From 276f7089e0a36990d596be19e5ccbaf8d068d589 Mon Sep 17 00:00:00 2001 From: Parveen Kumar Date: Thu, 8 Oct 2026 19:26:27 +0530 Subject: [PATCH] Revert "[minor] Support October Interim Catalog Update (#519)" This reverts commit 6603e9101aae2eae84881dd6e7745af7462e3f8f. --- .../devops/data/catalogs/v9-261007-amd64.yaml | 209 ------------ .../data/catalogs/v9-261007-ppc64le.yaml | 76 ----- .../devops/data/catalogs/v9-261007-s390x.yaml | 76 ----- src/mas/devops/tekton.py | 312 ++++++++++++++---- .../pipelinerun-aiservice-upgrade.yml.j2 | 20 +- .../templates/pipelinerun-backup.yml.j2 | 15 +- .../templates/pipelinerun-install.yml.j2 | 20 +- .../templates/pipelinerun-restore.yml.j2 | 19 +- .../templates/pipelinerun-update.yml.j2 | 18 +- .../templates/pipelinerun-upgrade.yml.j2 | 19 +- test/src/test_data.py | 2 +- 11 files changed, 284 insertions(+), 502 deletions(-) delete mode 100644 src/mas/devops/data/catalogs/v9-261007-amd64.yaml delete mode 100644 src/mas/devops/data/catalogs/v9-261007-ppc64le.yaml delete mode 100644 src/mas/devops/data/catalogs/v9-261007-s390x.yaml diff --git a/src/mas/devops/data/catalogs/v9-261007-amd64.yaml b/src/mas/devops/data/catalogs/v9-261007-amd64.yaml deleted file mode 100644 index bb75b9cd..00000000 --- a/src/mas/devops/data/catalogs/v9-261007-amd64.yaml +++ /dev/null @@ -1,209 +0,0 @@ ---- -# Case bundle configuration for IBM Maximo Operator Catalog 261007 (AMD64) -# ----------------------------------------------------------------------------- -# In the future this won't be necessary as we'll be able to mirror from the -# catalog itself, but not everything in the catalog supports this yet (including MAS) -# so we need to use the CASE bundle mirror process still. - -catalog_digest: sha256:48853583aafe1351ac766c50f5297c67015751269c476de31c2b9bfe66e29d8f - -ocp_compatibility: -- "4.18" -- "4.19" -- "4.20" -- "4.21" -- "4.22" - -# Dependencies - Cloud Pak for Data -# ----------------------------------------------------------------------------- -cpd_product_version_default: 5.3.1 # No Updated - -# Dependencies -# ----------------------------------------------------------------------------- -ibm_licensing_version: 4.2.24 # Operator version 4.2.20 (https://github.com/IBM/cloud-pak/tree/master/repo/case/ibm-licensing) -common_svcs_version: 4.17.0 # Operator version 4.17.0 (https://github.com/IBM/cloud-pak/tree/master/repo/case/ibm-cp-common-services) -#common_svcs_version_1: 4.11.0 # Additional version 4.11.0 - -cp4d_platform_version: 5.4.0+20260501.120952.925.640.50 # Operator version 5.4.0 (https://github.com/IBM/cloud-pak/tree/master/repo/case/ibm-cp-datacore/) -ibm_zen_version: 6.4.0+20260210.170932.92 # For CPD5 ibm-zen has to be explicitily mirrored - -# CPD 5.3.1 Helm Component Versions (CASE versions For Helm charts) -wsl_version: 12.1.0 # CPD 5.3.1 Watson Studio CASE version for Helm -wsl_runtimes_version: 12.1.0 # CPD 5.3.1 Watson Studio Runtimes CASE version -wml_version: 12.1.0 # CPD 5.3.1 Watson Machine Learning CASE version for Helm -redis_version: 1.3.1 # CPD 5.3.1 Redis CASE version (WML dependency) -postgress_version: 5.31.0+20260129.161021.2713 # ibm-cpd-cloud-native-postgresql-operator 5.2.0 cp4d - -# CPD 5.3.1 Shared Dependencies -ccs_build: 12.1.0 # CPD 5.3.1 Common Core Services CASE version -opensearch_version: 1.2.0 # CPD 5.3.1 OpenSearch CASE version -datarefinery_version: 12.1.0 # CPD 5.3.1 Data Refinery CASE version - -spark_version: 12.1.0 # CPD 5.3.1 Analytics Engine/Spark CASE version for Helm -cognos_version: 29.1.0 # CPD 5.3.1 Cognos Analytics CASE version for Helm (Helm-only) -elasticsearch_version: 1.1.2667 - - -# Dependencies - Db2u -# ----------------------------------------------------------------------------- -db2u_version: 7.7.1+20260729.095150.20860 # Operator version 120105.0.1 (https://github.com/IBM/cloud-pak/tree/master/repo/case/ibm-db2uoperator) -db2u_extras_version: 1.0.6 -db2u_filter: db2 - -db2_channel_default: v120105.0 # No Updated # Default Channel version for db2u-operator - - -# Dependencies - CouchDb -# ----------------------------------------------------------------------------- -# Note: This is required for Assist 9.0 (https://github.com/IBM/cloud-pak/blob/master/repo/case/ibm-couchdb/index.yaml) -couchdb_version: 1.0.13 # Operator version 2.2.1 (1.0.13) sticking with 1.0.13 - - -# Dependencies - Minio -# ----------------------------------------------------------------------------- -minio_version: RELEASE.2025-06-13T11-33-47Z -minio_extras_version: 1.0.0 - -# Dependencies - MongoDB -# ----------------------------------------------------------------------------- -mongo_extras_version_default: 8.0.30 -mongo_extras_version_4: 4.4.21 -mongo_extras_version_5: 5.0.23 -mongo_extras_version_6: 6.0.12 -mongo_extras_version_7: 7.0.23 -mongo_extras_version_8: 8.0.30 # No Update - - -# Dependencies - Amlen -# ----------------------------------------------------------------------------- -amlen_extras_version: 1.1.6 # No Update - - -# Dependencies - UDS -# ----------------------------------------------------------------------------- -uds_version: 2.0.12 # Operator version 2.0.12 # sticking to 2.0.12 version # Please do Not Change -uds_extras_version: 1.5.0 - - -# Dependencies - App Connect -# ----------------------------------------------------------------------------- -appconnect_version: 6.2.0 # Operator version 6.2.0 # sticking to 6.2.0 version # Please do Not Change - - -# Dependencies - Suite License Service -# ----------------------------------------------------------------------------- -# https://github.ibm.com/maximoappsuite/ibm-sls/releases -sls_version: 3.13.2 # No Update - - -# Dependencies - Truststore Manager -# ----------------------------------------------------------------------------- -# https://github.ibm.com/maximoappsuite/ibm-truststore-mgr/releases -tsm_version: 1.7.9 # No Update - - -# Dependencies - Data Dictionary -# ----------------------------------------------------------------------------- -# https://github.ibm.com/maximoappsuite/ibm-data-dictionary/releases -dd_version: 1.1.23 # No Update - -# Dependencies - Opendata hub -# ----------------------------------------------------------------------------- -# https://github.com/opendatahub-io/opendatahub-operator/releases -odh_version: 2.32.0 - -# Extra Images for Redis (Collaborate) -# ------------------------------------------------------------------------------ -redis_extras_version: 2.1.40 # No Update - - -# Maximo Application Suite -# ----------------------------------------------------------------------------- -mas_core_version: - 9.2.x: 9.2.8 # Updated - 9.2.x-feature: 9.2.0 # No Update - 9.1.x: 9.1.27 # Updated - 9.0.x: 9.0.33 # Updated - 8.10.x: 8.10.37 # No Update - 8.11.x: 8.11.34 # No Update -mas_assist_version: - 9.1.x: 9.1.15 # No Update - 9.0.x: 9.0.21 # No Update - 8.10.x: 8.7.8 # No Update - 8.11.x: 8.8.7 # No Update -mas_hputilities_version: - 9.1.x: "" # Not Supported - 9.0.x: "" # Not Supported - 8.10.x: 8.6.7 # No Update - 8.11.x: "" # Not Supported -mas_iot_version: - 9.2.x: 9.2.4 # No Update - 9.2.x-feature: 9.2.0 # No Update - 9.1.x: 9.1.15 # No Update - 9.0.x: 9.0.24 # No Update - 8.10.x: 8.7.33 # No Update - 8.11.x: 8.8.30 # No Update -mas_manage_version: - 9.2.x: 9.2.4 # No Update - 9.2.x-feature: 9.2.0 # No Update - 9.1.x: 9.1.25 # No Update - 9.0.x: 9.0.32 # No Update - 8.10.x: 8.6.38 # No Update - 8.11.x: 8.7.32 # No Update -mas_monitor_version: - 9.2.x: 9.2.4 # No Update - 9.2.x-feature: 9.2.0 # No Update - 9.1.x: 9.1.15 # No Update - 9.0.x: 9.0.25 # No Update - 8.10.x: 8.10.30 # No Update - 8.11.x: 8.11.28 # No Update -mas_optimizer_version: - 9.2.x: 9.2.3 # No Update - 9.2.x-feature: 9.2.0 # No Update - 9.1.x: 9.1.16 # No Update - 9.0.x: 9.0.27 # No Update - 8.10.x: 8.4.28 # No Update - 8.11.x: 8.5.28 # No Update -mas_predict_version: - 9.2.x: 9.2.2 # No Update - 9.2.x-feature: 9.2.0 # No Update - 9.1.x: 9.1.11 # No Update - 9.0.x: 9.0.18 # No Update - 8.10.x: 8.8.15 # No Update - 8.11.x: 8.9.17 # No Update -mas_visualinspection_version: - 9.2.x: 9.2.3 # No Update - 9.2.x-feature: 9.2.0 # No Update - 9.1.x: 9.1.21 # No Update - 9.0.x: 9.0.24 # No Update - 8.10.x: 8.8.4 # No Update - 8.11.x: 8.9.21 # No Update -mas_facilities_version: - 9.2.x: 9.2.3 # No Update - 9.2.x-feature: 9.2.0 # No Update - 9.1.x: 9.1.15 # No Update - 9.0.x: "" # Not Supported - 8.10.x: "" # Not Supported - 8.11.x: "" # Not Supported - - -# Maximo AI Service -# ------------------------------------------------------------------------------ -aiservice_version: - 9.2.x: 9.2.3 # No Update - 9.2.x-feature: 9.2.0 # No Update - 9.1.x: 9.1.19 # No Update - -aiservice_tenant_version: - 9.2.x: 9.2.3 # No Update - 9.2.x-feature: 9.2.0 # No Update - - -# Editorial -# ------------------------------------------------------------------------------ -editorial: - whats_new: - - title: '**Security updates and bug fixes**' - details: - - Security fix available for CVE-2026-105052 (Path Traversal, CVSS 7.5) Details: https://www.ibm.com/support/pages/node/7289766 - - IBM Maximo Application Suite Core Platform [v9.0.33], [v9.1.27] and [v9.2.8] diff --git a/src/mas/devops/data/catalogs/v9-261007-ppc64le.yaml b/src/mas/devops/data/catalogs/v9-261007-ppc64le.yaml deleted file mode 100644 index b2088dd6..00000000 --- a/src/mas/devops/data/catalogs/v9-261007-ppc64le.yaml +++ /dev/null @@ -1,76 +0,0 @@ ---- -# Case bundle configuration for IBM Maximo Operator Catalog 261007 (PPC) -# ----------------------------------------------------------------------------- -# In the future this won't be necessary as we'll be able to mirror from the -# catalog itself, but not everything in the catalog supports this yet (including MAS) -# so we need to use the CASE bundle mirror process still. - -catalog_digest: sha256:910e5b3d32711686e12044d95a51c200379ae46eea3a0ed3e8b85a912aa0ac69 - -ocp_compatibility: -- "4.18" -- "4.19" -- "4.20" -- "4.21" -- "4.22" - -# Dependencies - Db2u -# ----------------------------------------------------------------------------- -db2u_version: 7.7.1+20260729.095150.20860 # Operator version 120105.0.1 (https://github.com/IBM/cloud-pak/tree/master/repo/case/ibm-db2uoperator) - -db2_channel_default: v120105.0 # No Updated # Default Channel version for db2u-operator - - -# Dependencies - UDS -# ----------------------------------------------------------------------------- -uds_version: 2.0.12 # Operator version 2.0.12 # sticking to 2.0.12 version # Please do Not Change -uds_extras_version: 1.5.0 # No Update - - -# Dependencies - Suite License Service -# ----------------------------------------------------------------------------- -# https://github.ibm.com/maximoappsuite/ibm-sls/releases -sls_version: 3.13.2 # No Update - - -# Dependencies - Truststore Manager -# ----------------------------------------------------------------------------- -# https://github.ibm.com/maximoappsuite/ibm-truststore-mgr/releases -tsm_version: 1.7.9 # No Update - - -# Dependencies - MongoDB -# ----------------------------------------------------------------------------- -mongo_extras_version_default: 8.0.30 -mongo_extras_version_4: 4.4.21 -mongo_extras_version_5: 5.0.23 -mongo_extras_version_6: 6.0.12 -mongo_extras_version_7: 7.0.12 -mongo_extras_version_8: 8.0.30 # No Update - -# Maximo Application Suite -# ----------------------------------------------------------------------------- -mas_core_version: - 9.2.x: 9.2.8 # Updated - 9.2.x-feature: 9.2.0 # No Update - 9.1.x: 9.1.27 # Updated - 9.0.x: 9.0.33 # Updated - 8.10.x: "" # Not Supported - 8.11.x: "" # Not Supported -mas_manage_version: - 9.2.x: 9.2.4 # No Update - 9.2.x-feature: 9.2.0 # No Update - 9.1.x: 9.1.25 # No Update - 9.0.x: 9.0.32 # No Update - 8.10.x: "" # Not Supported - 8.11.x: "" # Not Supported - - -# Editorial -# ------------------------------------------------------------------------------ -editorial: - whats_new: - - title: '**Security updates and bug fixes**' - details: - - Security fix available for CVE-2026-105052 (Path Traversal, CVSS 7.5) Details: https://www.ibm.com/support/pages/node/7289766 - - IBM Maximo Application Suite Core Platform [v9.0.33], [v9.1.27] and [v9.2.8] \ No newline at end of file diff --git a/src/mas/devops/data/catalogs/v9-261007-s390x.yaml b/src/mas/devops/data/catalogs/v9-261007-s390x.yaml deleted file mode 100644 index ba932848..00000000 --- a/src/mas/devops/data/catalogs/v9-261007-s390x.yaml +++ /dev/null @@ -1,76 +0,0 @@ ---- -# Case bundle configuration for IBM Maximo Operator Catalog 261007 (Z) -# ----------------------------------------------------------------------------- -# In the future this won't be necessary as we'll be able to mirror from the -# catalog itself, but not everything in the catalog supports this yet (including MAS) -# so we need to use the CASE bundle mirror process still. - -catalog_digest: sha256:0654a9b9cc9b1304b3314dbde457548bfae322c4f2f962971212a15cb2bce7de - -ocp_compatibility: -- "4.18" -- "4.19" -- "4.20" -- "4.21" -- "4.22" - -# Dependencies - Db2u -# ----------------------------------------------------------------------------- -db2u_version: 7.7.1+20260729.095150.20860 # Operator version 120105.0.1 (https://github.com/IBM/cloud-pak/tree/master/repo/case/ibm-db2uoperator) - -db2_channel_default: v120105.0 # No Update # Default Channel version for db2u-operator - - -# Dependencies - UDS -# ----------------------------------------------------------------------------- -uds_version: 2.0.12 # Operator version 2.0.12 # sticking to 2.0.12 version # Please do Not Change -uds_extras_version: 1.5.0 # No Update - - -# Dependencies - Suite License Service -# ----------------------------------------------------------------------------- -# https://github.ibm.com/maximoappsuite/ibm-sls/releases -sls_version: 3.13.2 # No Update - - -# Dependencies - Truststore Manager -# ----------------------------------------------------------------------------- -# https://github.ibm.com/maximoappsuite/ibm-truststore-mgr/releases -tsm_version: 1.7.9 # No Update - - -# Dependencies - MongoDB -# ----------------------------------------------------------------------------- -mongo_extras_version_default: 8.0.30 -mongo_extras_version_4: 4.4.21 -mongo_extras_version_5: 5.0.23 -mongo_extras_version_6: 6.0.12 -mongo_extras_version_7: 7.0.12 -mongo_extras_version_8: 8.0.30 # No Update - -# Maximo Application Suite -# ----------------------------------------------------------------------------- -mas_core_version: - 9.2.x: 9.2.8 # Updated - 9.2.x-feature: 9.2.0 # No Update - 9.1.x: 9.1.27 # Updated - 9.0.x: 9.0.33 # Updated - 8.10.x: "" # Not Supported - 8.11.x: "" # Not Supported -mas_manage_version: - 9.2.x: 9.2.4 # No Update - 9.2.x-feature: 9.2.0 # No Update - 9.1.x: 9.1.25 # No Update - 9.0.x: 9.0.32 # No Update - 8.10.x: "" # Not Supported - 8.11.x: "" # Not Supported - - -# Editorial -# ------------------------------------------------------------------------------ -editorial: - whats_new: - - title: '**Security updates and bug fixes**' - details: - - Security fix available for CVE-2026-105052 (Path Traversal, CVSS 7.5) Details: https://www.ibm.com/support/pages/node/7289766 - - IBM Maximo Application Suite Core Platform [v9.0.33], [v9.1.27] and [v9.2.8] \ No newline at end of file diff --git a/src/mas/devops/tekton.py b/src/mas/devops/tekton.py index e017a3dd..ed44dc4e 100644 --- a/src/mas/devops/tekton.py +++ b/src/mas/devops/tekton.py @@ -843,17 +843,30 @@ def prepareAiServicePipelinesNamespace( logger.info(f"Storage class {storageClass} uses volumeBindingMode={volumeBindingMode}, skipping PVC bind wait") -def prepareRestoreSecrets(dynClient: DynamicClient, namespace: str, restoreConfigs: dict = None): +def prepareRestoreSecrets( + dynClient: DynamicClient, + namespace: str, + restoreConfigs: dict = None, + ibm_entitlement_key: str = None, + artifactory_token: str = None, + artifactory_username: str = None, + registry_secret_name: str = "mas-restore-secrets", +): """ Create or update secret required for MAS Restore pipeline. - Creates secret in the specified namespace: + Creates secrets in the specified namespace: - pipeline-restore-configs + - {registry_secret_name} (only when credentials are provided) Parameters: dynClient (DynamicClient): OpenShift Dynamic Client namespace (str): The namespace to create secrets in restoreConfigs (dict, optional): configuration data for restore. Defaults to None (empty secret). + ibm_entitlement_key (str, optional): IBM entitlement key for registry access. Defaults to None. + artifactory_token (str, optional): Artifactory token for dev catalog access. Defaults to None. + artifactory_username (str, optional): Artifactory username for dev catalog access. Defaults to None. + registry_secret_name (str, optional): Name of the per-pipeline registry credentials secret. Defaults to "mas-restore-secrets". Returns: None @@ -880,6 +893,37 @@ def prepareRestoreSecrets(dynClient: DynamicClient, namespace: str, restoreConfi } secretsAPI.create(body=restoreConfigs, namespace=namespace) + # 2. Secret/{registry_secret_name} + # ------------------------------------------------------------------------- + credentials_data = {} + + if ibm_entitlement_key: + credentials_data["IBM_ENTITLEMENT_KEY"] = base64.b64encode(ibm_entitlement_key.encode()).decode() + + if artifactory_token: + credentials_data["ARTIFACTORY_TOKEN"] = base64.b64encode(artifactory_token.encode()).decode() + + if artifactory_username: + credentials_data["ARTIFACTORY_USERNAME"] = base64.b64encode(artifactory_username.encode()).decode() + + if credentials_data: + try: + secretsAPI.delete(name=registry_secret_name, namespace=namespace) + except NotFoundError: + pass + + secretsAPI.create( + body={ + "apiVersion": "v1", + "kind": "Secret", + "type": "Opaque", + "metadata": {"name": registry_secret_name}, + "data": credentials_data, + }, + namespace=namespace, + ) + logger.info(f"Created {registry_secret_name} secret in namespace {namespace}") + def prepareInstallSecrets( dynClient: DynamicClient, @@ -893,13 +937,18 @@ def prepareInstallSecrets( aiserviceConfig: str = None, db2LicenseFile: dict | None = None, facilitiesProperties: dict | None = None, + ibm_entitlement_key: str = None, + artifactory_token: str = None, + artifactory_username: str = None, + registry_secret_name: str = None, ) -> None: """ Create or update secrets required for MAS installation pipelines. - Creates secrets in the specified namespace: mas-devops-slack, pipeline-additional-configs, - pipeline-sls-entitlement, pipeline-certificates, pipeline-pod-templates, pipeline-aiservice-config, - pipeline-db2-license, and pipeline-facilities-properties. + Creates secrets in the specified namespace: mas-devops-slack, {registry_secret_name}, + pipeline-additional-configs, pipeline-sls-entitlement, pipeline-certificates, + pipeline-pod-templates, pipeline-aiservice-config, pipeline-db2-license, and + pipeline-facilities-properties. Parameters: dynClient (DynamicClient): OpenShift Dynamic Client @@ -913,6 +962,9 @@ def prepareInstallSecrets( slack_channel (str, optional): Slack channel ID for notifications. Defaults to None. aiserviceConfig (str, optional): AI Service tenant config data. Defaults to None (empty secret). facilitiesProperties (dict, optional): Facilities properties file content. Defaults to None (empty secret). + ibm_entitlement_key (str, optional): IBM entitlement key for registry access. Defaults to None. + artifactory_token (str, optional): Artifactory token for dev catalog access. Defaults to None. + artifactory_username (str, optional): Artifactory username for dev catalog access. Defaults to None. Returns: None @@ -959,6 +1011,46 @@ def prepareInstallSecrets( secretsAPI.create(body=mas_devops_secret, namespace=namespace) logger.info(f"Created mas-devops-slack secret with MAS_INSTANCE_ID={instance_id} in namespace {namespace}") + # 1. Secret/{registry_secret_name} + # ------------------------------------------------------------------------- + # Per-pipeline secret holding registry credentials sourced from secret instead of pipeline params. + # Only created when at least one credential is provided — all keys are optional. + # Secret name is derived from namespace prefix if not explicitly provided: + # mas-{id}-pipelines → mas-install-secrets + # aiservice-{id}-pipelines → mas-aiservice-install-secrets + if instance_id: + if registry_secret_name is None: + registry_secret_name = "mas-aiservice-install-secrets" if namespace.startswith("aiservice-") else "mas-install-secrets" + + credentials_data = {} + + if ibm_entitlement_key: + credentials_data["IBM_ENTITLEMENT_KEY"] = base64.b64encode(ibm_entitlement_key.encode()).decode() + + if artifactory_token: + credentials_data["ARTIFACTORY_TOKEN"] = base64.b64encode(artifactory_token.encode()).decode() + + if artifactory_username: + credentials_data["ARTIFACTORY_USERNAME"] = base64.b64encode(artifactory_username.encode()).decode() + + if credentials_data: + try: + secretsAPI.delete(name=registry_secret_name, namespace=namespace) + except NotFoundError: + pass + + secretsAPI.create( + body={ + "apiVersion": "v1", + "kind": "Secret", + "type": "Opaque", + "metadata": {"name": registry_secret_name}, + "data": credentials_data, + }, + namespace=namespace, + ) + logger.info(f"Created {registry_secret_name} secret in namespace {namespace}") + # 1. Secret/pipeline-additional-configs # ------------------------------------------------------------------------- # Must exist, but can be empty @@ -1074,17 +1166,24 @@ def prepareUpdateSecrets( slack_token: str = None, slack_channel: str = None, db2LicenseFile: dict | None = None, + artifactory_token: str = None, + artifactory_username: str = None, + registry_secret_name: str = "mas-update-secrets", ) -> None: """ Create or update mas-devops-slack secret in mas-pipelines namespace for update pipeline. Creates the slack secret in mas-pipelines namespace if it exists and slack credentials are provided. + Also creates {registry_secret_name} secret if artifactory credentials are provided. Parameters: dynClient (DynamicClient): OpenShift Dynamic Client slack_token (str, optional): Slack bot token for notifications. Defaults to None. slack_channel (str, optional): Slack channel ID for notifications. Defaults to None. db2LicenseFile (dict, optional): Db2 license file content. Defaults to None (empty secret). + artifactory_token (str, optional): Artifactory token for dev catalog access. Defaults to None. + artifactory_username (str, optional): Artifactory username for dev catalog access. Defaults to None. + registry_secret_name (str, optional): Name of the per-pipeline registry credentials secret. Defaults to "mas-update-secrets". Returns: None @@ -1152,6 +1251,95 @@ def prepareUpdateSecrets( secretsAPI.create(body=mas_devops_secret, namespace=namespace) logger.info(f"Created mas-devops-slack secret in namespace {namespace}") + # Create {registry_secret_name} if artifactory credentials are provided + # Note: update pipeline does not use ibm_entitlement_key (skipped via skip_entitlement_key_flag) + credentials_data = {} + + if artifactory_token: + credentials_data["ARTIFACTORY_TOKEN"] = base64.b64encode(artifactory_token.encode()).decode() + + if artifactory_username: + credentials_data["ARTIFACTORY_USERNAME"] = base64.b64encode(artifactory_username.encode()).decode() + + if credentials_data: + try: + secretsAPI.delete(name=registry_secret_name, namespace=namespace) + except NotFoundError: + pass + + secretsAPI.create( + body={ + "apiVersion": "v1", + "kind": "Secret", + "type": "Opaque", + "metadata": {"name": registry_secret_name}, + "data": credentials_data, + }, + namespace=namespace, + ) + logger.info(f"Created {registry_secret_name} secret in namespace {namespace}") + + +def prepareUpgradeSecrets( + dynClient: DynamicClient, + namespace: str, + ibm_entitlement_key: str = None, + artifactory_token: str = None, + artifactory_username: str = None, + registry_secret_name: str = "mas-upgrade-secrets", +) -> None: + """ + Create the registry credentials secret required for the MAS Upgrade pipeline. + + Upgrade tasks pull images from ICR (ibm_entitlement_key) and optionally from + Artifactory (artifactory_token / artifactory_username). Credentials are written + into a named OCP Secret so they are never visible as plaintext PipelineRun params. + + Only keys with non-empty values are written to the secret. + The secret is skipped entirely if no credentials are provided. + + Parameters: + dynClient (DynamicClient): OpenShift Dynamic Client + namespace (str): The pipeline namespace (mas-{instanceId}-pipelines) + ibm_entitlement_key (str, optional): IBM entitlement key for ICR image pulls. Defaults to None. + artifactory_token (str, optional): Artifactory token for dev catalog access. Defaults to None. + artifactory_username (str, optional): Artifactory username for dev catalog access. Defaults to None. + registry_secret_name (str, optional): Name of the secret to create. Defaults to "mas-upgrade-secrets". + + Returns: + None + """ + secretsAPI = dynClient.resources.get(api_version="v1", kind="Secret") + + credentials_data = {} + + if ibm_entitlement_key: + credentials_data["IBM_ENTITLEMENT_KEY"] = base64.b64encode(ibm_entitlement_key.encode()).decode() + + if artifactory_token: + credentials_data["ARTIFACTORY_TOKEN"] = base64.b64encode(artifactory_token.encode()).decode() + + if artifactory_username: + credentials_data["ARTIFACTORY_USERNAME"] = base64.b64encode(artifactory_username.encode()).decode() + + if credentials_data: + try: + secretsAPI.delete(name=registry_secret_name, namespace=namespace) + except NotFoundError: + pass + + secretsAPI.create( + body={ + "apiVersion": "v1", + "kind": "Secret", + "type": "Opaque", + "metadata": {"name": registry_secret_name}, + "data": credentials_data, + }, + namespace=namespace, + ) + logger.info(f"Created {registry_secret_name} secret in namespace {namespace}") + def testCLI() -> None: pass @@ -1186,63 +1374,6 @@ def testCLI() -> None: # fi -def prepareUpgradeSecrets( - dynClient: DynamicClient, - namespace: str, - ibm_entitlement_key: str = None, - artifactory_token: str = None, - artifactory_username: str = None, -) -> None: - """Create or update the registry credentials secret for MAS upgrade pipelines. - - Creates a secret named 'mas-secrets' in the specified namespace containing the - IBM entitlement key and Artifactory credentials used by Tekton task steps - via the task_registry_secret_name parameter. - - Args: - dynClient (DynamicClient): OpenShift Dynamic Client. - namespace (str): The pipelines namespace (format: mas-{instance_id}-pipelines). - ibm_entitlement_key (str, optional): IBM Entitled Registry pull key. Defaults to None. - artifactory_token (str, optional): Artifactory API token. Defaults to None. - artifactory_username (str, optional): Artifactory username. Defaults to None. - - Returns: - None - - Raises: - NotFoundError: If the secret cannot be created in the namespace. - """ - import base64 - - secretsAPI = dynClient.resources.get(api_version="v1", kind="Secret") - - secret_name = "mas-secrets" - - # Delete existing secret if it exists - try: - secretsAPI.delete(name=secret_name, namespace=namespace) - except NotFoundError: - pass - - secret_data = {} - if ibm_entitlement_key: - secret_data["IBM_ENTITLEMENT_KEY"] = base64.b64encode(ibm_entitlement_key.encode()).decode() - if artifactory_token: - secret_data["ARTIFACTORY_TOKEN"] = base64.b64encode(artifactory_token.encode()).decode() - if artifactory_username: - secret_data["ARTIFACTORY_USERNAME"] = base64.b64encode(artifactory_username.encode()).decode() - - secret_body = { - "apiVersion": "v1", - "kind": "Secret", - "type": "Opaque", - "metadata": {"name": secret_name}, - "data": secret_data, - } - secretsAPI.create(body=secret_body, namespace=namespace) - logger.info(f"Created {secret_name} secret in namespace {namespace}") - - def launchUpgradePipeline( dynClient: DynamicClient, instanceId: str, @@ -1420,6 +1551,63 @@ def launchUpdatePipeline(dynClient: DynamicClient, params: dict) -> str: return pipelineURL +def prepareBackupSecrets( + dynClient: DynamicClient, + namespace: str, + artifactory_token: str = None, + artifactory_username: str = None, + registry_secret_name: str = "mas-backup-secrets", +) -> None: + """ + Create the registry credentials secret required for the MAS Backup pipeline. + + Backup tasks do not use ibm_entitlement_key (no image pulls from ICR), but may + use Artifactory credentials to upload backup archives to an Artifactory repository. + Credentials are written into a named OCP Secret so they are never visible as + plaintext PipelineRun params. + + Only keys with non-empty values are written to the secret. + The secret is skipped entirely if no credentials are provided. + + Parameters: + dynClient (DynamicClient): OpenShift Dynamic Client + namespace (str): The pipeline namespace (mas-{instanceId}-pipelines) + artifactory_token (str, optional): Artifactory token for archive upload. Defaults to None. + artifactory_username (str, optional): Artifactory username for archive upload. Defaults to None. + registry_secret_name (str, optional): Name of the secret to create. Defaults to "mas-backup-secrets". + + Returns: + None + """ + secretsAPI = dynClient.resources.get(api_version="v1", kind="Secret") + + credentials_data = {} + + if artifactory_token: + credentials_data["ARTIFACTORY_TOKEN"] = base64.b64encode(artifactory_token.encode()).decode() + + if artifactory_username: + credentials_data["ARTIFACTORY_USERNAME"] = base64.b64encode(artifactory_username.encode()).decode() + + if credentials_data: + try: + secretsAPI.delete(name=registry_secret_name, namespace=namespace) + except NotFoundError: + pass + + secretsAPI.create( + body={ + "apiVersion": "v1", + "kind": "Secret", + "type": "Opaque", + "metadata": {"name": registry_secret_name}, + "data": credentials_data, + }, + namespace=namespace, + ) + logger.info(f"Created {registry_secret_name} secret in namespace {namespace}") + + def launchBackupPipeline(dynClient: DynamicClient, params: dict) -> str: """ Create a PipelineRun to backup a MAS instance. diff --git a/src/mas/devops/templates/pipelinerun-aiservice-upgrade.yml.j2 b/src/mas/devops/templates/pipelinerun-aiservice-upgrade.yml.j2 index 4b5bc70c..d340ce8d 100644 --- a/src/mas/devops/templates/pipelinerun-aiservice-upgrade.yml.j2 +++ b/src/mas/devops/templates/pipelinerun-aiservice-upgrade.yml.j2 @@ -15,6 +15,11 @@ spec: pipeline: "0" params: + # Registry Credentials Secret + # ------------------------------------------------------------------------- + - name: pipeline_registry_secret_name + value: "mas-aiservice-upgrade-secrets" + # Target AI Service Instance # ------------------------------------------------------------------------- - name: aiservice_instance_id @@ -22,27 +27,12 @@ spec: - name: aiservice_channel value: "{{ aiservice_channel }}" - # IBM Entitlement Key - # ------------------------------------------------------------------------- - - name: ibm_entitlement_key - value: "{{ ibm_entitlement_key }}" - {%- if skip_pre_check is defined and skip_pre_check != "" %} # Skip pre-check # ------------------------------------------------------------------------- - name: skip_pre_check value: "{{ skip_pre_check }}" {%- endif %} -{%- if artifactory_username is defined and artifactory_username != "" %} - - # Enable development catalogs - # ------------------------------------------------------------------------- - - name: artifactory_username - value: "{{ artifactory_username }}" - - name: artifactory_token - value: "{{ artifactory_token }}" -{%- endif %} - workspaces: # The generated configuration files # ------------------------------------------------------------------------- diff --git a/src/mas/devops/templates/pipelinerun-backup.yml.j2 b/src/mas/devops/templates/pipelinerun-backup.yml.j2 index d5386710..3019ef70 100644 --- a/src/mas/devops/templates/pipelinerun-backup.yml.j2 +++ b/src/mas/devops/templates/pipelinerun-backup.yml.j2 @@ -17,6 +17,11 @@ spec: persistentVolumeClaim: claimName: backup-pvc params: + # Registry Credentials Secret + # ------------------------------------------------------------------------- + - name: pipeline_registry_secret_name + value: "mas-backup-secrets" + # Common Parameters - name: image_pull_policy value: IfNotPresent @@ -74,16 +79,6 @@ spec: value: "{{ cert_manager_provider }}" {% endif %} - # Development Build Support - {% if artifactory_username is defined and artifactory_username != "" %} - - name: artifactory_username - value: "{{ artifactory_username }}" - {% endif %} - {% if artifactory_token is defined and artifactory_token != "" %} - - name: artifactory_token - value: "{{ artifactory_token }}" - {% endif %} - # Upload Configuration {% if upload_backup is defined and upload_backup != "" %} - name: upload_backup diff --git a/src/mas/devops/templates/pipelinerun-install.yml.j2 b/src/mas/devops/templates/pipelinerun-install.yml.j2 index ca6dd277..eb422e8e 100644 --- a/src/mas/devops/templates/pipelinerun-install.yml.j2 +++ b/src/mas/devops/templates/pipelinerun-install.yml.j2 @@ -19,10 +19,15 @@ spec: pipeline: "0" params: - # IBM Entitlement Key + # Registry Credentials Secret # ------------------------------------------------------------------------- - - name: ibm_entitlement_key - value: "{{ ibm_entitlement_key }}" + - name: pipeline_registry_secret_name +{%- if mas_instance_id is defined and mas_instance_id != "" %} + value: "mas-install-secrets" +{%- else %} + value: "mas-aiservice-install-secrets" +{%- endif %} + {%- if skip_pre_check is defined and skip_pre_check != "" %} # Pipeline config @@ -44,15 +49,6 @@ spec: - name: ocp_ingress_tls_secret_name value: "{{ ocp_ingress_tls_secret_name }}" {%- endif %} -{%- if artifactory_username is defined and artifactory_username != "" %} - - # Enable development catalogs - # ------------------------------------------------------------------------- - - name: artifactory_username - value: "{{ artifactory_username }}" - - name: artifactory_token - value: "{{ artifactory_token }}" -{%- endif %} {%- if ibmcloud_apikey is defined and ibmcloud_resourcegroup != "" %} # IBM Cloud diff --git a/src/mas/devops/templates/pipelinerun-restore.yml.j2 b/src/mas/devops/templates/pipelinerun-restore.yml.j2 index bf5ae6fa..10654533 100644 --- a/src/mas/devops/templates/pipelinerun-restore.yml.j2 +++ b/src/mas/devops/templates/pipelinerun-restore.yml.j2 @@ -20,6 +20,11 @@ spec: secret: secretName: pipeline-restore-configs params: + # Registry Credentials Secret + # ------------------------------------------------------------------------- + - name: pipeline_registry_secret_name + value: "mas-restore-secrets" + # Common Parameters - name: image_pull_policy value: IfNotPresent @@ -99,10 +104,6 @@ spec: - name: dro_contact_lastname value: "{{ dro_contact_lastname }}" {% endif %} - {% if ibm_entitlement_key is defined and ibm_entitlement_key != "" %} - - name: ibm_entitlement_key - value: "{{ ibm_entitlement_key }}" - {% endif %} {% if dro_namespace is defined and dro_namespace != "" %} - name: dro_namespace value: "{{ dro_namespace }}" @@ -148,16 +149,6 @@ spec: value: "{{ cert_manager_provider }}" {% endif %} - # Development Build Support - {% if artifactory_username is defined and artifactory_username != "" %} - - name: artifactory_username - value: "{{ artifactory_username }}" - {% endif %} - {% if artifactory_token is defined and artifactory_token != "" %} - - name: artifactory_token - value: "{{ artifactory_token }}" - {% endif %} - # Download Configuration {% if backup_archive_name is defined and backup_archive_name != "" %} - name: backup_archive_name diff --git a/src/mas/devops/templates/pipelinerun-update.yml.j2 b/src/mas/devops/templates/pipelinerun-update.yml.j2 index 1370379e..2886d644 100644 --- a/src/mas/devops/templates/pipelinerun-update.yml.j2 +++ b/src/mas/devops/templates/pipelinerun-update.yml.j2 @@ -15,6 +15,11 @@ spec: pipeline: "0" params: + # Registry Credentials Secret + # ------------------------------------------------------------------------- + - name: pipeline_registry_secret_name + value: "mas-update-secrets" + {%- if image_pull_policy is defined and image_pull_policy != "" %} # Image Pull Policy @@ -28,19 +33,6 @@ spec: - name: mas_catalog_version value: "{{ mas_catalog_version }}" -{%- if ibm_entitlement_key is defined and ibm_entitlement_key != "" %} - # TODO: What even uses this, nothing in the update pipeline should be using this - - name: ibm_entitlement_key - value: "{{ ibm_entitlement_key }}" -{%- endif %} -{%- if artifactory_username is defined and artifactory_username != "" %} - # Enable development catalogs - # ------------------------------------------------------------------------- - - name: artifactory_username - value: "{{ artifactory_username }}" - - name: artifactory_token - value: "{{ artifactory_token }}" -{%- endif %} {%- if skip_pre_check is defined and skip_pre_check != "" %} # Skip pre-check # ------------------------------------------------------------------------- diff --git a/src/mas/devops/templates/pipelinerun-upgrade.yml.j2 b/src/mas/devops/templates/pipelinerun-upgrade.yml.j2 index 2d451ab9..11780e1e 100644 --- a/src/mas/devops/templates/pipelinerun-upgrade.yml.j2 +++ b/src/mas/devops/templates/pipelinerun-upgrade.yml.j2 @@ -15,6 +15,11 @@ spec: pipeline: "0" params: + # Registry Credentials Secret + # ------------------------------------------------------------------------- + - name: pipeline_registry_secret_name + value: "mas-upgrade-secrets" + {%- if image_pull_policy is defined and image_pull_policy != "" %} # Image Pull Policy @@ -30,26 +35,12 @@ spec: - name: mas_channel value: "{{ mas_channel }}" - # IBM Entitlement Key - # ------------------------------------------------------------------------- - - name: ibm_entitlement_key - value: "{{ ibm_entitlement_key }}" - {%- if skip_pre_check is defined and skip_pre_check != "" %} # Skip pre-check # ------------------------------------------------------------------------- - name: skip_pre_check value: "{{ skip_pre_check }}" {%- endif %} -{%- if artifactory_username is defined and artifactory_username != "" %} - - # Enable development catalogs - # ------------------------------------------------------------------------- - - name: artifactory_username - value: "{{ artifactory_username }}" - - name: artifactory_token - value: "{{ artifactory_token }}" -{%- endif %} {%- if storage_class_rwo is defined and storage_class_rwo != "" %} - name: storage_class_rwo value: "{{ storage_class_rwo }}" diff --git a/test/src/test_data.py b/test/src/test_data.py index 183d7918..c99c76f5 100644 --- a/test/src/test_data.py +++ b/test/src/test_data.py @@ -32,7 +32,7 @@ def test_list_catalogs(): def test_get_newest_catalog_tag(): catalogTag = getNewestCatalogTag("amd64") # Reminder: update this test when adding a new catalog each month! - assert catalogTag == "v9-261007-amd64" + assert catalogTag == "v9-260924-amd64" def test_get_newest_catalog_tag_fail():