Skip to content

[kustomize_deploy] Skip SKMO admin bootstrap in generate-only runs - #4215

Open
abays wants to merge 1 commit into
openstack-k8s-operators:mainfrom
abays:fix/skip-skmo-admin-bootstrap-generate-only
Open

abays wants to merge 1 commit into
openstack-k8s-operators:mainfrom
abays:fix/skip-skmo-admin-bootstrap-generate-only

Conversation

@abays

@abays abays commented Sep 29, 2026

Copy link
Copy Markdown
Contributor

What this change does

Skip configure_skmo_leaf_admin_user.yml when cifmw_kustomize_deploy_generate_crs_only is true.

Why

The architecture validation playbook generates manifests without applying them. It sets cifmw_kustomize_deploy_generate_crs_only: true, but the SKMO leaf admin bootstrap still queries the Kubernetes API while waiting for central Keystone. In validation jobs without a kubeconfig, that task retries and fails. This was observed in the architecture validation for PR #823.

Testing

  • git diff --check passed.
  • The Molecule test was not run.

The architecture validator generates manifests without applying them and has no cluster kubeconfig. Skip the SKMO Keystone bootstrap in generate-only mode to avoid an unnecessary Kubernetes API call.

Signed-off-by: Andrew Bays <abays@redhat.com>
@qodo-code-review

Copy link
Copy Markdown

PR Summary by Qodo

Skip SKMO admin bootstrap during generate-only deployments

🐞 Bug fix 🕐 Less than 10 minutes

Grey Divider

AI Description

• Skip SKMO leaf admin bootstrap when deployments only generate manifests.
• Prevent architecture validation from querying Kubernetes without a kubeconfig.
Diagram

graph TD
  A["Build manifests"] --> B{"Generate only?"} -->|no| C["SKMO bootstrap"] --> D["Store artifacts"]
  B -->|yes| D
Loading
High-Level Assessment

Guarding the task include with the existing generate-only flag is the narrowest fix. Guarding individual bootstrap tasks would leave unnecessary work in a manifest-only run.

Files changed (1) +1 / -0

Bug fix (1) +1 / -0
execute_step.ymlGate SKMO bootstrap on deployment mode +1/-0

Gate SKMO bootstrap on deployment mode

• Skips the SKMO leaf admin task include when generate-only mode is enabled. Normal deployments continue to bootstrap the user before applying the leaf manifests.

roles/kustomize_deploy/tasks/execute_step.yml

@abays
abays requested a review from Deydra71 September 29, 2026 09:57
@qodo-code-review

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (0) 📘 Rule violations (0) 📎 Requirement gaps (0)

Grey Divider

Great, no issues found!

Qodo reviewed your code and found no material issues that require review

Grey Divider

Tip of the day
💡 Did you know, you can add REVIEW.md to your repo root and Qodo follows it on every PR

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

@abays

abays commented Sep 29, 2026

Copy link
Copy Markdown
Contributor Author

This fixes the issue see here, which is currently affecting all architecture PRs: openstack-k8s-operators/architecture#823 (comment)

@Deydra71 Deydra71 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm

Thanks @abays !

"Fun" fact: Qodo actually flagged this in its review of #4182 in the comment --> #4182 (comment)

But we dismissed it :(

@Deydra71

Copy link
Copy Markdown
Contributor

@Valkyrie00 Hi! Can we please have your review on this fix 🙏

@Valkyrie00 Valkyrie00 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/approve

@openshift-ci

openshift-ci Bot commented Sep 29, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: Valkyrie00

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@nemarjan nemarjan left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm

@centosinfra-prod-github-app

Copy link
Copy Markdown

Build failed (check pipeline). Post recheck (without leading slash)
to rerun all jobs. Make sure the failure cause has been resolved before
you rerun jobs.

https://gateway-cloud-softwarefactory.apps.ocp.cloud.ci.centos.org/zuul/t/rdoproject.org/buildset/8c67f0c85b8f47e6931cc61e02f5a57d

✔️ openstack-k8s-operators-content-provider SUCCESS in 8h 27m 55s
❌ podified-multinode-edpm-deployment-crc POST_FAILURE in 18m 58s
✔️ podified-multinode-edpm-deployment-crc-centos-10 SUCCESS in 1h 29m 00s
❌ cifmw-crc-podified-edpm-baremetal FAILURE in 29m 25s
❌ cifmw-crc-podified-edpm-baremetal-minor-update NODE_FAILURE Node(set) request 099-0000217921 failed in 0s
✔️ cifmw-pod-zuul-files SUCCESS in 4m 38s
✔️ openstack-k8s-operators-content-provider-bootc SUCCESS in 3h 37m 53s
✔️ cifmw-crc-podified-edpm-baremetal-bootc SUCCESS in 1h 23m 17s
✔️ noop SUCCESS in 0s
✔️ cifmw-pod-ansible-test SUCCESS in 8m 30s
✔️ cifmw-pod-pre-commit SUCCESS in 8m 49s
✔️ cifmw-architecture-validate-hci SUCCESS in 5m 52s
✔️ cifmw-molecule-kustomize_deploy SUCCESS in 6m 14s

@abays

abays commented Sep 30, 2026

Copy link
Copy Markdown
Contributor Author

recheck

@centosinfra-prod-github-app

Copy link
Copy Markdown

Build failed (check pipeline). Post recheck (without leading slash)
to rerun all jobs. Make sure the failure cause has been resolved before
you rerun jobs.

https://gateway-cloud-softwarefactory.apps.ocp.cloud.ci.centos.org/zuul/t/rdoproject.org/buildset/48ba039ecce043cf8b18b0062efd1bda

❌ openstack-k8s-operators-content-provider FAILURE in 5m 13s
⚠️ podified-multinode-edpm-deployment-crc SKIPPED Skipped due to failed job openstack-k8s-operators-content-provider
⚠️ podified-multinode-edpm-deployment-crc-centos-10 SKIPPED Skipped due to failed job openstack-k8s-operators-content-provider
⚠️ cifmw-crc-podified-edpm-baremetal SKIPPED Skipped due to failed job openstack-k8s-operators-content-provider
⚠️ cifmw-crc-podified-edpm-baremetal-minor-update SKIPPED Skipped due to failed job openstack-k8s-operators-content-provider
✔️ cifmw-pod-zuul-files SUCCESS in 4m 33s
❌ openstack-k8s-operators-content-provider-bootc FAILURE in 5m 15s
⚠️ cifmw-crc-podified-edpm-baremetal-bootc SKIPPED Skipped due to failed job openstack-k8s-operators-content-provider-bootc
✔️ noop SUCCESS in 0s
✔️ cifmw-pod-ansible-test SUCCESS in 8m 07s
✔️ cifmw-pod-pre-commit SUCCESS in 8m 58s
✔️ cifmw-architecture-validate-hci SUCCESS in 5m 54s
✔️ cifmw-molecule-kustomize_deploy SUCCESS in 6m 12s

@abays

abays commented Sep 30, 2026

Copy link
Copy Markdown
Contributor Author

recheck

@centosinfra-prod-github-app

Copy link
Copy Markdown

Build failed (check pipeline). Post recheck (without leading slash)
to rerun all jobs. Make sure the failure cause has been resolved before
you rerun jobs.

https://gateway-cloud-softwarefactory.apps.ocp.cloud.ci.centos.org/zuul/t/rdoproject.org/buildset/3ee7a0fe71c444e480acbf0427361408

❌ openstack-k8s-operators-content-provider FAILURE in 6m 26s
⚠️ podified-multinode-edpm-deployment-crc SKIPPED Skipped due to failed job openstack-k8s-operators-content-provider
⚠️ podified-multinode-edpm-deployment-crc-centos-10 SKIPPED Skipped due to failed job openstack-k8s-operators-content-provider
⚠️ cifmw-crc-podified-edpm-baremetal SKIPPED Skipped due to failed job openstack-k8s-operators-content-provider
⚠️ cifmw-crc-podified-edpm-baremetal-minor-update SKIPPED Skipped due to failed job openstack-k8s-operators-content-provider
✔️ cifmw-pod-zuul-files SUCCESS in 4m 39s
❌ openstack-k8s-operators-content-provider-bootc FAILURE in 5m 56s
⚠️ cifmw-crc-podified-edpm-baremetal-bootc SKIPPED Skipped due to failed job openstack-k8s-operators-content-provider-bootc
✔️ noop SUCCESS in 0s
✔️ cifmw-pod-ansible-test SUCCESS in 8m 59s
✔️ cifmw-pod-pre-commit SUCCESS in 9m 04s
✔️ cifmw-architecture-validate-hci SUCCESS in 6m 05s
✔️ cifmw-molecule-kustomize_deploy SUCCESS in 6m 12s

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants