Update repositories and container images (2025.1) - #2502
Conversation
|
Important Review skippedAuto incremental reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
📝 WalkthroughUpdated 2025.1 Kolla, overcloud host image, OFED, and Pulp repository versions for Rocky Linux and Ubuntu. Added Grafana and OpenSearch Dashboard vulnerability allowances. Documented updated OFED modules and the Rocky Linux 9.8 security kernel. WalkthroughThis change refreshes Kolla and Overcloud image tags, OFED kernel module versions, Pulp repository timestamps, vulnerability allowlists, and release notes for Rocky Linux and Ubuntu environments. ChangesConfiguration refresh
Estimated code review effort: 2 (Simple) | ~10 minutes Possibly related PRs
🚥 Pre-merge checks | ✅ 3✅ Passed checks (3 passed)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 2
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: 63cf436b-564a-461a-8b00-8577f5c1e96b
📒 Files selected for processing (6)
etc/kayobe/kolla-image-tags.ymletc/kayobe/ofed.ymletc/kayobe/pulp-host-image-versions.ymletc/kayobe/pulp-repo-versions.ymletc/kayobe/trivy/allowed-vulnerabilities.ymlreleasenotes/notes/repo-bump-20260808-c75da1bda2befae7.yaml
📜 Review details
⏰ Context from checks skipped due to timeout. (3)
- GitHub Check: stackhpc/check
- GitHub Check: Ansible 2.18 lint with Python 3.12
- GitHub Check: Ansible 2.17 lint with Python 3.10
🔇 Additional comments (4)
etc/kayobe/trivy/allowed-vulnerabilities.yml (1)
27-27: 🔒 Security & PrivacyVerify both exceptions against the deployed package versions.
These vulnerable IDs are copied by
tools/scan-images.shinto.trivyignore.GHSA-r277-6w6q-xmqwcovers authentication bypass ingithub.com/getkin/kin-openapi/openapi3filterversions before0.144.0;CVE-2026-59873coversnode-tarversions before7.5.19. Confirm the affected package versions are deployed and reachable before suppressing CRITICAL findings; if suppression is required, add an inline reason and a removal condition.Also applies to: 69
etc/kayobe/pulp-host-image-versions.yml (1)
4-8: 🩺 Stability & AvailabilityVerify that every new host image exists in SMS.
The file states that these images must be in SMS.
etc/kayobe/stackhpc-overcloud-host-images.ymlbuilds deployment URLs directly from these values. Verify the2025.1-20260809T214130snapshot for Rocky 9, Rocky 10, both Rocky architectures, and Ubuntu Noble. A missing path will fail host-image deployment or AIO CI.etc/kayobe/ofed.yml (1)
22-23: 🗄️ Data Integrity & IntegrationVerify that the new kernel module builds exist in the selected Pulp snapshots.
Lines 22-23 feed
doca_kernel_versioninetc/kayobe/ansible/tools/install-doca.yml. The changed snapshots inetc/kayobe/pulp-repo-versions.ymlLines 35-40 must contain5.14.0.687.36.1.el9.8and6.12.0.211.43.1.el10.2for both architectures. Verify the exact package paths before merge. A missing package will fail DOCA installation.etc/kayobe/pulp-repo-versions.yml (1)
5-8: LGTM!Also applies to: 15-18, 43-43, 45-52, 57-57, 62-62, 85-91, 93-93, 97-102, 161-167, 169-169, 176-184
55feabc to
fc3ec6a
Compare
No description provided.