Skip to content

Remove images from TEC definition & run watchers independently of TECs#246

Open
Jakob-Naucke wants to merge 3 commits intotrusted-execution-clusters:mainfrom
Jakob-Naucke:decouple-tec-pcr-compute
Open

Remove images from TEC definition & run watchers independently of TECs#246
Jakob-Naucke wants to merge 3 commits intotrusted-execution-clusters:mainfrom
Jakob-Naucke:decouple-tec-pcr-compute

Conversation

@Jakob-Naucke
Copy link
Copy Markdown
Contributor

Move trusteeImage etc. out of the TEC CRD. Treat them as
operator-wide, and always use RELATED_IMAGE_TRUSTEE etc. as reference
instead of as fallback.

Fixes: #215

Watch ApprovedImages and compute reference values independently of a
TEC existing. Adopt ApprovedImages from the TEC in order to include
them in uninstallation. Have PCR computation jobs owned by the
ApprovedImages. This avoids conflicting watchers on ApprovedImages
while using a simple flow.

Fixes: #216

Move trusteeImage etc. out of the TEC CRD. Treat them as
operator-wide, and always use RELATED_IMAGE_TRUSTEE etc. as reference
instead of as fallback.

Fixes: trusted-execution-clusters#215

Signed-off-by: Jakob Naucke <jnaucke@redhat.com>
@Jakob-Naucke Jakob-Naucke requested a review from alicefr April 23, 2026 17:34
@openshift-ci
Copy link
Copy Markdown

openshift-ci Bot commented Apr 23, 2026

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: Jakob-Naucke

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

Signed-off-by: Jakob Naucke <jnaucke@redhat.com>
@Jakob-Naucke Jakob-Naucke force-pushed the decouple-tec-pcr-compute branch from 09bd163 to 70daeb6 Compare April 23, 2026 17:52
Watch ApprovedImages and compute reference values independently of a
TEC existing. Adopt ApprovedImages from the TEC in order to include
them in uninstallation. Have PCR computation jobs owned by the
ApprovedImages. This avoids conflicting watchers on ApprovedImages
while using a simple flow.

Fixes: trusted-execution-clusters#216

Signed-off-by: Jakob Naucke <jnaucke@redhat.com>
@Jakob-Naucke Jakob-Naucke force-pushed the decouple-tec-pcr-compute branch from 70daeb6 to 051b57c Compare April 24, 2026 08:47
@Jakob-Naucke
Copy link
Copy Markdown
Contributor Author

Let's see if we can get past login without openshift/release#77892 's changes
/retest

@Jakob-Naucke
Copy link
Copy Markdown
Contributor Author

/retest

@Jakob-Naucke
Copy link
Copy Markdown
Contributor Author

Jakob-Naucke commented Apr 24, 2026

/retest
e: apparently not

@openshift-ci
Copy link
Copy Markdown

openshift-ci Bot commented Apr 24, 2026

@Jakob-Naucke: The following test failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test name Commit Details Required Rerun command
ci/prow/operator-lifecycle-verify 051b57c link true /test operator-lifecycle-verify

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

1 participant