Skip to content
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,10 @@ base_images:
name: cli-operator-sdk
namespace: ocp
tag: v1.31.0
tls-scanner-tool:
name: tls-scanner
namespace: tls-scanner
tag: tls-scanner-tool
ubi-min9:
name: ubi-minimal
namespace: ocp
Expand Down Expand Up @@ -106,6 +110,223 @@ tests:
cpu: 100m
memory: 200Mi
workflow: optional-operators-ci-operator-sdk-aws
- always_run: false
as: install-bundle-tls-scan
optional: true
steps:
cluster_profile: openshift-org-aws
dependencies:
OO_BUNDLE: operator-bundle
env:
COMPUTE_NODE_TYPE: m5.2xlarge
OO_INSTALL_NAMESPACE: oran-o2ims
PQC_CHECK: "true"
SCAN_NAMESPACE: oran-o2ims
SCANNER_NAMESPACE: oran-o2ims
TLS_13_ENABLE_TLS_ADHERENCE: "true"
TLS_13_TLS_ADHERENCE_POLICY: StrictAllComponents
test:
- ref: optional-operators-operator-sdk
- as: wait-for-server-pods

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Medium: ~65-line inline script duplicated 4 times

This wait-for-server-pods commands block is copy-pasted identically across:

  1. This on-demand job
  2. The periodic job below (line ~220)
  3. release-4.22.yaml on-demand job
  4. release-4.22.yaml periodic job

Any bug fix (like adding the missing exit 1 from the other comments) would need to be applied in 4 places. Consider extracting this into a step-registry ref (e.g., oran-o2ims-wait-for-tls-pods-ref.yaml) that all 4 jobs reference.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[Comment authored by Claude]

Agreed. Tracked as CNF-26477 and addressed in a follow-up PR: #83194, which extracts the script into a step-registry ref at oran-o2ims/wait-for-tls-pods. We'd prefer not to block this PR on the refactoring — the error handling fixes are already applied to all 4 copies here, and the dedup PR depends on this one merging first.

cli: latest
commands: |
NAMESPACE=oran-o2ims
echo "Waiting for Inventory CR to be auto-created..."
for i in $(seq 1 60); do
if oc get inventory default -n "$NAMESPACE" &>/dev/null; then
echo "Inventory CR 'default' found."
break
fi
echo " attempt $i/60..."
sleep 5
done
Comment thread
rauhersu marked this conversation as resolved.

if ! oc get inventory default -n "$NAMESPACE" &>/dev/null; then
echo "ERROR: Inventory CR 'default' was not created after 5 minutes"
exit 1
fi

echo ""
echo "Discovering services with TLS serving certs..."
TLS_SERVICES=$(oc get services -n "$NAMESPACE" \
-o jsonpath='{range .items[?(@.metadata.annotations.service\.beta\.openshift\.io/serving-cert-secret-name)]}{.metadata.name}{"\n"}{end}')

echo "TLS services found:"
while read -r svc; do
[ -z "$svc" ] && continue
SECRET=$(oc get service "$svc" -n "$NAMESPACE" \
-o jsonpath='{.metadata.annotations.service\.beta\.openshift\.io/serving-cert-secret-name}')
echo " $svc -> secret: $SECRET"
done <<< "$TLS_SERVICES"

echo ""
echo "Waiting for TLS service pods to be ready..."
FAILED=false
while read -r svc; do
[ -z "$svc" ] && continue
SELECTOR=$(oc get service "$svc" -n "$NAMESPACE" \
-o go-template='{{range $k,$v := .spec.selector}}{{$k}}={{$v}},{{end}}' | sed 's/,$//')
if [ -z "$SELECTOR" ]; then
echo " SKIP: $svc has no selector"
continue
fi
echo " $svc (selector: $SELECTOR)..."
if ! oc wait pods -l "$SELECTOR" -n "$NAMESPACE" \
--for=condition=Ready --timeout=5m; then
echo " ERROR: pods for $svc did not become ready within 5m"
echo " Pod status:"
oc get pods -l "$SELECTOR" -n "$NAMESPACE" --no-headers | sed 's/^/ /'
echo " Recent events:"
oc get events -n "$NAMESPACE" --field-selector reason!=Pulling,reason!=Pulled \
--sort-by='.lastTimestamp' 2>/dev/null | grep "$svc" | tail -5 | sed 's/^/ /' \
|| echo " (no events found)"
FAILED=true
fi
done <<< "$TLS_SERVICES"

if [ "$FAILED" = true ]; then
echo "ERROR: one or more TLS service pods failed readiness checks"
exit 1
fi

echo ""
echo "Verifying TLS secrets from service-ca..."
while read -r svc; do
[ -z "$svc" ] && continue
SECRET=$(oc get service "$svc" -n "$NAMESPACE" \
-o jsonpath='{.metadata.annotations.service\.beta\.openshift\.io/serving-cert-secret-name}')
if oc get secret "$SECRET" -n "$NAMESPACE" &>/dev/null; then
echo " $SECRET exists"
else
echo " ERROR: $SECRET not found"
FAILED=true
fi
done <<< "$TLS_SERVICES"

if [ "$FAILED" = true ]; then
echo "ERROR: one or more TLS secrets are missing"
exit 1
fi

echo ""
echo "Final pod status in $NAMESPACE:"
oc get pods -n "$NAMESPACE"
from: cli
resources:
requests:
cpu: 100m
memory: 200Mi
- ref: tls-13
- ref: tls-scanner-run
workflow: ipi-aws
- as: install-bundle-tls-scan-periodic
cron: 0 3 * * 5
steps:
cluster_profile: openshift-org-aws
dependencies:
OO_BUNDLE: operator-bundle
env:
COMPUTE_NODE_TYPE: m5.2xlarge
OO_INSTALL_NAMESPACE: oran-o2ims
PQC_CHECK: "true"
SCAN_NAMESPACE: oran-o2ims
SCANNER_NAMESPACE: oran-o2ims
TLS_13_ENABLE_TLS_ADHERENCE: "true"
TLS_13_TLS_ADHERENCE_POLICY: StrictAllComponents
test:
- ref: optional-operators-operator-sdk
- as: wait-for-server-pods
cli: latest
commands: |
NAMESPACE=oran-o2ims
echo "Waiting for Inventory CR to be auto-created..."
for i in $(seq 1 60); do
if oc get inventory default -n "$NAMESPACE" &>/dev/null; then
echo "Inventory CR 'default' found."
break
fi
echo " attempt $i/60..."
sleep 5
done

if ! oc get inventory default -n "$NAMESPACE" &>/dev/null; then
echo "ERROR: Inventory CR 'default' was not created after 5 minutes"
exit 1
fi

echo ""
echo "Discovering services with TLS serving certs..."
TLS_SERVICES=$(oc get services -n "$NAMESPACE" \
-o jsonpath='{range .items[?(@.metadata.annotations.service\.beta\.openshift\.io/serving-cert-secret-name)]}{.metadata.name}{"\n"}{end}')

echo "TLS services found:"
while read -r svc; do
[ -z "$svc" ] && continue
SECRET=$(oc get service "$svc" -n "$NAMESPACE" \
-o jsonpath='{.metadata.annotations.service\.beta\.openshift\.io/serving-cert-secret-name}')
echo " $svc -> secret: $SECRET"
done <<< "$TLS_SERVICES"

echo ""
echo "Waiting for TLS service pods to be ready..."
FAILED=false
while read -r svc; do
[ -z "$svc" ] && continue
SELECTOR=$(oc get service "$svc" -n "$NAMESPACE" \
-o go-template='{{range $k,$v := .spec.selector}}{{$k}}={{$v}},{{end}}' | sed 's/,$//')
if [ -z "$SELECTOR" ]; then
echo " SKIP: $svc has no selector"
continue
fi
echo " $svc (selector: $SELECTOR)..."
if ! oc wait pods -l "$SELECTOR" -n "$NAMESPACE" \
--for=condition=Ready --timeout=5m; then
echo " ERROR: pods for $svc did not become ready within 5m"
echo " Pod status:"
oc get pods -l "$SELECTOR" -n "$NAMESPACE" --no-headers | sed 's/^/ /'
echo " Recent events:"
oc get events -n "$NAMESPACE" --field-selector reason!=Pulling,reason!=Pulled \
--sort-by='.lastTimestamp' 2>/dev/null | grep "$svc" | tail -5 | sed 's/^/ /' \
|| echo " (no events found)"
FAILED=true
fi
done <<< "$TLS_SERVICES"

if [ "$FAILED" = true ]; then
echo "ERROR: one or more TLS service pods failed readiness checks"
exit 1
fi

echo ""
echo "Verifying TLS secrets from service-ca..."
while read -r svc; do
[ -z "$svc" ] && continue
SECRET=$(oc get service "$svc" -n "$NAMESPACE" \
-o jsonpath='{.metadata.annotations.service\.beta\.openshift\.io/serving-cert-secret-name}')
if oc get secret "$SECRET" -n "$NAMESPACE" &>/dev/null; then
echo " $SECRET exists"
else
echo " ERROR: $SECRET not found"
FAILED=true
fi
done <<< "$TLS_SERVICES"

if [ "$FAILED" = true ]; then
echo "ERROR: one or more TLS secrets are missing"
exit 1
fi

echo ""
echo "Final pod status in $NAMESPACE:"
oc get pods -n "$NAMESPACE"
from: cli
resources:
requests:
cpu: 100m
memory: 200Mi
- ref: tls-13
- ref: tls-scanner-run
workflow: ipi-aws
- always_run: false
as: markdownlint
commands: |
Expand Down
Loading