Skip to content

chore: pull PCO E2E from correct branch - #586

Merged
JasonPowr merged 1 commit into
mainfrom
pull-pco-e2e-from-correct-branch
Aug 6, 2026
Merged

chore: pull PCO E2E from correct branch#586
JasonPowr merged 1 commit into
mainfrom
pull-pco-e2e-from-correct-branch

Conversation

@JasonPowr

Copy link
Copy Markdown
Member

No description provided.

@github-actions

github-actions Bot commented Aug 6, 2026

Copy link
Copy Markdown

Configuration Diff

15 document(s) impacted:

+ 0 added
- 0 removed
! 15 modified
Diff
@@ spec.resources.appstudio.redhat.com/v1beta2/IntegrationTestScenario/{{.application}}{{.nameSuffix}}-v4-16-e2e.spec.params @@
# projctl.konflux.dev/v1beta1/ProjectDevelopmentStreamTemplate/rhtas-tenant/pco-fbc-template
! - two list entries removed:
- - name: POLICY_CONTROLLER_OPERATOR_GIT_REVISION
-   value: {{.policyControllerOperatorGitRevision}}
- - name: POLICY_CONTROLLER_OPERATOR_INSTALL_CHANNEL
-   value: {{.installChannel}}

@@ spec.resources.appstudio.redhat.com/v1beta2/IntegrationTestScenario/{{.application}}{{.nameSuffix}}-v4-16-upgrade.spec.params @@
# projctl.konflux.dev/v1beta1/ProjectDevelopmentStreamTemplate/rhtas-tenant/pco-fbc-template
! - three list entries removed:
- - name: POLICY_CONTROLLER_OPERATOR_GIT_REVISION
-   value: {{.policyControllerOperatorGitRevision}}
- - name: UPGRADE_FROM_CHANNEL
-   value: stable
- - name: UPGRADE_TO_CHANNEL
-   value: {{.installChannel}}

@@ spec.resources.appstudio.redhat.com/v1beta2/IntegrationTestScenario/{{.application}}{{.nameSuffix}}-v4-17-e2e.spec.params @@
# projctl.konflux.dev/v1beta1/ProjectDevelopmentStreamTemplate/rhtas-tenant/pco-fbc-template
! - two list entries removed:
- - name: POLICY_CONTROLLER_OPERATOR_GIT_REVISION
-   value: {{.policyControllerOperatorGitRevision}}
- - name: POLICY_CONTROLLER_OPERATOR_INSTALL_CHANNEL
-   value: {{.installChannel}}

@@ spec.resources.appstudio.redhat.com/v1beta2/IntegrationTestScenario/{{.application}}{{.nameSuffix}}-v4-17-upgrade.spec.params @@
# projctl.konflux.dev/v1beta1/ProjectDevelopmentStreamTemplate/rhtas-tenant/pco-fbc-template
! - three list entries removed:
- - name: POLICY_CONTROLLER_OPERATOR_GIT_REVISION
-   value: {{.policyControllerOperatorGitRevision}}
- - name: UPGRADE_FROM_CHANNEL
-   value: stable
- - name: UPGRADE_TO_CHANNEL
-   value: {{.installChannel}}

@@ spec.resources.appstudio.redhat.com/v1beta2/IntegrationTestScenario/{{.application}}{{.nameSuffix}}-v4-18-e2e.spec.params @@
# projctl.konflux.dev/v1beta1/ProjectDevelopmentStreamTemplate/rhtas-tenant/pco-fbc-template
! - two list entries removed:
- - name: POLICY_CONTROLLER_OPERATOR_GIT_REVISION
-   value: {{.policyControllerOperatorGitRevision}}
- - name: POLICY_CONTROLLER_OPERATOR_INSTALL_CHANNEL
-   value: {{.installChannel}}

@@ spec.resources.appstudio.redhat.com/v1beta2/IntegrationTestScenario/{{.application}}{{.nameSuffix}}-v4-18-upgrade.spec.params @@
# projctl.konflux.dev/v1beta1/ProjectDevelopmentStreamTemplate/rhtas-tenant/pco-fbc-template
! - three list entries removed:
- - name: POLICY_CONTROLLER_OPERATOR_GIT_REVISION
-   value: {{.policyControllerOperatorGitRevision}}
- - name: UPGRADE_FROM_CHANNEL
-   value: stable
- - name: UPGRADE_TO_CHANNEL
-   value: {{.installChannel}}

@@ spec.resources.appstudio.redhat.com/v1beta2/IntegrationTestScenario/{{.application}}{{.nameSuffix}}-v4-19-e2e.spec.params @@
# projctl.konflux.dev/v1beta1/ProjectDevelopmentStreamTemplate/rhtas-tenant/pco-fbc-template
! - two list entries removed:
- - name: POLICY_CONTROLLER_OPERATOR_GIT_REVISION
-   value: {{.policyControllerOperatorGitRevision}}
- - name: POLICY_CONTROLLER_OPERATOR_INSTALL_CHANNEL
-   value: {{.installChannel}}

@@ spec.resources.appstudio.redhat.com/v1beta2/IntegrationTestScenario/{{.application}}{{.nameSuffix}}-v4-19-upgrade.spec.params @@
# projctl.konflux.dev/v1beta1/ProjectDevelopmentStreamTemplate/rhtas-tenant/pco-fbc-template
! - three list entries removed:
- - name: POLICY_CONTROLLER_OPERATOR_GIT_REVISION
-   value: {{.policyControllerOperatorGitRevision}}
- - name: UPGRADE_FROM_CHANNEL
-   value: stable
- - name: UPGRADE_TO_CHANNEL
-   value: {{.installChannel}}

@@ spec.resources.appstudio.redhat.com/v1beta2/IntegrationTestScenario/{{.application}}{{.nameSuffix}}-v4-20-e2e.spec.params @@
# projctl.konflux.dev/v1beta1/ProjectDevelopmentStreamTemplate/rhtas-tenant/pco-fbc-template
! - two list entries removed:
- - name: POLICY_CONTROLLER_OPERATOR_GIT_REVISION
-   value: {{.policyControllerOperatorGitRevision}}
- - name: POLICY_CONTROLLER_OPERATOR_INSTALL_CHANNEL
-   value: {{.installChannel}}

@@ spec.resources.appstudio.redhat.com/v1beta2/IntegrationTestScenario/{{.application}}{{.nameSuffix}}-v4-20-upgrade.spec.params @@
# projctl.konflux.dev/v1beta1/ProjectDevelopmentStreamTemplate/rhtas-tenant/pco-fbc-template
! - three list entries removed:
- - name: POLICY_CONTROLLER_OPERATOR_GIT_REVISION
-   value: {{.policyControllerOperatorGitRevision}}
- - name: UPGRADE_FROM_CHANNEL
-   value: stable
- - name: UPGRADE_TO_CHANNEL
-   value: {{.installChannel}}

@@ spec.resources.appstudio.redhat.com/v1beta2/IntegrationTestScenario/{{.application}}{{.nameSuffix}}-v4-21-e2e.spec.params @@
# projctl.konflux.dev/v1beta1/ProjectDevelopmentStreamTemplate/rhtas-tenant/pco-fbc-template
! - two list entries removed:
- - name: POLICY_CONTROLLER_OPERATOR_GIT_REVISION
-   value: {{.policyControllerOperatorGitRevision}}
- - name: POLICY_CONTROLLER_OPERATOR_INSTALL_CHANNEL
-   value: {{.installChannel}}

@@ spec.resources.appstudio.redhat.com/v1beta2/IntegrationTestScenario/{{.application}}{{.nameSuffix}}-v4-21-upgrade.spec.params @@
# projctl.konflux.dev/v1beta1/ProjectDevelopmentStreamTemplate/rhtas-tenant/pco-fbc-template
! - three list entries removed:
- - name: POLICY_CONTROLLER_OPERATOR_GIT_REVISION
-   value: {{.policyControllerOperatorGitRevision}}
- - name: UPGRADE_FROM_CHANNEL
-   value: stable
- - name: UPGRADE_TO_CHANNEL
-   value: {{.installChannel}}

@@ spec.resources.appstudio.redhat.com/v1beta2/IntegrationTestScenario/{{.application}}{{.nameSuffix}}-v4-22-e2e.spec.params @@
# projctl.konflux.dev/v1beta1/ProjectDevelopmentStreamTemplate/rhtas-tenant/pco-fbc-template
! - two list entries removed:
- - name: POLICY_CONTROLLER_OPERATOR_GIT_REVISION
-   value: {{.policyControllerOperatorGitRevision}}
- - name: POLICY_CONTROLLER_OPERATOR_INSTALL_CHANNEL
-   value: {{.installChannel}}

@@ spec.resources.appstudio.redhat.com/v1beta2/IntegrationTestScenario/{{.application}}{{.nameSuffix}}-v4-22-upgrade.spec.params @@
# projctl.konflux.dev/v1beta1/ProjectDevelopmentStreamTemplate/rhtas-tenant/pco-fbc-template
! - three list entries removed:
- - name: POLICY_CONTROLLER_OPERATOR_GIT_REVISION
-   value: {{.policyControllerOperatorGitRevision}}
- - name: UPGRADE_FROM_CHANNEL
-   value: stable
- - name: UPGRADE_TO_CHANNEL
-   value: {{.installChannel}}

@@ spec.variables @@
# projctl.konflux.dev/v1beta1/ProjectDevelopmentStreamTemplate/rhtas-tenant/pco-fbc-template
! - two list entries removed:
- - name: policyControllerOperatorGitRevision
-   defaultValue: main
-   description: "Git revision of policy-controller-operator repo used by PCO FBC e2e"
- - name: installChannel
-   defaultValue: stable
-   description: "The operator install channel used for e2e"

📦 Artifacts: base-output.yaml, head-output.yaml, dyff-output.txt

@qodo-for-securesign

Copy link
Copy Markdown

PR Summary by Qodo

Derive PCO E2E branch/channel from FBC metadata (remove manual params)

✨ Enhancement ⚙️ Configuration changes 🕐 20-40 Minutes

Grey Divider

AI Description

• Add a pipeline step to derive PCO release branch/channel from the built FBC image.
• Remove hardcoded PCO git revision and install/upgrade channel parameters across Konflux configs.
• Update PCO E2E and upgrade pipelines to clone the correct release branch and use derived channel.
Diagram

graph TD
  CFG["Konflux PCO patches"] --> PL["PCO E2E pipelines"] --> SNAP["FBC image (snapshot)"] --> PM["parse-metadata task"] --> RI["derive release-info"] --> CL["clone operator source"] --> REPO["PCO git repo"] --> TEST["E2E / upgrade tests"]
Loading
High-Level Assessment

The following are alternative approaches to this PR:

1. Keep explicit revision/channel parameters
  • ➕ Simple mental model; fully controllable from PipelineRun/trigger.
  • ➕ No dependency on external derive-release-info task.
  • ➖ Easy to drift from the intended release branch/channel.
  • ➖ Requires manual updates across OCP versions and pipelines.
2. Derive branch/channel in an inline script step
  • ➕ Avoids pulling a shared task from an external repo.
  • ➕ Can be tailored tightly to this repo’s conventions.
  • ➖ Logic duplication across pipelines; harder to standardize and maintain.
  • ➖ Less discoverable/reusable than a shared task.
3. Pin to an immutable git tag from FBC/CSV metadata
  • ➕ Reproducible tests; avoids branch moving targets.
  • ➕ Clear traceability from released content to source.
  • ➖ Requires reliable tag/commit mapping in metadata and release process.
  • ➖ May complicate testing of pre-release branch content.

Recommendation: Current approach (shared derive-release-info task) is the best fit: it centralizes release-branch/channel derivation, reduces manual parameter drift, and keeps pipelines aligned with the FBC under test. Ensure the external task contract (result names like release-branch/channel) is stable, since multiple pipelines now depend on it.

Files changed (10) +45 / -91

Other (10) +45 / -91
patch.yamlDrop PCO git revision and install/upgrade channel params (OCP 4.16) +0/-10

Drop PCO git revision and install/upgrade channel params (OCP 4.16)

• Removes POLICY_CONTROLLER_OPERATOR_GIT_REVISION and channel-related parameters from the OCP 4.16 Konflux patch. This shifts responsibility for choosing the correct branch/channel away from static config.

konflux-configs/base/project/base/ocp/pco/v4.16/patch.yaml

patch.yamlDrop PCO git revision and install/upgrade channel params (OCP 4.17) +0/-10

Drop PCO git revision and install/upgrade channel params (OCP 4.17)

• Removes POLICY_CONTROLLER_OPERATOR_GIT_REVISION and channel-related parameters from the OCP 4.17 Konflux patch. Keeps only OCP version and deployment name inputs.

konflux-configs/base/project/base/ocp/pco/v4.17/patch.yaml

patch.yamlDrop PCO git revision and install/upgrade channel params (OCP 4.18) +0/-10

Drop PCO git revision and install/upgrade channel params (OCP 4.18)

• Removes the operator git revision and install/upgrade channel parameters for OCP 4.18. Aligns config with pipelines that derive these values dynamically.

konflux-configs/base/project/base/ocp/pco/v4.18/patch.yaml

patch.yamlDrop PCO git revision and install/upgrade channel params (OCP 4.19) +0/-10

Drop PCO git revision and install/upgrade channel params (OCP 4.19)

• Removes the operator git revision and upgrade channel parameters for OCP 4.19. Reduces the number of templated inputs required by the patch.

konflux-configs/base/project/base/ocp/pco/v4.19/patch.yaml

patch.yamlDrop PCO git revision and install/upgrade channel params (OCP 4.20) +0/-10

Drop PCO git revision and install/upgrade channel params (OCP 4.20)

• Removes static git revision and channel parameters from the OCP 4.20 patch. Leaves the patch focused on OCP version and deployment identifiers.

konflux-configs/base/project/base/ocp/pco/v4.20/patch.yaml

patch.yamlDrop PCO git revision and install/upgrade channel params (OCP 4.21) +0/-10

Drop PCO git revision and install/upgrade channel params (OCP 4.21)

• Removes the operator git revision and upgrade channel settings from the OCP 4.21 patch. Intended to ensure E2E pulls from the correct release content via pipeline-derived values.

konflux-configs/base/project/base/ocp/pco/v4.21/patch.yaml

patch.yamlDrop PCO git revision and install/upgrade channel params (OCP 4.22) +0/-10

Drop PCO git revision and install/upgrade channel params (OCP 4.22)

• Removes POLICY_CONTROLLER_OPERATOR_GIT_REVISION and upgrade channel parameters from OCP 4.22 patch configuration. Relies on pipeline-derived release branch/channel instead of templated params.

konflux-configs/base/project/base/ocp/pco/v4.22/patch.yaml

template.yamlRemove template params for PCO revision and install channel +0/-6

Remove template params for PCO revision and install channel

• Deletes the template parameters policyControllerOperatorGitRevision and installChannel (including defaults and descriptions). This matches the new pipeline behavior where these values are derived from FBC metadata.

konflux-configs/base/project/overlay/pco-fbc/template.yaml

pco-operator-upgrade.yamlDerive release branch/channel and use them for upgrade testing +22/-7

Derive release branch/channel and use them for upgrade testing

• Adds a new release-info task (derive-release-info.yaml) to compute the operator release branch and channel from the FBC image and OCP version. Updates clone-operator-source-code to use the derived release branch and sets UPGRADE_TO_CHANNEL from the derived channel, removing the previous explicit params.

pipelines/integration-test/pco-operator-upgrade.yaml

policy-controller-fbc-e2e.yamlDerive release branch/channel and use them for FBC E2E install +23/-8

Derive release branch/channel and use them for FBC E2E install

• Adds the release-info task to derive the correct release branch and install channel from the FBC image metadata. Updates the operator clone revision and the installChannel passed to the install task to use derived results, removing the old explicit params.

pipelines/integration-test/policy-controller-fbc-e2e.yaml

@qodo-for-securesign

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (1) 📘 Rule violations (0) 📜 Skill insights (0)

Grey Divider


Remediation recommended

1. Unpinned release-info task 🐞 Bug ☼ Reliability
Description
The newly added release-info task is resolved from securesign/pipelines.git at the floating
main revision, so upstream task changes can change or break the PCO e2e/upgrade pipelines without
any change in this repo. This makes CI behavior non-reproducible and increases the risk of
unexpected pipeline failures.
Code

pipelines/integration-test/pco-operator-upgrade.yaml[R57-60]

+            - name: url
+              value: https://github.com/securesign/pipelines.git
+            - name: revision
+              value: main
Relevance

●● Moderate

Past review on pinning resolverRef from main was undetermined; also precedent rejecting reverting
to parameterized revision.

PR-#253
PR-#304

ⓘ Recommendations generated based on similar findings in past PRs

Evidence
Both PCO PipelineRuns added by this PR define a release-info task resolved via the git resolver
from securesign/pipelines.git with revision: main, meaning the task definition is not pinned to
an immutable version.

pipelines/integration-test/pco-operator-upgrade.yaml[51-63]
pipelines/integration-test/policy-controller-fbc-e2e.yaml[56-68]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

### Issue description
The PCO pipelines now fetch `tasks/integration-test/derive-release-info.yaml` from `https://github.com/securesign/pipelines.git` using `revision: main`. Because `main` is mutable, the resolved task definition can change independently of this repository, making pipeline runs non-deterministic and potentially breaking CI unexpectedly.

### Issue Context
This PR introduced `release-info` into both PCO PipelineRuns, so this PR is also introducing the new unpinned dependency.

### Fix
Pin the git resolver `revision` to an immutable reference (commit SHA or immutable tag). If you need easy updates, consider passing the pinned revision via a PipelineRun param that is updated intentionally.

### Fix Focus Areas
- pipelines/integration-test/pco-operator-upgrade.yaml[51-63]
- pipelines/integration-test/policy-controller-fbc-e2e.yaml[56-68]

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


To customize comments, go to the Qodo configuration screen, or learn more in the docs.

Qodo Logo

@JasonPowr
JasonPowr force-pushed the pull-pco-e2e-from-correct-branch branch from c0ebb6e to 8e7ca65 Compare August 6, 2026 10:01
@JasonPowr
JasonPowr merged commit f3b7ae2 into main Aug 6, 2026
4 checks passed
@JasonPowr
JasonPowr deleted the pull-pco-e2e-from-correct-branch branch August 6, 2026 10:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants