-
Epic
-
Resolution: Unresolved
-
Major
-
None
-
None
-
None
-
Introduce tests for new permissions required as presubmit tests on PRs
-
False
-
None
-
False
-
Green
-
To Do
-
OCPSTRAT-1664 - Continuosly test minimum permissions required for AWS ROSA
-
OCPSTRAT-1664Continuosly test minimum permissions required for AWS ROSA
-
10% To Do, 10% In Progress, 80% Done
-
OCP/Telco Definition of Done
Epic Template descriptions and documentation.
<--- Cut-n-Paste the entire contents of this description into your new Epic --->
Epic Goal
- To introduce tests for new permissions required as presubmit tests on PRs so so PR authors can see whenever their changes affect the minimum required permissions
Why is this important?
- Currently the process is that QE installs with the documented minimum permissions, that starts failing whenever something new unknowingly requires additional permissions. That test runs once a week. When it fails QE reviews and files bugs, installer then goes and adds them to a file which tracks the required permissions in the installer repo.
- The issue is that it takes some time to get a permissions change implemented by AWS, so the late discovery of a need can become a release blocker
Acceptance Criteria
- CI - MUST be running successfully with tests automated
- Release Technical Enablement - Provide necessary release enablement details and documents.
- ...
Open questions::
- The details of what would happen when the tests then fail and a new permission is required for example. As in would it be a new PR or what documentation we need to put in place to explain.
Done Checklist
- CI - CI is running, tests are automated and merged.
- Release Enablement <link to Feature Enablement Presentation>
- DEV - Upstream code and tests merged: <link to meaningful PR or GitHub Issue>
- DEV - Upstream documentation merged: <link to meaningful PR or GitHub Issue>
- DEV - Downstream build attached to advisory: <link to errata>
- QE - Test plans in Polarion: <link or reference to Polarion>
- QE - Automated tests merged: <link or reference to automated tests>
- DOC - Downstream documentation merged: <link to meaningful PR>
- is related to
-
SPLAT-1843 [aws][CI] Continuously track minimum permissions used by OpenShift cluster on AWS - Part 1 (track required permissions)
- In Progress
- is triggering
-
OCPBUGS-44745 [aws] tag:UntagResources when destroying cluster with BYO IAM profile
- POST
-
OCPBUGS-43439 [aws] ec2:DescribeInstanceTypes permission is required when instance type specified
- ON_QA
- relates to
-
OCPBUGS-35378 Assess whether AWS perms are still required
- ASSIGNED
-
OCPBUGS-43453 [aws] ec2:DescribeInstanceTypeOfferings permission required when zones not specified
- POST
- links to