Skip to content

NO-JIRA: sync with upstream 2026-07-23 - #405

Merged
openshift-merge-bot[bot] merged 16 commits into
mainfrom
upstream-sync
Aug 4, 2026
Merged

NO-JIRA: sync with upstream 2026-07-23#405
openshift-merge-bot[bot] merged 16 commits into
mainfrom
upstream-sync

Conversation

@openshift-ci-robot

@openshift-ci-robot openshift-ci-robot commented Jul 23, 2026

Copy link
Copy Markdown

🔄 Upstream Sync

Update: Tue Aug 4 08:04:32 UTC 2026

New changes detected from upstream:

Signed-off-by: Calum Murray <cmurray@redhat.com>
@openshift-ci-robot openshift-ci-robot added the jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. label Jul 23, 2026
@openshift-ci-robot

Copy link
Copy Markdown
Author

@openshift-ci-robot: This pull request explicitly references no jira issue.

Details

In response to this:

🔄 Upstream Sync

This PR syncs the fork with the latest upstream changes.

Changes:

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@coderabbitai

coderabbitai Bot commented Jul 23, 2026

Copy link
Copy Markdown

Important

Review skipped

Ignore keyword(s) in the title.

⛔ Ignored keywords (1)
  • NO-JIRA: sync with upstream

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 9346bac2-01f1-4baf-810b-4d7d42b3e17d

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch upstream-sync

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@openshift-ci
openshift-ci Bot requested review from 2uasimojo and bentito July 23, 2026 08:03
Cali0707 and others added 4 commits July 23, 2026 14:47
* cleanup: point eval targets and docs to new eval format

Signed-off-by: Calum Murray <cmurray@redhat.com>

* cleanup: remove unused old eval suites

Signed-off-by: Calum Murray <cmurray@redhat.com>

---------

Signed-off-by: Calum Murray <cmurray@redhat.com>
…ners#1327)

Follow-up to containers#1325 / containers#1314. containers#1325 removed the top-level
evals/claude-code and evals/openai-agent configs but left a few
references to the retired agent naming behind.

- Delete evals/tasks/kubevirt/{claude-code,openai-agent}/eval.yaml:
  old-format (type: "builtin.claude-code" / "builtin.llm-agent") under
  retired agent-named dirs, unreachable via the new agent names, and
  redundant with evals/core-eval-testing/<agent>/eval-kubevirt.yaml.
- Reword the "Eval configs" priority list in evals/README.md so the
  per-suite override no longer claims kubevirt ships one (none do now)
  and core-eval-testing is documented as the canonical config.
- Point the toolset-design review checklist at
  evals/core-eval-testing/<agent>/eval-<suite>.yaml instead of the old
  claude-code / openai-agent names.

Signed-off-by: Marc Nuri <marc@marcnuri.com>
Signed-off-by: Calum Murray <cmurray@redhat.com>
Bumps the kubernetes group with 8 updates:

| Package | From | To |
| --- | --- | --- |
| [k8s.io/api](https://github.com/kubernetes/api) | `0.36.2` | `0.36.3` |
| [k8s.io/apiextensions-apiserver](https://github.com/kubernetes/apiextensions-apiserver) | `0.36.2` | `0.36.3` |
| [k8s.io/apimachinery](https://github.com/kubernetes/apimachinery) | `0.36.2` | `0.36.3` |
| [k8s.io/cli-runtime](https://github.com/kubernetes/cli-runtime) | `0.36.2` | `0.36.3` |
| [k8s.io/client-go](https://github.com/kubernetes/client-go) | `0.36.2` | `0.36.3` |
| [k8s.io/kubectl](https://github.com/kubernetes/kubectl) | `0.36.2` | `0.36.3` |
| [k8s.io/metrics](https://github.com/kubernetes/metrics) | `0.36.2` | `0.36.3` |
| [k8s.io/streaming](https://github.com/kubernetes/streaming) | `0.36.2` | `0.36.3` |


Updates `k8s.io/api` from 0.36.2 to 0.36.3
- [Commits](kubernetes/api@v0.36.2...v0.36.3)

Updates `k8s.io/apiextensions-apiserver` from 0.36.2 to 0.36.3
- [Release notes](https://github.com/kubernetes/apiextensions-apiserver/releases)
- [Commits](kubernetes/apiextensions-apiserver@v0.36.2...v0.36.3)

Updates `k8s.io/apimachinery` from 0.36.2 to 0.36.3
- [Commits](kubernetes/apimachinery@v0.36.2...v0.36.3)

Updates `k8s.io/cli-runtime` from 0.36.2 to 0.36.3
- [Commits](kubernetes/cli-runtime@v0.36.2...v0.36.3)

Updates `k8s.io/client-go` from 0.36.2 to 0.36.3
- [Changelog](https://github.com/kubernetes/client-go/blob/master/CHANGELOG.md)
- [Commits](kubernetes/client-go@v0.36.2...v0.36.3)

Updates `k8s.io/kubectl` from 0.36.2 to 0.36.3
- [Commits](kubernetes/kubectl@v0.36.2...v0.36.3)

Updates `k8s.io/metrics` from 0.36.2 to 0.36.3
- [Commits](kubernetes/metrics@v0.36.2...v0.36.3)

Updates `k8s.io/streaming` from 0.36.2 to 0.36.3
- [Commits](kubernetes/streaming@v0.36.2...v0.36.3)

---
updated-dependencies:
- dependency-name: k8s.io/api
  dependency-version: 0.36.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: kubernetes
- dependency-name: k8s.io/apiextensions-apiserver
  dependency-version: 0.36.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: kubernetes
- dependency-name: k8s.io/apimachinery
  dependency-version: 0.36.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: kubernetes
- dependency-name: k8s.io/cli-runtime
  dependency-version: 0.36.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: kubernetes
- dependency-name: k8s.io/client-go
  dependency-version: 0.36.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: kubernetes
- dependency-name: k8s.io/kubectl
  dependency-version: 0.36.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: kubernetes
- dependency-name: k8s.io/metrics
  dependency-version: 0.36.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: kubernetes
- dependency-name: k8s.io/streaming
  dependency-version: 0.36.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: kubernetes
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

@2uasimojo 2uasimojo left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is there a reason we wouldn't auto-merge sync PRs with green CI?

@Cali0707

Copy link
Copy Markdown

Overall I'm happy with auto merge once we fix a few issues with the sync (currently it can overwrite the README tools list...)

dependabot Bot and others added 5 commits July 27, 2026 06:11
Bumps [github.com/prometheus/client_golang](https://github.com/prometheus/client_golang) from 1.23.2 to 1.24.1.
- [Release notes](https://github.com/prometheus/client_golang/releases)
- [Changelog](https://github.com/prometheus/client_golang/blob/v1.24.1/CHANGELOG.md)
- [Commits](prometheus/client_golang@v1.23.2...v1.24.1)

---
updated-dependencies:
- dependency-name: github.com/prometheus/client_golang
  dependency-version: 1.24.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: Calum Murray <cmurray@redhat.com>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
With this change, if `--config` is not given on the CLI, we will look
for an environment variable specifying a path to the main config file.

The variable is spelled `$K8S_MCP_CONFIG_PATH` here, but this change
includes an override mechanism so downstreams can choose their own
spelling.

Signed-off-by: Eric Fried <efried@redhat.com>
Signed-off-by: Calum Murray <cmurray@redhat.com>
@openshift-ci openshift-ci Bot added the lgtm Indicates that a PR is ready to be merged. label Jul 29, 2026
@openshift-ci openshift-ci Bot removed the lgtm Indicates that a PR is ready to be merged. label Jul 31, 2026
sradco and others added 2 commits July 31, 2026 10:13
…containers#1239)

* feat(kubevirt): add vm_troubleshoot tool with
automated issue detection for small-model performance

Adds a new vm_troubleshoot MCP Tool that collects
comprehensive diagnostic data for KubeVirt VMs and
runs heuristic checks to produce pre-digested
"Detected Issues" and "Suggested Fixes" sections.
This enables small LLMs (e.g. gpt-4o-mini) to relay
actionable findings without synthesizing root causes
from raw YAML.

Diagnostic data collected:
- VM/VMI status and conditions
- DataVolume/PVC state with StorageClass info
- Cloud-init configuration (sensitive fields redacted)
- virt-launcher pod state and logs
- Related events (field-selector targeted)

Heuristic checks implemented:
- Missing StorageClass with available SC list
- DataVolume/PVC errors with SC deduplication
- Dangerous cloud-init commands (shutdown, poweroff,
  halt, reboot, systemctl variants, init 0/6)
- Hostname nodeSelector migration blockers
- Pod crashloops and OOMKill detection
- Failed VirtualMachineInstanceMigration detection
- VM condition analysis (Ready=False reasons)

Key design decisions:
- float64-safe numeric conversion for real cluster
  data (K8s JSON deserializes numbers as float64)
- False-positive prevention in cloud-init parsing
- Deduplication between StorageClass and DV errors
- API call limiting (Limit: 50) for migrations

Signed-off-by: Shirly Radco <sradco@redhat.com>
Co-authored-by: AI Assistant <noreply@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>

* eval(kubevirt): add vm_troubleshoot tool evals for
missing StorageClass and cloud-init crashloop

Adds two eval tasks that exercise the vm_troubleshoot
tool's heuristic issue detection:

1. troubleshoot-vm-missing-storageclass: Creates a VM
   referencing a non-existent StorageClass. Verifies
   the agent calls vm_troubleshoot and reports the
   CRITICAL missing SC finding with alternatives.

2. troubleshoot-vm-cloudinit-shutdown: Creates a VM
   with "shutdown -h now" in cloud-init runcmd that
   causes CrashLoopBackOff. Verifies the agent
   identifies the dangerous command as root cause.

Both scenarios are deterministic and non-flaky on any
cluster with KubeVirt installed.

Signed-off-by: Shirly Radco <sradco@redhat.com>
Co-authored-by: AI Assistant <noreply@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(kubevirt): redact base64 cloud-init variants in vm_troubleshoot

The Volumes section dumped userDataBase64/networkDataBase64 verbatim
because stripCloudInitBodies only stripped the plain-text userData and
networkData keys. Base64 is not a security control, so any VM using the
base64 cloud-init fields leaked the secrets the Cloud-Init Configuration
section is careful to redact.

Strip the base64 variants from the raw volume dump too, and decode and
redact them in extractCloudInit via a new cloudInitData helper so the
payload stays diagnosable while always flowing through redaction.

Signed-off-by: Marc Nuri <marc@marcnuri.com>
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* test(kubevirt): assert vm_troubleshoot surfaces detected root causes

The MCP-layer test only exercised a healthy VM, so the heuristic
analysis engine was never validated end to end. Add fault-injection
subtests that create a broken VM (dangerous cloud-init command and a
missing StorageClass) and assert the report surfaces the Detected
Issues / Suggested Fixes sections and the exact strings the kubevirt
troubleshoot evals judge on (shutdown -h now, non-existent-sc-xyz).

Signed-off-by: Marc Nuri <marc@marcnuri.com>
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Signed-off-by: Shirly Radco <sradco@redhat.com>
Signed-off-by: Marc Nuri <marc@marcnuri.com>
Co-authored-by: AI Assistant <noreply@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Marc Nuri <marc@marcnuri.com>
Co-authored-by: Claude Opus <noreply@anthropic.com>
* feat(mcp): add 2026-07-28 spec support

Signed-off-by: Calum Murray <cmurray@redhat.com>

* chore: update test snapshots for new mcp sdk

Signed-off-by: Calum Murray <cmurray@redhat.com>

---------

Signed-off-by: Calum Murray <cmurray@redhat.com>
@openshift-ci

openshift-ci Bot commented Aug 4, 2026

Copy link
Copy Markdown

@openshift-ci-robot: all tests passed!

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

@Cali0707 Cali0707 left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm
/approve

@openshift-ci openshift-ci Bot added the lgtm Indicates that a PR is ready to be merged. label Aug 4, 2026
@openshift-ci

openshift-ci Bot commented Aug 4, 2026

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: Cali0707, grokspawn, openshift-ci-robot

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci openshift-ci Bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Aug 4, 2026
@openshift-merge-bot
openshift-merge-bot Bot merged commit 2468a3c into main Aug 4, 2026
11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. lgtm Indicates that a PR is ready to be merged.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants