🐛 fix missing commits from main - #18
Merged
Merged
Conversation
* Add RosaRoleConfig API and CRD. * Enable partial reconcile of Rosa Operator Roles * Review fixes * Add integration tests * Add more tests * Fix comments Signed-off-by: serngawy <serngawy@gmail.com> --------- Signed-off-by: serngawy <serngawy@gmail.com> Co-authored-by: rknaur <rknaur@redhat.com>
The overall job timeout in prow is 5h, let's use all of the available time.
* feat: support setting EKS AuthenticationMode * feat: support setting EKS AuthenticationMode * Update controlplane/eks/api/v1beta2/awsmanagedcontrolplane_webhook_test.go Co-authored-by: Damiano Donati <damiano.donati@gmail.com> * add EOF to new files --------- Co-authored-by: Adam Malcontenti-Wilson <amalcontenti-wilson@zendesk.com> Co-authored-by: Damiano Donati <damiano.donati@gmail.com>
The API for DescribeEgressOnlyInternetGateways does not support attachment.vpc-id filter. Thus, the call will return all available eigw. Consequences: - CAPA incorrectly selects an unintended eigw for use. Leading to route creation failure since the eigw belongs to a different VPC. - CAPA incorrectly destroys all eigw of all VPCs. This is very catastrophic as it can break other workloads. This commit changes the filter to use cluster tag instead. Additional safeguard is also included to check if the eigw is truly attached the VPC.
Signed-off-by: serngawy <serngawy@gmail.com>
…re for ROSA-HCP (kubernetes-sigs#5464) * RosaNetwork: new CRD & reconciler to provision net infra for ROSA-HCP * ROSANetwork: tests
Co-authored-by: Daniel Lipovetsky <daniel.lipovetsky@gmail.com>
* Support EKS upgrade policy * Apply suggestions from code review Co-authored-by: Damiano Donati <damiano.donati@gmail.com> * regenerate * Apply suggestions from code review Co-authored-by: Damiano Donati <damiano.donati@gmail.com> * Update pkg/cloud/services/eks/cluster.go Co-authored-by: Damiano Donati <damiano.donati@gmail.com> * remove log * Update config/crd/bases/controlplane.cluster.x-k8s.io_awsmanagedcontrolplanes.yaml Co-authored-by: Faiq <faiq.raza@nutanix.com> * docstring typo * set NotReady if cluster was automatically upgraded * Update pkg/cloud/services/eks/cluster.go Co-authored-by: Faiq <faiq.raza@nutanix.com> * fix version compare logic * e2e * Apply suggestions from code review Co-authored-by: Damiano Donati <damiano.donati@gmail.com> * syntax * WaitForEKSClusterUpgradePolicy fail early on NotFound --------- Co-authored-by: Damiano Donati <damiano.donati@gmail.com> Co-authored-by: Faiq <faiq.raza@nutanix.com>
Update Red Hat documentation links.
Bumps [github.com/go-jose/go-jose/v4](https://github.com/go-jose/go-jose) from 4.0.2 to 4.0.5. - [Release notes](https://github.com/go-jose/go-jose/releases) - [Commits](go-jose/go-jose@v4.0.2...v4.0.5) --- updated-dependencies: - dependency-name: github.com/go-jose/go-jose/v4 dependency-version: 4.0.5 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 3 to 4. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@v3...v4) --- updated-dependencies: - dependency-name: github/codeql-action dependency-version: '4' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
…king until previous one is finished (which may have led to failing nodes due to outdated join token)
The unit tests for `getInstanceCPUOptionsRequest` are more lightweight and faster than testing various CPU option configurations through the larger `CreateInstance` function. This commit refactors the existing tests by moving the specific CPU option test cases from `TestCreateInstance` into a new, more focused `TestGetInstanceCPUOptionsRequest` function. A single test case remains in `TestCreateInstance` to ensure the integration between the functions is correct. Signed-off-by: Fangge Jin <fjin@redhat.com>
Signed-off-by: serngawy <serngawy@gmail.com>
Bumps the dependencies group in /hack/tools with 1 update: [github.com/mikefarah/yq/v4](https://github.com/mikefarah/yq). Updates `github.com/mikefarah/yq/v4` from 4.47.2 to 4.48.1 - [Release notes](https://github.com/mikefarah/yq/releases) - [Changelog](https://github.com/mikefarah/yq/blob/master/release_notes.txt) - [Commits](mikefarah/yq@v4.47.2...v4.48.1) --- updated-dependencies: - dependency-name: github.com/mikefarah/yq/v4 dependency-version: 4.48.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: serngawy <serngawy@gmail.com>
…wnerReferencesPermissionEnforcement` for setting `BlockOwnerDeletion: true` on AWSMachinePool Machines
Bumps [golangci/golangci-lint-action](https://github.com/golangci/golangci-lint-action) from 8.0.0 to 9.0.0. - [Release notes](https://github.com/golangci/golangci-lint-action/releases) - [Commits](golangci/golangci-lint-action@4afd733...0a35821) --- updated-dependencies: - dependency-name: golangci/golangci-lint-action dependency-version: 9.0.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps the dependencies group in /hack/tools with 1 update: [sigs.k8s.io/kustomize/kustomize/v5](https://github.com/kubernetes-sigs/kustomize). Updates `sigs.k8s.io/kustomize/kustomize/v5` from 5.7.1 to 5.8.0 - [Release notes](https://github.com/kubernetes-sigs/kustomize/releases) - [Commits](kubernetes-sigs/kustomize@kustomize/v5.7.1...kustomize/v5.8.0) --- updated-dependencies: - dependency-name: sigs.k8s.io/kustomize/kustomize/v5 dependency-version: 5.8.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
…nd tests This PR updates the default value for HostAffinity from `host` to `default` as that's also the AWS platform default, and potentially a more sensible value to set if the user does not have a preference. It also improves the API's go doc comments to further explain the effects of the settings and adds a bunch more units to pinpoint the exact behaviour described in the updated doc.
* Add Access Entry support Co-authored-by: Adam Malcontenti-Wilson <amalcontenti-wilson@zendesk.com> * return early to avoid indentation * add new permissions to cloudformation template * lint fix updated access entry descriptions taken from latest AWS CDK * update access entry tests * only manage access entries created by the controller when auth mode is api or api_and_configmap, EKS will create a service-linked access entry. there may also be manual or other access entries. when reconciling access entries, only manage those originally created by this controller. * replace access entries when username changes the AWS API doesn't provide a way to nil out an existing username, so just replace the access entry whenever the username changes regardless of value. * fix access entries tests --------- Co-authored-by: Adam Malcontenti-Wilson <amalcontenti-wilson@zendesk.com>
The book now lists the Disabling EKS Support page, and the links to that page are no longer broken.
Bumps [golangci/golangci-lint-action](https://github.com/golangci/golangci-lint-action) from 9.0.0 to 9.2.0. - [Release notes](https://github.com/golangci/golangci-lint-action/releases) - [Commits](golangci/golangci-lint-action@0a35821...1e7e51e) --- updated-dependencies: - dependency-name: golangci/golangci-lint-action dependency-version: 9.2.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/cache](https://github.com/actions/cache) from 4 to 5. - [Release notes](https://github.com/actions/cache/releases) - [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md) - [Commits](actions/cache@v4...v5) --- updated-dependencies: - dependency-name: actions/cache dependency-version: '5' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: arpit529srivastava <arpitsrivastava529@gmail.com>
Relaxes the validation for ROSA NodePool autoscaling to allow users to specify a minimum of 0 replicas, enabling scale-to-zero scenarios. MaxReplicas remains with a minimum of 1. Co-Authored-By: Claude Sonnet 4.5 (1M context) <noreply@anthropic.com>
Signed-off-by: serngawy <serngawy@gmail.com>
Signed-off-by: serngawy <serngawy@gmail.com>
the webhook server should use the tlsconfig specified in the manager options, so users setting tls fields in the manager see their preference honoured not only for the metrics server but also for the webhook server.
Signed-off-by: arpit529srivastava <arpitsrivastava529@gmail.com>
Signed-off-by: arpit529srivastava <arpitsrivastava529@gmail.com>
Bumps [aws-actions/configure-aws-credentials](https://github.com/aws-actions/configure-aws-credentials) from 5 to 6. - [Release notes](https://github.com/aws-actions/configure-aws-credentials/releases) - [Changelog](https://github.com/aws-actions/configure-aws-credentials/blob/main/CHANGELOG.md) - [Commits](aws-actions/configure-aws-credentials@v5...v6) --- updated-dependencies: - dependency-name: aws-actions/configure-aws-credentials dependency-version: '6' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
This also addresses minor review comments
faiq
marked this pull request as ready for review
February 11, 2026 22:50
dkoshkin
approved these changes
Feb 11, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What type of PR is this?
What this PR does / why we need it:
Which issue(s) this PR fixes (optional, in
fixes #<issue number>(, fixes #<issue_number>, ...)format, will close the issue(s) when PR gets merged):Fixes #
Special notes for your reviewer:
Checklist:
Release note: