Skip to content

CORS-4334: Konnectivity#10344

Open
patrickdillon wants to merge 3 commits intoopenshift:mainfrom
patrickdillon:konnectivity
Open

CORS-4334: Konnectivity#10344
patrickdillon wants to merge 3 commits intoopenshift:mainfrom
patrickdillon:konnectivity

Conversation

@patrickdillon
Copy link
Contributor

@patrickdillon patrickdillon commented Mar 2, 2026

Continuation of #10280:

  • Refactored to reduce in-lining in bootkube.sh
  • Added some gating (needs port opening on some or all platforms)

Will break the API vendoring into a separate PR to get that merged sooner rather than later.

Not tested. Opening this now as a /WIP to continue discussion of #10280 with #9628
/cc @JoelSpeed @mdbooth

@openshift-ci-robot openshift-ci-robot added the jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. label Mar 2, 2026
@openshift-ci openshift-ci bot requested a review from JoelSpeed March 2, 2026 04:08
@openshift-ci-robot
Copy link
Contributor

openshift-ci-robot commented Mar 2, 2026

@patrickdillon: This pull request references CORS-4334 which is a valid jira issue.

Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the story to target the "4.22.0" version, but no target version was set.

Details

In response to this:

Continuation of #10280:

  • Refactored to reduce in-lining in bootkube.sh
  • Added some gating (needs port opening on some or all platforms)

Will break the API changes into a separate PR.

Not tested. Opening this now as a /WIP to continue discussion of #10280 with #9628
/cc @JoelSpeed @mdbooth

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-ci openshift-ci bot requested a review from mdbooth March 2, 2026 04:08
@patrickdillon
Copy link
Contributor Author

patrickdillon commented Mar 2, 2026

/wip
/hold

@openshift-ci
Copy link
Contributor

openshift-ci bot commented Mar 2, 2026

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
Once this PR has been reviewed and has the lgtm label, please assign tthvo for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci-robot
Copy link
Contributor

openshift-ci-robot commented Mar 2, 2026

@patrickdillon: This pull request references CORS-4334 which is a valid jira issue.

Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the story to target the "4.22.0" version, but no target version was set.

Details

In response to this:

Continuation of #10280:

  • Refactored to reduce in-lining in bootkube.sh
  • Added some gating (needs port opening on some or all platforms)

Will break the API vendoring into a separate PR to get that merged sooner rather than later.

Not tested. Opening this now as a /WIP to continue discussion of #10280 with #9628
/cc @JoelSpeed @mdbooth

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

patrickdillon and others added 3 commits March 2, 2026 17:13
Enables kube-apiserver running on the bootstrap node to access the pod network,
specifically to enable access to webhooks running in the cluster.

Changes:

* Adds a new static Konnectivity server pod running on the bootstrap node
* Configures the bootstrap KAS to use its local Konnectivity server for
outbound cluster traffic
* Add a daemonset deployed into the cluster to run Konnectivity agent on every
cluster node
* Removes daemonset automatically in bootstrap teardown

Co-authored-by: Matthew Booth <mbooth@redhat.com>
Adds error handling to report konnectivity specific failures
when running gather bootstrap or analyze.
This updates all platforms to open the konnectivity port. Baremetal
and on-prem platform have user-provisioned networks, so that
will need be handled up front.
@patrickdillon
Copy link
Contributor Author

/test e2e-vsphere-ovn e2e-nutanix-ovn
/test ?

@patrickdillon
Copy link
Contributor Author

/test e2e-metal-ipi-ovn
/test e2e-agent-compact-ipv4

@patrickdillon
Copy link
Contributor Author

We probably want to clean up the konnectivity ports on bootstrap destroy as well.

@patrickdillon
Copy link
Contributor Author

I have experimented with adding a feature gate to control this and it is possible.

@patrickdillon
Copy link
Contributor Author

Need to not deploy this on a true single node cluster.

@JoelSpeed
Copy link
Contributor

Have read through the changes and the scripts all seem reasonable to me. I'll open a PR to CAPIO that switches us back to Fail webhook policy to test this with

@patrickdillon
Copy link
Contributor Author

/retest-required

2 similar comments
@patrickdillon
Copy link
Contributor Author

/retest-required

@patrickdillon
Copy link
Contributor Author

/retest-required

@openshift-ci
Copy link
Contributor

openshift-ci bot commented Mar 4, 2026

@patrickdillon: The following tests failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test name Commit Details Required Rerun command
ci/prow/aws-private 836e8d2 link false /test aws-private
ci/prow/e2e-openstack-proxy 836e8d2 link false /test e2e-openstack-proxy
ci/prow/e2e-gcp-custom-dns 836e8d2 link false /test e2e-gcp-custom-dns
ci/prow/e2e-aws-ovn-fips 836e8d2 link false /test e2e-aws-ovn-fips
ci/prow/e2e-gcp-custom-endpoints 836e8d2 link false /test e2e-gcp-custom-endpoints
ci/prow/e2e-gcp-xpn-custom-dns 836e8d2 link false /test e2e-gcp-xpn-custom-dns
ci/prow/e2e-azurestack 836e8d2 link false /test e2e-azurestack
ci/prow/e2e-aws-byo-subnet-role-security-groups 836e8d2 link false /test e2e-aws-byo-subnet-role-security-groups
ci/prow/e2e-ibmcloud-ovn 836e8d2 link false /test e2e-ibmcloud-ovn
ci/prow/e2e-gcp-ovn-xpn 836e8d2 link false /test e2e-gcp-ovn-xpn
ci/prow/e2e-gcp-xpn-dedicated-dns-project 836e8d2 link false /test e2e-gcp-xpn-dedicated-dns-project
ci/prow/gcp-custom-endpoints-proxy-wif 836e8d2 link false /test gcp-custom-endpoints-proxy-wif
ci/prow/e2e-azure-ovn-shared-vpc 836e8d2 link false /test e2e-azure-ovn-shared-vpc
ci/prow/e2e-metal-ipi-ovn 836e8d2 link false /test e2e-metal-ipi-ovn
ci/prow/e2e-gcp-secureboot 836e8d2 link false /test e2e-gcp-secureboot
ci/prow/e2e-gcp-ovn-byo-vpc 836e8d2 link false /test e2e-gcp-ovn-byo-vpc
ci/prow/e2e-aws-ovn-heterogeneous 836e8d2 link false /test e2e-aws-ovn-heterogeneous
ci/prow/e2e-aws-ovn-shared-vpc-edge-zones 836e8d2 link false /test e2e-aws-ovn-shared-vpc-edge-zones
ci/prow/azure-private 836e8d2 link false /test azure-private
ci/prow/e2e-aws-ovn-shared-vpc-custom-security-groups 836e8d2 link false /test e2e-aws-ovn-shared-vpc-custom-security-groups
ci/prow/e2e-aws-ovn-edge-zones 836e8d2 link false /test e2e-aws-ovn-edge-zones
ci/prow/e2e-openstack-nfv-intel 836e8d2 link false /test e2e-openstack-nfv-intel
ci/prow/azure-ovn-marketplace-images 836e8d2 link false /test azure-ovn-marketplace-images
ci/prow/e2e-aws-ovn-single-node 836e8d2 link false /test e2e-aws-ovn-single-node
ci/prow/e2e-aws-ovn-imdsv2 836e8d2 link false /test e2e-aws-ovn-imdsv2
ci/prow/e2e-openstack-ovn 836e8d2 link true /test e2e-openstack-ovn

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

jira/valid-reference Indicates that this PR references a valid Jira ticket of any type.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants