-
Notifications
You must be signed in to change notification settings - Fork 45
192 lines (174 loc) · 8.92 KB
/
Copy pathprocess-operator-bundle.yaml
File metadata and controls
192 lines (174 loc) · 8.92 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
name: Process Operator Bundle
run-name: Process Operator Bundle
on:
workflow_dispatch:
inputs:
rhoai_version:
description: 'RHOAI version to process (e.g. rhoai-3.5, rhoai-3.5-ea.2). Branch name used if omitted.'
required: false
type: string
dry_run:
description: 'Push results to BRANCH-dry-run instead of the actual branch.'
required: false
type: boolean
default: false
push:
paths:
- bundle/additional-images-patch.yaml
- bundle/bundle-patch.yaml
- bundle/csv-patch.yaml
- to-be-processed/bundle/**
- to-be-processed/helm/**
- helm/xks-values-patch.yaml
- helm/openshift-values-patch.yaml
branches:
- 'rhoai-[23].[0-9]' # e.g. rhoai-2.1, rhoai-3.1, rhoai-3.4
- 'rhoai-[23].[0-9][0-9]' # e.g. rhoai-2.10, rhoai-3.10, rhoai-3.22
- 'rhoai-[3].[0-9]-ea.[0-9]' # e.g. rhoai-3.4-ea.1, rhoai-3.5-ea.2
- 'rhoai-[3].[0-9][0-9]-ea.[0-9]' # e.g. rhoai-3.10-ea.3
permissions:
contents: write
env:
GITHUB_ORG: red-hat-data-services
LOG_FILE_NAME: bundle-processor.log
jobs:
process-bundle:
if: ${{ github.ref_name != 'main' }}
runs-on: ubuntu-latest
container:
# defined here: https://github.com/red-hat-data-services/devops-images/tree/main/builds
image: quay.io/rhoai-devops/olm-runner:latest
steps:
- name: Resolve branch and RHOAI version
shell: bash
run: |
BRANCH="${GITHUB_HEAD_REF:-${GITHUB_REF#refs/heads/}}"
echo "branch=$BRANCH" >> $GITHUB_OUTPUT
VERSION_SOURCE="${{ inputs.rhoai_version || github.head_ref || github.ref_name }}"
VERSION_SOURCE="${VERSION_SOURCE#rhoai-}"
if ! [[ "$VERSION_SOURCE" =~ ^([0-9]+\.[0-9]+(-ea\.[0-9]+)?)$ ]]; then
echo "::error::Cannot resolve RHOAI version from '$VERSION_SOURCE'. Provide rhoai_version input (e.g. rhoai-3.5)."
exit 1
fi
echo "rhoai_version=${BASH_REMATCH[1]}" >> $GITHUB_OUTPUT
id: get_branch
- name: Git checkout
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
with:
ref: ${{ steps.get_branch.outputs.branch }}
path: ${{ steps.get_branch.outputs.branch }}
- name: Git checkout utils
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
with:
repository: ${{ env.GITHUB_ORG }}/RHOAI-Konflux-Automation
ref: main
path: utils
- name: Install dependencies
run: |
pip install --default-timeout=100 -r utils/utils/processors/requirements.txt
- name: Login to container registries
env:
REGISTRY_REDHAT_IO_USERNAME: ${{ secrets.REGISTRY_REDHAT_IO_USERNAME }}
REGISTRY_REDHAT_IO_PASSWORD: ${{ secrets.REGISTRY_REDHAT_IO_PASSWORD }}
REGISTRY_STAGE_REDHAT_IO_USERNAME: ${{ secrets.REGISTRY_STAGE_REDHAT_IO_USERNAME }}
REGISTRY_STAGE_REDHAT_IO_PASSWORD: ${{ secrets.REGISTRY_STAGE_REDHAT_IO_PASSWORD }}
AIPCC_QUAY_RO_USERNAME: ${{ secrets.AIPCC_QUAY_RO_USERNAME }}
AIPCC_QUAY_RO_TOKEN: ${{ secrets.AIPCC_QUAY_RO_TOKEN }}
run: |
cosign login registry.redhat.io -u "${REGISTRY_REDHAT_IO_USERNAME}" -p "${REGISTRY_REDHAT_IO_PASSWORD}"
cosign login registry.stage.redhat.io -u "${REGISTRY_STAGE_REDHAT_IO_USERNAME}" -p "${REGISTRY_STAGE_REDHAT_IO_PASSWORD}"
cosign login quay.io -u "${AIPCC_QUAY_RO_USERNAME}" -p "${AIPCC_QUAY_RO_TOKEN}"
- name: Process Operator Bundle
env:
BRANCH: ${{ steps.get_branch.outputs.branch }}
RHOAI_VERSION: ${{ steps.get_branch.outputs.rhoai_version }}
OC_TOKEN: ${{ secrets.KONFLUX_INTERNAL_OC_TOKEN }}
CLUSTER: p02
RHOAI_QUAY_API_TOKEN: ${{ secrets.RHOAI_QUAY_API_TOKEN }}
# NOTE: LOG_FILE_DIR is set at step level (not workflow level) for container jobs.
# At workflow level, ${{ github.workspace }} resolves to the HOST path (e.g., /home/runner/work/REPO/REPO),
# which doesn't exist inside the container. Using '.' writes to the current working directory,
# which is correctly set to the container's mounted workspace.
LOG_FILE_DIR: .
LOG_FILE_NAME: ${{ env.LOG_FILE_NAME }}
run: |
#Declare basic variables
OPENSHIFT_VERSION=v4.13
COMPONENT_SUFFIX=v${RHOAI_VERSION//./-}
OPERATOR_BUNDLE_COMPONENT_NAME=odh-operator-bundle-${COMPONENT_SUFFIX}
XKS_HELM_CHART_COMPONENT_NAME=rhai-on-xks-chart-${COMPONENT_SUFFIX}
OPENSHIFT_HELM_CHART_COMPONENT_NAME=rhai-on-openshift-chart-${COMPONENT_SUFFIX}
#copy all the raw content to tmp location
RAW_INPUTS_DIR=utils/tmp/bundle
mkdir -p $RAW_INPUTS_DIR
cp -r ${BRANCH}/to-be-processed/bundle/* $RAW_INPUTS_DIR
#copy helm raw content to tmp location
HELM_RAW_INPUTS_DIR=utils/tmp/helm
mkdir -p $HELM_RAW_INPUTS_DIR
cp -r ${BRANCH}/to-be-processed/helm/* $HELM_RAW_INPUTS_DIR
#Declare Bundle processing variables
BUILD_CONFIG_PATH=${BRANCH}/config/build-config.yaml
BUNDLE_CSV_PATH=${RAW_INPUTS_DIR}/manifests/rhods-operator.clusterserviceversion.yaml
PATCH_YAML_PATH=${BRANCH}/bundle/bundle-patch.yaml
OUTPUT_FILE_PATH=${RAW_INPUTS_DIR}/manifests/rhods-operator.clusterserviceversion.yaml
ANNOTATION_YAML_PATH=${RAW_INPUTS_DIR}/metadata/annotations.yaml
BUNDLE_PUSH_PIPELINE_PATH=${BRANCH}/.tekton/${OPERATOR_BUNDLE_COMPONENT_NAME}-push.yaml
#Declare XKS Helm processing variables
XKS_HELM_PATCH_YAML_PATH=${BRANCH}/helm/xks-values-patch.yaml
XKS_HELM_VALUES_YAML_PATH=${HELM_RAW_INPUTS_DIR}/rhai-on-xks-chart/values.yaml
XKS_HELM_PUSH_PIPELINE_PATH=${BRANCH}/.tekton/${XKS_HELM_CHART_COMPONENT_NAME}-push.yaml
#Declare OpenShift Helm processing variables
OPENSHIFT_HELM_PATCH_YAML_PATH=${BRANCH}/helm/openshift-values-patch.yaml
OPENSHIFT_HELM_VALUES_YAML_PATH=${HELM_RAW_INPUTS_DIR}/rhai-on-openshift-chart/values.yaml
OPENSHIFT_HELM_PUSH_PIPELINE_PATH=${BRANCH}/.tekton/${OPENSHIFT_HELM_CHART_COMPONENT_NAME}-push.yaml
#Declare SBOM metadata config path
METADATA_CONFIG_PATH=${BRANCH}/bundle/metadata-config.yaml
METADATA_CONFIG_FLAG=""
if [ -f "${METADATA_CONFIG_PATH}" ]; then
METADATA_CONFIG_FLAG="-mc ${METADATA_CONFIG_PATH}"
fi
#Invoke Bundle processor to patch the catalog
python3 utils/utils/processors/bundle-processor.py \
-op bundle-patch \
-b ${BUILD_CONFIG_PATH} \
-c ${BUNDLE_CSV_PATH} \
-p ${PATCH_YAML_PATH} \
-o ${OUTPUT_FILE_PATH} \
-v rhoai-${RHOAI_VERSION} \
-a ${ANNOTATION_YAML_PATH} \
-xhp ${XKS_HELM_PATCH_YAML_PATH} \
-xhv ${XKS_HELM_VALUES_YAML_PATH} \
-xhpp ${XKS_HELM_PUSH_PIPELINE_PATH} \
-ohp ${OPENSHIFT_HELM_PATCH_YAML_PATH} \
-ohv ${OPENSHIFT_HELM_VALUES_YAML_PATH} \
-ohpp ${OPENSHIFT_HELM_PUSH_PIPELINE_PATH} \
-y ${BUNDLE_PUSH_PIPELINE_PATH} \
-x enable \
${METADATA_CONFIG_FLAG}
# Sync processed content back to bundle and helm directories
# Convention: root-level files are permanent configs, subdirectories are synced content
# Strategy: delete all subdirectories then copy processed content to remove stale files
# WARNING: If permanent config subdirectories are added, this logic must be updated
find ${BRANCH}/bundle/ -mindepth 1 -maxdepth 1 -type d -exec rm -rf {} \;
cp -r ${RAW_INPUTS_DIR}/* ${BRANCH}/bundle/
find ${BRANCH}/helm/ -mindepth 1 -maxdepth 1 -type d -exec rm -rf {} \;
cp -r ${HELM_RAW_INPUTS_DIR}/* ${BRANCH}/helm/
- name: Print debug logs
if: always()
run: |
if [ -f "${{ env.LOG_FILE_NAME }}" ]; then
echo "=== Bundle processor log ==="
cat "${{ env.LOG_FILE_NAME }}"
else
echo "Log file not found: ${{ env.LOG_FILE_NAME }}"
fi
- name: Commit and push the changes to release branch
working-directory: ${{ steps.get_branch.outputs.branch }}
run: |
git config user.name "Openshift-AI DevOps"
git config user.email "openshift-ai-devops@redhat.com"
git add -A
PUSH_BRANCH="${{ inputs.dry_run == true && format('{0}-dry-run-bundle', steps.get_branch.outputs.branch) || steps.get_branch.outputs.branch }}"
FORCE_FLAG="${{ inputs.dry_run == true && '--force' || '' }}"
git diff --staged --quiet || (git commit -m "Updating the bundle-csv and helm chart values with latest images
${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }}" && git push ${FORCE_FLAG} origin HEAD:${PUSH_BRANCH})