Skip to content

Automated - Update component image digests - #6337

Merged
Rael Garcia (raelga) merged 3 commits into
mainfrom
automated---update-component-image-digests
Aug 5, 2026
Merged

Automated - Update component image digests#6337
Rael Garcia (raelga) merged 3 commits into
mainfrom
automated---update-component-image-digests

Conversation

@aro-hcp-robot

@aro-hcp-robot aro-hcp-robot Bot commented Jul 30, 2026

Copy link
Copy Markdown
Contributor

This automated PR updates ARO-HCP container image digests to the latest versions from registries.

Name Old Digest New Digest Tag Date Status
arobit-forwarder c81f949228a0… e8df41b2461b… v5.0.4 2026-07-31 18:54 updated
arobit-mdsd 5c0159feac33… 83b9cbd2662c… 1.43.0-20260730-1 2026-07-30 17:43 updated
kubeEvents 10a020acbc38… dea4ec46b0d9… 20260802.1 2026-08-02 03:25 updated
hypershift 0a0397b7e1fe… f74ffb720e62… latest 2026-08-04 18:25 updated
velero-server a48979677ab5… a611f6c4f62b… 1.6.1 2026-08-04 18:27 updated
velero-azure-plugin c4c26fca6614… 6c9a836847b7… 1.6.1 2026-08-04 18:34 updated
velero-hypershift-plugin e07251298031… 1e959bed1cbf… 1.6.1 2026-08-04 18:37 updated
thanos 6249f7aaadd3… b567818fe608… v0.42.4 2026-07-30 13:37 updated
maestro-agent-sidecar b770cd63558c… 2c0ba08f2ebb… 1.28.3-8-azl3.0.20260728 2026-07-31 23:27 updated
maestro b18d465c3ade… f70df67b0e21… ab480c6578bcbcbceeeb2c964c7bef6aed119c18 2026-08-04 15:37 updated
acm-operator 72b7793fba6c… 219d7a80b0c0… v2.16.3-552 2026-08-04 18:38 updated
acm-mce c8b9aa2f3e0d… bc1c8b78956c… v2.11.5-599 2026-08-04 22:04 updated
clusters-service 981637a1e08c… 5931b36242ac… latest 2026-08-04 19:30 updated
imageSync aa1a693a0d0d… 81441ace3a17… 4f421a9 2026-08-05 04:58 updated
tenant-quota e550b375a611… 36f2251c6181… dd702fa 2026-08-04 19:49 updated

Schedule: Monday through Friday at 2 AM UTC
Generated by: periodic-ci-Azure-ARO-HCP-main-image-updater-tooling
Generated at: 2026-08-05T06:32:31+0000

Copilot AI lite review requested due to automatic review settings July 30, 2026 14:31

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Note

Copilot could not run the full agentic suite for this review because it was automatically requested on a bot-authored pull request. Request a review from Copilot under Reviewers to retry with the full agentic suite. Improved support for bot-authored pull requests is coming soon.

Updates pinned container image digests across dev environment rendered configs and ACM/MCE Helm charts to roll forward operator bundles and component images.

Changes:

  • Bump ACM/MCE operator bundle digests across dev rendered configs and Helm chart metadata.
  • Update pinned digests/SHAs for hypershift operator, oc-mirror, maestro sidecar nginx, and thanos images in defaults and rendered env configs.
  • Refresh selected MCE operand image digests in the multicluster-engine operator deployment template.

Reviewed changes

Copilot reviewed 11 out of 11 changed files in this pull request and generated 4 comments.

Show a summary per file
File Description
config/rendered/dev/pers/westus3.yaml Updates image digests/SHAs for ACM/MCE bundles and core components in pers westus3 rendered config.
config/rendered/dev/perf/westus3.yaml Updates image digests/SHAs for ACM/MCE bundles and core components in perf westus3 rendered config.
config/rendered/dev/dev/westus3.yaml Updates image digests/SHAs for ACM/MCE bundles and core components in dev westus3 rendered config.
config/rendered/dev/cspr/westus3.yaml Updates image digests/SHAs for ACM/MCE bundles and core components in cspr westus3 rendered config.
config/rendered/dev/ci01/centralus.yaml Updates image digests/SHAs for ACM/MCE bundles and core components in ci01 centralus rendered config.
config/rendered/dev/ci00/centralus.yaml Updates image digests/SHAs for ACM/MCE bundles and core components in ci00 centralus rendered config.
config/config.yaml Updates defaults for hypershift, thanos, maestro sidecar nginx, ACM/MCE bundles, and oc-mirror digests/SHAs.
acm/deploy/helm/multicluster-engine/templates/multicluster-engine-operator.deployment.yaml Updates a couple of operand image digests used by the operator deployment.
acm/deploy/helm/multicluster-engine/Chart.yaml Updates chart source reference to the new MCE bundle digest.
acm/deploy/helm/multicluster-engine-crds/Chart.yaml Updates chart source reference to the new MCE bundle digest.
acm/deploy/helm/multicluster-engine-config/charts/policy/values.yaml Updates governance policy framework addon image digest.
Comments suppressed due to low confidence (1)

config/rendered/dev/dev/westus3.yaml:1

  • Rendered configs still show tag: v0.41.0 with the updated sha. If sha is intended to correspond to a different release (as suggested by the defaults comment in config/config.yaml), the rendered output should be regenerated after fixing the tag/SHA alignment in the source defaults, so that all environments consistently reference the intended thanos version.
acm:

Comment thread config/config.yaml
Comment on lines 609 to +612
registry: arohcpsvcdev.azurecr.io
repository: thanos/thanos
tag: v0.41.0
sha: 6249f7aaadd3695df637fb2eb4cb9a9955611eee691c3970892fe9c0dc3f2db6 # v0.42.2 (2026-07-16 20:22)
sha: b567818fe608067eb0f1d7c2c4fe361e7ad83c8a256234c97685f1d0bf670cc8 # v0.42.4 (2026-07-30 13:37)
Comment thread config/config.yaml
Comment on lines 740 to +743
registry: arohcpsvcdev.azurecr.io
repository: thanos/thanos
tag: v0.41.0
sha: 6249f7aaadd3695df637fb2eb4cb9a9955611eee691c3970892fe9c0dc3f2db6 # v0.42.2 (2026-07-16 20:22)
sha: b567818fe608067eb0f1d7c2c4fe361e7ad83c8a256234c97685f1d0bf670cc8 # v0.42.4 (2026-07-30 13:37)
Comment on lines 1062 to +1065
image:
registry: arohcpsvcdev.azurecr.io
repository: thanos/thanos
sha: 6249f7aaadd3695df637fb2eb4cb9a9955611eee691c3970892fe9c0dc3f2db6
sha: b567818fe608067eb0f1d7c2c4fe361e7ad83c8a256234c97685f1d0bf670cc8
repository: thanos/thanos
sha: 6249f7aaadd3695df637fb2eb4cb9a9955611eee691c3970892fe9c0dc3f2db6
sha: b567818fe608067eb0f1d7c2c4fe361e7ad83c8a256234c97685f1d0bf670cc8
tag: v0.41.0
Copilot AI review requested due to automatic review settings July 30, 2026 22:34
@aro-hcp-robot
aro-hcp-robot Bot force-pushed the automated---update-component-image-digests branch from 06c206b to 003e0b3 Compare July 30, 2026 22:34

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 10 out of 10 changed files in this pull request and generated no new comments.

Comments suppressed due to low confidence (3)

config/config.yaml:612

  • The tag value (v0.41.0) conflicts with the SHA comment indicating v0.42.4. If the rendering/deployment logic uses tag (even as a fallback), this can deploy a different version than intended or confuse operators during incident/debugging. Recommendation: align tag with the version implied by the pinned SHA (or update the SHA/comment to match v0.41.0) so the human-readable tag and pinned digest represent the same release. (Same issue appears again in the later defaults thanos image section.)
          registry: arohcpsvcdev.azurecr.io
          repository: thanos/thanos
          tag: v0.41.0
          sha: b567818fe608067eb0f1d7c2c4fe361e7ad83c8a256234c97685f1d0bf670cc8 # v0.42.4 (2026-07-30 13:37)

acm/deploy/helm/multicluster-engine/templates/multicluster-engine-operator.deployment.yaml:137

  • The backplane operator image digest is duplicated in two places (env var and container image). This makes future bumps error-prone (easy to update one and miss the other). Recommendation: define this image reference once (e.g., in values.yaml under a single key or a named template helper) and reference it from both locations.
          value: '{{ .Values.imageRegistry }}/{{ .Values.imageRootRepository }}/backplane-rhel9-operator@sha256:1c59e0a1ed54e8480bbe7e84c271e55cc600391530791412e7eeee9d6444abfa'

acm/deploy/helm/multicluster-engine/templates/multicluster-engine-operator.deployment.yaml:142

  • The backplane operator image digest is duplicated in two places (env var and container image). This makes future bumps error-prone (easy to update one and miss the other). Recommendation: define this image reference once (e.g., in values.yaml under a single key or a named template helper) and reference it from both locations.
        image: '{{ .Values.imageRegistry }}/{{ .Values.imageRootRepository }}/backplane-rhel9-operator@sha256:1c59e0a1ed54e8480bbe7e84c271e55cc600391530791412e7eeee9d6444abfa'

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

/retest-required

Remaining retests: 0 against base HEAD 0a517d3 and 2 for PR HEAD 003e0b3 in total

Copilot AI review requested due to automatic review settings July 31, 2026 06:36
@aro-hcp-robot
aro-hcp-robot Bot force-pushed the automated---update-component-image-digests branch from 003e0b3 to 4245da1 Compare July 31, 2026 06:36

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 10 out of 10 changed files in this pull request and generated no new comments.

Suppressed comments (2)

config/config.yaml:612

  • The Thanos image metadata is internally inconsistent: tag: v0.41.0 while the sha comment indicates v0.42.4. If your image reference is constructed using both tag + sha, this can resolve to an unexpected image (or fail validation if you enforce tag/sha pairing). Align these fields by either updating the tag to match the referenced version, or updating the sha/comment to match v0.41.0.
          registry: arohcpsvcdev.azurecr.io
          repository: thanos/thanos
          tag: v0.41.0
          sha: b567818fe608067eb0f1d7c2c4fe361e7ad83c8a256234c97685f1d0bf670cc8 # v0.42.4 (2026-07-30 13:37)

config/config.yaml:743

  • The Thanos image metadata is internally inconsistent: tag: v0.41.0 while the sha comment indicates v0.42.4. If your image reference is constructed using both tag + sha, this can resolve to an unexpected image (or fail validation if you enforce tag/sha pairing). Align these fields by either updating the tag to match the referenced version, or updating the sha/comment to match v0.41.0.
          registry: arohcpsvcdev.azurecr.io
          repository: thanos/thanos
          tag: v0.41.0
          sha: b567818fe608067eb0f1d7c2c4fe361e7ad83c8a256234c97685f1d0bf670cc8 # v0.42.4 (2026-07-30 13:37)

Copilot AI review requested due to automatic review settings July 31, 2026 14:32
@aro-hcp-robot
aro-hcp-robot Bot force-pushed the automated---update-component-image-digests branch from 4245da1 to d664018 Compare July 31, 2026 14:32

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 10 out of 10 changed files in this pull request and generated 2 comments.

Suppressed comments (2)

config/config.yaml:612

  • The thanos image fields are inconsistent: tag is v0.41.0 while the sha comment indicates v0.42.4. If both fields are used to select/build the image, this can result in deploying an unexpected version. Align the tag with the referenced version (or update the sha/comment to match the tag).
          tag: v0.41.0
          sha: b567818fe608067eb0f1d7c2c4fe361e7ad83c8a256234c97685f1d0bf670cc8 # v0.42.4 (2026-07-30 13:37)

config/config.yaml:743

  • Same inconsistency in the second thanos block: tag: v0.41.0 but sha comment says v0.42.4. Align these to avoid confusion and potential version skew.
          tag: v0.41.0
          sha: b567818fe608067eb0f1d7c2c4fe361e7ad83c8a256234c97685f1d0bf670cc8 # v0.42.4 (2026-07-30 13:37)

Comment on lines 9 to 12
sources:
- quay.io/redhat-user-workloads/crt-redhat-acm-tenant/mce-operator-bundle-mce-211@sha256:c8b9aa2f3e0d3db6c11974c2ae820dab5cf3c290f7de8b5115e1839e0a8aab1d
- quay.io/redhat-user-workloads/crt-redhat-acm-tenant/mce-operator-bundle-mce-211@sha256:80c9c12c8f47f5e94f6129487346379e9b3dce7cae710c3eb1e34914577dc374
type: application
version: 2.11.4
Comment on lines 9 to 12
sources:
- quay.io/redhat-user-workloads/crt-redhat-acm-tenant/mce-operator-bundle-mce-211@sha256:c8b9aa2f3e0d3db6c11974c2ae820dab5cf3c290f7de8b5115e1839e0a8aab1d
- quay.io/redhat-user-workloads/crt-redhat-acm-tenant/mce-operator-bundle-mce-211@sha256:80c9c12c8f47f5e94f6129487346379e9b3dce7cae710c3eb1e34914577dc374
type: application
version: 2.11.4
@openshift-merge-bot

Copy link
Copy Markdown
Contributor

/retest-required

Remaining retests: 0 against base HEAD e671079 and 2 for PR HEAD d664018 in total

Copilot AI review requested due to automatic review settings July 31, 2026 22:32
@aro-hcp-robot
aro-hcp-robot Bot force-pushed the automated---update-component-image-digests branch from d664018 to 0dfcae7 Compare July 31, 2026 22:32

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 11 out of 11 changed files in this pull request and generated 2 comments.

Suppressed comments (3)

config/config.yaml:615

  • The Thanos tag remains v0.41.0 while the sha comment indicates v0.42.4. Even if your tooling uses the digest/sha as the source of truth, this mismatch is confusing and can lead to incorrect assumptions during incident response or upgrades. Please align the tag (and/or the comment) with the pinned digest so they describe the same version.
          registry: arohcpsvcdev.azurecr.io
          repository: thanos/thanos
          tag: v0.41.0
          sha: b567818fe608067eb0f1d7c2c4fe361e7ad83c8a256234c97685f1d0bf670cc8 # v0.42.4 (2026-07-30 13:37)

config/config.yaml:747

  • The Thanos tag remains v0.41.0 while the sha comment indicates v0.42.4. Even if your tooling uses the digest/sha as the source of truth, this mismatch is confusing and can lead to incorrect assumptions during incident response or upgrades. Please align the tag (and/or the comment) with the pinned digest so they describe the same version.
          registry: arohcpsvcdev.azurecr.io
          repository: thanos/thanos
          tag: v0.41.0
          sha: b567818fe608067eb0f1d7c2c4fe361e7ad83c8a256234c97685f1d0bf670cc8 # v0.42.4 (2026-07-30 13:37)

acm/deploy/helm/multicluster-engine/templates/multicluster-engine-operator.deployment.yaml:175

  • This changes scheduling semantics from a preferred placement on infra nodes (via preferredDuringSchedulingIgnoredDuringExecution) to a hard requirement (via nodeSelector). If any cluster/environment lacks nodes labeled aro-hcp.azure.com/role: infra, the operator will become unschedulable and remain Pending. If the intent is still 'prefer infra but allow fallback', consider restoring preferred nodeAffinity; if the intent is 'infra-only', consider making this behavior configurable via values so other environments can opt out safely.
      nodeSelector:
        aro-hcp.azure.com/role: infra

Comment on lines +9 to +10
sources:
- quay.io/redhat-user-workloads/crt-redhat-acm-tenant/mce-operator-bundle-mce-211@sha256:c8b9aa2f3e0d3db6c11974c2ae820dab5cf3c290f7de8b5115e1839e0a8aab1d
- quay.io/redhat-user-workloads/crt-redhat-acm-tenant/mce-operator-bundle-mce-211@sha256:07a34fcadced16168de23d3a53993fae84c3083c390658760b33f1d5f6c5dded
Comment on lines +9 to +10
sources:
- quay.io/redhat-user-workloads/crt-redhat-acm-tenant/mce-operator-bundle-mce-211@sha256:c8b9aa2f3e0d3db6c11974c2ae820dab5cf3c290f7de8b5115e1839e0a8aab1d
- quay.io/redhat-user-workloads/crt-redhat-acm-tenant/mce-operator-bundle-mce-211@sha256:07a34fcadced16168de23d3a53993fae84c3083c390658760b33f1d5f6c5dded
@inbharajmani

Copy link
Copy Markdown
Collaborator

/test e2e-parallel

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

/retest-required

Remaining retests: 0 against base HEAD 93889dd and 2 for PR HEAD 0dfcae7 in total

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

/retest-required

Remaining retests: 0 against base HEAD 502d894 and 1 for PR HEAD 0dfcae7 in total

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

/retest-required

Remaining retests: 0 against base HEAD 44592e2 and 0 for PR HEAD 0dfcae7 in total

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

/hold

Revision 0dfcae7 was retested 3 times: holding

Copilot AI review requested due to automatic review settings August 3, 2026 06:32
@aro-hcp-robot
aro-hcp-robot Bot force-pushed the automated---update-component-image-digests branch from 0dfcae7 to d590f09 Compare August 3, 2026 06:32

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 11 out of 11 changed files in this pull request and generated 1 comment.

Suppressed comments (2)

config/config.yaml:615

  • The tag and sha metadata appear to be out of sync (tag: v0.41.0 but the sha comment indicates v0.42.4). If both fields participate in image selection/pinning, this can lead to deploying an unintended version; if only one is used, it still creates a misleading config. Align the tag with the intended sha (or update the comment/field so they consistently refer to the same upstream version).
          registry: arohcpsvcdev.azurecr.io
          repository: thanos/thanos
          tag: v0.41.0
          sha: b567818fe608067eb0f1d7c2c4fe361e7ad83c8a256234c97685f1d0bf670cc8 # v0.42.4 (2026-07-30 13:37)

config/config.yaml:747

  • Same tag/SHA mismatch as the earlier thanos entry. Please update this block to match the intended version consistently.
          registry: arohcpsvcdev.azurecr.io
          repository: thanos/thanos
          tag: v0.41.0
          sha: b567818fe608067eb0f1d7c2c4fe361e7ad83c8a256234c97685f1d0bf670cc8 # v0.42.4 (2026-07-30 13:37)

Comment on lines +174 to +175
nodeSelector:
aro-hcp.azure.com/role: infra
Copilot AI review requested due to automatic review settings August 4, 2026 06:28
@aro-hcp-robot
aro-hcp-robot Bot force-pushed the automated---update-component-image-digests branch from c7ff1cf to 533b1fa Compare August 4, 2026 06:28
@openshift-ci openshift-ci Bot removed the lgtm label Aug 4, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 12 out of 12 changed files in this pull request and generated 1 comment.

Suppressed comments (2)

config/config.yaml:619

  • The Thanos tag value (v0.41.0) conflicts with the inline comment indicating the pinned sha corresponds to v0.42.4. This is likely to cause confusion at best, and at worst could pull an unintended image version depending on how tag+sha are combined/consumed downstream. Align these fields by updating the tag (and any rendered outputs) to match the pinned sha/version, or correct the comment/sha to match v0.41.0.
          registry: arohcpsvcdev.azurecr.io
          repository: thanos/thanos
          tag: v0.41.0
          sha: b567818fe608067eb0f1d7c2c4fe361e7ad83c8a256234c97685f1d0bf670cc8 # v0.42.4 (2026-07-30 13:37)

config/config.yaml:751

  • The Thanos tag value (v0.41.0) conflicts with the inline comment indicating the pinned sha corresponds to v0.42.4. This is likely to cause confusion at best, and at worst could pull an unintended image version depending on how tag+sha are combined/consumed downstream. Align these fields by updating the tag (and any rendered outputs) to match the pinned sha/version, or correct the comment/sha to match v0.41.0.
          registry: arohcpsvcdev.azurecr.io
          repository: thanos/thanos
          tag: v0.41.0
          sha: b567818fe608067eb0f1d7c2c4fe361e7ad83c8a256234c97685f1d0bf670cc8 # v0.42.4 (2026-07-30 13:37)

Comment on lines +174 to +175
nodeSelector:
aro-hcp.azure.com/role: infra
@ashishmax31

Copy link
Copy Markdown
Collaborator

/lgtm

@openshift-ci

openshift-ci Bot commented Aug 4, 2026

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: aro-hcp-robot[bot], ashishmax31, raelga

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

Copilot AI review requested due to automatic review settings August 4, 2026 14:33
@aro-hcp-robot
aro-hcp-robot Bot force-pushed the automated---update-component-image-digests branch from 533b1fa to ae78031 Compare August 4, 2026 14:33
@openshift-ci openshift-ci Bot removed the lgtm label Aug 4, 2026
@openshift-ci

openshift-ci Bot commented Aug 4, 2026

Copy link
Copy Markdown

New changes are detected. LGTM label has been removed.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 12 out of 12 changed files in this pull request and generated no new comments.

Suppressed comments (4)

config/config.yaml:620

  • The Thanos tag is still set to v0.41.0 while the pinned sha comment indicates v0.42.4. This inconsistency risks deploying an unintended version (depending on how tag/sha are used downstream) and is confusing to operators. Align the tag (and/or the comment) with the intended release, and ensure the pinned value corresponds to that version.
          registry: arohcpsvcdev.azurecr.io
          repository: thanos/thanos
          tag: v0.41.0
          sha: b567818fe608067eb0f1d7c2c4fe361e7ad83c8a256234c97685f1d0bf670cc8 # v0.42.4 (2026-07-30 13:37)

config/config.yaml:752

  • The Thanos tag is still set to v0.41.0 while the pinned sha comment indicates v0.42.4. This inconsistency risks deploying an unintended version (depending on how tag/sha are used downstream) and is confusing to operators. Align the tag (and/or the comment) with the intended release, and ensure the pinned value corresponds to that version.
          registry: arohcpsvcdev.azurecr.io
          repository: thanos/thanos
          tag: v0.41.0
          sha: b567818fe608067eb0f1d7c2c4fe361e7ad83c8a256234c97685f1d0bf670cc8 # v0.42.4 (2026-07-30 13:37)

acm/deploy/helm/multicluster-engine/templates/multicluster-engine-operator.deployment.yaml:30

  • Switching from a preferred infra nodeAffinity to a hard nodeSelector changes scheduling semantics: the operator will now remain Pending if no nodes are labeled aro-hcp.azure.com/role=infra. If this is intentional (must-run-on-infra), consider making the selector configurable via values (so non-infra clusters can deploy), or restoring a preferred affinity-based approach for a safer default.
      affinity:
        podAntiAffinity:
          preferredDuringSchedulingIgnoredDuringExecution:
          - podAffinityTerm:

acm/deploy/helm/multicluster-engine/templates/multicluster-engine-operator.deployment.yaml:175

  • Switching from a preferred infra nodeAffinity to a hard nodeSelector changes scheduling semantics: the operator will now remain Pending if no nodes are labeled aro-hcp.azure.com/role=infra. If this is intentional (must-run-on-infra), consider making the selector configurable via values (so non-infra clusters can deploy), or restoring a preferred affinity-based approach for a safer default.
      nodeSelector:
        aro-hcp.azure.com/role: infra

Copilot AI review requested due to automatic review settings August 4, 2026 22:29
@aro-hcp-robot
aro-hcp-robot Bot force-pushed the automated---update-component-image-digests branch from ae78031 to 0ce7c4f Compare August 4, 2026 22:29

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 13 out of 13 changed files in this pull request and generated no new comments.

Suppressed comments (4)

config/config.yaml:620

  • The Thanos image metadata is internally inconsistent: tag: v0.41.0 while the pinned sha comment indicates v0.42.4. If consumers combine tag+sha (or validate they match), this can lead to pulling/labeling the wrong version. Align the tag with the sha (or adjust the sha/comment) so they refer to the same upstream release.
          registry: arohcpsvcdev.azurecr.io
          repository: thanos/thanos
          tag: v0.41.0
          sha: b567818fe608067eb0f1d7c2c4fe361e7ad83c8a256234c97685f1d0bf670cc8 # v0.42.4 (2026-07-30 13:37)

config/config.yaml:752

  • Same issue as the earlier Thanos stanza: tag: v0.41.0 conflicts with the v0.42.4 SHA/comment. Please make tag and sha/comment consistent to avoid version skew in downstream tooling.
          registry: arohcpsvcdev.azurecr.io
          repository: thanos/thanos
          tag: v0.41.0
          sha: b567818fe608067eb0f1d7c2c4fe361e7ad83c8a256234c97685f1d0bf670cc8 # v0.42.4 (2026-07-30 13:37)

acm/deploy/helm/multicluster-engine/templates/multicluster-engine-operator.deployment.yaml:175

  • This changes scheduling semantics from a preference to a hard requirement: nodeSelector will keep the operator Pending if no nodes carry aro-hcp.azure.com/role=infra (or if those nodes are tainted without matching tolerations). If this is intended for all deployments, consider documenting the required node labeling/taints; otherwise, make the nodeSelector configurable via Helm values so environments without dedicated infra nodes can still schedule the operator.
      nodeSelector:
        aro-hcp.azure.com/role: infra

config/config-dev-ci.yaml:164

  • This line changes style from a quoted digest string to an unquoted scalar with an inline comment, while adjacent fields in this stanza remain quoted. For consistency (and to minimize YAML parsing surprises across tooling), keep the digest formatting consistent with the surrounding config (e.g., quote the digest here as well, or standardize the whole block).
            digest: sha256:36f2251c61812dded8489affdc5b16f010705da6001bbfa90e10e318922e5a4d # dd702fa31e866201f704288af2b1e5a2d87d8848 (2026-08-04 19:49)

@trevorwilliams2025

Copy link
Copy Markdown
Collaborator

/test e2e-parallel

@aro-hcp-robot
aro-hcp-robot Bot force-pushed the automated---update-component-image-digests branch from 0ce7c4f to c1040f9 Compare August 5, 2026 06:32
Copilot AI review requested due to automatic review settings August 5, 2026 06:32

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 13 out of 13 changed files in this pull request and generated 2 comments.

Suppressed comments (1)

acm/deploy/helm/multicluster-engine/templates/multicluster-engine-operator.deployment.yaml:175

  • Introducing a hard nodeSelector changes scheduling semantics from a preference (previous preferredDuringSchedulingIgnoredDuringExecution) to a requirement. This can prevent the operator from scheduling in clusters that don't label any nodes with aro-hcp.azure.com/role=infra (or during transient labeling issues), creating an availability risk. Consider making this configurable via values (defaulting to the prior preferred behavior), or keeping the soft preference unless a strict requirement is necessary.
      nodeSelector:
        aro-hcp.azure.com/role: infra

Comment thread config/config.yaml
Comment on lines 617 to +620
registry: arohcpsvcdev.azurecr.io
repository: thanos/thanos
tag: v0.41.0
sha: 6249f7aaadd3695df637fb2eb4cb9a9955611eee691c3970892fe9c0dc3f2db6 # v0.42.2 (2026-07-16 20:22)
sha: b567818fe608067eb0f1d7c2c4fe361e7ad83c8a256234c97685f1d0bf670cc8 # v0.42.4 (2026-07-30 13:37)
Comment thread config/config.yaml
Comment on lines 749 to +752
registry: arohcpsvcdev.azurecr.io
repository: thanos/thanos
tag: v0.41.0
sha: 6249f7aaadd3695df637fb2eb4cb9a9955611eee691c3970892fe9c0dc3f2db6 # v0.42.2 (2026-07-16 20:22)
sha: b567818fe608067eb0f1d7c2c4fe361e7ad83c8a256234c97685f1d0bf670cc8 # v0.42.4 (2026-07-30 13:37)
@raelga

Copy link
Copy Markdown
Collaborator

Force-merge justification (P0 exception)

This does not fit the standard force-merge policy: it is not a clean revert. It is requested as a P0 exception, and the request should be escalated and approved on that basis.

1. P0 security fix with a fixed production deadline.
#6337 bumps acm-operator to v2.16.3-552 and acm-mce to v2.11.5-599, which remediate CVE-2026-4740 (GHSA-q4gv-pjmh-c735) by picking up the managedcluster-import-controller image built against the fixed OCM v1.2.1 dependency. These are the same versions as the dedicated P0 PR #6422; merging #6337 propagates the fix into ARO-HCP so it can roll to prod ahead of the fixed P0 deadline.

2. E2E has greened for this change.
On #6337's e2e-parallel run 2084890326891237376, both the environment provisioning and the full test suite passed (aro-hcp-provision-environment: SUCCESS, aro-hcp-test-local: SUCCESS). The change is validated end to end by e2e. All other required checks are green (config-change-detection, integration, verify, test-unit, lint, images); the only outstanding context is e2e-parallel.

3. The required e2e-parallel gate is currently unreliable (flaky), so waiting for a green required run through tide is not dependable.
Over the last 115 e2e-parallel presubmit runs (~16h, 2026-08-04 14:34 to 2026-08-05 06:50 UTC): 25 SUCCESS, 57 FAILURE, 31 ABORTED. Pass rate of completed runs is 30% (25/82). The failures are dominated by flakiness, not by this change: in a sample of 10 recent failures, 7 failed in the test stage (flaky/latched tests), 1 in provisioning, and 1 was marked FAILURE even though provisioning AND the full test suite both passed (run 2084866302274441216, a pure job-level flake). At a 30% pass rate, landing a green required e2e-parallel through the merge queue is unreliable and would jeopardize the P0 deadline, while this PR has already produced a green provision + test run.

Scope / risk.
#6337 is the automated image-digest bump (13 files, config + rendered digests). Its own e2e run passed provisioning and tests, and every other required check is green.

@raelga
Rael Garcia (raelga) merged commit 3e8d348 into main Aug 5, 2026
15 of 16 checks passed
@raelga
Rael Garcia (raelga) deleted the automated---update-component-image-digests branch August 5, 2026 08:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants