Skip to content

Boilerplate: Update to a8a3172411f3f2b8848f64333843e028ef4b3ed1 - #355

Open
redhat-chai-bot wants to merge 1 commit into
openshift:masterfrom
redhat-chai-bot:boilerplate-update-1-a8a3172411f3f2b8848f64333843e028ef4b3ed1
Open

redhat-chai-bot wants to merge 1 commit into
openshift:masterfrom
redhat-chai-bot:boilerplate-update-1-a8a3172411f3f2b8848f64333843e028ef4b3ed1

Conversation

@redhat-chai-bot

@redhat-chai-bot redhat-chai-bot commented Sep 4, 2026 •

Copy link
Copy Markdown

Conventions:

  • openshift/golang-osd-operator: Update
  • openshift/golang-osd-e2e: Update

openshift/boilerplate@f66d57c...a8a3172


AI-generated. Review for accuracy.

Automated by scheduled task rosa_sre_boilerplate_update (instructions: ship_help_bot/shared/instructions/scheduled/rosa_sre_boilerplate_update.md, run: 22ff8a8c, commit: 20a4c3bc-dirty)

Summary by CodeRabbit

  • Chores
    • Updated automated pipeline checks to use the latest approved configuration.
    • Refined automated review coverage for repository content.
    • Updated repository ownership and access assignments to reflect current responsibilities.

Conventions:
- openshift/golang-osd-operator: Update
---
openshift/boilerplate@a19deeb...a8a3172

commit: 39b903e8c5db27cee7bb5b2dcce9ff4b5a07da5e
author: red-hat-konflux[bot]
chore(deps): update konflux references

Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>

commit: c678988174f35841a156cc2bba88d043b84cea9f
author: red-hat-konflux[bot]
chore(deps): update registry.access.redhat.com/ubi8/ubi-minimal:latest docker digest to d9beb74

Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>

commit: 1542cb9a6f953091ea36868f18ef42542103dba7
author: Bo Meng
Add shared CodeRabbit configuration

commit: 76056e0c32e5423cbc9e163c2053cd36b7435961
author: Dustin Row
Update roxctl-scan task bundle to fix null jq error

Updates the roxctl-scan task bundle SHA to include the fix for
KONFLUX-15651, where the proccess-output step fails with
"Cannot iterate over null" on scratch-based images.

Fix: konflux-ci/konflux-test#906

commit: e857a1ac44cb260f0df165bc3cdc77524fcdca48
author: Dustin Row
gangway-bridge: tighten POLL_OVERSHOOT and remove redundant 429 sleep

POLL_OVERSHOOT now uses max(POLL_INTERVAL, 300) + 30 instead of the
hardcoded 300+30+300, so the budget reflects whichever delay is larger.
The extra sleep in the 429 branch is removed; the loop leading sleep
already provides the backoff on the next iteration.

commit: bcf83f16fe1a00029f45af9c3ac0584203090991
author: Dustin Row
gangway-bridge: fix REQUIRED_DEADLINE to include INITIAL_DELAY and larger POLL_OVERSHOOT

commit: 7f5eecc7db7d567023b2015c71f2786b91d77c19
author: Dustin Row
gangway-bridge: longer poll interval and retry backoff cap

Double default POLL_INTERVAL from 60s to 120s to reduce the baseline
polling rate. With multiple concurrent jobs the polling alone can consume
the 9 req/min Gangway rate limit budget.

Raise the inter-retry backoff cap from 480s to 900s so later retry
attempts back off more aggressively when contention is high.

commit: d2a4c7a5454223b2169392c645f108e364bb57be
author: Dustin Row
gangway-bridge: add INITIAL_DELAY and poll 429 backoff

Gangway rate-limits at 9 req/min per source IP with nodelay burst of 5.
When multiple operators deploy in the same SAPM pipeline run their
gangway-bridge jobs all start simultaneously and saturate the shared
quota, causing trigger attempts to exhaust all retries and fail.

Add INITIAL_DELAY parameter (default 0s) so callers can stagger
concurrent jobs by setting different delays per target in the saas file.

Also fix the status-poll loop to back off exponentially (doubling up to
300s) on 429 responses instead of silently retrying at the normal
POLL_INTERVAL, which was burning rate limit budget during polling and
competing with trigger retries from other concurrent jobs.

commit: 03d7a11d4b501360c57e0d4aec00f0f19d556044
author: Chai Bot
gangway-bridge: back off on 429 during status polling

commit: b55a066cc92d9f51b06add5f046e3e90d4c463d1
author: Chai Bot
Add 429 rate-limit handling with exponential backoff and jitter to gangway bridge

- Increase MAX_RETRIES default from 1 to 5 and ACTIVE_DEADLINE from
  14430 to 50400 to accommodate additional retry attempts with backoff
- Replace fixed deadline formula with backoff-aware calculation that
  accounts for exponential delays and jitter
- Capture HTTP response code from curl and handle 429 responses by
  parsing the Retry-After header (capped at 600s) before falling
  through to the outer retry loop
- Replace fixed 30s retry delay with exponential backoff (30s base,
  doubling per attempt, capped at 480s) plus random jitter (0-15s)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

commit: b5c538a3d4db95d1a543c2d111686211ec803cca
author: red-hat-konflux[bot]
chore(deps): update konflux references

Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>

commit: 6ded743c2641eee96ac36c242e936a68bd842516
author: red-hat-konflux[bot]
chore(deps): update registry.access.redhat.com/ubi8/ubi-minimal:latest docker digest to c2483a8

Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>

commit: 63c3b7097adf9f68250309eab02b6ac4161556a7
author: Chai Bot
Fix CodeRabbit path filter override for boilerplate directory

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

commit: 22b25670188fa481117bb381e2bde9683844d031
author: Chai Bot
Remove departed members from OWNERS_ALIASES

Remove c-e-brumm, OliviaHY, and syncrou from the rosa-managers alias
group, and Tessg22 from the srep-functional-team-thor alias group.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

commit: d547835be8964f9069a0ca23b2daf00670d518b2
author: Alice Hubenko
Drop osd-cluster-ready from boilerplate subscribers.

The Job is no longer deployed; keep subscriber list aligned with live operators.

Co-authored-by: Cursor <cursoragent@cursor.com>

commit: 2ab6bf81e5778a8804ea7ed606f1f552c4bd56c8
author: Chai Bot
Add geowa4 to rosa-staff-engineers alias

Closes #858

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

commit: 68e5a1af106eafcae0440ea6b085858b81719f89
author: red-hat-konflux[bot]
chore(deps): update konflux references to v0.4.0

Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>

commit: 342174c70548ea540a3666bfdc80f1374cb9f96b
author: Alice Hubenko
ROSAENG-65731: harden gangway-bridge retry and timeout handling

- Validate ACTIVE_DEADLINE covers the full retry budget at startup
- Return immediately from trigger_and_poll on POST failure or
  invalid response instead of polling an empty URL until timeout
- Add --max-time to curl requests to prevent hangs beyond budget

Co-authored-by: Cursor <cursoragent@cursor.com>

commit: 8da3e3cea5fa0bbaa460e74757772d79bce6ae74
author: red-hat-konflux[bot]
chore(deps): update konflux references

Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>

commit: 1d375dff0c3edcffcbc40873a59c65b26d8107ad
author: Alice Hubenko
fix: replace curl|bash codecov uploader with pinned codecov-cli

Replace the deprecated `curl https://codecov.io/bash | bash` pattern
with a pinned Codecov CLI binary (v11.3.1) downloaded from GitHub
releases and verified via SHA256 checksum before execution.

The legacy bash uploader was the vector for the April 2021 Codecov
supply-chain compromise (CWE-494, CWE-829). Because boilerplate
vendors this script into every subscribing OSD operator, a single
upstream tampering event would yield arbitrary code execution in
dozens of operator CI jobs.

Files updated:
- boilerplate/openshift/golang-osd-operator/codecov.sh
- boilerplate/openshift/golang-codecov/codecov.sh
- boilerplate/test/test-base-convention/codecov.sh

Closes: ROSAENG-61296
Ref: HCMSEC-3528
Co-authored-by: Cursor <cursoragent@cursor.com>

commit: 7ea236f59482d4cba85bbd637ed2b0d284aed30c
author: red-hat-konflux[bot]
chore(deps): update registry.access.redhat.com/ubi8/ubi-minimal:latest docker digest to 8eb4bce

Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>

commit: ab82d119c6080be925eddb9c20b0b52af2089d97
author: red-hat-konflux[bot]
chore(deps): update konflux references

Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>

commit: b8fba3028968377cb61b03af6844f78df706d1ba
author: red-hat-konflux[bot]
chore(deps): update konflux references to v0.2.6

Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>

commit: 163faa4dc74b5696a93a8f95bd1fb9f3013ed05b
author: red-hat-konflux[bot]
chore(deps): update registry.access.redhat.com/ubi8/ubi-minimal:latest docker digest to 2e70a98

Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>

commit: c1c11cc2d6c8228894588c689282a9f7847ffb99
author: red-hat-konflux[bot]
chore(deps): update konflux references

Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>

commit: 3d0f3b2d49f63f14624458e4f99aee19301d9dd6
author: Dustin Row
ROSAENG-62320: Add automatic retry to gangway bridge template

Add MAX_RETRIES parameter (default 1) so the bridge retries the Prow
job once on failure before reporting failure. Most infra flakes
(DiskPressure, node eviction, quota) are transient and pass on retry.

Also adds ACTIVE_DEADLINE parameter to set the Kubernetes Job deadline
independently from the per-attempt TIMEOUT, since retries need more
total wall time.
@coderabbitai

coderabbitai Bot commented Sep 4, 2026 •

Copy link
Copy Markdown

Warning

This pull request changes a CodeRabbit configuration file. Because it comes from a fork or its author is not a repository collaborator, reviews use only the configuration from the target branch. The proposed configuration will take effect after it is merged.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Central YAML (inherited)

Review profile: CHILL

Plan: Team

Run ID: 79b898da-f55f-4d5d-8b66-18397e4387fb

📥 Commits

Reviewing files that changed from the base of the PR and between be5b613 and 3049147.

⛔ Files ignored due to path filters (7)
  • boilerplate/_data/last-boilerplate-commit is excluded by !boilerplate/**
  • boilerplate/openshift/golang-osd-operator/.coderabbit.yaml is excluded by !boilerplate/**
  • boilerplate/openshift/golang-osd-operator/OWNERS_ALIASES is excluded by !boilerplate/**
  • boilerplate/openshift/golang-osd-operator/codecov.sh is excluded by !boilerplate/**
  • boilerplate/openshift/golang-osd-operator/update is excluded by !boilerplate/**
  • build/Dockerfile is excluded by !build/**
  • build/Dockerfile.olm-registry is excluded by !build/**
📒 Files selected for processing (3)
  • .coderabbit.yaml
  • .tekton/deadmanssnitch-operator-agentic-sdlc-check-pull-request.yaml
  • OWNERS_ALIASES

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.


Walkthrough

The change updates review path filters, pins the agentic SDLC pipeline to a new boilerplate revision, and modifies three ownership aliases.

Changes

Review and pipeline configuration

Layer / File(s) Summary
Review and pipeline settings
.coderabbit.yaml, .tekton/deadmanssnitch-operator-agentic-sdlc-check-pull-request.yaml
Review filters now exclude boilerplate/** and vendor/**. The pipeline pins a new openshift/boilerplate revision.

Ownership alias updates

Layer / File(s) Summary
Ownership membership changes
OWNERS_ALIASES
The aliases remove Tessg22, c-e-brumm, OliviaHY, syncrou, and tkiss28, and add geowa4.

Estimated code review effort: 1 (Trivial) | ~5 minutes

Merge Risk: ⚪ Minimal · up to 30491

The update revises repository review settings, a pinned pipeline revision, and ownership aliases. No current merge-blocking risk remains.

Suggested reviewers: anispate, tnierman

🚥 Pre-merge checks | ✅ 15
✅ Passed checks (15 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly identifies the main change: updating the repository boilerplate to commit a8a3172411f3f2b8848f64333843e028ef4b3ed1.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Stable And Deterministic Test Names ✅ Passed PASS: The commit changes configuration, Tekton revision data, ownership aliases, boilerplate shell/config files, and image tags. No test file changes exist. The added and removed lines contain no Gink…
Test Structure And Quality ✅ Passed PASS: The pull request changes configuration, Tekton revision data, ownership aliases, boilerplate scripts, and Docker image digests. The parent-to-HEAD diff contains no Go test files, Ginkgo construc…
Microshift Test Compatibility ✅ Passed PASS: The pull request adds no Ginkgo e2e tests. The diff only changes configuration, a boilerplate revision pin, ownership aliases, Codecov tooling, and image digests. Therefore, the MicroShift API a…
Single Node Openshift (Sno) Test Compatibility ✅ Passed PASS: The pull request adds no new Ginkgo e2e tests. The exact commit diff changes configuration, pipeline, ownership, boilerplate scripts, and Docker image digests only; it contains no added It(), …
Topology-Aware Scheduling Compatibility ✅ Passed PASS: The PR does not add or modify deployment manifests, operator code, or controllers. The changed paths are configuration, ownership data, boilerplate scripts, Dockerfiles, and a Tekton PipelineRun…
Ote Binary Stdout Contract ✅ Passed No OTE binary or Ginkgo suite code changed in this pull request. The diff contains configuration, ownership data, shell tooling, Tekton revision, and Docker image updates only. The repository has a pr…
Ipv6 And Disconnected Network Test Compatibility ✅ Passed PASS: The pull request adds no Ginkgo e2e tests. The actual diff contains only YAML, OWNERS_ALIASES, a boilerplate update script, a Codecov shell script, and Dockerfiles. No added It(), Describe(), Co…
No-Weak-Crypto ✅ Passed PASS — The PR adds no MD5, SHA1, DES, RC4, Blowfish, 3DES, or ECB usage. The only cryptographic operation added is SHA-256 verification with sha256sum -c. The changed scripts add no custom cryptogra…
Container-Privileges ✅ Passed No custom-check failure was introduced. The only Kubernetes manifest change updates the external Pipeline revision; the old and new referenced Pipeline definitions contain no privileged, host namesp…
No-Sensitive-Data-In-Logs ✅ Passed No changed line adds logging of passwords, tokens, API keys, PII, session IDs, customer data, or internal hostnames. The new shell output logs only coverage paths, a checksum verification result, and …
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Comment @coderabbitai help to get the list of available commands.

@openshift-ci

openshift-ci Bot commented Sep 4, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: redhat-chai-bot
Once this PR has been reviewed and has the lgtm label, please assign bmeng for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci

openshift-ci Bot commented Sep 4, 2026

Copy link
Copy Markdown
Contributor

@redhat-chai-bot: all tests passed!

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

@codecov-commenter

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 43.76%. Comparing base (be5b613) to head (3049147).

Additional details and impacted files

Impacted file tree graph

@@           Coverage Diff           @@
##           master     #355   +/-   ##
=======================================
  Coverage   43.76%   43.76%           
=======================================
  Files          11       11           
  Lines         834      834           
=======================================
  Hits          365      365           
  Misses        422      422           
  Partials       47       47           
🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants