Skip to content

[ROSAENG-61017] Onboard openshift-online/rosa-trusted-actions to Prow - #81734

Merged
openshift-merge-bot[bot] merged 1 commit into
openshift:mainfrom
bergmannf:add-rosa-trusted-actions
Jul 14, 2026
Merged

[ROSAENG-61017] Onboard openshift-online/rosa-trusted-actions to Prow#81734
openshift-merge-bot[bot] merged 1 commit into
openshift:mainfrom
bergmannf:add-rosa-trusted-actions

Conversation

@bergmannf

@bergmannf bergmannf commented Jul 10, 2026

Copy link
Copy Markdown
Contributor

Enable Prow merge automation (Tide + plugins) and add an OpenAPI spec validation presubmit job for rosa-trusted-actions.

This is a draft as we are still in the process of renaming the repository from rosa-trusted-actions-server to rosa-trusted-actions

Summary by CodeRabbit

  • Onboards openshift-online/rosa-trusted-actions to OpenShift CI/Prow by adding CI-operator config for the openshift-online-rosa-trusted-actions-main branch with prowgen.expose: true.
  • Adds a validate-spec presubmit that runs HOME=/tmp make validate-spec in the generated container to validate the repository’s OpenAPI spec.
  • Enables Prow merge automation via Tide using squash merges, requiring both approved and lgtm, and preventing merges when specific “do-not-merge”/rebase-related labels are present (including needs-rebase and do-not-merge/invalid-owners-file).
  • Configures Prow for openshift-merge-bot with repo-scoped plugin setup, including an approve policy where lgtm acts as approve, requiring self-approval, plus an external needs-rebase plugin (wired to issue_comment and pull_request).
  • Adds generated OWNERS config for the relevant CI and Prow paths, defining the same approver/reviewer login sets and an empty options block.

@openshift-ci openshift-ci Bot added the do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. label Jul 10, 2026
@openshift-ci

openshift-ci Bot commented Jul 10, 2026

Copy link
Copy Markdown
Contributor

Skipping CI for Draft Pull Request.
If you want CI signal for your change, please convert it to an actual PR.
You can still manually trigger a test run with /test all

@coderabbitai

coderabbitai Bot commented Jul 10, 2026

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Central YAML (inherited)

Review profile: CHILL

Plan: Enterprise

Run ID: 248f96b3-4a46-4609-85e2-475d6c1a5647

📥 Commits

Reviewing files that changed from the base of the PR and between 9721594 and d7ade1f.

⛔ Files ignored due to path filters (2)
  • ci-operator/jobs/openshift-online/rosa-trusted-actions/OWNERS is excluded by !ci-operator/jobs/**
  • ci-operator/jobs/openshift-online/rosa-trusted-actions/openshift-online-rosa-trusted-actions-main-presubmits.yaml is excluded by !ci-operator/jobs/**
📒 Files selected for processing (5)
  • ci-operator/config/openshift-online/rosa-trusted-actions/OWNERS
  • ci-operator/config/openshift-online/rosa-trusted-actions/openshift-online-rosa-trusted-actions-main.yaml
  • core-services/prow/02_config/openshift-online/rosa-trusted-actions/OWNERS
  • core-services/prow/02_config/openshift-online/rosa-trusted-actions/_pluginconfig.yaml
  • core-services/prow/02_config/openshift-online/rosa-trusted-actions/_prowconfig.yaml
🚧 Files skipped from review as they are similar to previous changes (5)
  • core-services/prow/02_config/openshift-online/rosa-trusted-actions/OWNERS
  • ci-operator/config/openshift-online/rosa-trusted-actions/OWNERS
  • ci-operator/config/openshift-online/rosa-trusted-actions/openshift-online-rosa-trusted-actions-main.yaml
  • core-services/prow/02_config/openshift-online/rosa-trusted-actions/_pluginconfig.yaml
  • core-services/prow/02_config/openshift-online/rosa-trusted-actions/_prowconfig.yaml

Walkthrough

The change onboards openshift-online/rosa-trusted-actions with generated ownership files, an exposed CI validation job, Prow plugin and trigger settings, and Tide requirements for squash merging.

Changes

ROSA Trusted Actions onboarding

Layer / File(s) Summary
Ownership and CI validation
ci-operator/config/openshift-online/rosa-trusted-actions/*, core-services/prow/02_config/openshift-online/rosa-trusted-actions/OWNERS
Adds matching approver and reviewer lists, plus an exposed validate-spec job using UBI9 Node.js 22 and configured resource requests.
Prow plugins and trusted triggers
core-services/prow/02_config/openshift-online/rosa-trusted-actions/_pluginconfig.yaml
Configures approval rules, the external needs-rebase plugin, enabled Prow plugins, and the openshift-merge-bot trusted application.
Tide merge policy
core-services/prow/02_config/openshift-online/rosa-trusted-actions/_prowconfig.yaml
Requires approved and lgtm labels, excludes configured blocking labels, and selects squash merging.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

  • openshift/release#81735: Onboards another repository with corresponding ownership, CI-operator, Prow, and Tide configuration.

Suggested labels: rehearsals-ack

Suggested reviewers: droslean, hector-vido

🚥 Pre-merge checks | ✅ 15
✅ Passed checks (15 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: onboarding openshift-online/rosa-trusted-actions to Prow.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Stable And Deterministic Test Names ✅ Passed PR only adds Prow/config YAML and OWNERS files; no Ginkgo test titles were added or modified.
Test Structure And Quality ✅ Passed PR only changes Prow/ci-operator YAML; no Ginkgo test code or assertions were added or modified, so this check is not applicable.
Microshift Test Compatibility ✅ Passed The PR only adds Prow/OWNERS YAML; no new Ginkgo e2e tests or MicroShift-unsupported APIs/resources were added.
Single Node Openshift (Sno) Test Compatibility ✅ Passed The PR only adds Prow/CI YAML and OWNERS files; the new presubmit runs make validate-spec, with no Ginkgo e2e tests or topology assumptions introduced.
Topology-Aware Scheduling Compatibility ✅ Passed Only Prow/ci-operator config and a presubmit job were added; no deployment manifests, controllers, or topology-sensitive scheduling fields appear.
Ote Binary Stdout Contract ✅ Passed Only OWNERS and Prow/ci YAML were changed; no Go or process-level runtime code was added, so no stdout contract risk.
Ipv6 And Disconnected Network Test Compatibility ✅ Passed Only OWNERS and CI config files changed; no new Ginkgo/e2e test code or IPv4/network assumptions were added.
No-Weak-Crypto ✅ Passed PASS: The PR only adds Prow/OWNERS YAML configs; no MD5/SHA1/DES/RC4/3DES/Blowfish/ECB, custom crypto, or secret comparisons appear in the changed files.
Container-Privileges ✅ Passed No changed manifest sets privileged/hostPID/hostNetwork/hostIPC/SYS_ADMIN/allowPrivilegeEscalation; the only root use is in a build Dockerfile, not a runtime pod spec.
No-Sensitive-Data-In-Logs ✅ Passed Changed files are Prow/CI config only; no log statements or secrets found, and the only matched terms are comments and repo/plugin settings.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@openshift-ci openshift-ci Bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Jul 10, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
ci-operator/config/openshift-online/rosa-trusted-actions/openshift-online-rosa-trusted-actions-main.yaml (1)

4-4: 🔒 Security & Privacy | 🔵 Trivial | ⚡ Quick win

Pin the build-root image instead of using :latest.

Use an immutable digest or explicitly versioned image tag so CI behavior cannot change without a reviewed configuration change.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In
`@ci-operator/config/openshift-online/rosa-trusted-actions/openshift-online-rosa-trusted-actions-main.yaml`
at line 4, Replace the floating :latest tag in the build-root image declaration
with an immutable digest or explicitly versioned Node.js image tag, ensuring
future image updates require a reviewed configuration change.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Nitpick comments:
In
`@ci-operator/config/openshift-online/rosa-trusted-actions/openshift-online-rosa-trusted-actions-main.yaml`:
- Line 4: Replace the floating :latest tag in the build-root image declaration
with an immutable digest or explicitly versioned Node.js image tag, ensuring
future image updates require a reviewed configuration change.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Central YAML (inherited)

Review profile: CHILL

Plan: Enterprise

Run ID: f4d0de2d-efda-46b4-9b57-1143a0f2c3c4

📥 Commits

Reviewing files that changed from the base of the PR and between 454aaa9 and 359afff.

⛔ Files ignored due to path filters (2)
  • ci-operator/jobs/openshift-online/rosa-trusted-actions/OWNERS is excluded by !ci-operator/jobs/**
  • ci-operator/jobs/openshift-online/rosa-trusted-actions/openshift-online-rosa-trusted-actions-main-presubmits.yaml is excluded by !ci-operator/jobs/**
📒 Files selected for processing (5)
  • ci-operator/config/openshift-online/rosa-trusted-actions/OWNERS
  • ci-operator/config/openshift-online/rosa-trusted-actions/openshift-online-rosa-trusted-actions-main.yaml
  • core-services/prow/02_config/openshift-online/rosa-trusted-actions/OWNERS
  • core-services/prow/02_config/openshift-online/rosa-trusted-actions/_pluginconfig.yaml
  • core-services/prow/02_config/openshift-online/rosa-trusted-actions/_prowconfig.yaml

@bergmannf
bergmannf marked this pull request as ready for review July 13, 2026 06:20
@openshift-ci openshift-ci Bot removed the do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. label Jul 13, 2026
@bergmannf

Copy link
Copy Markdown
Contributor Author

/pj-rehearse auto-ack

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

@bergmannf: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel.

@openshift-ci
openshift-ci Bot requested review from droslean and hector-vido July 13, 2026 06:20
@bergmannf

Copy link
Copy Markdown
Contributor Author

/pj-rehearse pull-ci-openshift-online-rosa-trusted-actions-main-validate-spec

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

@bergmannf: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel.

@bergmannf
bergmannf force-pushed the add-rosa-trusted-actions branch from 359afff to 9721594 Compare July 13, 2026 10:47
@bergmannf

Copy link
Copy Markdown
Contributor Author

/retest-required

@bergmannf

Copy link
Copy Markdown
Contributor Author

/pj-rehearse pull-ci-openshift-online-rosa-trusted-actions-main-validate-spec

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

@bergmannf: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel.

Enable Prow merge automation (Tide + plugins) and add an OpenAPI
spec validation presubmit job for rosa-trusted-actions.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@bergmannf
bergmannf force-pushed the add-rosa-trusted-actions branch from 9721594 to d7ade1f Compare July 13, 2026 14:38
@bergmannf

Copy link
Copy Markdown
Contributor Author

/pj-rehearse pull-ci-openshift-online-rosa-trusted-actions-main-validate-spec

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

@bergmannf: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel.

@bergmannf

Copy link
Copy Markdown
Contributor Author

/pj-rehearse pull-ci-openshift-online-rosa-trusted-actions-main-validate-spec

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

@bergmannf: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel.

@bergmannf

Copy link
Copy Markdown
Contributor Author

/test core-valid

@openshift-ci

openshift-ci Bot commented Jul 14, 2026

Copy link
Copy Markdown
Contributor

@bergmannf: all tests passed!

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

@tiwillia

Copy link
Copy Markdown
Member

/lgtm

@openshift-ci openshift-ci Bot added the lgtm Indicates that a PR is ready to be merged. label Jul 14, 2026
@gvnnn

gvnnn commented Jul 14, 2026

Copy link
Copy Markdown

/lgtm

@openshift-ci

openshift-ci Bot commented Jul 14, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: bergmannf, gvnnn, tiwillia

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@bergmannf

Copy link
Copy Markdown
Contributor Author

/pj-rehearse ack

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

@bergmannf: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel.

@openshift-merge-bot openshift-merge-bot Bot added the rehearsals-ack Signifies that rehearsal jobs have been acknowledged label Jul 14, 2026
@openshift-merge-bot
openshift-merge-bot Bot merged commit 1d6c6c0 into openshift:main Jul 14, 2026
21 checks passed
@openshift-ci

openshift-ci Bot commented Jul 14, 2026

Copy link
Copy Markdown
Contributor

@bergmannf: Updated the following 2 configmaps:

  • config configmap in namespace ci at cluster app.ci using the following files:
    • key core-services-prow-02_config-openshift-online-rosa-trusted-actions-_prowconfig.yaml using file core-services/prow/02_config/openshift-online/rosa-trusted-actions/_prowconfig.yaml
  • config configmap in namespace ci at cluster core-ci using the following files:
    • key core-services-prow-02_config-openshift-online-rosa-trusted-actions-_prowconfig.yaml using file core-services/prow/02_config/openshift-online/rosa-trusted-actions/_prowconfig.yaml
Details

In response to this:

Enable Prow merge automation (Tide + plugins) and add an OpenAPI spec validation presubmit job for rosa-trusted-actions.

This is a draft as we are still in the process of renaming the repository from rosa-trusted-actions-server to rosa-trusted-actions

Summary by CodeRabbit

  • Onboards openshift-online/rosa-trusted-actions to OpenShift CI/Prow by adding CI-operator config for the openshift-online-rosa-trusted-actions-main branch with prowgen.expose: true.
  • Adds a validate-spec presubmit that runs HOME=/tmp make validate-spec in the generated container to validate the repository’s OpenAPI spec.
  • Enables Prow merge automation via Tide using squash merges, requiring both approved and lgtm, and preventing merges when specific “do-not-merge”/rebase-related labels are present (including needs-rebase and do-not-merge/invalid-owners-file).
  • Configures Prow for openshift-merge-bot with repo-scoped plugin setup, including an approve policy where lgtm acts as approve, requiring self-approval, plus an external needs-rebase plugin (wired to issue_comment and pull_request).
  • Adds generated OWNERS config for the relevant CI and Prow paths, defining the same approver/reviewer login sets and an empty options block.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@coderabbitai coderabbitai Bot mentioned this pull request Jul 16, 2026
SachinNinganure pushed a commit to SachinNinganure/release that referenced this pull request Jul 20, 2026
Enable Prow merge automation (Tide + plugins) and add an OpenAPI
spec validation presubmit job for rosa-trusted-actions.

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. lgtm Indicates that a PR is ready to be merged. rehearsals-ack Signifies that rehearsal jobs have been acknowledged

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants