Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
92 commits
Select commit Hold shift + click to select a range
292c62f
test
Axuba Dec 10, 2024
e9d2701
test
Axuba Dec 10, 2024
42353bd
test
Axuba Dec 11, 2024
269cb46
test
Axuba Dec 11, 2024
8dfa4b7
test
Axuba Dec 11, 2024
5598a01
test
Axuba Dec 11, 2024
ecb1b83
test
Axuba Dec 12, 2024
cf257c4
tesT
Axuba Dec 12, 2024
7e9c205
test
Axuba Dec 13, 2024
873012a
test
Axuba Dec 13, 2024
0a5b6b9
test
Axuba Dec 16, 2024
b0e8fb5
test
Axuba Dec 19, 2024
c090765
test
Axuba Dec 19, 2024
f3100b1
test
Axuba Dec 19, 2024
8622961
test
Axuba Dec 19, 2024
0ed659c
test
Axuba Dec 19, 2024
a7abbbf
Add snapshot id parameter to be also exported
Axuba Dec 31, 2024
9e83286
test
Axuba Jan 15, 2025
0fe16e4
test
Axuba Jan 16, 2025
8d3c9a0
Update fbc-post-release.yaml
Axuba Jan 20, 2025
67909fd
Add version and releasePlan null params
Axuba Jan 30, 2025
4b00938
Update script
Axuba Jan 30, 2025
d0c8e35
Temporarily hardcode version parameter
Axuba Jan 30, 2025
6727160
Change stages to lanes folder
Axuba Jan 30, 2025
990246e
Channel folder to commit to will now depend on the fbc channel itself
Axuba Jan 31, 2025
4dbebd1
Update fbc-post-release.yaml
Axuba Feb 6, 2025
e12796d
added prNumber to the payload structure
tal-hason Feb 20, 2025
7db7353
Merge pull request #2 from openshift-cnv/adde-PRnumber-to-payload-schema
Axuba Feb 24, 2025
e1eed21
added minorVersion for kargo to use
tal-hason Mar 2, 2025
81eefca
Merge pull request #3 from openshift-cnv/minor-version-key
Axuba Mar 3, 2025
a3935a6
first release
tal-hason Mar 18, 2025
b326d2b
Merge pull request #4 from openshift-cnv/firstRelease-Flag
Axuba Mar 18, 2025
215bea2
Separate v4.99 builds on fbc payloads
Axuba Mar 28, 2025
4d9db25
Add version, releaseplan and freightname data
Axuba Jun 4, 2025
f50ff82
Merge pull request #5 from openshift-cnv/Axuba-patch-1
Axuba Jun 6, 2025
7c2fc9f
Temporarily update repo
Axuba Jun 6, 2025
0b36a55
Fix
Axuba Jun 6, 2025
d1e07c4
Update fbc-post-release.yaml
Axuba Jun 6, 2025
c29b04d
Update fbc-post-release.yaml
tal-hason Jul 2, 2025
e4296d5
Add rhelVersion parameter
Axuba Jul 15, 2025
1ed5ae7
Add environment parameter
Axuba Aug 25, 2025
cc4c615
Fix typo
Axuba Aug 25, 2025
2e64cc5
Add update-bundle pipeline (#8)
Axuba Nov 26, 2025
3e36af3
Pull with creds
Axuba Nov 26, 2025
d12c626
Make sure all the commits in every component are the same
Axuba Nov 27, 2025
53553ee
Fix IIB status path as it changed
Axuba Nov 27, 2025
2297da5
Fix operator check as now it includes -rhel suffix
Axuba Dec 10, 2025
545e7e3
Another fix so test images dont go to core params
Axuba Dec 10, 2025
7847dd7
Add snapshot id to a new snapshots json file
Axuba Dec 22, 2025
bc659e8
Push release skeleton for hco-bundle-images (#9)
Axuba Jan 8, 2026
ac16481
Use tmp for quay build creds path
Axuba Jan 8, 2026
adb0e6e
Use pipeline tools image to push the chart
Axuba Jan 8, 2026
38c121b
Check if there are actually changes before committing
Axuba Jan 8, 2026
b4e410c
Increase clone depth
Axuba Jan 8, 2026
8003543
Work under a tmpdir
Axuba Jan 8, 2026
ce791e2
Use tmp as home, instead of default /
Axuba Jan 8, 2026
28d5b62
Fix quay url
Axuba Jan 8, 2026
7f6c73a
Fill releaseplan and namespace
Axuba Jan 8, 2026
0b30634
Fix
Axuba Jan 8, 2026
05da569
Fix typo
Axuba Jan 8, 2026
98e6950
Add hco bundle url to payload
Axuba Jan 12, 2026
82e75a0
Add skeleton chart version parameter to update-bundle pipeline and do…
tal-hason Jan 20, 2026
193bc3e
Enhance update-bundle pipeline with detailed logging and validation s…
tal-hason Jan 21, 2026
cd43177
Refactor update-bundle pipeline to improve script clarity and organiz…
tal-hason Jan 21, 2026
5b5ed1a
Update chart versioning logic in update-bundle pipeline for improved …
tal-hason Jan 22, 2026
6cff380
Add .gitignore and new MDC files for execution layer and Tekton pipel…
tal-hason Feb 5, 2026
74ef0c9
Fix: export update_images_snapshots function
Axuba Feb 5, 2026
24d98a1
Use git status porcelain when checking if there are changes
Axuba Feb 5, 2026
d10638b
Refactor update-bundle pipeline to improve counter increment syntax f…
tal-hason Feb 5, 2026
8e34e70
Refactor execution summary function in execution-layer-reference.mdc …
tal-hason Feb 5, 2026
6f0ef9e
Enhance update-bundle pipeline by defining snapshots_file outside the…
tal-hason Feb 5, 2026
ce3efd8
Refactor Quay registry login process in update-bundle pipeline to enh…
tal-hason Feb 6, 2026
a4f55bc
Improve commit consistency validation in update-bundle pipeline by di…
tal-hason Feb 6, 2026
757b9fc
fix(update-bundle): use deterministic chart filename to prevent skele…
tal-hason Feb 13, 2026
2211360
refactor(update-bundle): enhance logging and error handling in snapsh…
tal-hason Feb 13, 2026
57aadad
If application is a test application, don't update the snapshot file
Axuba Feb 16, 2026
ec166f5
Fail when revisions differ
Axuba Feb 17, 2026
5ba25d0
fix(update-bundle): update chart name and refine values.yaml hydratio…
tal-hason Feb 17, 2026
fc4436c
fix(fbc-post-release): add retry loop for git push race condition
tal-hason Feb 20, 2026
2fc3267
delete: remove execution-layer-reference.mdc and tekton-pipelines.mdc…
tal-hason Feb 22, 2026
ed3d043
fix(update-bundle): enhance chart name hydration logic and update log…
tal-hason Feb 25, 2026
17b73c9
docs(tekton-pipelines): add credential patterns and Helm OCI chart li…
tal-hason Feb 25, 2026
e323e8a
feat(pipeline): persist Snapshot objects in chart for GC resilience
tal-hason Feb 26, 2026
5282662
feat(fbc-post-release): add Smartsheet prod release tracking per channel
tal-hason Mar 9, 2026
e4524e0
Virt-platform-autopilot should also be in the core-params
Axuba Mar 12, 2026
803507d
feat(report-fbc-build-status): add new task for reporting FBC build s…
tal-hason Mar 17, 2026
7c0b1a1
Update if case image to handle v4.12 images
Axuba Apr 27, 2026
002f70c
Sort parameter json for clarity
Axuba Apr 28, 2026
30b9fe6
Do not add test images to core params
Axuba Apr 28, 2026
cf993ac
Fix wrong if clause
Axuba Apr 29, 2026
620a698
Bump tag
Axuba Jul 16, 2026
4f1cdca
VMER-1129: Do not fail if commits are not consistent
Axuba Jul 27, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
140 changes: 140 additions & 0 deletions .cursor/rules/010-tekton-pipelines.mdc
Original file line number Diff line number Diff line change
@@ -0,0 +1,140 @@
---
description: Guidelines for Tekton pipeline development with resilient execution patterns
alwaysApply: true
---

# Tekton Tasks Repository Guidelines

## Repository Overview

This repository contains Tekton pipelines and tasks for OpenShift Virtualization CI/CD workflows. All pipelines follow the **Resilient Execution Layer** pattern for observability and debugging.

## Key Patterns

### Resilient Execution Layer

Every pipeline step MUST include:

1. **Execution Layer Header** - Initialize tracking at script start:
```bash
SCRIPT_START=$(date +%s)
declare -a ACTION_LOG=()
FINAL_EXIT_CODE=0
```

2. **exec_action() wrapper** - Wrap external commands with timeouts and structured logging:
```bash
exec_action "Action name" <timeout_secs> "<command>"
```

3. **execution_summary() trap** - Guarantee summary output on ANY exit:
```bash
trap execution_summary EXIT
```

4. **Fail-fast run logic** - Keep `set -eo pipefail` for business logic after the execution layer.

### Timeout Guidelines

| Command Type | Recommended Timeout |
|-------------|---------------------|
| kubectl/oc API calls | 60s |
| git clone | 120s |
| git pull/push | 60s |
| helm pull | 120s |
| helm push | 120s |
| helm lint/package | 30s |
| Registry login | 30s |
| Validation checks | 30s |

### Validation Requirements

Before executing any command, validate:
- Required parameters are not empty
- Environment variables (tokens, credentials) exist
- Files exist before reading them
- JSON/YAML is valid before parsing

### Output Formatting

Use box-drawing characters for structured output:
- `┌─────` Action start
- `│` Output prefix
- `├─────` Status separator
- `└─────` Action end
- `╔═════` Summary header
- `║` Summary lines
- `╚═════` Summary footer

### Credential Patterns

#### Registry Auth (Quay OCI)

For steps that pull/push OCI artifacts (Helm charts, images):
1. Mount the docker config secret as a **volume** (provides `.dockerconfigjson` file)
2. Extract username/password via `jq` from the mounted file
3. Run `helm registry login <host>` **inline** (not through `exec_action`) -- passwords cannot be safely piped through `bash -c`
4. A single `helm registry login quay.io` covers ALL quay.io repos the robot has access to

#### Secret Injection

- Use `envFrom` for tokens needed as env vars (e.g., `GITLAB_TOKEN`)
- Use `volumeMounts` for structured credentials (e.g., `.dockerconfigjson`)
- Never hardcode credentials in pipeline YAML

### Helm OCI Chart Lifecycle

When pipelines produce Helm charts via OCI:

1. **Pull** a skeleton (template) chart from OCI registry
2. **Hydrate** Chart.yaml fields (name, version, appVersion) from build metadata
3. **Hydrate** values.yaml with runtime configuration
4. **Lint** the hydrated chart (`helm lint .`)
5. **Package** (`helm package .`) -- filename is `{Chart.yaml name}-{Chart.yaml version}.tgz`
6. **Push** to target OCI registry (`helm push <file> oci://<registry>`)

`helm package` derives the .tgz filename from `Chart.yaml`, not from shell variables. Always verify `PACKAGE_FILE` matches what `helm package` actually produces.

### Cross-Step Data Sharing

Steps within the same Tekton task share `/tekton/results/`:
- Step N writes: `echo -n "$VALUE" > /tekton/results/<name>`
- Step N+1 reads: `cat /tekton/results/<name>`
- Size limit: ~4KB per result, ~12KB total. Monitor for large JSON payloads.

## File Structure

```
tekton-tasks/
├── pipelines/ # Full pipeline definitions
│ └── *.yaml
├── fbc/ # FBC-specific tasks
│ └── *.yaml
└── README.md
```

## Pipeline Parameters

Always include a `debug` parameter for verbose output:
```yaml
- name: debug
type: string
default: "false"
description: Enable debug mode with verbose output (set -x)
```

## Testing Changes

Before committing:
1. Validate YAML syntax: `python3 -c "import yaml; yaml.safe_load(open('file.yaml'))"`
2. Validate bash syntax: Extract script and run `bash -n script.sh`
3. Test in a non-production namespace first

## Commit Messages

Format: `<type>(<scope>): <description>`

Examples:
- `feat(pipeline): add new release automation step`
- `fix(update-bundle): handle empty snapshot gracefully`
- `refactor(pipeline): improve error handling and observability`
149 changes: 149 additions & 0 deletions .cursor/rules/020-execution-layer-reference.mdc
Original file line number Diff line number Diff line change
@@ -0,0 +1,149 @@
---
description: Reference implementation for the resilient execution layer pattern
globs: "**/*.yaml"
alwaysApply: false
---

# Execution Layer Reference Implementation

## Full Template

Copy this template when creating new pipeline steps:

```bash
#!/usr/bin/env bash

# ============================================================
# EXECUTION LAYER - Resilient wrapper for observability
# ============================================================
SCRIPT_START=$(date +%s)
declare -a ACTION_LOG=()
FINAL_EXIT_CODE=0

# Enable debug mode if requested
if [[ "$(params.DEBUG)" == "true" ]]; then
set -x
fi

exec_action() {
local action_name="$1"
local timeout_secs="${2:-60}"
shift 2
local cmd="$*"

local start_ts=$(date +%s)
echo ""
echo "┌─────────────────────────────────────────────────────────────"
echo "│ ACTION: $action_name"
echo "│ CMD: $cmd"
echo "│ TIMEOUT: ${timeout_secs}s"
echo "├─────────────────────────────────────────────────────────────"

local output exit_code
output=$(timeout "$timeout_secs" bash -c "$cmd" 2>&1)
exit_code=$?

local end_ts=$(date +%s)
local duration=$((end_ts - start_ts))

if [[ -n "$output" ]]; then
echo "$output" | sed 's/^/│ /'
fi

local status
if [[ $exit_code -eq 0 ]]; then
status="OK"
elif [[ $exit_code -eq 124 ]]; then
status="TIMEOUT"
else
status="FAILED"
fi

echo "├─────────────────────────────────────────────────────────────"
echo "│ STATUS: $status (exit: $exit_code, duration: ${duration}s)"
echo "└─────────────────────────────────────────────────────────────"

ACTION_LOG+=("$status|$action_name|exit=$exit_code|${duration}s")
return $exit_code
}

execution_summary() {
local script_exit_code=$?
local script_end=$(date +%s)
local total_duration=$((script_end - SCRIPT_START))

echo ""
echo "╔═════════════════════════════════════════════════════════════"
echo "║ EXECUTION SUMMARY - <step-name>"
echo "║ Total Duration: ${total_duration}s"
echo "║ Final Exit Code: ${FINAL_EXIT_CODE:-$script_exit_code}"
echo "╠═════════════════════════════════════════════════════════════"

local ok_count=0 fail_count=0 timeout_count=0

for entry in "${ACTION_LOG[@]}"; do
local status=$(echo "$entry" | cut -d'|' -f1)
local action=$(echo "$entry" | cut -d'|' -f2)
local details=$(echo "$entry" | cut -d'|' -f3-)

case "$status" in
OK) ok_count=$((ok_count + 1)); echo "║ ✓ $action ($details)" ;;
FAILED) fail_count=$((fail_count + 1)); echo "║ ✗ $action ($details)" ;;
TIMEOUT) timeout_count=$((timeout_count + 1)); echo "║ ⏱ $action ($details)" ;;
esac
done

echo "╠═════════════════════════════════════════════════════════════"
echo "║ OK: $ok_count | FAILED: $fail_count | TIMEOUT: $timeout_count"
echo "╚═════════════════════════════════════════════════════════════"

exit ${FINAL_EXIT_CODE:-$script_exit_code}
}

trap execution_summary EXIT

# ============================================================
# RUN LOGIC - Business logic with fail-fast behavior
# ============================================================
set -eo pipefail

# Your business logic here...
```

## Usage Patterns

### Wrapping Commands

```bash
# With exec_action (preferred for external calls)
if ! exec_action "Fetch data" 60 "kubectl get pod -ojson"; then
echo "ERROR: Failed to fetch data"
FINAL_EXIT_CODE=1
exit 1
fi

# Quick validation (no external call)
if [[ -z "$REQUIRED_VAR" ]]; then
echo "ERROR: REQUIRED_VAR is empty"
FINAL_EXIT_CODE=1
exit 1
fi
ACTION_LOG+=("OK|Validate REQUIRED_VAR|exit=0|0s")
```

### Early Exit (Success)

```bash
if [[ "$CONDITION" == "skip" ]]; then
ACTION_LOG+=("OK|Skip - condition met|exit=0|0s")
FINAL_EXIT_CODE=0
exit 0
fi
```

## Key Principles

1. **Always set FINAL_EXIT_CODE before exit** - Ensures trap reports correct status
2. **Log manual validations** - Add to ACTION_LOG for visibility
3. **Timeout all external calls** - Prevent indefinite hangs
4. **Validate before use** - Check files/vars exist before operations
Loading