Skip to content

[ARO-22145] Bump to Azure Linux 3.0#4766

Open
rhamitarora wants to merge 27 commits intomasterfrom
rhamitarora/ARO-22145-azure-linux3
Open

[ARO-22145] Bump to Azure Linux 3.0#4766
rhamitarora wants to merge 27 commits intomasterfrom
rhamitarora/ARO-22145-azure-linux3

Conversation

@rhamitarora
Copy link
Copy Markdown
Collaborator

@rhamitarora rhamitarora commented Apr 13, 2026

Which issue this PR addresses:

Fixes ARO-22145 — Migrate Azure Red Hat OpenShift RP/Gateway VMSS from Azure Linux 2.0 (EOL July 31, 2025) to Azure Linux 3.0.

What this PR does / why we need it:

  • Switching VMSS base images from CBL-Mariner 2.0 to Azure Linux 3.0 FIPS
  • Updating Dockerfiles to use azurelinux base images instead of mariner
  • Adding podman 5.x dependencies (crun, netavark) required on Azure Linux 3
  • Removing the iptables firewalld backend switch (Azure Linux 3 uses nftables natively)
  • Updating fluentbit build for Azure Linux 3 compatibility
  • Bumping e2e and CI pipeline resources to Azure Linux 3
  • Adding the Azure Linux extended repo for additional package availability

Test plan for issue:

Verify RP and Gateway VMSS boot and run successfully on Azure Linux 3 FIPS images

Is there any documentation that needs to be updated for this PR?

How do you know this will function as expected in production?

INT and Canary Testing
Refer attached screen-shots from https://redhat.atlassian.net/browse/ARO-22197

@openshift-ci
Copy link
Copy Markdown

openshift-ci Bot commented Apr 13, 2026

Skipping CI for Draft Pull Request.
If you want CI signal for your change, please convert it to an actual PR.
You can still manually trigger a test run with /test all

@rhamitarora rhamitarora force-pushed the rhamitarora/ARO-22145-azure-linux3 branch from 273c839 to d499bc1 Compare April 13, 2026 02:54
@rhamitarora rhamitarora changed the title azure linux3 [ARO-22145] Bump to Azure Linux 3.0 Apr 13, 2026
@github-actions
Copy link
Copy Markdown

Please rebase pull request.

1 similar comment
@github-actions
Copy link
Copy Markdown

Please rebase pull request.

@github-actions github-actions Bot added the needs-rebase branch needs a rebase label Apr 13, 2026
@rhamitarora rhamitarora force-pushed the rhamitarora/ARO-22145-azure-linux3 branch from d499bc1 to 454c1c8 Compare April 20, 2026 12:40
@github-actions github-actions Bot removed the needs-rebase branch needs a rebase label Apr 20, 2026
@rhamitarora rhamitarora marked this pull request as ready for review April 20, 2026 16:05
Copilot AI review requested due to automatic review settings April 20, 2026 16:05
@rhamitarora rhamitarora added the priority-medium Medium priority issue or pull request label Apr 20, 2026
hawkowl and others added 27 commits May 7, 2026 17:13
Podman 5.x on Azure Linux 3 requires crun (OCI runtime), netavark
(network stack), and aardvark-dns explicitly installed. Without these,
az acr login fails with "could not find netavark" on RP and gateway VMSS.

Made-with: Cursor
aardvark-dns is not a separate package in Azure Linux 3 repos.
DNS functionality is bundled with netavark on this platform.

Made-with: Cursor
On Azure Linux 3, nftables is the default and native firewall backend.
Forcing iptables causes firewalld to crash with a DBus NoReply error
because the iptables backend is not functional on this platform.

Made-with: Cursor
…ackages

- Use block list for nginx command in route/loadbalancer e2e manifests
- Rename dnf_*_pkgs to tdnf_*_pkgs and use tdnf consistently with extended repo
- Regenerate gateway and rp production deploy assets

Made-with: Cursor
Add a file-level comment to util-packages.sh clarifying that the RP and
gateway VMSS bootstrap uses tdnf exclusively (extended repo, update, and
install), consistent with the dev-env Azure Linux migration in PR #4777.

Made-with: Cursor
…red gallery

The Mariner 2 FIPS marketplace SKU was absent from the platform-image
allowlist for VMSS Automatic OS Upgrades, so ARO used the non-FIPS image
and configured FIPS manually at boot. Azure Linux 3 FIPS is referenced
via the 1P Shared Gallery, which uses the gallery-based automatic upgrade
path and is not subject to that allowlist restriction.

Addresses reviewer question from PR #4777.

Made-with: Cursor
Switch configure_repo_azurelinux_extended to use dnf instead of tdnf,
and update the default argument fallback from 1 to empty string.

Made-with: Cursor
- Replace dnf with tdnf in configure_repo_azurelinux_extended in
  util-packages.sh to prevent VMSS bootstrapping failure on Azure
  Linux 3 where dnf is not present
- Replace yum with tdnf in devProxyVMSS.sh weekly cron job to prevent
  silent failures; rename cron file from yumupdate to tdnfupdate
- Regenerate assets after changes

Made-with: Cursor
Remove unused get_boot_dev_uuid after grub-based FIPS configure removal.
Use repo_retry_count=5 for extended-repo enablement; keep pkg_retry_count=60
for tdnf update/install. Regenerate production assets (make generate).

Co-authored-by: Cursor <cursoragent@cursor.com>
Use direct bash array appends in tdnf install/update helpers so package and exclude flags are passed as clean argv elements without mapfile parsing side effects.

Co-authored-by: Cursor <cursoragent@cursor.com>
Ensure VMSS package updates call tdnf with the update subcommand before -x exclusions so WALinuxAgent exclusions are parsed correctly, then regenerate deployment assets.

Co-authored-by: Cursor <cursoragent@cursor.com>
@rhamitarora rhamitarora force-pushed the rhamitarora/ARO-22145-azure-linux3 branch from 076db1f to 411eb59 Compare May 7, 2026 13:17
@github-actions github-actions Bot added the needs-rebase branch needs a rebase label May 8, 2026
@github-actions
Copy link
Copy Markdown

github-actions Bot commented May 8, 2026

Please rebase pull request.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

firefly Issues or Pull requests owned by Team Firefly go Pull requests that update Go code needs-rebase branch needs a rebase priority-medium Medium priority issue or pull request python Pull requests that update python code skippy pull requests raised by member of Team Skippy

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants