diff --git a/ci-operator/config/stolostron/policy-collection/stolostron-policy-collection-main__ocp4.22.yaml b/ci-operator/config/stolostron/policy-collection/stolostron-policy-collection-main__ocp4.22.yaml index c3a92c8259122..a0e8de8d517ff 100644 --- a/ci-operator/config/stolostron/policy-collection/stolostron-policy-collection-main__ocp4.22.yaml +++ b/ci-operator/config/stolostron/policy-collection/stolostron-policy-collection-main__ocp4.22.yaml @@ -123,7 +123,7 @@ tests: - chain: cucushift-installer-check-cluster-health - ref: stackrox-opp-readiness - ref: stackrox-opp-smoke - - ref: acm-tests-clc-create + - ref: acm-tests-clc-smoke - ref: acm-fetch-managed-clusters - ref: acm-opp-app - ref: interop-opp-odf-health diff --git a/ci-operator/config/stolostron/policy-collection/stolostron-policy-collection-main__ocp5.0.yaml b/ci-operator/config/stolostron/policy-collection/stolostron-policy-collection-main__ocp5.0.yaml index e31b7716529a3..decdf2d896ba8 100644 --- a/ci-operator/config/stolostron/policy-collection/stolostron-policy-collection-main__ocp5.0.yaml +++ b/ci-operator/config/stolostron/policy-collection/stolostron-policy-collection-main__ocp5.0.yaml @@ -104,7 +104,7 @@ tests: - ref: acm-policies-openshift-plus-setup - ref: acm-policies-openshift-plus - chain: cucushift-installer-check-cluster-health - - ref: acm-tests-clc-create + - ref: acm-tests-clc-smoke - ref: acm-fetch-managed-clusters - ref: acm-opp-app - ref: interop-opp-odf-health diff --git a/ci-operator/step-registry/acm/tests/clc-smoke/OWNERS b/ci-operator/step-registry/acm/tests/clc-smoke/OWNERS new file mode 100644 index 0000000000000..76364ea3076e7 --- /dev/null +++ b/ci-operator/step-registry/acm/tests/clc-smoke/OWNERS @@ -0,0 +1,9 @@ +approvers: +- cspi-qe-ocp-lp +- dtthuynh +- vboulos +options: {} +reviewers: +- cspi-qe-ocp-lp +- dtthuynh +- vboulos diff --git a/ci-operator/step-registry/acm/tests/clc-smoke/README.md b/ci-operator/step-registry/acm/tests/clc-smoke/README.md new file mode 100644 index 0000000000000..192fbd4eecca1 --- /dev/null +++ b/ci-operator/step-registry/acm/tests/clc-smoke/README.md @@ -0,0 +1,38 @@ +# acm-tests-clc-smoke-ref + +## Table of Contents +- [Purpose](#purpose) +- [Process](#process) +- [Requirements](#requirements) + - [Infrastructure](#infrastructure) + - [Environment Variables](#environment-variables) + +## Purpose + +Smoke-scoped variant of [acm-tests-clc-create](../clc-create/README.md) with a right-sized timeout and strict failure handling for OPP interop. + +The full `acm-tests-clc-create` step already creates only 1 AWS managed cluster (~50 min actual runtime) but carries a 28800s (8h) timeout and suppresses failures with `|| :`. This step: +- Reduces the timeout to 5400s (90 min), giving ~80% headroom over the observed average. +- Runs with `best_effort: true` so independent downstream validations (ODF health, Quay smoke, observability) continue regardless of CLC outcome. The script still exits with the CLC status code for JUnit reporting and failure visibility. + +> **IMPORTANT** +> You must use the [acm-tests-clc-destroy-ref](../clc-destroy/README.md) as a post step when using this step. If you do not and succeed in running this step then you will leave clusters running on the ACM QE team's cloud. + +## Process + +- Copies secret options file needed for test execution. +- Injects AWS credentials from the cluster profile into options.yaml. +- Sets dynamic variables based on the provisioned hub cluster. +- Runs `execute_clc_interop_commands.sh` which invokes Cypress with tag filter `@create+aws+-sno+-@clusterpool` (controlled by `TEST_STAGE=OCPInterop-create` inside the image). + +## Requirements + +### Infrastructure + +- An existing OpenShift cluster to act as the target Hub. +- "advanced-cluster-management" operator installed (see [`install-operators`](../../../install-operators/README.md)). +- MCH custom resource installed (see [acm-mch step](../mch/README.md)). + +### Environment Variables + +- Please see [acm-tests-clc-smoke-ref.yaml](acm-tests-clc-smoke-ref.yaml) env section. diff --git a/ci-operator/step-registry/acm/tests/clc-smoke/acm-tests-clc-smoke-commands.sh b/ci-operator/step-registry/acm/tests/clc-smoke/acm-tests-clc-smoke-commands.sh new file mode 100755 index 0000000000000..90a03212f85a3 --- /dev/null +++ b/ci-operator/step-registry/acm/tests/clc-smoke/acm-tests-clc-smoke-commands.sh @@ -0,0 +1,78 @@ +#!/bin/bash +set -euxo pipefail; shopt -s inherit_errexit + +typeset secretsDir="/tmp/secrets" +typeset optionFile="./options.yaml" +typeset awsCredFile="${CLUSTER_PROFILE_DIR}/.awscred" + +if [[ "${SKIP_OCP_DEPLOY:-false}" == "true" ]]; then + cp "${secretsDir}/ci/kubeconfig" "${SHARED_DIR}/kubeconfig" + cp "${secretsDir}/ci/kubeadmin-password" "${SHARED_DIR}/kubeadmin-password" +fi + +cp "${secretsDir}/clc-interop/secret-options-yaml" "${optionFile}" + +if [[ -f "${awsCredFile}" ]]; then + typeset awsAccKeyID= + typeset awsAccKeyToken= + + # tracing off: AWS credentials + set +x + awsAccKeyID="$(sed -nE 's/^\s*aws_access_key_id\s*=\s*//p;T;q' "${awsCredFile}")" + awsAccKeyToken="$(sed -nE 's/^\s*aws_secret_access_key\s*=\s*//p;T;q' "${awsCredFile}")" + + if [[ -z "${awsAccKeyID}" ]] || [[ -z "${awsAccKeyToken}" ]]; then + echo "ERROR: Failed to extract AWS credentials from ${awsCredFile}" 1>&2 + exit 1 + fi + + yq -o json eval . "${optionFile}" | + jq -c \ + --arg awsAccKeyID "${awsAccKeyID}" \ + --rawfile awsAccKeyToken <(printf '%s' "${awsAccKeyToken}") \ + ' + .options.connections.apiKeys.aws|=( + .awsAccessKeyID=$awsAccKeyID | + .awsSecretAccessKeyID=($awsAccKeyToken | rtrimstr("\n")) + ) + ' | + yq -p json -o yaml eval . > "${optionFile}.tmp" + mv -f "${optionFile}.tmp" "${optionFile}" + set -x + + unset awsAccKeyID awsAccKeyToken +fi + +# tracing off: kubeadmin password +set +x +export CYPRESS_OPTIONS_HUB_PASSWORD= +CYPRESS_OPTIONS_HUB_PASSWORD="$(cat "${SHARED_DIR}/kubeadmin-password")" + +typeset cypress_base_url cypress_hub_api_url cypress_ocp_version cloud_providers +cypress_base_url="$(oc whoami --show-console)" +cypress_hub_api_url="$(oc whoami --show-server)" +cypress_ocp_version="$(cat "${secretsDir}/clc/ocp_image_version")" +cloud_providers="$(cat "${secretsDir}/clc/ocp_cloud_providers")" + +if [[ -z "${cypress_base_url}" ]] || [[ -z "${cypress_hub_api_url}" ]]; then + echo "ERROR: Console URL or API URL is empty; oc whoami returned no usable value" 1>&2 + exit 1 +fi + +typeset clcStatus=0 + +CYPRESS_BASE_URL="${cypress_base_url}" \ +CYPRESS_HUB_API_URL="${cypress_hub_api_url}" \ +CYPRESS_CLC_OCP_IMAGE_VERSION="${cypress_ocp_version}" \ +CLOUD_PROVIDERS="${cloud_providers}" \ +bash +x ./execute_clc_interop_commands.sh || clcStatus=$? +set -x + +unset CYPRESS_OPTIONS_HUB_PASSWORD + +typeset reportStatus=0 +cp -r reports "${ARTIFACT_DIR}/" || reportStatus=$? +if (( clcStatus != 0 )); then + exit "${clcStatus}" +fi +exit "${reportStatus}" diff --git a/ci-operator/step-registry/acm/tests/clc-smoke/acm-tests-clc-smoke-ref.metadata.json b/ci-operator/step-registry/acm/tests/clc-smoke/acm-tests-clc-smoke-ref.metadata.json new file mode 100644 index 0000000000000..bfcc856a27d44 --- /dev/null +++ b/ci-operator/step-registry/acm/tests/clc-smoke/acm-tests-clc-smoke-ref.metadata.json @@ -0,0 +1,15 @@ +{ + "path": "acm/tests/clc-smoke/acm-tests-clc-smoke-ref.yaml", + "owners": { + "approvers": [ + "cspi-qe-ocp-lp", + "dtthuynh", + "vboulos" + ], + "reviewers": [ + "cspi-qe-ocp-lp", + "dtthuynh", + "vboulos" + ] + } +} \ No newline at end of file diff --git a/ci-operator/step-registry/acm/tests/clc-smoke/acm-tests-clc-smoke-ref.yaml b/ci-operator/step-registry/acm/tests/clc-smoke/acm-tests-clc-smoke-ref.yaml new file mode 100644 index 0000000000000..775b3cda884ae --- /dev/null +++ b/ci-operator/step-registry/acm/tests/clc-smoke/acm-tests-clc-smoke-ref.yaml @@ -0,0 +1,74 @@ +ref: + as: acm-tests-clc-smoke + from: clc-ui-e2e + commands: acm-tests-clc-smoke-commands.sh + timeout: 5400s + best_effort: true + resources: + requests: + cpu: '2' + memory: 6Gi + credentials: + - namespace: test-credentials + name: opp-acm-clc-credentials + mount_path: /tmp/secrets/clc-interop + - namespace: test-credentials + name: acm-clc-credentials + mount_path: /tmp/secrets/clc + - namespace: test-credentials + name: acm-ci-credentials + mount_path: /tmp/secrets/ci + env: + - name: CYPRESS_OC_IDP + default: "kube:admin" + documentation: |- + Identity + - name: CYPRESS_OPTIONS_HUB_USER + default: "kubeadmin" + documentation: |- + Hub cluster username + - name: CYPRESS_SPOKE_CLUSTER + default: "" + documentation: |- + Identify spoke clusters + - name: BROWSER + default: "chrome" + documentation: |- + Set browser for cypress + - name: CUSTOMER_TAGS + default: "" + documentation: |- + Cypress grep tag filter (passed through to test execution) + - name: CYPRESS_CLC_OC_IDP + default: "clc-e2e-htpasswd" + documentation: |- + Serves tests RBAC settings + - name: CYPRESS_CLC_RBAC_PASS + default: "test-RBAC-4-e2e" + documentation: |- + Serves tests RBAC settings + - name: CYPRESS_CLC_OCP_IMAGE_REGISTRY + default: "quay.io/openshift-release-dev/ocp-release" + documentation: |- + Image registry + - name: CYPRESS_ACM_NAMESPACE + default: "ocm" + documentation: |- + Acm namespace + - name: CYPRESS_MCE_NAMESPACE + default: "multicluster-engine" + documentation: |- + Mce namespace + - name: IMPORT_KUBERNETES_CLUSTERS + default: "" + documentation: |- + Comma separated list of imports + - name: SKIP_OCP_DEPLOY + default: "false" + documentation: |- + When true, copies kubeconfig from CI secrets instead of using cluster profile + documentation: |- + Smoke-scoped ACM cluster lifecycle step that creates a single managed + cluster on AWS (~50 min). Runs with best_effort so that CLC failures + do not block independent downstream validations (ODF health, Quay smoke, + observability). JUnit results are still reported for failure visibility. diff --git a/ci-operator/step-registry/stackrox/opp-smoke/stackrox-opp-smoke-ref.yaml b/ci-operator/step-registry/stackrox/opp-smoke/stackrox-opp-smoke-ref.yaml index 74d11f0815aa9..329a34c9d7a71 100644 --- a/ci-operator/step-registry/stackrox/opp-smoke/stackrox-opp-smoke-ref.yaml +++ b/ci-operator/step-registry/stackrox/opp-smoke/stackrox-opp-smoke-ref.yaml @@ -11,6 +11,7 @@ ref: memory: 4Gi from: acs-smoke-runner timeout: 1h0m0s + best_effort: true documentation: |- Run the ACS qa-tests-backend SMOKE suite against a live ACS instance. Reads connection credentials from SHARED_DIR