Skip to content

OCPBUGS-129376: Azure dual-stack load balancers should expose public and internal services over IPv4 and IPv6 - #31716

Open
sadasu wants to merge 1 commit into
openshift:mainfrom
sadasu:azure-dualstack
Open

sadasu wants to merge 1 commit into
openshift:mainfrom
sadasu:azure-dualstack

Conversation

@sadasu

@sadasu sadasu commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

The backend Deployment's pod template pinned runAsUser: 1000, which no SCC available to the namespace's default ServiceAccount will admit.

The fix keeps the pod restricted-compliant (runAsNonRoot, RuntimeDefault seccomp) but omits runAsUser so restricted-v2 allocates it from the namespace range. The container-level context (allowPrivilegeEscalation: false, drop ALL) is already compatible, and agnhost netexec on port 8080 don't need a fixed UID or a privileged port.

Summary by CodeRabbit

  • Tests
    • Updated Azure dual-stack test coverage to use a non-root backend pod with runtime-default security settings. The test no longer relies on a fixed user ID, allowing it to run with dynamically assigned IDs while checking the same dual-stack behavior.

The backend Deployment's pod template pinned runAsUser: 1000,
which no SCC available to the namespace's default ServiceAccount will admit.

The fix keeps the pod restricted-compliant (runAsNonRoot, RuntimeDefault seccomp)
but omits runAsUser so restricted-v2 allocates it from the namespace range.
The container-level context (allowPrivilegeEscalation: false, drop ALL) is already
compatible, and agnhost netexec on port 8080 don't need a fixed UID or a privileged port.
@sadasu sadasu changed the title OCPBUGS-129376: Fix : Azure dual-stack load balancers should expose public and internal services over IPv4 and IPv6 OCPBUGS-129376: Azure dual-stack load balancers should expose public and internal services over IPv4 and IPv6 Oct 6, 2026
@sadasu

sadasu commented Oct 6, 2026

Copy link
Copy Markdown
Contributor Author

/jira refresh

@openshift-ci-robot openshift-ci-robot added jira/severity-important Referenced Jira bug's severity is important for the branch this PR is targeting. jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. jira/valid-bug Indicates that a referenced Jira bug is valid for the branch this PR is targeting. labels Oct 6, 2026
@openshift-ci-robot

Copy link
Copy Markdown

@sadasu: This pull request references Jira Issue OCPBUGS-129376, which is valid. The bug has been moved to the POST state.

3 validation(s) were run on this bug
  • bug is open, matching expected state (open)
  • bug target version (5.1.0) matches configured target version for branch (5.1.0)
  • bug is in the state ASSIGNED, which is one of the valid states (NEW, ASSIGNED, POST)

The bug has been updated to refer to the pull request using the external bug tracker.

Details

In response to this:

/jira refresh

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@sadasu sadasu added jira/valid-bug Indicates that a referenced Jira bug is valid for the branch this PR is targeting. jira/severity-important Referenced Jira bug's severity is important for the branch this PR is targeting. jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. labels Oct 6, 2026
@openshift-merge-bot

Copy link
Copy Markdown
Contributor

Pipeline controller notification

This PR uses the pipeline controller for second-stage tests. Selection and triggering follow the repository configuration.

Use /test ? to list jobs, /pipeline remaining to request missing second-stage tests, or /pipeline required to rerun the selected second-stage set.

@openshift-ci-robot

Copy link
Copy Markdown

@sadasu: This pull request references Jira Issue OCPBUGS-129376, which is valid.

3 validation(s) were run on this bug
  • bug is open, matching expected state (open)
  • bug target version (5.1.0) matches configured target version for branch (5.1.0)
  • bug is in the state POST, which is one of the valid states (NEW, ASSIGNED, POST)
Details

In response to this:

The backend Deployment's pod template pinned runAsUser: 1000, which no SCC available to the namespace's default ServiceAccount will admit.

The fix keeps the pod restricted-compliant (runAsNonRoot, RuntimeDefault seccomp) but omits runAsUser so restricted-v2 allocates it from the namespace range. The container-level context (allowPrivilegeEscalation: false, drop ALL) is already compatible, and agnhost netexec on port 8080 don't need a fixed UID or a privileged port.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@coderabbitai

coderabbitai Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository YAML (base), Central YAML (inherited)
  • Review profile: CHILL
  • Plan: Enterprise
  • Run ID: 46fef5b4-4740-4449-a86f-c9033d4b9908
📥 Commits

Reviewing files that changed from the base of the PR and between 5da4f1c and b98ddd3.

📒 Files selected for processing (1)
  • test/extended/cloud_controller_manager/azure_dualstack.go

Included review availability: This review used your included allowance. Your plan provides up to 12 included reviews per hour; 11 remain after this review.


Walkthrough

The Azure dual-stack test now configures the backend pod with RunAsNonRoot: true and the RuntimeDefault seccomp profile instead of using GetRestrictedPodSecurityContext().

Changes

Azure dual-stack test

Layer / File(s) Summary
Backend pod security context
test/extended/cloud_controller_manager/azure_dualstack.go
The backend pod uses RunAsNonRoot: true and the RuntimeDefault seccomp profile. The test no longer uses a security context that pins runAsUser to 1000.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix

Suggested reviewers: bandrade

Merge Risk: ⚪ Minimal · up to b98dd

The backend no longer pins its UID and retains the inspected security restrictions. No concrete failure in the supported test paths is established, so merge risk is minimal.

🚥 Pre-merge checks | ✅ 15
✅ Passed checks (15 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly describes the Azure dual-stack load-balancer objective addressed by the change.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 1…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Stable And Deterministic Test Names ✅ Passed The pull request changes only the backend pod security context and imports ptr. It does not change any Ginkgo test title. The titles in the changed file use static text and contain no generated name…
Test Structure And Quality ✅ Passed The PR changes only the backend pod security-context setup in the existing Azure dual-stack It block. The test’s scope, cleanup, waits, and assertions are unchanged. The test registers `DeferCleanup…
Microshift Test Compatibility ✅ Passed The pull request changes only the backend pod security context; it does not add a Ginkgo test. The existing test is named with [apigroup:config.openshift.io], which protects it from running on Micro…
Single Node Openshift (Sno) Test Compatibility ✅ Passed The PR adds no Ginkgo test. The Azure dual-stack g.It already exists in the base revision. The only behavioral change updates the backend pod security context; it does not add a multi-node or HA ass…
Topology-Aware Scheduling Compatibility ✅ Passed The pull request changes only test/extended/cloud_controller_manager/azure_dualstack.go. Its diff replaces the pod security context and adds the ptr import. It does not add or modify replicas, aff…
Ote Binary Stdout Contract ✅ Passed The PR changes only test/extended/cloud_controller_manager/azure_dualstack.go. Its added code sets pod security context inside the g.It test body. The diff adds no process-level stdout writes or s…
Ipv6 And Disconnected Network Test Compatibility ✅ Passed The pull request changes only the backend pod security context in the existing Ginkgo test. It adds no test and introduces no IP-address handling, network requests, or external connectivity requiremen…
No-Weak-Crypto ✅ Passed The PR changes only the Azure dual-stack test’s pod security context and adds a ptr import. The changed code sets RunAsNonRoot and RuntimeDefault seccomp; it introduces no weak cryptography, cus…
Container-Privileges ✅ Passed The PR changes only the backend pod security context. It sets RunAsNonRoot: true and RuntimeDefault seccomp, and the container retains the restricted helper context, which sets `AllowPrivilegeEsca…
No-Sensitive-Data-In-Logs ✅ Passed The pull request changes only the backend pod security context. The diff adds no logging statements or logged sensitive data. Existing log calls in the file are unchanged and report the IP family, ser…
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR

Comment @coderabbitai help to get the list of available commands.

@openshift-ci openshift-ci Bot added the ready-for-human-review Indicates a PR has been reviewed by automated tools and is ready for human review label Oct 6, 2026
@openshift-merge-bot

Copy link
Copy Markdown
Contributor

Scheduling tests matching the pipeline_run_if_changed or not excluded by pipeline_skip_if_only_changed parameters:
/test e2e-aws-ovn-fips
/test e2e-aws-ovn-microshift
/test e2e-aws-ovn-microshift-serial
/test e2e-aws-ovn-serial-1of2
/test e2e-aws-ovn-serial-2of2
/test e2e-gcp-ovn
/test e2e-metal-ipi-ovn-ipv6

@redhat-chai-bot

Copy link
Copy Markdown
Contributor

/override-sticky ci/prow/e2e-aws-ovn-microshift

Automated risk analysis: This failure is unrelated to the PR's Azure-only test change.

Job classification: Eligible long-running e2e job. The Prow definition provisions AWS EC2 MicroShift and runs the MicroShift origin conformance workflow; this run took 2h 11m.
Revision check: Run b98ddd31b58d7517f3eb024a93942285c58f7824; live PR HEAD b98ddd31b58d7517f3eb024a93942285c58f7824; match.
Execution status: Tests executed. JUnit records these blocking failures:

  • [sig-api-machinery] StorageVersionMigration CRUD Tests storagemigration.k8s.io/v1 StorageVersionMigration [Conformance] — API discovery returned the server could not find the requested resource.
  • [sig-auth] PodCertificateRequest API [Privileged:ClusterAdmin] should support PodCertificateRequest API operations [Conformance] — API discovery did not include podcertificaterequests.
    Completed supporting jobs: e2e-aws-ovn-fips, e2e-aws-ovn-serial-1of2, and e2e-aws-ovn-serial-2of2 passed. These are adjacent AWS OVN coverage, not MicroShift coverage. Pending: tide only; no pending e2e job.
    Fleet-wide failure rate: Job pass rate 15.9% (7 successes / 37 failures over 7 days). Each failed test has a 98.7% global pass rate in the 5.1 Sippy view; no MicroShift-topology rate is available because those tests are not represented in that slice.
    Open regressions: None found for either exact failed test in the 5.1 Component Readiness view.
    Linked bugs: None linked to either exact failed test through bug_tests.
    Overlap assessment: None. The PR changes only test/extended/cloud_controller_manager/azure_dualstack.go, an Azure dual-stack test's backend pod security context; it changes no MicroShift API, conformance selection, or shared infrastructure.
    Missing-coverage risk: Low for this PR's changed surface because this MicroShift-only run does not exercise the Azure-specific test. This override does not establish that the changed Azure test passed; no Azure-specific passing job is present in the check set.
    Prior bot activity on this SHA: One /test e2e-aws-ovn-microshift was already issued at 15:57 UTC and produced this failed current-HEAD run; no prior override. Do not spend another retest on this SHA.
    Rationale: Both observed failures are unsupported API discovery in the MicroShift environment. The current run and Prow JUnit establish the incompatibility; the PR changes only an Azure test. This job fails broadly across PRs, at a 15.9% pass rate.

If you disagree with this assessment, rerun the current job with /test e2e-aws-ovn-microshift.


AI-generated. Review for accuracy.

@redhat-chai-bot

Copy link
Copy Markdown
Contributor

/override-sticky ci/prow/e2e-gcp-ovn

Automated risk analysis: The blocking failures are unrelated to the PR; the run recorded DNS lookup failures during the test window.

Job classification: Eligible long-running e2e job. The Prow definition uses the GCP cluster profile, runs IPI installation, then openshift-e2e-test; this run took 3h 54m.
Revision check: Run b98ddd31b58d7517f3eb024a93942285c58f7824; live PR HEAD b98ddd31b58d7517f3eb024a93942285c58f7824; match.
Execution status: Tests executed. The five blocking failures were:

  • [sig-arch] [Conformance] sysctl whitelists net.ipv4.ping_group_range [Suite:openshift/conformance/parallel/minimal]
  • [Conformance][sig-api-machinery][Feature:APIServer] local kubeconfig "lb-int.kubeconfig" should be present on all masters and work [Suite:openshift/conformance/parallel/minimal]
  • [sig-api-machinery][Feature:ServerSideApply] Server-Side Apply should work for oauth.openshift.io/v1, Resource=oauthclientauthorizations [apigroup:oauth.openshift.io] [Suite:openshift/conformance/parallel]
  • [sig-cli] oc set image can set images for pods and deployments [apigroup:image.openshift.io][apigroup:apps.openshift.io] [Suite:openshift/conformance/parallel]
  • [sig-node] [Jira:Node/Kubelet] Kubelet, CRI-O, CPU manager [OTP] validate KUBELET_LOG_LEVEL [Suite:openshift/conformance/parallel]

Each blocking failure coincided with DNS timeout or connection-refused errors to the API endpoint. The run's disruption sampler logged DNS timeouts and identified the likely problem as the cluster running tests, not the cluster under test. One additional non-blocking informing failure was [sig-cli] Workloads client test ROSA-OSD_CCS-ARO-ConnectedOnly-Author:yinzhou-Medium-71273-Medium-71275-Validate user is able to extract rhel8 and rhel9 oc from the ocp payload; Sippy reports 0/1773 passes globally for that informing test, and its GCP-filtered rate was not established. It did not cause the blocking result.
Completed supporting jobs: None on GCP; the other completed e2e checks were on AWS or metal. Pending: tide only; no pending e2e job.
Fleet-wide failure rate: Job pass rate 25.5% (12 successes / 35 failures over 7 days). In the 5.1 Sippy view, the five blocking tests have 100% pass rate on GCP; global rates range from 99.9% to 100%.
Open regressions: None found for the five blocking tests in the 5.1 Component Readiness view.
Linked bugs: OCPBUGS-8874 (Closed) is associated with the lb-int.kubeconfig test but tracks an IBM Cloud issue, not this DNS failure. OCPBUGS-44067 (New) concerns the disconnected oc set image variant and a registry-pull failure, not this run's exact variant or DNS signature. Neither explains the observed failures.
Overlap assessment: None. The PR changes only test/extended/cloud_controller_manager/azure_dualstack.go, an Azure dual-stack test's backend pod security context; the GCP failures are unrelated platform conformance tests.
Missing-coverage risk: Low for this PR's changed surface because this GCP job does not exercise the Azure-specific test. This override does not establish that the changed Azure test passed; no Azure-specific passing job is present in the check set.
Prior bot activity on this SHA: One /test e2e-gcp-ovn was already issued at 15:57 UTC and produced this failed current-HEAD run; no prior override. Do not spend another retest on this SHA.
Rationale: The direct Prow log documents DNS lookup failures across all five blocking tests and the disruption sampler identifies the likely failure domain as the test-running cluster. All five have clean GCP Sippy results and no open regressions; the job itself has a 25.5% 7-day pass rate. The PR only changes Azure test code.

If you disagree with this assessment, rerun the current job with /test e2e-gcp-ovn.


AI-generated. Review for accuracy.

@redhat-chai-bot

Copy link
Copy Markdown
Contributor

/override-sticky ci/prow/e2e-aws-ovn-microshift-serial

Automated risk analysis: This failure is unrelated to the PR's Azure-only test change.

Job classification: Eligible long-running e2e job. The Prow definition provisions AWS EC2 MicroShift and runs the serial MicroShift origin conformance workflow; this run took 1h 44m.
Revision check: Run b98ddd31b58d7517f3eb024a93942285c58f7824; live PR HEAD b98ddd31b58d7517f3eb024a93942285c58f7824; match.
Execution status: Tests executed. The exact blocking failure is [sig-apps] Daemon set should rollback without unnecessary restarts [Conformance] [Serial]; its assertion says the suite requires at least 2 nodes, but the observed cluster had 1.
Completed supporting jobs: e2e-aws-ovn-fips, e2e-aws-ovn-serial-1of2, and e2e-aws-ovn-serial-2of2 passed. These are adjacent AWS OVN coverage, not MicroShift coverage. Pending: tide only; no pending e2e job.
Fleet-wide failure rate: Job pass rate 14.0% (7 successes / 43 failures over 7 days). The exact test's 5.1 Sippy rate is 87.2% global, 58.3% on AWS, and 0/5 on single-node topology; no MicroShift-topology rate is available.
Open regressions: None found for the exact failed test in the 5.1 Component Readiness view.
Linked bugs: None linked to the exact failed test through bug_tests.
Overlap assessment: None. The PR changes only test/extended/cloud_controller_manager/azure_dualstack.go, an Azure dual-stack test's backend pod security context; it changes no MicroShift test or single-node behavior.
Missing-coverage risk: Low for this PR's changed surface because this MicroShift-only run does not exercise the Azure-specific test. This override does not establish that the changed Azure test passed; no Azure-specific passing job is present in the check set.
Prior bot activity on this SHA: One /test e2e-aws-ovn-microshift-serial was already issued at 15:57 UTC and produced this failed current-HEAD run; no prior override. Do not spend another retest on this SHA.
Rationale: The failure is an explicit single-node incompatibility: the test requires at least two nodes and MicroShift is single-node. Its failures concentrate in AWS/single-node history, and the PR changes only an Azure test.

If you disagree with this assessment, rerun the current job with /test e2e-aws-ovn-microshift-serial.


AI-generated. Review for accuracy.

@openshift-ci

openshift-ci Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

@redhat-chai-bot: Overrode contexts on behalf of redhat-chai-bot: ci/prow/e2e-aws-ovn-microshift

These overrides will persist across retests on the current HEAD SHA. Pushing a new commit will clear them. Use /override-cancel to remove them.

Details

In response to this:

/override-sticky ci/prow/e2e-aws-ovn-microshift

Automated risk analysis: This failure is unrelated to the PR's Azure-only test change.

Job classification: Eligible long-running e2e job. The Prow definition provisions AWS EC2 MicroShift and runs the MicroShift origin conformance workflow; this run took 2h 11m.
Revision check: Run b98ddd31b58d7517f3eb024a93942285c58f7824; live PR HEAD b98ddd31b58d7517f3eb024a93942285c58f7824; match.
Execution status: Tests executed. JUnit records these blocking failures:

  • [sig-api-machinery] StorageVersionMigration CRUD Tests storagemigration.k8s.io/v1 StorageVersionMigration [Conformance] — API discovery returned the server could not find the requested resource.
  • [sig-auth] PodCertificateRequest API [Privileged:ClusterAdmin] should support PodCertificateRequest API operations [Conformance] — API discovery did not include podcertificaterequests.
    Completed supporting jobs: e2e-aws-ovn-fips, e2e-aws-ovn-serial-1of2, and e2e-aws-ovn-serial-2of2 passed. These are adjacent AWS OVN coverage, not MicroShift coverage. Pending: tide only; no pending e2e job.
    Fleet-wide failure rate: Job pass rate 15.9% (7 successes / 37 failures over 7 days). Each failed test has a 98.7% global pass rate in the 5.1 Sippy view; no MicroShift-topology rate is available because those tests are not represented in that slice.
    Open regressions: None found for either exact failed test in the 5.1 Component Readiness view.
    Linked bugs: None linked to either exact failed test through bug_tests.
    Overlap assessment: None. The PR changes only test/extended/cloud_controller_manager/azure_dualstack.go, an Azure dual-stack test's backend pod security context; it changes no MicroShift API, conformance selection, or shared infrastructure.
    Missing-coverage risk: Low for this PR's changed surface because this MicroShift-only run does not exercise the Azure-specific test. This override does not establish that the changed Azure test passed; no Azure-specific passing job is present in the check set.
    Prior bot activity on this SHA: One /test e2e-aws-ovn-microshift was already issued at 15:57 UTC and produced this failed current-HEAD run; no prior override. Do not spend another retest on this SHA.
    Rationale: Both observed failures are unsupported API discovery in the MicroShift environment. The current run and Prow JUnit establish the incompatibility; the PR changes only an Azure test. This job fails broadly across PRs, at a 15.9% pass rate.

If you disagree with this assessment, rerun the current job with /test e2e-aws-ovn-microshift.


AI-generated. Review for accuracy.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@openshift-ci

openshift-ci Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

@redhat-chai-bot: Overrode contexts on behalf of redhat-chai-bot: ci/prow/e2e-aws-ovn-microshift-serial

These overrides will persist across retests on the current HEAD SHA. Pushing a new commit will clear them. Use /override-cancel to remove them.

Details

In response to this:

/override-sticky ci/prow/e2e-aws-ovn-microshift-serial

Automated risk analysis: This failure is unrelated to the PR's Azure-only test change.

Job classification: Eligible long-running e2e job. The Prow definition provisions AWS EC2 MicroShift and runs the serial MicroShift origin conformance workflow; this run took 1h 44m.
Revision check: Run b98ddd31b58d7517f3eb024a93942285c58f7824; live PR HEAD b98ddd31b58d7517f3eb024a93942285c58f7824; match.
Execution status: Tests executed. The exact blocking failure is [sig-apps] Daemon set should rollback without unnecessary restarts [Conformance] [Serial]; its assertion says the suite requires at least 2 nodes, but the observed cluster had 1.
Completed supporting jobs: e2e-aws-ovn-fips, e2e-aws-ovn-serial-1of2, and e2e-aws-ovn-serial-2of2 passed. These are adjacent AWS OVN coverage, not MicroShift coverage. Pending: tide only; no pending e2e job.
Fleet-wide failure rate: Job pass rate 14.0% (7 successes / 43 failures over 7 days). The exact test's 5.1 Sippy rate is 87.2% global, 58.3% on AWS, and 0/5 on single-node topology; no MicroShift-topology rate is available.
Open regressions: None found for the exact failed test in the 5.1 Component Readiness view.
Linked bugs: None linked to the exact failed test through bug_tests.
Overlap assessment: None. The PR changes only test/extended/cloud_controller_manager/azure_dualstack.go, an Azure dual-stack test's backend pod security context; it changes no MicroShift test or single-node behavior.
Missing-coverage risk: Low for this PR's changed surface because this MicroShift-only run does not exercise the Azure-specific test. This override does not establish that the changed Azure test passed; no Azure-specific passing job is present in the check set.
Prior bot activity on this SHA: One /test e2e-aws-ovn-microshift-serial was already issued at 15:57 UTC and produced this failed current-HEAD run; no prior override. Do not spend another retest on this SHA.
Rationale: The failure is an explicit single-node incompatibility: the test requires at least two nodes and MicroShift is single-node. Its failures concentrate in AWS/single-node history, and the PR changes only an Azure test.

If you disagree with this assessment, rerun the current job with /test e2e-aws-ovn-microshift-serial.


AI-generated. Review for accuracy.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@openshift-ci

openshift-ci Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

@redhat-chai-bot: Overrode contexts on behalf of redhat-chai-bot: ci/prow/e2e-gcp-ovn

These overrides will persist across retests on the current HEAD SHA. Pushing a new commit will clear them. Use /override-cancel to remove them.

Details

In response to this:

/override-sticky ci/prow/e2e-gcp-ovn

Automated risk analysis: The blocking failures are unrelated to the PR; the run recorded DNS lookup failures during the test window.

Job classification: Eligible long-running e2e job. The Prow definition uses the GCP cluster profile, runs IPI installation, then openshift-e2e-test; this run took 3h 54m.
Revision check: Run b98ddd31b58d7517f3eb024a93942285c58f7824; live PR HEAD b98ddd31b58d7517f3eb024a93942285c58f7824; match.
Execution status: Tests executed. The five blocking failures were:

  • [sig-arch] [Conformance] sysctl whitelists net.ipv4.ping_group_range [Suite:openshift/conformance/parallel/minimal]
  • [Conformance][sig-api-machinery][Feature:APIServer] local kubeconfig "lb-int.kubeconfig" should be present on all masters and work [Suite:openshift/conformance/parallel/minimal]
  • [sig-api-machinery][Feature:ServerSideApply] Server-Side Apply should work for oauth.openshift.io/v1, Resource=oauthclientauthorizations [apigroup:oauth.openshift.io] [Suite:openshift/conformance/parallel]
  • [sig-cli] oc set image can set images for pods and deployments [apigroup:image.openshift.io][apigroup:apps.openshift.io] [Suite:openshift/conformance/parallel]
  • [sig-node] [Jira:Node/Kubelet] Kubelet, CRI-O, CPU manager [OTP] validate KUBELET_LOG_LEVEL [Suite:openshift/conformance/parallel]

Each blocking failure coincided with DNS timeout or connection-refused errors to the API endpoint. The run's disruption sampler logged DNS timeouts and identified the likely problem as the cluster running tests, not the cluster under test. One additional non-blocking informing failure was [sig-cli] Workloads client test ROSA-OSD_CCS-ARO-ConnectedOnly-Author:yinzhou-Medium-71273-Medium-71275-Validate user is able to extract rhel8 and rhel9 oc from the ocp payload; Sippy reports 0/1773 passes globally for that informing test, and its GCP-filtered rate was not established. It did not cause the blocking result.
Completed supporting jobs: None on GCP; the other completed e2e checks were on AWS or metal. Pending: tide only; no pending e2e job.
Fleet-wide failure rate: Job pass rate 25.5% (12 successes / 35 failures over 7 days). In the 5.1 Sippy view, the five blocking tests have 100% pass rate on GCP; global rates range from 99.9% to 100%.
Open regressions: None found for the five blocking tests in the 5.1 Component Readiness view.
Linked bugs: OCPBUGS-8874 (Closed) is associated with the lb-int.kubeconfig test but tracks an IBM Cloud issue, not this DNS failure. OCPBUGS-44067 (New) concerns the disconnected oc set image variant and a registry-pull failure, not this run's exact variant or DNS signature. Neither explains the observed failures.
Overlap assessment: None. The PR changes only test/extended/cloud_controller_manager/azure_dualstack.go, an Azure dual-stack test's backend pod security context; the GCP failures are unrelated platform conformance tests.
Missing-coverage risk: Low for this PR's changed surface because this GCP job does not exercise the Azure-specific test. This override does not establish that the changed Azure test passed; no Azure-specific passing job is present in the check set.
Prior bot activity on this SHA: One /test e2e-gcp-ovn was already issued at 15:57 UTC and produced this failed current-HEAD run; no prior override. Do not spend another retest on this SHA.
Rationale: The direct Prow log documents DNS lookup failures across all five blocking tests and the disruption sampler identifies the likely failure domain as the test-running cluster. All five have clean GCP Sippy results and no open regressions; the job itself has a 25.5% 7-day pass rate. The PR only changes Azure test code.

If you disagree with this assessment, rerun the current job with /test e2e-gcp-ovn.


AI-generated. Review for accuracy.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@openshift-ci

openshift-ci Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

@sadasu: all tests passed!

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

@tthvo

tthvo commented Oct 7, 2026

Copy link
Copy Markdown
Member

/testwith openshift/installer/main/e2e-azure-ovn-dualstack-ipv4-primary-techpreview openshift/installer#10950

@tthvo tthvo left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm

@openshift-ci openshift-ci Bot added the lgtm Indicates that a PR is ready to be merged. label Oct 7, 2026
@openshift-ci

openshift-ci Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: sadasu, tthvo
Once this PR has been reviewed and has the lgtm label, please assign maysamacedo for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

jira/severity-important Referenced Jira bug's severity is important for the branch this PR is targeting. jira/valid-bug Indicates that a referenced Jira bug is valid for the branch this PR is targeting. jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. lgtm Indicates that a PR is ready to be merged. ready-for-human-review Indicates a PR has been reviewed by automated tools and is ready for human review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants