Skip to content

feat(release): publish Konflux release bundles - #291

Merged
jsell-rh merged 8 commits into
mainfrom
feat/konflux-release-bundle
Sep 15, 2026
Merged

jsell-rh merged 8 commits into
mainfrom
feat/konflux-release-bundle

Conversation

@jsell-rh

@jsell-rh jsell-rh commented Sep 15, 2026 •

Copy link
Copy Markdown
Collaborator

Publish the three component images from a successful Konflux managed release as one OCI bundle. Reuse the API server build repository in Quay with release-bundle-* tags. The JSON contains the released image digests and each component's source revision.

The final pipeline rejects failed releases, incomplete image sets, digest mismatches, and source revisions outside main. It uses the existing Konflux build account and its repository credential. The tenant ReleasePlan must enable this pipeline in a separate config MR with revision main.

The publisher reads the resolved Git commit from its PipelineRun provenance and fetches the Python script from that commit. A change to main during the run cannot change the script version. Missing or invalid provenance stops publication. The step runs as non-root with all Linux capabilities removed and privilege escalation disabled.

Validation: nine tests passed locally and in the pinned publisher image as UID 1001. The tests cover the release checks, use of the resolved pipeline commit, missing provenance, and a failed PipelineRun read. Tekton schema and shell syntax checks passed. An earlier local OCI test confirmed that repeated publication gives the same digest and that the downloaded JSON matches the input. Live Konflux permissions, credentials, provenance, and Kargo discovery still require the first cluster test.

This PR does not enable deployment. Merge it before the tenant config MR. Konflux Snapshots can include earlier images for unchanged or still-building components; the bundle preserves the accepted Snapshot.

@coderabbitai

coderabbitai Bot commented Sep 15, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository YAML (base), Central YAML (inherited)

Review profile: CHILL

Plan: Advanced

Run ID: 32c4bcd1-cd89-4b6d-9751-e96a3258f119

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Sep 15, 2026 •

Copy link
Copy Markdown

HyperShell environment deploying

Deploying commit ea9088b to an ephemeral OpenShift environment. This
comment will update in place once the environment is ready.

@jsell-rh
jsell-rh marked this pull request as ready for review September 15, 2026 21:00
@jsell-rh
jsell-rh enabled auto-merge September 15, 2026 21:03
@amber-review-bot

amber-review-bot commented Sep 15, 2026 •

Copy link
Copy Markdown
Collaborator

Amber review: comment

Amber review

Status: Complete

View the submitted review.

amber-review-bot

This comment was marked as outdated.

@jsell-rh jsell-rh changed the title Publish Konflux release bundles in the existing Quay repository feat(release): publish Konflux release bundles Sep 15, 2026
amber-review-bot

This comment was marked as outdated.

@jsell-rh
jsell-rh disabled auto-merge September 15, 2026 21:39

@amber-review-bot amber-review-bot left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verdict

The release-bundle publisher is well-gated and the offline test suite (9 tests) passes locally; since the prior review the only change is a merge of main (renovate config), so the publisher, pipeline, and tests are unchanged. The previously flagged restricted securityContext and Conventional Commit title are in place; one Low-confidence defense-in-depth item remains and is already tracked in an existing thread.

Strengths

  • Pre-registry gating in make_bundle is thorough: release plan, namespace, ManagedPipelineProcessed=Succeeded, exact three-component set, digest-to-snapshot match, and source-on-main are all checked before any registry call.
  • Provenance-pinned bootstrap: the script is fetched from the exact commit Tekton resolved (status.provenance.refSource.digest.sha1, validated as 40 hex chars); a missing/invalid sha1 or a failed read stops publication before any git/publisher call (covered by tests).
  • Reproducible by construction: tag and OCI created derive from the Snapshot time and a Release-UID hash, and the pushed manifest digest is re-verified after push.
  • Secret hygiene: registry credentials are written to a 0600 file in a TemporaryDirectory and never logged.
  • Restricted step securityContext is explicit in pipeline.yaml (runAsNonRoot, allowPrivilegeEscalation: false, drop ALL, seccompProfile: RuntimeDefault).

Cross-PR coordination

Coordinate with #237 on what constitutes a "release" that produces a bundle. #237 reworks the .tekton push triggers and the CI change-detection so that a VERSION (Release Please) merge to main builds all three component images together from one commit, while an ordinary push builds only the changed component. This PR's publisher instead fires on any successful managed-release push Snapshot and deliberately preserves whatever Snapshot was accepted, bundling components that may originate from different source revisions (see pipelines/release-bundle/README.md: "This pipeline preserves the accepted Snapshot; it does not add a test that waits for all builds from one commit"). Both PRs define the release-triggering model, so maintainers should decide whether bundle publication keys off #237's VERSION-driven all-three-from-one-commit builds or continues to publish from every push Snapshot, and confirm the merge order that keeps the two consistent.

Previous concerns

  • Restricted securityContext on the publish step - Addressed. pipelines/release-bundle/pipeline.yaml (steps[].securityContext) sets runAsNonRoot: true, allowPrivilegeEscalation: false, capabilities.drop: [ALL], and seccompProfile.type: RuntimeDefault.
  • push event-type gate is skipped when the annotation is absent - Still present. In scripts/release_bundle.py the require(value == "push", ...) check runs only inside if key.endswith("/event-type"), so a Snapshot with no event-type annotation passes this gate. This remains a Low-confidence defense-in-depth item behind the stronger hypershell-releaseplan / ManagedPipelineProcessed=Succeeded / no-pull-request gates; tracked in the existing thread. No new inline comment added.
  • PR title lacked a Conventional Commit prefix - Addressed. The title is now feat(release): publish Konflux release bundles.

Findings

Minor

  1. push event-type enforcement is conditional on the annotation being present (scripts/release_bundle.py). Unchanged from the prior review and tracked in the existing inline thread. A positive assertion that a push event-type was seen (reject if none) would be stronger defense in depth. Confidence: Low.

Note

Live behavior (Konflux credentials, select-oci-auth, oras push, PipelineRun provenance, Kargo discovery) is not exercisable in CI and, as the PR body states, still needs the first cluster run. The offline tests cannot prove those paths.

Findings Summary (ordered by severity, highest first)

  1. [Minor] push event-type gate is skipped when the annotation is absent (existing thread) - Input Validation / Defense in Depth (scripts/release_bundle.py)

Convention Checklist

Convention Result
No secrets in logs or responses Pass
Input validated (digests, revisions, resource names, resolved commit) Pass
Reproducible / idempotent publish Pass
Errors propagate (no swallowed failures) Pass
Restricted SecurityContext on all containers Pass
Conventional commit message Pass
Tests added and passing Pass

@jsell-rh
jsell-rh merged commit 6c17321 into main Sep 15, 2026
2 of 3 checks passed
@jsell-rh
jsell-rh deleted the feat/konflux-release-bundle branch September 15, 2026 21:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants