The charts have no unit tests. CI runs ct lint plus a helm template and
kustomize build, which prove the charts render but never assert what
they render, so conditional template logic goes unverified.
Add helm-unittest, pinned and installed as a standalone binary, a
test.helm make target, and a Helm Unittests workflow that runs it. The
first suite covers the toolbox deployment: the image composed from the
toolbox and cephImage settings, the precedence of both over the older
toolbox.image setting, the hostNetwork branch driven by the cluster
network provider, and the revisionHistoryLimit guard.
The new job is a required check in .mergify.yml, alongside the existing
chart linting.
Suites live under tests/ in a chart and are excluded from the packaged
chart via .helmignore. The runner is invoked with --strict so that a
misspelled key fails the suite instead of silently rendering defaults.
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
Nothing verified that the commit being tagged for a release actually
carries the intended version. Tagging a release branch before the version
update PR is merged publishes images and manifests that reference the
previous release. Add build/release/validate-tag.sh to check that the tree
is clean and that deploy/examples/images.txt and the helm chart values
match the tag, run it from the release build workflow before any artifact
is published, and document it in the tagging steps. Alpha tags are exempt
as they only mark the creation of a release branch.
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
The daily CI smoke, object, and other suites now run
all of the known Ceph versions, including stable
Squid, Tentacle, and Umbrella, as well as devel
versions of the same releases.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
The rook fork should only run the daily integration
tests. This disables the markdown checker in other
forks.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
ceph version v21 was release couple of days back, this
commit add the version to daily ci test list.
Also, updated the go.work
Signed-off-by: subhamkrai <srai@redhat.com>
Add the arm64 devel/release images built by ceph-ci (main-arm64,
squid-release-arm64, tentacle-arm64, umbrella-release-arm64) to the
canary-arm64 matrix, so the job exercises multiple Ceph versions on
arm64, matching the ceph-suite-tests/canary-tests coverage pattern.
Resolves: #17625
Signed-off-by: Pasan <pasan.chamikara@owasp.org>
Extract the canary-arm64 job into a reusable ceph-arm64-suite-test.yml
workflow, matrixed on a ceph_images input, matching the
ceph-suite-tests/canary-tests reusable-workflow pattern. The matrix
currently carries only the image already used by default
(quay.io/ceph/ceph:v20), so this is a pure refactor with no change in
test coverage. Adding or changing an arm64 test image is now a one-line
variable update.
Signed-off-by: Pasan <pasan.chamikara@owasp.org>
Add nightly smoke tests and installer support for the umbrella-devel Ceph image.
Also, refactored the test to use reusable code, and since we run the tests in
k8s, removed the k8s matrix from the input.
Signed-off-by: subhamkrai <srai@redhat.com>
This adds markdown link checking in th documentation sources
to the daily-nightly CI jobs.
The purpose of this is to catch breaking external links to help
keep out documentation clean.
Catching breaking external links is best done in the daily CI runs
instead of checking links in PRs. link checking in PRs would prevent
changes in PRs from newly introducing broken links.
Signed-off-by: Michael Adam <obnox@samba.org>
The minikube-to-kind conversion moved the master/release integration
tests to kind, which selects the Kubernetes version via the
kindest/node:<version> image tag. There is no published
kindest/node:v1.32.13 image (Docker Hub returns 404); the latest 1.32
node image kind ever built is v1.32.11, since later kind releases
advanced to 1.33+ and never produced a newer 1.32 patch.
Pin the on-release matrix's 1.32 entry to v1.32.11 so the 1.32-line
coverage keeps a node image that actually exists. The other matrix
versions (v1.31.14, v1.34.8, v1.36.1) already have published images.
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
Bump the most recent kubernetes version exercised by the integration and
canary matrices from v1.35.5 to v1.36.1. The kindest/node image for 1.36 is
provided by the kind v0.32.0 pinned by the kind-conversion commit. The older
matrix versions are unchanged.
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
The integration and canary suites ran on a single-node minikube
`driver: none` cluster, where the kubelet ran directly on the GitHub
runner, so the host docker daemon doubled as the cluster runtime and
host block devices and host paths were directly visible to pods. Replace
that with a kind cluster.
Every suite creates its cluster through the shared
integration-test-setup-cluster-resources composite action, so the
conversion is centralized there and converts the smoke, object, helm,
keystone, multi-cluster, upgrade, on-release, nightly, encryption-KMS and
all canary jobs at once.
- Replace the setup-minikube step with helm/kind-action, selecting the
kubernetes version via the kindest/node image tag and creating a
single-node cluster from a new kind config (kind pinned to v0.32.0 for
reproducibility).
- Drop the cri-dockerd install; kind nodes use their built-in containerd.
- Add a kind config that bind-mounts the host /dev, /var/lib/rook and
/run/udev into the node so the existing host-based disk-prep helpers
(use_local_disk*, create_partitions_for_osds, blockDevicePV.sh,
localPathPV.sh, ...) keep working unchanged: devices and partitions
created on the host appear in the node and in the OSD pods that
hostPath-mount the node /dev, and ceph-volume can read the host udev
database it needs to inventory disks.
- Prepare the kind node for the host-level operations rook runs against the
underlying host: remount /sys read-write so CSI's kernel RBD mapping
(`rbd map --device-type krbd`, which writes /sys/bus/rbd) works, and install
lvm2 and cryptsetup, which rook runs in the node's mount namespace to
provision LVM- and encryption-backed OSDs. kindest/node images provide none
of this; the minikube driver:none runner host did.
- Route the Service and pod CIDRs from the runner to the kind node so
host-side tests (the `go test` process runs on the runner) can reach
in-cluster ClusterIPs, e.g. an S3 request to the RGW service. With minikube
driver:none the runner already shared the cluster network.
- Load locally built images into the cluster. Under minikube `driver: none`
the built image was already in the cluster runtime; under kind it must be
imported, so build_rook and create_helm_tag now import their images into
each node's containerd through a new load_image_into_cluster helper (via the
node's ctr, which avoids the kind/kindest-node containerd-config version
skew that breaks `kind load docker-image`).
- Point Vault's kubernetes-auth at the in-cluster API endpoint
(kubernetes.default.svc) instead of the kubeconfig server URL: kind exposes
that as https://127.0.0.1:<port>, unreachable from the in-cluster Vault pod,
so OSD encryption-key retrieval via k8s-auth failed.
- Replace the remaining direct minikube references in the canary workflow: a
`minikube kubectl` call and the external-cluster topology values.
- Adapt host-name assumptions that only held under driver:none: resolve the
disk-cleanup job by the k8s node name rather than the runner hostname, and
let kind-action ignore post-job cluster-teardown failures (the runner is
ephemeral; nvme/multus devices can wedge `docker rm` of the node).
- Update stale comments that described the CI environment as minikube.
- Move the multus integration test's kind config under tests/config too, so
both kind cluster configs live in one place.
create-dev-cluster.sh and other local-dev tooling are intentionally left on
minikube.
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>