Skip to content

Add prepare_client_pod stage for warm shiftstackclient bootstrap - #43

Merged
openshift-merge-bot[bot] merged 1 commit into
mainfrom
feature/prepare-client-pod-stage
Sep 28, 2026
Merged

openshift-merge-bot[bot] merged 1 commit into
mainfrom
feature/prepare-client-pod-stage

Conversation

@tusharjadhav3302

Copy link
Copy Markdown
Contributor

Summary

  • Add a new prepare_client_pod stage for warm testing when full prepare is skipped.
  • After the shiftstackclient pod is recreated, restore only pod-local state that prepare normally provides:
    • oc / kubectl from the OpenShift mirror
    • ~/.config/openstack from the PVC osp_config_dir (fallback: original-config)
    • /etc/hosts API/apps entries from install-config.yaml FIPs
    • artifacts/resources.yml when missing
  • Does not recreate OpenStack projects, FIPs, app credentials, or installer hosts.

Motivation

Callers that omit prepare (to avoid re-initializing a warm guest) still need a way to rehydrate the empty client pod. Keeping that subset in shiftstack-qa avoids duplicating prepare knowledge in cifmw.

Usage

Include prepare_client_pod in the stages list (or stages override) before verification/test stages.

Test plan

  • Stage is skipped when not listed in stages
  • With the stage enabled on a recreated client pod, oc, clouds.shiftstack, guest /etc/hosts, and resources.yml are available before verification
  • Full prepare path remains unchanged

Made with Cursor

vars:
_ic: "{{ prepare_client_pod_install_config_slurp.content | b64decode | from_yaml }}"
ansible.builtin.set_fact:
api_accessible_ip: "{{ _ic.platform.openstack.apiFloatingIP }}"

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This unconditionally reads platform.openstack.apiFloatingIP and ingressFloatingIP but the proxy install-config use apiVIP and ingressVIP instead.
As a result, enabling prepare_clint_pod for the existing *ipi-proxy jobs will fail here with an undefined-variable error. Please handle proxy installation using the same address election logic as the existing prepare role or explixitly skil/fail this stage with clear reason for unsupported proxy deployments.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good catch — fixed. We now prefer apiFloatingIP / ingressFloatingIP (standard IPI), then fall back to apiVIP/ingressVIP (or apiVIPs/ingressVIPs, taking the first entry when a list). If neither form resolves, the stage fails with an explicit assert instead of an undefined-variable error.

failed_when: false

- name: Bootstrap oc and kubectl from the OpenShift mirror
when: prepare_client_pod_oc_which.rc != 0

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This condition checks only oc exists. So the bootstrap is skipped when oc exists, but kutectl is absent. Please check both commands before skipping the bootstrap block.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Agreed — fixed. Bootstrap now runs when oc or kubectl is missing (which checks for both), so a partial install no longer skips installing the missing binary.

Comment thread collection/stages/roles/prepare_client_pod/tasks/main.yml
Comment thread playbooks/ocp_testing.yaml Outdated
tasks_from: create_installer_group.yml
when: "not deploy_installer_host"

- name: Prepare the shiftstackclient pod when full prepare was skipped

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could we run prepare_client_pod before create_installer_group.yml? On a recreated client pod, the OpenStack credentials have not been restored when create_installer_group.yml calls openstack.cloud.server_info. That task suppresses the error and treats an existing installer VM as absent, adding localhost to the installer inventory. Restoring the credentials afterward cannot correct that inventory.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good catch. Moved the prepare_client_pod import ahead of the play that runs create_installer_group.yml, so OpenStack credentials are restored before server_info looks up the installer VM on a recreated client pod.

remote_src: true
mode: preserve

- name: Fall back to original-config OpenStack clouds when PVC copy is absent

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could we verify that the fallback clouds.yaml contains clouds[user_cloud] before accepting it? The prepare role adds that cloud to .config/openstack/clouds.yaml and copies it to osp_config_dir; it does not add it to .original-config. If the PVC copy is missing and the original config contains only the admin cloud, this branch succeeds without restoring the shiftstack cloud, leaving the failure for later OpenStack tasks.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Agreed. Before accepting the original-config fallback we now load that clouds.yaml and assert clouds[user_cloud] is present. After either PVC or fallback restore we also assert the same key on ~/.config/openstack/clouds.yaml, so an admin-only original config cannot silently succeed.

@tusharjadhav3302
tusharjadhav3302 force-pushed the feature/prepare-client-pod-stage branch from 604e6bd to 0d2f243 Compare September 28, 2026 08:25
Comment thread collection/stages/roles/prepare_client_pod/tasks/main.yml
When cifmw recreates shiftstackclient and jobs omit prepare (Pipeline B
run-tests), the empty pod lacks oc, clouds.shiftstack, /etc/hosts, and
resources.yml. Add a lightweight stage that restores only that subset
from the PVC / install-config without re-running full prepare.

Address review feedback:
- Assert a clouds.yaml source exists before creating ~/.config/openstack
- Bootstrap when oc or kubectl is missing
- Resolve API/apps from FloatingIP with VIP/VIPs fallback for proxy IC
- Run prepare_client_pod before create_installer_group
- Reject original-config fallback unless clouds[user_cloud] is present
- Add YAML document start for ansible-lint

Co-authored-by: Cursor <cursoragent@cursor.com>
@tusharjadhav3302
tusharjadhav3302 force-pushed the feature/prepare-client-pod-stage branch from 0d2f243 to 0f31965 Compare September 28, 2026 09:16
@IlanZuckerman

Copy link
Copy Markdown

/lgtm

@ekuris-redhat

Copy link
Copy Markdown
Contributor

/approve

@openshift-ci

openshift-ci Bot commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: ekuris-redhat

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-merge-bot
openshift-merge-bot Bot merged commit a52cf8b into main Sep 28, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Development

Successfully merging this pull request may close these issues.

3 participants