ROX-34110: Turning on ROX_LABEL_BASED_POLICY_SCOPING feature flag - #19987
Conversation
🚀 Build Images ReadyImages are ready for commit ca48bc0. To use with deploy scripts: export MAIN_IMAGE_TAG=4.11.x-741-gca48bc029d |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## master #19987 +/- ##
==========================================
- Coverage 49.61% 49.61% -0.01%
==========================================
Files 2765 2765
Lines 208628 208628
==========================================
- Hits 103509 103508 -1
- Misses 97462 97464 +2
+ Partials 7657 7656 -1
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Sentry. 🚀 New features to boost your workflow:
|
|
/test ocp-4-21-qa-e2e-tests |
|
@AlexVulaj: No presubmit jobs available for stackrox/stackrox@AlexVulaj/ROX-34110-skip-ac-label-tests-openshift DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
cb6a785 to
38d1ce5
Compare
|
/test ocp-4-21-qa-e2e-tests |
There was a problem hiding this comment.
Given the feature flag ROX_LABEL_BASED_POLICY_SCOPING will be required to be set to true before release, some of the changes in this PR will not be required and the recommendation below will be a cleaner fix for the long term:
- Set it to true.
- Add the
ci-release-buildlabel on the PR that implements 1. Ensure CI green. - Merge PR and profit.
If you choose a separate PR to enable the feature flag, then hold back on this one, and then merge this one such that only the IgnoreIfs are removed after your PR to enable is merged. Or implement the recommendation in this one. Either way.
38d1ce5 to
a5c7347
Compare
|
/test ocp-4-21-qa-e2e-tests |
|
The All four label scoping tests passed: |
|
/retest |
Description
The AC label scoping tests (AdmissionControllerTest.groovy) fail on OpenShift when deployed via the operator path. The root cause is that deploy_sensor_via_operator() in tests/e2e/lib.sh does not inject ROX_LABEL_BASED_POLICY_SCOPING into Sensor's environment variables. Without this flag, Sensor's detector rejects namespace-label-scoped policies at pkg/scopecomp/scope.go:75-76, so the Admission Controller never receives them. deploy_central_via_operator() already sets this flag, but the Sensor operator deploy path was missing it.
User-facing documentation
Testing and quality
Automated testing
How I validated my change
The re-enabled Groovy tests will serve as the primary validation. These tests were failing on the OCP qa e2e tests specifically. CI results on this branch (particularly OCP QA e2e runs) need to be inspected to confirm the tests pass with the flag now injected into Sensor.