diff --git a/ci-operator/config/openshift-kni/oran-o2ims/openshift-kni-oran-o2ims-main.yaml b/ci-operator/config/openshift-kni/oran-o2ims/openshift-kni-oran-o2ims-main.yaml index cf6ce7938375a..7108db6230183 100644 --- a/ci-operator/config/openshift-kni/oran-o2ims/openshift-kni-oran-o2ims-main.yaml +++ b/ci-operator/config/openshift-kni/oran-o2ims/openshift-kni-oran-o2ims-main.yaml @@ -126,9 +126,12 @@ tests: TLS_13_ENABLE_TLS_ADHERENCE: "true" TLS_13_TLS_ADHERENCE_POLICY: StrictAllComponents test: + - chain: acm-install + - ref: rhobs-acm-setup-observability - ref: optional-operators-operator-sdk - ref: oran-o2ims-wait-for-tls-pods - ref: tls-13 + - ref: oran-o2ims-wait-for-tls-pods-post-rollout - ref: tls-scanner-run workflow: ipi-aws - as: install-bundle-tls-scan-periodic @@ -146,9 +149,12 @@ tests: TLS_13_ENABLE_TLS_ADHERENCE: "true" TLS_13_TLS_ADHERENCE_POLICY: StrictAllComponents test: + - chain: acm-install + - ref: rhobs-acm-setup-observability - ref: optional-operators-operator-sdk - ref: oran-o2ims-wait-for-tls-pods - ref: tls-13 + - ref: oran-o2ims-wait-for-tls-pods-post-rollout - ref: tls-scanner-run workflow: ipi-aws - always_run: false diff --git a/ci-operator/config/openshift-kni/oran-o2ims/openshift-kni-oran-o2ims-release-4.22.yaml b/ci-operator/config/openshift-kni/oran-o2ims/openshift-kni-oran-o2ims-release-4.22.yaml index 8669f3afae7e7..86ab74a92045a 100644 --- a/ci-operator/config/openshift-kni/oran-o2ims/openshift-kni-oran-o2ims-release-4.22.yaml +++ b/ci-operator/config/openshift-kni/oran-o2ims/openshift-kni-oran-o2ims-release-4.22.yaml @@ -126,9 +126,12 @@ tests: TLS_13_ENABLE_TLS_ADHERENCE: "true" TLS_13_TLS_ADHERENCE_POLICY: StrictAllComponents test: + - chain: acm-install + - ref: rhobs-acm-setup-observability - ref: optional-operators-operator-sdk - ref: oran-o2ims-wait-for-tls-pods - ref: tls-13 + - ref: oran-o2ims-wait-for-tls-pods-post-rollout - ref: tls-scanner-run workflow: ipi-aws - as: install-bundle-tls-scan-periodic @@ -146,9 +149,12 @@ tests: TLS_13_ENABLE_TLS_ADHERENCE: "true" TLS_13_TLS_ADHERENCE_POLICY: StrictAllComponents test: + - chain: acm-install + - ref: rhobs-acm-setup-observability - ref: optional-operators-operator-sdk - ref: oran-o2ims-wait-for-tls-pods - ref: tls-13 + - ref: oran-o2ims-wait-for-tls-pods-post-rollout - ref: tls-scanner-run workflow: ipi-aws - always_run: false diff --git a/ci-operator/step-registry/oran-o2ims/wait-for-tls-pods-post-rollout/OWNERS b/ci-operator/step-registry/oran-o2ims/wait-for-tls-pods-post-rollout/OWNERS new file mode 120000 index 0000000000000..ec405d65a79df --- /dev/null +++ b/ci-operator/step-registry/oran-o2ims/wait-for-tls-pods-post-rollout/OWNERS @@ -0,0 +1 @@ +../OWNERS \ No newline at end of file diff --git a/ci-operator/step-registry/oran-o2ims/wait-for-tls-pods-post-rollout/oran-o2ims-wait-for-tls-pods-post-rollout-commands.sh b/ci-operator/step-registry/oran-o2ims/wait-for-tls-pods-post-rollout/oran-o2ims-wait-for-tls-pods-post-rollout-commands.sh new file mode 120000 index 0000000000000..e3b9dbe09f38f --- /dev/null +++ b/ci-operator/step-registry/oran-o2ims/wait-for-tls-pods-post-rollout/oran-o2ims-wait-for-tls-pods-post-rollout-commands.sh @@ -0,0 +1 @@ +../wait-for-tls-pods/oran-o2ims-wait-for-tls-pods-commands.sh \ No newline at end of file diff --git a/ci-operator/step-registry/oran-o2ims/wait-for-tls-pods-post-rollout/oran-o2ims-wait-for-tls-pods-post-rollout-ref.metadata.json b/ci-operator/step-registry/oran-o2ims/wait-for-tls-pods-post-rollout/oran-o2ims-wait-for-tls-pods-post-rollout-ref.metadata.json new file mode 100644 index 0000000000000..a4e2e2f995cd5 --- /dev/null +++ b/ci-operator/step-registry/oran-o2ims/wait-for-tls-pods-post-rollout/oran-o2ims-wait-for-tls-pods-post-rollout-ref.metadata.json @@ -0,0 +1,15 @@ +{ + "path": "oran-o2ims/wait-for-tls-pods-post-rollout/oran-o2ims-wait-for-tls-pods-post-rollout-ref.yaml", + "owners": { + "approvers": [ + "alegacy", + "donpenney", + "rauhersu" + ], + "reviewers": [ + "alegacy", + "donpenney", + "rauhersu" + ] + } +} \ No newline at end of file diff --git a/ci-operator/step-registry/oran-o2ims/wait-for-tls-pods-post-rollout/oran-o2ims-wait-for-tls-pods-post-rollout-ref.yaml b/ci-operator/step-registry/oran-o2ims/wait-for-tls-pods-post-rollout/oran-o2ims-wait-for-tls-pods-post-rollout-ref.yaml new file mode 100644 index 0000000000000..a98cf30b10839 --- /dev/null +++ b/ci-operator/step-registry/oran-o2ims/wait-for-tls-pods-post-rollout/oran-o2ims-wait-for-tls-pods-post-rollout-ref.yaml @@ -0,0 +1,20 @@ +ref: + as: oran-o2ims-wait-for-tls-pods-post-rollout + from: cli + cli: latest + commands: oran-o2ims-wait-for-tls-pods-post-rollout-commands.sh + env: + - name: WAIT_NAMESPACE + default: oran-o2ims + documentation: "Namespace where the oran-o2ims operator is deployed." + resources: + requests: + cpu: 100m + memory: 200Mi + documentation: |- + Runs the same checks as oran-o2ims-wait-for-tls-pods but is + intended to be placed after the tls-13 step. The Modern TLS + profile rollout restarts service-ca, which re-issues serving + certificates and causes operator pods to be recreated. This + step waits for the pods to come back up and serve TLS before + the tls-scanner-run step executes.