Bug 1788214
| Summary: | create a CI job to test disconnected install/upgrade via proxy with custom CA root | ||
|---|---|---|---|
| Product: | OpenShift Container Platform | Reporter: | Chet Hosey <ChetRHosey> |
| Component: | Networking | Assignee: | Ben Bennett <bbennett> |
| Networking sub component: | openshift-sdn | QA Contact: | |
| Status: | CLOSED WONTFIX | Docs Contact: | |
| Severity: | medium | ||
| Priority: | low | CC: | aconstan, anbhat, aos-bugs, bbennett, eparis, jokerman, scuppett, sponnaga, sttts |
| Version: | 4.2.z | ||
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | SDN-CI-IMPACT | ||
| Fixed In Version: | Doc Type: | If docs needed, set a value | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2021-07-12 15:12:49 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
Chet Hosey
2020-01-06 17:52:45 UTC
Setting target release to 4.4 to perform investigation on the active development branch (will be re-set/cloned where fixes & backports, if any, are required). Xiaoli has explained that this set of test cases already exists in those which QE runs. Do we have a compelling reason to duplicate it? It seems the major gap is in upgrading from 4.1 -> 4.2 and adding proxy configuration. My assumption is that if these issues *were* caught by existing test cases, they wouldn't have made it into the released product. Do you disagree? To clarify, there are at least two gaps: - Proxied operations must be tested on a disconnected cluster. For example, prior to 4.2.13 the cluster version operator just ignored proxy settings and accessed the internet directly. If upgrade-via-proxy was tested, there's no way it was tested from a disconnected cluster because it wouldn't have worked. - Upgrade from 4.1 -> 4.2 and enable proxy settings. - First, this caused the network operator to crashloop. This is resolved in 4.2.13. - Second, the machine config operator isn't configuring the hosts with the bundle listed in the proxy's trustedCA setting, so kubelet isn't able to pull images through a proxy that uses a corporate certificate authority. Do we have an owner for this? Test infrastructure does not fit it. Minus upgrade coverage, https://github.com/openshift/release/pull/5308 is attempting to provide the necessary CI coverage. Eric, Can you provide an update on the status of PR 5308? Aside from upgrades, can you verify your PR addresses these use cases? Does a Jira card exist for creating an upgrade test for a proxied environment? Eric, we need information on this one. Moving to 4.4z as this is certainly not blocking the release today or tomorrow. > Can you provide an update on the status of PR 5308? I had been focusing on Logging work to get that out before the feature freeze, so I haven't looked in a while. Last I saw the AWS rehearsal job was still failing due to (I believe) gaps from other teams tests since this was now going to be removing direct egress access... I had opened a bz to track this with the oauth team, but am not sure when it will be addressed. I'll rerun the rehearsal job and see where things are -- it looked like the non-aws platform rehearsal failed due to different issues as the proxy work is restricted to only the AWS scope. > Aside from upgrades, can you verify your PR addresses these use cases? > ignoring proxy settings and trying to access the internet directly https://github.com/openshift/release/pull/5308 covers this use case. > Does a Jira card exist for creating an upgrade test for a proxied environment? Not that I'm aware of.. the only JIRA card was to create the initial blackhole'd VPC job https://issues.redhat.com/browse/DPTP-591 I feel that if there is going to be an upgrade test it would fall on testplatform team to build upon release/5308. ewolinet, I created separate bugs to address proxy CI coverage for a) each supported provider b) an upgrade job and c) a day-2 config job. Setting the target to 4.7. |