Skip to content

test: add acceptance coverage for the ITS pipeline - #3591

Open
dheerajodha wants to merge 3 commits into
conforma:mainfrom
dheerajodha:EC-1948
Open

dheerajodha wants to merge 3 commits into
conforma:mainfrom
dheerajodha:EC-1948

Conversation

@dheerajodha

@dheerajodha dheerajodha commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

What:

Add acceptance coverage for the ITS pipeline in a kind cluster using the pipeline definition and task bundles from the checkout. Five scenario executions cover a trusted signed image passing validation, image lookup failures with both values of STRICT, and untrusted image/attestation signatures with both values of STRICT. Each checks both PipelineRun completion and the pipeline's TEST_OUTPUT result.

The untrusted-signature scenarios create and sign an image with an untrusted key, then verify it against the known public key. The missing-image scenarios remain separate lookup-failure coverage.

The Kubernetes test helpers launch and await PipelineRuns with a bounded timeout. Rename the existing keyless ConfigMap fixture so its dummy service URLs do not affect concurrent pipeline tests.

Why:

Catch pipeline wiring and verification regressions in the CLI repository before merge, complementing the separate e2e coverage. The scenarios run in the existing acceptance suite and PR Checks workflow, which already includes pipeline-only changes.

Validation:

  • The original three-scenario version passed the CI acceptance suite.
  • The expanded feature parses into five executions with Godog; all step texts match existing step registrations. Execution of the new cases is pending CI.
  • CGO_ENABLED=0 go test ./kubernetes/... in the acceptance module passed (package compilation), including after rebasing. No Go helpers changed in the scenario expansion.
  • Repository golangci-lint on ./kubernetes/... previously passed with zero issues.
  • git diff --check: passed.
  • Local end-to-end testing remains blocked by the existing Podman memory and macOS-to-Linux test-image build issues described during development.

Tickets:

EC-1948

@coderabbitai

coderabbitai Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Enterprise
  • Run ID: 9801015f-5285-4ca5-beec-9a16bfe1c460
📥 Commits

Reviewing files that changed from the base of the PR and between 96186bb and 3904095.

📒 Files selected for processing (2)
  • acceptance/README.md
  • features/pipeline_validate_image.feature

Included review availability: This review used your included allowance. Your plan provides up to 12 included reviews per hour; 11 remain after this review.


📝 Walkthrough

Walkthrough

The acceptance framework now runs repository pipeline definitions in kind and checks PipelineRun outcomes and results. New scenarios cover trusted signed images, missing images, and untrusted signatures. The README documents the coverage, and a task-test ConfigMap name changed.

Changes

ITS pipeline acceptance

Layer / File(s) Summary
Pipeline execution in kind
acceptance/kubernetes/types/types.go, acceptance/kubernetes/kind/kind.go, acceptance/kubernetes/kind/pipeline.go, acceptance/kubernetes/stub/stub.go
The Cluster interface adds pipeline execution and completion methods, and PipelineInfo describes completion data. The kind implementation loads local pipeline definitions, replaces task bundle parameters, creates PipelineRuns, and polls for completion. The stub returns errors for pipeline operations.
Pipeline acceptance steps
acceptance/kubernetes/pipeline.go, acceptance/kubernetes/kubernetes.go
Godog steps run a versioned pipeline, check whether it succeeds or fails, and compare its TEST_OUTPUT result. Kubernetes acceptance setup registers the steps.
Image validation scenarios and guidance
features/pipeline_validate_image.feature, features/task_validate_image.feature, acceptance/README.md
The new feature covers trusted signed-image success and missing-image and untrusted-signature outcomes for both STRICT values. The task feature uses cluster-config-keyless. The README documents the scenarios, command, workflow coverage, and ConfigMap fixture restriction.

Priority: ➖ Normal

Estimated code review effort: 3 (Moderate) | ~20 minutes

Change: Other

Sequence Diagram(s)

sequenceDiagram
  participant GodogSteps
  participant kindCluster
  participant KubernetesAPI
  GodogSteps->>kindCluster: RunPipeline with pipeline parameters
  kindCluster->>KubernetesAPI: Create PipelineRun
  GodogSteps->>kindCluster: AwaitUntilPipelineIsDone
  kindCluster->>KubernetesAPI: Poll PipelineRun
  KubernetesAPI-->>kindCluster: Completion status and results
  kindCluster-->>GodogSteps: PipelineInfo
Loading

Suggested reviewers: joejstuart, simonbaird

Merge Risk: ⚪ Minimal · up to 39040

The added kind scenarios check trusted-image success and strict-dependent failure handling, including the pipeline result. Their assertions match the inspected pipeline behavior; no concrete merge-blocking risk remains.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 33.33% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 6 functions across 6 files. (2 skipped: 2… Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title clearly summarizes the main change: adding acceptance coverage for the ITS pipeline.
Description check ✅ Passed The description covers what the change does, why it is needed, and the related ticket. It also provides useful validation details.
Full details: Docstring Coverage

Explanation

Docstring coverage is 33.33% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 6 functions across 6 files. (2 skipped: 2 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Create a new PR

Comment @coderabbitai help to get the list of available commands.

@fullsend-ai-review fullsend-ai-review Bot added the risk/moderate PR risk: moderate label Sep 28, 2026
@fullsend-ai-review

Copy link
Copy Markdown

Risk Assessment: moderate (2/5)

Details

All changes are test/acceptance code with no production paths touched, but the XL size, new Cluster-interface method additions, and rename of a shared test fixture in a stable directory each contribute incremental integration risk, landing the PR at moderate.

@fullsend-ai-review

Copy link
Copy Markdown

Looks good to me

@fullsend-ai-review fullsend-ai-review Bot added the requires-manual-review Review requires human judgment label Sep 28, 2026
@codecov

codecov Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

Flag Coverage Δ
acceptance 54.51% <ø> (ø)
generative 12.25% <ø> (ø)
integration 23.56% <ø> (ø)
unit 72.24% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@dheerajodha
dheerajodha marked this pull request as ready for review October 1, 2026 13:10
@dheerajodha
dheerajodha requested a review from a team as a code owner October 1, 2026 13:10
@fullsend-ai-review

Copy link
Copy Markdown

🤖 Finished Review · ❌ Failure (ensuring provider "vertex-ai": provider create "vertex-ai" failed: exit status 1 (output: Error: × code: 'Client specified an invalid argument', message: "provider │ credentials are not declared by pr…) · Started 1:12 PM UTC · Completed 1:12 PM UTC

Commit: 92a766c · View workflow run →

Effort: high

@fullsend-ai-review

Copy link
Copy Markdown

🤖 Finished Review · ❌ Failure (ensuring provider "vertex-ai": provider create "vertex-ai" failed: exit status 1 (output: Error: × code: 'Client specified an invalid argument', message: "provider │ credentials are not declared by pr…) · Started 11:52 AM UTC · Completed 11:52 AM UTC

Commit: 96186bb · View workflow run →

Effort: high

st3penta
st3penta previously approved these changes Oct 6, 2026

@st3penta st3penta left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm, with a couple of nitpicks

@@ -0,0 +1,41 @@
@its-pipeline

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

leftover?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks like it, idky the bot thought we'd need a GoDog tag for focused testing of these scenarios in main. Removed, thanks!

Comment on lines +29 to +31
Scenario Outline: ITS pipeline handles validation failures according to STRICT
When version 0.1 of the pipeline named "enterprise-contract" is run with parameters:
| SNAPSHOT | {"components": [{"containerImage": "${REGISTRY}/acceptance/its-missing"}]} |

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nitpick: this scenario doesn't create the image 'its-missing', so it tests image lookup failure rather than a validation failure. Consider adding something like:

Given an image named "acceptance/its-missing"
And a valid attestation of "acceptance/its-missing" signed by the "known" key

so that the validation fails for the missing image signature.
The outcome of the test is the same, but the scenario is more precise

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good point, I modified that into image lookup failures scenario, and added 2 new scenarios for "ITS pipeline handles untrusted signatures".

@fullsend-ai-review

Copy link
Copy Markdown

🤖 Finished Review · ❌ Failure (ensuring provider "github-ro": provider create "github-ro" failed: exit status 1 (output: Error: × code: 'Client specified an invalid argument', message: "provider │ credentials are not declared by pr…) · Started 1:23 PM UTC · Completed 1:23 PM UTC

Commit: 0d14308 · View workflow run →

Effort: high

@fullsend-ai-review

Copy link
Copy Markdown

🤖 Finished Review · ❌ Failure (ensuring provider "vertex-ai": provider create "vertex-ai" failed: exit status 1 (output: Error: × code: 'Client specified an invalid argument', message: "provider │ credentials are not declared by pr…) · Started 1:29 PM UTC · Completed 1:29 PM UTC

Commit: 3904095 · View workflow run →

Effort: high

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

requires-manual-review Review requires human judgment risk/moderate PR risk: moderate size: XL

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants