Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -305,6 +305,123 @@ tests:
osImage: quay.io/openshift-release-dev/ocp-v4.0-art-dev@sha256:1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1a2b
osExtensionsImage: quay.io/openshift-release-dev/ocp-v4.0-art-dev@sha256:9f8e7d6c5b4a3f2e1d0c9b8a7f6e5d4c3b2a1f0e9d8c7b6a5f4e3d2c1b0a9f8e

- name: Should accept updating spec.defaultStream to a valid stream when status is populated
initial: |
apiVersion: machineconfiguration.openshift.io/v1alpha1
kind: OSImageStream
metadata:
name: cluster
spec:
defaultStream: rhel-coreos
status:
defaultStream: rhel-coreos
availableStreams:
- name: rhel-coreos
osImage: quay.io/openshift-release-dev/ocp-v4.0-art-dev@sha256:a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2
osExtensionsImage: quay.io/openshift-release-dev/ocp-v4.0-art-dev@sha256:f9e8d7c6b5a4f3e2d1c0b9a8f7e6d5c4b3a2f1e0d9c8b7a6f5e4d3c2b1a0f9e8
- name: rhel10-coreos
osImage: quay.io/openshift-release-dev/ocp-v4.0-art-dev@sha256:1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1a2b
osExtensionsImage: quay.io/openshift-release-dev/ocp-v4.0-art-dev@sha256:9f8e7d6c5b4a3f2e1d0c9b8a7f6e5d4c3b2a1f0e9d8c7b6a5f4e3d2c1b0a9f8e
updated: |
apiVersion: machineconfiguration.openshift.io/v1alpha1
kind: OSImageStream
metadata:
name: cluster
spec:
defaultStream: rhel10-coreos
status:
defaultStream: rhel-coreos
availableStreams:
- name: rhel-coreos
osImage: quay.io/openshift-release-dev/ocp-v4.0-art-dev@sha256:a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2
osExtensionsImage: quay.io/openshift-release-dev/ocp-v4.0-art-dev@sha256:f9e8d7c6b5a4f3e2d1c0b9a8f7e6d5c4b3a2f1e0d9c8b7a6f5e4d3c2b1a0f9e8
- name: rhel10-coreos
osImage: quay.io/openshift-release-dev/ocp-v4.0-art-dev@sha256:1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1a2b
osExtensionsImage: quay.io/openshift-release-dev/ocp-v4.0-art-dev@sha256:9f8e7d6c5b4a3f2e1d0c9b8a7f6e5d4c3b2a1f0e9d8c7b6a5f4e3d2c1b0a9f8e
expected: |
apiVersion: machineconfiguration.openshift.io/v1alpha1
kind: OSImageStream
metadata:
name: cluster
spec:
defaultStream: rhel10-coreos
status:
defaultStream: rhel-coreos
availableStreams:
- name: rhel-coreos
osImage: quay.io/openshift-release-dev/ocp-v4.0-art-dev@sha256:a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2
osExtensionsImage: quay.io/openshift-release-dev/ocp-v4.0-art-dev@sha256:f9e8d7c6b5a4f3e2d1c0b9a8f7e6d5c4b3a2f1e0d9c8b7a6f5e4d3c2b1a0f9e8
- name: rhel10-coreos
osImage: quay.io/openshift-release-dev/ocp-v4.0-art-dev@sha256:1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1a2b
osExtensionsImage: quay.io/openshift-release-dev/ocp-v4.0-art-dev@sha256:9f8e7d6c5b4a3f2e1d0c9b8a7f6e5d4c3b2a1f0e9d8c7b6a5f4e3d2c1b0a9f8e

- name: Should reject updating spec.defaultStream to a stream not in status.availableStreams
initial: |
apiVersion: machineconfiguration.openshift.io/v1alpha1
kind: OSImageStream
metadata:
name: cluster
spec:
defaultStream: rhel-coreos
status:
defaultStream: rhel-coreos
availableStreams:
- name: rhel-coreos
osImage: quay.io/openshift-release-dev/ocp-v4.0-art-dev@sha256:a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2
osExtensionsImage: quay.io/openshift-release-dev/ocp-v4.0-art-dev@sha256:f9e8d7c6b5a4f3e2d1c0b9a8f7e6d5c4b3a2f1e0d9c8b7a6f5e4d3c2b1a0f9e8
- name: rhel10-coreos
osImage: quay.io/openshift-release-dev/ocp-v4.0-art-dev@sha256:1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1a2b
osExtensionsImage: quay.io/openshift-release-dev/ocp-v4.0-art-dev@sha256:9f8e7d6c5b4a3f2e1d0c9b8a7f6e5d4c3b2a1f0e9d8c7b6a5f4e3d2c1b0a9f8e
updated: |
apiVersion: machineconfiguration.openshift.io/v1alpha1
kind: OSImageStream
metadata:
name: cluster
spec:
defaultStream: non-existent-stream
status:
defaultStream: rhel-coreos
availableStreams:
- name: rhel-coreos
osImage: quay.io/openshift-release-dev/ocp-v4.0-art-dev@sha256:a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2
osExtensionsImage: quay.io/openshift-release-dev/ocp-v4.0-art-dev@sha256:f9e8d7c6b5a4f3e2d1c0b9a8f7e6d5c4b3a2f1e0d9c8b7a6f5e4d3c2b1a0f9e8
- name: rhel10-coreos
osImage: quay.io/openshift-release-dev/ocp-v4.0-art-dev@sha256:1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1a2b
osExtensionsImage: quay.io/openshift-release-dev/ocp-v4.0-art-dev@sha256:9f8e7d6c5b4a3f2e1d0c9b8a7f6e5d4c3b2a1f0e9d8c7b6a5f4e3d2c1b0a9f8e
expectedError: "spec.defaultStream must reference an existing stream name from status.availableStreams"

- name: Should reject removing a stream from status.availableStreams that spec.defaultStream references
initial: |
apiVersion: machineconfiguration.openshift.io/v1alpha1
kind: OSImageStream
metadata:
name: cluster
spec:
defaultStream: rhel-coreos
status:
defaultStream: rhel-coreos
availableStreams:
- name: rhel-coreos
osImage: quay.io/openshift-release-dev/ocp-v4.0-art-dev@sha256:a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2
osExtensionsImage: quay.io/openshift-release-dev/ocp-v4.0-art-dev@sha256:f9e8d7c6b5a4f3e2d1c0b9a8f7e6d5c4b3a2f1e0d9c8b7a6f5e4d3c2b1a0f9e8
- name: rhel10-coreos
osImage: quay.io/openshift-release-dev/ocp-v4.0-art-dev@sha256:1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1a2b
osExtensionsImage: quay.io/openshift-release-dev/ocp-v4.0-art-dev@sha256:9f8e7d6c5b4a3f2e1d0c9b8a7f6e5d4c3b2a1f0e9d8c7b6a5f4e3d2c1b0a9f8e
updated: |
apiVersion: machineconfiguration.openshift.io/v1alpha1
kind: OSImageStream
metadata:
name: cluster
spec:
defaultStream: rhel-coreos
status:
defaultStream: rhel10-coreos
availableStreams:
- name: rhel10-coreos
osImage: quay.io/openshift-release-dev/ocp-v4.0-art-dev@sha256:1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1a2b
osExtensionsImage: quay.io/openshift-release-dev/ocp-v4.0-art-dev@sha256:9f8e7d6c5b4a3f2e1d0c9b8a7f6e5d4c3b2a1f0e9d8c7b6a5f4e3d2c1b0a9f8e
expectedStatusError: "spec.defaultStream must reference an existing stream name from status.availableStreams"

- name: Should reject an status update without defaultStream
initial: |
apiVersion: machineconfiguration.openshift.io/v1alpha1
Expand Down
8 changes: 8 additions & 0 deletions machineconfiguration/v1alpha1/types_osimagestream.go
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,7 @@ import (
// +openshift:enable:FeatureGate=OSStreams
// +kubebuilder:metadata:labels=openshift.io/operator-managed=
// +kubebuilder:validation:XValidation:rule="self.metadata.name == 'cluster'",message="osimagestream is a singleton, .metadata.name must be 'cluster'"
// +kubebuilder:validation:XValidation:rule="!has(self.spec.defaultStream) || !has(self.status) || self.spec.defaultStream in self.status.availableStreams.map(s, s.name)",message="spec.defaultStream must reference an existing stream name from status.availableStreams"
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

You need to test this, integration ratcheting tests in particular.

You'll also want to make sure that this only rejects spec writes.

Imagine a case where the user forces through any upgrade checks, currently a status update could fail if their spec value is no longer present in the spec list after update.

Adjust this to accept any time self.spec == oldSelf.spec would be a useful guard here

type OSImageStream struct {
metav1.TypeMeta `json:",inline"`

Expand Down Expand Up @@ -84,6 +85,13 @@ type OSImageStreamSpec struct {
// status.availableStreams to apply as the default for MachineConfigPools
// that do not specify a stream override.
//
// When status.availableStreams has been populated by the operator, this field
// must reference the name of one of the streams in status.availableStreams.
// During initial creation, before the operator has populated status, any
// valid value is accepted.
//
// When omitted, the operator determines the default stream automatically.
//
// It must be a valid RFC 1123 subdomain between 1 and 253 characters in length,
// consisting of lowercase alphanumeric characters, hyphens ('-'), and periods ('.').
//
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -62,6 +62,13 @@ spec:
status.availableStreams to apply as the default for MachineConfigPools
that do not specify a stream override.

When status.availableStreams has been populated by the operator, this field
must reference the name of one of the streams in status.availableStreams.
During initial creation, before the operator has populated status, any
valid value is accepted.

When omitted, the operator determines the default stream automatically.

It must be a valid RFC 1123 subdomain between 1 and 253 characters in length,
consisting of lowercase alphanumeric characters, hyphens ('-'), and periods ('.').
maxLength: 253
Expand Down Expand Up @@ -184,6 +191,10 @@ spec:
x-kubernetes-validations:
- message: osimagestream is a singleton, .metadata.name must be 'cluster'
rule: self.metadata.name == 'cluster'
- message: spec.defaultStream must reference an existing stream name from
status.availableStreams
rule: '!has(self.spec.defaultStream) || !has(self.status) || self.spec.defaultStream
in self.status.availableStreams.map(s, s.name)'
served: true
storage: true
subresources:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -62,6 +62,13 @@ spec:
status.availableStreams to apply as the default for MachineConfigPools
that do not specify a stream override.

When status.availableStreams has been populated by the operator, this field
must reference the name of one of the streams in status.availableStreams.
During initial creation, before the operator has populated status, any
valid value is accepted.

When omitted, the operator determines the default stream automatically.

It must be a valid RFC 1123 subdomain between 1 and 253 characters in length,
consisting of lowercase alphanumeric characters, hyphens ('-'), and periods ('.').
maxLength: 253
Expand Down Expand Up @@ -184,6 +191,10 @@ spec:
x-kubernetes-validations:
- message: osimagestream is a singleton, .metadata.name must be 'cluster'
rule: self.metadata.name == 'cluster'
- message: spec.defaultStream must reference an existing stream name from
status.availableStreams
rule: '!has(self.spec.defaultStream) || !has(self.status) || self.spec.defaultStream
in self.status.availableStreams.map(s, s.name)'
served: true
storage: true
subresources:
Expand Down

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion openapi/generated_openapi/zz_generated.openapi.go

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Original file line number Diff line number Diff line change
Expand Up @@ -62,6 +62,13 @@ spec:
status.availableStreams to apply as the default for MachineConfigPools
that do not specify a stream override.

When status.availableStreams has been populated by the operator, this field
must reference the name of one of the streams in status.availableStreams.
During initial creation, before the operator has populated status, any
valid value is accepted.

When omitted, the operator determines the default stream automatically.

It must be a valid RFC 1123 subdomain between 1 and 253 characters in length,
consisting of lowercase alphanumeric characters, hyphens ('-'), and periods ('.').
maxLength: 253
Expand Down Expand Up @@ -184,6 +191,10 @@ spec:
x-kubernetes-validations:
- message: osimagestream is a singleton, .metadata.name must be 'cluster'
rule: self.metadata.name == 'cluster'
- message: spec.defaultStream must reference an existing stream name from
status.availableStreams
rule: '!has(self.spec.defaultStream) || !has(self.status) || self.spec.defaultStream
in self.status.availableStreams.map(s, s.name)'
served: true
storage: true
subresources:
Expand Down