but omits runAsUser so restricted-v2 allocates it from the namespace range. The container-level context (allowPrivilegeEscalation: false, drop ALL) is already compatible, and agnhost netexec on port 8080 don't need a fixed UID or a privileged port.
|
/jira refresh |
|
@sadasu: This pull request references Jira Issue OCPBUGS-129376, which is valid. The bug has been moved to the POST state. 3 validation(s) were run on this bug
The bug has been updated to refer to the pull request using the external bug tracker. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
Pipeline controller notification This PR uses the pipeline controller for second-stage tests. Selection and triggering follow the repository configuration. Use |
|
@sadasu: This pull request references Jira Issue OCPBUGS-129376, which is valid. 3 validation(s) were run on this bug
DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (1)
Included review availability: This review used your included allowance. Your plan provides up to 12 included reviews per hour; 11 remain after this review. WalkthroughThe Azure dual-stack test now configures the backend pod with ChangesAzure dual-stack test
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~10 minutes Change: Bug fix Suggested reviewers: Merge Risk: ⚪ Minimal · up to The backend no longer pins its UID and retains the inspected security restrictions. No concrete failure in the supported test paths is established, so merge risk is minimal. 🚥 Pre-merge checks | ✅ 15✅ Passed checks (15 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
|
Scheduling tests matching the |
|
/override-sticky ci/prow/e2e-aws-ovn-microshift Automated risk analysis: This failure is unrelated to the PR's Azure-only test change. Job classification: Eligible long-running e2e job. The Prow definition provisions AWS EC2 MicroShift and runs the MicroShift origin conformance workflow; this run took 2h 11m.
If you disagree with this assessment, rerun the current job with AI-generated. Review for accuracy. |
|
/override-sticky ci/prow/e2e-gcp-ovn Automated risk analysis: The blocking failures are unrelated to the PR; the run recorded DNS lookup failures during the test window. Job classification: Eligible long-running e2e job. The Prow definition uses the GCP cluster profile, runs IPI installation, then
Each blocking failure coincided with DNS timeout or connection-refused errors to the API endpoint. The run's disruption sampler logged DNS timeouts and identified the likely problem as the cluster running tests, not the cluster under test. One additional non-blocking informing failure was If you disagree with this assessment, rerun the current job with AI-generated. Review for accuracy. |
|
/override-sticky ci/prow/e2e-aws-ovn-microshift-serial Automated risk analysis: This failure is unrelated to the PR's Azure-only test change. Job classification: Eligible long-running e2e job. The Prow definition provisions AWS EC2 MicroShift and runs the serial MicroShift origin conformance workflow; this run took 1h 44m. If you disagree with this assessment, rerun the current job with AI-generated. Review for accuracy. |
|
@redhat-chai-bot: Overrode contexts on behalf of redhat-chai-bot: ci/prow/e2e-aws-ovn-microshift These overrides will persist across retests on the current HEAD SHA. Pushing a new commit will clear them. Use DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
|
@redhat-chai-bot: Overrode contexts on behalf of redhat-chai-bot: ci/prow/e2e-aws-ovn-microshift-serial These overrides will persist across retests on the current HEAD SHA. Pushing a new commit will clear them. Use DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
|
@redhat-chai-bot: Overrode contexts on behalf of redhat-chai-bot: ci/prow/e2e-gcp-ovn These overrides will persist across retests on the current HEAD SHA. Pushing a new commit will clear them. Use DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
|
@sadasu: all tests passed! Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
|
/testwith openshift/installer/main/e2e-azure-ovn-dualstack-ipv4-primary-techpreview openshift/installer#10950 |
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: sadasu, tthvo The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
The backend Deployment's pod template pinned runAsUser: 1000, which no SCC available to the namespace's default ServiceAccount will admit.
The fix keeps the pod restricted-compliant (runAsNonRoot, RuntimeDefault seccomp) but omits runAsUser so restricted-v2 allocates it from the namespace range. The container-level context (allowPrivilegeEscalation: false, drop ALL) is already compatible, and agnhost netexec on port 8080 don't need a fixed UID or a privileged port.
Summary by CodeRabbit