Update Konflux pipelines: Fix OPM for OCP 5.x, update Go 1.26 builder, migrate to roxctl-scan - #1008
Merged
openshift-merge-bot[bot] merged 4 commits intoSep 3, 2026
Conversation
- Update extractMinor to extractMajorMinor to handle both major and minor - Update getOPMImage to support OpenShift 5.x registry paths - OpenShift 4.x: registry.redhat.io/openshift4/ose-operator-registry-rhel9:v4.X - OpenShift 5.x: registry.redhat.io/openshift5/ose-operator-registry-rhel9:v5.X - Update OLM migration flag check to only apply for OCP 4.17+ This fixes the issue where OPM_IMAGE was incorrectly using openshift4 registry for OpenShift 5.0 versions. Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
- Replace clair-scan with roxctl-scan task in all pipeline templates - Update scanner bundle to quay.io/konflux-ci/tekton-catalog/task-roxctl-scan:0.1@sha256:97e2b2cdca9110fdc8a93ba585a1a1a743f989f2fd85f4073f6e5ea9ad2ce828 - Add 20m timeout for roxctl-scan tasks - Keep same parameter structure (image-digest, image-url) - Update test fixtures and test expectations to match new scanner Files updated: - pkg/konfluxgen/docker-build.yaml - pkg/konfluxgen/bundle-build.yaml - pkg/konfluxgen/docker-java-build.yaml - pkg/konfluxgen/kustomize/docker-build.yaml - pkg/konfluxgen/testdata/docker-build.yaml - pkg/konfluxgen/testdata/docker-build-expected.yaml - pkg/konfluxgen/konfluxgen_test.go This migration aligns with the platform roadmap to deprecate clair-scan in favor of Red Hat Advanced Cluster Security (ACS) scanner. Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
dsimansk
reviewed
Sep 3, 2026
Comment on lines
-336
to
339
| value: clair-scan | ||
| value: roxctl-scan | ||
| - name: bundle | ||
| value: quay.io/konflux-ci/tekton-catalog/task-clair-scan:0.3@sha256:f5b4415db9ac1fba3e11d993a617e0b275d1f0ed2fc669b12c400ed848c39174 | ||
| value: quay.io/konflux-ci/tekton-catalog/task-roxctl-scan:0.1@sha256:97e2b2cdca9110fdc8a93ba585a1a1a743f989f2fd85f4073f6e5ea9ad2ce828 | ||
| - name: kind |
Contributor
There was a problem hiding this comment.
I thought such changes should come form rendering newer docker-build pipeline, but... :)
Collaborator
Author
There was a problem hiding this comment.
Yeah, it gets updated across the repo through Konflux PAC, but our tool tries to override it because the old value is already present here.
Contributor
|
Test data fix needed. |
Go 1.26 images are only available starting from OpenShift 4.23, not 4.22. Update test fixtures to match the correct version. Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
Contributor
|
/approve for tests |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: dsimansk, Kaustubh-pande The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
Collaborator
Author
|
/unhold |
openshift-merge-bot
Bot
merged commit Sep 3, 2026
84ead71
into
openshift-knative:main
4 checks passed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This PR includes three important updates to Konflux pipeline configurations and related tooling:
Changes
1. Fix OPM Image Selection for OpenShift 5.x
Problem: OPM_IMAGE was incorrectly using
openshift4registry paths for OpenShift 5.0, resulting in non-existent image references.Solution:
extractMinor()→extractMajorMinor()to handle both major and minor versionsgetOPMImage()to support version-specific registry paths:registry.redhat.io/openshift4/ose-operator-registry-rhel9:v4.Xregistry.redhat.io/openshift5/ose-operator-registry-rhel9:v5.XFiles changed:
pkg/prowgen/prowgen_konflux.go2. Update Go 1.26 Builder Image References
Problem: Go 1.26 configurations were using incorrect or outdated builder image references.
Solution:
Files changed:
config/serverless-operator.yaml(if applicable)3. Migrate from clair-scan to roxctl-scan (ACS)
Problem: clair-scan is being deprecated in favor of Red Hat Advanced Cluster Security (ACS) scanner.
Solution:
quay.io/konflux-ci/tekton-catalog/task-roxctl-scan:0.1@sha256:97e2b2cdca9110fdc8a93ba585a1a1a743f989f2fd85f4073f6e5ea9ad2ce828image-digest,image-url) for compatibilityFiles changed:
pkg/konfluxgen/docker-build.yamlpkg/konfluxgen/bundle-build.yamlpkg/konfluxgen/docker-java-build.yamlpkg/konfluxgen/kustomize/docker-build.yamlpkg/konfluxgen/testdata/docker-build.yamlpkg/konfluxgen/testdata/docker-build-expected.yamlpkg/konfluxgen/konfluxgen_test.goAffected pipelines:
Testing
go test ./pkg/prowgen/...)go test ./pkg/konfluxgen/...)Impact
After Merge:
make generate-cito propagate changes to all managed repositoriesMigration Notes
This PR aligns with the platform-level roadmap:
Related