diff --git a/ci-operator/config/openshift/sandboxed-containers-operator/openshift-sandboxed-containers-operator-devel__downstream-candidate.yaml b/ci-operator/config/openshift/sandboxed-containers-operator/openshift-sandboxed-containers-operator-devel__downstream-candidate.yaml index 0ae6a9a4f8976..6323275fd35a5 100644 --- a/ci-operator/config/openshift/sandboxed-containers-operator/openshift-sandboxed-containers-operator-devel__downstream-candidate.yaml +++ b/ci-operator/config/openshift/sandboxed-containers-operator/openshift-sandboxed-containers-operator-devel__downstream-candidate.yaml @@ -7,6 +7,11 @@ base_images: name: "4.19" namespace: ocp tag: upi-installer +build_root: + image_stream_tag: + name: builder + namespace: ocp + tag: rhel-9-golang-1.26-openshift-4.23 prowgen: disable_sparse_checkout: true releases: @@ -53,6 +58,7 @@ tests: TEST_RELEASE_TYPE: Pre-GA TEST_SCENARIOS: sig-kata.*Kata Author TEST_TIMEOUT: "90" + TESTS_KATA_UPSTREAM_ENABLE: "true" workflow: sandboxed-containers-operator-e2e-azure timeout: 24h0m0s - as: azure-ipi-peerpods diff --git a/ci-operator/config/openshift/sandboxed-containers-operator/openshift-sandboxed-containers-operator-devel__downstream-candidate417.yaml b/ci-operator/config/openshift/sandboxed-containers-operator/openshift-sandboxed-containers-operator-devel__downstream-candidate417.yaml index db71f5e3490d1..8f2607e340abd 100644 --- a/ci-operator/config/openshift/sandboxed-containers-operator/openshift-sandboxed-containers-operator-devel__downstream-candidate417.yaml +++ b/ci-operator/config/openshift/sandboxed-containers-operator/openshift-sandboxed-containers-operator-devel__downstream-candidate417.yaml @@ -7,6 +7,11 @@ base_images: name: "4.17" namespace: ocp tag: upi-installer +build_root: + image_stream_tag: + name: builder + namespace: ocp + tag: rhel-9-golang-1.26-openshift-4.23 prowgen: disable_sparse_checkout: true releases: @@ -54,6 +59,7 @@ tests: TEST_RELEASE_TYPE: Pre-GA TEST_SCENARIOS: sig-kata.*Kata Author TEST_TIMEOUT: "90" + TESTS_KATA_UPSTREAM_ENABLE: "true" TRUSTEE_URL: "" workflow: sandboxed-containers-operator-e2e-azure timeout: 24h0m0s diff --git a/ci-operator/config/openshift/sandboxed-containers-operator/openshift-sandboxed-containers-operator-devel__downstream-candidate418.yaml b/ci-operator/config/openshift/sandboxed-containers-operator/openshift-sandboxed-containers-operator-devel__downstream-candidate418.yaml index e31bf60690b0e..302b2364e3602 100644 --- a/ci-operator/config/openshift/sandboxed-containers-operator/openshift-sandboxed-containers-operator-devel__downstream-candidate418.yaml +++ b/ci-operator/config/openshift/sandboxed-containers-operator/openshift-sandboxed-containers-operator-devel__downstream-candidate418.yaml @@ -7,6 +7,11 @@ base_images: name: "4.18" namespace: ocp tag: upi-installer +build_root: + image_stream_tag: + name: builder + namespace: ocp + tag: rhel-9-golang-1.26-openshift-4.23 prowgen: disable_sparse_checkout: true releases: @@ -54,6 +59,7 @@ tests: TEST_RELEASE_TYPE: Pre-GA TEST_SCENARIOS: sig-kata.*Kata Author TEST_TIMEOUT: "90" + TESTS_KATA_UPSTREAM_ENABLE: "true" TRUSTEE_URL: "" workflow: sandboxed-containers-operator-e2e-azure timeout: 24h0m0s diff --git a/ci-operator/config/openshift/sandboxed-containers-operator/openshift-sandboxed-containers-operator-devel__downstream-candidate419.yaml b/ci-operator/config/openshift/sandboxed-containers-operator/openshift-sandboxed-containers-operator-devel__downstream-candidate419.yaml index 52df395275353..882e11639d2ef 100644 --- a/ci-operator/config/openshift/sandboxed-containers-operator/openshift-sandboxed-containers-operator-devel__downstream-candidate419.yaml +++ b/ci-operator/config/openshift/sandboxed-containers-operator/openshift-sandboxed-containers-operator-devel__downstream-candidate419.yaml @@ -7,6 +7,11 @@ base_images: name: "4.19" namespace: ocp tag: upi-installer +build_root: + image_stream_tag: + name: builder + namespace: ocp + tag: rhel-9-golang-1.26-openshift-4.23 prowgen: disable_sparse_checkout: true releases: @@ -54,6 +59,7 @@ tests: TEST_RELEASE_TYPE: Pre-GA TEST_SCENARIOS: sig-kata.*Kata Author TEST_TIMEOUT: "90" + TESTS_KATA_UPSTREAM_ENABLE: "true" TRUSTEE_URL: "" workflow: sandboxed-containers-operator-e2e-azure timeout: 24h0m0s diff --git a/ci-operator/config/openshift/sandboxed-containers-operator/openshift-sandboxed-containers-operator-devel__downstream-candidate420.yaml b/ci-operator/config/openshift/sandboxed-containers-operator/openshift-sandboxed-containers-operator-devel__downstream-candidate420.yaml index ec32f25caba41..59d58867e36b9 100644 --- a/ci-operator/config/openshift/sandboxed-containers-operator/openshift-sandboxed-containers-operator-devel__downstream-candidate420.yaml +++ b/ci-operator/config/openshift/sandboxed-containers-operator/openshift-sandboxed-containers-operator-devel__downstream-candidate420.yaml @@ -7,6 +7,11 @@ base_images: name: "4.20" namespace: ocp tag: upi-installer +build_root: + image_stream_tag: + name: builder + namespace: ocp + tag: rhel-9-golang-1.26-openshift-4.23 prowgen: disable_sparse_checkout: true releases: @@ -54,6 +59,7 @@ tests: TEST_RELEASE_TYPE: Pre-GA TEST_SCENARIOS: sig-kata.*Kata Author TEST_TIMEOUT: "90" + TESTS_KATA_UPSTREAM_ENABLE: "true" TRUSTEE_URL: "" workflow: sandboxed-containers-operator-e2e-azure timeout: 24h0m0s diff --git a/ci-operator/config/openshift/sandboxed-containers-operator/openshift-sandboxed-containers-operator-devel__downstream-candidate421.yaml b/ci-operator/config/openshift/sandboxed-containers-operator/openshift-sandboxed-containers-operator-devel__downstream-candidate421.yaml index e8e549a686753..99b3a1e962017 100644 --- a/ci-operator/config/openshift/sandboxed-containers-operator/openshift-sandboxed-containers-operator-devel__downstream-candidate421.yaml +++ b/ci-operator/config/openshift/sandboxed-containers-operator/openshift-sandboxed-containers-operator-devel__downstream-candidate421.yaml @@ -7,6 +7,11 @@ base_images: name: "4.21" namespace: ocp tag: upi-installer +build_root: + image_stream_tag: + name: builder + namespace: ocp + tag: rhel-9-golang-1.26-openshift-4.23 prowgen: disable_sparse_checkout: true releases: @@ -54,6 +59,7 @@ tests: TEST_RELEASE_TYPE: Pre-GA TEST_SCENARIOS: sig-kata.*Kata Author TEST_TIMEOUT: "90" + TESTS_KATA_UPSTREAM_ENABLE: "true" TRUSTEE_URL: "" workflow: sandboxed-containers-operator-e2e-azure timeout: 24h0m0s diff --git a/ci-operator/config/openshift/sandboxed-containers-operator/openshift-sandboxed-containers-operator-devel__downstream-candidate422.yaml b/ci-operator/config/openshift/sandboxed-containers-operator/openshift-sandboxed-containers-operator-devel__downstream-candidate422.yaml index 71313dc64df09..6f75b27a74e76 100644 --- a/ci-operator/config/openshift/sandboxed-containers-operator/openshift-sandboxed-containers-operator-devel__downstream-candidate422.yaml +++ b/ci-operator/config/openshift/sandboxed-containers-operator/openshift-sandboxed-containers-operator-devel__downstream-candidate422.yaml @@ -7,6 +7,11 @@ base_images: name: "4.22" namespace: ocp tag: upi-installer +build_root: + image_stream_tag: + name: builder + namespace: ocp + tag: rhel-9-golang-1.26-openshift-4.23 prowgen: disable_sparse_checkout: true releases: @@ -34,18 +39,19 @@ tests: report_template: '{{if eq .Status.State "success"}}SUCCESS{{else}}ERROR{{end}} {{trimPrefix "periodic-ci-openshift-sandboxed-containers-operator-" .Spec.Job}} <{{.Status.URL}}|View logs>' - restrict_network_access: false + restrict_network_access: true steps: cluster_profile: azure-qe env: BASE_DOMAIN: qe.azure.devcluster.openshift.com - CATALOG_SOURCE_IMAGE: quay.io/redhat-user-workloads/ose-osc-tenant/osc-test-fbc:latest + CATALOG_SOURCE_IMAGE: quay.io/redhat-user-workloads/ose-osc-tenant/osc-test-fbc:1.13.1-1788510424 CATALOG_SOURCE_NAME: brew-catalog CUSTOM_AZURE_REGION: eastus ENABLE_MUST_GATHER: "true" INITDATA: "" INSTALL_KATA_RPM: "true" - KATA_RPM_VERSION: 3.31.0-4.rhaos4.19.el9 + KATA_RPM_BUILD_TASK: "71750058" + KATA_RPM_VERSION: 4.1.0-1.scratch1788526231.rhaos4.22.el9 MUST_GATHER_IMAGE: registry.redhat.io/openshift-sandboxed-containers/osc-must-gather-rhel9:latest MUST_GATHER_ON_FAILURE_ONLY: "false" OSC_INSTALL: "true" @@ -53,9 +59,9 @@ tests: TEST_FILTERS: ~DisconnectedOnly&;~Disruptive& TEST_RELEASE_TYPE: Pre-GA TEST_SCENARIOS: sig-kata.*Kata Author - TEST_SKELETON_ENABLE: "false" - TEST_SKELETON2_ENABLE: "false" TEST_TIMEOUT: "90" + TESTS_KATA_UPSTREAM_ENABLE: "true" + TESTS_SKELETON2_ENABLE: "true" TRUSTEE_URL: "" workflow: sandboxed-containers-operator-e2e-azure timeout: 24h0m0s diff --git a/ci-operator/config/openshift/sandboxed-containers-operator/openshift-sandboxed-containers-operator-devel__downstream-release.yaml b/ci-operator/config/openshift/sandboxed-containers-operator/openshift-sandboxed-containers-operator-devel__downstream-release.yaml index 9bbfab1879ede..f65644553f2d9 100644 --- a/ci-operator/config/openshift/sandboxed-containers-operator/openshift-sandboxed-containers-operator-devel__downstream-release.yaml +++ b/ci-operator/config/openshift/sandboxed-containers-operator/openshift-sandboxed-containers-operator-devel__downstream-release.yaml @@ -7,6 +7,11 @@ base_images: name: "4.19" namespace: ocp tag: upi-installer +build_root: + image_stream_tag: + name: builder + namespace: ocp + tag: rhel-9-golang-1.26-openshift-4.23 prowgen: disable_sparse_checkout: true releases: @@ -53,6 +58,7 @@ tests: TEST_RELEASE_TYPE: GA TEST_SCENARIOS: sig-kata.*Kata Author TEST_TIMEOUT: "90" + TESTS_KATA_UPSTREAM_ENABLE: "true" TRUSTEE_URL: "" workflow: sandboxed-containers-operator-e2e-azure timeout: 24h0m0s diff --git a/ci-operator/step-registry/sandboxed-containers-operator/testsuites/README.md b/ci-operator/step-registry/sandboxed-containers-operator/testsuites/README.md index 89fe426be1aa1..eff028fe0d8ed 100644 --- a/ci-operator/step-registry/sandboxed-containers-operator/testsuites/README.md +++ b/ci-operator/step-registry/sandboxed-containers-operator/testsuites/README.md @@ -31,18 +31,18 @@ Design decisions that follow from that intent: - **Suites do not block each other on pass / error / skip.** This is the whole point — one repository's suite failing must not prevent another's from running. Achieved with `best_effort` in `post` (see below). -- **Explicit, per-suite enable gating** via `TEST__ENABLE`, so a job opts +- **Explicit, per-suite enable gating** via `TESTS__ENABLE`, so a job opts into exactly the suites it wants and everything else skips gracefully. Every ProwJob - variable for a suite is prefixed `TEST__`. + variable for a suite follows the `TESTS__` convention. - **Every suite emits standard Prow artifacts + JUnit**, so results show up in Spyglass whether the suite ran, was skipped, or failed. **Scope** is deliberately limited to `ci-operator/**/sandboxed-containers-operator/`. -`skeleton` / `skeleton2` are the reference implementation of a suite step: `skeleton` -echoes its `TEST_SKELETON_ENABLE` value and (when enabled) exits with a failure to -prove non-blocking; `skeleton2` runs after it and always succeeds. They are DEMOs and -disabled by default (see below) — real suites replace them following the same pattern. +`kata-upstream` is the first **real** suite in the chain (the upstream Kata +Containers e2e tests). `skeleton2` is a DEMO/template suite that, when enabled, +always succeeds; it is disabled by default (see below) and serves as the copy-paste +pattern new suites follow. ## Why POST (and not `test:`) @@ -67,17 +67,17 @@ Non-blocking behaviour requires **both**: testsuites/ ├── README.md (this file) ├── sandboxed-containers-operator-testsuites-chain.yaml (the POST chain) -├── skeleton/ (DEMO suite -- fails on purpose) -│ ├── ...-skeleton-ref.yaml -│ └── ...-skeleton-commands.sh -└── skeleton2/ (DEMO suite -- always succeeds) +├── kata-upstream/ (real suite -- upstream Kata e2e) +│ ├── ...-kata-upstream-ref.yaml +│ └── ...-kata-upstream-commands.sh +└── skeleton2/ (DEMO/template suite -- always succeeds) ├── ...-skeleton2-ref.yaml └── ...-skeleton2-commands.sh ``` ## Enable convention -Each suite is gated by `TEST__ENABLE`, **skip-by-default**: +Each suite is gated by `TESTS__ENABLE`, **skip-by-default**: - `== "true"` → the suite runs and logs its result. - `"false"` or unset → the suite logs the value and exits 0 (graceful skip). @@ -85,23 +85,21 @@ Each suite is gated by `TEST__ENABLE`, **skip-by-default**: Every suite writes a JUnit file to `${ARTIFACT_DIR}/junit_.xml` in **both** the run and skip paths, so Prow always ingests a result. -## The `skeleton` / `skeleton2` steps are a DEMO — disabled by default +## The `skeleton2` step is a DEMO — disabled by default -`skeleton` and `skeleton2` are **demonstration** suites, not real tests. They exist -to prove the non-blocking wiring end-to-end and to serve as a copy-paste template -for real suites. They are **disabled by default** (`TEST_SKELETON_ENABLE` and -`TEST_SKELETON2_ENABLE` default to `"false"` in their refs), so in normal jobs they -just log the value and exit 0. +`skeleton2` is a **demonstration/template** suite, not a real test. It exists to +prove the non-blocking wiring end-to-end and to serve as a copy-paste template for +real suites. It is **disabled by default** (`TESTS_SKELETON2_ENABLE` defaults to +`"false"` in its ref), so in normal jobs it just logs the value and exits 0. -| Step | When enabled (`..._ENABLE=true`) | JUnit | -|-------------|-------------------------------------------------------------------|--------------------------| -| `skeleton` | **Deliberately fails** (exit 1) to show a failing suite is non-blocking | `` in `junit_skeleton.xml` | -| `skeleton2` | **Always succeeds** (exit 0); runs after `skeleton` | passing `junit_skeleton2.xml` | +| Step | When enabled (`TESTS_SKELETON2_ENABLE=true`) | JUnit | +|-------------|-------------------------------------------------------|-------------------------------| +| `skeleton2` | **Always succeeds** (exit 0) | passing `junit_skeleton2.xml` | -Enabling both on a job demonstrates the key behaviour: `skeleton` fails, yet -`skeleton2` still runs and passes, and the post phase continues through must-gather -and deprovision. Because they are demos, do **not** enable them on production -periodics (enabling `skeleton` makes that job red every run by design). +Because `skeleton2` runs after `kata-upstream` in the chain and always passes, it +also demonstrates the key behaviour: a later suite still runs and passes even when +an earlier suite failed, and the post phase continues through must-gather and +deprovision. Because it is a demo, do **not** enable it on production periodics. ## Wiring into a workflow @@ -122,15 +120,16 @@ workflow: ## Adding a real suite 1. Create a step directory under `testsuites/` (e.g. `testsuites//`) with a - `...--ref.yaml` (env `TEST__ENABLE`, default `"false"`) and a + `...--ref.yaml` (env `TESTS__ENABLE`, default `"false"`; + name all suite parameters `TESTS__`) and a `...--commands.sh` (default `set -euo pipefail`; write `${ARTIFACT_DIR}/junit_.xml` in both the run and skip paths). 2. Append the ref to `sandboxed-containers-operator-testsuites-chain.yaml` with `best_effort: true`. 3. Run `make update` (generates the `*.metadata.json` files) and validate with the ci-operator config resolver. -4. Enable it on the desired job(s) by setting `TEST__ENABLE: "true"` in that - job's `steps.env`. +4. Enable it on the desired job(s) by setting `TESTS__ENABLE: "true"` in + that job's `steps.env`. The registry naming rule requires each `as:` name to equal its directory path relative to `step-registry/` with `/` replaced by `-` (e.g. diff --git a/ci-operator/step-registry/sandboxed-containers-operator/testsuites/skeleton/OWNERS b/ci-operator/step-registry/sandboxed-containers-operator/testsuites/kata-upstream/OWNERS similarity index 100% rename from ci-operator/step-registry/sandboxed-containers-operator/testsuites/skeleton/OWNERS rename to ci-operator/step-registry/sandboxed-containers-operator/testsuites/kata-upstream/OWNERS diff --git a/ci-operator/step-registry/sandboxed-containers-operator/testsuites/kata-upstream/sandboxed-containers-operator-testsuites-kata-upstream-commands.sh b/ci-operator/step-registry/sandboxed-containers-operator/testsuites/kata-upstream/sandboxed-containers-operator-testsuites-kata-upstream-commands.sh new file mode 100755 index 0000000000000..84f4f1022c364 --- /dev/null +++ b/ci-operator/step-registry/sandboxed-containers-operator/testsuites/kata-upstream/sandboxed-containers-operator-testsuites-kata-upstream-commands.sh @@ -0,0 +1,129 @@ +#!/bin/bash + +set -euo pipefail +# No -x: this step only echoes non-sensitive values. It does not print the +# kubeconfig or any credentials. Exit code mirrors the upstream runner. + +# Enable-gate: skip-by-default so the suite stays non-blocking in the post chain. +ENABLE="${TESTS_KATA_UPSTREAM_ENABLE:-false}" + +echo "==========================================" +echo "OSC testsuites :: kata-upstream" +echo "TESTS_KATA_UPSTREAM_ENABLE=${ENABLE}" +echo "==========================================" + +if [[ "${ENABLE}" != "true" ]]; then + echo "kata-upstream suite disabled (TESTS_KATA_UPSTREAM_ENABLE=${ENABLE}); exiting 0." + cat > "${ARTIFACT_DIR}/junit_kata_upstream_skip.xml" < + + + + + +EOF + exit 0 +fi + +# --- Configuration ----------------------------------------------------------- +# The upstream test runner lives in the operator repo. We always run the +# runner from the development branch. +OPERATOR_REPO="https://github.com/openshift/sandboxed-containers-operator" +OPERATOR_REF="devel" + +# User-facing parameters (see the ref for defaults/documentation). They follow +# the TESTS__ convention shared by all OSC test suites: +# TESTS_KATA_UPSTREAM_PROFILE -> runner -t/--test +# TESTS_KATA_UPSTREAM_REPO -> runner --tests-repo +# TESTS_KATA_UPSTREAM_REPO_REF -> runner --tests-repo-ref +# Empty values are omitted so the runner falls back to its own defaults. +TEST_PROFILE="${TESTS_KATA_UPSTREAM_PROFILE:-full}" +TESTS_REPO="${TESTS_KATA_UPSTREAM_REPO:-}" +TESTS_REPO_REF="${TESTS_KATA_UPSTREAM_REPO_REF:-}" + +# --- Provide the tools the runner needs --------------------------------------- +# The runner requires: bats yq jq kubectl envsubst oc git. git comes from the +# src image, oc is injected via the ref's `cli` field; anything still missing is +# installed on-demand into a writable dir. Every downloaded artifact is pinned +# to a version and verified against a recorded SHA-256 to guard against +# tampering. (Long term these tools should ship in a pre-built image.) +BINDIR="/tmp/bin" +mkdir -p "${BINDIR}" +export PATH="${BINDIR}:${PATH}" + +# oc is kubectl-compatible; expose it as kubectl since only oc is injected. +command -v kubectl >/dev/null 2>&1 || ln -sf "$(command -v oc)" "${BINDIR}/kubectl" + +# install_verified URL DEST SHA256 +install_verified() { + local url="$1" dest="$2" sha="$3" + echo "Installing $(basename "${dest}") from ${url}" + curl -sSfL "${url}" -o "${dest}" + echo "${sha} ${dest}" | sha256sum -c - + chmod +x "${dest}" +} + +command -v yq >/dev/null 2>&1 || install_verified \ + "https://github.com/mikefarah/yq/releases/download/v4.44.3/yq_linux_amd64" \ + "${BINDIR}/yq" "a2c097180dd884a8d50c956ee16a9cec070f30a7947cf4ebf87d5f36213e9ed7" +command -v jq >/dev/null 2>&1 || install_verified \ + "https://github.com/jqlang/jq/releases/download/jq-1.7.1/jq-linux-amd64" \ + "${BINDIR}/jq" "5942c9b0934e510ee61eb3e30273f1b3fe2590df93933a93d7c58b81d19c8ff5" +command -v envsubst >/dev/null 2>&1 || install_verified \ + "https://github.com/a8m/envsubst/releases/download/v1.4.2/envsubst-Linux-x86_64" \ + "${BINDIR}/envsubst" "a216fad03fb21a5459f57b3e8e02598679229d52e4b24d0c6ed0c46d90d5af3b" + +# bats ships no release binary; clone the pinned tag and verify the resulting +# commit SHA (content-addressed) so a re-pointed tag cannot swap the code. +if ! command -v bats >/dev/null 2>&1; then + echo "Installing bats-core v1.11.1" + git clone --depth 1 -b v1.11.1 https://github.com/bats-core/bats-core /tmp/bats-core + bats_sha="$(git -C /tmp/bats-core rev-parse HEAD)" + if [[ "${bats_sha}" != "b640ec3cf2c7c9cfc9e6351479261186f76eeec8" ]]; then + echo "ERROR: bats-core commit ${bats_sha} does not match the pinned commit" + exit 1 + fi + ln -sf /tmp/bats-core/bin/bats "${BINDIR}/bats" +fi + +for tool in oc kubectl git bats yq jq envsubst; do + command -v "${tool}" >/dev/null 2>&1 || { echo "ERROR: required tool '${tool}' not found on PATH"; exit 1; } +done + +# --- Fetch the operator repo (hosts the runner, setup and manifests) --------- +OPERATOR_DIR="$(mktemp -d /tmp/osc-XXXXXX)" +echo "Cloning ${OPERATOR_REPO} (${OPERATOR_REF})" +git clone --depth 1 -b "${OPERATOR_REF}" "${OPERATOR_REPO}" "${OPERATOR_DIR}" + +# --- Run the upstream test runner -------------------------------------------- +# The runner writes per-suite JUnit under ${RESULTS_DIR}//. +RESULTS_DIR="$(mktemp -d /tmp/kata-results-XXXXXX)" +export RESULTS_DIR + +RUNNER="${OPERATOR_DIR}/test/e2e/run_upstream_tests.sh" +runner_args=(-t "${TEST_PROFILE}") +[[ -n "${TESTS_REPO}" ]] && runner_args+=(--tests-repo "${TESTS_REPO}") +[[ -n "${TESTS_REPO_REF}" ]] && runner_args+=(--tests-repo-ref "${TESTS_REPO_REF}") + +# Log only non-sensitive metadata: a user-supplied tests-repo URL may embed +# credentials, so never echo the raw runner arguments. +echo "Running runner with profile=${TEST_PROFILE}${TESTS_REPO:+ (custom tests-repo)}${TESTS_REPO_REF:+ (custom tests-repo-ref)}" +rc=0 +"${RUNNER}" "${runner_args[@]}" || rc=$? + +# --- Publish JUnit so prow indexes the results ------------------------------- +shopt -s nullglob +found=0 +for xml in "${RESULTS_DIR}"/*/*.xml; do + found=1 + cp "${xml}" "${ARTIFACT_DIR}/junit_kata_upstream_$(basename "${xml}")" +done +if [[ "${found}" -eq 0 ]]; then + # An enabled suite that yields no results is a failure: surface it even when + # the runner itself exited 0, so the step never "passes" silently. + echo "ERROR: no JUnit files produced under ${RESULTS_DIR}; failing the suite" + [[ "${rc}" -eq 0 ]] && rc=1 +fi + +echo "kata-upstream runner exited ${rc}" +exit "${rc}" diff --git a/ci-operator/step-registry/sandboxed-containers-operator/testsuites/skeleton/sandboxed-containers-operator-testsuites-skeleton-ref.metadata.json b/ci-operator/step-registry/sandboxed-containers-operator/testsuites/kata-upstream/sandboxed-containers-operator-testsuites-kata-upstream-ref.metadata.json similarity index 57% rename from ci-operator/step-registry/sandboxed-containers-operator/testsuites/skeleton/sandboxed-containers-operator-testsuites-skeleton-ref.metadata.json rename to ci-operator/step-registry/sandboxed-containers-operator/testsuites/kata-upstream/sandboxed-containers-operator-testsuites-kata-upstream-ref.metadata.json index cc5864a384a61..c3d686e2d3831 100644 --- a/ci-operator/step-registry/sandboxed-containers-operator/testsuites/skeleton/sandboxed-containers-operator-testsuites-skeleton-ref.metadata.json +++ b/ci-operator/step-registry/sandboxed-containers-operator/testsuites/kata-upstream/sandboxed-containers-operator-testsuites-kata-upstream-ref.metadata.json @@ -1,5 +1,5 @@ { - "path": "sandboxed-containers-operator/testsuites/skeleton/sandboxed-containers-operator-testsuites-skeleton-ref.yaml", + "path": "sandboxed-containers-operator/testsuites/kata-upstream/sandboxed-containers-operator-testsuites-kata-upstream-ref.yaml", "owners": { "approvers": [ "ldoktor", diff --git a/ci-operator/step-registry/sandboxed-containers-operator/testsuites/kata-upstream/sandboxed-containers-operator-testsuites-kata-upstream-ref.yaml b/ci-operator/step-registry/sandboxed-containers-operator/testsuites/kata-upstream/sandboxed-containers-operator-testsuites-kata-upstream-ref.yaml new file mode 100644 index 0000000000000..cb1cb4736c6b4 --- /dev/null +++ b/ci-operator/step-registry/sandboxed-containers-operator/testsuites/kata-upstream/sandboxed-containers-operator-testsuites-kata-upstream-ref.yaml @@ -0,0 +1,46 @@ +ref: + as: sandboxed-containers-operator-testsuites-kata-upstream + from: src + cli: latest + commands: sandboxed-containers-operator-testsuites-kata-upstream-commands.sh + resources: + requests: + cpu: 500m + memory: 1Gi + timeout: 45m0s + grace_period: 10m0s + # Environment variables follow the TESTS__ convention + # shared by all OSC test suites (see the testsuites AGENTS.md). + env: + - name: TESTS_KATA_UPSTREAM_ENABLE + default: "false" + documentation: |- + Enable-gate for the upstream Kata Containers test suite (skip-by-default). + "true" -> the step runs the tests. + "false"/unset -> the step writes a skipped JUnit and exits 0. + - name: TESTS_KATA_UPSTREAM_PROFILE + default: "full" + documentation: |- + Test profile/suite passed to the runner via -t/--test. One of + sanity|pods|workloads|resources|volumes|networking|full, or a single + .bats file name. + - name: TESTS_KATA_UPSTREAM_REPO + default: "" + documentation: |- + Kata Containers tests repository passed to the runner via --tests-repo. + Empty uses the runner default (https://github.com/openshift/kata-containers). + - name: TESTS_KATA_UPSTREAM_REPO_REF + default: "" + documentation: |- + Branch or tag of the tests repository passed to the runner via + --tests-repo-ref. Empty uses the runner default (main). + documentation: |- + Run the upstream Kata Containers e2e tests against a cluster that already + has the Sandboxed Containers Operator deployed. + + The step clones the openshift/sandboxed-containers-operator repository + (devel branch) to obtain test/e2e/run_upstream_tests.sh and executes it. + It runs on the src image (which provides git) with oc injected via cli; + tools the runner needs that are still missing (bats, yq, jq, envsubst) are + installed on-demand. Per-suite JUnit results are copied to the artifacts + directory so prow indexes them. diff --git a/ci-operator/step-registry/sandboxed-containers-operator/testsuites/sandboxed-containers-operator-testsuites-chain.yaml b/ci-operator/step-registry/sandboxed-containers-operator/testsuites/sandboxed-containers-operator-testsuites-chain.yaml index ac56cabaf02ab..a585a8dc850b6 100644 --- a/ci-operator/step-registry/sandboxed-containers-operator/testsuites/sandboxed-containers-operator-testsuites-chain.yaml +++ b/ci-operator/step-registry/sandboxed-containers-operator/testsuites/sandboxed-containers-operator-testsuites-chain.yaml @@ -1,7 +1,7 @@ chain: as: sandboxed-containers-operator-testsuites steps: - - ref: sandboxed-containers-operator-testsuites-skeleton + - ref: sandboxed-containers-operator-testsuites-kata-upstream best_effort: true - ref: sandboxed-containers-operator-testsuites-skeleton2 best_effort: true diff --git a/ci-operator/step-registry/sandboxed-containers-operator/testsuites/skeleton/sandboxed-containers-operator-testsuites-skeleton-commands.sh b/ci-operator/step-registry/sandboxed-containers-operator/testsuites/skeleton/sandboxed-containers-operator-testsuites-skeleton-commands.sh deleted file mode 100755 index 6b797915d9cdc..0000000000000 --- a/ci-operator/step-registry/sandboxed-containers-operator/testsuites/skeleton/sandboxed-containers-operator-testsuites-skeleton-commands.sh +++ /dev/null @@ -1,42 +0,0 @@ -#!/bin/bash - -set -euo pipefail -# No -x: this step echoes only non-sensitive values. Exit codes are set -# explicitly (exit 0 on skip, exit 1 on the deliberate enabled failure). - -STEP_NAME="SKELETON" -ENABLE_VAL="${TEST_SKELETON_ENABLE:-false}" -JUNIT="${ARTIFACT_DIR}/junit_skeleton.xml" - -echo "==========================================" -echo "OSC testsuites :: skeleton" -echo "TEST_${STEP_NAME}_ENABLE=${ENABLE_VAL}" -echo "==========================================" - -if [[ "${ENABLE_VAL}" != "true" ]]; then - echo "skeleton suite DISABLED (TEST_${STEP_NAME}_ENABLE=${ENABLE_VAL}); exiting 0." - cat > "${JUNIT}" < - - - - - -EOF - exit 0 -fi - -echo "skeleton suite ENABLED; deliberately failing to demonstrate non-blocking best_effort." -cat > "${JUNIT}" < - - - Skeleton intentionally failed with TEST_SKELETON_ENABLE=true; other suites and post steps must still run. - - -EOF -echo "------------------------------------------" -echo "RESULT: FAILED (skeleton, deliberate)" -echo "JUnit written: ${JUNIT}" -echo "------------------------------------------" -exit 1 diff --git a/ci-operator/step-registry/sandboxed-containers-operator/testsuites/skeleton/sandboxed-containers-operator-testsuites-skeleton-ref.yaml b/ci-operator/step-registry/sandboxed-containers-operator/testsuites/skeleton/sandboxed-containers-operator-testsuites-skeleton-ref.yaml deleted file mode 100644 index dab63cce1c661..0000000000000 --- a/ci-operator/step-registry/sandboxed-containers-operator/testsuites/skeleton/sandboxed-containers-operator-testsuites-skeleton-ref.yaml +++ /dev/null @@ -1,23 +0,0 @@ -ref: - as: sandboxed-containers-operator-testsuites-skeleton - from: cli - commands: sandboxed-containers-operator-testsuites-skeleton-commands.sh - resources: - requests: - cpu: 100m - memory: 200Mi - timeout: 10m0s - grace_period: 1m0s - env: - - name: TEST_SKELETON_ENABLE - default: "false" - documentation: |- - Enable-gate for the skeleton test suite (skip-by-default). - "true" -> the step runs, logs the value, and DELIBERATELY exits 1 to - demonstrate that a failing suite still produces a JUnit artifact - and does not block other suites or post steps. - "false"/unset -> the step logs the value and exits 0 (skipped). - documentation: |- - Skeleton demonstration suite for the OSC testsuites chain. Echoes - TEST_SKELETON_ENABLE and, when enabled, fails on purpose to prove best_effort - non-blocking behaviour. Always writes $ARTIFACT_DIR/junit_skeleton.xml. diff --git a/ci-operator/step-registry/sandboxed-containers-operator/testsuites/skeleton2/sandboxed-containers-operator-testsuites-skeleton2-commands.sh b/ci-operator/step-registry/sandboxed-containers-operator/testsuites/skeleton2/sandboxed-containers-operator-testsuites-skeleton2-commands.sh index 3938120e2cbe0..c24315cb2a7fe 100755 --- a/ci-operator/step-registry/sandboxed-containers-operator/testsuites/skeleton2/sandboxed-containers-operator-testsuites-skeleton2-commands.sh +++ b/ci-operator/step-registry/sandboxed-containers-operator/testsuites/skeleton2/sandboxed-containers-operator-testsuites-skeleton2-commands.sh @@ -5,28 +5,28 @@ set -euo pipefail # explicitly (exit 0 on skip, exit 0 on the deliberate enabled success). STEP_NAME="SKELETON2" -ENABLE_VAL="${TEST_SKELETON2_ENABLE:-false}" +ENABLE_VAL="${TESTS_SKELETON2_ENABLE:-false}" JUNIT="${ARTIFACT_DIR}/junit_skeleton2.xml" echo "==========================================" echo "OSC testsuites :: skeleton2" -echo "TEST_${STEP_NAME}_ENABLE=${ENABLE_VAL}" +echo "TESTS_${STEP_NAME}_ENABLE=${ENABLE_VAL}" echo "==========================================" if [[ "${ENABLE_VAL}" != "true" ]]; then - echo "skeleton2 suite DISABLED (TEST_${STEP_NAME}_ENABLE=${ENABLE_VAL}); exiting 0." + echo "skeleton2 suite DISABLED (TESTS_${STEP_NAME}_ENABLE=${ENABLE_VAL}); exiting 0." cat > "${JUNIT}" < - + EOF exit 0 fi -echo "skeleton2 suite ENABLED; always succeeds -- demonstrates it runs even after skeleton fails." +echo "skeleton2 suite ENABLED; always succeeds -- demonstrates it runs even after an earlier suite fails." cat > "${JUNIT}" < diff --git a/ci-operator/step-registry/sandboxed-containers-operator/testsuites/skeleton2/sandboxed-containers-operator-testsuites-skeleton2-ref.yaml b/ci-operator/step-registry/sandboxed-containers-operator/testsuites/skeleton2/sandboxed-containers-operator-testsuites-skeleton2-ref.yaml index 4bfe2dd2c6698..237495805a543 100644 --- a/ci-operator/step-registry/sandboxed-containers-operator/testsuites/skeleton2/sandboxed-containers-operator-testsuites-skeleton2-ref.yaml +++ b/ci-operator/step-registry/sandboxed-containers-operator/testsuites/skeleton2/sandboxed-containers-operator-testsuites-skeleton2-ref.yaml @@ -8,15 +8,17 @@ ref: memory: 200Mi timeout: 10m0s grace_period: 1m0s + # Environment variables follow the TESTS__ convention + # shared by all OSC test suites (see the testsuites AGENTS.md). env: - - name: TEST_SKELETON2_ENABLE + - name: TESTS_SKELETON2_ENABLE default: "false" documentation: |- Enable-gate for the skeleton2 test suite (skip-by-default). "true" -> the step runs, logs the value, and exits 0 (always succeeds). "false"/unset -> the step logs the value and exits 0 (skipped). documentation: |- - Second skeleton demonstration suite for the OSC testsuites chain. Runs after - the skeleton step and, when enabled, always succeeds -- proving that a later - suite still runs and passes even when an earlier suite (skeleton) failed. + Demonstration/template suite for the OSC testsuites chain. Runs after the + other suites in the chain and, when enabled, always succeeds -- proving that + a later suite still runs and passes even when an earlier suite failed. Always writes $ARTIFACT_DIR/junit_skeleton2.xml.