Skip to content

Add ci for ExternalOIDCExternalClaimsSourcing - #85411

Merged
openshift-merge-bot[bot] merged 1 commit into
openshift:mainfrom
gangwgr:add-oidc-claimsourcing
Sep 18, 2026
Merged

openshift-merge-bot[bot] merged 1 commit into
openshift:mainfrom
gangwgr:add-oidc-claimsourcing

Conversation

@gangwgr

@gangwgr gangwgr commented Sep 17, 2026

Copy link
Copy Markdown
Contributor

Add ci for ExternalOIDCExternalClaimsSourcing

Summary by CodeRabbit

Adds an optional AWS end-to-end CI job for ExternalOIDCExternalClaimsSourcing in the Cluster Authentication Operator repository.

The job uses the openshift/auth/external-oidc suite through openshift-e2e-aws and runs with TechPreviewNoUpgrade. It excludes external tests, legacy CVO and test-framework invariants, and three ExternalOIDC feature-gate scenarios.

@coderabbitai

coderabbitai Bot commented Sep 17, 2026

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Central YAML (inherited)

Review profile: CHILL

Plan: Enterprise

Run ID: d21ad6b7-c745-4c08-8530-91f36f002af8

📥 Commits

Reviewing files that changed from the base of the PR and between 9a52ab4 and 9cc5d6c.

⛔ Files ignored due to path filters (1)
  • ci-operator/jobs/openshift/cluster-authentication-operator/openshift-cluster-authentication-operator-master-presubmits.yaml is excluded by !ci-operator/jobs/**
📒 Files selected for processing (1)
  • ci-operator/config/openshift/cluster-authentication-operator/openshift-cluster-authentication-operator-master.yaml

Included review availability: Your plan provides up to 12 included reviews per hour; 11 remain after this review.


Walkthrough

Changes

External OIDC AWS test

Layer / File(s) Summary
AWS External OIDC test configuration
ci-operator/config/openshift/cluster-authentication-operator/openshift-cluster-authentication-operator-master.yaml
Adds an optional AWS end-to-end test for External OIDC upstream claim sourcing. The configuration enables TechPreviewNoUpgrade, sets External OIDC-specific skips, selects the openshift/auth/external-oidc suite, and uses openshift-e2e-aws.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Feature

Suggested reviewers: psalajova

Merge Risk: ⚪ Minimal · up to 9cc5d

The optional AWS External OIDC configuration matches established repository configurations and is ready to merge.

🚥 Pre-merge checks | ✅ 15
✅ Passed checks (15 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly states that CI was added for ExternalOIDCExternalClaimsSourcing, which matches the pull request objective and changeset.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Stable And Deterministic Test Names ✅ Passed The pull request changes only CI configuration and the generated Prow job. It adds static identifiers such as e2e-aws-external-oidc-upstream-claim-sourcing and static feature-gate skip patterns. It …
Test Structure And Quality ✅ Passed PASS: The pull request changes only CI configuration. The authoritative diff contains two YAML files: one adds the optional openshift/auth/external-oidc AWS job, and the other adds its generated Pro…
Microshift Test Compatibility ✅ Passed PASS — The pull request changes only CI configuration and a generated Prow presubmit job. It adds no Ginkgo test code, and no new It(), Describe(), Context(), or When() declarations. Therefore…
Single Node Openshift (Sno) Test Compatibility ✅ Passed PASS: The pull request adds only CI configuration and generated presubmit configuration. The authoritative diff contains no new Go or Ginkgo test code, and it does not add an It(), Describe(), `Co…
Topology-Aware Scheduling Compatibility ✅ Passed PASS — The pull request changes only CI configuration and a generated Prow presubmit job. The added test selects TechPreviewNoUpgrade, test arguments, and the openshift-e2e-aws workflow. It adds n…
Ote Binary Stdout Contract ✅ Passed PASS. The authoritative pull-request diff changes only two YAML configuration files: the test configuration (+12 lines) and generated presubmit configuration (+104 lines). The additions select `TEST_S…
Ipv6 And Disconnected Network Test Compatibility ✅ Passed PASS. The review-scoped diff changes only CI YAML and generated Prow job YAML. It adds an optional openshift/auth/external-oidc AWS job with OPENSHIFT_SKIP_EXTERNAL_TESTS: "True"; it adds no Ginkg…
No-Weak-Crypto ✅ Passed PASS: The pull request changes only CI configuration and generated presubmit YAML. The added job selects an External OIDC test suite and references CI secret mounts, but it introduces no MD5, SHA1, DE…
Container-Privileges ✅ Passed The pull request adds an External OIDC test configuration and its generated Prow job. The added YAML contains no privileged: true, hostPID, hostNetwork, hostIPC, SYS_ADMIN, or `allowPrivileg…
No-Sensitive-Data-In-Logs ✅ Passed PASS: The pull request adds CI configuration only. The changed lines define an External OIDC test job and its generated Prow job, including references to existing secret volumes and credential file pa…
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR

Comment @coderabbitai help to get the list of available commands.

@openshift-ci openshift-ci Bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Sep 17, 2026
@openshift-merge-bot

Copy link
Copy Markdown
Contributor

[REHEARSALNOTIFIER]
@gangwgr: the pj-rehearse plugin accommodates running rehearsal tests for the changes in this PR. Expand 'Interacting with pj-rehearse' for usage details. The following rehearsable tests have been affected by this change:

Test name Repo Type Reason
pull-ci-openshift-cluster-authentication-operator-master-e2e-aws-external-oidc-upstream-claim-sourcing openshift/cluster-authentication-operator presubmit Presubmit changed

Prior to this PR being merged, you will need to either run and acknowledge or opt to skip these rehearsals.

Interacting with pj-rehearse

Comment: /pj-rehearse to run up to 5 rehearsals
Comment: /pj-rehearse skip to opt-out of rehearsals
Comment: /pj-rehearse {test-name}, with each test separated by a space, to run one or more specific rehearsals
Comment: /pj-rehearse more to run up to 10 rehearsals
Comment: /pj-rehearse max to run up to 25 rehearsals
Comment: /pj-rehearse auto-ack to run up to 5 rehearsals, and add the rehearsals-ack label on success
Comment: /pj-rehearse list to get an up-to-date list of affected jobs
Comment: /pj-rehearse abort to abort all active rehearsals
Comment: /pj-rehearse network-access-allowed to allow rehearsals of tests that have the restrict_network_access field set to false. This must be executed by an openshift org member who is not the PR author

Once you are satisfied with the results of the rehearsals, comment: /pj-rehearse ack to unblock merge. When the rehearsals-ack label is present on your PR, merge will no longer be blocked by rehearsals.
If you would like the rehearsals-ack label removed, comment: /pj-rehearse reject to re-block merging.

@gangwgr

gangwgr commented Sep 17, 2026

Copy link
Copy Markdown
Contributor Author

/retest

@gangwgr

gangwgr commented Sep 17, 2026

Copy link
Copy Markdown
Contributor Author

/pj-rehearse ack

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

@gangwgr: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel.

@openshift-merge-bot openshift-merge-bot Bot added the rehearsals-ack Signifies that rehearsal jobs have been acknowledged label Sep 17, 2026
@YamunadeviShanmugam

Copy link
Copy Markdown
Contributor

/lgtm

@openshift-ci openshift-ci Bot added the lgtm Indicates that a PR is ready to be merged. label Sep 18, 2026
@openshift-ci

openshift-ci Bot commented Sep 18, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: gangwgr, YamunadeviShanmugam

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci

openshift-ci Bot commented Sep 18, 2026

Copy link
Copy Markdown
Contributor

@gangwgr: all tests passed!

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

@openshift-merge-bot
openshift-merge-bot Bot merged commit 4c87d7a into openshift:main Sep 18, 2026
17 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. lgtm Indicates that a PR is ready to be merged. rehearsals-ack Signifies that rehearsal jobs have been acknowledged

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants