feat(release): publish Konflux release bundles - #291
Conversation
|
Important Review skippedAuto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Repository YAML (base), Central YAML (inherited) Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Comment |
HyperShell environment deployingDeploying commit |
…o feat/konflux-release-bundle
Amber reviewStatus: Complete |
amber-review-bot
left a comment
There was a problem hiding this comment.
Verdict
The release-bundle publisher is well-gated and the offline test suite (9 tests) passes locally; since the prior review the only change is a merge of main (renovate config), so the publisher, pipeline, and tests are unchanged. The previously flagged restricted securityContext and Conventional Commit title are in place; one Low-confidence defense-in-depth item remains and is already tracked in an existing thread.
Strengths
- Pre-registry gating in
make_bundleis thorough: release plan, namespace,ManagedPipelineProcessed=Succeeded, exact three-component set, digest-to-snapshot match, and source-on-mainare all checked before any registry call. - Provenance-pinned bootstrap: the script is fetched from the exact commit Tekton resolved (
status.provenance.refSource.digest.sha1, validated as 40 hex chars); a missing/invalidsha1or a failed read stops publication before anygit/publisher call (covered by tests). - Reproducible by construction: tag and OCI
createdderive from the Snapshot time and a Release-UID hash, and the pushed manifest digest is re-verified after push. - Secret hygiene: registry credentials are written to a
0600file in aTemporaryDirectoryand never logged. - Restricted step
securityContextis explicit inpipeline.yaml(runAsNonRoot,allowPrivilegeEscalation: false, dropALL,seccompProfile: RuntimeDefault).
Cross-PR coordination
Coordinate with #237 on what constitutes a "release" that produces a bundle. #237 reworks the .tekton push triggers and the CI change-detection so that a VERSION (Release Please) merge to main builds all three component images together from one commit, while an ordinary push builds only the changed component. This PR's publisher instead fires on any successful managed-release push Snapshot and deliberately preserves whatever Snapshot was accepted, bundling components that may originate from different source revisions (see pipelines/release-bundle/README.md: "This pipeline preserves the accepted Snapshot; it does not add a test that waits for all builds from one commit"). Both PRs define the release-triggering model, so maintainers should decide whether bundle publication keys off #237's VERSION-driven all-three-from-one-commit builds or continues to publish from every push Snapshot, and confirm the merge order that keeps the two consistent.
Previous concerns
- Restricted
securityContexton the publish step - Addressed.pipelines/release-bundle/pipeline.yaml(steps[].securityContext) setsrunAsNonRoot: true,allowPrivilegeEscalation: false,capabilities.drop: [ALL], andseccompProfile.type: RuntimeDefault. pushevent-type gate is skipped when the annotation is absent - Still present. Inscripts/release_bundle.pytherequire(value == "push", ...)check runs only insideif key.endswith("/event-type"), so a Snapshot with noevent-typeannotation passes this gate. This remains a Low-confidence defense-in-depth item behind the strongerhypershell-releaseplan/ManagedPipelineProcessed=Succeeded/ no-pull-requestgates; tracked in the existing thread. No new inline comment added.- PR title lacked a Conventional Commit prefix - Addressed. The title is now
feat(release): publish Konflux release bundles.
Findings
Minor
pushevent-type enforcement is conditional on the annotation being present (scripts/release_bundle.py). Unchanged from the prior review and tracked in the existing inline thread. A positive assertion that a push event-type was seen (reject if none) would be stronger defense in depth. Confidence: Low.
Note
Live behavior (Konflux credentials, select-oci-auth, oras push, PipelineRun provenance, Kargo discovery) is not exercisable in CI and, as the PR body states, still needs the first cluster run. The offline tests cannot prove those paths.
Findings Summary (ordered by severity, highest first)
- [Minor]
pushevent-type gate is skipped when the annotation is absent (existing thread) - Input Validation / Defense in Depth (scripts/release_bundle.py)
Convention Checklist
| Convention | Result |
|---|---|
| No secrets in logs or responses | Pass |
| Input validated (digests, revisions, resource names, resolved commit) | Pass |
| Reproducible / idempotent publish | Pass |
| Errors propagate (no swallowed failures) | Pass |
| Restricted SecurityContext on all containers | Pass |
| Conventional commit message | Pass |
| Tests added and passing | Pass |

Publish the three component images from a successful Konflux managed release as one OCI bundle. Reuse the API server build repository in Quay with
release-bundle-*tags. The JSON contains the released image digests and each component's source revision.The final pipeline rejects failed releases, incomplete image sets, digest mismatches, and source revisions outside main. It uses the existing Konflux build account and its repository credential. The tenant ReleasePlan must enable this pipeline in a separate config MR with revision
main.The publisher reads the resolved Git commit from its PipelineRun provenance and fetches the Python script from that commit. A change to main during the run cannot change the script version. Missing or invalid provenance stops publication. The step runs as non-root with all Linux capabilities removed and privilege escalation disabled.
Validation: nine tests passed locally and in the pinned publisher image as UID 1001. The tests cover the release checks, use of the resolved pipeline commit, missing provenance, and a failed PipelineRun read. Tekton schema and shell syntax checks passed. An earlier local OCI test confirmed that repeated publication gives the same digest and that the downloaded JSON matches the input. Live Konflux permissions, credentials, provenance, and Kargo discovery still require the first cluster test.
This PR does not enable deployment. Merge it before the tenant config MR. Konflux Snapshots can include earlier images for unchanged or still-building components; the bundle preserves the accepted Snapshot.