Repository navigation
OSAC-4909: Reflect vault provisioning failures in tenant status - #879
jira-autofix[bot] wants to merge 4 commits into
Conversation
|
@jira-autofix[bot]: This pull request references OSAC-4909 which is a valid jira issue. Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the bug to target the "5.1.0" version, but no target version was set. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
🧭 E2E Suite Selection (POC, informational only)
AI judgment confidence: 100%. This comment is informational only; nothing is gated on it yet. |
b320617 to
5f90594
Compare
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Comment |
|
/lgtm |
E2E on
|
|
/e2e-ready |
5f90594 to
8a0295f
Compare
|
/ok-to-test |
|
Labeled |
|
⏳ E2E BMaaS Full Install -- Running ⏳ E2E VMaaS Full Install -- Running ⏳ E2E CaaS Full Install -- Running Total AI diagnostic cost for this PR: $0.2572 (70015 input + 9768 output tokens across 3 diagnoses) |
|
Labeled |
E2E on
|
🧭 Jobs Selection (informational only)E2E Suites
AI judgment confidence: 80%. Unit Tests
Integration Tests
Helm Lint
Checks & Builds
Every table above is informational only -- nothing here gates whether a job actually runs. The E2E Suites table can use AI judgment for ambiguous files; every other table is deterministic-only (no AI). |
When ensureVaultNamespace fails (e.g. OpenBAO is unreachable), the error was propagated up causing Run() to return before persisting the tenant status update. This left the tenant stuck in PENDING/SYNCED with no indication of failure. Now ensureVaultNamespace sets the tenant state to FAILED with a descriptive message, updates the VaultReady condition to FALSE with reason ProvisionFailed, and returns nil so the status is persisted. This follows the same pattern used for CreateTenant failures. In syncToIDP, an early return after ensureVaultNamespace prevents subsequent code from overwriting the FAILED state with SYNCED. Assisted-by: Claude claude-opus-4-6 <noreply@anthropic.com> Signed-off-by: aipcc-bot <aipcc-bot@redhat.com>
Add missing FAILED-state guard after ensureVaultNamespace in the SYNCED tenant path of update(), consistent with the existing guards after updateIDP and in syncToIDP. Without this guard, checkDefaultNetworkingReadiness would run after a vault provisioning failure, making unnecessary API calls and potentially returning errors that mask the FAILED state. Assisted-by: Claude claude-opus-4-6 <noreply@anthropic.com>
|
Removed |
|
/ok-to-test |
|
/approve |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: CrystalChun, jira-autofix[bot] The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
|
Labeled |
E2E on
|
|
New changes are detected. LGTM label has been removed. |
|
Removed |
|
/e2e-ready |
|
Labeled |
E2E on
|
|
/close superseded by #1498 |
|
@CrystalChun: Closed this PR. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
Problem
When
ensureVaultNamespacefails (e.g., OpenBAO is unreachable), the error propagated up toRun()which returned before callingTenants/Update. This left the tenant stuck inPENDINGorSYNCEDstate with no indication of failure, causing an infinite retry loop with no user-visible status change.Fix
Modified
ensureVaultNamespaceto handle errors by:TENANT_STATE_FAILEDwith a descriptive messageVaultReadycondition toFALSEwith reasonProvisionFailednilinstead of the error, so the status update is persistedAdded early return guards after the
ensureVaultNamespacecall in both:syncToIDP— preventspersistBreakGlassSecretand subsequent operations from overwriting theFAILEDstate withSYNCEDupdate(SYNCED path) — preventscheckDefaultNetworkingReadinessfrom running after a vault failureThis follows the same error-handling pattern used for
CreateTenantfailures.Tests
Added two test cases to the "Vault namespace provisioning" suite: