OAPE-696: Add E2E coverage reporting with Codecov integration - #111
OAPE-696: Add E2E coverage reporting with Codecov integration#111PillaiManish wants to merge 3 commits into
Conversation
|
Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
WalkthroughAdds E2E coverage infrastructure for the operator, including a coverage-instrumented image, Makefile build and collection targets, deployment setup, coverage report generation, and optional Codecov uploads. ChangesE2E Coverage Instrumentation and Collection
Estimated code review effort: 3 (Moderate) | ~25 minutes Sequence Diagram(s)sequenceDiagram
participant User as User/CI
participant Kubernetes
participant OperatorPod
participant LocalArtifacts
participant Codecov
User->>Kubernetes: Patch CSV with coverage image and GOCOVERDIR
Kubernetes->>OperatorPod: Roll out coverage-enabled operator
User->>OperatorPod: Send SIGTERM to flush coverage
User->>OperatorPod: Copy coverage data
LocalArtifacts->>LocalArtifacts: Generate coverage-e2e.out with go tool covdata
LocalArtifacts->>Codecov: Upload report when CODECOV_TOKEN is set
Suggested reviewers: 🚥 Pre-merge checks | ✅ 14 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (14 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
|
@PillaiManish: This pull request references OAPE-696 which is a valid jira issue. Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the sub-task to target the "5.0.0" version, but no target version was set. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
There was a problem hiding this comment.
Actionable comments posted: 3
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@cmd/secrets-store-csi-driver-operator/coverage_flush.go`:
- Around line 14-16: The GOCOVERDIR creation currently uses os.MkdirAll(dir,
0o777) and ignores errors; change this to create the directory with restrictive
permissions (e.g., 0o700 or 0o755 as appropriate) and handle the returned error
from os.MkdirAll instead of discarding it: call os.MkdirAll(dir, 0o700), check
the error, and propagate or log/fail fast (using the existing operator logger or
by returning the error) so coverage flush code won’t proceed when directory
creation fails; update the block that reads the GOCOVERDIR env var and the
os.MkdirAll call accordingly.
In `@hack/e2e-coverage.sh`:
- Around line 93-95: The current send of SIGUSR1 uses a hardcoded PID 1 (the
line invoking oc exec ... 'kill -USR1 1'), which can be wrong if the operator
isn't PID 1; update the script to locate the actual operator process inside the
container (using pidof or pgrep) and send SIGUSR1 to that PID, falling back to
PID 1 if no process is found. Inside the block that uses "${NAMESPACE}" and
"${pod}", run something like pidof <operator-binary-name> || pgrep -f
<operator-binary-name> to capture the PID(s) and then call kill -USR1 "$PID" (or
kill -USR1 1 if the lookup returns empty) so the script remains compatible with
single-binary containers while handling wrapper/init cases. Ensure the lookup
happens inside the oc exec command so the PID refers to the container namespace.
In `@Makefile`:
- Around line 80-85: The build-coverage target is generating invalid Go flag
syntax by naively concatenating "$(GO_BUILD_FLAGS),e2ecoverage" and the
suggested "-tags e2ecoverage" breaks FIPS by producing duplicate -tags; fix by
producing a single -tags value for the coverage build: detect if GO_BUILD_FLAGS
already contains a -tags clause and if so append ",e2ecoverage" to that existing
tag list, otherwise add a new "-tags e2ecoverage" flag; implement this logic in
the Makefile when constructing flags for the build-coverage target (use
GO_BUILD_FLAGS and create/compute a temporary coverage tags variable or a
modified FLAGS variable) so the final go build invocation has at most one -tags
flag and includes e2ecoverage.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Repository: openshift/coderabbit/.coderabbit.yaml
Review profile: CHILL
Plan: Enterprise
Run ID: f4068362-35f1-4771-9630-6d924234b1da
📒 Files selected for processing (4)
Dockerfile.coverageMakefilecmd/secrets-store-csi-driver-operator/coverage_flush.gohack/e2e-coverage.sh
There was a problem hiding this comment.
🧹 Nitpick comments (1)
Dockerfile.coverage (1)
6-9: ⚡ Quick winDrop root default in the coverage runtime image.
The runtime stage has no explicit
USER, so it defaults to root. Please set a non-root user for defense-in-depth.Proposed hardening
FROM registry.ci.openshift.org/ocp/4.22:base-rhel9 COPY --from=builder /go/src/github.com/openshift/secrets-store-csi-driver-operator/secrets-store-csi-driver-operator /usr/bin/ ENV GOCOVERDIR=/tmp/e2e-cover +USER 65532 ENTRYPOINT ["/bin/sh", "-c", "mkdir -p /tmp/e2e-cover && exec /usr/bin/secrets-store-csi-driver-operator \"$@\"", "--"]🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@Dockerfile.coverage` around lines 6 - 9, The runtime stage in Dockerfile.coverage defaults to root; add a non-root user and switch to it before ENTRYPOINT to improve hardening: create a dedicated user/group (or use an existing non-root UID), ensure ownership/permissions of /tmp/e2e-cover and the binary at /usr/bin/secrets-store-csi-driver-operator are adjusted (chown/chmod) so the non-root user can write to GOCOVERDIR and execute the binary, then add a USER instruction before ENTRYPOINT to run the container as that non-root user.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@Dockerfile.coverage`:
- Around line 6-9: The runtime stage in Dockerfile.coverage defaults to root;
add a non-root user and switch to it before ENTRYPOINT to improve hardening:
create a dedicated user/group (or use an existing non-root UID), ensure
ownership/permissions of /tmp/e2e-cover and the binary at
/usr/bin/secrets-store-csi-driver-operator are adjusted (chown/chmod) so the
non-root user can write to GOCOVERDIR and execute the binary, then add a USER
instruction before ENTRYPOINT to run the container as that non-root user.
ℹ️ Review info
⚙️ Run configuration
Configuration used: Repository: openshift/coderabbit/.coderabbit.yaml
Review profile: CHILL
Plan: Enterprise
Run ID: 67bd0df7-10b1-406d-8f94-fae8b631578c
📒 Files selected for processing (3)
Dockerfile.coverageMakefilehack/e2e-coverage.sh
🚧 Files skipped from review as they are similar to previous changes (1)
- hack/e2e-coverage.sh
|
/retest |
|
/label tide/merge-method-squash |
|
/retest |
2 similar comments
|
/retest |
|
/retest |
chiragkyal
left a comment
There was a problem hiding this comment.
LGTM, with a few questions.
/cc @mytreya-rh
| fi | ||
| echo "Found CSV: ${csv}" | ||
|
|
||
| echo "Patching CSV with coverage image..." |
There was a problem hiding this comment.
Which image is it exactly replacing?
There was a problem hiding this comment.
It replaces the standard secrets-store-csi-driver-operator image (built from Dockerfile.openshift via make → normal go build) with the coverage-instrumented image (built from Dockerfile.coverage via make build-coverage → go build -cover -covermode=atomic -coverpkg=./...).
Both produce the same binary at /usr/bin/secrets-store-csi-driver-operator, but the coverage version is compiled with Go's coverage instrumentation. The JSON patch targets /spec/install/spec/deployments[0]/spec/template/spec/containers[0]/image — the first container of the first deployment in the CSV (which is the operator container).
The coverage image additionally sets GOCOVERDIR=/tmp/e2e-cover and wraps the entrypoint with mkdir -p /tmp/e2e-cover so coverage data is written to disk during execution.
| -o jsonpath='{.spec.install.spec.deployments[0].spec.template.spec.containers[0].env[?(@.name=="GOCOVERDIR")].name}' 2>/dev/null) | ||
| if [[ -z "${has_gocoverdir}" ]]; then | ||
| echo "Adding GOCOVERDIR env var to CSV..." | ||
| oc patch csv "${csv}" -n "${NAMESPACE}" --type=json -p "[ |
There was a problem hiding this comment.
I believe CSV patch won't be overwritten by OLM.
There was a problem hiding this comment.
Correct — this is safe. OLM does not reconcile/overwrite the CSV's spec.install.spec.deployments once the CSV is in the Succeeded phase. OLM creates the deployment from the CSV spec, and the CSV is essentially static after that. The JSON patch triggers OLM to update the deployment with the new image and env var, which is exactly what we want.
The only risk would be if OLM reinstalled/upgraded the operator during the test, but in a CI e2e run that doesn't happen.
| local job_type="${JOB_TYPE:-local}" | ||
| if [[ "${job_type}" == "presubmit" ]]; then | ||
| echo "Detected presubmit (PR #${PULL_NUMBER:-unknown})" | ||
| [[ -n "${PULL_NUMBER:-}" ]] && codecov_args+=(--pr "${PULL_NUMBER}") | ||
| [[ -n "${PULL_PULL_SHA:-}" ]] && codecov_args+=(--sha "${PULL_PULL_SHA}") | ||
| [[ -n "${PULL_BASE_REF:-}" ]] && codecov_args+=(--branch "${PULL_BASE_REF}") | ||
| [[ -n "${REPO_OWNER:-}" && -n "${REPO_NAME:-}" ]] && codecov_args+=(--slug "${REPO_OWNER}/${REPO_NAME}") |
There was a problem hiding this comment.
How are we defining these env vars?
There was a problem hiding this comment.
These are not defined by us — they are standard Prow job environment variables automatically injected into every CI job container by Prow:
| Variable | Description |
|---|---|
JOB_TYPE |
presubmit, postsubmit, or periodic |
PULL_NUMBER |
PR number (presubmit only) |
PULL_PULL_SHA |
HEAD commit SHA of the PR |
PULL_BASE_REF |
Base branch name (e.g., main) |
PULL_BASE_SHA |
Base branch commit SHA |
REPO_OWNER |
GitHub org (e.g., openshift) |
REPO_NAME |
GitHub repo name |
The script uses them to provide correct PR/commit context to the Codecov uploader so coverage reports show up on the right PR. When running locally (JOB_TYPE is unset, defaults to local), these are all skipped and Codecov auto-detects from git.
There was a problem hiding this comment.
Did we check in any rehearsal whether they are getting populated correctly?
There was a problem hiding this comment.
Yes — these Prow env vars are standard and well-established. They're populated for every CI job automatically. You can verify in any Prow job log by looking at the environment. For example, in the rehearsal run from the release repo PR, the Prow container env includes JOB_TYPE=presubmit, PULL_NUMBER, REPO_OWNER=openshift, etc.
That said, the Codecov upload only happens if CODECOV_TOKEN is set (from the mounted secret). In the rehearsal, the upload was skipped since the secret wasn't available in the rehearsal namespace — which is expected and harmless. The env vars themselves are always present; they're part of Prow's core infrastructure, documented at https://docs.prow.k8s.io/docs/jobs/#job-environment-variables.
There was a problem hiding this comment.
Are these Make commands meant to be used locally?
There was a problem hiding this comment.
Yes, the Makefile targets support both CI and local use:
make build-coverage— builds the coverage-instrumented binary. Used byDockerfile.coveragein CI, but can also be run locally.make docker-build-coverage— builds the coverage Docker image locally (convenience for dev testing).make docker-push-coverage— pushes the coverage image to a registry (local workflow only).make e2e-coverage-collect— runshack/e2e-coverage.sh collectlocally, for collecting coverage after you've run e2e tests against a dev cluster with the coverage image deployed.
In CI, only build-coverage is used directly (inside Dockerfile.coverage). The other targets are convenience wrappers for developers who want to test the coverage flow against a dev cluster without going through the full CI pipeline.
There was a problem hiding this comment.
Except make build-coverage, others are not used in CI. If they are for local testing, I think some documentation on how to run and verify coverage would help.
There was a problem hiding this comment.
Good point. I'll add a section to the README documenting how to run and verify coverage locally. Something like:
## E2E Coverage (Local)
1. Build and push the coverage image:
make docker-build-coverage docker-push-coverage
2. Deploy the operator with the coverage image on your dev cluster:
hack/e2e-coverage.sh setup
3. Run e2e tests:
make test-e2e
4. Collect coverage:
make e2e-coverage-collect
Will add this in the next push.
There was a problem hiding this comment.
the README update is still pending
|
/retest |
|
/retest-required |
|
/retest |
|
/test operator-e2e-fips |
|
/retest-required |
mytreya-rh
left a comment
There was a problem hiding this comment.
LGTM
few minor comments
| echo "Found operator pod: ${pod}" | ||
|
|
||
| echo "Sending SIGTERM to flush coverage data (container will restart)..." | ||
| oc exec -n "${NAMESPACE}" "${pod}" -- /bin/sh -c 'kill -TERM 1' 2>/dev/null || true |
There was a problem hiding this comment.
If we cannot successfully send the SIGTERM, the job should fail correct?
But here it continues..
| oc exec -n "${NAMESPACE}" "${pod}" -- /bin/sh -c 'kill -TERM 1' 2>/dev/null || true | ||
|
|
||
| echo "Waiting for container to restart and become ready..." | ||
| sleep 5 |
There was a problem hiding this comment.
Here, we are assuming that the container restarted in 5 seconds.
More reliable approach would be to check that the restartCount got incremented by one from the value that was before sending the SIGTERM
| @@ -0,0 +1,11 @@ | |||
| FROM registry.ci.openshift.org/ocp/builder:rhel-9-golang-1.25-openshift-4.22 AS builder | |||
There was a problem hiding this comment.
we should update these to the 5.0 and golang 1.26 base images
There was a problem hiding this comment.
the README update is still pending
4fe4186 to
6c922db
Compare
Add coverage-instrumented build and collection scripts for E2E test coverage reporting. Uses a no-PVC approach: SIGUSR1 flushes coverage data from the running operator pod, which is then copied out via oc cp and uploaded to Codecov. Co-authored-by: Cursor <cursoragent@cursor.com>
Remove coverage_flush.go and use SIGTERM to flush coverage data instead of SIGUSR1. Container restarts after SIGTERM, emptyDir preserves coverage files, and oc cp runs from the restarted container. Co-authored-by: Cursor <cursoragent@cursor.com>
27c2dbd to
a02ffdd
Compare
There was a problem hiding this comment.
Actionable comments posted: 5
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@Dockerfile.coverage`:
- Line 3: Replace the broad COPY instruction in Dockerfile.coverage with
explicit COPY statements for only the files and directories required by make
build-coverage, and add or tighten a restrictive .dockerignore to exclude
credentials, build outputs, and unrelated artifacts.
- Around line 6-11: Add a meaningful Docker HEALTHCHECK to the runtime stage
after the operator ENTRYPOINT, using a probe command available in the base RHEL9
image that verifies the operator process is running and tolerates its startup
behavior. Keep the existing ENTRYPOINT and labels unchanged.
- Around line 1-6: Update the final runtime stage after the builder stage to use
an approved UBI minimal or distroless image from catalog.redhat.com instead of
registry.ci.openshift.org/ocp/5.0:base-rhel9. Keep the existing builder stage
and its separation from the runtime stage unchanged.
- Around line 6-9: Add a supported non-root user in the Dockerfile before the
ENTRYPOINT, switch to that user with USER, and ensure /tmp/e2e-cover is created
with ownership or permissions allowing it to be written at runtime. Keep the
existing GOCOVERDIR and secrets-store-csi-driver-operator startup behavior
unchanged.
In `@hack/e2e-coverage.sh`:
- Around line 80-87: Update the pod lookup in the coverage collection flow so a
non-zero oc get result for no matching pods does not trigger set -e before the
empty-pod check. Explicitly tolerate or handle the lookup failure, then preserve
the existing [[ -z "${pod}" ]] custom error path and exit behavior.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Repository: openshift/coderabbit/.coderabbit.yaml
Review profile: CHILL
Plan: Enterprise
Run ID: 8f392ebc-ac62-4e8a-8fab-ea04f6e0cec2
📒 Files selected for processing (4)
Dockerfile.coverageMakefileREADME.mdhack/e2e-coverage.sh
| FROM registry.ci.openshift.org/ocp/builder:rhel-9-golang-1.26-openshift-5.0 AS builder | ||
| WORKDIR /go/src/github.com/openshift/secrets-store-csi-driver-operator | ||
| COPY . . | ||
| RUN make build-coverage | ||
|
|
||
| FROM registry.ci.openshift.org/ocp/5.0:base-rhel9 |
There was a problem hiding this comment.
🔒 Security & Privacy | 🟠 Major | 🏗️ Heavy lift
Use the approved runtime base image.
The final stage uses registry.ci.openshift.org/ocp/5.0:base-rhel9, but the container policy requires a UBI minimal or distroless runtime image from catalog.redhat.com. Replace it with an approved catalog image while keeping the builder stage separate.
🧰 Tools
🪛 Trivy (0.69.3)
[error] 1-1: Image user should not be 'root'
Specify at least 1 USER command in Dockerfile with non-root user as argument
Rule: DS-0002
(IaC/Dockerfile)
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@Dockerfile.coverage` around lines 1 - 6, Update the final runtime stage after
the builder stage to use an approved UBI minimal or distroless image from
catalog.redhat.com instead of registry.ci.openshift.org/ocp/5.0:base-rhel9. Keep
the existing builder stage and its separation from the runtime stage unchanged.
Source: Path instructions
| @@ -0,0 +1,11 @@ | |||
| FROM registry.ci.openshift.org/ocp/builder:rhel-9-golang-1.26-openshift-5.0 AS builder | |||
| WORKDIR /go/src/github.com/openshift/secrets-store-csi-driver-operator | |||
| COPY . . | |||
There was a problem hiding this comment.
🔒 Security & Privacy | 🟠 Major | 🏗️ Heavy lift
Do not copy the entire build context.
COPY . . places every context file into the builder layer/cache, potentially including credentials or unrelated artifacts. Use explicit COPY statements for the files required by make build-coverage, together with a restrictive .dockerignore.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@Dockerfile.coverage` at line 3, Replace the broad COPY instruction in
Dockerfile.coverage with explicit COPY statements for only the files and
directories required by make build-coverage, and add or tighten a restrictive
.dockerignore to exclude credentials, build outputs, and unrelated artifacts.
Source: Path instructions
| FROM registry.ci.openshift.org/ocp/5.0:base-rhel9 | ||
| COPY --from=builder /go/src/github.com/openshift/secrets-store-csi-driver-operator/secrets-store-csi-driver-operator /usr/bin/ | ||
| ENV GOCOVERDIR=/tmp/e2e-cover | ||
| ENTRYPOINT ["/bin/sh", "-c", "mkdir -p /tmp/e2e-cover && exec /usr/bin/secrets-store-csi-driver-operator \"$@\"", "--"] |
There was a problem hiding this comment.
🔒 Security & Privacy | 🟠 Major | ⚡ Quick win
Run the runtime image as non-root.
No USER is declared, and Trivy reports the image’s effective user as root. Add a non-root user supported by the base image and verify that /tmp/e2e-cover remains writable.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@Dockerfile.coverage` around lines 6 - 9, Add a supported non-root user in the
Dockerfile before the ENTRYPOINT, switch to that user with USER, and ensure
/tmp/e2e-cover is created with ownership or permissions allowing it to be
written at runtime. Keep the existing GOCOVERDIR and
secrets-store-csi-driver-operator startup behavior unchanged.
Sources: Path instructions, Linters/SAST tools
| FROM registry.ci.openshift.org/ocp/5.0:base-rhel9 | ||
| COPY --from=builder /go/src/github.com/openshift/secrets-store-csi-driver-operator/secrets-store-csi-driver-operator /usr/bin/ | ||
| ENV GOCOVERDIR=/tmp/e2e-cover | ||
| ENTRYPOINT ["/bin/sh", "-c", "mkdir -p /tmp/e2e-cover && exec /usr/bin/secrets-store-csi-driver-operator \"$@\"", "--"] | ||
| LABEL io.k8s.display-name="OpenShift Secrets Store CSI Driver Operator" \ | ||
| io.k8s.description="The Secrets Store CSI Driver Operator installs and maintains the Secrets Store CSI Driver on a cluster." |
There was a problem hiding this comment.
🩺 Stability & Availability | 🟠 Major | ⚡ Quick win
Add a meaningful HEALTHCHECK.
The runtime image has no healthcheck, despite the container policy requiring one. Use a probe available in the runtime image and compatible with the operator’s startup behavior.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@Dockerfile.coverage` around lines 6 - 11, Add a meaningful Docker HEALTHCHECK
to the runtime stage after the operator ENTRYPOINT, using a probe command
available in the base RHEL9 image that verifies the operator process is running
and tolerates its startup behavior. Keep the existing ENTRYPOINT and labels
unchanged.
Source: Path instructions
| local pod | ||
| pod=$(oc get pods -n "${NAMESPACE}" -l "${POD_LABEL}" \ | ||
| -o jsonpath='{.items[0].metadata.name}' 2>/dev/null) | ||
| if [[ -z "${pod}" ]]; then | ||
| echo "Error: no operator pod found with label ${POD_LABEL}" | ||
| echo "Coverage collection requires the operator pod to be running." | ||
| exit 1 | ||
| fi |
There was a problem hiding this comment.
🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win
Pod lookup should not short-circuit the custom error path.
oc get ... -o jsonpath='{.items[0].metadata.name}' exits non-zero when no pod matches, so set -e stops the script before if [[ -z "${pod}" ]] can print the intended message. Handle the empty case explicitly instead of relying on that branch.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@hack/e2e-coverage.sh` around lines 80 - 87, Update the pod lookup in the
coverage collection flow so a non-zero oc get result for no matching pods does
not trigger set -e before the empty-pod check. Explicitly tolerate or handle the
lookup failure, then preserve the existing [[ -z "${pod}" ]] custom error path
and exit behavior.
|
/retest |
|
/retest |
…update README and base images - Remove || true from kill -TERM so the job fails if SIGTERM cannot be sent - Use oc wait --for=jsonpath restartCount for reliable restart detection - Add E2E Coverage section to README with usage instructions - Update Dockerfile.coverage to golang-1.26-openshift-5.0 and ocp/5.0:base-rhel9 matching production Dockerfile Co-authored-by: Cursor <cursoragent@cursor.com>
a02ffdd to
1cf2651
Compare
|
/lgtm |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: mytreya-rh, PillaiManish The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
|
/retest |
2 similar comments
|
/retest |
|
/retest |
|
@PillaiManish: The following tests failed, say
Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
Summary
Dockerfile.coverage) that builds the operator with Go's-coverflags and FIPS compliancehack/e2e-coverage.shwithsetupandcollectsubcommands for CI and local usebuild-coverage,docker-build-coverage,docker-push-coverage,e2e-coverage-collect)How it works
Dockerfile.coverage(usesmake build-coveragewhich adds-cover -covermode=atomic -coverpkg=./...)hack/e2e-coverage.sh setuppatches the live CSV to swap in the coverage image and setGOCOVERDIR=/tmp/e2e-coverhack/e2e-coverage.sh collectsends SIGTERM to flush coverage data (Go runtime writes on clean exit), waits for container restart, copies data viaoc cp, converts to Go profile, and uploads to CodecovCoverage data survives the container restart because the operator's CSV already defines an emptyDir volume at
/tmp(medium: Memory), which persists across container restarts within the same pod. No PVC or extractor pod is needed.Files
Dockerfile.coverageDockerfile.openshiftbut builds with coverage flagshack/e2e-coverage.shMakefile(appended)Tested
-cover -covermode=atomic -coverpkg=./...pkg/operator64.5%,assets100%,pkg/version100%Follow-up (separate PR)
sscsi-ci-secrets/codecov-tokenSummary by CodeRabbit