Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update testimages as needed #12657

Merged
merged 1 commit into from
Feb 11, 2025
Merged

Conversation

kyma-bot
Copy link
Contributor

No eu.gcr.io/kyma-project/test-infra/ changes.

Multiple distinct europe-docker.pkg.dev/kyma-project/prod/ changes:

Commits Dates Images
5de2e18...fbc77d1 2025‑02‑05 → 2025‑02‑11 prod/automated-approver, prod/cors-proxy, prod/create-github-issue, prod/dashboard-token-proxy, prod/externalsecretschecker, prod/github-webhook-gateway, prod/image-autobumper, prod/image-syncer, prod/markdown-index, prod/scan-logs-for-secrets, prod/search-github-issue
84fa6f6...fbc77d1 2025‑02‑07 → 2025‑02‑11 prod/image-builder
43ce852...fbc77d1 2025‑02‑07 → 2025‑02‑11 prod/test-infra/rotate-service-account
4a1ca2a...fbc77d1 2025‑02‑07 → 2025‑02‑11 prod/test-infra/service-account-keys-cleaner
dd7ca6d...fbc77d1 2025‑02‑07 → 2025‑02‑11 prod/move-gcs-bucket
3d5d518...fbc77d1 2025‑02‑07 → 2025‑02‑11 prod/image-detector

No eu.gcr.io/kyma-project/test-infra/ changes.

Multiple distinct europe-docker.pkg.dev/kyma-project/prod/ changes:

Commits | Dates | Images
--- | --- | ---
kyma-project/test-infra@5de2e18...fbc77d1 | 2025‑02‑05 → 2025‑02‑11 | prod/automated-approver, prod/cors-proxy, prod/create-github-issue, prod/dashboard-token-proxy, prod/externalsecretschecker, prod/github-webhook-gateway, prod/image-autobumper, prod/image-syncer, prod/markdown-index, prod/scan-logs-for-secrets, prod/search-github-issue
kyma-project/test-infra@84fa6f6...fbc77d1 | 2025‑02‑07 → 2025‑02‑11 | prod/image-builder
kyma-project/test-infra@43ce852...fbc77d1 | 2025‑02‑07 → 2025‑02‑11 | prod/test-infra/rotate-service-account
kyma-project/test-infra@dd7ca6d...fbc77d1 | 2025‑02‑07 → 2025‑02‑11 | prod/move-gcs-bucket
kyma-project/test-infra@3d5d518...fbc77d1 | 2025‑02‑07 → 2025‑02‑11 | prod/image-detector
kyma-project/test-infra@4a1ca2a...fbc77d1 | 2025‑02‑07 → 2025‑02‑11 | prod/test-infra/service-account-keys-cleaner
@kyma-bot kyma-bot requested review from neighbors-dev-bot and a team as code owners February 11, 2025 09:46
@kyma-bot kyma-bot added cla: yes Indicates the PR's author has signed the CLA. size/M Denotes a PR that changes 30-99 lines, ignoring generated files. labels Feb 11, 2025
@Sawthis Sawthis enabled auto-merge (squash) February 11, 2025 09:46
@neighbors-dev-bot neighbors-dev-bot added the auto-approved Denotes a PR that was approved by automation. label Feb 11, 2025
@kyma-bot kyma-bot added lgtm Looks good to me! add-or-update labels Feb 11, 2025
@kyma-bot
Copy link
Contributor Author

Plan Result

CI link

Plan: 0 to add, 10 to change, 0 to destroy.
  • Update
    • kubectl_manifest.automated_approver["/apis/apps/v1/namespaces/default/deployments/automated-approver"]
    • module.cors_proxy.google_cloud_run_service.cors_proxy
    • module.github_webhook_gateway.google_cloud_run_service.github_webhook_gateway
    • module.secrets_leaks_log_scanner.google_cloud_run_service.gcs_bucket_mover
    • module.secrets_leaks_log_scanner.google_cloud_run_service.github_issue_creator
    • module.secrets_leaks_log_scanner.google_cloud_run_service.github_issue_finder
    • module.secrets_leaks_log_scanner.google_cloud_run_service.secrets_leak_log_scanner
    • module.security_dashboard_token.google_cloud_run_service.security_dashboard_token
    • module.service_account_keys_cleaner.google_cloud_run_service.service_account_keys_cleaner
    • module.service_account_keys_rotator.google_cloud_run_service.service_account_keys_rotator
Change Result (Click me)
  # kubectl_manifest.automated_approver["/apis/apps/v1/namespaces/default/deployments/automated-approver"] will be updated in-place
  ~ resource "kubectl_manifest" "automated_approver" {
        id                      = "/apis/apps/v1/namespaces/default/deployments/automated-approver"
        name                    = "automated-approver"
      ~ yaml_body               = (sensitive value)
      ~ yaml_body_parsed        = <<-EOT
            apiVersion: apps/v1
            kind: Deployment
            metadata:
              labels:
                app: automated-approver
              name: automated-approver
              namespace: default
            spec:
              selector:
                matchLabels:
                  app: automated-approver
              template:
                metadata:
                  labels:
                    app: automated-approver
                spec:
                  containers:
                  - args:
                    - --dry-run=false
                    - --port=8080
                    - --hmac-secret-file=/etc/webhook/hmac
                    - --log-level=info
                    - --github-endpoint=http://ghproxy
                    - --github-endpoint=https://api.github.com
                    - --github-token-path=/etc/github/oauth
                    - --rules-path=/etc/config/rules.yaml
                    - --wait-for-statuses-timeout=1800
          -         image: europe-docker.pkg.dev/kyma-project/prod/automated-approver:v20250205-5de2e187
          +         image: europe-docker.pkg.dev/kyma-project/prod/automated-approver:v20250211-fbc77d1c
                    imagePullPolicy: Always
                    name: automated-approver
                    ports:
                    - containerPort: 8080
                      name: http
                    volumeMounts:
                    - mountPath: /etc/webhook
                      name: hmac
                      readOnly: true
                    - mountPath: /etc/github
                      name: oauth
                      readOnly: true
                    - mountPath: /etc/config
                      name: rules
                      readOnly: true
                  volumes:
                  - name: hmac
                    secret:
                      secretName: hmac-token
                  - name: oauth
                    secret:
                      secretName: neighbors-dev-bot-github-token
                  - configMap:
                      items:
                      - key: rules
                        path: rules.yaml
                      name: automated-approver-rules
                    name: rules
        EOT
        # (14 unchanged attributes hidden)
    }

  # module.cors_proxy.google_cloud_run_service.cors_proxy will be updated in-place
  ~ resource "google_cloud_run_service" "cors_proxy" {
        id                         = "locations/europe-west3/namespaces/sap-kyma-prow/services/cors-proxy"
        name                       = "cors-proxy"
        # (4 unchanged attributes hidden)

      ~ template {
          ~ spec {
                # (3 unchanged attributes hidden)

              ~ containers {
                  ~ image   = "europe-docker.pkg.dev/kyma-project/prod/cors-proxy:v20250205-5de2e187" -> "europe-docker.pkg.dev/kyma-project/prod/cors-proxy:v20250211-fbc77d1c"
                    # (2 unchanged attributes hidden)

                    # (6 unchanged blocks hidden)
                }
            }

            # (1 unchanged block hidden)
        }

        # (2 unchanged blocks hidden)
    }

  # module.github_webhook_gateway.google_cloud_run_service.github_webhook_gateway will be updated in-place
  ~ resource "google_cloud_run_service" "github_webhook_gateway" {
        id                         = "locations/europe-west3/namespaces/sap-kyma-prow/services/github-webhook-gateway"
        name                       = "github-webhook-gateway"
        # (4 unchanged attributes hidden)

      ~ template {
          ~ spec {
                # (3 unchanged attributes hidden)

              ~ containers {
                  ~ image   = "europe-docker.pkg.dev/kyma-project/prod/github-webhook-gateway:v20250205-5de2e187" -> "europe-docker.pkg.dev/kyma-project/prod/github-webhook-gateway:v20250211-fbc77d1c"
                    # (2 unchanged attributes hidden)

                    # (12 unchanged blocks hidden)
                }

                # (2 unchanged blocks hidden)
            }

            # (1 unchanged block hidden)
        }

        # (2 unchanged blocks hidden)
    }

  # module.secrets_leaks_log_scanner.google_cloud_run_service.gcs_bucket_mover will be updated in-place
  ~ resource "google_cloud_run_service" "gcs_bucket_mover" {
        id                         = "locations/europe-west3/namespaces/sap-kyma-prow/services/gcs-bucket-mover"
        name                       = "gcs-bucket-mover"
        # (4 unchanged attributes hidden)

      ~ template {
          ~ spec {
                # (3 unchanged attributes hidden)

              ~ containers {
                  ~ image   = "europe-docker.pkg.dev/kyma-project/prod/move-gcs-bucket:v20250207-dd7ca6d9" -> "europe-docker.pkg.dev/kyma-project/prod/move-gcs-bucket:v20250211-fbc77d1c"
                    # (2 unchanged attributes hidden)

                    # (9 unchanged blocks hidden)
                }
            }

            # (1 unchanged block hidden)
        }

        # (2 unchanged blocks hidden)
    }

  # module.secrets_leaks_log_scanner.google_cloud_run_service.github_issue_creator will be updated in-place
  ~ resource "google_cloud_run_service" "github_issue_creator" {
        id                         = "locations/europe-west3/namespaces/sap-kyma-prow/services/github-issue-creator"
        name                       = "github-issue-creator"
        # (4 unchanged attributes hidden)

      ~ template {
          ~ spec {
                # (3 unchanged attributes hidden)

              ~ containers {
                  ~ image   = "europe-docker.pkg.dev/kyma-project/prod/create-github-issue:v20250205-5de2e187" -> "europe-docker.pkg.dev/kyma-project/prod/create-github-issue:v20250211-fbc77d1c"
                    # (2 unchanged attributes hidden)

                    # (11 unchanged blocks hidden)
                }

                # (1 unchanged block hidden)
            }

            # (1 unchanged block hidden)
        }

        # (2 unchanged blocks hidden)
    }

  # module.secrets_leaks_log_scanner.google_cloud_run_service.github_issue_finder will be updated in-place
  ~ resource "google_cloud_run_service" "github_issue_finder" {
        id                         = "locations/europe-west3/namespaces/sap-kyma-prow/services/github-issue-finder"
        name                       = "github-issue-finder"
        # (4 unchanged attributes hidden)

      ~ template {
          ~ spec {
                # (3 unchanged attributes hidden)

              ~ containers {
                  ~ image   = "europe-docker.pkg.dev/kyma-project/prod/search-github-issue:v20250205-5de2e187" -> "europe-docker.pkg.dev/kyma-project/prod/search-github-issue:v20250211-fbc77d1c"
                    # (2 unchanged attributes hidden)

                    # (11 unchanged blocks hidden)
                }

                # (1 unchanged block hidden)
            }

            # (1 unchanged block hidden)
        }

        # (2 unchanged blocks hidden)
    }

  # module.secrets_leaks_log_scanner.google_cloud_run_service.secrets_leak_log_scanner will be updated in-place
  ~ resource "google_cloud_run_service" "secrets_leak_log_scanner" {
        id                         = "locations/europe-west3/namespaces/sap-kyma-prow/services/secrets-leak-log-scanner"
        name                       = "secrets-leak-log-scanner"
        # (4 unchanged attributes hidden)

      ~ template {
          ~ spec {
                # (3 unchanged attributes hidden)

              ~ containers {
                  ~ image   = "europe-docker.pkg.dev/kyma-project/prod/scan-logs-for-secrets:v20250205-5de2e187" -> "europe-docker.pkg.dev/kyma-project/prod/scan-logs-for-secrets:v20250211-fbc77d1c"
                    # (2 unchanged attributes hidden)

                    # (7 unchanged blocks hidden)
                }
            }

            # (1 unchanged block hidden)
        }

        # (2 unchanged blocks hidden)
    }

  # module.security_dashboard_token.google_cloud_run_service.security_dashboard_token will be updated in-place
  ~ resource "google_cloud_run_service" "security_dashboard_token" {
        id                         = "locations/europe-west1/namespaces/sap-kyma-prow/services/security-dashboard-token"
        name                       = "security-dashboard-token"
        # (4 unchanged attributes hidden)

      ~ template {
          ~ spec {
                # (3 unchanged attributes hidden)

              ~ containers {
                  ~ image   = "europe-docker.pkg.dev/kyma-project/prod/dashboard-token-proxy:v20250205-5de2e187" -> "europe-docker.pkg.dev/kyma-project/prod/dashboard-token-proxy:v20250211-fbc77d1c"
                    name    = "dashboard-token-proxy-1"
                    # (2 unchanged attributes hidden)

                    # (6 unchanged blocks hidden)
                }
            }

            # (1 unchanged block hidden)
        }

        # (2 unchanged blocks hidden)
    }

  # module.service_account_keys_cleaner.google_cloud_run_service.service_account_keys_cleaner will be updated in-place
  ~ resource "google_cloud_run_service" "service_account_keys_cleaner" {
        id                         = "locations/europe-west4/namespaces/sap-kyma-prow/services/service-account-keys-cleaner"
        name                       = "service-account-keys-cleaner"
        # (4 unchanged attributes hidden)

      ~ template {
          ~ spec {
                # (3 unchanged attributes hidden)

              ~ containers {
                  ~ image   = "europe-docker.pkg.dev/kyma-project/prod/test-infra/service-account-keys-cleaner:v20250207-4a1ca2ad" -> "europe-docker.pkg.dev/kyma-project/prod/test-infra/service-account-keys-cleaner:v20250211-fbc77d1c"
                    # (2 unchanged attributes hidden)

                    # (6 unchanged blocks hidden)
                }
            }

            # (1 unchanged block hidden)
        }

        # (2 unchanged blocks hidden)
    }

  # module.service_account_keys_rotator.google_cloud_run_service.service_account_keys_rotator will be updated in-place
  ~ resource "google_cloud_run_service" "service_account_keys_rotator" {
        id                         = "locations/europe-west4/namespaces/sap-kyma-prow/services/service-account-keys-rotator"
        name                       = "service-account-keys-rotator"
        # (4 unchanged attributes hidden)

      ~ template {
          ~ spec {
                # (3 unchanged attributes hidden)

              ~ containers {
                  ~ image   = "europe-docker.pkg.dev/kyma-project/prod/test-infra/rotate-service-account:v20250207-43ce8529" -> "europe-docker.pkg.dev/kyma-project/prod/test-infra/rotate-service-account:v20250211-fbc77d1c"
                    # (2 unchanged attributes hidden)

                    # (6 unchanged blocks hidden)
                }
            }

            # (1 unchanged block hidden)
        }

        # (2 unchanged blocks hidden)
    }

Plan: 0 to add, 10 to change, 0 to destroy.

Changes to Outputs:
  ~ service_account_keys_cleaner                   = {
      ~ service_account_keys_cleaner_cloud_run_service = {
            id                         = "locations/europe-west4/namespaces/sap-kyma-prow/services/service-account-keys-cleaner"
            name                       = "service-account-keys-cleaner"
          ~ template                   = [
              ~ {
                  ~ spec     = [
                      ~ {
                          ~ containers            = [
                              ~ {
                                  ~ image          = "europe-docker.pkg.dev/kyma-project/prod/test-infra/service-account-keys-cleaner:v20250207-4a1ca2ad" -> "europe-docker.pkg.dev/kyma-project/prod/test-infra/service-account-keys-cleaner:v20250211-fbc77d1c"
                                    name           = ""
                                    # (10 unchanged attributes hidden)
                                },
                            ]
                            # (5 unchanged attributes hidden)
                        },
                    ]
                    # (1 unchanged attribute hidden)
                },
            ]
            # (7 unchanged attributes hidden)
        }
        # (2 unchanged attributes hidden)
    }
  ~ service_account_keys_rotator                   = {
      ~ service_account_keys_rotator_cloud_run_service   = {
            id                         = "locations/europe-west4/namespaces/sap-kyma-prow/services/service-account-keys-rotator"
            name                       = "service-account-keys-rotator"
          ~ template                   = [
              ~ {
                  ~ spec     = [
                      ~ {
                          ~ containers            = [
                              ~ {
                                  ~ image          = "europe-docker.pkg.dev/kyma-project/prod/test-infra/rotate-service-account:v20250207-43ce8529" -> "europe-docker.pkg.dev/kyma-project/prod/test-infra/rotate-service-account:v20250211-fbc77d1c"
                                    name           = ""
                                    # (10 unchanged attributes hidden)
                                },
                            ]
                            # (5 unchanged attributes hidden)
                        },
                    ]
                    # (1 unchanged attribute hidden)
                },
            ]
            # (7 unchanged attributes hidden)
        }
        # (3 unchanged attributes hidden)
    }

@Sawthis Sawthis merged commit d7ce898 into kyma-project:main Feb 11, 2025
10 checks passed
@kyma-bot
Copy link
Contributor Author

❌ Apply Result

CI link

Error: Error acquiring the state lock

Error message: writing
"gs://tf-state-kyma-project/kyma-test-infra-prod/default.tflock" failed:
googleapi: Error 412: At least one of the pre-conditions you specified did
not hold., conditionNotMet
Lock Info:
  ID:        1739267542480725
  Path:      gs://tf-state-kyma-project/kyma-test-infra-prod/default.tflock
  Operation: OperationTypePlan
  Who:       runner@fv-az813-993
  Version:   1.6.1
  Created:   2025-02-11 09:52:21.81422773 +0000 UTC
  Info:      


OpenTofu acquires a state lock to protect the state from being written
by multiple users at the same time. Please resolve the issue above and try
again. For most commands, you can disable locking with the "-lock=false"
flag, but this is not recommended.
Details (Click me)
Acquiring state lock. This may take a few moments...

Error: Error acquiring the state lock

Error message: writing
"gs://tf-state-kyma-project/kyma-test-infra-prod/default.tflock" failed:
googleapi: Error 412: At least one of the pre-conditions you specified did
not hold., conditionNotMet
Lock Info:
  ID:        1739267542480725
  Path:      gs://tf-state-kyma-project/kyma-test-infra-prod/default.tflock
  Operation: OperationTypePlan
  Who:       runner@fv-az813-993
  Version:   1.6.1
  Created:   2025-02-11 09:52:21.81422773 +0000 UTC
  Info:      


OpenTofu acquires a state lock to protect the state from being written
by multiple users at the same time. Please resolve the issue above and try
again. For most commands, you can disable locking with the "-lock=false"
flag, but this is not recommended.

`

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
add-or-update auto-approved Denotes a PR that was approved by automation. cla: yes Indicates the PR's author has signed the CLA. lgtm Looks good to me! size/M Denotes a PR that changes 30-99 lines, ignoring generated files.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants