Merge https://github.com/kubernetes/cloud-provider-openstack:release-1.34 (a804c47) into release-4.21 - #430
Conversation
…ubernetes#3179) Co-authored-by: Yi-Ying Tan <yi-ying.tan.ext@nokia.com>
The Keystone authentication webhook handler writes the raw bearer token submitted in every TokenReview to the log stream when verbosity is 4 or higher. It is pretty common to set this level (-v=4) while e.g. debugging. Additionally, it is common for logs to be sent to a central store, with different access controls than the main cluster. A user with access to this store can use the captured token for replay attacks for any user that authenticates against the cluster until the token's TTL. Stop logging the token and avoid all of this. The combo of user, any error and the usual timestamp etc. should be more than sufficient. Signed-off-by: Stephen Finucane <stephenfin@redhat.com> Co-authored-by: Stephen Finucane <stephenfin@redhat.com>
Adding myself to the OWNERS file. I'm no stranger to CPO, having reviewed a number of patches already [1], and as noted a comment [2] I intend to increase my participation to the project. [1] https://github.com/kubernetes/cloud-provider-openstack/pulls?q=is%3Apr+involves%3Amandre [2] kubernetes#3166 (comment) Co-authored-by: Martin André <m.andre@redhat.com>
…netes#3190) * magnum-auto-healer: Add certificate validation The controller always sets InsecureSkipVerify. The two modern Magnum drivers in use today both use CAPI and thus kubeadm under the hood. kubeadm injects nodes internal IPs as SANs into the certs it generates, meaning certificate validation should pass when using the same root cert. Thus, we add two new configuration knobs: one to point to a CA file to use (defaulting to the well-known location k8s mounts certs to) and another to explicitly disable verification as an escape hatch. Signed-off-by: Stephen Finucane <stephenfin@redhat.com> Assisted-by: Claude Sonnet 4.8 <noreply@anthropic.com> * magnum-auto-healer: Document Endpoint health check parameters Add a parameter reference table covering all Endpoint check options, including the newly added ca-file and tls-insecure fields. Signed-off-by: Stephen Finucane <stephenfin@redhat.com> * magnum-auto-healer: Respect the unhealthy-duration grace period Signed-off-by: Stephen Finucane <stephenfin@redhat.com> --------- Signed-off-by: Stephen Finucane <stephenfin@redhat.com> Co-authored-by: Stephen Finucane <stephenfin@redhat.com>
|
Pipeline controller notification For optional jobs, comment This repository is configured in: LGTM mode |
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: shiftstack-merge-bot[bot] The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
|
Hi @shiftstack-merge-bot[bot]. Thanks for your PR. I'm waiting for a openshift member to verify that this patch is reasonable to test. If it is, they should reply with Regular contributors should join the org to skip this step. Once the patch is verified, the new status will be reflected by the I understand the commands that are listed here. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
No new linter violations, but this should help minimise future breakages as we e.g. bump go versions. Signed-off-by: Stephen Finucane <stephenfin@redhat.com> Co-authored-by: Stephen Finucane <stephenfin@redhat.com>
Tagged releases are no longer allowed in kubernetes/cloud-provider-openstack and all actions must be pinned to a full-length commit SHA. Co-authored-by: Matt Anson <matta@stackhpc.com>
The system:cloud-node-controller ClusterRoleBinding was bound to a non-existent cloud-node-controller ServiceAccount. The DaemonSet uses cloud-controller-manager, so fix the binding subject to match. Co-authored-by: Furkan Akman <hi@furkanakman.dev>
* update helm charts to 1.34.1 (kubernetes#3019) (cherry picked from commit 0973c52) * Add node affinity to schedule cloud controller manager only on control plane nodes. (kubernetes#2929) (cherry picked from commit 9c54a3d) * fix: Incorrect SA name in auth-delegate clusterRoleBiding (kubernetes#2907) (cherry picked from commit f6cd984) * [cinder-csi-plugin] podSecurityContext is missing in nodePlugin DaemonSet (kubernetes#2981) * podSecurityContext is missing is nodePlugin DaemonSet * [cinder-csi-plugin] Bump chart version (cherry picked from commit a326616) * [occm] Add container-level securityContext to Helm chart (kubernetes#3041) * feat: add security context support for openstack-cloud-controller-manager * chore: bump version to 2.34.2 in Chart.yaml (cherry picked from commit e862efc) * bump Cinder CSI sidecar versions to latest minor version (kubernetes#3046) (cherry picked from commit 8d0ffea) * bump Manila CSI sidecar versions to latest minor version (kubernetes#3047) (cherry picked from commit 20e8042) --------- Co-authored-by: Jesse Haka <haka.jesse@gmail.com> Co-authored-by: Furkan Akman <hi@furkanakman.dev> Co-authored-by: Haorui Peng <haorui.peng0512@gmail.com> Co-authored-by: Mathieu REHO <mathieu.reho@rehzzo.com> Co-authored-by: Denis GERMAIN <dt.germain@gmail.com> Co-authored-by: Janne Mensonen <47865038+jauru@users.noreply.github.com>
Co-authored-by: kayrus <kay.diam@gmail.com>
Co-authored-by: kayrus <kay.diam@gmail.com>
Co-authored-by: kayrus <kay.diam@gmail.com>
Co-authored-by: pýrus <kayrus@users.noreply.github.com>
…ntainer image to be consistent with ART for 4.19 Reconciling with https://github.com/openshift/ocp-build-data/tree/a39508c86497b4e5e463d7b2c78e51e577be9e7d/images/ose-openstack-cloud-controller-manager.yml
…ernetes#2723) * prepare release 1.31.2 * update deps * use k8s 1.31.3 * Fix CSI tests (kubernetes#2712) * [tests] bump devstack branch to stable/2023.2, fix python issues (kubernetes#2716) * [tests] bump ubuntu to 24.04 jammy (kubernetes#2721) --------- Co-authored-by: pýrus <kayrus@users.noreply.github.com>
…rnetes#2746) Many clouds do not have a 1:1 mapping of compute and storage AZs. As we generate topology information from the metadata service on the node (i.e. a compute AZ), this can prevent us from being able to schedule VMs. Add a new boolean, '--with-topology', to allow users to disable the topology feature where it does not make sense. An identical option already exists for the Manila CSI driver. However, unlike that option, this one defaults to 'true' to retain current behavior. Signed-off-by: Stephen Finucane <stephenfin@redhat.com> (cherry picked from commit ac23a1e) Co-authored-by: Stephen Finucane <stephenfin@redhat.com>
as a preemptive measure against [CVE-2024-45338](GHSA-w32m-9786-jp63). This is essentially a backport of bbb82f4 Signed-off-by: Lennart Jern <lennart.jern@est.tech>
Co-authored-by: pýrus <kayrus@users.noreply.github.com>
…es#2842) * refactor list volumes call * upgrade tests * comments improvements * fix imports and list options * token split * add more jointoken tests Co-authored-by: Konstantinos Angelopoulos <konstantinos.angelopoulos@sap.com>
%T prints the type. %t prints the word true/false, which is what we want. [1] [1] https://pkg.go.dev/fmt Conflicts: pkg/csi/manila/driver.go NOTE(stephenfin): Merge conflicts are due to the absence of PR kubernetes#2734, which we don't want to backport. Signed-off-by: Stephen Finucane <stephenfin@redhat.com>
This causes issue with vendoring.
…clouds.yaml (kubernetes#2911) * handle boolean values correctly when reading from secrets Previously, the validator failed when attempting to parse boolean fields like `UseClouds` in `AuthOpts` from secrets. This was due to secrets being stored as strings, leading to a type mismatch. Added logic to correctly parse string representations of booleans to match the expected type in the struct. (cherry picked from commit f3e4fdb) * Implement clouds.yaml support and make auth params optional Enables reading credentials/config from clouds.yaml when UseClouds is set. Mark Region and AuthURL as optional. (cherry picked from commit 1d66e56)
Co-authored-by: pýrus <kayrus@users.noreply.github.com>
Signed-off-by: moonek <gghonor@naver.com> Signed-off-by: Carlos da Silva <ces.eduardo98@gmail.com>
…ntainer image to be consistent with ART for 4.21 Reconciling with https://github.com/openshift/ocp-build-data/tree/4fbe3fab45239dc4be6f5d9d98a0bf36e0274ec9/images/ose-openstack-cloud-controller-manager.yml
0a73ab8 to
881d2e9
Compare
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Repository: openshift/coderabbit/.coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Comment |
This is an automated rebase PR generated by RebaseBot.
Summary
https://github.com/kubernetes/cloud-provider-openstack:release-1.34https://github.com/openshift/cloud-provider-openstack:release-4.21Logs
View job log