Skip to content

Update Konflux pipelines: Fix OPM for OCP 5.x, update Go 1.26 builder, migrate to roxctl-scan - #1008

Merged
openshift-merge-bot[bot] merged 4 commits into
openshift-knative:mainfrom
Kaustubh-pande:update-go-image-tag
Sep 3, 2026
Merged

openshift-merge-bot[bot] merged 4 commits into
openshift-knative:mainfrom
Kaustubh-pande:update-go-image-tag

Conversation

@Kaustubh-pande

Copy link
Copy Markdown
Collaborator

Summary

This PR includes three important updates to Konflux pipeline configurations and related tooling:

  1. Fix OPM image selection for OpenShift 5.x versions
  2. Update Go 1.26 builder image references
  3. Migrate from clair-scan to roxctl-scan (ACS)

Changes

1. Fix OPM Image Selection for OpenShift 5.x

Problem: OPM_IMAGE was incorrectly using openshift4 registry paths for OpenShift 5.0, resulting in non-existent image references.

Solution:

  • Refactored extractMinor() → extractMajorMinor() to handle both major and minor versions
  • Updated getOPMImage() to support version-specific registry paths:
    • OpenShift 4.x: registry.redhat.io/openshift4/ose-operator-registry-rhel9:v4.X
    • OpenShift 5.x: registry.redhat.io/openshift5/ose-operator-registry-rhel9:v5.X
  • Updated OLM migration flag check to only apply for OCP 4.17+

Files changed:

  • pkg/prowgen/prowgen_konflux.go

2. Update Go 1.26 Builder Image References

Problem: Go 1.26 configurations were using incorrect or outdated builder image references.

Solution:

  • Updated builder image mappings for Go 1.26
  • Ensured generated Dockerfiles use available and correct registry images
  • Fixed image tag references in configuration files

Files changed:

  • config/serverless-operator.yaml (if applicable)
  • Builder image configuration updates

3. Migrate from clair-scan to roxctl-scan (ACS)

Problem: clair-scan is being deprecated in favor of Red Hat Advanced Cluster Security (ACS) scanner.

Solution:

  • Replace clair-scan with roxctl-scan task in all pipeline templates
  • Update scanner bundle to quay.io/konflux-ci/tekton-catalog/task-roxctl-scan:0.1@sha256:97e2b2cdca9110fdc8a93ba585a1a1a743f989f2fd85f4073f6e5ea9ad2ce828
  • Add 20m timeout for roxctl-scan tasks
  • Keep same parameter structure (image-digest, image-url) for compatibility
  • Update all test fixtures and test expectations to match new scanner

Files changed:

  • pkg/konfluxgen/docker-build.yaml
  • pkg/konfluxgen/bundle-build.yaml
  • pkg/konfluxgen/docker-java-build.yaml
  • pkg/konfluxgen/kustomize/docker-build.yaml
  • pkg/konfluxgen/testdata/docker-build.yaml
  • pkg/konfluxgen/testdata/docker-build-expected.yaml
  • pkg/konfluxgen/konfluxgen_test.go

Affected pipelines:

  • docker-build
  • bundle-build
  • docker-java-build
  • kustomize/docker-build

Testing

  • Unit tests pass (go test ./pkg/prowgen/...)
  • Unit tests pass (go test ./pkg/konfluxgen/...)
  • OPM image correctly resolves for OpenShift 5.x
  • Go 1.26 builder images are correctly referenced
  • roxctl-scan task properly replaces clair-scan

Impact

After Merge:

  1. FBC applications for OpenShift 5.x will use correct OPM images
  2. Dockerfiles generated with Go 1.26 will reference valid builder images
  3. All Konflux pipelines will use the new ACS scanner instead of deprecated clair-scan
  4. Run make generate-ci to propagate changes to all managed repositories

Migration Notes

This PR aligns with the platform-level roadmap:

  • ✅ OpenShift 5.x support for OPM-based builds
  • ✅ Go 1.26 ecosystem readiness
  • ✅ Advanced Cluster Security (ACS) scanner adoption (clair-scan deprecation path)

Related

  • Platform migration from clair-scan to roxctl-scan (ACS)
  • OpenShift 5.x support initiative

Kaustubh-pande and others added 3 commits September 3, 2026 08:37
- Update extractMinor to extractMajorMinor to handle both major and minor
- Update getOPMImage to support OpenShift 5.x registry paths
- OpenShift 4.x: registry.redhat.io/openshift4/ose-operator-registry-rhel9:v4.X
- OpenShift 5.x: registry.redhat.io/openshift5/ose-operator-registry-rhel9:v5.X
- Update OLM migration flag check to only apply for OCP 4.17+

This fixes the issue where OPM_IMAGE was incorrectly using openshift4
registry for OpenShift 5.0 versions.

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
- Replace clair-scan with roxctl-scan task in all pipeline templates
- Update scanner bundle to quay.io/konflux-ci/tekton-catalog/task-roxctl-scan:0.1@sha256:97e2b2cdca9110fdc8a93ba585a1a1a743f989f2fd85f4073f6e5ea9ad2ce828
- Add 20m timeout for roxctl-scan tasks
- Keep same parameter structure (image-digest, image-url)
- Update test fixtures and test expectations to match new scanner

Files updated:
- pkg/konfluxgen/docker-build.yaml
- pkg/konfluxgen/bundle-build.yaml
- pkg/konfluxgen/docker-java-build.yaml
- pkg/konfluxgen/kustomize/docker-build.yaml
- pkg/konfluxgen/testdata/docker-build.yaml
- pkg/konfluxgen/testdata/docker-build-expected.yaml
- pkg/konfluxgen/konfluxgen_test.go

This migration aligns with the platform roadmap to deprecate clair-scan
in favor of Red Hat Advanced Cluster Security (ACS) scanner.

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
@openshift-ci
openshift-ci Bot requested review from creydr and matzew September 3, 2026 09:15
@openshift-ci openshift-ci Bot added the approved label Sep 3, 2026
Comment on lines -336 to 339
value: clair-scan
value: roxctl-scan
- name: bundle
value: quay.io/konflux-ci/tekton-catalog/task-clair-scan:0.3@sha256:f5b4415db9ac1fba3e11d993a617e0b275d1f0ed2fc669b12c400ed848c39174
value: quay.io/konflux-ci/tekton-catalog/task-roxctl-scan:0.1@sha256:97e2b2cdca9110fdc8a93ba585a1a1a743f989f2fd85f4073f6e5ea9ad2ce828
- name: kind

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I thought such changes should come form rendering newer docker-build pipeline, but... :)

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yeah, it gets updated across the repo through Konflux PAC, but our tool tries to override it because the old value is already present here.

@dsimansk

dsimansk commented Sep 3, 2026

Copy link
Copy Markdown
Contributor

Test data fix needed.

=== Failed
=== FAIL: cmd/generate TestGenerateMain (0.29s)
2026/09/03 09:16:14 Main package path: cmd/discover
2026/09/03 09:16:14 Use Default version substitution knative-v1.17 for main branch
2026/09/03 09:16:14 Dockerfile written: /tmp/TestGenerateMain3108750916/001/openshift/ci-operator/build-image/Dockerfile
2026/09/03 09:16:14 Dockerfile written: /tmp/TestGenerateMain3108750916/001/openshift/ci-operator/source-image/Dockerfile
2026/09/03 09:16:14 Dockerfile written: /tmp/TestGenerateMain3108750916/001/openshift/ci-operator/knative-images/discover/Dockerfile
2026/09/03 09:16:14 Additional image from hack knative.dev/eventing/cmd/foo bar
2026/09/03 09:16:14 Images mapping file written: /tmp/TestGenerateMain3108750916/001/openshift/images.yaml
    main_test.go:42: 
        	Error Trace:	/home/runner/work/hack/hack/cmd/generate/main_test.go:42
        	Error:      	Received unexpected error:
        	            	exit status 1
        	Test:       	TestGenerateMain
        	Messages:   	Output: %!(EXTRA string=diff --unified -r /home/runner/work/hack/hack/pkg/project/testoutput/openshift/ci-operator/build-image/Dockerfile /tmp/TestGenerateMain3108750916/001/openshift/ci-operator/build-image/Dockerfile
        	            	--- /home/runner/work/hack/hack/pkg/project/testoutput/openshift/ci-operator/build-image/Dockerfile	2026-09-03 09:15:53.292310979 +0000
        	            	+++ /tmp/TestGenerateMain3108750916/001/openshift/ci-operator/build-image/Dockerfile	2026-09-03 09:16:14.374110412 +0000
        	            	@@ -3,7 +3,7 @@
        	            	 FROM registry.ci.openshift.org/ocp/4.19:cli-artifacts as tools
        	            	 
        	            	 # Dockerfile to bootstrap build and test in openshift-ci
        	            	-FROM registry.ci.openshift.org/openshift/release:rhel-9-release-golang-1.26-openshift-4.22 as builder
        	            	+FROM registry.ci.openshift.org/openshift/release:rhel-9-release-golang-1.26-openshift-4.23 as builder
        	            	 
        	            	 ARG TARGETARCH
        	            	 
        	            	diff --unified -r /home/runner/work/hack/hack/pkg/project/testoutput/openshift/ci-operator/knative-images/discover/Dockerfile /tmp/TestGenerateMain3108750916/001/openshift/ci-operator/knative-images/discover/Dockerfile
        	            	--- /home/runner/work/hack/hack/pkg/project/testoutput/openshift/ci-operator/knative-images/discover/Dockerfile	2026-09-03 09:15:53.292420484 +0000
        	            	+++ /tmp/TestGenerateMain3108750916/001/openshift/ci-operator/knative-images/discover/Dockerfile	2026-09-03 09:16:14.375210882 +0000
        	            	@@ -1,5 +1,5 @@
        	            	 # DO NOT EDIT! Generated Dockerfile for cmd/discover.
        	            	-ARG GO_BUILDER=registry.ci.openshift.org/openshift/release:rhel-9-release-golang-1.26-openshift-4.22
        	            	+ARG GO_BUILDER=registry.ci.openshift.org/openshift/release:rhel-9-release-golang-1.26-openshift-4.23
        	            	 ARG GO_RUNTIME=registry.access.redhat.com/ubi9/ubi-minimal
        	            	 
        	            	 FROM $GO_BUILDER as builder
        	            	)

DONE 59 tests, 1 failure in 5.954s
=== Failed
=== FAIL: cmd/generate TestGenerateMain (0.29s)
2026/09/03 09:16:14 Main package path: cmd/discover
2026/09/03 09:16:14 Use Default version substitution knative-v1.17 for main branch
2026/09/03 09:16:14 Dockerfile written: /tmp/TestGenerateMain3108750916/001/openshift/ci-operator/build-image/Dockerfile
2026/09/03 09:16:14 Dockerfile written: /tmp/TestGenerateMain3108750916/001/openshift/ci-operator/source-image/Dockerfile
2026/09/03 09:16:14 Dockerfile written: /tmp/TestGenerateMain3108750916/001/openshift/ci-operator/knative-images/discover/Dockerfile
2026/09/03 09:16:14 Additional image from hack knative.dev/eventing/cmd/foo bar
2026/09/03 09:16:14 Images mapping file written: /tmp/TestGenerateMain3108750916/001/openshift/images.yaml
    main_test.go:42: 
        	Error Trace:	/home/runner/work/hack/hack/cmd/generate/main_test.go:42
        	Error:      	Received unexpected error:
        	            	exit status 1
        	Test:       	TestGenerateMain
        	Messages:   	Output: %!(EXTRA string=diff --unified -r /home/runner/work/hack/hack/pkg/project/testoutput/openshift/ci-operator/build-image/Dockerfile /tmp/TestGenerateMain3108750916/001/openshift/ci-operator/build-image/Dockerfile
        	            	--- /home/runner/work/hack/hack/pkg/project/testoutput/openshift/ci-operator/build-image/Dockerfile	2026-09-03 09:15:53.292310979 +0000
        	            	+++ /tmp/TestGenerateMain3108750916/001/openshift/ci-operator/build-image/Dockerfile	2026-09-03 09:16:14.374110412 +0000
        	            	@@ -3,7 +3,7 @@
        	            	 FROM registry.ci.openshift.org/ocp/4.19:cli-artifacts as tools
        	            	 
        	            	 # Dockerfile to bootstrap build and test in openshift-ci
        	            	-FROM registry.ci.openshift.org/openshift/release:rhel-9-release-golang-1.26-openshift-4.22 as builder
        	            	+FROM registry.ci.openshift.org/openshift/release:rhel-9-release-golang-1.26-openshift-4.23 as builder
        	            	 
        	            	 ARG TARGETARCH
        	            	 
        	            	diff --unified -r /home/runner/work/hack/hack/pkg/project/testoutput/openshift/ci-operator/knative-images/discover/Dockerfile /tmp/TestGenerateMain3108750916/001/openshift/ci-operator/knative-images/discover/Dockerfile
        	            	--- /home/runner/work/hack/hack/pkg/project/testoutput/openshift/ci-operator/knative-images/discover/Dockerfile	2026-09-03 09:15:53.292420484 +0000
        	            	+++ /tmp/TestGenerateMain3108750916/001/openshift/ci-operator/knative-images/discover/Dockerfile	2026-09-03 09:16:14.375210882 +0000
        	            	@@ -1,5 +1,5 @@
        	            	 # DO NOT EDIT! Generated Dockerfile for cmd/discover.
        	            	-ARG GO_BUILDER=registry.ci.openshift.org/openshift/release:rhel-9-release-golang-1.26-openshift-4.22
        	            	+ARG GO_BUILDER=registry.ci.openshift.org/openshift/release:rhel-9-release-golang-1.26-openshift-4.23
        	            	 ARG GO_RUNTIME=registry.access.redhat.com/ubi9/ubi-minimal
        	            	 
        	            	 FROM $GO_BUILDER as builder
        	            	)

DONE 59 tests, 1 failure in 5.954s

Go 1.26 images are only available starting from OpenShift 4.23,
not 4.22. Update test fixtures to match the correct version.

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
@dsimansk

dsimansk commented Sep 3, 2026

Copy link
Copy Markdown
Contributor

/approve
/lgtm

for tests
/hold

@openshift-ci

openshift-ci Bot commented Sep 3, 2026

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: dsimansk, Kaustubh-pande

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:
  • OWNERS [Kaustubh-pande,dsimansk]

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@Kaustubh-pande

Copy link
Copy Markdown
Collaborator Author

/unhold

@openshift-merge-bot
openshift-merge-bot Bot merged commit 84ead71 into openshift-knative:main Sep 3, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants