Skip to content

Conversation

@openshift-bot
Copy link

@openshift-bot openshift-bot commented Jan 13, 2026

The downstream repository has been updated with the following following upstream commits:

Date Commit Author Message
2026-01-15 17:25:06 operator-framework/operator-controller@b08a054 dependabot[bot] 🌱 Bump pymdown-extensions from 10.19.1 to 10.20 (#2448)
2026-01-15 10:15:46 operator-framework/operator-controller@42be3fc Per Goncalves da Silva Adds bundle configuration documentation (#2380)
2026-01-14 14:37:46 operator-framework/operator-controller@dc20dfb Predrag Knezevic Simplify Boxcutter applier interface (#2446)
2026-01-14 07:20:02 operator-framework/operator-controller@347be32 dependabot[bot] 🌱 Bump github.com/sigstore/fulcio from 1.7.1 to 1.8.5 (#2445)
2026-01-13 20:53:30 operator-framework/operator-controller@da9e337 Predrag Knezevic Prevent showing duplicate entry under .status.activeRevisions (#2444)
2026-01-13 16:41:00 operator-framework/operator-controller@049f813 Camila Macedo ✨ (feat): When using Boxcutter feature-gate, use ClusterExtension ServiceAccount for revision operations (#2429)
2026-01-12 11:20:49 operator-framework/operator-controller@1fa4169 Camila Macedo 🌱 Add a Makefile target and start running the API diff linter as part of CI (#2411)

The vendor/ directory has been updated and the following commits were carried:

Date Commit Author Message
2026-01-11 00:06:49 openshift/operator-framework-operator-controller@12531f0 dtfranz UPSTREAM: <carry>: Add OpenShift specific files
2026-01-11 00:06:51 openshift/operator-framework-operator-controller@5c5685a Camila Macedo UPSTREAM: <carry>: Add new tests for single/own namespaces install modes
2026-01-11 00:06:51 openshift/operator-framework-operator-controller@dd0ebd6 Camila Macedo UPSTREAM: <carry>: Upgrade OCP image from 4.20 to 4.21
2026-01-11 00:06:52 openshift/operator-framework-operator-controller@063feb9 Camila Macedo UPSTREAM: <carry>: [Default Catalog Tests] - Change logic to get ocp images from openshift/catalogd/manifests.yaml
2026-01-11 00:06:53 openshift/operator-framework-operator-controller@42664da Todd Short UPSTREAM: <carry>: Update OCP catalogs to v4.21
2026-01-11 00:06:53 openshift/operator-framework-operator-controller@e5c6d5e Kui Wang UPSTREAM: <carry>: support singleown cases in disconnected
2026-01-11 00:06:54 openshift/operator-framework-operator-controller@9ca54bf Kui Wang UPSTREAM: <carry>: fix cases 81696 and 74618 for product code changes
2026-01-11 00:06:55 openshift/operator-framework-operator-controller@45f9ba3 Camila Macedo UPSTREAM: <carry>: Define Default timeouts and apply their usage accross to avoid flakes
2026-01-11 00:06:55 openshift/operator-framework-operator-controller@7b52396 Todd Short UPSTREAM: <carry>: Update to new feature-gate options in helm
2026-01-11 00:06:56 openshift/operator-framework-operator-controller@b935806 Camila Macedo UPSTREAM: <carry>: Fix flake for single/own ns tests by ensuring uniquess and waiting for k8s cleanups
2026-01-11 00:06:57 openshift/operator-framework-operator-controller@5e74730 Camila Macedo UPSTREAM: <carry>: [OTE]: Enhance single/own ns based on review comments ( Follow-Up of: 714977c )
2026-01-11 00:06:57 openshift/operator-framework-operator-controller@4f83cc5 Kui Wang UPSTREAM: <carry>: Update OwnSingle template to use spec.config.inline.watchNamespace
2026-01-11 00:06:58 openshift/operator-framework-operator-controller@4d30817 Camila Macedo UPSTREAM: <carry>: [OTE]: Add webhook cleanup validation on extension uninstall
2026-01-11 00:06:59 openshift/operator-framework-operator-controller@82b00b6 Kui Wang UPSTREAM: <carry>: Add [OTP] to migrated cases
2026-01-11 00:07:00 openshift/operator-framework-operator-controller@d55f4c9 Camila Macedo UPSTREAM: <carry>: [OTE]: Upgrade dependencies used
2026-01-11 00:07:01 openshift/operator-framework-operator-controller@ce1343e Camila Macedo UPSTREAM: <carry>: fix(OTE): fix OpenShift Kubernetes replace version format
2026-01-11 00:07:02 openshift/operator-framework-operator-controller@a04938e Camila Macedo UPSTREAM: <carry>: [Default Catalog Tests] Upgrade go 1.24.6 and dependencies
2026-01-11 00:07:03 openshift/operator-framework-operator-controller@462a74e Kui Wang UPSTREAM: <carry>: add disconnected environment support with custom prow job for migrated qe cases
2026-01-11 00:07:04 openshift/operator-framework-operator-controller@dd2ba88 Jian Zhang UPSTREAM: <carry>: migrate jiazha test cases to OTE
2026-01-11 00:07:04 openshift/operator-framework-operator-controller@fac0d12 Xia Zhao UPSTREAM: <carry>: migrate clustercatalog case to ote
2026-01-11 00:07:05 openshift/operator-framework-operator-controller@55b9b02 Kui Wang UPSTREAM: <carry>: migrate olmv1 QE stress cases
2026-01-11 00:07:06 openshift/operator-framework-operator-controller@958e4fb Todd Short UPSTREAM: <carry>: Use busybox/httpd to simulate probes
2026-01-11 00:07:06 openshift/operator-framework-operator-controller@f214401 Xia Zhao UPSTREAM: <carry>: migrate olmv1 QE cases
2026-01-11 00:07:07 openshift/operator-framework-operator-controller@62e2f4c Kui Wang UPSTREAM: <carry>: add agent for olmv1 qe cases
2026-01-11 00:07:08 openshift/operator-framework-operator-controller@282bace Todd Short UPSTREAM: <carry>: Disable upstream PodDisruptionBudget
2026-01-11 00:07:08 openshift/operator-framework-operator-controller@46ada0c Rashmi Gottipati UPSTREAM: <carry>: Add AGENTS.md for AI code contributions
2026-01-11 00:07:09 openshift/operator-framework-operator-controller@fa7ecec Rashmi Gottipati UPSTREAM: <carry>: address review comments through addl prompts
2026-01-11 00:07:10 openshift/operator-framework-operator-controller@b91e2c2 Rashmi Gottipati UPSTREAM: <carry>: addressing some more review comments
2026-01-11 00:07:10 openshift/operator-framework-operator-controller@2aa16d9 Rashmi Gottipati UPSTREAM: <carry>: remove DCO line
2026-01-11 00:07:11 openshift/operator-framework-operator-controller@ca2289b Bruno Andrade UPSTREAM: <carry>: migrate bandrade test cases to OTE
2026-01-11 00:07:12 openshift/operator-framework-operator-controller@a84bc62 Bruno Andrade UPSTREAM: <carry>: update metadata
2026-01-11 00:07:12 openshift/operator-framework-operator-controller@72811de Bruno Andrade UPSTREAM: <carry>: remove originalName
2026-01-11 00:07:13 openshift/operator-framework-operator-controller@38385e7 Jian Zhang UPSTREAM: <carry>: update 80458's timeout to 180s
2026-01-11 00:07:13 openshift/operator-framework-operator-controller@f35df2b Jian Zhang UPSTREAM: <carry>: update 83026 to specify the clustercatalog
2026-01-11 00:07:14 openshift/operator-framework-operator-controller@48f7256 Catherine Chan-Tse UPSTREAM: <carry>: Update to golang 1.25 and ocp 4.22
2026-01-13 10:49:41 openshift/operator-framework-operator-controller@9fbe333 Predrag Knezevic UPSTREAM: <carry>: Use oc client for running e2e tests
2026-01-14 17:38:29 openshift/operator-framework-operator-controller@32e334f Predrag Knezevic UPSTREAM: <carry>: Run upstream e2e tests tagged with @catalogd-update
2026-01-15 14:05:34 openshift/operator-framework-operator-controller@f80683f Kui Wang UPSTREAM: <carry>: enhance case to make it more stable

This pull request is expected to merge without any human intervention. If tests are failing here, changes must land upstream to fix any issues so that future downstreaming efforts succeed.

/cc @openshift/openshift-team-operator-framework

… of CI (#2411)

* Add a Makefile target and start running the API diff linter as part of CI.

* Update hack/api-lint-diff/run.sh

Co-authored-by: Todd Short <tmshort@users.noreply.github.com>

* Run for pull requests only

* Update .github/workflows/api-diff-lint.yaml

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

* Update .github/workflows/api-diff-lint.yaml

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

* Update hack/api-lint-diff/run.sh

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

* Update Makefile

Co-authored-by: Predrag Knezevic <pedjak@gmail.com>

* Apply suggestion from to improve branch check

* Apply suggestion from @camilamacedo86

By Copilot:

When sourcing .bingo/variables.env, the file contains GOBIN=${GOBIN:=$(go env GOBIN)} which requires the go command to be available. While this works in CI after the setup-go step, the script might fail if run locally without Go in PATH. Consider adding a check that Go is available before sourcing, or handle the source operation with error checking using source .bingo/variables.env 2>/dev/null || true and validate the variable afterward.

* Update .github/workflows/api-diff-lint.yaml

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

---------

Co-authored-by: Todd Short <tmshort@users.noreply.github.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Predrag Knezevic <pedjak@gmail.com>
@openshift-bot openshift-bot added tide/merge-method-merge Denotes a PR that should use a standard merge by tide when it merges. kind/sync approved Indicates a PR has been approved by an approver from all required OWNERS files. lgtm Indicates that a PR is ready to be merged. labels Jan 13, 2026
@openshift-ci-robot openshift-ci-robot added the jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. label Jan 13, 2026
@openshift-ci-robot
Copy link

@openshift-bot: This pull request explicitly references no jira issue.

Details

In response to this:

The downstream repository has been updated with the following following upstream commits:

Date Commit Author Message
2026-01-12 11:20:49 operator-framework/operator-controller@1fa4169 Camila Macedo 🌱 Add a Makefile target and start running the API diff linter as part of CI (#2411)

The vendor/ directory has been updated and the following commits were carried:

Date Commit Author Message
2026-01-11 00:06:49 openshift/operator-framework-operator-controller@12531f0 dtfranz UPSTREAM: <carry>: Add OpenShift specific files
2026-01-11 00:06:51 openshift/operator-framework-operator-controller@5c5685a Camila Macedo UPSTREAM: <carry>: Add new tests for single/own namespaces install modes
2026-01-11 00:06:51 openshift/operator-framework-operator-controller@dd0ebd6 Camila Macedo UPSTREAM: <carry>: Upgrade OCP image from 4.20 to 4.21
2026-01-11 00:06:52 openshift/operator-framework-operator-controller@063feb9 Camila Macedo UPSTREAM: <carry>: [Default Catalog Tests] - Change logic to get ocp images from openshift/catalogd/manifests.yaml
2026-01-11 00:06:53 openshift/operator-framework-operator-controller@42664da Todd Short UPSTREAM: <carry>: Update OCP catalogs to v4.21
2026-01-11 00:06:53 openshift/operator-framework-operator-controller@e5c6d5e Kui Wang UPSTREAM: <carry>: support singleown cases in disconnected
2026-01-11 00:06:54 openshift/operator-framework-operator-controller@9ca54bf Kui Wang UPSTREAM: <carry>: fix cases 81696 and 74618 for product code changes
2026-01-11 00:06:55 openshift/operator-framework-operator-controller@45f9ba3 Camila Macedo UPSTREAM: <carry>: Define Default timeouts and apply their usage accross to avoid flakes
2026-01-11 00:06:55 openshift/operator-framework-operator-controller@7b52396 Todd Short UPSTREAM: <carry>: Update to new feature-gate options in helm
2026-01-11 00:06:56 openshift/operator-framework-operator-controller@b935806 Camila Macedo UPSTREAM: <carry>: Fix flake for single/own ns tests by ensuring uniquess and waiting for k8s cleanups
2026-01-11 00:06:57 openshift/operator-framework-operator-controller@5e74730 Camila Macedo UPSTREAM: <carry>: [OTE]: Enhance single/own ns based on review comments ( Follow-Up of: 714977c )
2026-01-11 00:06:57 openshift/operator-framework-operator-controller@4f83cc5 Kui Wang UPSTREAM: <carry>: Update OwnSingle template to use spec.config.inline.watchNamespace
2026-01-11 00:06:58 openshift/operator-framework-operator-controller@4d30817 Camila Macedo UPSTREAM: <carry>: [OTE]: Add webhook cleanup validation on extension uninstall
2026-01-11 00:06:59 openshift/operator-framework-operator-controller@82b00b6 Kui Wang UPSTREAM: <carry>: Add [OTP] to migrated cases
2026-01-11 00:07:00 openshift/operator-framework-operator-controller@d55f4c9 Camila Macedo UPSTREAM: <carry>: [OTE]: Upgrade dependencies used
2026-01-11 00:07:01 openshift/operator-framework-operator-controller@ce1343e Camila Macedo UPSTREAM: <carry>: fix(OTE): fix OpenShift Kubernetes replace version format
2026-01-11 00:07:02 openshift/operator-framework-operator-controller@a04938e Camila Macedo UPSTREAM: <carry>: [Default Catalog Tests] Upgrade go 1.24.6 and dependencies
2026-01-11 00:07:03 openshift/operator-framework-operator-controller@462a74e Kui Wang UPSTREAM: <carry>: add disconnected environment support with custom prow job for migrated qe cases
2026-01-11 00:07:04 openshift/operator-framework-operator-controller@dd2ba88 Jian Zhang UPSTREAM: <carry>: migrate jiazha test cases to OTE
2026-01-11 00:07:04 openshift/operator-framework-operator-controller@fac0d12 Xia Zhao UPSTREAM: <carry>: migrate clustercatalog case to ote
2026-01-11 00:07:05 openshift/operator-framework-operator-controller@55b9b02 Kui Wang UPSTREAM: <carry>: migrate olmv1 QE stress cases
2026-01-11 00:07:06 openshift/operator-framework-operator-controller@958e4fb Todd Short UPSTREAM: <carry>: Use busybox/httpd to simulate probes
2026-01-11 00:07:06 openshift/operator-framework-operator-controller@f214401 Xia Zhao UPSTREAM: <carry>: migrate olmv1 QE cases
2026-01-11 00:07:07 openshift/operator-framework-operator-controller@62e2f4c Kui Wang UPSTREAM: <carry>: add agent for olmv1 qe cases
2026-01-11 00:07:08 openshift/operator-framework-operator-controller@282bace Todd Short UPSTREAM: <carry>: Disable upstream PodDisruptionBudget
2026-01-11 00:07:08 openshift/operator-framework-operator-controller@46ada0c Rashmi Gottipati UPSTREAM: <carry>: Add AGENTS.md for AI code contributions
2026-01-11 00:07:09 openshift/operator-framework-operator-controller@fa7ecec Rashmi Gottipati UPSTREAM: <carry>: address review comments through addl prompts
2026-01-11 00:07:10 openshift/operator-framework-operator-controller@b91e2c2 Rashmi Gottipati UPSTREAM: <carry>: addressing some more review comments
2026-01-11 00:07:10 openshift/operator-framework-operator-controller@2aa16d9 Rashmi Gottipati UPSTREAM: <carry>: remove DCO line
2026-01-11 00:07:11 openshift/operator-framework-operator-controller@ca2289b Bruno Andrade UPSTREAM: <carry>: migrate bandrade test cases to OTE
2026-01-11 00:07:12 openshift/operator-framework-operator-controller@a84bc62 Bruno Andrade UPSTREAM: <carry>: update metadata
2026-01-11 00:07:12 openshift/operator-framework-operator-controller@72811de Bruno Andrade UPSTREAM: <carry>: remove originalName
2026-01-11 00:07:13 openshift/operator-framework-operator-controller@38385e7 Jian Zhang UPSTREAM: <carry>: update 80458's timeout to 180s
2026-01-11 00:07:13 openshift/operator-framework-operator-controller@f35df2b Jian Zhang UPSTREAM: <carry>: update 83026 to specify the clustercatalog
2026-01-11 00:07:14 openshift/operator-framework-operator-controller@48f7256 Catherine Chan-Tse UPSTREAM: <carry>: Update to golang 1.25 and ocp 4.22
2026-01-13 10:49:41 openshift/operator-framework-operator-controller@9fbe333 Predrag Knezevic UPSTREAM: <carry>: Use oc client for running e2e tests

This pull request is expected to merge without any human intervention. If tests are failing here, changes must land upstream to fix any issues so that future downstreaming efforts succeed.

/cc @openshift/openshift-team-operator-framework

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-ci
Copy link
Contributor

openshift-ci bot commented Jan 13, 2026

@openshift-bot: GitHub didn't allow me to request PR reviews from the following users: openshift/openshift-team-operator-framework.

Note that only openshift members and repo collaborators can review this PR, and authors cannot review their own PRs.

Details

In response to this:

The downstream repository has been updated with the following following upstream commits:

Date Commit Author Message
2026-01-12 11:20:49 operator-framework/operator-controller@1fa4169 Camila Macedo 🌱 Add a Makefile target and start running the API diff linter as part of CI (#2411)

The vendor/ directory has been updated and the following commits were carried:

Date Commit Author Message
2026-01-11 00:06:49 openshift/operator-framework-operator-controller@12531f0 dtfranz UPSTREAM: <carry>: Add OpenShift specific files
2026-01-11 00:06:51 openshift/operator-framework-operator-controller@5c5685a Camila Macedo UPSTREAM: <carry>: Add new tests for single/own namespaces install modes
2026-01-11 00:06:51 openshift/operator-framework-operator-controller@dd0ebd6 Camila Macedo UPSTREAM: <carry>: Upgrade OCP image from 4.20 to 4.21
2026-01-11 00:06:52 openshift/operator-framework-operator-controller@063feb9 Camila Macedo UPSTREAM: <carry>: [Default Catalog Tests] - Change logic to get ocp images from openshift/catalogd/manifests.yaml
2026-01-11 00:06:53 openshift/operator-framework-operator-controller@42664da Todd Short UPSTREAM: <carry>: Update OCP catalogs to v4.21
2026-01-11 00:06:53 openshift/operator-framework-operator-controller@e5c6d5e Kui Wang UPSTREAM: <carry>: support singleown cases in disconnected
2026-01-11 00:06:54 openshift/operator-framework-operator-controller@9ca54bf Kui Wang UPSTREAM: <carry>: fix cases 81696 and 74618 for product code changes
2026-01-11 00:06:55 openshift/operator-framework-operator-controller@45f9ba3 Camila Macedo UPSTREAM: <carry>: Define Default timeouts and apply their usage accross to avoid flakes
2026-01-11 00:06:55 openshift/operator-framework-operator-controller@7b52396 Todd Short UPSTREAM: <carry>: Update to new feature-gate options in helm
2026-01-11 00:06:56 openshift/operator-framework-operator-controller@b935806 Camila Macedo UPSTREAM: <carry>: Fix flake for single/own ns tests by ensuring uniquess and waiting for k8s cleanups
2026-01-11 00:06:57 openshift/operator-framework-operator-controller@5e74730 Camila Macedo UPSTREAM: <carry>: [OTE]: Enhance single/own ns based on review comments ( Follow-Up of: 714977c )
2026-01-11 00:06:57 openshift/operator-framework-operator-controller@4f83cc5 Kui Wang UPSTREAM: <carry>: Update OwnSingle template to use spec.config.inline.watchNamespace
2026-01-11 00:06:58 openshift/operator-framework-operator-controller@4d30817 Camila Macedo UPSTREAM: <carry>: [OTE]: Add webhook cleanup validation on extension uninstall
2026-01-11 00:06:59 openshift/operator-framework-operator-controller@82b00b6 Kui Wang UPSTREAM: <carry>: Add [OTP] to migrated cases
2026-01-11 00:07:00 openshift/operator-framework-operator-controller@d55f4c9 Camila Macedo UPSTREAM: <carry>: [OTE]: Upgrade dependencies used
2026-01-11 00:07:01 openshift/operator-framework-operator-controller@ce1343e Camila Macedo UPSTREAM: <carry>: fix(OTE): fix OpenShift Kubernetes replace version format
2026-01-11 00:07:02 openshift/operator-framework-operator-controller@a04938e Camila Macedo UPSTREAM: <carry>: [Default Catalog Tests] Upgrade go 1.24.6 and dependencies
2026-01-11 00:07:03 openshift/operator-framework-operator-controller@462a74e Kui Wang UPSTREAM: <carry>: add disconnected environment support with custom prow job for migrated qe cases
2026-01-11 00:07:04 openshift/operator-framework-operator-controller@dd2ba88 Jian Zhang UPSTREAM: <carry>: migrate jiazha test cases to OTE
2026-01-11 00:07:04 openshift/operator-framework-operator-controller@fac0d12 Xia Zhao UPSTREAM: <carry>: migrate clustercatalog case to ote
2026-01-11 00:07:05 openshift/operator-framework-operator-controller@55b9b02 Kui Wang UPSTREAM: <carry>: migrate olmv1 QE stress cases
2026-01-11 00:07:06 openshift/operator-framework-operator-controller@958e4fb Todd Short UPSTREAM: <carry>: Use busybox/httpd to simulate probes
2026-01-11 00:07:06 openshift/operator-framework-operator-controller@f214401 Xia Zhao UPSTREAM: <carry>: migrate olmv1 QE cases
2026-01-11 00:07:07 openshift/operator-framework-operator-controller@62e2f4c Kui Wang UPSTREAM: <carry>: add agent for olmv1 qe cases
2026-01-11 00:07:08 openshift/operator-framework-operator-controller@282bace Todd Short UPSTREAM: <carry>: Disable upstream PodDisruptionBudget
2026-01-11 00:07:08 openshift/operator-framework-operator-controller@46ada0c Rashmi Gottipati UPSTREAM: <carry>: Add AGENTS.md for AI code contributions
2026-01-11 00:07:09 openshift/operator-framework-operator-controller@fa7ecec Rashmi Gottipati UPSTREAM: <carry>: address review comments through addl prompts
2026-01-11 00:07:10 openshift/operator-framework-operator-controller@b91e2c2 Rashmi Gottipati UPSTREAM: <carry>: addressing some more review comments
2026-01-11 00:07:10 openshift/operator-framework-operator-controller@2aa16d9 Rashmi Gottipati UPSTREAM: <carry>: remove DCO line
2026-01-11 00:07:11 openshift/operator-framework-operator-controller@ca2289b Bruno Andrade UPSTREAM: <carry>: migrate bandrade test cases to OTE
2026-01-11 00:07:12 openshift/operator-framework-operator-controller@a84bc62 Bruno Andrade UPSTREAM: <carry>: update metadata
2026-01-11 00:07:12 openshift/operator-framework-operator-controller@72811de Bruno Andrade UPSTREAM: <carry>: remove originalName
2026-01-11 00:07:13 openshift/operator-framework-operator-controller@38385e7 Jian Zhang UPSTREAM: <carry>: update 80458's timeout to 180s
2026-01-11 00:07:13 openshift/operator-framework-operator-controller@f35df2b Jian Zhang UPSTREAM: <carry>: update 83026 to specify the clustercatalog
2026-01-11 00:07:14 openshift/operator-framework-operator-controller@48f7256 Catherine Chan-Tse UPSTREAM: <carry>: Update to golang 1.25 and ocp 4.22
2026-01-13 10:49:41 openshift/operator-framework-operator-controller@9fbe333 Predrag Knezevic UPSTREAM: <carry>: Use oc client for running e2e tests

This pull request is expected to merge without any human intervention. If tests are failing here, changes must land upstream to fix any issues so that future downstreaming efforts succeed.

/cc @openshift/openshift-team-operator-framework

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@openshift-ci
Copy link
Contributor

openshift-ci bot commented Jan 13, 2026

[APPROVALNOTIFIER] This PR is APPROVED

Approval requirements bypassed by manually added approval.

This pull-request has been approved by: openshift-bot

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

1 similar comment
@openshift-ci
Copy link
Contributor

openshift-ci bot commented Jan 13, 2026

[APPROVALNOTIFIER] This PR is APPROVED

Approval requirements bypassed by manually added approval.

This pull-request has been approved by: openshift-bot

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

camilamacedo86 and others added 2 commits January 13, 2026 16:41
…viceAccount for revision operations (#2429)

* (feat): [Boxcutter] Use ClusterExtension ServiceAccount for revision operations

Implement serviceAccount-scoped token-based authentication for
ClusterExtensionRevision controller using annotation-based configuration.

- Add RevisionEngineFactory with CreateRevisionEngine(ctx, rev) interface
- Read ServiceAccount from annotations (no ClusterExtension dependency)
- Token-based auth using TokenInjectingRoundTripper
- ServiceAccount name and namespace in annotations for observability
- TrackingCache uses global client for caching/cleanup
- Comprehensive error path tests

ClusterExtensionRevision can exist independently.
Easy mode impersonation deferred until API is finalized.

Assisted-by: Cursor

* (doc) Add godoc comments to label constants

Adds documentation comments to all label/annotation constants explaining:
- What each constant represents
- Where they are applied (labels vs annotations)
- ServiceAccount constants document their relationship to ClusterExtension spec

Addresses code review feedback for improved maintainability.

* (fix) Add ClusterExtensionRevision permissions to upgrade test RBAC

The upgrade test ServiceAccount needs permissions to manage
ClusterExtensionRevisions when BoxcutterRuntime is enabled.
Without these permissions, the upgraded controller cannot create
or update ClusterExtensionRevision resources, causing the
ClusterExtension to fail reconciliation after upgrade.

* review changes

* (fix): e2e: add bind/escalate verbs for Boxcutter Server-Side Apply

Add `bind` and `escalate` RBAC verbs to e2e test ServiceAccount to support
Boxcutter applier's use of Kubernetes Server-Side Apply (SSA).

Experimental e2e tests fail when Boxcutter uses ServiceAccount-scoped clients
to apply bundle RBAC resources (ClusterRoles and ClusterRoleBindings):

```
clusterrolebindings.rbac.authorization.k8s.io is forbidden:
User "system:serviceaccount:olmv1-e2e:olm-sa" cannot bind ClusterRole:
RBAC: attempting to grant RBAC permissions not currently held
```

- Uses helm.sh/helm/v3 library
- Applies resources with traditional CREATE/UPDATE operations
- Kubernetes RBAC allows ClusterRoleBinding creation when the ServiceAccount
  already has all the permissions being granted (permission matching)
- **Works WITHOUT `bind`/`escalate` verbs** ✅

- Uses pkg.package-operator.run/boxcutter machinery
- Applies resources with **Server-Side Apply (SSA)** (`client.Apply`)
- SSA enforces field-level ownership and **stricter RBAC enforcement**
- Kubernetes API server **requires explicit `bind` verb** for ClusterRoleBindings
- Permission matching fallback does NOT work reliably with SSA
- **REQUIRES `bind`/`escalate` verbs** ❌

Validated by running actual tests:

**Test 1: Main branch standard-e2e (Helm, NO bind/escalate)**
```bash
make test-e2e
```
Result: ✅ PASS (21 scenarios passed)

**Test 2: PR branch experimental-e2e (Boxcutter, NO bind/escalate)**
```bash
make test-experimental-e2e
```
Result: ❌ FAIL (cannot bind ClusterRole error)

**Test 3: PR branch experimental-e2e (Boxcutter, WITH bind/escalate)**
Result: ✅ PASS (all tests pass)

Add `bind` and `escalate` verbs to the e2e test RBAC template:

```yaml
- apiGroups: ["rbac.authorization.k8s.io"]
  resources: [clusterroles, roles, clusterrolebindings, rolebindings]
  verbs: [ update, create, list, watch, get, delete, patch, bind, escalate ]
```

These verbs allow the ServiceAccount to:
- `bind`: Create ClusterRoleBindings that reference roles with permissions
  the ServiceAccount doesn't have
- `escalate`: Create ClusterRoles with permissions the ServiceAccount doesn't have

This is the documented requirement in `docs/concepts/permission-model.md` for
extension installers and aligns with Kubernetes RBAC best practices.

1. **Required for SSA**: Server-Side Apply has stricter RBAC enforcement
2. **Documented requirement**: OLMv1 docs specify bind/escalate as proper approach
3. **Industry best practice**: Operator installers should have these verbs
4. **Supports all operators**: Not just test-operator with matching permissions
5. **Maintains SSA benefits**: Field ownership, conflict resolution, GitOps support

- Kubernetes RBAC: https://kubernetes.io/docs/reference/access-authn-authz/rbac/#privilege-escalation-prevention-and-bootstrapping
- OLMv1 Permission Model: docs/concepts/permission-model.md
- Boxcutter machinery: pkg.package-operator.run/boxcutter/machinery (uses client.Apply)
- Testing evidence: FINAL_TESTED_ANSWER.md, SERVER_SIDE_APPLY_ANSWER.md

Tested-by: Actual e2e test runs comparing Helm vs Boxcutter behavior
Signed-off-by: Camila <camil@example.com>

* Split rbac phase into two

Signed-off-by: Per Goncalves da Silva <pegoncal@redhat.com>

---------

Signed-off-by: Camila <camil@example.com>
Signed-off-by: Per Goncalves da Silva <pegoncal@redhat.com>
Co-authored-by: Per Goncalves da Silva <pegoncal@redhat.com>
Updating `ClusterExtension` with duplicate entry under `.status.activeRevisions` fails.
Thus, we repopulate it from the installed and rolling out revisions.
@openshift-ci openshift-ci bot removed the lgtm Indicates that a PR is ready to be merged. label Jan 14, 2026
dependabot bot and others added 2 commits January 14, 2026 07:20
Bumps [github.com/sigstore/fulcio](https://github.com/sigstore/fulcio) from 1.7.1 to 1.8.5.
- [Release notes](https://github.com/sigstore/fulcio/releases)
- [Changelog](https://github.com/sigstore/fulcio/blob/main/CHANGELOG.md)
- [Commits](sigstore/fulcio@v1.7.1...v1.8.5)

---
updated-dependencies:
- dependency-name: github.com/sigstore/fulcio
  dependency-version: 1.8.5
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
- Change Apply() to return only error instead of (bool, string, error),
  removing status interpretation logic from the applier. ClusterExtensionRevision conditions
  are already mirrored to ClusterExtension.
- Change ApplyBundleWithBoxcutter to accept a function instead of an
  interface, making unit tests simpler by allowing inline function mocks

Co-authored-by: Claude <noreply@anthropic.com>
@openshift-bot openshift-bot added the lgtm Indicates that a PR is ready to be merged. label Jan 15, 2026
@openshift-ci openshift-ci bot removed the lgtm Indicates that a PR is ready to be merged. label Jan 15, 2026
@jianzhangbjz
Copy link
Member

/verified bypass

@openshift-ci-robot openshift-ci-robot added the verified Signifies that the PR passed pre-merge verification criteria label Jan 15, 2026
@openshift-ci-robot
Copy link

@jianzhangbjz: The verified label has been added.

Details

In response to this:

/verified bypass

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-bot openshift-bot added the lgtm Indicates that a PR is ready to be merged. label Jan 15, 2026
@openshift-ci-robot openshift-ci-robot removed the verified Signifies that the PR passed pre-merge verification criteria label Jan 15, 2026
@openshift-ci-robot
Copy link

@openshift-bot: This pull request explicitly references no jira issue.

Details

In response to this:

The downstream repository has been updated with the following following upstream commits:

Date Commit Author Message
2026-01-14 14:37:46 operator-framework/operator-controller@dc20dfb Predrag Knezevic Simplify Boxcutter applier interface (#2446)
2026-01-14 07:20:02 operator-framework/operator-controller@347be32 dependabot[bot] 🌱 Bump github.com/sigstore/fulcio from 1.7.1 to 1.8.5 (#2445)
2026-01-13 20:53:30 operator-framework/operator-controller@da9e337 Predrag Knezevic Prevent showing duplicate entry under .status.activeRevisions (#2444)
2026-01-13 16:41:00 operator-framework/operator-controller@049f813 Camila Macedo ✨ (feat): When using Boxcutter feature-gate, use ClusterExtension ServiceAccount for revision operations (#2429)
2026-01-12 11:20:49 operator-framework/operator-controller@1fa4169 Camila Macedo 🌱 Add a Makefile target and start running the API diff linter as part of CI (#2411)

The vendor/ directory has been updated and the following commits were carried:

Date Commit Author Message
2026-01-11 00:06:49 openshift/operator-framework-operator-controller@12531f0 dtfranz UPSTREAM: <carry>: Add OpenShift specific files
2026-01-11 00:06:51 openshift/operator-framework-operator-controller@5c5685a Camila Macedo UPSTREAM: <carry>: Add new tests for single/own namespaces install modes
2026-01-11 00:06:51 openshift/operator-framework-operator-controller@dd0ebd6 Camila Macedo UPSTREAM: <carry>: Upgrade OCP image from 4.20 to 4.21
2026-01-11 00:06:52 openshift/operator-framework-operator-controller@063feb9 Camila Macedo UPSTREAM: <carry>: [Default Catalog Tests] - Change logic to get ocp images from openshift/catalogd/manifests.yaml
2026-01-11 00:06:53 openshift/operator-framework-operator-controller@42664da Todd Short UPSTREAM: <carry>: Update OCP catalogs to v4.21
2026-01-11 00:06:53 openshift/operator-framework-operator-controller@e5c6d5e Kui Wang UPSTREAM: <carry>: support singleown cases in disconnected
2026-01-11 00:06:54 openshift/operator-framework-operator-controller@9ca54bf Kui Wang UPSTREAM: <carry>: fix cases 81696 and 74618 for product code changes
2026-01-11 00:06:55 openshift/operator-framework-operator-controller@45f9ba3 Camila Macedo UPSTREAM: <carry>: Define Default timeouts and apply their usage accross to avoid flakes
2026-01-11 00:06:55 openshift/operator-framework-operator-controller@7b52396 Todd Short UPSTREAM: <carry>: Update to new feature-gate options in helm
2026-01-11 00:06:56 openshift/operator-framework-operator-controller@b935806 Camila Macedo UPSTREAM: <carry>: Fix flake for single/own ns tests by ensuring uniquess and waiting for k8s cleanups
2026-01-11 00:06:57 openshift/operator-framework-operator-controller@5e74730 Camila Macedo UPSTREAM: <carry>: [OTE]: Enhance single/own ns based on review comments ( Follow-Up of: 714977c )
2026-01-11 00:06:57 openshift/operator-framework-operator-controller@4f83cc5 Kui Wang UPSTREAM: <carry>: Update OwnSingle template to use spec.config.inline.watchNamespace
2026-01-11 00:06:58 openshift/operator-framework-operator-controller@4d30817 Camila Macedo UPSTREAM: <carry>: [OTE]: Add webhook cleanup validation on extension uninstall
2026-01-11 00:06:59 openshift/operator-framework-operator-controller@82b00b6 Kui Wang UPSTREAM: <carry>: Add [OTP] to migrated cases
2026-01-11 00:07:00 openshift/operator-framework-operator-controller@d55f4c9 Camila Macedo UPSTREAM: <carry>: [OTE]: Upgrade dependencies used
2026-01-11 00:07:01 openshift/operator-framework-operator-controller@ce1343e Camila Macedo UPSTREAM: <carry>: fix(OTE): fix OpenShift Kubernetes replace version format
2026-01-11 00:07:02 openshift/operator-framework-operator-controller@a04938e Camila Macedo UPSTREAM: <carry>: [Default Catalog Tests] Upgrade go 1.24.6 and dependencies
2026-01-11 00:07:03 openshift/operator-framework-operator-controller@462a74e Kui Wang UPSTREAM: <carry>: add disconnected environment support with custom prow job for migrated qe cases
2026-01-11 00:07:04 openshift/operator-framework-operator-controller@dd2ba88 Jian Zhang UPSTREAM: <carry>: migrate jiazha test cases to OTE
2026-01-11 00:07:04 openshift/operator-framework-operator-controller@fac0d12 Xia Zhao UPSTREAM: <carry>: migrate clustercatalog case to ote
2026-01-11 00:07:05 openshift/operator-framework-operator-controller@55b9b02 Kui Wang UPSTREAM: <carry>: migrate olmv1 QE stress cases
2026-01-11 00:07:06 openshift/operator-framework-operator-controller@958e4fb Todd Short UPSTREAM: <carry>: Use busybox/httpd to simulate probes
2026-01-11 00:07:06 openshift/operator-framework-operator-controller@f214401 Xia Zhao UPSTREAM: <carry>: migrate olmv1 QE cases
2026-01-11 00:07:07 openshift/operator-framework-operator-controller@62e2f4c Kui Wang UPSTREAM: <carry>: add agent for olmv1 qe cases
2026-01-11 00:07:08 openshift/operator-framework-operator-controller@282bace Todd Short UPSTREAM: <carry>: Disable upstream PodDisruptionBudget
2026-01-11 00:07:08 openshift/operator-framework-operator-controller@46ada0c Rashmi Gottipati UPSTREAM: <carry>: Add AGENTS.md for AI code contributions
2026-01-11 00:07:09 openshift/operator-framework-operator-controller@fa7ecec Rashmi Gottipati UPSTREAM: <carry>: address review comments through addl prompts
2026-01-11 00:07:10 openshift/operator-framework-operator-controller@b91e2c2 Rashmi Gottipati UPSTREAM: <carry>: addressing some more review comments
2026-01-11 00:07:10 openshift/operator-framework-operator-controller@2aa16d9 Rashmi Gottipati UPSTREAM: <carry>: remove DCO line
2026-01-11 00:07:11 openshift/operator-framework-operator-controller@ca2289b Bruno Andrade UPSTREAM: <carry>: migrate bandrade test cases to OTE
2026-01-11 00:07:12 openshift/operator-framework-operator-controller@a84bc62 Bruno Andrade UPSTREAM: <carry>: update metadata
2026-01-11 00:07:12 openshift/operator-framework-operator-controller@72811de Bruno Andrade UPSTREAM: <carry>: remove originalName
2026-01-11 00:07:13 openshift/operator-framework-operator-controller@38385e7 Jian Zhang UPSTREAM: <carry>: update 80458's timeout to 180s
2026-01-11 00:07:13 openshift/operator-framework-operator-controller@f35df2b Jian Zhang UPSTREAM: <carry>: update 83026 to specify the clustercatalog
2026-01-11 00:07:14 openshift/operator-framework-operator-controller@48f7256 Catherine Chan-Tse UPSTREAM: <carry>: Update to golang 1.25 and ocp 4.22
2026-01-13 10:49:41 openshift/operator-framework-operator-controller@9fbe333 Predrag Knezevic UPSTREAM: <carry>: Use oc client for running e2e tests
2026-01-14 17:38:29 openshift/operator-framework-operator-controller@32e334f Predrag Knezevic UPSTREAM: <carry>: Run upstream e2e tests tagged with @catalogd-update

This pull request is expected to merge without any human intervention. If tests are failing here, changes must land upstream to fix any issues so that future downstreaming efforts succeed.

/cc @openshift/openshift-team-operator-framework

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

perdasilva and others added 2 commits January 15, 2026 10:15
Signed-off-by: Per Goncalves da Silva <pegoncal@redhat.com>
Co-authored-by: Per Goncalves da Silva <pegoncal@redhat.com>
Bumps [pymdown-extensions](https://github.com/facelessuser/pymdown-extensions) from 10.19.1 to 10.20.
- [Release notes](https://github.com/facelessuser/pymdown-extensions/releases)
- [Commits](facelessuser/pymdown-extensions@10.19.1...10.20)

---
updated-dependencies:
- dependency-name: pymdown-extensions
  dependency-version: '10.20'
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
@openshift-ci openshift-ci bot removed the lgtm Indicates that a PR is ready to be merged. label Jan 16, 2026
Xia-Zhao-rh and others added 19 commits January 16, 2026 03:04
Signed-off-by: Todd Short <todd.short@me.com>
Signed-off-by: Rashmi Gottipati <rgottipa@redhat.com>
Signed-off-by: Rashmi Gottipati <rgottipa@redhat.com>
Signed-off-by: Rashmi Gottipati <rgottipa@redhat.com>
Signed-off-by: Rashmi Gottipati <rgottipa@redhat.com>
Expose docker-registry to e2e test code by creating Openshift route
Merge of openshift@9fbe333
enabled proper exposure of docker-registry to upstream e2e tests. Thus, we are now able to run downstream the tests tagged
with `@catalogd-update`
@openshift-bot openshift-bot added the lgtm Indicates that a PR is ready to be merged. label Jan 16, 2026
@openshift-ci openshift-ci bot removed the lgtm Indicates that a PR is ready to be merged. label Jan 16, 2026
@Xia-Zhao-rh
Copy link
Contributor

/verified by @Xia-Zhao-rh

@openshift-ci-robot openshift-ci-robot added the verified Signifies that the PR passed pre-merge verification criteria label Jan 16, 2026
@openshift-ci-robot
Copy link

@Xia-Zhao-rh: This PR has been marked as verified by @Xia-Zhao-rh.

Details

In response to this:

/verified by @Xia-Zhao-rh

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@jianzhangbjz
Copy link
Member

/lgtm

@openshift-ci openshift-ci bot added the lgtm Indicates that a PR is ready to be merged. label Jan 16, 2026
@openshift-ci
Copy link
Contributor

openshift-ci bot commented Jan 16, 2026

@openshift-bot: all tests passed!

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

@openshift-merge-bot openshift-merge-bot bot merged commit dcbfaf2 into openshift:main Jan 16, 2026
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. kind/sync lgtm Indicates that a PR is ready to be merged. tide/merge-method-merge Denotes a PR that should use a standard merge by tide when it merges. verified Signifies that the PR passed pre-merge verification criteria

Projects

None yet

Development

Successfully merging this pull request may close these issues.