Skip to content

chore: use latest supported OCP - #643

Merged
bouskaJ merged 1 commit into
mainfrom
use_latest_supported_ocp
Oct 5, 2026
Merged

bouskaJ merged 1 commit into
mainfrom
use_latest_supported_ocp

Conversation

@bouskaJ

@bouskaJ bouskaJ commented Oct 5, 2026

Copy link
Copy Markdown
Member

No description provided.

@github-actions

github-actions Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Configuration Diff

15 document(s) impacted:

+ 0 added
- 0 removed
! 15 modified
Diff
@@ spec.template.values @@
# projctl.konflux.dev/v1beta1/ProjectDevelopmentStream/rhtas-tenant/ansible-v1-3
! + one list entry added:
+   - name: ocpVersion
+     value: 4.21

@@ spec.template.values @@
# projctl.konflux.dev/v1beta1/ProjectDevelopmentStream/rhtas-tenant/cli-stacks-v1-3
! + one list entry added:
+   - name: ocpVersion
+     value: 4.21

@@ spec.template.values @@
# projctl.konflux.dev/v1beta1/ProjectDevelopmentStream/rhtas-tenant/client-server-v1-3
! + one list entry added:
+   - name: ocpVersion
+     value: 4.21

@@ spec.template.values @@
# projctl.konflux.dev/v1beta1/ProjectDevelopmentStream/rhtas-tenant/create-tree-v1-3
! + one list entry added:
+   - name: ocpVersion
+     value: 4.21

@@ spec.template.values @@
# projctl.konflux.dev/v1beta1/ProjectDevelopmentStream/rhtas-tenant/operator-v1-3
! + one list entry added:
+   - name: ocpVersion
+     value: 4.21

@@ spec.template.values @@
# projctl.konflux.dev/v1beta1/ProjectDevelopmentStream/rhtas-tenant/rekor-monitor-v1-3
! + one list entry added:
+   - name: ocpVersion
+     value: 4.21

@@ spec.template.values @@
# projctl.konflux.dev/v1beta1/ProjectDevelopmentStream/rhtas-tenant/segment-backup-job-v1-3
! + one list entry added:
+   - name: ocpVersion
+     value: 4.21

@@ spec.template.values @@
# projctl.konflux.dev/v1beta1/ProjectDevelopmentStream/rhtas-tenant/tas-components-v1-3
! + one list entry added:
+   - name: ocpVersion
+     value: 4.21

@@ spec.template.values @@
# projctl.konflux.dev/v1beta1/ProjectDevelopmentStream/rhtas-tenant/tas-tools-v1-3
! + one list entry added:
+   - name: ocpVersion
+     value: 4.21

@@ spec.template.values @@
# projctl.konflux.dev/v1beta1/ProjectDevelopmentStream/rhtas-tenant/tough-v1-3
! + one list entry added:
+   - name: ocpVersion
+     value: 4.21

@@ spec.template.values @@
# projctl.konflux.dev/v1beta1/ProjectDevelopmentStream/rhtas-tenant/tufcli-v1-3
! + one list entry added:
+   - name: ocpVersion
+     value: 4.21

@@ spec.resources.appstudio.redhat.com/v1beta2/IntegrationTestScenario/rhtas-operator-e2e-test{{.nameSuffix}}.spec.params @@
# projctl.konflux.dev/v1beta1/ProjectDevelopmentStreamTemplate/rhtas-tenant/operator-template
! + one list entry added:
+   - name: OCP_VERSION
+     value: {{.ocpVersion}}

@@ spec.resources.appstudio.redhat.com/v1beta2/IntegrationTestScenario/rhtas-operator-e2e-test{{.nameSuffix}}-fips.spec.params @@
# projctl.konflux.dev/v1beta1/ProjectDevelopmentStreamTemplate/rhtas-tenant/operator-template
! + one list entry added:
+   - name: OCP_VERSION
+     value: {{.ocpVersion}}

@@ spec.variables @@
# projctl.konflux.dev/v1beta1/ProjectDevelopmentStreamTemplate/rhtas-tenant/operator-template
! + one list entry added:
+   - name: ocpVersion
+     defaultValue: 4.22
+     description: "OCP version for e2e tests"

@@ spec.resources.appstudio.redhat.com/v1beta2/IntegrationTestScenario/{{.application}}{{.nameSuffix}}-v4-19-dast.spec @@
# projctl.konflux.dev/v1beta1/ProjectDevelopmentStreamTemplate/rhtas-tenant/rhtas-fbc-template
! + one map entry added:
+   params:
+   - name: OCP_VERSION
+     value: {{.ocpVersion}}

📦 Artifacts: base-output.yaml, head-output.yaml, dyff-output.txt

@bouskaJ
bouskaJ marked this pull request as ready for review October 5, 2026 11:53
@qodo-for-securesign

Copy link
Copy Markdown

PR Summary by Qodo

Select supported OCP versions for operator integration tests

⚙️ Configuration changes 🕐 20-40 Minutes

Grey Divider

AI Description

• Default operator end-to-end tests to OCP 4.22, with OCP 4.21 for the v1.3 stream.
• Pass the stream’s OCP version to standard and FIPS operator test scenarios.
• Require an explicit OCP version in four integration pipelines instead of falling back to 4.19.
Diagram

graph TD
  T["Operator template"] --> S["Operator scenarios"] --> R["Integration runs"] --> C["OCP clusters"]
  V["v1.3 override"] --> S
  F["FBC scenarios"] --> R
Loading
High-Level Assessment

The existing template default and stream override provide a single place to select each stream’s version. Keeping pipeline versions explicit is preferable to replacing the old 4.19 fallback with another hard-coded pipeline default, which could silently test the wrong release.

Files changed (7) +9 / -4

Other (7) +9 / -4
e2e.yamlPass the stream OCP version to operator end-to-end scenarios +4/-0

Pass the stream OCP version to operator end-to-end scenarios

• Adds OCP_VERSION to both the standard and FIPS IntegrationTestScenario parameters, using the template’s ocpVersion variable.

konflux-configs/base/project/overlay/rhtas-operator/patch/e2e.yaml

template.yamlDefault operator test streams to OCP 4.22 +3/-0

Default operator test streams to OCP 4.22

• Introduces an ocpVersion template variable with a 4.22 default for operator end-to-end tests.

konflux-configs/base/project/overlay/rhtas-operator/template.yaml

stream.yamlSelect OCP 4.21 for the v1.3 stream +2/-0

Select OCP 4.21 for the v1.3 stream

• Overrides the operator template’s OCP version for release-1.3, so its end-to-end scenarios use 4.21 instead of the 4.22 default.

konflux-configs/base/stream/rhtas/overlay/v1-3/patch/stream.yaml

operator-dast.yamlRequire an OCP version for operator DAST +0/-1

Require an OCP version for operator DAST

• Removes the OCP_VERSION parameter’s 4.19 default, requiring the invoking scenario to supply a version.

pipelines/integration-test/operator-dast.yaml

operator-upgrade.yamlRequire an OCP version for operator upgrade tests +0/-1

Require an OCP version for operator upgrade tests

• Removes the OCP_VERSION parameter’s 4.19 default so upgrade tests use the version supplied by their scenario.

pipelines/integration-test/operator-upgrade.yaml

rhtas-fbc-e2e.yamlRequire an OCP version for FBC end-to-end tests +0/-1

Require an OCP version for FBC end-to-end tests

• Removes the OCP_VERSION parameter’s 4.19 default, leaving version selection to the invoking scenario.

pipelines/integration-test/rhtas-fbc-e2e.yaml

rhtas-operator-e2e.yamlRequire an OCP version for operator end-to-end tests +0/-1

Require an OCP version for operator end-to-end tests

• Removes the OCP_VERSION parameter’s 4.19 default; the updated operator scenarios now supply the stream-selected version.

pipelines/integration-test/rhtas-operator-e2e.yaml

@qodo-for-securesign

qodo-for-securesign Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (0) 📘 Rule violations (0) 🔗 Cross-repo conflicts (0) 📜 Skill insights (0)

Grey Divider


Action required

1. Catalog DAST tests cannot start ✓ Resolved
Description
operator-dast.yaml removes the OCP_VERSION default, making the parameter required, but the v4.19
DAST IntegrationTestScenario invokes the pipeline without supplying it. When the scenario runs for
the securesign/fbc v4.19 operator catalog component, Tekton rejects the run before release
derivation, cluster provisioning, catalog validation, or installed-operator validation can proceed.
Code

pipelines/integration-test/operator-dast.yaml[20]

-        default: "4.19"
Relevance

●●● Strong

The v4.19 scenario omits newly required OCP_VERSION, causing Tekton rejection; parameter propagation
fixes were previously accepted.

PR-#358
PR-#596

ⓘ Recommendations generated based on similar findings in past PRs

Evidence
The pipeline declares OCP_VERSION without a default and later references it for release
derivation. The active FBC template's v4.19 DAST scenario points to that pipeline without a params
section, while the FBC repository builds the matching v4.19 operator catalog component.

pipelines -> fbc
pipelines/integration-test/operator-dast.yaml[17-21]
konflux-configs/base/project/base/ocp/rhtas/v4.19/patch.yaml[113-135]
konflux-configs/base/project/overlay/rhtas-fbc/kustomization.yaml[4-13]
pipelines/integration-test/operator-dast.yaml[15-20]
konflux-configs/base/project/base/ocp/rhtas/v4.19/patch.yaml[120-136]
pipelines/integration-test/operator-dast.yaml[56-62]
External repo: securesign/fbc, .tekton/rhtas-fbc-v4-19-push.yaml [13-42]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
Removing the DAST pipeline's `OCP_VERSION` default leaves the v4.19 FBC IntegrationTestScenario without a required parameter, preventing its test from running.

## Fix Focus Areas
- konflux-configs/base/project/base/ocp/rhtas/v4.19/patch.yaml[120-136]
- pipelines/integration-test/operator-dast.yaml[17-20]

## Recommended Fix
Add `spec.params` to the v4.19 DAST IntegrationTestScenario with `OCP_VERSION: "4.19"`, matching the removed default and the neighboring v4.19 scenarios.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


Grey Divider

Context sources
✅ Cross-repo context — repo relationships
  Explored: repo: securesign/fbc (sha: 61a9b735) — View relationship
  Explored: repo: securesign/sigstore-e2e (sha: 66ad6a7b) — View relationship
  Explored: repo: securesign/secure-sign-operator (branch: release-1.3, sha: 4a8fe1b9) — View relationship
Review mode: Auto: ⚖️ Balanced: This changes OCP version parameter propagation and defaults across multiple pipeline and Konflux configuration paths, creating behavioral compatibility risk despite the small diff.

Grey Divider

Tip of the day
💡 Did you know, you can turn on the rule miner and Qodo learns your standards from review history

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

Comment thread pipelines/integration-test/operator-dast.yaml
ompushkara
ompushkara previously approved these changes Oct 5, 2026
@bouskaJ
bouskaJ merged commit 2f2214f into main Oct 5, 2026
4 checks passed
@bouskaJ
bouskaJ deleted the use_latest_supported_ocp branch October 5, 2026 12:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants