Skip to content

chore: Make the airgap script work with CI index images - #779

Merged
rm3l merged 1 commit into
redhat-developer:mainfrom
rm3l:fix_make_airgap_script_work_with_ci_index_images
Feb 11, 2025
Merged

chore: Make the airgap script work with CI index images#779
rm3l merged 1 commit into
redhat-developer:mainfrom
rm3l:fix_make_airgap_script_work_with_ci_index_images

Conversation

@rm3l

@rm3l rm3l commented Feb 11, 2025

Copy link
Copy Markdown
Member

Description

This introduces a new '--ci-index' option, which, when set to 'true', will replace all references to the internal Red Hat registries with quay.io when extracting and rebuilding the catalog.

Which issue(s) does this PR fix or relate to

PR acceptance criteria

  • Tests
  • Documentation

How to test changes / Special notes to the reviewer

Example usage:

.rhdh/scripts/prepare-restricted-environment.sh \
	--index-image quay.io/rhdh/iib:next-v4.18-x86_64 \
	--ci-index true \
	--filter-versions '*' \
	--to-registry registry.localhost:5000/my-ns

@openshift-ci

openshift-ci Bot commented Feb 11, 2025

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
Once this PR has been reviewed and has the lgtm label, please ask for approval from rm3l. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

Comment thread .rhdh/scripts/prepare-restricted-environment.sh Fixed
Comment thread .rhdh/scripts/prepare-restricted-environment.sh Fixed
@rm3l
rm3l force-pushed the fix_make_airgap_script_work_with_ci_index_images branch from 416cfdc to 67be90b Compare February 11, 2025 12:56
This introduces a new '--ci-index' option, which, when set to 'true',
will replace all references
to the internal Red Hat registries with quay.io when extracting and rebuilding the catalog.
@rm3l
rm3l force-pushed the fix_make_airgap_script_work_with_ci_index_images branch from 67be90b to 761abb6 Compare February 11, 2025 12:59
@rm3l
rm3l merged commit 64cc1c9 into redhat-developer:main Feb 11, 2025
@rm3l
rm3l deleted the fix_make_airgap_script_work_with_ci_index_images branch February 11, 2025 13:02
rm3l added a commit to rm3l/redhat-developer-hub-operator that referenced this pull request Feb 14, 2025
…oper#779)

This introduces a new '--ci-index' option, which, when set to 'true',
will replace all references
to the internal Red Hat registries with quay.io when extracting and rebuilding the catalog.
rm3l added a commit that referenced this pull request Mar 10, 2025
…eparation script (#796)

* chore: Improve the airgap env preparation script [RHIDP-1442][RHIDP-4415] (#705)

* wip

* Allow to mirror extra-images

* Create IDMS on OCP and various fixes

* Fix issue when pushing to the internal OCP registry

Image names should follow this format: <project>/<name>

* Update prepare-restricted-environment.sh script instead (in a backward compatible manner)

* Default to installing the operator

* Improve usage docs

* Automatically detect and use the internal OCP registry unless --to-registry is set

* Make sure the operand images can be pulles when using the internal OCP registry

It works by adding the pull secrets to the namespace default service account. So it will only work when creating the CR in the operator namespace.
Otherwise, we are displaying the instructions for different namespaces

* Allow to use `oc-mirror` as tool for mirroring

This is useful if users want to explicitly use `oc-mirror` as their
tool of choice and they know they are already on OCP

TBD: this currently does not work with the internal OCP registry when autodetected by the script

* Fix an unbound variable issue

* Fix unbound variable issue

* Update docs

* Use a temporary registry auth file for `skopeo` and `podman`

Otherwise tools like 'skopeo login' will attempt to write to /run,
which might be restricted in CI environments.
This also ensures that the credentials don't conflict with
any existing creds for the same registry.

Co-authored-by: Zbynek Drapela <zdrapela@redhat.com>

* Revert "Use a temporary registry auth file for `skopeo` and `podman`"

This reverts commit c02beca.

* Reapply "Use a temporary registry auth file for `skopeo` and `podman`"

This reverts commit c6dc186.

* Use a temporary registry auth file for `skopeo` and `podman`

Otherwise tools like 'skopeo login' will attempt to write to /run,
which might be restricted in CI environments.

Since the user is required to be logged into the index image registry (and the target mirror registry eventually),
it also makes sure these auth information are not lost when switching to a temporary auth file.

* Disable redirects on the integrated OCP image registry

Otherwise, as depicted in [1], this might cause some 403 errors to be returned to Skopeo.

This fixes the behavior seen on the QE airgap bastion host.

[1] https://access.redhat.com/solutions/6022011

* Fix registry auth creds loading

oc-mirror v1 always loads the docker creds first [1].
But we want to use our own credentials file, which is not possible until oc-mirror v2 (currently tech preview).

[1] https://github.com/openshift/oc-mirror/blob/main/pkg/image/credentials.go

* Allow to filter all versions from the catalog

By specifying `--filter-versions '*'`

* Allow to override the path to the oc-mirror binary

This adds a new option: --oc-mirror-path

Might be useful when troubleshooting issues.

* Provide hint to log into the OCP cluster when neither --to-registry nor --to-dir are specified

* Fix issues with oc-mirror

Because of targetCatalog in the ImageSet,
the catalog image needs to exist in the target registry

* Fix unbound variable issue

* Append the default pull secrets in the catalog source manifest generated by oc-mirror

* Remove note about oc-mirror limitation

* Update docs

* [oc-mirror] Fix target catalog image path in the registry when using the integrated OCP registry

* Fix issues when mirroring with oc-mirror

---------

Co-authored-by: Zbynek Drapela <zdrapela@redhat.com>

* ci: Check install and airgap scripts in CI [RHIDP 5162] (#751)

* Check sh scripts in CI

* Include registry auth creds for know registries by default in the airgap install script

* chore: Make the airgap script work with CI index images (#779)

This introduces a new '--ci-index' option, which, when set to 'true',
will replace all references
to the internal Red Hat registries with quay.io when extracting and rebuilding the catalog.

---------

Co-authored-by: Zbynek Drapela <zdrapela@redhat.com>
Fortune-Ndlovu pushed a commit to Fortune-Ndlovu/rhdh-operator that referenced this pull request Sep 6, 2025
…oper#779)

This introduces a new '--ci-index' option, which, when set to 'true',
will replace all references
to the internal Red Hat registries with quay.io when extracting and rebuilding the catalog.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants