Uploaded image for project: 'OpenShift Bugs'
  1. OpenShift Bugs
  2. OCPBUGS-33378

Builds TestWebhook failed on step testing unauthenticated forbidden on upgrade


    • Icon: Bug Bug
    • Resolution: Done-Errata
    • Icon: Critical Critical
    • 4.16.0
    • 4.16
    • Build
    • None
    • Important
    • No
    • 2
    • Builds Sprint #3
    • 1
    • Proposed
    • False
    • Hide


    • Hide
      Previously, clusters that updated from earlier versions to 4.16 continued to allow builds to be triggered by unauthenticated webhooks. With this release, new clusters require build webhooks to be authenticated. Builds are not triggered by unauthenticated webhooks unless a cluster admin allows unauthenticated wehbooks in the namespace or cluster.
      Previously, clusters that updated from earlier versions to 4.16 continued to allow builds to be triggered by unauthenticated webhooks. With this release, new clusters require build webhooks to be authenticated. Builds are not triggered by unauthenticated webhooks unless a cluster admin allows unauthenticated wehbooks in the namespace or cluster.
    • Bug Fix
    • Done

      During jobs that upgrade to 4.16 from 4.15, the testing of unauthenticated build webhook invocation fails (I suspect due to the existing rolebindings from 4.15 surviving the upgrade).

      [sig-builds][Feature:Builds][webhook] TestWebhook [apigroup:build.openshift.io][apigroup:image.openshift.io] [Suite:openshift/conformance/parallel] 
          STEP: testing unauthenticated forbidden webhooks @ 05/07/24 20:03:20.024
          STEP: executing the webhook to get the build object @ 05/07/24 20:03:20.024
          [FAILED] in [It] - github.com/openshift/origin/test/extended/builds/webhook.go:36 @ 05/07/24 20:03:20.148


            adkaplan@redhat.com Adam Kaplan
            lusanche@redhat.com Luis Sanchez
            Sayan Biswas Sayan Biswas
            0 Vote for this issue
            9 Start watching this issue
