Skip to content

Automated - Update component image digests - #6337

Open
aro-hcp-robot[bot] wants to merge 3 commits into
mainfrom
automated---update-component-image-digests
Open

Automated - Update component image digests#6337
aro-hcp-robot[bot] wants to merge 3 commits into
mainfrom
automated---update-component-image-digests

Conversation

@aro-hcp-robot

@aro-hcp-robot aro-hcp-robot Bot commented Jul 30, 2026

Copy link
Copy Markdown
Contributor

This automated PR updates ARO-HCP container image digests to the latest versions from registries.

Name Old Digest New Digest Tag Date Status
arobit-forwarder c81f949228a0… e8df41b2461b… v5.0.4 2026-07-31 18:54 updated
arobit-mdsd 5c0159feac33… 83b9cbd2662c… 1.43.0-20260730-1 2026-07-30 17:43 updated
hypershift 0a0397b7e1fe… 7581cf404916… latest 2026-07-31 17:56 updated
velero-server a48979677ab5… f0ada3a00630… 1.6.1 2026-07-31 17:20 updated
velero-azure-plugin c4c26fca6614… fb68bef55f03… 1.6.1 2026-07-31 17:15 updated
velero-hypershift-plugin e07251298031… d805fc319982… 1.6.1 2026-07-31 14:45 updated
thanos 6249f7aaadd3… b567818fe608… v0.42.4 2026-07-30 13:37 updated
acm-operator 72b7793fba6c… 09a29a059975… v2.16.3-548 2026-07-31 19:13 updated
acm-mce c8b9aa2f3e0d… 07a34fcadced… v2.11.4-594 2026-07-31 20:36 updated
clusters-service 981637a1e08c… 4394f21f23e3… latest 2026-07-31 08:16 updated
imageSync aa1a693a0d0d… ae24e3c95183… 2b75898 2026-07-31 21:31 updated

Schedule: Monday through Friday at 2 AM UTC
Generated by: periodic-ci-Azure-ARO-HCP-main-image-updater-tooling
Generated at: 2026-07-31T22:32:06+0000

Copilot AI review requested due to automatic review settings July 30, 2026 14:31
@openshift-ci

openshift-ci Bot commented Jul 30, 2026

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: aro-hcp-robot[bot]
Once this PR has been reviewed and has the lgtm label, please assign mmazur for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Note

Copilot could not run the full agentic suite for this review because it was automatically requested on a bot-authored pull request. Request a review from Copilot under Reviewers to retry with the full agentic suite. Improved support for bot-authored pull requests is coming soon.

Updates pinned container image digests across dev environment rendered configs and ACM/MCE Helm charts to roll forward operator bundles and component images.

Changes:

  • Bump ACM/MCE operator bundle digests across dev rendered configs and Helm chart metadata.
  • Update pinned digests/SHAs for hypershift operator, oc-mirror, maestro sidecar nginx, and thanos images in defaults and rendered env configs.
  • Refresh selected MCE operand image digests in the multicluster-engine operator deployment template.

Reviewed changes

Copilot reviewed 11 out of 11 changed files in this pull request and generated 4 comments.

Show a summary per file
File Description
config/rendered/dev/pers/westus3.yaml Updates image digests/SHAs for ACM/MCE bundles and core components in pers westus3 rendered config.
config/rendered/dev/perf/westus3.yaml Updates image digests/SHAs for ACM/MCE bundles and core components in perf westus3 rendered config.
config/rendered/dev/dev/westus3.yaml Updates image digests/SHAs for ACM/MCE bundles and core components in dev westus3 rendered config.
config/rendered/dev/cspr/westus3.yaml Updates image digests/SHAs for ACM/MCE bundles and core components in cspr westus3 rendered config.
config/rendered/dev/ci01/centralus.yaml Updates image digests/SHAs for ACM/MCE bundles and core components in ci01 centralus rendered config.
config/rendered/dev/ci00/centralus.yaml Updates image digests/SHAs for ACM/MCE bundles and core components in ci00 centralus rendered config.
config/config.yaml Updates defaults for hypershift, thanos, maestro sidecar nginx, ACM/MCE bundles, and oc-mirror digests/SHAs.
acm/deploy/helm/multicluster-engine/templates/multicluster-engine-operator.deployment.yaml Updates a couple of operand image digests used by the operator deployment.
acm/deploy/helm/multicluster-engine/Chart.yaml Updates chart source reference to the new MCE bundle digest.
acm/deploy/helm/multicluster-engine-crds/Chart.yaml Updates chart source reference to the new MCE bundle digest.
acm/deploy/helm/multicluster-engine-config/charts/policy/values.yaml Updates governance policy framework addon image digest.
Comments suppressed due to low confidence (1)

config/rendered/dev/dev/westus3.yaml:1

  • Rendered configs still show tag: v0.41.0 with the updated sha. If sha is intended to correspond to a different release (as suggested by the defaults comment in config/config.yaml), the rendered output should be regenerated after fixing the tag/SHA alignment in the source defaults, so that all environments consistently reference the intended thanos version.
acm:

Comment thread config/config.yaml
Comment on lines 609 to +612
registry: arohcpsvcdev.azurecr.io
repository: thanos/thanos
tag: v0.41.0
sha: 6249f7aaadd3695df637fb2eb4cb9a9955611eee691c3970892fe9c0dc3f2db6 # v0.42.2 (2026-07-16 20:22)
sha: b567818fe608067eb0f1d7c2c4fe361e7ad83c8a256234c97685f1d0bf670cc8 # v0.42.4 (2026-07-30 13:37)
Comment thread config/config.yaml
Comment on lines 740 to +743
registry: arohcpsvcdev.azurecr.io
repository: thanos/thanos
tag: v0.41.0
sha: 6249f7aaadd3695df637fb2eb4cb9a9955611eee691c3970892fe9c0dc3f2db6 # v0.42.2 (2026-07-16 20:22)
sha: b567818fe608067eb0f1d7c2c4fe361e7ad83c8a256234c97685f1d0bf670cc8 # v0.42.4 (2026-07-30 13:37)
Comment on lines 1062 to +1065
image:
registry: arohcpsvcdev.azurecr.io
repository: thanos/thanos
sha: 6249f7aaadd3695df637fb2eb4cb9a9955611eee691c3970892fe9c0dc3f2db6
sha: b567818fe608067eb0f1d7c2c4fe361e7ad83c8a256234c97685f1d0bf670cc8
repository: thanos/thanos
sha: 6249f7aaadd3695df637fb2eb4cb9a9955611eee691c3970892fe9c0dc3f2db6
sha: b567818fe608067eb0f1d7c2c4fe361e7ad83c8a256234c97685f1d0bf670cc8
tag: v0.41.0
Copilot AI review requested due to automatic review settings July 30, 2026 22:34
@aro-hcp-robot
aro-hcp-robot Bot force-pushed the automated---update-component-image-digests branch from 06c206b to 003e0b3 Compare July 30, 2026 22:34

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 10 out of 10 changed files in this pull request and generated no new comments.

Comments suppressed due to low confidence (3)

config/config.yaml:612

  • The tag value (v0.41.0) conflicts with the SHA comment indicating v0.42.4. If the rendering/deployment logic uses tag (even as a fallback), this can deploy a different version than intended or confuse operators during incident/debugging. Recommendation: align tag with the version implied by the pinned SHA (or update the SHA/comment to match v0.41.0) so the human-readable tag and pinned digest represent the same release. (Same issue appears again in the later defaults thanos image section.)
          registry: arohcpsvcdev.azurecr.io
          repository: thanos/thanos
          tag: v0.41.0
          sha: b567818fe608067eb0f1d7c2c4fe361e7ad83c8a256234c97685f1d0bf670cc8 # v0.42.4 (2026-07-30 13:37)

acm/deploy/helm/multicluster-engine/templates/multicluster-engine-operator.deployment.yaml:137

  • The backplane operator image digest is duplicated in two places (env var and container image). This makes future bumps error-prone (easy to update one and miss the other). Recommendation: define this image reference once (e.g., in values.yaml under a single key or a named template helper) and reference it from both locations.
          value: '{{ .Values.imageRegistry }}/{{ .Values.imageRootRepository }}/backplane-rhel9-operator@sha256:1c59e0a1ed54e8480bbe7e84c271e55cc600391530791412e7eeee9d6444abfa'

acm/deploy/helm/multicluster-engine/templates/multicluster-engine-operator.deployment.yaml:142

  • The backplane operator image digest is duplicated in two places (env var and container image). This makes future bumps error-prone (easy to update one and miss the other). Recommendation: define this image reference once (e.g., in values.yaml under a single key or a named template helper) and reference it from both locations.
        image: '{{ .Values.imageRegistry }}/{{ .Values.imageRootRepository }}/backplane-rhel9-operator@sha256:1c59e0a1ed54e8480bbe7e84c271e55cc600391530791412e7eeee9d6444abfa'

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

/retest-required

Remaining retests: 0 against base HEAD 0a517d3 and 2 for PR HEAD 003e0b3 in total

Copilot AI review requested due to automatic review settings July 31, 2026 06:36
@aro-hcp-robot
aro-hcp-robot Bot force-pushed the automated---update-component-image-digests branch from 003e0b3 to 4245da1 Compare July 31, 2026 06:36

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 10 out of 10 changed files in this pull request and generated no new comments.

Suppressed comments (2)

config/config.yaml:612

  • The Thanos image metadata is internally inconsistent: tag: v0.41.0 while the sha comment indicates v0.42.4. If your image reference is constructed using both tag + sha, this can resolve to an unexpected image (or fail validation if you enforce tag/sha pairing). Align these fields by either updating the tag to match the referenced version, or updating the sha/comment to match v0.41.0.
          registry: arohcpsvcdev.azurecr.io
          repository: thanos/thanos
          tag: v0.41.0
          sha: b567818fe608067eb0f1d7c2c4fe361e7ad83c8a256234c97685f1d0bf670cc8 # v0.42.4 (2026-07-30 13:37)

config/config.yaml:743

  • The Thanos image metadata is internally inconsistent: tag: v0.41.0 while the sha comment indicates v0.42.4. If your image reference is constructed using both tag + sha, this can resolve to an unexpected image (or fail validation if you enforce tag/sha pairing). Align these fields by either updating the tag to match the referenced version, or updating the sha/comment to match v0.41.0.
          registry: arohcpsvcdev.azurecr.io
          repository: thanos/thanos
          tag: v0.41.0
          sha: b567818fe608067eb0f1d7c2c4fe361e7ad83c8a256234c97685f1d0bf670cc8 # v0.42.4 (2026-07-30 13:37)

Copilot AI review requested due to automatic review settings July 31, 2026 14:32
@aro-hcp-robot
aro-hcp-robot Bot force-pushed the automated---update-component-image-digests branch from 4245da1 to d664018 Compare July 31, 2026 14:32

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 10 out of 10 changed files in this pull request and generated 2 comments.

Suppressed comments (2)

config/config.yaml:612

  • The thanos image fields are inconsistent: tag is v0.41.0 while the sha comment indicates v0.42.4. If both fields are used to select/build the image, this can result in deploying an unexpected version. Align the tag with the referenced version (or update the sha/comment to match the tag).
          tag: v0.41.0
          sha: b567818fe608067eb0f1d7c2c4fe361e7ad83c8a256234c97685f1d0bf670cc8 # v0.42.4 (2026-07-30 13:37)

config/config.yaml:743

  • Same inconsistency in the second thanos block: tag: v0.41.0 but sha comment says v0.42.4. Align these to avoid confusion and potential version skew.
          tag: v0.41.0
          sha: b567818fe608067eb0f1d7c2c4fe361e7ad83c8a256234c97685f1d0bf670cc8 # v0.42.4 (2026-07-30 13:37)

Comment on lines 9 to 12
sources:
- quay.io/redhat-user-workloads/crt-redhat-acm-tenant/mce-operator-bundle-mce-211@sha256:c8b9aa2f3e0d3db6c11974c2ae820dab5cf3c290f7de8b5115e1839e0a8aab1d
- quay.io/redhat-user-workloads/crt-redhat-acm-tenant/mce-operator-bundle-mce-211@sha256:80c9c12c8f47f5e94f6129487346379e9b3dce7cae710c3eb1e34914577dc374
type: application
version: 2.11.4
Comment on lines 9 to 12
sources:
- quay.io/redhat-user-workloads/crt-redhat-acm-tenant/mce-operator-bundle-mce-211@sha256:c8b9aa2f3e0d3db6c11974c2ae820dab5cf3c290f7de8b5115e1839e0a8aab1d
- quay.io/redhat-user-workloads/crt-redhat-acm-tenant/mce-operator-bundle-mce-211@sha256:80c9c12c8f47f5e94f6129487346379e9b3dce7cae710c3eb1e34914577dc374
type: application
version: 2.11.4
@openshift-merge-bot

Copy link
Copy Markdown
Contributor

/retest-required

Remaining retests: 0 against base HEAD e671079 and 2 for PR HEAD d664018 in total

Copilot AI review requested due to automatic review settings July 31, 2026 22:32
@aro-hcp-robot
aro-hcp-robot Bot force-pushed the automated---update-component-image-digests branch from d664018 to 0dfcae7 Compare July 31, 2026 22:32

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 11 out of 11 changed files in this pull request and generated 2 comments.

Suppressed comments (3)

config/config.yaml:615

  • The Thanos tag remains v0.41.0 while the sha comment indicates v0.42.4. Even if your tooling uses the digest/sha as the source of truth, this mismatch is confusing and can lead to incorrect assumptions during incident response or upgrades. Please align the tag (and/or the comment) with the pinned digest so they describe the same version.
          registry: arohcpsvcdev.azurecr.io
          repository: thanos/thanos
          tag: v0.41.0
          sha: b567818fe608067eb0f1d7c2c4fe361e7ad83c8a256234c97685f1d0bf670cc8 # v0.42.4 (2026-07-30 13:37)

config/config.yaml:747

  • The Thanos tag remains v0.41.0 while the sha comment indicates v0.42.4. Even if your tooling uses the digest/sha as the source of truth, this mismatch is confusing and can lead to incorrect assumptions during incident response or upgrades. Please align the tag (and/or the comment) with the pinned digest so they describe the same version.
          registry: arohcpsvcdev.azurecr.io
          repository: thanos/thanos
          tag: v0.41.0
          sha: b567818fe608067eb0f1d7c2c4fe361e7ad83c8a256234c97685f1d0bf670cc8 # v0.42.4 (2026-07-30 13:37)

acm/deploy/helm/multicluster-engine/templates/multicluster-engine-operator.deployment.yaml:175

  • This changes scheduling semantics from a preferred placement on infra nodes (via preferredDuringSchedulingIgnoredDuringExecution) to a hard requirement (via nodeSelector). If any cluster/environment lacks nodes labeled aro-hcp.azure.com/role: infra, the operator will become unschedulable and remain Pending. If the intent is still 'prefer infra but allow fallback', consider restoring preferred nodeAffinity; if the intent is 'infra-only', consider making this behavior configurable via values so other environments can opt out safely.
      nodeSelector:
        aro-hcp.azure.com/role: infra

Comment on lines 9 to +10
sources:
- quay.io/redhat-user-workloads/crt-redhat-acm-tenant/mce-operator-bundle-mce-211@sha256:c8b9aa2f3e0d3db6c11974c2ae820dab5cf3c290f7de8b5115e1839e0a8aab1d
- quay.io/redhat-user-workloads/crt-redhat-acm-tenant/mce-operator-bundle-mce-211@sha256:07a34fcadced16168de23d3a53993fae84c3083c390658760b33f1d5f6c5dded
Comment on lines 9 to +10
sources:
- quay.io/redhat-user-workloads/crt-redhat-acm-tenant/mce-operator-bundle-mce-211@sha256:c8b9aa2f3e0d3db6c11974c2ae820dab5cf3c290f7de8b5115e1839e0a8aab1d
- quay.io/redhat-user-workloads/crt-redhat-acm-tenant/mce-operator-bundle-mce-211@sha256:07a34fcadced16168de23d3a53993fae84c3083c390658760b33f1d5f6c5dded
@inbharajmani

Copy link
Copy Markdown
Collaborator

/test e2e-parallel

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

/retest-required

Remaining retests: 0 against base HEAD 93889dd and 2 for PR HEAD 0dfcae7 in total

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

/retest-required

Remaining retests: 0 against base HEAD 502d894 and 1 for PR HEAD 0dfcae7 in total

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

/retest-required

Remaining retests: 0 against base HEAD 44592e2 and 0 for PR HEAD 0dfcae7 in total

@openshift-ci

openshift-ci Bot commented Aug 1, 2026

Copy link
Copy Markdown

@aro-hcp-robot[bot]: The following test failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test name Commit Details Required Rerun command
ci/prow/e2e-parallel 0dfcae7 link true /test e2e-parallel

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

/hold

Revision 0dfcae7 was retested 3 times: holding

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants