diff --git a/.tekton/integration-tests/pipelines/lightspeed-operator-e2e-test-all-features.yaml b/.tekton/integration-tests/pipelines/lightspeed-operator-e2e-test-all-features.yaml index 7d44389e6..63b1d07fc 100644 --- a/.tekton/integration-tests/pipelines/lightspeed-operator-e2e-test-all-features.yaml +++ b/.tekton/integration-tests/pipelines/lightspeed-operator-e2e-test-all-features.yaml @@ -22,71 +22,45 @@ spec: - name: namespace description: 'Namespace to run tests in' default: 'openshift-lightspeed' + - name: openshift-version-prefix + description: 'OpenShift minor version to provision (for example, 4.22).' + default: '4.22' + type: string tasks: - - name: eaas-provision-space + - name: provision-ephemeral-cluster taskRef: resolver: git params: - name: url - value: https://github.com/konflux-ci/build-definitions.git + value: https://github.com/openshift/konflux-tasks - name: revision value: main - name: pathInRepo - value: task/eaas-provision-space/0.1/eaas-provision-space.yaml + value: tasks/provision-ephemeral-cluster/0.1/provision-ephemeral-cluster.yaml params: - - name: ownerKind - value: PipelineRun - name: ownerName value: $(context.pipelineRun.name) - name: ownerUid value: $(context.pipelineRun.uid) - - name: provision-cluster - runAfter: - - eaas-provision-space - taskSpec: - results: - - name: clusterName - value: "$(steps.create-cluster.results.clusterName)" - steps: - - name: pick-version - ref: - resolver: git - params: - - name: url - value: https://github.com/konflux-ci/build-definitions.git - - name: revision - value: main - - name: pathInRepo - value: stepactions/eaas-get-latest-openshift-version-by-prefix/0.1/eaas-get-latest-openshift-version-by-prefix.yaml - params: - - name: prefix - value: "4.19." - - name: create-cluster - ref: - resolver: git - params: - - name: url - value: https://github.com/konflux-ci/build-definitions.git - - name: revision - value: main - - name: pathInRepo - value: stepactions/eaas-create-ephemeral-cluster-hypershift-aws/0.1/eaas-create-ephemeral-cluster-hypershift-aws.yaml - params: - - name: eaasSpaceSecretRef - value: $(tasks.eaas-provision-space.results.secretRef) - - name: version - value: "$(steps.pick-version.results.version)" - - name: instanceType - value: "m5.2xlarge" + - name: workflow + value: hypershift-hostedcluster-workflow + - name: clusterProfile + value: aws-konflux-prod + - name: env + value: '{"COMPUTE_NODE_TYPE": "m5.2xlarge", "HYPERSHIFT_NODE_COUNT": "3", "HOSTED_MANAGEMENT_CLUSTER": "hosted-mgmt2"}' + - name: releases + value: '{"latest":{"release":{"channel":"stable","version":"$(params.openshift-version-prefix)","architecture":"multi"}}}' - name: ols-install description: Task to install bundle onto ephemeral namespace runAfter: - - provision-cluster + - provision-ephemeral-cluster params: - name: SNAPSHOT value: $(params.SNAPSHOT) - name: namespace value: "$(params.namespace)" + - name: clusterCredentialsSecretRef + value: $(tasks.provision-ephemeral-cluster.results.secretRef) taskSpec: results: - name: bundle-image @@ -97,27 +71,13 @@ spec: - name: SNAPSHOT - name: namespace type: string + - name: clusterCredentialsSecretRef + type: string volumes: - - name: credentials - emptyDir: {} + - name: cluster-credentials + secret: + secretName: $(params.clusterCredentialsSecretRef) steps: - - name: get-kubeconfig - ref: - resolver: git - params: - - name: url - value: https://github.com/konflux-ci/build-definitions.git - - name: revision - value: main - - name: pathInRepo - value: stepactions/eaas-get-ephemeral-cluster-credentials/0.1/eaas-get-ephemeral-cluster-credentials.yaml - params: - - name: eaasSpaceSecretRef - value: $(tasks.eaas-provision-space.results.secretRef) - - name: clusterName - value: "$(tasks.provision-cluster.results.clusterName)" - - name: credentials - value: credentials - name: install-operator env: - name: SNAPSHOT @@ -127,9 +87,9 @@ spec: fieldRef: fieldPath: metadata.labels['appstudio.openshift.io/component'] - name: KUBECONFIG - value: "/credentials/$(steps.get-kubeconfig.results.kubeconfig)" + value: "/credentials/kubeconfig" volumeMounts: - - name: credentials + - name: cluster-credentials mountPath: /credentials image: registry.redhat.io/openshift4/ose-cli:latest script: | @@ -175,11 +135,15 @@ spec: params: - name: commit value: $(tasks.ols-install.results.commit) + - name: clusterCredentialsSecretRef + value: $(tasks.provision-ephemeral-cluster.results.secretRef) runAfter: - ols-install taskSpec: params: - name: commit + - name: clusterCredentialsSecretRef + type: string volumes: - name: azure-openai-token secret: @@ -196,29 +160,13 @@ spec: - name: watsonx-token secret: secretName: watsonx-apitoken - - name: credentials - emptyDir: {} + - name: cluster-credentials + secret: + secretName: $(params.clusterCredentialsSecretRef) - name: ols-konflux-artifacts-bot-creds secret: secretName: ols-konflux-artifacts-bot steps: - - name: get-kubeconfig - ref: - resolver: git - params: - - name: url - value: https://github.com/konflux-ci/build-definitions.git - - name: revision - value: main - - name: pathInRepo - value: stepactions/eaas-get-ephemeral-cluster-credentials/0.1/eaas-get-ephemeral-cluster-credentials.yaml - params: - - name: eaasSpaceSecretRef - value: $(tasks.eaas-provision-space.results.secretRef) - - name: clusterName - value: "$(tasks.provision-cluster.results.clusterName)" - - name: credentials - value: credentials - name: run-e2e-tests resources: requests: @@ -237,11 +185,11 @@ spec: mountPath: /var/run/openai - name: watsonx-token mountPath: /var/run/watsonx - - name: credentials + - name: cluster-credentials mountPath: /credentials env: - name: KUBECONFIG - value: "/credentials/$(steps.get-kubeconfig.results.kubeconfig)" + value: "/credentials/kubeconfig" - name: BAM_PROVIDER_KEY_PATH value: "/var/run/bam/token" - name: AZUREOPENAI_PROVIDER_KEY_PATH @@ -291,9 +239,9 @@ spec: value: stepactions/gather-cluster-resources/0.1/gather-cluster-resources.yaml params: - name: credentials - value: "credentials" + value: "cluster-credentials" - name: kubeconfig - value: "$(steps.get-kubeconfig.results.kubeconfig)" + value: "kubeconfig" - name: artifact-dir value: "/workspace/konflux-artifacts" # validate that the cluster resources are available in another tekton step @@ -333,6 +281,21 @@ spec: - name: pathInRepo value: stepactions/fail-if-any-step-failed/0.1/fail-if-any-step-failed.yaml finally: + - name: deprovision-ephemeral-cluster + taskRef: + resolver: git + params: + - name: url + value: https://github.com/openshift/konflux-tasks + - name: revision + value: main + - name: pathInRepo + value: tasks/deprovision-ephemeral-cluster/0.1/deprovision-ephemeral-cluster.yaml + params: + - name: testPlatformClusterClaimName + value: $(tasks.provision-ephemeral-cluster.results.testPlatformClusterClaimName) + - name: testPlatformClusterClaimNamespace + value: $(tasks.provision-ephemeral-cluster.results.testPlatformClusterClaimNamespace) - name: export-logs-for-retention taskRef: resolver: git diff --git a/.tekton/integration-tests/pipelines/lightspeed-operator-e2e-test-pipeline-416.yaml b/.tekton/integration-tests/pipelines/lightspeed-operator-e2e-test-pipeline-416.yaml deleted file mode 100644 index d9dad921a..000000000 --- a/.tekton/integration-tests/pipelines/lightspeed-operator-e2e-test-pipeline-416.yaml +++ /dev/null @@ -1,370 +0,0 @@ ---- -apiVersion: tekton.dev/v1beta1 -kind: Pipeline -metadata: - annotations: - pipelinesascode.tekton.dev/task: "[ols-installer, ols-e2e-task]" - name: ols-integration-tests-pipeline -spec: - description: | - Runs OpenShift Lightspeed operator e2e tests on a Konflux ephemeral OpenShift cluster (EaaS). - Provisions the cluster, installs the operator (OLM bundle or direct/kustomize per install-mode), - runs tests from the snapshot commit, collects artifacts, then deprovisions. - - Per OpenShift minor: set params.openshift-version-prefix (e.g. 4.16.) and params.test-name - (Konflux integration test id). For OpenShift 4.16 only, set params.artifact-oci-tag-prefix to "416" - so pushed artifacts use tag 416; leave artifact-oci-tag-prefix empty for other versions. - params: - - name: SNAPSHOT - description: 'The JSON string representing the snapshot of the application under test.' - default: '{"components": [{"name":"test-app", "containerImage": "quay.io/example/repo:latest"}]}' - type: string - - name: test-name - description: 'The name of the test corresponding to a defined Konflux integration test.' - default: 'ols-e2e-tests-4.16' - type: string - - name: namespace - description: 'Namespace to run tests in' - default: 'openshift-lightspeed' - type: string - - name: openshift-version-prefix - description: 'Minor line prefix for eaas-get-latest-openshift-version-by-prefix (include trailing dot, e.g. 4.19.)' - default: '4.16.' - type: string - - name: artifact-oci-tag-prefix - description: 'Prepended to commit SHA in ols-operator-artifacts Quay tag. Use "416" for OCP 4.16; empty for other minors.' - default: '416' - type: string - - name: install-mode - description: 'Operator install: bundle (OLM) or direct (kustomize; IMG from lightspeed-operator in SNAPSHOT).' - type: string - default: 'bundle' - tasks: - - name: eaas-provision-space - taskRef: - resolver: git - params: - - name: url - value: https://github.com/konflux-ci/build-definitions.git - - name: revision - value: main - - name: pathInRepo - value: task/eaas-provision-space/0.1/eaas-provision-space.yaml - params: - - name: ownerKind - value: PipelineRun - - name: ownerName - value: $(context.pipelineRun.name) - - name: ownerUid - value: $(context.pipelineRun.uid) - - name: provision-cluster - runAfter: - - eaas-provision-space - params: - - name: openshift-version-prefix - value: $(params.openshift-version-prefix) - taskSpec: - params: - - name: openshift-version-prefix - type: string - results: - - name: clusterName - value: "$(steps.create-cluster.results.clusterName)" - steps: - - name: pick-version - ref: - resolver: git - params: - - name: url - value: https://github.com/konflux-ci/build-definitions.git - - name: revision - value: main - - name: pathInRepo - value: stepactions/eaas-get-latest-openshift-version-by-prefix/0.1/eaas-get-latest-openshift-version-by-prefix.yaml - params: - - name: prefix - value: "$(params.openshift-version-prefix)" - - name: create-cluster - ref: - resolver: git - params: - - name: url - value: https://github.com/konflux-ci/build-definitions.git - - name: revision - value: main - - name: pathInRepo - value: stepactions/eaas-create-ephemeral-cluster-hypershift-aws/0.1/eaas-create-ephemeral-cluster-hypershift-aws.yaml - params: - - name: eaasSpaceSecretRef - value: $(tasks.eaas-provision-space.results.secretRef) - - name: version - value: "$(steps.pick-version.results.version)" - - name: instanceType - value: "m5.2xlarge" - - name: ols-install - description: Install operator (OLM bundle or direct); record SNAPSHOT containerImage and commit for downstream tasks. - runAfter: - - provision-cluster - params: - - name: SNAPSHOT - value: $(params.SNAPSHOT) - - name: namespace - value: "$(params.namespace)" - - name: install-mode - value: $(params.install-mode) - taskSpec: - results: - - name: bundle-image - value: "$(steps.get-snapshot-component.results.bundle-image)" - - name: commit - value: "$(steps.get-snapshot-component.results.commit)" - params: - - name: SNAPSHOT - - name: namespace - type: string - - name: install-mode - type: string - default: "bundle" - volumes: - - name: credentials - emptyDir: {} - steps: - - name: get-kubeconfig - ref: - resolver: git - params: - - name: url - value: https://github.com/konflux-ci/build-definitions.git - - name: revision - value: main - - name: pathInRepo - value: stepactions/eaas-get-ephemeral-cluster-credentials/0.1/eaas-get-ephemeral-cluster-credentials.yaml - params: - - name: eaasSpaceSecretRef - value: $(tasks.eaas-provision-space.results.secretRef) - - name: clusterName - value: "$(tasks.provision-cluster.results.clusterName)" - - name: credentials - value: credentials - - name: install-operator - env: - - name: SNAPSHOT - value: $(params.SNAPSHOT) - - name: KONFLUX_COMPONENT_NAME - valueFrom: - fieldRef: - fieldPath: metadata.labels['appstudio.openshift.io/component'] - - name: KUBECONFIG - value: "/credentials/$(steps.get-kubeconfig.results.kubeconfig)" - - name: OLS_NAMESPACE - value: "$(params.namespace)" - volumeMounts: - - name: credentials - mountPath: /credentials - image: registry.redhat.io/openshift4/ose-cli:latest - script: | - set -euo pipefail - dnf -y install jq python3-pip git curl make golang - COMMIT="$(jq -r --arg component_name "${KONFLUX_COMPONENT_NAME}" '.components[] | select(.name == $component_name) | .source.git.revision' <<< "$SNAPSHOT")" - echo "Cloning lightspeed-operator@${COMMIT} for Konflux operator install" - rm -rf /workspace/lightspeed-operator - mkdir -p /workspace/lightspeed-operator - cd /workspace/lightspeed-operator - git init -q - git remote add origin https://github.com/openshift/lightspeed-operator.git - git fetch --depth 1 origin "${COMMIT}" - git checkout -q FETCH_HEAD - ./.tekton/integration-tests/scripts/run-konflux-operator-install.sh "$(params.install-mode)" - - name: get-snapshot-component - image: registry.redhat.io/openshift4/ose-cli:latest - env: - - name: SNAPSHOT - value: $(params.SNAPSHOT) - - name: KONFLUX_COMPONENT_NAME - valueFrom: - fieldRef: - fieldPath: metadata.labels['appstudio.openshift.io/component'] - results: - - name: bundle-image - type: string - description: "SNAPSHOT containerImage for the PipelineRun-labeled Konflux component (bundle or operator manager image)." - - name: commit - type: string - description: "commit sha to be used to store artifacts" - script: | - dnf -y install jq - echo -n "$(jq -r --arg component_name "${KONFLUX_COMPONENT_NAME}" '.components[] | select(.name == $component_name) | .containerImage' <<< "$SNAPSHOT")" > $(step.results.bundle-image.path) - echo -n "$(jq -r --arg component_name "${KONFLUX_COMPONENT_NAME}" '.components[] | select(.name == $component_name) | .source.git.revision' <<< "$SNAPSHOT")" > $(step.results.commit.path) - - name: ols-operator-tests - description: Task to run tests from operator repository - params: - - name: commit - value: $(tasks.ols-install.results.commit) - - name: artifact-oci-tag-prefix - value: $(params.artifact-oci-tag-prefix) - runAfter: - - ols-install - taskSpec: - params: - - name: commit - - name: artifact-oci-tag-prefix - type: string - default: "" - volumes: - - name: azure-openai-token - secret: - secretName: azureopenai-apitoken - - name: azureopenai-entra-id - secret: - secretName: azureopenai-entra-id - - name: bam-token - secret: - secretName: bam-apitoken - - name: openai-token - secret: - secretName: openai - - name: watsonx-token - secret: - secretName: watsonx-apitoken - - name: credentials - emptyDir: {} - - name: ols-konflux-artifacts-bot-creds - secret: - secretName: ols-konflux-artifacts-bot - steps: - - name: get-kubeconfig - ref: - resolver: git - params: - - name: url - value: https://github.com/konflux-ci/build-definitions.git - - name: revision - value: main - - name: pathInRepo - value: stepactions/eaas-get-ephemeral-cluster-credentials/0.1/eaas-get-ephemeral-cluster-credentials.yaml - params: - - name: eaasSpaceSecretRef - value: $(tasks.eaas-provision-space.results.secretRef) - - name: clusterName - value: "$(tasks.provision-cluster.results.clusterName)" - - name: credentials - value: credentials - - name: run-e2e-tests - resources: - requests: - memory: "8Gi" - limits: - memory: "8Gi" - onError: continue - volumeMounts: - - name: azure-openai-token - mountPath: /var/run/azure_openai - - name: azureopenai-entra-id - mountPath: /var/run/azureopenai-entra-id - - name: bam-token - mountPath: /var/run/bam - - name: openai-token - mountPath: /var/run/openai - - name: watsonx-token - mountPath: /var/run/watsonx - - name: credentials - mountPath: /credentials - env: - - name: KUBECONFIG - value: "/credentials/$(steps.get-kubeconfig.results.kubeconfig)" - - name: BAM_PROVIDER_KEY_PATH - value: "/var/run/bam/token" - - name: AZUREOPENAI_PROVIDER_KEY_PATH - value: "/var/run/azure_openai/token" - - name: OPENAI_PROVIDER_KEY_PATH - value: "/var/run/openai/token" - - name: WATSONX_PROVIDER_KEY_PATH - value: "/var/run/watsonx/token" - - name: COMMIT_SHA - value: "$(params.commit)" - - name: ARTIFACT_DIR - value: "/workspace" - image: registry.redhat.io/openshift4/ose-cli:latest - script: | - dnf -y install git make golang jq gpgme-devel - git init lightspeed-operator - cd lightspeed-operator - git remote add origin https://github.com/openshift/lightspeed-operator.git - git fetch --depth=1 --filter=blob:none origin ${COMMIT_SHA} - git show "${COMMIT_SHA}:.tekton/integration-tests/scripts/run-operator-e2e-tests.sh" | bash -s -- "latest-4.16" - - name: gather-cluster-resources - onError: continue - ref: - resolver: git - params: - - name: url - value: https://github.com/openshift/lightspeed-operator - - name: revision - value: $(params.commit) - - name: pathInRepo - value: .tekton/integration-tests/stepactions/gather-cluster-resources/0.1/gather-cluster-resources.yaml - params: - - name: credentials - value: "credentials" - - name: kubeconfig - value: "$(steps.get-kubeconfig.results.kubeconfig)" - - name: artifact-dir - value: "/workspace/konflux-artifacts" - - name: gather-script-url - value: "https://raw.githubusercontent.com/openshift/lightspeed-operator/$(params.commit)/.tekton/integration-tests/scripts/gather-extra.sh" - # validate that the cluster resources are available in another tekton step - - name: list-artifacts - onError: continue - image: quay.io/konflux-qe-incubator/konflux-qe-tools:latest - workingDir: "/workspace" - script: | - #!/bin/bash - ls -la /workspace - - name: push-artifacts - onError: continue - ref: - resolver: git - params: - - name: url - value: https://github.com/konflux-ci/tekton-integration-catalog.git - - name: revision - value: main - - name: pathInRepo - value: stepactions/secure-push-oci/0.1/secure-push-oci.yaml - params: - - name: workdir-path - value: /workspace - - name: oci-ref - value: "quay.io/openshift-lightspeed/ols-operator-artifacts:$(params.artifact-oci-tag-prefix)$(params.commit)" - - name: credentials-volume-name - value: ols-konflux-artifacts-bot-creds - - name: fail-if-any-step-failed - ref: - resolver: git - params: - - name: url - value: https://github.com/konflux-ci/tekton-integration-catalog.git - - name: revision - value: main - - name: pathInRepo - value: stepactions/fail-if-any-step-failed/0.1/fail-if-any-step-failed.yaml - finally: - - name: export-logs-for-retention - taskRef: - resolver: git - params: - - name: url - value: https://github.com/konflux-ci/tekton-integration-catalog.git - - name: revision - value: main - - name: pathInRepo - value: tasks/export-logs/0.1/export-logs-to-quay.yaml - params: - - name: pipeline-run-name - value: $(context.pipelineRun.name) - - name: namespace - value: $(context.pipelineRun.namespace) - - name: quay-repo - value: "quay.io/openshift-lightspeed/ols-operator-artifacts" - - name: artifact-credentials-secret - value: ols-konflux-artifacts-bot diff --git a/.tekton/integration-tests/pipelines/lightspeed-operator-e2e-test-pipeline-417.yaml b/.tekton/integration-tests/pipelines/lightspeed-operator-e2e-test-pipeline-417.yaml deleted file mode 100644 index 0a431c5a5..000000000 --- a/.tekton/integration-tests/pipelines/lightspeed-operator-e2e-test-pipeline-417.yaml +++ /dev/null @@ -1,370 +0,0 @@ ---- -apiVersion: tekton.dev/v1beta1 -kind: Pipeline -metadata: - annotations: - pipelinesascode.tekton.dev/task: "[ols-installer, ols-e2e-task]" - name: ols-integration-tests-pipeline -spec: - description: | - Runs OpenShift Lightspeed operator e2e tests on a Konflux ephemeral OpenShift cluster (EaaS). - Provisions the cluster, installs the operator (OLM bundle or direct/kustomize per install-mode), - runs tests from the snapshot commit, collects artifacts, then deprovisions. - - Per OpenShift minor: set params.openshift-version-prefix (e.g. 4.16.) and params.test-name - (Konflux integration test id). For OpenShift 4.16 only, set params.artifact-oci-tag-prefix to "416" - so pushed artifacts use tag 416; leave artifact-oci-tag-prefix empty for other versions. - params: - - name: SNAPSHOT - description: 'The JSON string representing the snapshot of the application under test.' - default: '{"components": [{"name":"test-app", "containerImage": "quay.io/example/repo:latest"}]}' - type: string - - name: test-name - description: 'The name of the test corresponding to a defined Konflux integration test.' - default: 'ols-e2e-tests-4.19' - type: string - - name: namespace - description: 'Namespace to run tests in' - default: 'openshift-lightspeed' - type: string - - name: openshift-version-prefix - description: 'Minor line prefix for eaas-get-latest-openshift-version-by-prefix (include trailing dot, e.g. 4.19.)' - default: '4.19.' - type: string - - name: artifact-oci-tag-prefix - description: 'Prepended to commit SHA in ols-operator-artifacts Quay tag. Use "416" for OCP 4.16; empty for other minors.' - default: '' - type: string - - name: install-mode - description: 'Operator install: bundle (OLM) or direct (kustomize; IMG from lightspeed-operator in SNAPSHOT).' - type: string - default: 'bundle' - tasks: - - name: eaas-provision-space - taskRef: - resolver: git - params: - - name: url - value: https://github.com/konflux-ci/build-definitions.git - - name: revision - value: main - - name: pathInRepo - value: task/eaas-provision-space/0.1/eaas-provision-space.yaml - params: - - name: ownerKind - value: PipelineRun - - name: ownerName - value: $(context.pipelineRun.name) - - name: ownerUid - value: $(context.pipelineRun.uid) - - name: provision-cluster - runAfter: - - eaas-provision-space - params: - - name: openshift-version-prefix - value: $(params.openshift-version-prefix) - taskSpec: - params: - - name: openshift-version-prefix - type: string - results: - - name: clusterName - value: "$(steps.create-cluster.results.clusterName)" - steps: - - name: pick-version - ref: - resolver: git - params: - - name: url - value: https://github.com/konflux-ci/build-definitions.git - - name: revision - value: main - - name: pathInRepo - value: stepactions/eaas-get-latest-openshift-version-by-prefix/0.1/eaas-get-latest-openshift-version-by-prefix.yaml - params: - - name: prefix - value: "$(params.openshift-version-prefix)" - - name: create-cluster - ref: - resolver: git - params: - - name: url - value: https://github.com/konflux-ci/build-definitions.git - - name: revision - value: main - - name: pathInRepo - value: stepactions/eaas-create-ephemeral-cluster-hypershift-aws/0.1/eaas-create-ephemeral-cluster-hypershift-aws.yaml - params: - - name: eaasSpaceSecretRef - value: $(tasks.eaas-provision-space.results.secretRef) - - name: version - value: "$(steps.pick-version.results.version)" - - name: instanceType - value: "m5.2xlarge" - - name: ols-install - description: Install operator (OLM bundle or direct); record SNAPSHOT containerImage and commit for downstream tasks. - runAfter: - - provision-cluster - params: - - name: SNAPSHOT - value: $(params.SNAPSHOT) - - name: namespace - value: "$(params.namespace)" - - name: install-mode - value: $(params.install-mode) - taskSpec: - results: - - name: bundle-image - value: "$(steps.get-snapshot-component.results.bundle-image)" - - name: commit - value: "$(steps.get-snapshot-component.results.commit)" - params: - - name: SNAPSHOT - - name: namespace - type: string - - name: install-mode - type: string - default: "bundle" - volumes: - - name: credentials - emptyDir: {} - steps: - - name: get-kubeconfig - ref: - resolver: git - params: - - name: url - value: https://github.com/konflux-ci/build-definitions.git - - name: revision - value: main - - name: pathInRepo - value: stepactions/eaas-get-ephemeral-cluster-credentials/0.1/eaas-get-ephemeral-cluster-credentials.yaml - params: - - name: eaasSpaceSecretRef - value: $(tasks.eaas-provision-space.results.secretRef) - - name: clusterName - value: "$(tasks.provision-cluster.results.clusterName)" - - name: credentials - value: credentials - - name: install-operator - env: - - name: SNAPSHOT - value: $(params.SNAPSHOT) - - name: KONFLUX_COMPONENT_NAME - valueFrom: - fieldRef: - fieldPath: metadata.labels['appstudio.openshift.io/component'] - - name: KUBECONFIG - value: "/credentials/$(steps.get-kubeconfig.results.kubeconfig)" - - name: OLS_NAMESPACE - value: "$(params.namespace)" - volumeMounts: - - name: credentials - mountPath: /credentials - image: registry.redhat.io/openshift4/ose-cli:latest - script: | - set -euo pipefail - dnf -y install jq python3-pip git curl make golang - COMMIT="$(jq -r --arg component_name "${KONFLUX_COMPONENT_NAME}" '.components[] | select(.name == $component_name) | .source.git.revision' <<< "$SNAPSHOT")" - echo "Cloning lightspeed-operator@${COMMIT} for Konflux operator install" - rm -rf /workspace/lightspeed-operator - mkdir -p /workspace/lightspeed-operator - cd /workspace/lightspeed-operator - git init -q - git remote add origin https://github.com/openshift/lightspeed-operator.git - git fetch --depth 1 origin "${COMMIT}" - git checkout -q FETCH_HEAD - ./.tekton/integration-tests/scripts/run-konflux-operator-install.sh "$(params.install-mode)" - - name: get-snapshot-component - image: registry.redhat.io/openshift4/ose-cli:latest - env: - - name: SNAPSHOT - value: $(params.SNAPSHOT) - - name: KONFLUX_COMPONENT_NAME - valueFrom: - fieldRef: - fieldPath: metadata.labels['appstudio.openshift.io/component'] - results: - - name: bundle-image - type: string - description: "SNAPSHOT containerImage for the PipelineRun-labeled Konflux component (bundle or operator manager image)." - - name: commit - type: string - description: "commit sha to be used to store artifacts" - script: | - dnf -y install jq - echo -n "$(jq -r --arg component_name "${KONFLUX_COMPONENT_NAME}" '.components[] | select(.name == $component_name) | .containerImage' <<< "$SNAPSHOT")" > $(step.results.bundle-image.path) - echo -n "$(jq -r --arg component_name "${KONFLUX_COMPONENT_NAME}" '.components[] | select(.name == $component_name) | .source.git.revision' <<< "$SNAPSHOT")" > $(step.results.commit.path) - - name: ols-operator-tests - description: Task to run tests from operator repository - params: - - name: commit - value: $(tasks.ols-install.results.commit) - - name: artifact-oci-tag-prefix - value: $(params.artifact-oci-tag-prefix) - runAfter: - - ols-install - taskSpec: - params: - - name: commit - - name: artifact-oci-tag-prefix - type: string - default: "" - volumes: - - name: azure-openai-token - secret: - secretName: azureopenai-apitoken - - name: azureopenai-entra-id - secret: - secretName: azureopenai-entra-id - - name: bam-token - secret: - secretName: bam-apitoken - - name: openai-token - secret: - secretName: openai - - name: watsonx-token - secret: - secretName: watsonx-apitoken - - name: credentials - emptyDir: {} - - name: ols-konflux-artifacts-bot-creds - secret: - secretName: ols-konflux-artifacts-bot - steps: - - name: get-kubeconfig - ref: - resolver: git - params: - - name: url - value: https://github.com/konflux-ci/build-definitions.git - - name: revision - value: main - - name: pathInRepo - value: stepactions/eaas-get-ephemeral-cluster-credentials/0.1/eaas-get-ephemeral-cluster-credentials.yaml - params: - - name: eaasSpaceSecretRef - value: $(tasks.eaas-provision-space.results.secretRef) - - name: clusterName - value: "$(tasks.provision-cluster.results.clusterName)" - - name: credentials - value: credentials - - name: run-e2e-tests - resources: - requests: - memory: "8Gi" - limits: - memory: "8Gi" - onError: continue - volumeMounts: - - name: azure-openai-token - mountPath: /var/run/azure_openai - - name: azureopenai-entra-id - mountPath: /var/run/azureopenai-entra-id - - name: bam-token - mountPath: /var/run/bam - - name: openai-token - mountPath: /var/run/openai - - name: watsonx-token - mountPath: /var/run/watsonx - - name: credentials - mountPath: /credentials - env: - - name: KUBECONFIG - value: "/credentials/$(steps.get-kubeconfig.results.kubeconfig)" - - name: BAM_PROVIDER_KEY_PATH - value: "/var/run/bam/token" - - name: AZUREOPENAI_PROVIDER_KEY_PATH - value: "/var/run/azure_openai/token" - - name: OPENAI_PROVIDER_KEY_PATH - value: "/var/run/openai/token" - - name: WATSONX_PROVIDER_KEY_PATH - value: "/var/run/watsonx/token" - - name: COMMIT_SHA - value: "$(params.commit)" - - name: ARTIFACT_DIR - value: "/workspace" - image: registry.redhat.io/openshift4/ose-cli:latest - script: | - dnf -y install git make golang jq gpgme-devel - git init lightspeed-operator - cd lightspeed-operator - git remote add origin https://github.com/openshift/lightspeed-operator.git - git fetch --depth=1 --filter=blob:none origin ${COMMIT_SHA} - git show "${COMMIT_SHA}:.tekton/integration-tests/scripts/run-operator-e2e-tests.sh" | bash -s -- "latest-4.17" - - name: gather-cluster-resources - onError: continue - ref: - resolver: git - params: - - name: url - value: https://github.com/openshift/lightspeed-operator - - name: revision - value: $(params.commit) - - name: pathInRepo - value: .tekton/integration-tests/stepactions/gather-cluster-resources/0.1/gather-cluster-resources.yaml - params: - - name: credentials - value: "credentials" - - name: kubeconfig - value: "$(steps.get-kubeconfig.results.kubeconfig)" - - name: artifact-dir - value: "/workspace/konflux-artifacts" - - name: gather-script-url - value: "https://raw.githubusercontent.com/openshift/lightspeed-operator/$(params.commit)/.tekton/integration-tests/scripts/gather-extra.sh" - # validate that the cluster resources are available in another tekton step - - name: list-artifacts - onError: continue - image: quay.io/konflux-qe-incubator/konflux-qe-tools:latest - workingDir: "/workspace" - script: | - #!/bin/bash - ls -la /workspace - - name: push-artifacts - onError: continue - ref: - resolver: git - params: - - name: url - value: https://github.com/konflux-ci/tekton-integration-catalog.git - - name: revision - value: main - - name: pathInRepo - value: stepactions/secure-push-oci/0.1/secure-push-oci.yaml - params: - - name: workdir-path - value: /workspace - - name: oci-ref - value: "quay.io/openshift-lightspeed/ols-operator-artifacts:$(params.artifact-oci-tag-prefix)$(params.commit)" - - name: credentials-volume-name - value: ols-konflux-artifacts-bot-creds - - name: fail-if-any-step-failed - ref: - resolver: git - params: - - name: url - value: https://github.com/konflux-ci/tekton-integration-catalog.git - - name: revision - value: main - - name: pathInRepo - value: stepactions/fail-if-any-step-failed/0.1/fail-if-any-step-failed.yaml - finally: - - name: export-logs-for-retention - taskRef: - resolver: git - params: - - name: url - value: https://github.com/konflux-ci/tekton-integration-catalog.git - - name: revision - value: main - - name: pathInRepo - value: tasks/export-logs/0.1/export-logs-to-quay.yaml - params: - - name: pipeline-run-name - value: $(context.pipelineRun.name) - - name: namespace - value: $(context.pipelineRun.namespace) - - name: quay-repo - value: "quay.io/openshift-lightspeed/ols-operator-artifacts" - - name: artifact-credentials-secret - value: ols-konflux-artifacts-bot diff --git a/.tekton/integration-tests/pipelines/lightspeed-operator-e2e-test-pipeline-418.yaml b/.tekton/integration-tests/pipelines/lightspeed-operator-e2e-test-pipeline-418.yaml deleted file mode 100644 index 3f24feaf5..000000000 --- a/.tekton/integration-tests/pipelines/lightspeed-operator-e2e-test-pipeline-418.yaml +++ /dev/null @@ -1,370 +0,0 @@ ---- -apiVersion: tekton.dev/v1beta1 -kind: Pipeline -metadata: - annotations: - pipelinesascode.tekton.dev/task: "[ols-installer, ols-e2e-task]" - name: ols-integration-tests-pipeline -spec: - description: | - Runs OpenShift Lightspeed operator e2e tests on a Konflux ephemeral OpenShift cluster (EaaS). - Provisions the cluster, installs the operator (OLM bundle or direct/kustomize per install-mode), - runs tests from the snapshot commit, collects artifacts, then deprovisions. - - Per OpenShift minor: set params.openshift-version-prefix (e.g. 4.16.) and params.test-name - (Konflux integration test id). For OpenShift 4.16 only, set params.artifact-oci-tag-prefix to "416" - so pushed artifacts use tag 416; leave artifact-oci-tag-prefix empty for other versions. - params: - - name: SNAPSHOT - description: 'The JSON string representing the snapshot of the application under test.' - default: '{"components": [{"name":"test-app", "containerImage": "quay.io/example/repo:latest"}]}' - type: string - - name: test-name - description: 'The name of the test corresponding to a defined Konflux integration test.' - default: 'ols-e2e-tests-4.19' - type: string - - name: namespace - description: 'Namespace to run tests in' - default: 'openshift-lightspeed' - type: string - - name: openshift-version-prefix - description: 'Minor line prefix for eaas-get-latest-openshift-version-by-prefix (include trailing dot, e.g. 4.19.)' - default: '4.19.' - type: string - - name: artifact-oci-tag-prefix - description: 'Prepended to commit SHA in ols-operator-artifacts Quay tag. Use "416" for OCP 4.16; empty for other minors.' - default: '' - type: string - - name: install-mode - description: 'Operator install: bundle (OLM) or direct (kustomize; IMG from lightspeed-operator in SNAPSHOT).' - type: string - default: 'bundle' - tasks: - - name: eaas-provision-space - taskRef: - resolver: git - params: - - name: url - value: https://github.com/konflux-ci/build-definitions.git - - name: revision - value: main - - name: pathInRepo - value: task/eaas-provision-space/0.1/eaas-provision-space.yaml - params: - - name: ownerKind - value: PipelineRun - - name: ownerName - value: $(context.pipelineRun.name) - - name: ownerUid - value: $(context.pipelineRun.uid) - - name: provision-cluster - runAfter: - - eaas-provision-space - params: - - name: openshift-version-prefix - value: $(params.openshift-version-prefix) - taskSpec: - params: - - name: openshift-version-prefix - type: string - results: - - name: clusterName - value: "$(steps.create-cluster.results.clusterName)" - steps: - - name: pick-version - ref: - resolver: git - params: - - name: url - value: https://github.com/konflux-ci/build-definitions.git - - name: revision - value: main - - name: pathInRepo - value: stepactions/eaas-get-latest-openshift-version-by-prefix/0.1/eaas-get-latest-openshift-version-by-prefix.yaml - params: - - name: prefix - value: "$(params.openshift-version-prefix)" - - name: create-cluster - ref: - resolver: git - params: - - name: url - value: https://github.com/konflux-ci/build-definitions.git - - name: revision - value: main - - name: pathInRepo - value: stepactions/eaas-create-ephemeral-cluster-hypershift-aws/0.1/eaas-create-ephemeral-cluster-hypershift-aws.yaml - params: - - name: eaasSpaceSecretRef - value: $(tasks.eaas-provision-space.results.secretRef) - - name: version - value: "$(steps.pick-version.results.version)" - - name: instanceType - value: "m5.2xlarge" - - name: ols-install - description: Install operator (OLM bundle or direct); record SNAPSHOT containerImage and commit for downstream tasks. - runAfter: - - provision-cluster - params: - - name: SNAPSHOT - value: $(params.SNAPSHOT) - - name: namespace - value: "$(params.namespace)" - - name: install-mode - value: $(params.install-mode) - taskSpec: - results: - - name: bundle-image - value: "$(steps.get-snapshot-component.results.bundle-image)" - - name: commit - value: "$(steps.get-snapshot-component.results.commit)" - params: - - name: SNAPSHOT - - name: namespace - type: string - - name: install-mode - type: string - default: "bundle" - volumes: - - name: credentials - emptyDir: {} - steps: - - name: get-kubeconfig - ref: - resolver: git - params: - - name: url - value: https://github.com/konflux-ci/build-definitions.git - - name: revision - value: main - - name: pathInRepo - value: stepactions/eaas-get-ephemeral-cluster-credentials/0.1/eaas-get-ephemeral-cluster-credentials.yaml - params: - - name: eaasSpaceSecretRef - value: $(tasks.eaas-provision-space.results.secretRef) - - name: clusterName - value: "$(tasks.provision-cluster.results.clusterName)" - - name: credentials - value: credentials - - name: install-operator - env: - - name: SNAPSHOT - value: $(params.SNAPSHOT) - - name: KONFLUX_COMPONENT_NAME - valueFrom: - fieldRef: - fieldPath: metadata.labels['appstudio.openshift.io/component'] - - name: KUBECONFIG - value: "/credentials/$(steps.get-kubeconfig.results.kubeconfig)" - - name: OLS_NAMESPACE - value: "$(params.namespace)" - volumeMounts: - - name: credentials - mountPath: /credentials - image: registry.redhat.io/openshift4/ose-cli:latest - script: | - set -euo pipefail - dnf -y install jq python3-pip git curl make golang - COMMIT="$(jq -r --arg component_name "${KONFLUX_COMPONENT_NAME}" '.components[] | select(.name == $component_name) | .source.git.revision' <<< "$SNAPSHOT")" - echo "Cloning lightspeed-operator@${COMMIT} for Konflux operator install" - rm -rf /workspace/lightspeed-operator - mkdir -p /workspace/lightspeed-operator - cd /workspace/lightspeed-operator - git init -q - git remote add origin https://github.com/openshift/lightspeed-operator.git - git fetch --depth 1 origin "${COMMIT}" - git checkout -q FETCH_HEAD - ./.tekton/integration-tests/scripts/run-konflux-operator-install.sh "$(params.install-mode)" - - name: get-snapshot-component - image: registry.redhat.io/openshift4/ose-cli:latest - env: - - name: SNAPSHOT - value: $(params.SNAPSHOT) - - name: KONFLUX_COMPONENT_NAME - valueFrom: - fieldRef: - fieldPath: metadata.labels['appstudio.openshift.io/component'] - results: - - name: bundle-image - type: string - description: "SNAPSHOT containerImage for the PipelineRun-labeled Konflux component (bundle or operator manager image)." - - name: commit - type: string - description: "commit sha to be used to store artifacts" - script: | - dnf -y install jq - echo -n "$(jq -r --arg component_name "${KONFLUX_COMPONENT_NAME}" '.components[] | select(.name == $component_name) | .containerImage' <<< "$SNAPSHOT")" > $(step.results.bundle-image.path) - echo -n "$(jq -r --arg component_name "${KONFLUX_COMPONENT_NAME}" '.components[] | select(.name == $component_name) | .source.git.revision' <<< "$SNAPSHOT")" > $(step.results.commit.path) - - name: ols-operator-tests - description: Task to run tests from operator repository - params: - - name: commit - value: $(tasks.ols-install.results.commit) - - name: artifact-oci-tag-prefix - value: $(params.artifact-oci-tag-prefix) - runAfter: - - ols-install - taskSpec: - params: - - name: commit - - name: artifact-oci-tag-prefix - type: string - default: "" - volumes: - - name: azure-openai-token - secret: - secretName: azureopenai-apitoken - - name: azureopenai-entra-id - secret: - secretName: azureopenai-entra-id - - name: bam-token - secret: - secretName: bam-apitoken - - name: openai-token - secret: - secretName: openai - - name: watsonx-token - secret: - secretName: watsonx-apitoken - - name: credentials - emptyDir: {} - - name: ols-konflux-artifacts-bot-creds - secret: - secretName: ols-konflux-artifacts-bot - steps: - - name: get-kubeconfig - ref: - resolver: git - params: - - name: url - value: https://github.com/konflux-ci/build-definitions.git - - name: revision - value: main - - name: pathInRepo - value: stepactions/eaas-get-ephemeral-cluster-credentials/0.1/eaas-get-ephemeral-cluster-credentials.yaml - params: - - name: eaasSpaceSecretRef - value: $(tasks.eaas-provision-space.results.secretRef) - - name: clusterName - value: "$(tasks.provision-cluster.results.clusterName)" - - name: credentials - value: credentials - - name: run-e2e-tests - resources: - requests: - memory: "8Gi" - limits: - memory: "8Gi" - onError: continue - volumeMounts: - - name: azure-openai-token - mountPath: /var/run/azure_openai - - name: azureopenai-entra-id - mountPath: /var/run/azureopenai-entra-id - - name: bam-token - mountPath: /var/run/bam - - name: openai-token - mountPath: /var/run/openai - - name: watsonx-token - mountPath: /var/run/watsonx - - name: credentials - mountPath: /credentials - env: - - name: KUBECONFIG - value: "/credentials/$(steps.get-kubeconfig.results.kubeconfig)" - - name: BAM_PROVIDER_KEY_PATH - value: "/var/run/bam/token" - - name: AZUREOPENAI_PROVIDER_KEY_PATH - value: "/var/run/azure_openai/token" - - name: OPENAI_PROVIDER_KEY_PATH - value: "/var/run/openai/token" - - name: WATSONX_PROVIDER_KEY_PATH - value: "/var/run/watsonx/token" - - name: COMMIT_SHA - value: "$(params.commit)" - - name: ARTIFACT_DIR - value: "/workspace" - image: registry.redhat.io/openshift4/ose-cli:latest - script: | - dnf -y install git make golang jq gpgme-devel - git init lightspeed-operator - cd lightspeed-operator - git remote add origin https://github.com/openshift/lightspeed-operator.git - git fetch --depth=1 --filter=blob:none origin ${COMMIT_SHA} - git show "${COMMIT_SHA}:.tekton/integration-tests/scripts/run-operator-e2e-tests.sh" | bash -s -- "latest-4.18" - - name: gather-cluster-resources - onError: continue - ref: - resolver: git - params: - - name: url - value: https://github.com/openshift/lightspeed-operator - - name: revision - value: $(params.commit) - - name: pathInRepo - value: .tekton/integration-tests/stepactions/gather-cluster-resources/0.1/gather-cluster-resources.yaml - params: - - name: credentials - value: "credentials" - - name: kubeconfig - value: "$(steps.get-kubeconfig.results.kubeconfig)" - - name: artifact-dir - value: "/workspace/konflux-artifacts" - - name: gather-script-url - value: "https://raw.githubusercontent.com/openshift/lightspeed-operator/$(params.commit)/.tekton/integration-tests/scripts/gather-extra.sh" - # validate that the cluster resources are available in another tekton step - - name: list-artifacts - onError: continue - image: quay.io/konflux-qe-incubator/konflux-qe-tools:latest - workingDir: "/workspace" - script: | - #!/bin/bash - ls -la /workspace - - name: push-artifacts - onError: continue - ref: - resolver: git - params: - - name: url - value: https://github.com/konflux-ci/tekton-integration-catalog.git - - name: revision - value: main - - name: pathInRepo - value: stepactions/secure-push-oci/0.1/secure-push-oci.yaml - params: - - name: workdir-path - value: /workspace - - name: oci-ref - value: "quay.io/openshift-lightspeed/ols-operator-artifacts:$(params.artifact-oci-tag-prefix)$(params.commit)" - - name: credentials-volume-name - value: ols-konflux-artifacts-bot-creds - - name: fail-if-any-step-failed - ref: - resolver: git - params: - - name: url - value: https://github.com/konflux-ci/tekton-integration-catalog.git - - name: revision - value: main - - name: pathInRepo - value: stepactions/fail-if-any-step-failed/0.1/fail-if-any-step-failed.yaml - finally: - - name: export-logs-for-retention - taskRef: - resolver: git - params: - - name: url - value: https://github.com/konflux-ci/tekton-integration-catalog.git - - name: revision - value: main - - name: pathInRepo - value: tasks/export-logs/0.1/export-logs-to-quay.yaml - params: - - name: pipeline-run-name - value: $(context.pipelineRun.name) - - name: namespace - value: $(context.pipelineRun.namespace) - - name: quay-repo - value: "quay.io/openshift-lightspeed/ols-operator-artifacts" - - name: artifact-credentials-secret - value: ols-konflux-artifacts-bot diff --git a/.tekton/integration-tests/pipelines/lightspeed-operator-e2e-test-pipeline-419.yaml b/.tekton/integration-tests/pipelines/lightspeed-operator-e2e-test-pipeline-419.yaml deleted file mode 100644 index e83e85ddc..000000000 --- a/.tekton/integration-tests/pipelines/lightspeed-operator-e2e-test-pipeline-419.yaml +++ /dev/null @@ -1,370 +0,0 @@ ---- -apiVersion: tekton.dev/v1beta1 -kind: Pipeline -metadata: - annotations: - pipelinesascode.tekton.dev/task: "[ols-installer, ols-e2e-task]" - name: ols-integration-tests-pipeline -spec: - description: | - Runs OpenShift Lightspeed operator e2e tests on a Konflux ephemeral OpenShift cluster (EaaS). - Provisions the cluster, installs the operator (OLM bundle or direct/kustomize per install-mode), - runs tests from the snapshot commit, collects artifacts, then deprovisions. - - Per OpenShift minor: set params.openshift-version-prefix (e.g. 4.16.) and params.test-name - (Konflux integration test id). For OpenShift 4.16 only, set params.artifact-oci-tag-prefix to "416" - so pushed artifacts use tag 416; leave artifact-oci-tag-prefix empty for other versions. - params: - - name: SNAPSHOT - description: 'The JSON string representing the snapshot of the application under test.' - default: '{"components": [{"name":"test-app", "containerImage": "quay.io/example/repo:latest"}]}' - type: string - - name: test-name - description: 'The name of the test corresponding to a defined Konflux integration test.' - default: 'ols-e2e-tests-4.19' - type: string - - name: namespace - description: 'Namespace to run tests in' - default: 'openshift-lightspeed' - type: string - - name: openshift-version-prefix - description: 'Minor line prefix for eaas-get-latest-openshift-version-by-prefix (include trailing dot, e.g. 4.19.)' - default: '4.19.' - type: string - - name: artifact-oci-tag-prefix - description: 'Prepended to commit SHA in ols-operator-artifacts Quay tag. Use "416" for OCP 4.16; empty for other minors.' - default: '' - type: string - - name: install-mode - description: 'Operator install: bundle (OLM) or direct (kustomize; IMG from lightspeed-operator in SNAPSHOT).' - type: string - default: 'bundle' - tasks: - - name: eaas-provision-space - taskRef: - resolver: git - params: - - name: url - value: https://github.com/konflux-ci/build-definitions.git - - name: revision - value: main - - name: pathInRepo - value: task/eaas-provision-space/0.1/eaas-provision-space.yaml - params: - - name: ownerKind - value: PipelineRun - - name: ownerName - value: $(context.pipelineRun.name) - - name: ownerUid - value: $(context.pipelineRun.uid) - - name: provision-cluster - runAfter: - - eaas-provision-space - params: - - name: openshift-version-prefix - value: $(params.openshift-version-prefix) - taskSpec: - params: - - name: openshift-version-prefix - type: string - results: - - name: clusterName - value: "$(steps.create-cluster.results.clusterName)" - steps: - - name: pick-version - ref: - resolver: git - params: - - name: url - value: https://github.com/konflux-ci/build-definitions.git - - name: revision - value: main - - name: pathInRepo - value: stepactions/eaas-get-latest-openshift-version-by-prefix/0.1/eaas-get-latest-openshift-version-by-prefix.yaml - params: - - name: prefix - value: "$(params.openshift-version-prefix)" - - name: create-cluster - ref: - resolver: git - params: - - name: url - value: https://github.com/konflux-ci/build-definitions.git - - name: revision - value: main - - name: pathInRepo - value: stepactions/eaas-create-ephemeral-cluster-hypershift-aws/0.1/eaas-create-ephemeral-cluster-hypershift-aws.yaml - params: - - name: eaasSpaceSecretRef - value: $(tasks.eaas-provision-space.results.secretRef) - - name: version - value: "$(steps.pick-version.results.version)" - - name: instanceType - value: "m5.2xlarge" - - name: ols-install - description: Install operator (OLM bundle or direct); record SNAPSHOT containerImage and commit for downstream tasks. - runAfter: - - provision-cluster - params: - - name: SNAPSHOT - value: $(params.SNAPSHOT) - - name: namespace - value: "$(params.namespace)" - - name: install-mode - value: $(params.install-mode) - taskSpec: - results: - - name: bundle-image - value: "$(steps.get-snapshot-component.results.bundle-image)" - - name: commit - value: "$(steps.get-snapshot-component.results.commit)" - params: - - name: SNAPSHOT - - name: namespace - type: string - - name: install-mode - type: string - default: "bundle" - volumes: - - name: credentials - emptyDir: {} - steps: - - name: get-kubeconfig - ref: - resolver: git - params: - - name: url - value: https://github.com/konflux-ci/build-definitions.git - - name: revision - value: main - - name: pathInRepo - value: stepactions/eaas-get-ephemeral-cluster-credentials/0.1/eaas-get-ephemeral-cluster-credentials.yaml - params: - - name: eaasSpaceSecretRef - value: $(tasks.eaas-provision-space.results.secretRef) - - name: clusterName - value: "$(tasks.provision-cluster.results.clusterName)" - - name: credentials - value: credentials - - name: install-operator - env: - - name: SNAPSHOT - value: $(params.SNAPSHOT) - - name: KONFLUX_COMPONENT_NAME - valueFrom: - fieldRef: - fieldPath: metadata.labels['appstudio.openshift.io/component'] - - name: KUBECONFIG - value: "/credentials/$(steps.get-kubeconfig.results.kubeconfig)" - - name: OLS_NAMESPACE - value: "$(params.namespace)" - volumeMounts: - - name: credentials - mountPath: /credentials - image: registry.redhat.io/openshift4/ose-cli:latest - script: | - set -euo pipefail - dnf -y install jq python3-pip git curl make golang - COMMIT="$(jq -r --arg component_name "${KONFLUX_COMPONENT_NAME}" '.components[] | select(.name == $component_name) | .source.git.revision' <<< "$SNAPSHOT")" - echo "Cloning lightspeed-operator@${COMMIT} for Konflux operator install" - rm -rf /workspace/lightspeed-operator - mkdir -p /workspace/lightspeed-operator - cd /workspace/lightspeed-operator - git init -q - git remote add origin https://github.com/openshift/lightspeed-operator.git - git fetch --depth 1 origin "${COMMIT}" - git checkout -q FETCH_HEAD - ./.tekton/integration-tests/scripts/run-konflux-operator-install.sh "$(params.install-mode)" - - name: get-snapshot-component - image: registry.redhat.io/openshift4/ose-cli:latest - env: - - name: SNAPSHOT - value: $(params.SNAPSHOT) - - name: KONFLUX_COMPONENT_NAME - valueFrom: - fieldRef: - fieldPath: metadata.labels['appstudio.openshift.io/component'] - results: - - name: bundle-image - type: string - description: "SNAPSHOT containerImage for the PipelineRun-labeled Konflux component (bundle or operator manager image)." - - name: commit - type: string - description: "commit sha to be used to store artifacts" - script: | - dnf -y install jq - echo -n "$(jq -r --arg component_name "${KONFLUX_COMPONENT_NAME}" '.components[] | select(.name == $component_name) | .containerImage' <<< "$SNAPSHOT")" > $(step.results.bundle-image.path) - echo -n "$(jq -r --arg component_name "${KONFLUX_COMPONENT_NAME}" '.components[] | select(.name == $component_name) | .source.git.revision' <<< "$SNAPSHOT")" > $(step.results.commit.path) - - name: ols-operator-tests - description: Task to run tests from operator repository - params: - - name: commit - value: $(tasks.ols-install.results.commit) - - name: artifact-oci-tag-prefix - value: $(params.artifact-oci-tag-prefix) - runAfter: - - ols-install - taskSpec: - params: - - name: commit - - name: artifact-oci-tag-prefix - type: string - default: "" - volumes: - - name: azure-openai-token - secret: - secretName: azureopenai-apitoken - - name: azureopenai-entra-id - secret: - secretName: azureopenai-entra-id - - name: bam-token - secret: - secretName: bam-apitoken - - name: openai-token - secret: - secretName: openai - - name: watsonx-token - secret: - secretName: watsonx-apitoken - - name: credentials - emptyDir: {} - - name: ols-konflux-artifacts-bot-creds - secret: - secretName: ols-konflux-artifacts-bot - steps: - - name: get-kubeconfig - ref: - resolver: git - params: - - name: url - value: https://github.com/konflux-ci/build-definitions.git - - name: revision - value: main - - name: pathInRepo - value: stepactions/eaas-get-ephemeral-cluster-credentials/0.1/eaas-get-ephemeral-cluster-credentials.yaml - params: - - name: eaasSpaceSecretRef - value: $(tasks.eaas-provision-space.results.secretRef) - - name: clusterName - value: "$(tasks.provision-cluster.results.clusterName)" - - name: credentials - value: credentials - - name: run-e2e-tests - resources: - requests: - memory: "8Gi" - limits: - memory: "8Gi" - onError: continue - volumeMounts: - - name: azure-openai-token - mountPath: /var/run/azure_openai - - name: azureopenai-entra-id - mountPath: /var/run/azureopenai-entra-id - - name: bam-token - mountPath: /var/run/bam - - name: openai-token - mountPath: /var/run/openai - - name: watsonx-token - mountPath: /var/run/watsonx - - name: credentials - mountPath: /credentials - env: - - name: KUBECONFIG - value: "/credentials/$(steps.get-kubeconfig.results.kubeconfig)" - - name: BAM_PROVIDER_KEY_PATH - value: "/var/run/bam/token" - - name: AZUREOPENAI_PROVIDER_KEY_PATH - value: "/var/run/azure_openai/token" - - name: OPENAI_PROVIDER_KEY_PATH - value: "/var/run/openai/token" - - name: WATSONX_PROVIDER_KEY_PATH - value: "/var/run/watsonx/token" - - name: COMMIT_SHA - value: "$(params.commit)" - - name: ARTIFACT_DIR - value: "/workspace" - image: registry.redhat.io/openshift4/ose-cli:latest - script: | - dnf -y install git make golang jq gpgme-devel - git init lightspeed-operator - cd lightspeed-operator - git remote add origin https://github.com/openshift/lightspeed-operator.git - git fetch --depth=1 --filter=blob:none origin ${COMMIT_SHA} - git show "${COMMIT_SHA}:.tekton/integration-tests/scripts/run-operator-e2e-tests.sh" | bash -s -- "latest-4.19" - - name: gather-cluster-resources - onError: continue - ref: - resolver: git - params: - - name: url - value: https://github.com/openshift/lightspeed-operator - - name: revision - value: $(params.commit) - - name: pathInRepo - value: .tekton/integration-tests/stepactions/gather-cluster-resources/0.1/gather-cluster-resources.yaml - params: - - name: credentials - value: "credentials" - - name: kubeconfig - value: "$(steps.get-kubeconfig.results.kubeconfig)" - - name: artifact-dir - value: "/workspace/konflux-artifacts" - - name: gather-script-url - value: "https://raw.githubusercontent.com/openshift/lightspeed-operator/$(params.commit)/.tekton/integration-tests/scripts/gather-extra.sh" - # validate that the cluster resources are available in another tekton step - - name: list-artifacts - onError: continue - image: quay.io/konflux-qe-incubator/konflux-qe-tools:latest - workingDir: "/workspace" - script: | - #!/bin/bash - ls -la /workspace - - name: push-artifacts - onError: continue - ref: - resolver: git - params: - - name: url - value: https://github.com/konflux-ci/tekton-integration-catalog.git - - name: revision - value: main - - name: pathInRepo - value: stepactions/secure-push-oci/0.1/secure-push-oci.yaml - params: - - name: workdir-path - value: /workspace - - name: oci-ref - value: "quay.io/openshift-lightspeed/ols-operator-artifacts:$(params.artifact-oci-tag-prefix)$(params.commit)" - - name: credentials-volume-name - value: ols-konflux-artifacts-bot-creds - - name: fail-if-any-step-failed - ref: - resolver: git - params: - - name: url - value: https://github.com/konflux-ci/tekton-integration-catalog.git - - name: revision - value: main - - name: pathInRepo - value: stepactions/fail-if-any-step-failed/0.1/fail-if-any-step-failed.yaml - finally: - - name: export-logs-for-retention - taskRef: - resolver: git - params: - - name: url - value: https://github.com/konflux-ci/tekton-integration-catalog.git - - name: revision - value: main - - name: pathInRepo - value: tasks/export-logs/0.1/export-logs-to-quay.yaml - params: - - name: pipeline-run-name - value: $(context.pipelineRun.name) - - name: namespace - value: $(context.pipelineRun.namespace) - - name: quay-repo - value: "quay.io/openshift-lightspeed/ols-operator-artifacts" - - name: artifact-credentials-secret - value: ols-konflux-artifacts-bot diff --git a/.tekton/integration-tests/pipelines/lightspeed-service-integration-test-pipeline-4.18.yaml b/.tekton/integration-tests/pipelines/lightspeed-operator-e2e-test-pipeline.yaml similarity index 84% rename from .tekton/integration-tests/pipelines/lightspeed-service-integration-test-pipeline-4.18.yaml rename to .tekton/integration-tests/pipelines/lightspeed-operator-e2e-test-pipeline.yaml index 5396f42ed..035423f23 100644 --- a/.tekton/integration-tests/pipelines/lightspeed-service-integration-test-pipeline-4.18.yaml +++ b/.tekton/integration-tests/pipelines/lightspeed-operator-e2e-test-pipeline.yaml @@ -7,16 +7,13 @@ metadata: name: ols-integration-tests-pipeline spec: description: | - Runs OpenShift Lightspeed service integration tests on a HyperShift hosted cluster (openshift-ci): - provision cluster, install the operator via ols-install (OLM bundle or direct per install-mode), - then clone operator + service at related_images - revisions and run tests/scripts/test-e2e-cluster.sh, push artifacts. + Runs OpenShift Lightspeed operator e2e tests on a Konflux ephemeral OpenShift cluster (EaaS). + Provisions the cluster, installs the operator (OLM bundle or direct/kustomize per install-mode), + runs tests from the snapshot commit, collects artifacts, then deprovisions. - Per OpenShift minor: set openshift-version-prefix (e.g. 4.16.) and test-name. For OCP 4.16 only, - set artifact-oci-tag-prefix to "416" so ols-service-artifacts uses tag 416; leave empty - for other versions. The run step bootstraps git then runs - .tekton/integration-tests/scripts/run-service-integration-tests.sh (openshift-version-prefix - is passed through; install-oc-if-missing.sh supplies the oc client for latest-). + Per OpenShift minor: set params.openshift-version-prefix (e.g. 4.16) and params.test-name + (Konflux integration test id). For OpenShift 4.16 only, set params.artifact-oci-tag-prefix to "416" + so pushed artifacts use tag 416; leave artifact-oci-tag-prefix empty for other versions. params: - name: SNAPSHOT description: 'The JSON string representing the snapshot of the application under test.' @@ -24,18 +21,18 @@ spec: type: string - name: test-name description: 'The name of the test corresponding to a defined Konflux integration test.' - default: 'ols-e2e-tests-4.18' + default: 'ols-e2e-tests' type: string - name: namespace description: 'Namespace to run tests in' default: 'openshift-lightspeed' type: string - name: openshift-version-prefix - description: 'OpenShift minor version prefix (include trailing dot, e.g. 4.18.) passed to test scripts.' - default: '4.18.' + description: 'OpenShift minor version to provision (for example, 4.22).' + default: '4.22' type: string - name: artifact-oci-tag-prefix - description: 'Prepended to commit SHA in ols-service-artifacts Quay tag. Use "416" for OCP 4.16; empty for other minors.' + description: 'Prepended to commit SHA in ols-operator-artifacts Quay tag. Use "416" for OCP 4.16; empty for other minors.' default: '' type: string - name: install-mode @@ -65,9 +62,9 @@ spec: - name: env value: '{"COMPUTE_NODE_TYPE": "m5.2xlarge", "HYPERSHIFT_NODE_COUNT": "3", "HOSTED_MANAGEMENT_CLUSTER": "hosted-mgmt2"}' - name: releases - value: '{"latest":{"release":{"channel":"stable","version":"4.18","architecture":"multi"}}}' + value: '{"latest":{"release":{"channel":"stable","version":"$(params.openshift-version-prefix)","architecture":"multi"}}}' - name: ols-install - description: Install operator (OLM bundle or direct); record SNAPSHOT image ref and commit for service tests. + description: Install operator (OLM bundle or direct); record SNAPSHOT containerImage and commit for downstream tasks. runAfter: - provision-ephemeral-cluster params: @@ -148,37 +145,27 @@ spec: dnf -y install jq echo -n "$(jq -r --arg component_name "${KONFLUX_COMPONENT_NAME}" '.components[] | select(.name == $component_name) | .containerImage' <<< "$SNAPSHOT")" > $(step.results.bundle-image.path) echo -n "$(jq -r --arg component_name "${KONFLUX_COMPONENT_NAME}" '.components[] | select(.name == $component_name) | .source.git.revision' <<< "$SNAPSHOT")" > $(step.results.commit.path) - - name: ols-service-tests - description: Task to run tests from service repository + - name: ols-operator-tests + description: Task to run tests from operator repository params: - - name: SNAPSHOT - value: $(params.SNAPSHOT) - - name: bundleimage - value: $(tasks.ols-install.results.bundle-image) - name: commit value: $(tasks.ols-install.results.commit) - - name: namespace - value: "$(params.namespace)" - - name: openshift-version-prefix - value: $(params.openshift-version-prefix) - name: artifact-oci-tag-prefix value: $(params.artifact-oci-tag-prefix) + - name: openshift-version-prefix + value: $(params.openshift-version-prefix) - name: clusterCredentialsSecretRef value: $(tasks.provision-ephemeral-cluster.results.secretRef) runAfter: - ols-install taskSpec: params: - - name: SNAPSHOT - - name: bundleimage - description: SNAPSHOT containerImage for the labeled Konflux component (bundle or operator manager image). - name: commit - - name: namespace + - name: artifact-oci-tag-prefix type: string + default: "" - name: openshift-version-prefix type: string - - name: artifact-oci-tag-prefix - type: string - name: clusterCredentialsSecretRef type: string volumes: @@ -217,13 +204,12 @@ spec: secretName: $(params.clusterCredentialsSecretRef) steps: - name: run-e2e-tests - onError: continue resources: requests: - cpu: '1' - memory: 1Gi + memory: "8Gi" limits: - memory: 10Gi + memory: "8Gi" + onError: continue volumeMounts: - name: azure-openai-token mountPath: /var/run/azure_openai @@ -246,6 +232,8 @@ spec: - name: cluster-credentials mountPath: /credentials env: + - name: KUBECONFIG + value: "/credentials/kubeconfig" - name: BAM_PROVIDER_KEY_PATH value: "/var/run/bam/token" - name: AZUREOPENAI_PROVIDER_KEY_PATH @@ -288,22 +276,19 @@ spec: value: "true" - name: OLS_IMAGE value: "" - - name: BUNDLE_IMAGE - value: "$(params.bundleimage)" - name: BUNDLE_COMMIT_SHA value: "$(params.commit)" - - name: OLS_NAMESPACE - value: "$(params.namespace)" - image: registry.access.redhat.com/ubi9/ubi-minimal + - name: ARTIFACT_DIR + value: "/workspace" + image: registry.redhat.io/openshift4/ose-cli:latest script: | - set -euo pipefail - microdnf -y install git make python3.11 python3.11-devel python3.11-pip shadow-utils tar jq + dnf -y install git make golang jq gpgme-devel git init lightspeed-operator cd lightspeed-operator git remote add origin https://github.com/openshift/lightspeed-operator.git - git fetch --depth=1 origin "${BUNDLE_COMMIT_SHA}" - git checkout "${BUNDLE_COMMIT_SHA}" - bash .tekton/integration-tests/scripts/run-service-integration-tests.sh "$(params.openshift-version-prefix)" + export COMMIT_SHA="${BUNDLE_COMMIT_SHA}" + git fetch --depth=1 --filter=blob:none origin "${BUNDLE_COMMIT_SHA}" + git show "${BUNDLE_COMMIT_SHA}:.tekton/integration-tests/scripts/run-operator-e2e-tests.sh" | bash -s -- "latest-$(params.openshift-version-prefix)" - name: gather-cluster-resources onError: continue ref: @@ -347,7 +332,7 @@ spec: - name: workdir-path value: /workspace - name: oci-ref - value: "quay.io/openshift-lightspeed/ols-service-artifacts:$(params.artifact-oci-tag-prefix)$(params.commit)" + value: "quay.io/openshift-lightspeed/ols-operator-artifacts:$(params.artifact-oci-tag-prefix)$(params.commit)" - name: credentials-volume-name value: ols-konflux-artifacts-bot-creds - name: fail-if-any-step-failed @@ -392,6 +377,6 @@ spec: - name: namespace value: $(context.pipelineRun.namespace) - name: quay-repo - value: "quay.io/openshift-lightspeed/ols-service-artifacts" + value: "quay.io/openshift-lightspeed/ols-operator-artifacts" - name: artifact-credentials-secret value: ols-konflux-artifacts-bot diff --git a/.tekton/integration-tests/pipelines/lightspeed-operator-upgrade-e2e-test-pipeline-419.yaml b/.tekton/integration-tests/pipelines/lightspeed-operator-upgrade-e2e-test-pipeline-419.yaml deleted file mode 100644 index a2322cb32..000000000 --- a/.tekton/integration-tests/pipelines/lightspeed-operator-upgrade-e2e-test-pipeline-419.yaml +++ /dev/null @@ -1,362 +0,0 @@ ---- -apiVersion: tekton.dev/v1beta1 -kind: Pipeline -metadata: - annotations: - pipelinesascode.tekton.dev/task: "[ols-installer, ols-e2e-task]" - name: ols-integration-tests-pipeline -spec: - description: | - Runs OpenShift Lightspeed operator upgrade e2e tests on a Konflux ephemeral OpenShift cluster (EaaS): - provision cluster, OLM-install the second-newest catalog bundle (latest-1 semver among bundle-v*.yaml; avoids - known-bad upgrade chains from very old bases), skip final bundle in ols-install, run make test-upgrade to - bundle-upgrade to the snapshot bundle, gather artifacts, deprovision. - - Per OpenShift minor: set params.openshift-version-prefix (e.g. 4.16.) and params.test-name (Konflux integration - test id). Base bundle is the penultimate semver in lightspeed-catalog-; upgrade targets the snapshot - bundle (SNAPSHOT + component label). - params: - - name: SNAPSHOT - description: 'The JSON string representing the snapshot of the application under test.' - default: '{"components": [{"name":"test-app", "containerImage": "quay.io/example/repo:latest"}]}' - type: string - - name: test-name - description: 'The name of the test corresponding to a defined Konflux integration test.' - default: 'ols-upgrade-e2e-tests-4.19' - type: string - - name: namespace - description: 'Namespace to run tests in' - default: 'openshift-lightspeed' - type: string - - name: openshift-version-prefix - description: 'Minor line prefix for eaas-get-latest-openshift-version-by-prefix (include trailing dot, e.g. 4.19.)' - default: '4.19.' - type: string - tasks: - - name: eaas-provision-space - taskRef: - resolver: git - params: - - name: url - value: https://github.com/konflux-ci/build-definitions.git - - name: revision - value: main - - name: pathInRepo - value: task/eaas-provision-space/0.1/eaas-provision-space.yaml - params: - - name: ownerKind - value: PipelineRun - - name: ownerName - value: $(context.pipelineRun.name) - - name: ownerUid - value: $(context.pipelineRun.uid) - - name: provision-cluster - runAfter: - - eaas-provision-space - params: - - name: openshift-version-prefix - value: $(params.openshift-version-prefix) - taskSpec: - params: - - name: openshift-version-prefix - type: string - results: - - name: clusterName - value: "$(steps.create-cluster.results.clusterName)" - steps: - - name: pick-version - ref: - resolver: git - params: - - name: url - value: https://github.com/konflux-ci/build-definitions.git - - name: revision - value: main - - name: pathInRepo - value: stepactions/eaas-get-latest-openshift-version-by-prefix/0.1/eaas-get-latest-openshift-version-by-prefix.yaml - params: - - name: prefix - value: "$(params.openshift-version-prefix)" - - name: create-cluster - ref: - resolver: git - params: - - name: url - value: https://github.com/konflux-ci/build-definitions.git - - name: revision - value: main - - name: pathInRepo - value: stepactions/eaas-create-ephemeral-cluster-hypershift-aws/0.1/eaas-create-ephemeral-cluster-hypershift-aws.yaml - params: - - name: eaasSpaceSecretRef - value: $(tasks.eaas-provision-space.results.secretRef) - - name: version - value: "$(steps.pick-version.results.version)" - - name: instanceType - value: "m5.2xlarge" - - name: ols-install - description: Install operator bundle (upgrade base + snapshot); record SNAPSHOT commit for tests. - runAfter: - - provision-cluster - params: - - name: SNAPSHOT - value: $(params.SNAPSHOT) - - name: namespace - value: "$(params.namespace)" - - name: openshift-version-prefix - value: $(params.openshift-version-prefix) - taskSpec: - results: - - name: commit - value: "$(steps.get-snapshot-component.results.commit)" - params: - - name: SNAPSHOT - - name: namespace - - name: openshift-version-prefix - type: string - volumes: - - name: credentials - emptyDir: {} - steps: - - name: get-kubeconfig - ref: - resolver: git - params: - - name: url - value: https://github.com/konflux-ci/build-definitions.git - - name: revision - value: main - - name: pathInRepo - value: stepactions/eaas-get-ephemeral-cluster-credentials/0.1/eaas-get-ephemeral-cluster-credentials.yaml - params: - - name: eaasSpaceSecretRef - value: $(tasks.eaas-provision-space.results.secretRef) - - name: clusterName - value: "$(tasks.provision-cluster.results.clusterName)" - - name: credentials - value: credentials - - name: install-operator - env: - - name: SNAPSHOT - value: $(params.SNAPSHOT) - - name: KONFLUX_COMPONENT_NAME - valueFrom: - fieldRef: - fieldPath: metadata.labels['appstudio.openshift.io/component'] - - name: KUBECONFIG - value: "/credentials/$(steps.get-kubeconfig.results.kubeconfig)" - - name: OLS_NAMESPACE - value: "$(params.namespace)" - - name: UPGRADE_E2E_INSTALL_OLD_BASE_FROM_CATALOG - value: "$(params.openshift-version-prefix)" - volumeMounts: - - name: credentials - mountPath: /credentials - image: registry.redhat.io/openshift4/ose-cli:latest - script: | - set -euo pipefail - dnf -y install jq python3-pip git curl yq - COMMIT="$(jq -r --arg component_name "${KONFLUX_COMPONENT_NAME}" '.components[] | select(.name == $component_name) | .source.git.revision' <<< "$SNAPSHOT")" - echo "Cloning lightspeed-operator@${COMMIT} for Konflux operator install" - rm -rf /workspace/lightspeed-operator - mkdir -p /workspace/lightspeed-operator - cd /workspace/lightspeed-operator - git init -q - git remote add origin https://github.com/openshift/lightspeed-operator.git - git fetch --depth 1 origin "${COMMIT}" - git checkout -q FETCH_HEAD - ./.tekton/integration-tests/scripts/run-konflux-operator-install.sh bundle - - name: get-snapshot-component - image: registry.redhat.io/openshift4/ose-cli:latest - env: - - name: SNAPSHOT - value: $(params.SNAPSHOT) - - name: KONFLUX_COMPONENT_NAME - valueFrom: - fieldRef: - fieldPath: metadata.labels['appstudio.openshift.io/component'] - results: - - name: commit - type: string - description: "commit sha to be used to store artifacts" - script: | - dnf -y install jq - echo -n "$(jq -r --arg component_name "${KONFLUX_COMPONENT_NAME}" '.components[] | select(.name == $component_name) | .source.git.revision' <<< "$SNAPSHOT")" > $(step.results.commit.path) - - name: ols-operator-tests - description: Task to run tests from operator repository - params: - - name: commit - value: $(tasks.ols-install.results.commit) - - name: openshift-version-prefix - value: $(params.openshift-version-prefix) - - name: SNAPSHOT - value: $(params.SNAPSHOT) - runAfter: - - ols-install - taskSpec: - params: - - name: commit - - name: openshift-version-prefix - type: string - - name: SNAPSHOT - type: string - volumes: - - name: azure-openai-token - secret: - secretName: azureopenai-apitoken - - name: azureopenai-entra-id - secret: - secretName: azureopenai-entra-id - - name: bam-token - secret: - secretName: bam-apitoken - - name: openai-token - secret: - secretName: openai - - name: watsonx-token - secret: - secretName: watsonx-apitoken - - name: credentials - emptyDir: {} - - name: ols-konflux-artifacts-bot-creds - secret: - secretName: ols-konflux-artifacts-bot - steps: - - name: get-kubeconfig - ref: - resolver: git - params: - - name: url - value: https://github.com/konflux-ci/build-definitions.git - - name: revision - value: main - - name: pathInRepo - value: stepactions/eaas-get-ephemeral-cluster-credentials/0.1/eaas-get-ephemeral-cluster-credentials.yaml - params: - - name: eaasSpaceSecretRef - value: $(tasks.eaas-provision-space.results.secretRef) - - name: clusterName - value: "$(tasks.provision-cluster.results.clusterName)" - - name: credentials - value: credentials - - name: run-e2e-tests - onError: continue - volumeMounts: - - name: azure-openai-token - mountPath: /var/run/azure_openai - - name: azureopenai-entra-id - mountPath: /var/run/azureopenai-entra-id - - name: bam-token - mountPath: /var/run/bam - - name: openai-token - mountPath: /var/run/openai - - name: watsonx-token - mountPath: /var/run/watsonx - - name: credentials - mountPath: /credentials - env: - - name: KUBECONFIG - value: "/credentials/$(steps.get-kubeconfig.results.kubeconfig)" - - name: BAM_PROVIDER_KEY_PATH - value: "/var/run/bam/token" - - name: AZUREOPENAI_PROVIDER_KEY_PATH - value: "/var/run/azure_openai/token" - - name: OPENAI_PROVIDER_KEY_PATH - value: "/var/run/openai/token" - - name: WATSONX_PROVIDER_KEY_PATH - value: "/var/run/watsonx/token" - - name: COMMIT_SHA - value: "$(params.commit)" - - name: SNAPSHOT - value: $(params.SNAPSHOT) - - name: KONFLUX_COMPONENT_NAME - valueFrom: - fieldRef: - fieldPath: metadata.labels['appstudio.openshift.io/component'] - - name: ARTIFACT_DIR - value: "/workspace" - image: registry.redhat.io/openshift4/ose-cli:latest - script: | - dnf -y install git make golang jq gpgme-devel yq - git init lightspeed-operator - cd lightspeed-operator - git remote add origin https://github.com/openshift/lightspeed-operator.git - git fetch --depth=1 --filter=blob:none origin "${COMMIT_SHA}" - git checkout "${COMMIT_SHA}" - git show "${COMMIT_SHA}:.tekton/integration-tests/scripts/run-operator-upgrade-tests.sh" | bash -s -- "$(params.openshift-version-prefix)" - - name: gather-cluster-resources - onError: continue - ref: - resolver: git - params: - - name: url - value: https://github.com/openshift/lightspeed-operator - - name: revision - value: $(params.commit) - - name: pathInRepo - value: .tekton/integration-tests/stepactions/gather-cluster-resources/0.1/gather-cluster-resources.yaml - params: - - name: credentials - value: "credentials" - - name: kubeconfig - value: "$(steps.get-kubeconfig.results.kubeconfig)" - - name: artifact-dir - value: "/workspace/konflux-artifacts" - - name: gather-script-url - value: "https://raw.githubusercontent.com/openshift/lightspeed-operator/$(params.commit)/.tekton/integration-tests/scripts/gather-extra.sh" - # validate that the cluster resources are available in another tekton step - - name: list-artifacts - onError: continue - image: quay.io/konflux-qe-incubator/konflux-qe-tools:latest - workingDir: "/workspace" - script: | - #!/bin/bash - ls -la /workspace - - name: push-artifacts - onError: continue - ref: - resolver: git - params: - - name: url - value: https://github.com/konflux-ci/tekton-integration-catalog.git - - name: revision - value: main - - name: pathInRepo - value: stepactions/secure-push-oci/0.1/secure-push-oci.yaml - params: - - name: workdir-path - value: /workspace - - name: oci-ref - value: "quay.io/openshift-lightspeed/ols-operator-artifacts:$(params.commit)" - - name: credentials-volume-name - value: ols-konflux-artifacts-bot-creds - - name: fail-if-any-step-failed - ref: - resolver: git - params: - - name: url - value: https://github.com/konflux-ci/tekton-integration-catalog.git - - name: revision - value: main - - name: pathInRepo - value: stepactions/fail-if-any-step-failed/0.1/fail-if-any-step-failed.yaml - finally: - - name: export-logs-for-retention - taskRef: - resolver: git - params: - - name: url - value: https://github.com/konflux-ci/tekton-integration-catalog.git - - name: revision - value: main - - name: pathInRepo - value: tasks/export-logs/0.1/export-logs-to-quay.yaml - params: - - name: pipeline-run-name - value: $(context.pipelineRun.name) - - name: namespace - value: $(context.pipelineRun.namespace) - - name: quay-repo - value: "quay.io/openshift-lightspeed/ols-operator-artifacts" - - name: artifact-credentials-secret - value: ols-konflux-artifacts-bot diff --git a/.tekton/integration-tests/pipelines/lightspeed-operator-upgrade-e2e-test-pipeline-420.yaml b/.tekton/integration-tests/pipelines/lightspeed-operator-upgrade-e2e-test-pipeline-420.yaml deleted file mode 100644 index fd495baef..000000000 --- a/.tekton/integration-tests/pipelines/lightspeed-operator-upgrade-e2e-test-pipeline-420.yaml +++ /dev/null @@ -1,362 +0,0 @@ ---- -apiVersion: tekton.dev/v1beta1 -kind: Pipeline -metadata: - annotations: - pipelinesascode.tekton.dev/task: "[ols-installer, ols-e2e-task]" - name: ols-integration-tests-pipeline -spec: - description: | - Runs OpenShift Lightspeed operator upgrade e2e tests on a Konflux ephemeral OpenShift cluster (EaaS): - provision cluster, OLM-install the second-newest catalog bundle (latest-1 semver among bundle-v*.yaml; avoids - known-bad upgrade chains from very old bases), skip final bundle in ols-install, run make test-upgrade to - bundle-upgrade to the snapshot bundle, gather artifacts, deprovision. - - Per OpenShift minor: set params.openshift-version-prefix (e.g. 4.16.) and params.test-name (Konflux integration - test id). Base bundle is the penultimate semver in lightspeed-catalog-; upgrade targets the snapshot - bundle (SNAPSHOT + component label). - params: - - name: SNAPSHOT - description: 'The JSON string representing the snapshot of the application under test.' - default: '{"components": [{"name":"test-app", "containerImage": "quay.io/example/repo:latest"}]}' - type: string - - name: test-name - description: 'The name of the test corresponding to a defined Konflux integration test.' - default: 'ols-upgrade-e2e-tests-4.20' - type: string - - name: namespace - description: 'Namespace to run tests in' - default: 'openshift-lightspeed' - type: string - - name: openshift-version-prefix - description: 'Minor line prefix for eaas-get-latest-openshift-version-by-prefix (include trailing dot, e.g. 4.19.)' - default: '4.20.' - type: string - tasks: - - name: eaas-provision-space - taskRef: - resolver: git - params: - - name: url - value: https://github.com/konflux-ci/build-definitions.git - - name: revision - value: main - - name: pathInRepo - value: task/eaas-provision-space/0.1/eaas-provision-space.yaml - params: - - name: ownerKind - value: PipelineRun - - name: ownerName - value: $(context.pipelineRun.name) - - name: ownerUid - value: $(context.pipelineRun.uid) - - name: provision-cluster - runAfter: - - eaas-provision-space - params: - - name: openshift-version-prefix - value: $(params.openshift-version-prefix) - taskSpec: - params: - - name: openshift-version-prefix - type: string - results: - - name: clusterName - value: "$(steps.create-cluster.results.clusterName)" - steps: - - name: pick-version - ref: - resolver: git - params: - - name: url - value: https://github.com/konflux-ci/build-definitions.git - - name: revision - value: main - - name: pathInRepo - value: stepactions/eaas-get-latest-openshift-version-by-prefix/0.1/eaas-get-latest-openshift-version-by-prefix.yaml - params: - - name: prefix - value: "$(params.openshift-version-prefix)" - - name: create-cluster - ref: - resolver: git - params: - - name: url - value: https://github.com/konflux-ci/build-definitions.git - - name: revision - value: main - - name: pathInRepo - value: stepactions/eaas-create-ephemeral-cluster-hypershift-aws/0.1/eaas-create-ephemeral-cluster-hypershift-aws.yaml - params: - - name: eaasSpaceSecretRef - value: $(tasks.eaas-provision-space.results.secretRef) - - name: version - value: "$(steps.pick-version.results.version)" - - name: instanceType - value: "m5.2xlarge" - - name: ols-install - description: Install operator bundle (upgrade base + snapshot); record SNAPSHOT commit for tests. - runAfter: - - provision-cluster - params: - - name: SNAPSHOT - value: $(params.SNAPSHOT) - - name: namespace - value: "$(params.namespace)" - - name: openshift-version-prefix - value: $(params.openshift-version-prefix) - taskSpec: - results: - - name: commit - value: "$(steps.get-snapshot-component.results.commit)" - params: - - name: SNAPSHOT - - name: namespace - - name: openshift-version-prefix - type: string - volumes: - - name: credentials - emptyDir: {} - steps: - - name: get-kubeconfig - ref: - resolver: git - params: - - name: url - value: https://github.com/konflux-ci/build-definitions.git - - name: revision - value: main - - name: pathInRepo - value: stepactions/eaas-get-ephemeral-cluster-credentials/0.1/eaas-get-ephemeral-cluster-credentials.yaml - params: - - name: eaasSpaceSecretRef - value: $(tasks.eaas-provision-space.results.secretRef) - - name: clusterName - value: "$(tasks.provision-cluster.results.clusterName)" - - name: credentials - value: credentials - - name: install-operator - env: - - name: SNAPSHOT - value: $(params.SNAPSHOT) - - name: KONFLUX_COMPONENT_NAME - valueFrom: - fieldRef: - fieldPath: metadata.labels['appstudio.openshift.io/component'] - - name: KUBECONFIG - value: "/credentials/$(steps.get-kubeconfig.results.kubeconfig)" - - name: OLS_NAMESPACE - value: "$(params.namespace)" - - name: UPGRADE_E2E_INSTALL_OLD_BASE_FROM_CATALOG - value: "$(params.openshift-version-prefix)" - volumeMounts: - - name: credentials - mountPath: /credentials - image: registry.redhat.io/openshift4/ose-cli:latest - script: | - set -euo pipefail - dnf -y install jq python3-pip git curl yq - COMMIT="$(jq -r --arg component_name "${KONFLUX_COMPONENT_NAME}" '.components[] | select(.name == $component_name) | .source.git.revision' <<< "$SNAPSHOT")" - echo "Cloning lightspeed-operator@${COMMIT} for Konflux operator install" - rm -rf /workspace/lightspeed-operator - mkdir -p /workspace/lightspeed-operator - cd /workspace/lightspeed-operator - git init -q - git remote add origin https://github.com/openshift/lightspeed-operator.git - git fetch --depth 1 origin "${COMMIT}" - git checkout -q FETCH_HEAD - ./.tekton/integration-tests/scripts/run-konflux-operator-install.sh bundle - - name: get-snapshot-component - image: registry.redhat.io/openshift4/ose-cli:latest - env: - - name: SNAPSHOT - value: $(params.SNAPSHOT) - - name: KONFLUX_COMPONENT_NAME - valueFrom: - fieldRef: - fieldPath: metadata.labels['appstudio.openshift.io/component'] - results: - - name: commit - type: string - description: "commit sha to be used to store artifacts" - script: | - dnf -y install jq - echo -n "$(jq -r --arg component_name "${KONFLUX_COMPONENT_NAME}" '.components[] | select(.name == $component_name) | .source.git.revision' <<< "$SNAPSHOT")" > $(step.results.commit.path) - - name: ols-operator-tests - description: Task to run tests from operator repository - params: - - name: commit - value: $(tasks.ols-install.results.commit) - - name: openshift-version-prefix - value: $(params.openshift-version-prefix) - - name: SNAPSHOT - value: $(params.SNAPSHOT) - runAfter: - - ols-install - taskSpec: - params: - - name: commit - - name: openshift-version-prefix - type: string - - name: SNAPSHOT - type: string - volumes: - - name: azure-openai-token - secret: - secretName: azureopenai-apitoken - - name: azureopenai-entra-id - secret: - secretName: azureopenai-entra-id - - name: bam-token - secret: - secretName: bam-apitoken - - name: openai-token - secret: - secretName: openai - - name: watsonx-token - secret: - secretName: watsonx-apitoken - - name: credentials - emptyDir: {} - - name: ols-konflux-artifacts-bot-creds - secret: - secretName: ols-konflux-artifacts-bot - steps: - - name: get-kubeconfig - ref: - resolver: git - params: - - name: url - value: https://github.com/konflux-ci/build-definitions.git - - name: revision - value: main - - name: pathInRepo - value: stepactions/eaas-get-ephemeral-cluster-credentials/0.1/eaas-get-ephemeral-cluster-credentials.yaml - params: - - name: eaasSpaceSecretRef - value: $(tasks.eaas-provision-space.results.secretRef) - - name: clusterName - value: "$(tasks.provision-cluster.results.clusterName)" - - name: credentials - value: credentials - - name: run-e2e-tests - onError: continue - volumeMounts: - - name: azure-openai-token - mountPath: /var/run/azure_openai - - name: azureopenai-entra-id - mountPath: /var/run/azureopenai-entra-id - - name: bam-token - mountPath: /var/run/bam - - name: openai-token - mountPath: /var/run/openai - - name: watsonx-token - mountPath: /var/run/watsonx - - name: credentials - mountPath: /credentials - env: - - name: KUBECONFIG - value: "/credentials/$(steps.get-kubeconfig.results.kubeconfig)" - - name: BAM_PROVIDER_KEY_PATH - value: "/var/run/bam/token" - - name: AZUREOPENAI_PROVIDER_KEY_PATH - value: "/var/run/azure_openai/token" - - name: OPENAI_PROVIDER_KEY_PATH - value: "/var/run/openai/token" - - name: WATSONX_PROVIDER_KEY_PATH - value: "/var/run/watsonx/token" - - name: COMMIT_SHA - value: "$(params.commit)" - - name: SNAPSHOT - value: $(params.SNAPSHOT) - - name: KONFLUX_COMPONENT_NAME - valueFrom: - fieldRef: - fieldPath: metadata.labels['appstudio.openshift.io/component'] - - name: ARTIFACT_DIR - value: "/workspace" - image: registry.redhat.io/openshift4/ose-cli:latest - script: | - dnf -y install git make golang jq gpgme-devel yq - git init lightspeed-operator - cd lightspeed-operator - git remote add origin https://github.com/openshift/lightspeed-operator.git - git fetch --depth=1 --filter=blob:none origin "${COMMIT_SHA}" - git checkout "${COMMIT_SHA}" - git show "${COMMIT_SHA}:.tekton/integration-tests/scripts/run-operator-upgrade-tests.sh" | bash -s -- "$(params.openshift-version-prefix)" - - name: gather-cluster-resources - onError: continue - ref: - resolver: git - params: - - name: url - value: https://github.com/openshift/lightspeed-operator - - name: revision - value: $(params.commit) - - name: pathInRepo - value: .tekton/integration-tests/stepactions/gather-cluster-resources/0.1/gather-cluster-resources.yaml - params: - - name: credentials - value: "credentials" - - name: kubeconfig - value: "$(steps.get-kubeconfig.results.kubeconfig)" - - name: artifact-dir - value: "/workspace/konflux-artifacts" - - name: gather-script-url - value: "https://raw.githubusercontent.com/openshift/lightspeed-operator/$(params.commit)/.tekton/integration-tests/scripts/gather-extra.sh" - # validate that the cluster resources are available in another tekton step - - name: list-artifacts - onError: continue - image: quay.io/konflux-qe-incubator/konflux-qe-tools:latest - workingDir: "/workspace" - script: | - #!/bin/bash - ls -la /workspace - - name: push-artifacts - onError: continue - ref: - resolver: git - params: - - name: url - value: https://github.com/konflux-ci/tekton-integration-catalog.git - - name: revision - value: main - - name: pathInRepo - value: stepactions/secure-push-oci/0.1/secure-push-oci.yaml - params: - - name: workdir-path - value: /workspace - - name: oci-ref - value: "quay.io/openshift-lightspeed/ols-operator-artifacts:$(params.commit)" - - name: credentials-volume-name - value: ols-konflux-artifacts-bot-creds - - name: fail-if-any-step-failed - ref: - resolver: git - params: - - name: url - value: https://github.com/konflux-ci/tekton-integration-catalog.git - - name: revision - value: main - - name: pathInRepo - value: stepactions/fail-if-any-step-failed/0.1/fail-if-any-step-failed.yaml - finally: - - name: export-logs-for-retention - taskRef: - resolver: git - params: - - name: url - value: https://github.com/konflux-ci/tekton-integration-catalog.git - - name: revision - value: main - - name: pathInRepo - value: tasks/export-logs/0.1/export-logs-to-quay.yaml - params: - - name: pipeline-run-name - value: $(context.pipelineRun.name) - - name: namespace - value: $(context.pipelineRun.namespace) - - name: quay-repo - value: "quay.io/openshift-lightspeed/ols-operator-artifacts" - - name: artifact-credentials-secret - value: ols-konflux-artifacts-bot diff --git a/.tekton/integration-tests/pipelines/lightspeed-service-integration-test-pipeline-4.19.yaml b/.tekton/integration-tests/pipelines/lightspeed-operator-upgrade-e2e-test-pipeline.yaml similarity index 77% rename from .tekton/integration-tests/pipelines/lightspeed-service-integration-test-pipeline-4.19.yaml rename to .tekton/integration-tests/pipelines/lightspeed-operator-upgrade-e2e-test-pipeline.yaml index d43f52ee0..a4f073d8c 100644 --- a/.tekton/integration-tests/pipelines/lightspeed-service-integration-test-pipeline-4.19.yaml +++ b/.tekton/integration-tests/pipelines/lightspeed-operator-upgrade-e2e-test-pipeline.yaml @@ -7,16 +7,14 @@ metadata: name: ols-integration-tests-pipeline spec: description: | - Runs OpenShift Lightspeed service integration tests on a HyperShift hosted cluster (openshift-ci): - provision cluster, install the operator via ols-install (OLM bundle or direct per install-mode), - then clone operator + service at related_images - revisions and run tests/scripts/test-e2e-cluster.sh, push artifacts. + Runs OpenShift Lightspeed operator upgrade e2e tests on a Konflux ephemeral OpenShift cluster (EaaS): + provision cluster, OLM-install the second-newest catalog bundle (latest-1 semver among bundle-v*.yaml; avoids + known-bad upgrade chains from very old bases), skip final bundle in ols-install, run make test-upgrade to + bundle-upgrade to the snapshot bundle, gather artifacts, deprovision. - Per OpenShift minor: set openshift-version-prefix (e.g. 4.16.) and test-name. For OCP 4.16 only, - set artifact-oci-tag-prefix to "416" so ols-service-artifacts uses tag 416; leave empty - for other versions. The run step bootstraps git then runs - .tekton/integration-tests/scripts/run-service-integration-tests.sh (openshift-version-prefix - is passed through; install-oc-if-missing.sh supplies the oc client for latest-). + Per OpenShift minor: set params.openshift-version-prefix (e.g. 4.16.) and params.test-name (Konflux integration + test id). Base bundle is the penultimate semver in lightspeed-catalog-; upgrade targets the snapshot + bundle (SNAPSHOT + component label). params: - name: SNAPSHOT description: 'The JSON string representing the snapshot of the application under test.' @@ -24,24 +22,16 @@ spec: type: string - name: test-name description: 'The name of the test corresponding to a defined Konflux integration test.' - default: 'ols-e2e-tests-4.19' + default: 'ols-upgrade-e2e-tests' type: string - name: namespace description: 'Namespace to run tests in' default: 'openshift-lightspeed' type: string - name: openshift-version-prefix - description: 'OpenShift minor version prefix (include trailing dot, e.g. 4.19.) passed to test scripts.' - default: '4.19.' + description: 'OpenShift minor version to provision (for example, 4.22).' + default: '4.22' type: string - - name: artifact-oci-tag-prefix - description: 'Prepended to commit SHA in ols-service-artifacts Quay tag. Use "416" for OCP 4.16; empty for other minors.' - default: '' - type: string - - name: install-mode - description: 'Operator install: bundle (OLM) or direct (kustomize; IMG from lightspeed-operator in SNAPSHOT).' - type: string - default: 'bundle' tasks: - name: provision-ephemeral-cluster taskRef: @@ -65,9 +55,9 @@ spec: - name: env value: '{"COMPUTE_NODE_TYPE": "m5.2xlarge", "HYPERSHIFT_NODE_COUNT": "3", "HOSTED_MANAGEMENT_CLUSTER": "hosted-mgmt2"}' - name: releases - value: '{"latest":{"release":{"channel":"stable","version":"4.19","architecture":"multi"}}}' + value: '{"latest":{"release":{"channel":"stable","version":"$(params.openshift-version-prefix)","architecture":"multi"}}}' - name: ols-install - description: Install operator (OLM bundle or direct); record SNAPSHOT image ref and commit for service tests. + description: Install operator bundle (upgrade base + snapshot); record SNAPSHOT commit for tests. runAfter: - provision-ephemeral-cluster params: @@ -75,23 +65,19 @@ spec: value: $(params.SNAPSHOT) - name: namespace value: "$(params.namespace)" - - name: install-mode - value: $(params.install-mode) + - name: openshift-version-prefix + value: "$(params.openshift-version-prefix)." - name: clusterCredentialsSecretRef value: $(tasks.provision-ephemeral-cluster.results.secretRef) taskSpec: results: - - name: bundle-image - value: "$(steps.get-snapshot-component.results.bundle-image)" - name: commit value: "$(steps.get-snapshot-component.results.commit)" params: - name: SNAPSHOT - name: namespace + - name: openshift-version-prefix type: string - - name: install-mode - type: string - default: "bundle" - name: clusterCredentialsSecretRef type: string volumes: @@ -111,13 +97,22 @@ spec: value: "/credentials/kubeconfig" - name: OLS_NAMESPACE value: "$(params.namespace)" + - name: UPGRADE_E2E_INSTALL_OLD_BASE_FROM_CATALOG + value: "$(params.openshift-version-prefix)" volumeMounts: - name: cluster-credentials mountPath: /credentials image: registry.redhat.io/openshift4/ose-cli:latest script: | set -euo pipefail - dnf -y install jq python3-pip git curl make golang + dnf -y install jq python3-pip git curl + # yq is not shipped by the repositories enabled in ose-cli. Install the + # pinned upstream static binary so it is also available to the fallback path. + YQ_VERSION="v4.44.3" + curl --fail --location --silent --show-error \ + "https://github.com/mikefarah/yq/releases/download/${YQ_VERSION}/yq_linux_amd64" \ + --output /usr/local/bin/yq + chmod 0755 /usr/local/bin/yq COMMIT="$(jq -r --arg component_name "${KONFLUX_COMPONENT_NAME}" '.components[] | select(.name == $component_name) | .source.git.revision' <<< "$SNAPSHOT")" echo "Cloning lightspeed-operator@${COMMIT} for Konflux operator install" rm -rf /workspace/lightspeed-operator @@ -127,7 +122,7 @@ spec: git remote add origin https://github.com/openshift/lightspeed-operator.git git fetch --depth 1 origin "${COMMIT}" git checkout -q FETCH_HEAD - ./.tekton/integration-tests/scripts/run-konflux-operator-install.sh "$(params.install-mode)" + ./.tekton/integration-tests/scripts/run-konflux-operator-install.sh bundle - name: get-snapshot-component image: registry.redhat.io/openshift4/ose-cli:latest env: @@ -138,46 +133,31 @@ spec: fieldRef: fieldPath: metadata.labels['appstudio.openshift.io/component'] results: - - name: bundle-image - type: string - description: "SNAPSHOT containerImage for the PipelineRun-labeled Konflux component (bundle or operator manager image)." - name: commit type: string description: "commit sha to be used to store artifacts" script: | dnf -y install jq - echo -n "$(jq -r --arg component_name "${KONFLUX_COMPONENT_NAME}" '.components[] | select(.name == $component_name) | .containerImage' <<< "$SNAPSHOT")" > $(step.results.bundle-image.path) echo -n "$(jq -r --arg component_name "${KONFLUX_COMPONENT_NAME}" '.components[] | select(.name == $component_name) | .source.git.revision' <<< "$SNAPSHOT")" > $(step.results.commit.path) - - name: ols-service-tests - description: Task to run tests from service repository + - name: ols-operator-tests + description: Task to run tests from operator repository params: - - name: SNAPSHOT - value: $(params.SNAPSHOT) - - name: bundleimage - value: $(tasks.ols-install.results.bundle-image) - name: commit value: $(tasks.ols-install.results.commit) - - name: namespace - value: "$(params.namespace)" - name: openshift-version-prefix - value: $(params.openshift-version-prefix) - - name: artifact-oci-tag-prefix - value: $(params.artifact-oci-tag-prefix) + value: "$(params.openshift-version-prefix)." + - name: SNAPSHOT + value: $(params.SNAPSHOT) - name: clusterCredentialsSecretRef value: $(tasks.provision-ephemeral-cluster.results.secretRef) runAfter: - ols-install taskSpec: params: - - name: SNAPSHOT - - name: bundleimage - description: SNAPSHOT containerImage for the labeled Konflux component (bundle or operator manager image). - name: commit - - name: namespace - type: string - name: openshift-version-prefix type: string - - name: artifact-oci-tag-prefix + - name: SNAPSHOT type: string - name: clusterCredentialsSecretRef type: string @@ -218,12 +198,6 @@ spec: steps: - name: run-e2e-tests onError: continue - resources: - requests: - cpu: '1' - memory: 1Gi - limits: - memory: 10Gi volumeMounts: - name: azure-openai-token mountPath: /var/run/azure_openai @@ -246,6 +220,8 @@ spec: - name: cluster-credentials mountPath: /credentials env: + - name: KUBECONFIG + value: "/credentials/kubeconfig" - name: BAM_PROVIDER_KEY_PATH value: "/var/run/bam/token" - name: AZUREOPENAI_PROVIDER_KEY_PATH @@ -288,22 +264,33 @@ spec: value: "true" - name: OLS_IMAGE value: "" - - name: BUNDLE_IMAGE - value: "$(params.bundleimage)" - name: BUNDLE_COMMIT_SHA value: "$(params.commit)" - - name: OLS_NAMESPACE - value: "$(params.namespace)" - image: registry.access.redhat.com/ubi9/ubi-minimal + - name: SNAPSHOT + value: $(params.SNAPSHOT) + - name: KONFLUX_COMPONENT_NAME + valueFrom: + fieldRef: + fieldPath: metadata.labels['appstudio.openshift.io/component'] + - name: ARTIFACT_DIR + value: "/workspace" + image: registry.redhat.io/openshift4/ose-cli:latest script: | - set -euo pipefail - microdnf -y install git make python3.11 python3.11-devel python3.11-pip shadow-utils tar jq + dnf -y install git make golang jq gpgme-devel curl + # yq is not shipped by the repositories enabled in ose-cli. Use the + # same pinned upstream static binary as the install-operator step. + YQ_VERSION="v4.44.3" + curl --fail --location --silent --show-error \ + "https://github.com/mikefarah/yq/releases/download/${YQ_VERSION}/yq_linux_amd64" \ + --output /usr/local/bin/yq + chmod 0755 /usr/local/bin/yq git init lightspeed-operator cd lightspeed-operator git remote add origin https://github.com/openshift/lightspeed-operator.git - git fetch --depth=1 origin "${BUNDLE_COMMIT_SHA}" + export COMMIT_SHA="${BUNDLE_COMMIT_SHA}" + git fetch --depth=1 --filter=blob:none origin "${BUNDLE_COMMIT_SHA}" git checkout "${BUNDLE_COMMIT_SHA}" - bash .tekton/integration-tests/scripts/run-service-integration-tests.sh "$(params.openshift-version-prefix)" + git show "${BUNDLE_COMMIT_SHA}:.tekton/integration-tests/scripts/run-operator-upgrade-tests.sh" | bash -s -- "$(params.openshift-version-prefix)" - name: gather-cluster-resources onError: continue ref: @@ -347,7 +334,7 @@ spec: - name: workdir-path value: /workspace - name: oci-ref - value: "quay.io/openshift-lightspeed/ols-service-artifacts:$(params.artifact-oci-tag-prefix)$(params.commit)" + value: "quay.io/openshift-lightspeed/ols-operator-artifacts:$(params.commit)" - name: credentials-volume-name value: ols-konflux-artifacts-bot-creds - name: fail-if-any-step-failed @@ -392,6 +379,6 @@ spec: - name: namespace value: $(context.pipelineRun.namespace) - name: quay-repo - value: "quay.io/openshift-lightspeed/ols-service-artifacts" + value: "quay.io/openshift-lightspeed/ols-operator-artifacts" - name: artifact-credentials-secret value: ols-konflux-artifacts-bot diff --git a/.tekton/integration-tests/pipelines/lightspeed-service-integration-test-pipeline-4.16.yaml b/.tekton/integration-tests/pipelines/lightspeed-service-integration-test-pipeline-4.16.yaml deleted file mode 100644 index 0ca422d49..000000000 --- a/.tekton/integration-tests/pipelines/lightspeed-service-integration-test-pipeline-4.16.yaml +++ /dev/null @@ -1,397 +0,0 @@ ---- -apiVersion: tekton.dev/v1beta1 -kind: Pipeline -metadata: - annotations: - pipelinesascode.tekton.dev/task: "[ols-installer, ols-e2e-task]" - name: ols-integration-tests-pipeline -spec: - description: | - Runs OpenShift Lightspeed service integration tests on a HyperShift hosted cluster (openshift-ci): - provision cluster, install the operator via ols-install (OLM bundle or direct per install-mode), - then clone operator + service at related_images - revisions and run tests/scripts/test-e2e-cluster.sh, push artifacts. - - Per OpenShift minor: set openshift-version-prefix (e.g. 4.16.) and test-name. For OCP 4.16 only, - set artifact-oci-tag-prefix to "416" so ols-service-artifacts uses tag 416; leave empty - for other versions. The run step bootstraps git then runs - .tekton/integration-tests/scripts/run-service-integration-tests.sh (openshift-version-prefix - is passed through; install-oc-if-missing.sh supplies the oc client for latest-). - params: - - name: SNAPSHOT - description: 'The JSON string representing the snapshot of the application under test.' - default: '{"components": [{"name":"test-app", "containerImage": "quay.io/example/repo:latest"}]}' - type: string - - name: test-name - description: 'The name of the test corresponding to a defined Konflux integration test.' - default: 'ols-e2e-tests-4.16' - type: string - - name: namespace - description: 'Namespace to run tests in' - default: 'openshift-lightspeed' - type: string - - name: openshift-version-prefix - description: 'OpenShift minor version prefix (include trailing dot, e.g. 4.16.) passed to test scripts.' - default: '4.16.' - type: string - - name: artifact-oci-tag-prefix - description: 'Prepended to commit SHA in ols-service-artifacts Quay tag. Use "416" for OCP 4.16; empty for other minors.' - default: '416' - type: string - - name: install-mode - description: 'Operator install: bundle (OLM) or direct (kustomize; IMG from lightspeed-operator in SNAPSHOT).' - type: string - default: 'bundle' - tasks: - - name: provision-ephemeral-cluster - taskRef: - resolver: git - params: - - name: url - value: https://github.com/openshift/konflux-tasks - - name: revision - value: main - - name: pathInRepo - value: tasks/provision-ephemeral-cluster/0.1/provision-ephemeral-cluster.yaml - params: - - name: ownerName - value: $(context.pipelineRun.name) - - name: ownerUid - value: $(context.pipelineRun.uid) - - name: workflow - value: hypershift-hostedcluster-workflow - - name: clusterProfile - value: aws-konflux-prod - - name: env - value: '{"COMPUTE_NODE_TYPE": "m5.2xlarge", "HYPERSHIFT_NODE_COUNT": "3", "HOSTED_MANAGEMENT_CLUSTER": "hosted-mgmt2"}' - - name: releases - value: '{"latest":{"release":{"channel":"stable","version":"4.16","architecture":"multi"}}}' - - name: ols-install - description: Install operator (OLM bundle or direct); record SNAPSHOT image ref and commit for service tests. - runAfter: - - provision-ephemeral-cluster - params: - - name: SNAPSHOT - value: $(params.SNAPSHOT) - - name: namespace - value: "$(params.namespace)" - - name: install-mode - value: $(params.install-mode) - - name: clusterCredentialsSecretRef - value: $(tasks.provision-ephemeral-cluster.results.secretRef) - taskSpec: - results: - - name: bundle-image - value: "$(steps.get-snapshot-component.results.bundle-image)" - - name: commit - value: "$(steps.get-snapshot-component.results.commit)" - params: - - name: SNAPSHOT - - name: namespace - type: string - - name: install-mode - type: string - default: "bundle" - - name: clusterCredentialsSecretRef - type: string - volumes: - - name: cluster-credentials - secret: - secretName: $(params.clusterCredentialsSecretRef) - steps: - - name: install-operator - env: - - name: SNAPSHOT - value: $(params.SNAPSHOT) - - name: KONFLUX_COMPONENT_NAME - valueFrom: - fieldRef: - fieldPath: metadata.labels['appstudio.openshift.io/component'] - - name: KUBECONFIG - value: "/credentials/kubeconfig" - - name: OLS_NAMESPACE - value: "$(params.namespace)" - volumeMounts: - - name: cluster-credentials - mountPath: /credentials - image: registry.redhat.io/openshift4/ose-cli:latest - script: | - set -euo pipefail - dnf -y install jq python3-pip git curl make golang - COMMIT="$(jq -r --arg component_name "${KONFLUX_COMPONENT_NAME}" '.components[] | select(.name == $component_name) | .source.git.revision' <<< "$SNAPSHOT")" - echo "Cloning lightspeed-operator@${COMMIT} for Konflux operator install" - rm -rf /workspace/lightspeed-operator - mkdir -p /workspace/lightspeed-operator - cd /workspace/lightspeed-operator - git init -q - git remote add origin https://github.com/openshift/lightspeed-operator.git - git fetch --depth 1 origin "${COMMIT}" - git checkout -q FETCH_HEAD - ./.tekton/integration-tests/scripts/run-konflux-operator-install.sh "$(params.install-mode)" - - name: get-snapshot-component - image: registry.redhat.io/openshift4/ose-cli:latest - env: - - name: SNAPSHOT - value: $(params.SNAPSHOT) - - name: KONFLUX_COMPONENT_NAME - valueFrom: - fieldRef: - fieldPath: metadata.labels['appstudio.openshift.io/component'] - results: - - name: bundle-image - type: string - description: "SNAPSHOT containerImage for the PipelineRun-labeled Konflux component (bundle or operator manager image)." - - name: commit - type: string - description: "commit sha to be used to store artifacts" - script: | - dnf -y install jq - echo -n "$(jq -r --arg component_name "${KONFLUX_COMPONENT_NAME}" '.components[] | select(.name == $component_name) | .containerImage' <<< "$SNAPSHOT")" > $(step.results.bundle-image.path) - echo -n "$(jq -r --arg component_name "${KONFLUX_COMPONENT_NAME}" '.components[] | select(.name == $component_name) | .source.git.revision' <<< "$SNAPSHOT")" > $(step.results.commit.path) - - name: ols-service-tests - description: Task to run tests from service repository - params: - - name: SNAPSHOT - value: $(params.SNAPSHOT) - - name: bundleimage - value: $(tasks.ols-install.results.bundle-image) - - name: commit - value: $(tasks.ols-install.results.commit) - - name: namespace - value: "$(params.namespace)" - - name: openshift-version-prefix - value: $(params.openshift-version-prefix) - - name: artifact-oci-tag-prefix - value: $(params.artifact-oci-tag-prefix) - - name: clusterCredentialsSecretRef - value: $(tasks.provision-ephemeral-cluster.results.secretRef) - runAfter: - - ols-install - taskSpec: - params: - - name: SNAPSHOT - - name: bundleimage - description: SNAPSHOT containerImage for the labeled Konflux component (bundle or operator manager image). - - name: commit - - name: namespace - type: string - - name: openshift-version-prefix - type: string - - name: artifact-oci-tag-prefix - type: string - - name: clusterCredentialsSecretRef - type: string - volumes: - - name: azure-openai-token - secret: - secretName: azureopenai-apitoken - - name: azureopenai-entra-id - secret: - secretName: azureopenai-entra-id - - name: bam-token - secret: - secretName: bam-apitoken - - name: openai-token - secret: - secretName: openai - - name: watsonx-token - secret: - secretName: watsonx-apitoken - - name: insights-stage-upload-offline-token - secret: - secretName: insights-stage-upload-offline-token - - name: ols-konflux-artifacts-bot-creds - secret: - secretName: ols-konflux-artifacts-bot - - name: vertex-token - secret: - secretName: vertex-apitoken - - name: bedrock-token - secret: - secretName: bedrock-apitoken - - name: bedrock-role-token - secret: - secretName: bedrock-role-apitoken - - name: cluster-credentials - secret: - secretName: $(params.clusterCredentialsSecretRef) - steps: - - name: run-e2e-tests - onError: continue - resources: - requests: - cpu: '1' - memory: 1Gi - limits: - memory: 10Gi - volumeMounts: - - name: azure-openai-token - mountPath: /var/run/azure_openai - - name: azureopenai-entra-id - mountPath: /var/run/azureopenai-entra-id - - name: bam-token - mountPath: /var/run/bam - - name: openai-token - mountPath: /var/run/openai - - name: watsonx-token - mountPath: /var/run/watsonx - - name: vertex-token - mountPath: /var/run/vertex - - name: bedrock-token - mountPath: /var/run/bedrock - - name: bedrock-role-token - mountPath: /var/run/bedrock-role - - name: insights-stage-upload-offline-token - mountPath: /var/run/insights-stage-upload-offline-token - - name: cluster-credentials - mountPath: /credentials - env: - - name: BAM_PROVIDER_KEY_PATH - value: "/var/run/bam/token" - - name: AZUREOPENAI_PROVIDER_KEY_PATH - value: "/var/run/azure_openai/token" - - name: OPENAI_PROVIDER_KEY_PATH - value: "/var/run/openai/token" - - name: WATSONX_PROVIDER_KEY_PATH - value: "/var/run/watsonx/token" - - name: VERTEX_PROVIDER_KEY_PATH - value: "/var/run/vertex/token" - - name: BEDROCK_AWS_ACCESS_KEY_ID - valueFrom: - secretKeyRef: - name: bedrock-apitoken - key: aws_access_key_id - - name: BEDROCK_AWS_SECRET_ACCESS_KEY - valueFrom: - secretKeyRef: - name: bedrock-apitoken - key: aws_secret_access_key - - name: BEDROCK_ROLE_AWS_ACCESS_KEY_ID - valueFrom: - secretKeyRef: - name: bedrock-role-apitoken - key: aws_access_key_id - - name: BEDROCK_ROLE_AWS_SECRET_ACCESS_KEY - valueFrom: - secretKeyRef: - name: bedrock-role-apitoken - key: aws_secret_access_key - - name: BEDROCK_ROLE_ARN - value: "arn:aws:iam::103138678430:role/BedrockAccessRole" - - name: KUBECONFIG - value: "/credentials/kubeconfig" - - name: ARTIFACT_DIR - value: "/workspace/artifacts" - - name: SUITE_ID - value: "nosuite" - - name: KONFLUX_BOOL - value: "true" - - name: OLS_IMAGE - value: "" - - name: BUNDLE_IMAGE - value: "$(params.bundleimage)" - - name: BUNDLE_COMMIT_SHA - value: "$(params.commit)" - - name: OLS_NAMESPACE - value: "$(params.namespace)" - image: registry.access.redhat.com/ubi9/ubi-minimal - script: | - set -euo pipefail - microdnf -y install git make python3.11 python3.11-devel python3.11-pip shadow-utils tar jq - git init lightspeed-operator - cd lightspeed-operator - git remote add origin https://github.com/openshift/lightspeed-operator.git - git fetch --depth=1 origin "${BUNDLE_COMMIT_SHA}" - git checkout "${BUNDLE_COMMIT_SHA}" - bash .tekton/integration-tests/scripts/run-service-integration-tests.sh "$(params.openshift-version-prefix)" - - name: gather-cluster-resources - onError: continue - ref: - resolver: git - params: - - name: url - value: https://github.com/openshift/lightspeed-operator - - name: revision - value: $(params.commit) - - name: pathInRepo - value: .tekton/integration-tests/stepactions/gather-cluster-resources/0.1/gather-cluster-resources.yaml - params: - - name: credentials - value: "cluster-credentials" - - name: kubeconfig - value: "kubeconfig" - - name: artifact-dir - value: "/workspace/konflux-artifacts" - - name: gather-script-url - value: "https://raw.githubusercontent.com/openshift/lightspeed-operator/$(params.commit)/.tekton/integration-tests/scripts/gather-extra.sh" - # validate that the cluster resources are available in another tekton step - - name: list-artifacts - onError: continue - image: quay.io/konflux-qe-incubator/konflux-qe-tools:latest - workingDir: "/workspace" - script: | - #!/bin/bash - ls -la /workspace - - name: push-artifacts - onError: continue - ref: - resolver: git - params: - - name: url - value: https://github.com/konflux-ci/tekton-integration-catalog.git - - name: revision - value: main - - name: pathInRepo - value: stepactions/secure-push-oci/0.1/secure-push-oci.yaml - params: - - name: workdir-path - value: /workspace - - name: oci-ref - value: "quay.io/openshift-lightspeed/ols-service-artifacts:$(params.artifact-oci-tag-prefix)$(params.commit)" - - name: credentials-volume-name - value: ols-konflux-artifacts-bot-creds - - name: fail-if-any-step-failed - ref: - resolver: git - params: - - name: url - value: https://github.com/konflux-ci/tekton-integration-catalog.git - - name: revision - value: main - - name: pathInRepo - value: stepactions/fail-if-any-step-failed/0.1/fail-if-any-step-failed.yaml - finally: - - name: deprovision-ephemeral-cluster - taskRef: - resolver: git - params: - - name: url - value: https://github.com/openshift/konflux-tasks - - name: revision - value: main - - name: pathInRepo - value: tasks/deprovision-ephemeral-cluster/0.1/deprovision-ephemeral-cluster.yaml - params: - - name: testPlatformClusterClaimName - value: $(tasks.provision-ephemeral-cluster.results.testPlatformClusterClaimName) - - name: testPlatformClusterClaimNamespace - value: $(tasks.provision-ephemeral-cluster.results.testPlatformClusterClaimNamespace) - - name: export-logs-for-retention - taskRef: - resolver: git - params: - - name: url - value: https://github.com/konflux-ci/tekton-integration-catalog.git - - name: revision - value: main - - name: pathInRepo - value: tasks/export-logs/0.1/export-logs-to-quay.yaml - params: - - name: pipeline-run-name - value: $(context.pipelineRun.name) - - name: namespace - value: $(context.pipelineRun.namespace) - - name: quay-repo - value: "quay.io/openshift-lightspeed/ols-service-artifacts" - - name: artifact-credentials-secret - value: ols-konflux-artifacts-bot diff --git a/.tekton/integration-tests/pipelines/lightspeed-service-integration-test-pipeline-4.17.yaml b/.tekton/integration-tests/pipelines/lightspeed-service-integration-test-pipeline.yaml similarity index 98% rename from .tekton/integration-tests/pipelines/lightspeed-service-integration-test-pipeline-4.17.yaml rename to .tekton/integration-tests/pipelines/lightspeed-service-integration-test-pipeline.yaml index 866f83a6c..ebe03167a 100644 --- a/.tekton/integration-tests/pipelines/lightspeed-service-integration-test-pipeline-4.17.yaml +++ b/.tekton/integration-tests/pipelines/lightspeed-service-integration-test-pipeline.yaml @@ -24,15 +24,15 @@ spec: type: string - name: test-name description: 'The name of the test corresponding to a defined Konflux integration test.' - default: 'ols-e2e-tests-4.17' + default: 'ols-e2e-tests' type: string - name: namespace description: 'Namespace to run tests in' default: 'openshift-lightspeed' type: string - name: openshift-version-prefix - description: 'OpenShift minor version prefix (include trailing dot, e.g. 4.17.) passed to test scripts.' - default: '4.17.' + description: 'OpenShift minor version to provision (for example, 4.22).' + default: '4.22' type: string - name: artifact-oci-tag-prefix description: 'Prepended to commit SHA in ols-service-artifacts Quay tag. Use "416" for OCP 4.16; empty for other minors.' @@ -65,7 +65,7 @@ spec: - name: env value: '{"COMPUTE_NODE_TYPE": "m5.2xlarge", "HYPERSHIFT_NODE_COUNT": "3", "HOSTED_MANAGEMENT_CLUSTER": "hosted-mgmt2"}' - name: releases - value: '{"latest":{"release":{"channel":"stable","version":"4.17","architecture":"multi"}}}' + value: '{"latest":{"release":{"channel":"stable","version":"$(params.openshift-version-prefix)","architecture":"multi"}}}' - name: ols-install description: Install operator (OLM bundle or direct); record SNAPSHOT image ref and commit for service tests. runAfter: @@ -160,7 +160,7 @@ spec: - name: namespace value: "$(params.namespace)" - name: openshift-version-prefix - value: $(params.openshift-version-prefix) + value: "$(params.openshift-version-prefix)." - name: artifact-oci-tag-prefix value: $(params.artifact-oci-tag-prefix) - name: clusterCredentialsSecretRef @@ -361,21 +361,6 @@ spec: - name: pathInRepo value: stepactions/fail-if-any-step-failed/0.1/fail-if-any-step-failed.yaml finally: - - name: deprovision-ephemeral-cluster - taskRef: - resolver: git - params: - - name: url - value: https://github.com/openshift/konflux-tasks - - name: revision - value: main - - name: pathInRepo - value: tasks/deprovision-ephemeral-cluster/0.1/deprovision-ephemeral-cluster.yaml - params: - - name: testPlatformClusterClaimName - value: $(tasks.provision-ephemeral-cluster.results.testPlatformClusterClaimName) - - name: testPlatformClusterClaimNamespace - value: $(tasks.provision-ephemeral-cluster.results.testPlatformClusterClaimNamespace) - name: export-logs-for-retention taskRef: resolver: git @@ -395,3 +380,18 @@ spec: value: "quay.io/openshift-lightspeed/ols-service-artifacts" - name: artifact-credentials-secret value: ols-konflux-artifacts-bot + - name: deprovision-ephemeral-cluster + taskRef: + resolver: git + params: + - name: url + value: https://github.com/openshift/konflux-tasks + - name: revision + value: main + - name: pathInRepo + value: tasks/deprovision-ephemeral-cluster/0.1/deprovision-ephemeral-cluster.yaml + params: + - name: testPlatformClusterClaimName + value: $(tasks.provision-ephemeral-cluster.results.testPlatformClusterClaimName) + - name: testPlatformClusterClaimNamespace + value: $(tasks.provision-ephemeral-cluster.results.testPlatformClusterClaimNamespace) diff --git a/.tekton/integration-tests/pipelines/rapidast-scan.yaml b/.tekton/integration-tests/pipelines/rapidast-scan.yaml index 5e765ff5f..c1354be13 100644 --- a/.tekton/integration-tests/pipelines/rapidast-scan.yaml +++ b/.tekton/integration-tests/pipelines/rapidast-scan.yaml @@ -28,80 +28,44 @@ spec: default: 'openshift-lightspeed' type: string - name: openshift-version-prefix - description: 'Minor line prefix for eaas-get-latest-openshift-version-by-prefix (include trailing dot, e.g. 4.16.)' - default: '4.16.' + description: 'OpenShift minor version to provision (for example, 4.22).' + default: '4.22' type: string tasks: - - name: eaas-provision-space + - name: provision-ephemeral-cluster taskRef: resolver: git params: - name: url - value: https://github.com/konflux-ci/build-definitions.git + value: https://github.com/openshift/konflux-tasks - name: revision value: main - name: pathInRepo - value: task/eaas-provision-space/0.1/eaas-provision-space.yaml + value: tasks/provision-ephemeral-cluster/0.1/provision-ephemeral-cluster.yaml params: - - name: ownerKind - value: PipelineRun - name: ownerName value: $(context.pipelineRun.name) - name: ownerUid value: $(context.pipelineRun.uid) - - name: provision-cluster - runAfter: - - eaas-provision-space - params: - - name: openshift-version-prefix - value: $(params.openshift-version-prefix) - taskSpec: - params: - - name: openshift-version-prefix - type: string - results: - - name: clusterName - value: "$(steps.create-cluster.results.clusterName)" - steps: - - name: pick-version - ref: - resolver: git - params: - - name: url - value: https://github.com/konflux-ci/build-definitions.git - - name: revision - value: main - - name: pathInRepo - value: stepactions/eaas-get-latest-openshift-version-by-prefix/0.1/eaas-get-latest-openshift-version-by-prefix.yaml - params: - - name: prefix - value: "$(params.openshift-version-prefix)" - - name: create-cluster - ref: - resolver: git - params: - - name: url - value: https://github.com/konflux-ci/build-definitions.git - - name: revision - value: main - - name: pathInRepo - value: stepactions/eaas-create-ephemeral-cluster-hypershift-aws/0.1/eaas-create-ephemeral-cluster-hypershift-aws.yaml - params: - - name: eaasSpaceSecretRef - value: $(tasks.eaas-provision-space.results.secretRef) - - name: version - value: "$(steps.pick-version.results.version)" - - name: instanceType - value: "m5.2xlarge" + - name: workflow + value: hypershift-hostedcluster-workflow + - name: clusterProfile + value: aws-konflux-prod + - name: env + value: '{"COMPUTE_NODE_TYPE": "m5.2xlarge", "HYPERSHIFT_NODE_COUNT": "3", "HOSTED_MANAGEMENT_CLUSTER": "hosted-mgmt2"}' + - name: releases + value: '{"latest":{"release":{"channel":"stable","version":"$(params.openshift-version-prefix)","architecture":"multi"}}}' - name: ols-install description: Install operator via OLM bundle (Rapidast); calls run-konflux-operator-install.sh bundle only. runAfter: - - provision-cluster + - provision-ephemeral-cluster params: - name: SNAPSHOT value: $(params.SNAPSHOT) - name: namespace value: "$(params.namespace)" + - name: clusterCredentialsSecretRef + value: $(tasks.provision-ephemeral-cluster.results.secretRef) taskSpec: results: - name: bundle-image @@ -112,27 +76,13 @@ spec: - name: SNAPSHOT - name: namespace type: string + - name: clusterCredentialsSecretRef + type: string volumes: - - name: credentials - emptyDir: {} + - name: cluster-credentials + secret: + secretName: $(params.clusterCredentialsSecretRef) steps: - - name: get-kubeconfig - ref: - resolver: git - params: - - name: url - value: https://github.com/konflux-ci/build-definitions.git - - name: revision - value: main - - name: pathInRepo - value: stepactions/eaas-get-ephemeral-cluster-credentials/0.1/eaas-get-ephemeral-cluster-credentials.yaml - params: - - name: eaasSpaceSecretRef - value: $(tasks.eaas-provision-space.results.secretRef) - - name: clusterName - value: "$(tasks.provision-cluster.results.clusterName)" - - name: credentials - value: credentials - name: get-snapshot-component image: registry.redhat.io/openshift4/ose-cli:latest env: @@ -162,13 +112,13 @@ spec: fieldRef: fieldPath: metadata.labels['appstudio.openshift.io/component'] - name: KUBECONFIG - value: "/credentials/$(steps.get-kubeconfig.results.kubeconfig)" + value: "/credentials/kubeconfig" - name: OLS_NAMESPACE value: "$(params.namespace)" - name: IMAGE_DIGEST_MIRROR_SET_URL value: "https://raw.githubusercontent.com/openshift/lightspeed-operator/main/config/manager/imagedigestmirrorset.yaml" volumeMounts: - - name: credentials + - name: cluster-credentials mountPath: /credentials image: registry.redhat.io/openshift4/ose-cli:latest script: | @@ -189,47 +139,33 @@ spec: params: - name: commit value: $(tasks.ols-install.results.commit) + - name: clusterCredentialsSecretRef + value: $(tasks.provision-ephemeral-cluster.results.secretRef) runAfter: - ols-install taskSpec: params: - name: commit type: string + - name: clusterCredentialsSecretRef + type: string volumes: - name: openai-token secret: secretName: openai - - name: credentials - emptyDir: {} + - name: cluster-credentials + secret: + secretName: $(params.clusterCredentialsSecretRef) steps: - - name: get-kubeconfig - ref: - resolver: git - params: - - name: url - value: https://github.com/konflux-ci/build-definitions.git - - name: revision - value: main - - name: pathInRepo - value: stepactions/eaas-get-ephemeral-cluster-credentials/0.1/eaas-get-ephemeral-cluster-credentials.yaml - params: - - name: eaasSpaceSecretRef - value: $(tasks.eaas-provision-space.results.secretRef) - - name: clusterName - value: "$(tasks.provision-cluster.results.clusterName)" - - name: credentials - value: credentials - name: run-e2e-tests volumeMounts: - name: openai-token mountPath: /var/run/openai - - name: credentials + - name: cluster-credentials mountPath: /credentials env: - name: KUBECONFIG - value: "/credentials/$(steps.get-kubeconfig.results.kubeconfig)" - - name: CONSOLE_URL - value: "$(steps.get-kubeconfig.results.consoleURL)" + value: "/credentials/kubeconfig" - name: LLM_TOKEN_PATH value: "/var/run/openai/token" - name: COMMIT_SHA @@ -239,7 +175,8 @@ spec: set -euo pipefail echo "---------------------------------------------" export LLM_TOKEN=$(cat ${LLM_TOKEN_PATH}) - echo $CONSOLE_URL + CONSOLE_URL="https://$(oc get route console -n openshift-console -o jsonpath='{.spec.host}')" + echo "Cluster Console: ${CONSOLE_URL}" echo "---------------------------------------------" dnf -y install git make jq curl -Lo /go.tar.gz https://go.dev/dl/go1.23.4.linux-amd64.tar.gz @@ -260,3 +197,20 @@ spec: echo "---------------------------------------------" dnf -y install podman podman run -v ./ols-rapidast-config-updated.yaml:/opt/rapidast/config/config.yaml:Z quay.io/redhatproductsecurity/rapidast:latest ./rapidast.py + + finally: + - name: deprovision-ephemeral-cluster + taskRef: + resolver: git + params: + - name: url + value: https://github.com/openshift/konflux-tasks + - name: revision + value: main + - name: pathInRepo + value: tasks/deprovision-ephemeral-cluster/0.1/deprovision-ephemeral-cluster.yaml + params: + - name: testPlatformClusterClaimName + value: $(tasks.provision-ephemeral-cluster.results.testPlatformClusterClaimName) + - name: testPlatformClusterClaimNamespace + value: $(tasks.provision-ephemeral-cluster.results.testPlatformClusterClaimNamespace) diff --git a/.tekton/lightspeed-operator-pull-request.yaml b/.tekton/lightspeed-operator-pull-request.yaml index 99cfbcdea..7fbbafa43 100644 --- a/.tekton/lightspeed-operator-pull-request.yaml +++ b/.tekton/lightspeed-operator-pull-request.yaml @@ -10,7 +10,7 @@ metadata: pipelinesascode.tekton.dev/on-cel-expression: | event == "pull_request" && target_branch == "main" && - (".tekton/lightspeed-operator-pull-request.yaml".pathChanged() || "Dockerfile".pathChanged() || "LICENSE".pathChanged() || "go.*".pathChanged() || "cmd/***".pathChanged() || "api/***".pathChanged() || "internal/***".pathChanged() || "test/***".pathChanged() || "hack/install/***".pathChanged()) + (".tekton/lightspeed-operator-pull-request.yaml".pathChanged() || ".tekton/integration-tests/pipelines/***".pathChanged() || "Dockerfile".pathChanged() || "LICENSE".pathChanged() || "go.*".pathChanged() || "cmd/***".pathChanged() || "api/***".pathChanged() || "internal/***".pathChanged() || "test/***".pathChanged() || "hack/install/***".pathChanged()) creationTimestamp: labels: appstudio.openshift.io/application: ols diff --git a/.tekton/lightspeed-operator-push.yaml b/.tekton/lightspeed-operator-push.yaml index b7895f2ba..4d4573c14 100644 --- a/.tekton/lightspeed-operator-push.yaml +++ b/.tekton/lightspeed-operator-push.yaml @@ -9,7 +9,7 @@ metadata: pipelinesascode.tekton.dev/on-cel-expression: | event == "push" && target_branch == "main" && - (".tekton/lightspeed-operator-push.yaml".pathChanged() || "Dockerfile".pathChanged() || "LICENSE".pathChanged() || "go.*".pathChanged() || "cmd/***".pathChanged() || "api/***".pathChanged() || "internal/***".pathChanged() || "test/***".pathChanged()) + (".tekton/lightspeed-operator-push.yaml".pathChanged() || ".tekton/integration-tests/pipelines/***".pathChanged() || "Dockerfile".pathChanged() || "LICENSE".pathChanged() || "go.*".pathChanged() || "cmd/***".pathChanged() || "api/***".pathChanged() || "internal/***".pathChanged() || "test/***".pathChanged()) creationTimestamp: labels: appstudio.openshift.io/application: ols diff --git a/.tekton/ols-bundle-pull-request.yaml b/.tekton/ols-bundle-pull-request.yaml index 33655f0bd..e7bd63c26 100644 --- a/.tekton/ols-bundle-pull-request.yaml +++ b/.tekton/ols-bundle-pull-request.yaml @@ -11,7 +11,7 @@ metadata: pipelinesascode.tekton.dev/on-cel-expression: | event == "pull_request" && target_branch == "main" && - (".tekton/ols-bundle-pull-request.yaml".pathChanged() || "bundle/***".pathChanged() || "bundle.Dockerfile".pathChanged() || + (".tekton/ols-bundle-pull-request.yaml".pathChanged() || ".tekton/integration-tests/pipelines/***".pathChanged() || "bundle/***".pathChanged() || "bundle.Dockerfile".pathChanged() || "related_images.json".pathChanged()) creationTimestamp: labels: diff --git a/.tekton/ols-bundle-push.yaml b/.tekton/ols-bundle-push.yaml index 3c05088b9..4334d9c21 100644 --- a/.tekton/ols-bundle-push.yaml +++ b/.tekton/ols-bundle-push.yaml @@ -10,7 +10,7 @@ metadata: pipelinesascode.tekton.dev/on-cel-expression: | event == "push" && target_branch == "main" && - (".tekton/ols-bundle-push.yaml".pathChanged() || "bundle/***".pathChanged() || "bundle.Dockerfile".pathChanged() || + (".tekton/ols-bundle-push.yaml".pathChanged() || ".tekton/integration-tests/pipelines/***".pathChanged() || "bundle/***".pathChanged() || "bundle.Dockerfile".pathChanged() || "related_images.json".pathChanged()) creationTimestamp: labels: