[WIP] NE-2789: Creating 5 origin tests to graduate featuregate#31392
[WIP] NE-2789: Creating 5 origin tests to graduate featuregate#31392rhamini3 wants to merge 7 commits into
Conversation
|
Pipeline controller notification For optional jobs, comment This repository is configured in: automatic mode |
|
@rhamini3: This pull request references NE-2789 which is a valid jira issue. Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the story to target the "5.0.0" version, but no target version was set. DetailsIn response to this: Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
WalkthroughChangesAdds gated extended router tests covering HAProxy version validation, defaults, updates, and isolation. It also adds a delayed Python server Pod manifest with static OVN networking and updates the OpenShift API module revision. HAProxy version selection tests
Estimated code review effort: 4 (Complex) | ~45 minutes Sequence Diagram(s)sequenceDiagram
participant TestSuite
participant IngressController
participant RouterDeployment
participant HAProxy
TestSuite->>IngressController: create or patch haproxyVersion
IngressController->>RouterDeployment: reconcile router deployment
RouterDeployment->>HAProxy: run configured version
TestSuite->>HAProxy: exec show version
HAProxy-->>TestSuite: report runtime version
Suggested reviewers: 🚥 Pre-merge checks | ✅ 12 | ❌ 3❌ Failed checks (3 warnings)
✅ Passed checks (12 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
There was a problem hiding this comment.
Actionable comments posted: 10
🧹 Nitpick comments (2)
~ (2)
50-51: 🩺 Stability & Availability | 🔵 Trivial | ⚡ Quick winPin the backend image for repeatable e2e runs.
The image resolves to mutable
:latest, whileAlwayspulls it on every start. Registry changes can alter or break the test independently of this PR. Use an approved immutable digest and matching pull policy.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In @~ around lines 50 - 51, Update the backend container image configuration to use an approved immutable image digest instead of the mutable latest tag, and set imagePullPolicy to match the immutable reference so e2e runs remain repeatable.
52-58: 🩺 Stability & Availability | 🔵 Trivial | ⚡ Quick winAdd a readiness probe for port 8080.
Without a probe, Kubernetes can mark the container ready before
HTTPServerhas bound the port, allowing initial Route/Service requests to fail. Prefer a TCP probe because the handler intentionally delays HTTP responses.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In @~ around lines 52 - 58, Add a TCP readiness probe to the slow-server container targeting port 8080, using the existing Kubernetes probe configuration location near ports and resources. Ensure readiness is reported only after the HTTPServer has bound the port, without using an HTTP probe.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @~:
- Around line 8-30: Replace the live-cluster Pod snapshot with a minimal
desired-state fixture, removing OVN/network annotations, generated metadata,
nodeName, namespace-specific pull secrets and service-account volumes, plus the
full status block. Retain only fields required to define the slow-server Pod,
and let the test framework/API server assign name, namespace, metadata, and
runtime state across the affected fixture sections.
- Around line 33-49: Fix the embedded Python command in the fixture’s args
definition by representing the script as a valid YAML block scalar rather than
an unstructured quoted value. Remove leading indentation from Python top-level
statements while preserving the SlowHandler behavior and HTTP server startup,
and apply the same correction to the corresponding second fixture block.
- Around line 59-62: Disable service-account token mounting in the fixture
workloads by setting automountServiceAccountToken to false and removing the
explicit kube-api-access token volumeMounts and corresponding volume definitions
from all referenced sections. Preserve the existing HTTP server configuration
and other volume mounts.
In `@go.mod`:
- Around line 96-101: Update the go.mod dependency entries for
golang.org/x/crypto and golang.org/x/net to patched releases that address the
referenced OSV advisories, while leaving the surrounding module versions
unchanged.
In `@test/extended/router/multi-haproxy.go`:
- Around line 100-116: The HAProxy version test currently validates the
IngressController Spec rather than the custom router’s runtime version. In
test/extended/router/multi-haproxy.go:100-116, query the custom controller’s
effective status and HAProxy admin socket to verify the running version; in
test/extended/router/multi-haproxy.go:120-135, run the checks against
deploy/router-<custom-controller-name> instead of deploy/router-default.
- Around line 329-374: Update the resource setup flow around the Pod and Route
creation in the helper to wait for the Pod Ready condition before proceeding,
then poll the created Route until its status contains an admitted ingress with a
non-empty host. Refresh the Route from the API during polling and return that
refreshed object instead of the initial create response, while preserving
existing error propagation.
- Around line 139-145: Update the cleanup for this spec around the default
IngressController setup to capture its original HAProxyVersion and restore it in
bounded cleanup after the test, since existing AfterEach only removes custom
controllers. Also use the object returned by Patch or refetch the default
controller before asserting HAProxyVersion is empty, rather than checking the
stale ingressDefault object.
- Around line 42-57: Update the teardown context setup around ctx and the
g.AfterEach cleanup to derive the operational context from the spec context
rather than context.Background(). For deletion, use context.WithoutCancel(ctx)
followed by context.WithTimeout with an explicit deadline, and ensure the
resulting cancel function is invoked. Pass the bounded cleanup context to the
IngressControllers Delete calls while preserving spec cancellation for normal
operations.
- Around line 84-97: Update the test case around createSlowBackend to start the
delayed curl asynchronously, retain its process handle, trigger a router rolling
update by changing the relevant IngressController configuration, and await
rollout completion before waiting for the curl. Replace the exact "200" output
assertion with a success assertion that matches the curl response body and
verbose diagnostics, ensuring the original active request completes successfully
after the update.
- Around line 273-284: Remove the leading indentation from every line in the
serverScript raw string used by the slow-backend setup, including the top-level
import, class definition, handler body, and HTTPServer invocation, so the Python
script executes without an IndentationError.
---
Nitpick comments:
In @~:
- Around line 50-51: Update the backend container image configuration to use an
approved immutable image digest instead of the mutable latest tag, and set
imagePullPolicy to match the immutable reference so e2e runs remain repeatable.
- Around line 52-58: Add a TCP readiness probe to the slow-server container
targeting port 8080, using the existing Kubernetes probe configuration location
near ports and resources. Ensure readiness is reported only after the HTTPServer
has bound the port, without using an HTTP probe.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Repository YAML (base), Central YAML (inherited)
Review profile: CHILL
Plan: Enterprise
Run ID: 3975e131-f049-4638-bdb1-9c573933597b
⛔ Files ignored due to path filters (466)
go.sumis excluded by!**/*.sumvendor/github.com/go-openapi/swag/.codecov.ymlis excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/.golangci.ymlis excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/.mockery.ymlis excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/README.mdis excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/SECURITY.mdis excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/cmdutils/LICENSEis excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/cmdutils/cmd_utils.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/cmdutils/doc.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/cmdutils_iface.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/conv/LICENSEis excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/conv/convert.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/conv/convert_types.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/conv/doc.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/conv/format.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/conv/sizeof.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/conv/type_constraints.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/conv_iface.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/convert.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/convert_types.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/doc.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/errors.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/file.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/fileutils/LICENSEis excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/fileutils/doc.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/fileutils/file.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/fileutils/path.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/fileutils_iface.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/go.workis excluded by!**/*.work,!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/go.work.sumis excluded by!**/*.sum,!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/initialism_index.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/json.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/jsonname/LICENSEis excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/jsonname/doc.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/jsonname/name_provider.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/jsonname_iface.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/jsonutils/LICENSEis excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/jsonutils/README.mdis excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/jsonutils/adapters/doc.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/jsonutils/adapters/ifaces/doc.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/jsonutils/adapters/ifaces/ifaces.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/jsonutils/adapters/ifaces/registry_iface.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/jsonutils/adapters/registry.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/jsonutils/adapters/stdlib/json/adapter.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/jsonutils/adapters/stdlib/json/doc.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/jsonutils/adapters/stdlib/json/lexer.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/jsonutils/adapters/stdlib/json/ordered_map.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/jsonutils/adapters/stdlib/json/pool.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/jsonutils/adapters/stdlib/json/register.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/jsonutils/adapters/stdlib/json/writer.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/jsonutils/concat.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/jsonutils/doc.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/jsonutils/json.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/jsonutils/ordered_map.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/jsonutils_iface.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/loading/LICENSEis excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/loading/doc.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/loading/errors.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/loading/json.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/loading/loading.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/loading/options.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/loading/yaml.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/loading_iface.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/mangling/BENCHMARK.mdis excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/mangling/LICENSEis excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/mangling/doc.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/mangling/initialism_index.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/mangling/name_lexem.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/mangling/name_mangler.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/mangling/options.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/mangling/pools.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/mangling/split.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/mangling/string_bytes.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/mangling/util.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/mangling_iface.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/name_lexem.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/net.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/netutils/LICENSEis excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/netutils/doc.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/netutils/net.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/netutils_iface.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/split.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/stringutils/LICENSEis excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/stringutils/collection_formats.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/stringutils/doc.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/stringutils/strings.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/stringutils_iface.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/typeutils/LICENSEis excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/typeutils/doc.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/typeutils/types.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/typeutils_iface.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/util.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/yaml.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/yamlutils/LICENSEis excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/yamlutils/doc.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/yamlutils/errors.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/yamlutils/ordered_map.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/yamlutils/yaml.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/go-openapi/swag/yamlutils_iface.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/josharian/intern/README.mdis excluded by!**/vendor/**,!vendor/**vendor/github.com/josharian/intern/intern.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/josharian/intern/license.mdis excluded by!**/vendor/**,!vendor/**vendor/github.com/mailru/easyjson/LICENSEis excluded by!**/vendor/**,!vendor/**vendor/github.com/mailru/easyjson/buffer/pool.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/mailru/easyjson/jlexer/bytestostr.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/mailru/easyjson/jlexer/bytestostr_nounsafe.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/mailru/easyjson/jlexer/error.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/mailru/easyjson/jlexer/lexer.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/mailru/easyjson/jwriter/writer.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/.ci-operator.yamlis excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/.golangci.yamlis excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/Dockerfile.ocpis excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/Makefileis excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/apiextensions/v1alpha1/doc.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/apiextensions/v1alpha1/zz_generated.model_name.gois excluded by!**/vendor/**,!vendor/**,!**/zz_generated*vendor/github.com/openshift/api/apiserver/v1/doc.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/apiserver/v1/zz_generated.model_name.gois excluded by!**/vendor/**,!vendor/**,!**/zz_generated*vendor/github.com/openshift/api/apps/.codegen.yamlis excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/apps/v1/doc.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/apps/v1/zz_generated.model_name.gois excluded by!**/vendor/**,!vendor/**,!**/zz_generated*vendor/github.com/openshift/api/authorization/.codegen.yamlis excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/authorization/v1/doc.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/authorization/v1/zz_generated.model_name.gois excluded by!**/vendor/**,!vendor/**,!**/zz_generated*vendor/github.com/openshift/api/build/.codegen.yamlis excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/build/v1/doc.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/build/v1/zz_generated.model_name.gois excluded by!**/vendor/**,!vendor/**,!**/zz_generated*vendor/github.com/openshift/api/cloudnetwork/.codegen.yamlis excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/cloudnetwork/v1/doc.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/cloudnetwork/v1/zz_generated.model_name.gois excluded by!**/vendor/**,!vendor/**,!**/zz_generated*vendor/github.com/openshift/api/config/v1/doc.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/config/v1/register.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/config/v1/types_cluster_version.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/config/v1/types_crio_credential_provider_config.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/config/v1/types_infrastructure.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/config/v1/types_ingress.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/config/v1/types_network.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/config/v1/zz_generated.deepcopy.gois excluded by!**/vendor/**,!vendor/**,!**/zz_generated*vendor/github.com/openshift/api/config/v1/zz_generated.featuregated-crd-manifests.yamlis excluded by!**/vendor/**,!vendor/**,!**/zz_generated*vendor/github.com/openshift/api/config/v1/zz_generated.model_name.gois excluded by!**/vendor/**,!vendor/**,!**/zz_generated*vendor/github.com/openshift/api/config/v1/zz_generated.swagger_doc_generated.gois excluded by!**/vendor/**,!vendor/**,!**/zz_generated*vendor/github.com/openshift/api/config/v1alpha1/doc.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/config/v1alpha1/types_cluster_monitoring.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/config/v1alpha1/zz_generated.deepcopy.gois excluded by!**/vendor/**,!vendor/**,!**/zz_generated*vendor/github.com/openshift/api/config/v1alpha1/zz_generated.model_name.gois excluded by!**/vendor/**,!vendor/**,!**/zz_generated*vendor/github.com/openshift/api/config/v1alpha1/zz_generated.swagger_doc_generated.gois excluded by!**/vendor/**,!vendor/**,!**/zz_generated*vendor/github.com/openshift/api/config/v1alpha2/doc.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/config/v1alpha2/zz_generated.model_name.gois excluded by!**/vendor/**,!vendor/**,!**/zz_generated*vendor/github.com/openshift/api/console/v1/doc.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/console/v1/zz_generated.model_name.gois excluded by!**/vendor/**,!vendor/**,!**/zz_generated*vendor/github.com/openshift/api/etcd/v1/doc.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/etcd/v1/zz_generated.model_name.gois excluded by!**/vendor/**,!vendor/**,!**/zz_generated*vendor/github.com/openshift/api/etcd/v1alpha1/doc.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/etcd/v1alpha1/zz_generated.model_name.gois excluded by!**/vendor/**,!vendor/**,!**/zz_generated*vendor/github.com/openshift/api/features.mdis excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/features/features.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/helm/v1beta1/doc.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/helm/v1beta1/zz_generated.model_name.gois excluded by!**/vendor/**,!vendor/**,!**/zz_generated*vendor/github.com/openshift/api/image/.codegen.yamlis excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/image/v1/doc.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/image/v1/zz_generated.model_name.gois excluded by!**/vendor/**,!vendor/**,!**/zz_generated*vendor/github.com/openshift/api/imageregistry/v1/doc.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/imageregistry/v1/zz_generated.model_name.gois excluded by!**/vendor/**,!vendor/**,!**/zz_generated*vendor/github.com/openshift/api/kubecontrolplane/v1/doc.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/kubecontrolplane/v1/zz_generated.model_name.gois excluded by!**/vendor/**,!vendor/**,!**/zz_generated*vendor/github.com/openshift/api/legacyconfig/v1/doc.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/legacyconfig/v1/zz_generated.model_name.gois excluded by!**/vendor/**,!vendor/**,!**/zz_generated*vendor/github.com/openshift/api/machine/v1/doc.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/machine/v1/zz_generated.model_name.gois excluded by!**/vendor/**,!vendor/**,!**/zz_generated*vendor/github.com/openshift/api/machine/v1alpha1/doc.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/machine/v1alpha1/zz_generated.model_name.gois excluded by!**/vendor/**,!vendor/**,!**/zz_generated*vendor/github.com/openshift/api/machine/v1beta1/doc.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/machine/v1beta1/zz_generated.model_name.gois excluded by!**/vendor/**,!vendor/**,!**/zz_generated*vendor/github.com/openshift/api/machineconfiguration/v1/doc.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/machineconfiguration/v1/register.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/machineconfiguration/v1/types.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/machineconfiguration/v1/types_internalreleaseimage.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/machineconfiguration/v1/zz_generated.deepcopy.gois excluded by!**/vendor/**,!vendor/**,!**/zz_generated*vendor/github.com/openshift/api/machineconfiguration/v1/zz_generated.featuregated-crd-manifests.yamlis excluded by!**/vendor/**,!vendor/**,!**/zz_generated*vendor/github.com/openshift/api/machineconfiguration/v1/zz_generated.model_name.gois excluded by!**/vendor/**,!vendor/**,!**/zz_generated*vendor/github.com/openshift/api/machineconfiguration/v1/zz_generated.swagger_doc_generated.gois excluded by!**/vendor/**,!vendor/**,!**/zz_generated*vendor/github.com/openshift/api/machineconfiguration/v1alpha1/doc.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/machineconfiguration/v1alpha1/zz_generated.model_name.gois excluded by!**/vendor/**,!vendor/**,!**/zz_generated*vendor/github.com/openshift/api/monitoring/v1/doc.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/monitoring/v1/zz_generated.model_name.gois excluded by!**/vendor/**,!vendor/**,!**/zz_generated*vendor/github.com/openshift/api/network/.codegen.yamlis excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/network/v1/doc.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/network/v1/zz_generated.model_name.gois excluded by!**/vendor/**,!vendor/**,!**/zz_generated*vendor/github.com/openshift/api/network/v1alpha1/doc.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/network/v1alpha1/zz_generated.model_name.gois excluded by!**/vendor/**,!vendor/**,!**/zz_generated*vendor/github.com/openshift/api/networkoperator/.codegen.yamlis excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/networkoperator/v1/doc.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/networkoperator/v1/zz_generated.model_name.gois excluded by!**/vendor/**,!vendor/**,!**/zz_generated*vendor/github.com/openshift/api/oauth/.codegen.yamlis excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/oauth/v1/doc.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/oauth/v1/zz_generated.model_name.gois excluded by!**/vendor/**,!vendor/**,!**/zz_generated*vendor/github.com/openshift/api/openshiftcontrolplane/v1/doc.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/openshiftcontrolplane/v1/zz_generated.model_name.gois excluded by!**/vendor/**,!vendor/**,!**/zz_generated*vendor/github.com/openshift/api/operator/v1/doc.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/operator/v1/types_authentication.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/operator/v1/types_csi_cluster_driver.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/operator/v1/types_etcd.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/operator/v1/types_ingresscontroller.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/operator/v1/types_kmsencryption.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/operator/v1/types_kubeapiserver.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/operator/v1/types_openshiftapiserver.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/operator/v1/zz_generated.deepcopy.gois excluded by!**/vendor/**,!vendor/**,!**/zz_generated*vendor/github.com/openshift/api/operator/v1/zz_generated.featuregated-crd-manifests.yamlis excluded by!**/vendor/**,!vendor/**,!**/zz_generated*vendor/github.com/openshift/api/operator/v1/zz_generated.model_name.gois excluded by!**/vendor/**,!vendor/**,!**/zz_generated*vendor/github.com/openshift/api/operator/v1/zz_generated.swagger_doc_generated.gois excluded by!**/vendor/**,!vendor/**,!**/zz_generated*vendor/github.com/openshift/api/operator/v1alpha1/doc.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/operator/v1alpha1/zz_generated.model_name.gois excluded by!**/vendor/**,!vendor/**,!**/zz_generated*vendor/github.com/openshift/api/operatorcontrolplane/v1alpha1/doc.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/operatorcontrolplane/v1alpha1/zz_generated.model_name.gois excluded by!**/vendor/**,!vendor/**,!**/zz_generated*vendor/github.com/openshift/api/operatoringress/v1/doc.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/operatoringress/v1/zz_generated.model_name.gois excluded by!**/vendor/**,!vendor/**,!**/zz_generated*vendor/github.com/openshift/api/osin/v1/doc.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/osin/v1/types.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/osin/v1/zz_generated.model_name.gois excluded by!**/vendor/**,!vendor/**,!**/zz_generated*vendor/github.com/openshift/api/osin/v1/zz_generated.swagger_doc_generated.gois excluded by!**/vendor/**,!vendor/**,!**/zz_generated*vendor/github.com/openshift/api/project/.codegen.yamlis excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/project/v1/doc.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/project/v1/zz_generated.model_name.gois excluded by!**/vendor/**,!vendor/**,!**/zz_generated*vendor/github.com/openshift/api/quota/.codegen.yamlis excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/quota/v1/doc.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/quota/v1/zz_generated.model_name.gois excluded by!**/vendor/**,!vendor/**,!**/zz_generated*vendor/github.com/openshift/api/route/.codegen.yamlis excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/route/v1/doc.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/route/v1/zz_generated.model_name.gois excluded by!**/vendor/**,!vendor/**,!**/zz_generated*vendor/github.com/openshift/api/samples/.codegen.yamlis excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/samples/v1/doc.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/samples/v1/zz_generated.model_name.gois excluded by!**/vendor/**,!vendor/**,!**/zz_generated*vendor/github.com/openshift/api/security/.codegen.yamlis excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/security/v1/doc.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/security/v1/types.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/security/v1/zz_generated.model_name.gois excluded by!**/vendor/**,!vendor/**,!**/zz_generated*vendor/github.com/openshift/api/servicecertsigner/v1alpha1/doc.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/servicecertsigner/v1alpha1/zz_generated.model_name.gois excluded by!**/vendor/**,!vendor/**,!**/zz_generated*vendor/github.com/openshift/api/sharedresource/v1alpha1/doc.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/sharedresource/v1alpha1/zz_generated.model_name.gois excluded by!**/vendor/**,!vendor/**,!**/zz_generated*vendor/github.com/openshift/api/template/.codegen.yamlis excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/template/v1/doc.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/template/v1/zz_generated.model_name.gois excluded by!**/vendor/**,!vendor/**,!**/zz_generated*vendor/github.com/openshift/api/user/.codegen.yamlis excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/user/v1/doc.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/openshift/api/user/v1/zz_generated.model_name.gois excluded by!**/vendor/**,!vendor/**,!**/zz_generated*vendor/github.com/spf13/pflag/flag.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/crypto/chacha20poly1305/chacha20poly1305.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/crypto/chacha20poly1305/fips140only_compat.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/crypto/chacha20poly1305/fips140only_go1.26.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/crypto/chacha20poly1305/xchacha20poly1305.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/mod/modfile/print.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/mod/modfile/read.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/mod/modfile/rule.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/mod/module/module.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/mod/semver/semver.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/html/node.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/html/nodetype_string.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/client_priority_go126.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/client_priority_go127.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/frame.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/http2.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/server.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/transport.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/writesched_priority_rfc7540.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/writesched_priority_rfc9218.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/internal/httpsfv/httpsfv.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/trace/events.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/websocket/hybi.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sync/errgroup/errgroup.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/cpu/cpu.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/cpu/cpu_arm64.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/cpu/cpu_arm64.sis excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/cpu/cpu_gc_arm64.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/cpu/cpu_gccgo_arm64.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/cpu/cpu_netbsd_arm64.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/cpu/cpu_openbsd_arm64.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/cpu/cpu_other_arm64.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/cpu/cpu_windows_arm64.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/cpu/cpu_x86.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/ioctl_signed.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/ioctl_unsigned.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/mkerrors.shis excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/syscall_solaris.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/syscall_unix.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/zerrors_linux.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/zerrors_linux_386.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/zerrors_linux_amd64.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/zerrors_linux_arm.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/zerrors_linux_arm64.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/zerrors_linux_loong64.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/zerrors_linux_mips.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/zerrors_linux_mips64.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/zerrors_linux_mips64le.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/zerrors_linux_mipsle.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/zerrors_linux_ppc.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/zerrors_linux_ppc64.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/zerrors_linux_ppc64le.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/zerrors_linux_riscv64.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/zerrors_linux_s390x.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/zerrors_linux_sparc64.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/ztypes_netbsd_arm.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/windows/syscall_windows.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/windows/types_windows.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/windows/zsyscall_windows.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/term/terminal.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/text/cases/tables10.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/text/cases/tables11.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/text/cases/tables12.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/text/cases/tables15.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/text/cases/tables17.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/text/cases/tables9.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/text/encoding/japanese/eucjp.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/text/encoding/japanese/iso2022jp.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/text/encoding/japanese/shiftjis.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/text/encoding/korean/euckr.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/text/encoding/simplifiedchinese/gbk.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/text/encoding/simplifiedchinese/hzgb2312.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/text/encoding/traditionalchinese/big5.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/text/encoding/unicode/unicode.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/text/message/catalog/catalog.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/text/message/catalog/dict.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/text/message/catalog/go19.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/text/message/catalog/gopre19.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/text/secure/bidirule/bidirule.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/text/secure/bidirule/bidirule10.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/text/secure/bidirule/bidirule9.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/text/unicode/bidi/tables10.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/text/unicode/bidi/tables11.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/text/unicode/bidi/tables12.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/text/unicode/bidi/tables13.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/text/unicode/bidi/tables15.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/text/unicode/bidi/tables17.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/text/unicode/bidi/tables9.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/text/unicode/norm/forminfo.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/text/unicode/norm/tables10.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/text/unicode/norm/tables11.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/text/unicode/norm/tables12.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/text/unicode/norm/tables15.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/text/unicode/norm/tables17.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/text/unicode/norm/tables9.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/go/ast/inspector/cursor.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/go/ast/inspector/inspector.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/go/ast/inspector/iter.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/go/packages/packages.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/go/packages/visit.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/go/types/objectpath/objectpath.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/go/types/typeutil/callee.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/go/types/typeutil/map.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/aliases/aliases.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/aliases/aliases_go122.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/event/core/event.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/event/core/export.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/event/keys/keys.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/event/label/label.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/gcimporter/bimport.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/gcimporter/iexport.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/gcimporter/iimport.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/gcimporter/ureader_yes.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/stdlib/deps.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/stdlib/import.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/stdlib/manifest.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/stdlib/stdlib.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/typeparams/free.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/typeparams/normalize.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/typesinternal/classify_call.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/typesinternal/element.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/typesinternal/fx.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/typesinternal/isnamed.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/typesinternal/qualifier.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/typesinternal/types.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/typesinternal/varkind.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/typesinternal/varkind_go124.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/typesinternal/zerovalue.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/versions/features.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/klog/v2/README.mdis excluded by!**/vendor/**,!vendor/**vendor/k8s.io/klog/v2/internal/serialize/keyvalues.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/klog/v2/internal/serialize/keyvalues_no_slog.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/klog/v2/internal/serialize/keyvalues_slog.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/klog/v2/klog.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/klog/v2/klogr.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/klog/v2/klogr_slog.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/klog/v2/ktesting/testinglogger.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/klog/v2/textlogger/options.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/klog/v2/textlogger/textlogger.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/builder/openapi.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/builder3/openapi.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/internal/serialization.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/internal/third_party/go-json-experiment/json/README.mdis excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/internal/third_party/go-json-experiment/json/alias.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/internal/third_party/go-json-experiment/json/arshal.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/internal/third_party/go-json-experiment/json/arshal_any.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/internal/third_party/go-json-experiment/json/arshal_default.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/internal/third_party/go-json-experiment/json/arshal_funcs.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/internal/third_party/go-json-experiment/json/arshal_inlined.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/internal/third_party/go-json-experiment/json/arshal_methods.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/internal/third_party/go-json-experiment/json/arshal_time.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/internal/third_party/go-json-experiment/json/decode.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/internal/third_party/go-json-experiment/json/doc.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/internal/third_party/go-json-experiment/json/encode.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/internal/third_party/go-json-experiment/json/errors.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/internal/third_party/go-json-experiment/json/fields.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/internal/third_party/go-json-experiment/json/fold.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/internal/third_party/go-json-experiment/json/intern.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/internal/third_party/go-json-experiment/json/internal/internal.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/internal/third_party/go-json-experiment/json/internal/jsonflags/flags.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/internal/third_party/go-json-experiment/json/internal/jsonopts/options.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/internal/third_party/go-json-experiment/json/internal/jsonwire/decode.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/internal/third_party/go-json-experiment/json/internal/jsonwire/encode.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/internal/third_party/go-json-experiment/json/internal/jsonwire/wire.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/internal/third_party/go-json-experiment/json/jsontext/alias.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/internal/third_party/go-json-experiment/json/jsontext/decode.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/internal/third_party/go-json-experiment/json/jsontext/doc.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/internal/third_party/go-json-experiment/json/jsontext/encode.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/internal/third_party/go-json-experiment/json/jsontext/errors.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/internal/third_party/go-json-experiment/json/jsontext/export.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/internal/third_party/go-json-experiment/json/jsontext/options.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/internal/third_party/go-json-experiment/json/jsontext/pools.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/internal/third_party/go-json-experiment/json/jsontext/quote.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/internal/third_party/go-json-experiment/json/jsontext/state.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/internal/third_party/go-json-experiment/json/jsontext/token.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/internal/third_party/go-json-experiment/json/jsontext/value.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/internal/third_party/go-json-experiment/json/migrate.shis excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/internal/third_party/go-json-experiment/json/options.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/internal/third_party/go-json-experiment/json/value.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/schemaconv/openapi.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/schemaconv/proto_models.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/spec3/encoding.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/spec3/example.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/spec3/external_documentation.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/spec3/header.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/spec3/media_type.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/spec3/operation.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/spec3/parameter.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/spec3/path.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/spec3/request_body.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/spec3/response.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/spec3/security_scheme.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/spec3/server.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/spec3/spec.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/validation/spec/header.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/validation/spec/info.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/validation/spec/items.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/validation/spec/operation.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/validation/spec/parameter.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/validation/spec/path_item.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/validation/spec/paths.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/validation/spec/ref.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/validation/spec/response.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/validation/spec/responses.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/validation/spec/schema.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/validation/spec/security_scheme.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/validation/spec/swagger.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/validation/spec/tag.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/validation/validate/result.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/validation/validate/schema.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/kube-openapi/pkg/validation/validate/validator.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/utils/buffer/ring_fixed.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/utils/clock/testing/fake_clock.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/utils/exec/exec.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/utils/exec/fixup_go118.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/utils/exec/fixup_go119.gois excluded by!**/vendor/**,!vendor/**vendor/k8s.io/utils/strings/slices/slices.gois excluded by!**/vendor/**,!vendor/**vendor/modules.txtis excluded by!**/vendor/**,!vendor/**vendor/sigs.k8s.io/structured-merge-diff/v6/schema/elements.gois excluded by!**/vendor/**,!vendor/**vendor/sigs.k8s.io/structured-merge-diff/v6/typed/remove.gois excluded by!**/vendor/**,!vendor/**vendor/sigs.k8s.io/structured-merge-diff/v6/value/reflectcache.gois excluded by!**/vendor/**,!vendor/**
📒 Files selected for processing (3)
go.modtest/extended/router/multi-haproxy.go~
There was a problem hiding this comment.
Caution
Inline review comments failed to post. This is likely due to GitHub's internal server error or limits when posting large numbers of comments. If you are seeing this consistently it is likely a permissions issue. Please check "Moderation" -> "Code review limits" under your organization settings.
🛑 Comments failed to post (10)
~ (3)
8-30: 🩺 Stability & Availability | 🟠 Major | ⚡ Quick win
Do not commit this live-cluster Pod snapshot as the test fixture.
The OVN annotations, generated metadata/status, captured
nodeName, namespace-specific pull secret, service-account volume, and fullstatusblock make this non-portable and likely to collide withdefault/slow-server. Keep only desired fields; let the test framework choose the namespace/name and the API server populate runtime state.Also applies to: 65-108, 109-180
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In @~ around lines 8 - 30, Replace the live-cluster Pod snapshot with a minimal desired-state fixture, removing OVN/network annotations, generated metadata, nodeName, namespace-specific pull secrets and service-account volumes, plus the full status block. Retain only fields required to define the slow-server Pod, and let the test framework/API server assign name, namespace, metadata, and runtime state across the affected fixture sections.
33-49: 🎯 Functional Correctness | 🔴 Critical | ⚡ Quick win
Fix the embedded command before using this fixture.
argsis not valid YAML here:python3 -c "is neither a list item nor a block scalar. Even after fixing that, the Python source has leading top-level indentation, causing the observed exit code 1 andCrashLoopBackOff. Encode the script as a block scalar and remove indentation from top-level statements.Proposed shape
- args: - bash - -c - python3 -c " - import http.server, time + - | + exec python3 -c ' + import http.server + import time - class SlowHandler(http.server.BaseHTTPRequestHandler): - ... + class SlowHandler(http.server.BaseHTTPRequestHandler): + ... - " + 'Also applies to: 147-159
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In @~ around lines 33 - 49, Fix the embedded Python command in the fixture’s args definition by representing the script as a valid YAML block scalar rather than an unstructured quoted value. Remove leading indentation from Python top-level statements while preserving the SlowHandler behavior and HTTP server startup, and apply the same correction to the corresponding second fixture block.
59-62: 🔒 Security & Privacy | 🟠 Major | ⚡ Quick win
Disable the service-account token for this HTTP-only server.
The fixture mounts the default service-account token even though the backend never uses the Kubernetes API. If the server is compromised, the token unnecessarily exposes API credentials. Set
automountServiceAccountToken: falseand remove the explicit token mount/volume.Also applies to: 73-74, 85-108
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In @~ around lines 59 - 62, Disable service-account token mounting in the fixture workloads by setting automountServiceAccountToken to false and removing the explicit kube-api-access token volumeMounts and corresponding volume definitions from all referenced sections. Preserve the existing HTTP server configuration and other volume mounts.go.mod (1)
96-101: 🔒 Security & Privacy | 🟠 Major | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
govulncheck ./... make verify make checkRepository: openshift/origin
Length of output: 279
🏁 Script executed:
#!/bin/bash set -euo pipefail # Show the relevant go.mod section with line numbers. sed -n '88,108p' go.mod | cat -n # Search for the exact module pins in the repo. rg -n 'golang\.org/x/(crypto|net)\s+v' go.modRepository: openshift/origin
Length of output: 1036
🌐 Web query:
OSV golang.org/x/crypto v0.48.0 golang.org/x/net v0.50.0 advisories fixed versions💡 Result:
As of July 16, 2026, both golang.org/x/crypto version 0.48.0 and golang.org/x/net version 0.50.0 are affected by numerous security advisories, as they were released before several critical patches [1][2]. Users are advised to upgrade to the latest available versions to mitigate these vulnerabilities [3][4]. For golang.org/x/crypto, version 0.48.0 contains multiple documented security advisories [1]. Many of the vulnerabilities reported in this version, such as those related to SSH key parsing, authentication bypass, and resource exhaustion (e.g., GHSA-5cgq-3rg8-m6cv, GHSA-vgwf-h737-ff37, and GO-2026-5018), were addressed in version 0.52.0 [5][6][7][4]. For golang.org/x/net, version 0.50.0 is also affected by multiple security advisories [2]. Notable issues include HTTP/2 frame handling vulnerabilities (e.g., GO-2026-4559, GO-2026-4918) and HTML parsing issues (e.g., GO-2026-5028) [8][9][10]. These have been addressed in subsequent releases, with various fixes implemented in versions 0.51.0, 0.53.0, and 0.55.0 depending on the specific vulnerability [8][9][10]. To identify the precise fixed versions for specific vulnerabilities, you should consult the Open Source Vulnerabilities (OSV) database or the Go vulnerability database (vuln.go.dev) using the advisory IDs listed on the respective package pages [1][5][2]. It is strongly recommended to update to the most recent stable release of these packages to ensure all security patches are applied [3].
Citations:
- 1: https://pkg.go.dev/golang.org/x/crypto@v0.48.0
- 2: https://pkg.go.dev/golang.org/x/net@v0.50.0
- 3: https://pkg.go.dev/golang.org/x/crypto@v0.49.0
- 4: https://www.openwall.com/lists/oss-security/2026/05/22/6
- 5: https://osv.dev/vulnerability/GO-2026-5018
- 6: https://deps.dev/advisory/osv/GHSA-5cgq-3rg8-m6cv
- 7: https://deps.dev/advisory/osv/GHSA-vgwf-h737-ff37
- 8: https://osv.dev/vulnerability/CVE-2026-27141
- 9: https://osv.dev/vulnerability/GO-2026-4918
- 10: https://osv.dev/vulnerability/GO-2026-5028
Bump
golang.org/x/cryptoandgolang.org/x/net.v0.48.0andv0.50.0are still covered by OSV advisories; move both to patched releases before merging.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@go.mod` around lines 96 - 101, Update the go.mod dependency entries for golang.org/x/crypto and golang.org/x/net to patched releases that address the referenced OSV advisories, while leaving the surrounding module versions unchanged.Sources: Path instructions, MCP tools
test/extended/router/multi-haproxy.go (6)
42-57: 🩺 Stability & Availability | 🟠 Major | ⚡ Quick win
Bound teardown and preserve the spec context.
context.Background()disconnects API operations from spec cancellation, while theAfterEachdeletes have no deadline and can block teardown indefinitely. Derive operations from the spec context; for cleanup, detach cancellation and apply an explicit timeout.As per path instructions, contexts must provide cancellation and timeouts. Based on learnings, deferred cleanup should use
context.WithoutCancel(ctx)followed bycontext.WithTimeout(...), rather than an uncanceled root context.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@test/extended/router/multi-haproxy.go` around lines 42 - 57, Update the teardown context setup around ctx and the g.AfterEach cleanup to derive the operational context from the spec context rather than context.Background(). For deletion, use context.WithoutCancel(ctx) followed by context.WithTimeout with an explicit deadline, and ensure the resulting cancel function is invoked. Pass the bounded cleanup context to the IngressControllers Delete calls while preserving spec cancellation for normal operations.Sources: Path instructions, Learnings
84-97: 🎯 Functional Correctness | 🟠 Major | 🏗️ Heavy lift
Implement the rolling update this scenario claims to test.
The test only runs a synchronous curl; it never changes an IngressController while that request is active. Additionally,
curl -vreturns theOKbody plus diagnostic output, not exactly"200". Start the delayed request asynchronously, trigger and await the router rollout, then assert that the original request completes successfully.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@test/extended/router/multi-haproxy.go` around lines 84 - 97, Update the test case around createSlowBackend to start the delayed curl asynchronously, retain its process handle, trigger a router rolling update by changing the relevant IngressController configuration, and await rollout completion before waiting for the curl. Replace the exact "200" output assertion with a success assertion that matches the curl response body and verbose diagnostics, ensuring the original active request completes successfully after the update.
100-116: 🎯 Functional Correctness | 🟠 Major | ⚡ Quick win
Runtime-version checks do not inspect the custom router under test.
test/extended/router/multi-haproxy.go#L100-L116: query the custom router’s effective status and HAProxy admin socket instead of reading back its Spec.test/extended/router/multi-haproxy.go#L120-L135: execute againstdeploy/router-<custom-controller-name>, notdeploy/router-default.📍 Affects 1 file
test/extended/router/multi-haproxy.go#L100-L116(this comment)test/extended/router/multi-haproxy.go#L120-L135🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@test/extended/router/multi-haproxy.go` around lines 100 - 116, The HAProxy version test currently validates the IngressController Spec rather than the custom router’s runtime version. In test/extended/router/multi-haproxy.go:100-116, query the custom controller’s effective status and HAProxy admin socket to verify the running version; in test/extended/router/multi-haproxy.go:120-135, run the checks against deploy/router-<custom-controller-name> instead of deploy/router-default.
139-145: 🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win
Restore the default IngressController after this spec.
Clearing the shared default controller is not undone by
AfterEach, which only deletes custom controllers. This can contaminate subsequent tests. Capture and restore the original value in bounded cleanup; also assert against the object returned byPatchor refetch it, since Line 145 checks the stale pre-patch object.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@test/extended/router/multi-haproxy.go` around lines 139 - 145, Update the cleanup for this spec around the default IngressController setup to capture its original HAProxyVersion and restore it in bounded cleanup after the test, since existing AfterEach only removes custom controllers. Also use the object returned by Patch or refetch the default controller before asserting HAProxyVersion is empty, rather than checking the stale ingressDefault object.Source: Coding guidelines
273-284: 🩺 Stability & Availability | 🔴 Critical | ⚡ Quick win
Remove the leading indentation from the
python3 -cscript.The raw literal preserves the Go indentation, so Python encounters an indented top-level
importand exits withIndentationError. The slow-backend Pod will never become ready.Proposed fix
const serverScript = ` - import http.server, time +import http.server, time - class SlowHandler(http.server.BaseHTTPRequestHandler): - def do_GET(self): - time.sleep(20) - self.send_response(200) - self.end_headers() - self.wfile.write(b'OK') +class SlowHandler(http.server.BaseHTTPRequestHandler): + def do_GET(self): + time.sleep(20) + self.send_response(200) + self.end_headers() + self.wfile.write(b'OK') - http.server.HTTPServer(('', 8080), SlowHandler).serve_forever() +http.server.HTTPServer(('', 8080), SlowHandler).serve_forever() `📝 Committable suggestion
‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.const serverScript = ` import http.server, time class SlowHandler(http.server.BaseHTTPRequestHandler): def do_GET(self): time.sleep(20) self.send_response(200) self.end_headers() self.wfile.write(b'OK') http.server.HTTPServer(('', 8080), SlowHandler).serve_forever() `🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@test/extended/router/multi-haproxy.go` around lines 273 - 284, Remove the leading indentation from every line in the serverScript raw string used by the slow-backend setup, including the top-level import, class definition, handler body, and HTTPServer invocation, so the Python script executes without an IndentationError.
329-374: 🩺 Stability & Availability | 🔴 Critical | ⚡ Quick win
Wait for backend readiness and Route admission before returning.
Resource creation does not mean the Pod is ready or the Route status is populated. The caller immediately indexes
route.Status.Ingress[0], so this can panic or curl an unavailable backend. Wait for the Pod’s Ready condition and poll the Route until it has an admitted ingress with a non-empty host, then return the refreshed Route.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@test/extended/router/multi-haproxy.go` around lines 329 - 374, Update the resource setup flow around the Pod and Route creation in the helper to wait for the Pod Ready condition before proceeding, then poll the created Route until its status contains an admitted ingress with a non-empty host. Refresh the Route from the API during polling and return that refreshed object instead of the initial create response, while preserving existing error propagation.Source: Coding guidelines
|
Scheduling required tests: |
|
/testwith openshift/origin/main/e2e-gcp-ovn-techpreview openshift/cluster-ingress-operator#1498 |
|
/assign |
|
/testwith openshift/origin/main/e2e-gcp-ovn-techpreview openshift/cluster-ingress-operator#1498 |
There was a problem hiding this comment.
Actionable comments posted: 3
🧹 Nitpick comments (1)
test/extended/router/multi-haproxy.go (1)
343-360: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick winReadiness check relies on container name coincidentally matching Pod name; timeout duplicates
testsTimeout.
p.Name == pod.Namecompares aContainerStatus.Name("slow-backend" container) against the Pod'sObjectMeta.Name("slow-backend"). It only works because both happen to share the same literal string — if either is renamed independently, this silently times out instead of failing fast. Also, the poll timeout2*time.Minuteduplicates the already-declaredtestsTimeoutconstant (Line 35); consider threading it through as a parameter for consistency.- for _, p := range pods.Status.ContainerStatuses { - if p.Name == pod.Name && p.Ready { + for _, p := range pods.Status.ContainerStatuses { + if p.Name == "slow-backend" && p.Ready { e2e.Logf("The pod is ready!") return true, nil } }🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@test/extended/router/multi-haproxy.go` around lines 343 - 360, Update the readiness check in the wait.PollUntilContextTimeout callback to identify the intended container using its explicit container-name symbol or value, rather than comparing ContainerStatus.Name with pod.Name. Replace the duplicated 2*time.Minute polling timeout with the existing testsTimeout constant, passing it through any enclosing helper parameters if needed.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@test/extended/router/multi-haproxy.go`:
- Line 19: Replace the pointer.Bool usage in the SecurityContext struct literal
with the existing ptr.To helper, remove the now-unused k8s.io/utils/pointer
import, and keep the neighboring ptr.To(false) style consistent.
- Line 95: Update the wait.PollUntilContextTimeout call to use the existing
enclosing ctx instead of context.Background(), and rename the closure parameter
from context to a non-shadowing name such as ctx. Preserve the callback’s
context.Context type and existing polling behavior.
- Around line 87-116: The slow-backend request currently completes before the
router rollout begins. Update the curl execution in the test around oc.Run and
the subsequent rollout restart to run asynchronously, trigger the
deployment/router-default restart while curl remains in flight, then wait for
and validate the curl result and its 200 OK response.
---
Nitpick comments:
In `@test/extended/router/multi-haproxy.go`:
- Around line 343-360: Update the readiness check in the
wait.PollUntilContextTimeout callback to identify the intended container using
its explicit container-name symbol or value, rather than comparing
ContainerStatus.Name with pod.Name. Replace the duplicated 2*time.Minute polling
timeout with the existing testsTimeout constant, passing it through any
enclosing helper parameters if needed.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Repository YAML (base), Central YAML (inherited)
Review profile: CHILL
Plan: Enterprise
Run ID: 6f5b19c0-2043-48ad-b922-50260f246d78
📒 Files selected for processing (1)
test/extended/router/multi-haproxy.go
|
Scheduling required tests: |
|
/testwith openshift/origin/main/e2e-gcp-ovn-techpreview openshift/cluster-ingress-operator#1498 |
|
Scheduling required tests: |
gcs278
left a comment
There was a problem hiding this comment.
Sorry - I know it's WIP, but i wanted to have an early review to hopefully help with direction. It's looking pretty close to being ready!
My suggestion summary:
- should fail if selecting an unknown HAProxy version
should preserve active connections during router rolling update→ should revert to default HAProxy when the version field is cleared- should configure the same HAProxy version defined in the API
- should configure the default HAProxy if the version is unset
- should maintain default router unchanged if updating the version on a custom IngressController (record default's version, loop through all available versions on custom IC, verify default never changes)
| const testsTimeout = 2 * time.Minute | ||
|
|
||
| // defaultHAProxyVersion is the default HAProxy version for the current release. | ||
| const defaultHAProxyVersion = operatorv1.HAProxyVersion32 |
There was a problem hiding this comment.
More of a minor point, but it'd be better if we didn't hardcode this - that means that after each bump, we'd break this origin test, and wouldn't have a way to atomically update it.
Consider just using the status on the default IngressController to get the default:
| const defaultHAProxyVersion = operatorv1.HAProxyVersion32 | |
| // Discover the default version from the running cluster | |
| defaultIC, err := operatorClient.OperatorV1().IngressControllers("openshift-ingress-operator").Get(ctx, "default", metav1.GetOptions{}) | |
| defaultVersion := defaultIC.Status.EffectiveHAProxyVersion |
There was a problem hiding this comment.
Actually, it's fine to leave this as a follow up. We also want to extract the available versions from the CRD too, and I think we can figure that out later. Eventually we need either to:
- Not hardcode the versions so our origin tests break when we bump
- Move to openshift/cluster-ingress-operator as OTE (so they can be changed in the same PR)
There was a problem hiding this comment.
yeah +1 on leaving it as a followup also I guess we would have to figure out how to get the previous version also
There was a problem hiding this comment.
sorry I realized that this actually needs to be resolved now, otherwise our haproxy28 jobs will fail. The default can dynamically change, so we should really discover it via the way I suggested, rather than hardcoding.
Additionally, you will also need to set the alternative dynamically based on the default. Something like this works for now:
var defaultHAProxyVersion operatorv1.HAProxyVersion
var alternateHAProxyVersion operatorv1.HAProxyVersion
g.BeforeEach(func() {
defaultIC, err := operatorClient.OperatorV1().IngressControllers("openshift-ingress-operator").Get(ctx, "default", metav1.GetOptions{})
o.Expect(err).NotTo(o.HaveOccurred())
o.Expect(defaultIC.Status.EffectiveHAProxyVersion).NotTo(o.BeEmpty())
defaultHAProxyVersion = defaultIC.Status.EffectiveHAProxyVersion
if defaultHAProxyVersion == operatorv1.HAProxyVersion28 {
alternateHAProxyVersion = operatorv1.HAProxyVersion32
} else {
alternateHAProxyVersion = operatorv1.HAProxyVersion28
}
})
|
Scheduling required tests: |
gcs278
left a comment
There was a problem hiding this comment.
Thanks for the updates! looking good, just dropped a few comments, I should be good now. Hope it helps.
|
/assign @gcs278 |
| err = wait.PollUntilContextTimeout(ctx, 2*time.Second, testsTimeout, true, func(ctx context.Context) (bool, error) { | ||
| ic, err := operatorClient.OperatorV1().IngressControllers("openshift-ingress-operator").Get(ctx, ingress.Name, metav1.GetOptions{}) | ||
| if err != nil { | ||
| return false, nil | ||
| } | ||
| if ic.Status.EffectiveHAProxyVersion == "" { | ||
| e2e.Logf("EffectiveHAProxyVersion not yet set, waiting...") | ||
| return false, nil | ||
| } | ||
| effectiveVersion = string(ic.Status.EffectiveHAProxyVersion) | ||
| return true, nil | ||
| }) |
There was a problem hiding this comment.
This poll seems to be pretty much the one on another test, but here it is polling the status. In case the other one polls status as well, wondering if it worth to extract both to a waitStatus...() returning (effectiveVersion, error).
| if err != nil { | ||
| return false, nil | ||
| } |
There was a problem hiding this comment.
It worth logging here the reason of the failure as well.
|
/testwith openshift/origin/main/e2e-gcp-ovn-techpreview openshift/cluster-ingress-operator#1498 |
|
@gcs278 @jcmoraisjr Please take another round of review |
gcs278
left a comment
There was a problem hiding this comment.
thanks for the updates. Mind removing the WIP and adding some context to the PR Description? I don't think you need the logging of proof that it works (CI will prove that 😄), and would good to link the implementation that this tests (openshift/cluster-ingress-operator#1498).
/lgtm
|
@rhamini3: The following tests failed, say
Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: gcs278, rhamini3 The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
|
and I think you need a new |
Test Result
Summary by CodeRabbit
Tests
haproxyVersion, including rejecting invalid values and restoring the default after clearing it.effectiveHAProxyVersionreporting and that custom IngressController settings don’t change the default router’s HAProxy version.Chores