Skip to content

OCPBUGS-123649: enable DRADeviceTaintRules feature gate in TPNU - #3072

Open
haircommander wants to merge 1 commit into
openshift:masterfrom
haircommander:device-taint-enable
Open

haircommander wants to merge 1 commit into
openshift:masterfrom
haircommander:device-taint-enable

Conversation

@haircommander

Copy link
Copy Markdown
Member

No description provided.

@openshift-ci-robot openshift-ci-robot added jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. jira/valid-bug Indicates that a referenced Jira bug is valid for the branch this PR is targeting. labels Oct 1, 2026
@openshift-ci

openshift-ci Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Hello @haircommander! Some important instructions when contributing to openshift/api:
API design plays an important part in the user experience of OpenShift and as such API PRs are subject to a high level of scrutiny to ensure they follow our best practices. If you haven't already done so, please review the OpenShift API Conventions and ensure that your proposed changes are compliant. Following these conventions will help expedite the api review process for your PR.

@openshift-ci-robot

Copy link
Copy Markdown

@haircommander: This pull request references Jira Issue OCPBUGS-123649, which is valid.

3 validation(s) were run on this bug
  • bug is open, matching expected state (open)
  • bug target version (5.1.0) matches configured target version for branch (5.1.0)
  • bug is in the state POST, which is one of the valid states (NEW, ASSIGNED, POST)

The bug has been updated to refer to the pull request using the external bug tracker.

Details

In response to this:

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

Pipeline controller notification
This repo is configured to use the pipeline controller. Second-stage tests will be triggered either automatically or after lgtm label is added, depending on the repository configuration. The pipeline controller will automatically detect which contexts are required and will utilize /test Prow commands to trigger the second stage.

For optional jobs, comment /test ? to see a list of all defined jobs. To trigger manually all jobs from second stage use /pipeline required command.

This repository is configured in: LGTM mode

@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository YAML (base), Central YAML (inherited)
  • Review profile: CHILL
  • Plan: Enterprise
  • Run ID: 7b67402e-220f-4d8a-ad9d-9bbca70289a5
📥 Commits

Reviewing files that changed from the base of the PR and between 11d2283 and 4406402.

📒 Files selected for processing (8)
  • features.md
  • features/features.go
  • payload-manifests/featuregates/featureGate-4-10-Hypershift-DevPreviewNoUpgrade.yaml
  • payload-manifests/featuregates/featureGate-4-10-Hypershift-TechPreviewNoUpgrade.yaml
  • payload-manifests/featuregates/featureGate-4-SelfManagedHA-DevPreviewNoUpgrade.yaml
  • payload-manifests/featuregates/featureGate-4-SelfManagedHA-TechPreviewNoUpgrade.yaml
  • payload-manifests/featuregates/featureGate-5-10-SelfManagedHA-DevPreviewNoUpgrade.yaml
  • payload-manifests/featuregates/featureGate-5-10-SelfManagedHA-TechPreviewNoUpgrade.yaml
🚧 Files skipped from review as they are similar to previous changes (1)
  • features.md

Included review availability: This review used your included allowance. Your plan provides up to 12 included reviews per hour; 11 remain after this review.


📝 Walkthrough

Walkthrough

DRADeviceTaintRules is configured as enabled in DevPreviewNoUpgrade and TechPreviewNoUpgrade for Hypershift and SelfManagedHA. The feature declaration, payload manifests, and feature table reflect this configuration.

Suggested reviewers: joelanford

Priority: ⬇️ Low

Merge Risk: ⚪ Minimal · up to 44064

The reviewed changes enable DRADeviceTaintRules in the listed preview configurations; no actionable merge-blocking risk is evident.

🚥 Pre-merge checks | ✅ 14 | ❓ 1

❌ Failed checks (1 inconclusive)

Check name Status Explanation Resolution
Description check ❓ Inconclusive No pull request description was provided, so its relevance to the changeset cannot be assessed. Add a brief description that explains the DRADeviceTaintRules feature-gate changes.
✅ Passed checks (14 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly identifies the main change: enabling the DRADeviceTaintRules feature gate in TPNU.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 1…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Stable And Deterministic Test Names ✅ Passed The pull request changes feature-gate registration, documentation, and YAML manifests. The diff adds or removes no Ginkgo test titles, so it introduces no unstable or overly specific test names.
Test Structure And Quality ✅ Passed This check is not applicable to the pull request. The reviewed diff changes feature-gate documentation, feature-gate configuration, and generated FeatureGate manifests. It does not change Ginkgo test …
Microshift Test Compatibility ✅ Passed No new Ginkgo tests were added. The pull request changes only feature-gate documentation, registration, and manifests; the MicroShift test-compatibility check does not apply.
Single Node Openshift (Sno) Test Compatibility ✅ Passed The pull request changes only feature-gate documentation, registration, and YAML manifests. It adds or modifies no Ginkgo e2e tests, so the SNO test-compatibility check does not apply.
Topology-Aware Scheduling Compatibility ✅ Passed The pull request only enables DRADeviceTaintRules in the feature-gate registry and in TechPreviewNoUpgrade/DevPreviewNoUpgrade FeatureGate manifests. The changed manifests are `config.openshift.io/v…
Ote Binary Stdout Contract ✅ Passed PASS. The pull request changes only feature-gate registration, feature-gate manifests, and features.md. It does not modify OTE binary process-level code or introduce stdout writes in main, suite s…
Ipv6 And Disconnected Network Test Compatibility ✅ Passed The pull request changes only feature-gate declarations, documentation, and feature-gate manifests. The authoritative diff adds or moves no Ginkgo e2e tests, so this check does not apply.
No-Weak-Crypto ✅ Passed The check passes. The reviewed diff only enables the DRADeviceTaintRules feature gate in feature metadata, Go registration, and six feature-gate manifests. No weak-crypto primitive, custom crypto impl…
Container-Privileges ✅ Passed The pull request changes feature-gate registration, documentation, and six FeatureGate manifests. The manifest diffs only move DRADeviceTaintRules from disabled to enabled. No changed lines set pr…
No-Sensitive-Data-In-Logs ✅ Passed The changes only update feature-gate registration and feature-gate tables/manifests. The diff adds no logging behavior or sensitive data, so it does not introduce the stated logging risk.
✨ Finishing Touches 💡 1
🧪 Generate unit tests (beta)
  • Create a new PR
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR

Warning

Some tools did not complete. Review the errors below.

🔧 golangci-lint (2.13.2)

Error: build linters: unable to load custom analyzer "kubeapilinter": tools/_output/bin/kube-api-linter.so, plugin: not implemented
The command is terminated due to an error: build linters: unable to load custom analyzer "kubeapilinter": tools/_output/bin/kube-api-linter.so, plugin: not implemented


Comment @coderabbitai help to get the list of available commands.

@openshift-ci openshift-ci Bot added the size/S Denotes a PR that changes 10-29 lines, ignoring generated files. label Oct 1, 2026
@haircommander

Copy link
Copy Markdown
Member Author

will require openshift/origin#31566 to pass tests, waiting to trigger them for that to merge

Comment thread features/features.go Outdated
contactPerson("haircommander").
productScope(kubernetes).
enhancementPR("https://github.com/kubernetes/enhancements/issues/5055").
enable(inTechPreviewNoUpgrade()).

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Also needs DevPreviewNoUpgrade

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

whoops, done!

@openshift-ci openshift-ci Bot added size/M Denotes a PR that changes 30-99 lines, ignoring generated files. and removed size/S Denotes a PR that changes 10-29 lines, ignoring generated files. labels Oct 2, 2026
@haircommander

Copy link
Copy Markdown
Member Author

/pipeline required

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

Scheduling tests matching the pipeline_run_if_changed or not excluded by pipeline_skip_if_only_changed parameters:
/test e2e-aws-ovn
/test e2e-aws-ovn-hypershift
/test e2e-aws-ovn-hypershift-conformance
/test e2e-aws-ovn-techpreview
/test e2e-aws-serial-1of2
/test e2e-aws-serial-2of2
/test e2e-aws-serial-techpreview-1of2
/test e2e-aws-serial-techpreview-2of2
/test e2e-azure
/test e2e-gcp
/test e2e-upgrade
/test e2e-upgrade-out-of-change
/test minor-e2e-upgrade-minor

@haircommander

Copy link
Copy Markdown
Member Author

/retest

@JoelSpeed

Copy link
Copy Markdown
Contributor

/lgtm
/retest

@openshift-ci openshift-ci Bot added the lgtm Indicates that a PR is ready to be merged. label Oct 5, 2026
@openshift-merge-bot

Copy link
Copy Markdown
Contributor

Scheduling tests matching the pipeline_run_if_changed or not excluded by pipeline_skip_if_only_changed parameters:
/test e2e-aws-ovn-hypershift
/test e2e-aws-serial-1of2
/test e2e-aws-serial-2of2
/test e2e-aws-serial-techpreview-1of2
/test e2e-aws-serial-techpreview-2of2
/test e2e-upgrade
/test e2e-upgrade-out-of-change
/test minor-e2e-upgrade-minor

@openshift-ci

openshift-ci Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: JoelSpeed

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci openshift-ci Bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Oct 5, 2026
Signed-off-by: Peter Hunt <pehunt@redhat.com>
@openshift-ci openshift-ci Bot removed the lgtm Indicates that a PR is ready to be merged. label Oct 6, 2026
@openshift-ci

openshift-ci Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

New changes are detected. LGTM label has been removed.

@haircommander

Copy link
Copy Markdown
Member Author

/pipeline required

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

Scheduling tests matching the pipeline_run_if_changed or not excluded by pipeline_skip_if_only_changed parameters:
/test e2e-aws-ovn
/test e2e-aws-ovn-hypershift
/test e2e-aws-ovn-hypershift-conformance
/test e2e-aws-ovn-techpreview
/test e2e-aws-serial-1of2
/test e2e-aws-serial-2of2
/test e2e-aws-serial-techpreview-1of2
/test e2e-aws-serial-techpreview-2of2
/test e2e-azure
/test e2e-gcp
/test e2e-upgrade
/test e2e-upgrade-out-of-change
/test minor-e2e-upgrade-minor

@redhat-chai-bot

Copy link
Copy Markdown
Contributor

/override-sticky ci/prow/e2e-upgrade-out-of-change

Automated risk analysis: The failure is an isolated AWS load-balancer/network interruption, not a failure of the PR's feature-gate change.

Job classification: Eligible cluster-installing AWS upgrade e2e job (openshift-upgrade-aws).
Revision check: Run 440640204e45b06c772501dea90beb5cf3ede614; live PR HEAD 440640204e45b06c772501dea90beb5cf3ede614; match.
Execution status: The upgrade e2e suite ran. The exact failing check was [Monitor:service-type-load-balancer-availability][Jira:"Networking / router"] monitor test service-type-load-balancer-availability preparation; the LB readiness probe timed out. The same log recorded repeated aws-network-liveness 503 responses (Back-end server is at capacity).
Completed supporting jobs: ci/prow/e2e-upgrade, ci/prow/minor-e2e-upgrade-minor, ci/prow/e2e-aws-ovn, and both AWS TechPreview serial shards passed on this SHA. tide remains pending.
Fleet-wide failure rate: Job pass rate 65.38% (17/26 in the 14-day window). The exact monitor test is 99.18% passing in the current openshift-tests report (1,695/1,709) and 99.56% in the openshift-tests-upgrade report (1,130/1,135); an AWS-only test denominator was not available in the returned test report.
Open regressions: None found for the exact preparation test; the Sippy test report lists open_bugs: 0.
Linked bugs: None found for the exact failure.
Overlap assessment: None. The test is AWS load-balancer availability preparation; the PR changes feature-gate eligibility for no-upgrade preview feature sets, not AWS load-balancer/network code.
Missing-coverage risk: Low for the PR change. The upgrade suite completed except for this monitor preparation check, and the separate AWS upgrade and TechPreview checks passed on the same SHA.
Prior bot activity on this SHA: One /test e2e-upgrade-out-of-change was issued at 2026-10-06 17:11:45 UTC; this is that run. No prior override.
Decision and rationale: Override. The run log directly records a timed-out LB readiness probe alongside repeated AWS network-liveness 503s, and there is no overlap with the changed feature-gate data.

If you disagree with this assessment, rerun the current job with /test e2e-upgrade-out-of-change.


AI-generated. Review for accuracy.

@redhat-chai-bot

Copy link
Copy Markdown
Contributor

/override-sticky ci/prow/e2e-gcp

Automated risk analysis: The GCP bootstrap failure is supported by matching, open Component Readiness regressions and is not evidence against this PR's TechPreview feature-gate change.

Job classification: Eligible cluster-installing e2e job (openshift-e2e-gcp, GCP profile).
Revision check: Run 440640204e45b06c772501dea90beb5cf3ede614; live PR HEAD 440640204e45b06c772501dea90beb5cf3ede614; match.
Execution status: The installer bootstrap check install should succeed: cluster bootstrap failed during ipi-install-install with a bootstrap timeout. The post-install openshift-e2e-test suite did not run.
Completed supporting jobs: ci/prow/e2e-aws-ovn, ci/prow/e2e-azure, ci/prow/e2e-aws-serial-techpreview-1of2, ci/prow/e2e-aws-serial-techpreview-2of2, and ci/prow/e2e-upgrade passed on this SHA. No successful GCP e2e job; tide remains pending.
Fleet-wide failure rate: Job pass rate 50.00% (15/30 in the 14-day window). install should succeed: cluster bootstrap: 94.36% global (3,595/3,810); 90.2% GCP (643/713).
Open regressions: Open GCP bootstrap regressions for the same exact check include 50330 (default), 50259 (default/minor upgrade), 50258 (TechPreview), and 50411 (default/serial). The PR's e2e-gcp job uses the default feature set; the PR changes only TechPreviewNoUpgrade and DevPreviewNoUpgrade feature-gate data.
Linked bugs: No active Jira bug was validated as a match for this GCP failure. The open evidence is the platform-specific regression data above.
Overlap assessment: None for the observed default-feature-set bootstrap failure; the changed feature-set manifests are limited to the no-upgrade preview feature sets.
Missing-coverage risk: No installed-cluster GCP e2e coverage was obtained. Risk to this PR's changed surface is low because the failed job used the unchanged default feature set and the same-SHA TechPreview serial jobs passed.
Prior bot activity on this SHA: One /test e2e-gcp was issued at 2026-10-06 17:11:45 UTC; this is that run. No prior override.
Decision and rationale: Override. The named bootstrap check has matching open GCP Component Readiness regressions, and this job's default FeatureSet does not include the feature-set change in the PR.

If you disagree with this assessment, rerun the current job with /test e2e-gcp.


AI-generated. Review for accuracy.

@openshift-ci

openshift-ci Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

@redhat-chai-bot: Overrode contexts on behalf of redhat-chai-bot: ci/prow/e2e-upgrade-out-of-change

These overrides will persist across retests on the current HEAD SHA. Pushing a new commit will clear them. Use /override-cancel to remove them.

Details

In response to this:

/override-sticky ci/prow/e2e-upgrade-out-of-change

Automated risk analysis: The failure is an isolated AWS load-balancer/network interruption, not a failure of the PR's feature-gate change.

Job classification: Eligible cluster-installing AWS upgrade e2e job (openshift-upgrade-aws).
Revision check: Run 440640204e45b06c772501dea90beb5cf3ede614; live PR HEAD 440640204e45b06c772501dea90beb5cf3ede614; match.
Execution status: The upgrade e2e suite ran. The exact failing check was [Monitor:service-type-load-balancer-availability][Jira:"Networking / router"] monitor test service-type-load-balancer-availability preparation; the LB readiness probe timed out. The same log recorded repeated aws-network-liveness 503 responses (Back-end server is at capacity).
Completed supporting jobs: ci/prow/e2e-upgrade, ci/prow/minor-e2e-upgrade-minor, ci/prow/e2e-aws-ovn, and both AWS TechPreview serial shards passed on this SHA. tide remains pending.
Fleet-wide failure rate: Job pass rate 65.38% (17/26 in the 14-day window). The exact monitor test is 99.18% passing in the current openshift-tests report (1,695/1,709) and 99.56% in the openshift-tests-upgrade report (1,130/1,135); an AWS-only test denominator was not available in the returned test report.
Open regressions: None found for the exact preparation test; the Sippy test report lists open_bugs: 0.
Linked bugs: None found for the exact failure.
Overlap assessment: None. The test is AWS load-balancer availability preparation; the PR changes feature-gate eligibility for no-upgrade preview feature sets, not AWS load-balancer/network code.
Missing-coverage risk: Low for the PR change. The upgrade suite completed except for this monitor preparation check, and the separate AWS upgrade and TechPreview checks passed on the same SHA.
Prior bot activity on this SHA: One /test e2e-upgrade-out-of-change was issued at 2026-10-06 17:11:45 UTC; this is that run. No prior override.
Decision and rationale: Override. The run log directly records a timed-out LB readiness probe alongside repeated AWS network-liveness 503s, and there is no overlap with the changed feature-gate data.

If you disagree with this assessment, rerun the current job with /test e2e-upgrade-out-of-change.


AI-generated. Review for accuracy.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@openshift-ci

openshift-ci Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

@redhat-chai-bot: Overrode contexts on behalf of redhat-chai-bot: ci/prow/e2e-gcp

These overrides will persist across retests on the current HEAD SHA. Pushing a new commit will clear them. Use /override-cancel to remove them.

Details

In response to this:

/override-sticky ci/prow/e2e-gcp

Automated risk analysis: The GCP bootstrap failure is supported by matching, open Component Readiness regressions and is not evidence against this PR's TechPreview feature-gate change.

Job classification: Eligible cluster-installing e2e job (openshift-e2e-gcp, GCP profile).
Revision check: Run 440640204e45b06c772501dea90beb5cf3ede614; live PR HEAD 440640204e45b06c772501dea90beb5cf3ede614; match.
Execution status: The installer bootstrap check install should succeed: cluster bootstrap failed during ipi-install-install with a bootstrap timeout. The post-install openshift-e2e-test suite did not run.
Completed supporting jobs: ci/prow/e2e-aws-ovn, ci/prow/e2e-azure, ci/prow/e2e-aws-serial-techpreview-1of2, ci/prow/e2e-aws-serial-techpreview-2of2, and ci/prow/e2e-upgrade passed on this SHA. No successful GCP e2e job; tide remains pending.
Fleet-wide failure rate: Job pass rate 50.00% (15/30 in the 14-day window). install should succeed: cluster bootstrap: 94.36% global (3,595/3,810); 90.2% GCP (643/713).
Open regressions: Open GCP bootstrap regressions for the same exact check include 50330 (default), 50259 (default/minor upgrade), 50258 (TechPreview), and 50411 (default/serial). The PR's e2e-gcp job uses the default feature set; the PR changes only TechPreviewNoUpgrade and DevPreviewNoUpgrade feature-gate data.
Linked bugs: No active Jira bug was validated as a match for this GCP failure. The open evidence is the platform-specific regression data above.
Overlap assessment: None for the observed default-feature-set bootstrap failure; the changed feature-set manifests are limited to the no-upgrade preview feature sets.
Missing-coverage risk: No installed-cluster GCP e2e coverage was obtained. Risk to this PR's changed surface is low because the failed job used the unchanged default feature set and the same-SHA TechPreview serial jobs passed.
Prior bot activity on this SHA: One /test e2e-gcp was issued at 2026-10-06 17:11:45 UTC; this is that run. No prior override.
Decision and rationale: Override. The named bootstrap check has matching open GCP Component Readiness regressions, and this job's default FeatureSet does not include the feature-set change in the PR.

If you disagree with this assessment, rerun the current job with /test e2e-gcp.


AI-generated. Review for accuracy.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@openshift-ci

openshift-ci Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

@haircommander: The following tests failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test name Commit Details Required Rerun command
ci/prow/e2e-aws-ovn-techpreview 4406402 link true /test e2e-aws-ovn-techpreview
ci/prow/e2e-aws-ovn-hypershift 4406402 link true /test e2e-aws-ovn-hypershift

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. jira/valid-bug Indicates that a referenced Jira bug is valid for the branch this PR is targeting. jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. size/M Denotes a PR that changes 30-99 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants