Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

cert-rotation: CSR approval fixes #51885

Merged

Conversation

vrutkovs
Copy link
Member

@vrutkovs vrutkovs commented May 10, 2024

  • print when CSR approval is completed. This helps correlate between kubelet logs and csr approval start/end period

  • extend time we want for new certs. With leader election it takes ~7 minutes for new certs to be generated and distributed, so that kubelet could create CSRs after we finish approval.

    This extends timeout we wait for bootstrap certs to be approved from 30 * 10 / 60 = 5 minutes to 40 * 10 / 60 ~ 7 minutes

@openshift-ci openshift-ci bot requested review from stbenjam and xueqzhan May 10, 2024 13:05
@openshift-ci openshift-ci bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label May 10, 2024
@vrutkovs
Copy link
Member Author

/pj-rehearse pull-ci-openshift-cluster-kube-apiserver-operator-release-4.15-e2e-metal-ovn-ha-cert-rotation-suspend-90d pull-ci-openshift-cluster-kube-apiserver-operator-release-4.15-e2e-metal-ovn-sno-cert-rotation-suspend-90d

@openshift-ci-robot
Copy link
Contributor

@vrutkovs: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel.

@vrutkovs
Copy link
Member Author

/pj-rehearse pull-ci-openshift-cluster-kube-apiserver-operator-release-4.15-e2e-metal-ovn-ha-cert-rotation-suspend-90d pull-ci-openshift-cluster-kube-apiserver-operator-release-4.15-e2e-metal-ovn-sno-cert-rotation-suspend-90d

@openshift-ci-robot
Copy link
Contributor

@vrutkovs: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel.

@vrutkovs
Copy link
Member Author

/pj-rehearse pull-ci-openshift-cluster-kube-apiserver-operator-release-4.15-e2e-metal-ovn-ha-cert-rotation-suspend-90d pull-ci-openshift-cluster-kube-apiserver-operator-release-4.15-e2e-metal-ovn-sno-cert-rotation-suspend-90d

@openshift-ci-robot
Copy link
Contributor

@vrutkovs: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel.

* print when CSR approval is completed. This helps correlate between
  kubelet logs and csr approval start/end period
* extend time we want for new certs. With leader election
  it takes ~7 minutes for new certs to be generated and distributed,
  so that kubelet could create CSRs after we finish approval.

  This extends timeout we wait for bootstrap certs to be approved from
  30*10/60 = 5 minutes to 40*15/60 = 10 minutes
@vrutkovs
Copy link
Member Author

/pj-rehearse pull-ci-openshift-cluster-kube-apiserver-operator-release-4.15-e2e-metal-ovn-ha-cert-rotation-suspend-90d pull-ci-openshift-cluster-kube-apiserver-operator-release-4.15-e2e-metal-ovn-sno-cert-rotation-suspend-90d

@openshift-ci-robot
Copy link
Contributor

@vrutkovs: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel.

@openshift-ci-robot
Copy link
Contributor

[REHEARSALNOTIFIER]
@vrutkovs: the pj-rehearse plugin accommodates running rehearsal tests for the changes in this PR. Expand 'Interacting with pj-rehearse' for usage details. The following rehearsable tests have been affected by this change:

Test name Repo Type Reason
pull-ci-openshift-cluster-kube-apiserver-operator-master-e2e-metal-ovn-ha-cert-rotation-shutdown-90d openshift/cluster-kube-apiserver-operator presubmit Registry content changed
pull-ci-openshift-cluster-kube-apiserver-operator-master-e2e-metal-ovn-ha-cert-rotation-shutdown-180d openshift/cluster-kube-apiserver-operator presubmit Registry content changed
pull-ci-openshift-cluster-kube-apiserver-operator-master-e2e-metal-ovn-ha-cert-rotation-shutdown-360d openshift/cluster-kube-apiserver-operator presubmit Registry content changed
pull-ci-openshift-cluster-kube-apiserver-operator-release-4.17-e2e-metal-ovn-ha-cert-rotation-shutdown-90d openshift/cluster-kube-apiserver-operator presubmit Registry content changed
pull-ci-openshift-cluster-kube-apiserver-operator-release-4.17-e2e-metal-ovn-ha-cert-rotation-shutdown-180d openshift/cluster-kube-apiserver-operator presubmit Registry content changed
pull-ci-openshift-cluster-kube-apiserver-operator-release-4.17-e2e-metal-ovn-ha-cert-rotation-shutdown-360d openshift/cluster-kube-apiserver-operator presubmit Registry content changed
pull-ci-openshift-cluster-kube-apiserver-operator-release-4.16-e2e-metal-ovn-ha-cert-rotation-shutdown-90d openshift/cluster-kube-apiserver-operator presubmit Registry content changed
pull-ci-openshift-cluster-kube-apiserver-operator-release-4.16-e2e-metal-ovn-ha-cert-rotation-shutdown-180d openshift/cluster-kube-apiserver-operator presubmit Registry content changed
pull-ci-openshift-cluster-kube-apiserver-operator-release-4.16-e2e-metal-ovn-ha-cert-rotation-shutdown-360d openshift/cluster-kube-apiserver-operator presubmit Registry content changed
pull-ci-openshift-cluster-kube-apiserver-operator-release-4.15-e2e-metal-ovn-ha-cert-rotation-shutdown-90d openshift/cluster-kube-apiserver-operator presubmit Registry content changed
pull-ci-openshift-cluster-kube-apiserver-operator-release-4.15-e2e-metal-ovn-ha-cert-rotation-shutdown-180d openshift/cluster-kube-apiserver-operator presubmit Registry content changed
pull-ci-openshift-cluster-kube-apiserver-operator-release-4.15-e2e-metal-ovn-ha-cert-rotation-shutdown-360d openshift/cluster-kube-apiserver-operator presubmit Registry content changed
pull-ci-openshift-cluster-kube-apiserver-operator-release-4.14-e2e-metal-ovn-ha-cert-rotation-shutdown-90d openshift/cluster-kube-apiserver-operator presubmit Registry content changed
pull-ci-openshift-cluster-kube-apiserver-operator-release-4.14-e2e-metal-ovn-ha-cert-rotation-shutdown-180d openshift/cluster-kube-apiserver-operator presubmit Registry content changed
pull-ci-openshift-cluster-kube-apiserver-operator-release-4.14-e2e-metal-ovn-ha-cert-rotation-shutdown-360d openshift/cluster-kube-apiserver-operator presubmit Registry content changed
pull-ci-openshift-cluster-kube-apiserver-operator-master-e2e-metal-ovn-ha-cert-rotation-suspend-90d openshift/cluster-kube-apiserver-operator presubmit Registry content changed
pull-ci-openshift-cluster-kube-apiserver-operator-master-e2e-metal-ovn-ha-cert-rotation-suspend-180d openshift/cluster-kube-apiserver-operator presubmit Registry content changed
pull-ci-openshift-cluster-kube-apiserver-operator-master-e2e-metal-ovn-ha-cert-rotation-suspend-360d openshift/cluster-kube-apiserver-operator presubmit Registry content changed
pull-ci-openshift-cluster-kube-apiserver-operator-release-4.17-e2e-metal-ovn-ha-cert-rotation-suspend-90d openshift/cluster-kube-apiserver-operator presubmit Registry content changed
pull-ci-openshift-cluster-kube-apiserver-operator-release-4.17-e2e-metal-ovn-ha-cert-rotation-suspend-180d openshift/cluster-kube-apiserver-operator presubmit Registry content changed
pull-ci-openshift-cluster-kube-apiserver-operator-release-4.17-e2e-metal-ovn-ha-cert-rotation-suspend-360d openshift/cluster-kube-apiserver-operator presubmit Registry content changed
pull-ci-openshift-cluster-kube-apiserver-operator-release-4.16-e2e-metal-ovn-ha-cert-rotation-suspend-90d openshift/cluster-kube-apiserver-operator presubmit Registry content changed
pull-ci-openshift-cluster-kube-apiserver-operator-release-4.16-e2e-metal-ovn-ha-cert-rotation-suspend-180d openshift/cluster-kube-apiserver-operator presubmit Registry content changed
pull-ci-openshift-cluster-kube-apiserver-operator-release-4.16-e2e-metal-ovn-ha-cert-rotation-suspend-360d openshift/cluster-kube-apiserver-operator presubmit Registry content changed
pull-ci-openshift-cluster-kube-apiserver-operator-release-4.15-e2e-metal-ovn-ha-cert-rotation-suspend-90d openshift/cluster-kube-apiserver-operator presubmit Registry content changed

A total of 162 jobs have been affected by this change. The above listing is non-exhaustive and limited to 25 jobs.

A full list of affected jobs can be found here

Interacting with pj-rehearse

Comment: /pj-rehearse to run up to 5 rehearsals
Comment: /pj-rehearse skip to opt-out of rehearsals
Comment: /pj-rehearse {test-name}, with each test separated by a space, to run one or more specific rehearsals
Comment: /pj-rehearse more to run up to 10 rehearsals
Comment: /pj-rehearse max to run up to 25 rehearsals
Comment: /pj-rehearse auto-ack to run up to 5 rehearsals, and add the rehearsals-ack label on success
Comment: /pj-rehearse abort to abort all active rehearsals

Once you are satisfied with the results of the rehearsals, comment: /pj-rehearse ack to unblock merge. When the rehearsals-ack label is present on your PR, merge will no longer be blocked by rehearsals.
If you would like the rehearsals-ack label removed, comment: /pj-rehearse reject to re-block merging.

Copy link
Contributor

openshift-ci bot commented May 13, 2024

@vrutkovs: The following tests failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test name Commit Details Required Rerun command
ci/rehearse/openshift/cluster-kube-apiserver-operator/release-4.15/e2e-metal-ovn-ha-cert-rotation-suspend-90d 0ffd1d3 link unknown /pj-rehearse pull-ci-openshift-cluster-kube-apiserver-operator-release-4.15-e2e-metal-ovn-ha-cert-rotation-suspend-90d
ci/rehearse/openshift/cluster-kube-apiserver-operator/release-4.15/e2e-metal-ovn-sno-cert-rotation-suspend-90d 0ffd1d3 link unknown /pj-rehearse pull-ci-openshift-cluster-kube-apiserver-operator-release-4.15-e2e-metal-ovn-sno-cert-rotation-suspend-90d

Full PR test history. Your PR dashboard.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

@vrutkovs
Copy link
Member Author

/pj-rehearse ack

@openshift-ci-robot
Copy link
Contributor

@vrutkovs: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel.

@openshift-ci-robot openshift-ci-robot added the rehearsals-ack Signifies that rehearsal jobs have been acknowledged label May 14, 2024
@wangke19
Copy link
Contributor

/lgtm

@openshift-ci openshift-ci bot added the lgtm Indicates that a PR is ready to be merged. label May 14, 2024
Copy link
Contributor

@sanchezl sanchezl left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm

Copy link
Contributor

openshift-ci bot commented May 14, 2024

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: sanchezl, vrutkovs, wangke19

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@deepsm007
Copy link
Contributor

/hold
batch failure while merging, i'll unhold after clearing the batch

@openshift-ci openshift-ci bot added the do-not-merge/hold Indicates that a PR should not merge because someone has issued a /hold command. label May 14, 2024
@deepsm007
Copy link
Contributor

/hold cancel

@openshift-ci openshift-ci bot removed the do-not-merge/hold Indicates that a PR should not merge because someone has issued a /hold command. label May 14, 2024
@openshift-merge-bot openshift-merge-bot bot merged commit b24eab6 into openshift:master May 14, 2024
12 of 14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
approved Indicates a PR has been approved by an approver from all required OWNERS files. lgtm Indicates that a PR is ready to be merged. rehearsals-ack Signifies that rehearsal jobs have been acknowledged
Projects
None yet
5 participants