Skip to content

OCPBUGS-42434: Enable Managed Identity w/ Certificates in HyperShift Control Plane Components#5160

Merged
openshift-merge-bot[bot] merged 6 commits into
openshift:mainfrom
bryan-cox:OCPBUGS-42434-combined
Dec 4, 2024
Merged

OCPBUGS-42434: Enable Managed Identity w/ Certificates in HyperShift Control Plane Components#5160
openshift-merge-bot[bot] merged 6 commits into
openshift:mainfrom
bryan-cox:OCPBUGS-42434-combined

Conversation

@bryan-cox
Copy link
Copy Markdown
Member

@bryan-cox bryan-cox commented Nov 20, 2024

What this PR does / why we need it:
This PR enables components in the hosted control plane to authenticate with Azure Cloud through client certificate. These components include:

  1. KMS
  2. CPO
  3. CAPZ
  4. Cloud Provider

Which issue(s) this PR fixes:
Fixes OCPBUGS-42434

Checklist

  • Subject and description added to both, commit and PR.
  • Relevant issues have been referenced.
  • This change includes docs.
  • This change includes unit tests.

@openshift-ci openshift-ci Bot added the do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. label Nov 20, 2024
@openshift-ci
Copy link
Copy Markdown
Contributor

openshift-ci Bot commented Nov 20, 2024

Skipping CI for Draft Pull Request.
If you want CI signal for your change, please convert it to an actual PR.
You can still manually trigger a test run with /test all

@openshift-ci openshift-ci Bot added do-not-merge/needs-area area/api Indicates the PR includes changes for the API labels Nov 20, 2024
@openshift-ci
Copy link
Copy Markdown
Contributor

openshift-ci Bot commented Nov 20, 2024

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: bryan-cox

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci openshift-ci Bot added area/cli Indicates the PR includes changes for CLI approved Indicates a PR has been approved by an approver from all required OWNERS files. area/control-plane-operator Indicates the PR includes changes for the control plane operator - in an OCP release area/hypershift-operator Indicates the PR includes changes for the hypershift operator and API - outside an OCP release area/testing Indicates the PR includes changes for e2e testing and removed do-not-merge/needs-area labels Nov 20, 2024
@netlify
Copy link
Copy Markdown

netlify Bot commented Nov 20, 2024

Deploy Preview for hypershift-docs ready!

Name Link
🔨 Latest commit ef8852b
🔍 Latest deploy log https://app.netlify.com/sites/hypershift-docs/deploys/673dd254c493be0008a659e4
😎 Deploy Preview https://deploy-preview-5160--hypershift-docs.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify site configuration.

@bryan-cox bryan-cox force-pushed the OCPBUGS-42434-combined branch 4 times, most recently from 7cdb04d to 3ce0090 Compare November 20, 2024 03:05
@bryan-cox bryan-cox marked this pull request as ready for review November 20, 2024 03:05
@openshift-ci openshift-ci Bot removed the do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. label Nov 20, 2024
@openshift-ci openshift-ci Bot requested review from enxebre and hasueki November 20, 2024 03:06
@bryan-cox bryan-cox force-pushed the OCPBUGS-42434-combined branch from 3ce0090 to ef8852b Compare November 20, 2024 12:13
@bryan-cox bryan-cox changed the title Ocpbugs 42434 combined OCPBUGS-42434: Enable Managed Identity w/ Certificates in HyperShift Control Plane Components Nov 20, 2024
@openshift-ci-robot openshift-ci-robot added jira/severity-important Referenced Jira bug's severity is important for the branch this PR is targeting. jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. labels Nov 20, 2024
@openshift-ci-robot
Copy link
Copy Markdown

@bryan-cox: This pull request references Jira Issue OCPBUGS-42434, which is valid.

3 validation(s) were run on this bug
  • bug is open, matching expected state (open)
  • bug target version (4.18.0) matches configured target version for branch (4.18.0)
  • bug is in the state POST, which is one of the valid states (NEW, ASSIGNED, POST)

Requesting review from QA contact:
/cc @fxierh

The bug has been updated to refer to the pull request using the external bug tracker.

Details

In response to this:

What this PR does / why we need it:

Which issue(s) this PR fixes (optional, use fixes #<issue_number>(, fixes #<issue_number>, ...) format, where issue_number might be a GitHub issue, or a Jira story:
Fixes #

Checklist

  • Subject and description added to both, commit and PR.
  • Relevant issues have been referenced.
  • This change includes docs.
  • This change includes unit tests.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@bryan-cox bryan-cox force-pushed the OCPBUGS-42434-combined branch from d3f443f to 33cebed Compare December 2, 2024 20:16
@bryan-cox
Copy link
Copy Markdown
Member Author

/retest

}

// Reconcile the SecretProviderClass
nodepoolMgmtSecretProviderClass := manifests.ManagedAzureSecretProviderClass(config.ManagedAzureNodePoolMgmtSecretProviderClassName, controlPlaneNamespace)
Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nit: nodePool

@enxebre
Copy link
Copy Markdown
Member

enxebre commented Dec 3, 2024

/lgtm

@openshift-ci openshift-ci Bot added the lgtm Indicates that a PR is ready to be merged. label Dec 3, 2024
@openshift-ci-robot
Copy link
Copy Markdown

/retest-required

Remaining retests: 0 against base HEAD e9fec4b and 2 for PR HEAD 33cebed in total

@bryan-cox
Copy link
Copy Markdown
Member Author

/test e2e-aws-4-18

@bryan-cox
Copy link
Copy Markdown
Member Author

/retest-required

4 similar comments
@bryan-cox
Copy link
Copy Markdown
Member Author

/retest-required

@bryan-cox
Copy link
Copy Markdown
Member Author

/retest-required

@bryan-cox
Copy link
Copy Markdown
Member Author

/retest-required

@bryan-cox
Copy link
Copy Markdown
Member Author

/retest-required

@openshift-ci-robot
Copy link
Copy Markdown

/retest-required

Remaining retests: 0 against base HEAD e9fec4b and 2 for PR HEAD 33cebed in total

1 similar comment
@openshift-ci-robot
Copy link
Copy Markdown

/retest-required

Remaining retests: 0 against base HEAD e9fec4b and 2 for PR HEAD 33cebed in total

@openshift-ci
Copy link
Copy Markdown
Contributor

openshift-ci Bot commented Dec 4, 2024

@bryan-cox: The following tests failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test name Commit Details Required Rerun command
ci/prow/e2e-aws-4-17 ce31d49 link true /test e2e-aws-4-17
ci/prow/e2e-aks 33cebed link false /test e2e-aks

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

@openshift-ci-robot
Copy link
Copy Markdown

/retest-required

Remaining retests: 0 against base HEAD e9fec4b and 2 for PR HEAD 33cebed in total

1 similar comment
@openshift-ci-robot
Copy link
Copy Markdown

/retest-required

Remaining retests: 0 against base HEAD e9fec4b and 2 for PR HEAD 33cebed in total

@enxebre
Copy link
Copy Markdown
Member

enxebre commented Dec 4, 2024

/override ci/prow/e2e-kubevirt-aws-ovn-reduced

@openshift-ci
Copy link
Copy Markdown
Contributor

openshift-ci Bot commented Dec 4, 2024

@enxebre: Overrode contexts on behalf of enxebre: ci/prow/e2e-kubevirt-aws-ovn-reduced

Details

In response to this:

/override ci/prow/e2e-kubevirt-aws-ovn-reduced

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@openshift-merge-bot openshift-merge-bot Bot merged commit 857ccab into openshift:main Dec 4, 2024
@openshift-ci-robot
Copy link
Copy Markdown

@bryan-cox: Jira Issue OCPBUGS-42434: All pull requests linked via external trackers have merged:

Jira Issue OCPBUGS-42434 has been moved to the MODIFIED state.

Details

In response to this:

What this PR does / why we need it:
This PR enables components in the hosted control plane to authenticate with Azure Cloud through client certificate. These components include:

  1. KMS
  2. CPO
  3. CAPZ
  4. Cloud Provider

Which issue(s) this PR fixes:
Fixes OCPBUGS-42434

Checklist

  • Subject and description added to both, commit and PR.
  • Relevant issues have been referenced.
  • This change includes docs.
  • This change includes unit tests.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@bryan-cox bryan-cox deleted the OCPBUGS-42434-combined branch December 4, 2024 14:52
@bryan-cox
Copy link
Copy Markdown
Member Author

/cherry-pick release-4.18

@openshift-cherrypick-robot
Copy link
Copy Markdown

@bryan-cox: #5160 failed to apply on top of branch "release-4.18":

Applying: Authenticate Azure KMS with cert authentication
Applying: Reconcile SecretProvider for CPO on ARO HCP
Using index info to reconstruct a base tree...
M	cmd/infra/azure/create.go
M	control-plane-operator/controllers/hostedcontrolplane/hostedcontrolplane_controller.go
M	hypershift-operator/controllers/hostedcluster/hostedcluster_controller.go
Falling back to patching base and 3-way merge...
Auto-merging hypershift-operator/controllers/hostedcluster/hostedcluster_controller.go
Auto-merging control-plane-operator/controllers/hostedcontrolplane/hostedcontrolplane_controller.go
Auto-merging cmd/infra/azure/create.go
Applying: Update go.mod to include cert changes for CAPZ
Applying: Authenticate CAPZ with cert authentication
Using index info to reconstruct a base tree...
M	cmd/infra/azure/create.go
M	hypershift-operator/controllers/hostedcluster/internal/platform/azure/azure.go
Falling back to patching base and 3-way merge...
Auto-merging hypershift-operator/controllers/hostedcluster/internal/platform/azure/azure.go
Auto-merging cmd/infra/azure/create.go
CONFLICT (content): Merge conflict in cmd/infra/azure/create.go
error: Failed to merge in the changes.
hint: Use 'git am --show-current-patch=diff' to see the failed patch
hint: When you have resolved this problem, run "git am --continue".
hint: If you prefer to skip this patch, run "git am --skip" instead.
hint: To restore the original branch and stop patching, run "git am --abort".
hint: Disable this message with "git config advice.mergeConflict false"
Patch failed at 0004 Authenticate CAPZ with cert authentication

Details

In response to this:

/cherry-pick release-4.18

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@bryan-cox
Copy link
Copy Markdown
Member Author

/jira backport release-4.18

@openshift-ci-robot
Copy link
Copy Markdown

@bryan-cox: The following backport issues have been created:

Queuing cherrypicks to the requested branches to be created after this PR merges:
/cherrypick release-4.18

Details

In response to this:

/jira backport release-4.18

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-cherrypick-robot
Copy link
Copy Markdown

@openshift-ci-robot: #5160 failed to apply on top of branch "release-4.18":

Applying: Authenticate Azure KMS with cert authentication
Applying: Reconcile SecretProvider for CPO on ARO HCP
Using index info to reconstruct a base tree...
M	cmd/infra/azure/create.go
M	control-plane-operator/controllers/hostedcontrolplane/hostedcontrolplane_controller.go
M	hypershift-operator/controllers/hostedcluster/hostedcluster_controller.go
Falling back to patching base and 3-way merge...
Auto-merging hypershift-operator/controllers/hostedcluster/hostedcluster_controller.go
Auto-merging control-plane-operator/controllers/hostedcontrolplane/hostedcontrolplane_controller.go
Auto-merging cmd/infra/azure/create.go
Applying: Update go.mod to include cert changes for CAPZ
Applying: Authenticate CAPZ with cert authentication
Using index info to reconstruct a base tree...
M	cmd/infra/azure/create.go
M	hypershift-operator/controllers/hostedcluster/internal/platform/azure/azure.go
Falling back to patching base and 3-way merge...
Auto-merging hypershift-operator/controllers/hostedcluster/internal/platform/azure/azure.go
Auto-merging cmd/infra/azure/create.go
CONFLICT (content): Merge conflict in cmd/infra/azure/create.go
error: Failed to merge in the changes.
hint: Use 'git am --show-current-patch=diff' to see the failed patch
hint: When you have resolved this problem, run "git am --continue".
hint: If you prefer to skip this patch, run "git am --skip" instead.
hint: To restore the original branch and stop patching, run "git am --abort".
hint: Disable this message with "git config advice.mergeConflict false"
Patch failed at 0004 Authenticate CAPZ with cert authentication

Details

In response to this:

@bryan-cox: The following backport issues have been created:

Queuing cherrypicks to the requested branches to be created after this PR merges:
/cherrypick release-4.18

In response to this:

/jira backport release-4.18

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@openshift-bot
Copy link
Copy Markdown

[ART PR BUILD NOTIFIER]

Distgit: hypershift
This PR has been included in build ose-hypershift-container-v4.19.0-202412041809.p0.g857ccab.assembly.stream.el9.
All builds following this will include this PR.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. area/api Indicates the PR includes changes for the API area/cli Indicates the PR includes changes for CLI area/control-plane-operator Indicates the PR includes changes for the control plane operator - in an OCP release area/hypershift-operator Indicates the PR includes changes for the hypershift operator and API - outside an OCP release area/testing Indicates the PR includes changes for e2e testing jira/severity-important Referenced Jira bug's severity is important for the branch this PR is targeting. jira/valid-bug Indicates that a referenced Jira bug is valid for the branch this PR is targeting. jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. lgtm Indicates that a PR is ready to be merged.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

8 participants