Move e2e-aws-ovn-tls-13 periodic jobs to nightly configs for releases 4.18-4.22#74257
Conversation
|
/pj-rehearse pull-ci-openshift-origin-main-e2e-aws-ovn-tls-13 |
|
@wangke19: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
|
e2e-aws-ovn-tls-13 is failed because openshift/origin#30746 has been merged. |
7f05982 to
b5d10d4
Compare
This moves TLS 1.3 (Modern profile) periodic test jobs from CI stream
configs to nightly stream configs for OpenShift releases 4.18-4.22.
Rationale: The TLS 1.3 test modifies the API server's TLS security
profile, which propagates to 8+ critical control plane components:
- kube-apiserver, kube-controller-manager, kube-scheduler
- openshift-apiserver, openshift-oauth-apiserver, openshift-oauth-server
- etcd, Machine Config Operator
This is a high-risk, security-critical configuration change that:
1. Affects all API communications and authentication flows
2. Represents a deployment-time configuration (not code feature)
3. Should be tested against stable nightly builds, not pre-merge CI builds
4. Benefits from nightly's comprehensive test coverage (~189 vs ~33 tests)
Nightly stream testing is more appropriate for such cluster-wide security
configuration changes that impact production deployments.
Changes:
- Removed from: ci-operator/config/openshift/release/openshift-release-master__ci-4.{18,19}.yaml
- Added to: ci-operator/config/openshift/release/openshift-release-master__nightly-4.{18,19,20,21,22}.yaml
- Generated: ci-operator/jobs/openshift/release/openshift-release-master-periodics.yaml
b5d10d4 to
b43769c
Compare
|
[REHEARSALNOTIFIER]
Interacting with pj-rehearseComment: Once you are satisfied with the results of the rehearsals, comment: |
|
/pj-rehearse periodic-ci-openshift-release-master-nightly-4.21-e2e-aws-ovn-tls-13 |
|
@wangke19: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
|
From failed CI job periodic-ci-openshift-release-master-nightly-4.21-e2e-aws-ovn-tls-13, we saw, That's expected, we need to openshift/origin#30746 merge. |
|
/lgtm |
|
/approve |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: gangwgr, neisw, wangke19 The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
|
/pj-rehearse ack |
|
@wangke19: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
|
@wangke19: The following tests failed, say
Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
69315f0
into
openshift:master
Summary
This PR moves TLS 1.3 (Modern profile) periodic test jobs from CI stream configs to nightly stream configs for OpenShift release versions 4.18, 4.19, 4.20, 4.21, and 4.22.
Changes
Removed from CI configs:
ci-operator/config/openshift/release/openshift-release-master__ci-4.18.yamlci-operator/config/openshift/release/openshift-release-master__ci-4.19.yamlAdded to nightly configs:
ci-operator/config/openshift/release/openshift-release-master__nightly-4.18.yamlci-operator/config/openshift/release/openshift-release-master__nightly-4.19.yamlci-operator/config/openshift/release/openshift-release-master__nightly-4.20.yamlci-operator/config/openshift/release/openshift-release-master__nightly-4.21.yamlci-operator/config/openshift/release/openshift-release-master__nightly-4.22.yamlGenerated:
ci-operator/jobs/openshift/release/openshift-release-master-periodics.yamlJob Configuration
Each nightly periodic job:
openshift-e2e-aws-ovn-tls-13openshift/conformance/parallel168h(weekly)observers-resource-watchenabledRationale: Why Nightly Instead of CI?
Components Impacted by TLS Security Profile Changes
The TLS 1.3 test modifies the API server's TLS security profile, which propagates to 8+ critical control plane components:
Core Control Plane:
Impact Analysis
wait-for-stable-clusterto verify rolloutWhy Nightly Stream is More Appropriate
✅ Security-Critical Testing
✅ Production-Oriented Testing
✅ Comprehensive Coverage
✅ Appropriate Test Scope
References
Testing
openshift-e2e-aws-ovn-tls-13exists in step-registrymake updateto generate Prow job definitionsci-operator/jobs/openshift/release/openshift-release-master-periodics.yaml/assign @wangke19