Skip to content

fix issue where there is not default channel - #83177

Merged
openshift-merge-bot[bot] merged 1 commit into
openshift:mainfrom
eifrach:kpi_missing_channel
Aug 10, 2026
Merged

fix issue where there is not default channel#83177
openshift-merge-bot[bot] merged 1 commit into
openshift:mainfrom
eifrach:kpi_missing_channel

Conversation

@eifrach

@eifrach eifrach commented Aug 10, 2026

Copy link
Copy Markdown
Contributor
  • jobs fails when there is not default channel set. on PreGA the default channel is not always published

Summary by CodeRabbit

  • Updates OpenShift CI operator installation jobs to select the first available packagemanifest channel when no default channel is published.
  • Reports an error only when no channel is available.
  • Updates the log message to identify the selected channel without calling it the default channel.

- jobs fails when there is not default channel set. on PreGA the default
  channel is not always published

Signed-off-by: Eran Ifrach <eifrach@redhat.com>
@coderabbitai

coderabbitai Bot commented Aug 10, 2026

Copy link
Copy Markdown
Contributor

Walkthrough

The install-operators command now falls back to the first available channel when no default channel exists. It reports an error only when no channel is available and logs the selected channel.

Changes

Operator channel selection

Layer / File(s) Summary
Channel resolution and reporting
ci-operator/step-registry/install-operators/install-operators-commands.sh
When !default has no default channel, the script queries the first available channel. It reports failure only when no channel exists and logs the selected channel generically.

Estimated code review effort: 1 (Trivial) | ~5 minutes

Suggested reviewers: rlobillo

🚥 Pre-merge checks | ✅ 15
✅ Passed checks (15 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly describes the main change: fixing failures when no default channel exists.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Stable And Deterministic Test Names ✅ Passed The pull request changes only a shell script and adds no Ginkgo test declarations or test titles.
Test Structure And Quality ✅ Passed The PR changes only one Bash step file; no Ginkgo test files or Ginkgo constructs were added or modified, so this test-structure check is not applicable.
Microshift Test Compatibility ✅ Passed The change is limited to a shell command file; no new Ginkgo tests or MicroShift-incompatible test APIs or assumptions were added.
Single Node Openshift (Sno) Test Compatibility ✅ Passed The commit changes only an operator-install shell script; it adds no Ginkgo e2e tests or other test files, so SNO compatibility checks do not apply.
Topology-Aware Scheduling Compatibility ✅ Passed The PR changes only a shell script for operator channel resolution; it adds no deployment, controller, manifest, replica, affinity, topology, node, or PDB scheduling constraints.
Ote Binary Stdout Contract ✅ Passed PASS: The PR changes only a Bash operator-installation script; it adds no openshift-tests/OTE binary, Go entrypoint, suite setup, or process-level stdout write.
Ipv6 And Disconnected Network Test Compatibility ✅ Passed The commit changes only an operator-install shell script; it adds no Ginkgo tests, IPv4 assumptions, or external connectivity requirements.
No-Weak-Crypto ✅ Passed The only changed file adds channel fallback and log messages; the patch contains no MD5, SHA1, DES, RC4, Blowfish, ECB, crypto, or secret-comparison code.
Container-Privileges ✅ Passed The PR changes only channel resolution in one shell file; added lines contain no prohibited privilege settings, and emitted manifests lack securityContext privilege fields.
No-Sensitive-Data-In-Logs ✅ Passed The changed logs contain only the operator name and selected channel. The fallback adds no password, token, API key, PII, hostname, session ID, or customer data output.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@openshift-ci
openshift-ci Bot requested review from chaclark1974 and sg-rh August 10, 2026 13:40
@openshift-merge-bot

Copy link
Copy Markdown
Contributor

[REHEARSALNOTIFIER]
@eifrach: the pj-rehearse plugin accommodates running rehearsal tests for the changes in this PR. Expand 'Interacting with pj-rehearse' for usage details. The following rehearsable tests have been affected by this change:

Test name Repo Type Reason
pull-ci-red-hat-data-services-ods-ci-release-2.19-rhoai-ocp4.19-interop-rhoai-interop-aws red-hat-data-services/ods-ci presubmit Registry content changed
pull-ci-openshift-grafana-tempo-operator-main-upstream-ocp-4.12-amd64-tempo-upstream-tests openshift/grafana-tempo-operator presubmit Registry content changed
pull-ci-openshift-grafana-tempo-operator-main-upstream-ocp-4.22-amd64-tempo-upstream-tests openshift/grafana-tempo-operator presubmit Registry content changed
pull-ci-openshift-grafana-tempo-operator-main-upstream-ocp-4.21-amd64-tempo-upstream-tests openshift/grafana-tempo-operator presubmit Registry content changed
pull-ci-openshift-open-telemetry-opentelemetry-operator-main-upstream-ocp-4.21-amd64-opentelemetry-upstream-tests openshift/open-telemetry-opentelemetry-operator presubmit Registry content changed
pull-ci-openshift-open-telemetry-opentelemetry-operator-main-upstream-ocp-4.12-amd64-opentelemetry-upstream-tests openshift/open-telemetry-opentelemetry-operator presubmit Registry content changed
pull-ci-openshift-open-telemetry-opentelemetry-operator-main-upstream-ocp-4.22-amd64-opentelemetry-upstream-tests openshift/open-telemetry-opentelemetry-operator presubmit Registry content changed
pull-ci-openshift-faas-console-plugin-master-e2e-aws openshift/faas-console-plugin presubmit Registry content changed
pull-ci-openshift-cnv-virt-cluster-validate-main-e2e-azure openshift-cnv/virt-cluster-validate presubmit Registry content changed
pull-ci-openshift-cnv-virt-cluster-validate-main-e2e-gcp openshift-cnv/virt-cluster-validate presubmit Registry content changed
periodic-ci-openshift-openshift-tests-private-release-4.22-multi-stable-openshift-logging-6.6-gcp-ipi-arm-fips-f999-logging N/A periodic Registry content changed
periodic-ci-jboss-eap-qe-openshift-eap-tests-pit-7.4.x-eap-ocp4.18-lp-interop-eap-74-interop-aws N/A periodic Registry content changed
periodic-ci-openshift-cluster-nfd-operator-release-4.19-ocp4.19-lp-rosa-hypershift-nfd-e2e-master-aws-rosa-hypershift N/A periodic Registry content changed
periodic-ci-openshift-openshift-tests-private-release-4.16-amd64-nightly-openshift-logging-5.9-gcp-ipi-ovn-ipsec-fips-f999-logging N/A periodic Registry content changed
periodic-ci-oadp-qe-oadp-qe-automation-main-oadp1.4-ocp4.17-lp-interop-oadp-interop-aws N/A periodic Registry content changed
periodic-ci-oadp-qe-oadp-qe-automation-oadp-1.5-oadp1.5-ocp4.20-lp-interop-oadp-interop-aws-fips N/A periodic Registry content changed
periodic-ci-openshift-kni-eco-ci-cd-ztp-left-shifting-kpi-ci-4.22-telcov10n-virtualised-single-node-hub-ztp N/A periodic Registry content changed
periodic-ci-jboss-eap-qe-openshift-eap-tests-pit-7.4.x-eap-ocp4.16-lp-interop-eap-74-xp-interop-ibmcloud N/A periodic Registry content changed
periodic-ci-jboss-fuse-camel-k-test-container-main-camel-k-ocp4.18-lp-interop-camel-k-interop-aws N/A periodic Registry content changed
periodic-ci-jboss-fuse-camel-k-test-container-main-camel-k-ocp4.18-lp-interop-camel-k-interop-aws-fips N/A periodic Registry content changed
periodic-ci-jboss-eap-qe-openshift-eap-tests-pit-7.4.x-eap-ocp4.17-lp-interop-eap-74-xp-interop-aws N/A periodic Registry content changed
periodic-ci-openshift-open-telemetry-opentelemetry-operator-main-opentelemetry-product-ocp-4.16-ibm-z-stage-opentelemetry-stage-tests N/A periodic Registry content changed
periodic-ci-openshift-service-mesh-sail-operator-lpinterop-3.4-ocp-4.22-lp-interop-servicemesh-aws-fips N/A periodic Registry content changed
periodic-ci-oadp-qe-oadp-qe-automation-oadp-1.4-oadp1.4-ocp4.18-lp-interop-oadp-interop-aws-fips N/A periodic Registry content changed
periodic-ci-rhobs-observability-operator-main-amd64-ocp-4.19-gcp-coo-stage N/A periodic Registry content changed

A total of 256 jobs have been affected by this change. The above listing is non-exhaustive and limited to 25 jobs.

A full list of affected jobs can be found here
Prior to this PR being merged, you will need to either run and acknowledge or opt to skip these rehearsals.

Interacting with pj-rehearse

Comment: /pj-rehearse to run up to 5 rehearsals
Comment: /pj-rehearse skip to opt-out of rehearsals
Comment: /pj-rehearse {test-name}, with each test separated by a space, to run one or more specific rehearsals
Comment: /pj-rehearse more to run up to 10 rehearsals
Comment: /pj-rehearse max to run up to 25 rehearsals
Comment: /pj-rehearse auto-ack to run up to 5 rehearsals, and add the rehearsals-ack label on success
Comment: /pj-rehearse list to get an up-to-date list of affected jobs
Comment: /pj-rehearse abort to abort all active rehearsals
Comment: /pj-rehearse network-access-allowed to allow rehearsals of tests that have the restrict_network_access field set to false. This must be executed by an openshift org member who is not the PR author

Once you are satisfied with the results of the rehearsals, comment: /pj-rehearse ack to unblock merge. When the rehearsals-ack label is present on your PR, merge will no longer be blocked by rehearsals.
If you would like the rehearsals-ack label removed, comment: /pj-rehearse reject to re-block merging.

@eifrach

eifrach commented Aug 10, 2026

Copy link
Copy Markdown
Contributor Author

/pj-rehearse ack

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@ci-operator/step-registry/install-operators/install-operators-commands.sh`:
- Around line 81-87: Update the `!default` behavior documentation in `README.md`
to state that it uses the package default channel when available and falls back
to the first available channel otherwise. Keep the existing installation
semantics and terminology consistent with the `operator_channel` fallback flow.
- Around line 83-84: Quote the packagemanifest lookup arguments in both the
default-channel and fallback lookup paths: preserve operator_name as a single
value inside the jsonpath expression and quote operator_source in the catalog
label expression so glob characters remain literal. Update the corresponding oc
invocations without changing their lookup behavior.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Central YAML (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: 4761372d-75c7-4150-bb11-005d3e8fc125

📥 Commits

Reviewing files that changed from the base of the PR and between 9be95ee and ffdd128.

📒 Files selected for processing (1)
  • ci-operator/step-registry/install-operators/install-operators-commands.sh

Comment on lines +81 to +87
echo "WARNING: Default channel not found in '${operator_name}' packagemanifest. Falling back to the first available channel."
operator_channel=$(oc get packagemanifest \
-l catalog=${operator_source} \
-ojsonpath='{.items[?(.metadata.name=="'${operator_name}'")].status.channels[0].name}' 2>/dev/null || echo)
fi
if [[ -z "${operator_channel}" ]]; then
echo "ERROR: No channel found in '${operator_name}' packagemanifest."

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🗄️ Data Integrity & Integration | 🟡 Minor | ⚡ Quick win

Document the new !default fallback behavior.

ci-operator/step-registry/install-operators/README.md Lines 68-73 says that !default installs from the package default channel. This code now selects status.channels[0].name when no default channel exists. Update the documentation to state that !default uses the default channel when available and otherwise uses the first available channel.

🧰 Tools
🪛 Shellcheck (0.11.0)

[info] 83-83: Double quote to prevent globbing and word splitting.

(SC2086)


[info] 84-84: Double quote to prevent globbing and word splitting.

(SC2086)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@ci-operator/step-registry/install-operators/install-operators-commands.sh`
around lines 81 - 87, Update the `!default` behavior documentation in
`README.md` to state that it uses the package default channel when available and
falls back to the first available channel otherwise. Keep the existing
installation semantics and terminology consistent with the `operator_channel`
fallback flow.

Comment on lines +83 to +84
-l catalog=${operator_source} \
-ojsonpath='{.items[?(.metadata.name=="'${operator_name}'")].status.channels[0].name}' 2>/dev/null || echo)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo "Files:"
git ls-files | rg '(^|/)install-operators-commands\.sh$|install-operators/README\.md' || true

echo
echo "Relevant command script lines:"
sed -n '1,220p' ci-operator/step-registry/install-operators/install-operators-commands.sh || true

echo
echo "Relevant README lines:"
sed -n '1,140p' ci-operator/step-registry/install-operators/README.md || true

Repository: openshift/release

Length of output: 13968


🏁 Script executed:

#!/bin/bash
set -euo pipefail

python3 - <<'PY'
import shlex

def current_lookup(operator_source, operator_name):
    import subprocess, tempfile, os
    script = f"""#!/bin/bash
set -euo pipefail
operator_source={operator_source}
operator_name={operator_name}
printf '%s\\n' "$operator_source" "$operator_name"
"""
    with tempfile.NamedTemporaryFile('w', delete=False, suffix='.sh') as f:
        f.write(script)
        path = f.name
    try:
        os.chmod(path, 0o755)
        return subprocess.run(['bash', path], text=True, stdout=subprocess.PIPE, stderr=subprocess.PIPE).stdout
    finally:
        os.unlink(path)

def fixed_lookup(operator_source, operator_name):
    import subprocess, tempfile, os
    script = f"""#!/bin/bash
set -euo pipefail
operator_source={operator_source}
operator_name={operator_name}
printf '%s\\n' "$operator_source" "$operator_name"
"""
    with tempfile.NamedTemporaryFile('w', delete=False, suffix='.sh') as f:
        f.write(script)
        path = f.name
    try:
        os.chmod(path, 0o755)
        return subprocess.run(['bash', path], text=True, stdout=subprocess.PIPE, stderr=subprocess.PIPE).stdout
    finally:
        os.unlink(path)

cases = [
    "normal",
    "source with space",
    "**glob**",
    "name space",
]
for base in cases:
    print(base)
    print(current_lookup(base, "pkg"))
    print(fixed_lookup(base, "pkg"))

# Inspect the exact expansion paths in bash without executing repository code:
script = r'''
set -euo pipefail
operator_source='source name *'
operator_name='foo bar'
echo "expanded unquoted lines:"
printf '%s\n' "catalog=${operator_source}" "metadata.name==\""${operator_name}\"""
'''
print("direct expansion probe:")
print(subprocess.run(['bash','-c',script], text=True, stdout=subprocess.PIPE).stdout)
PY

Repository: openshift/release

Length of output: 398


🏁 Script executed:

#!/bin/bar

Repository: openshift/release

Length of output: 155


🏁 Script executed:

#!/bin/bash
set -euo pipefail
shopt -s extglobs

echo 'Unquoted expansions'
operator_source='source name *'
operator_name='foo bar'
set -x
echo "catalog=${operator_source}"
printf '%s\n' "metadata.name==\""${operator_name}\"""
set +x

echo
echo 'Quoted expansions'
operator_source='source name *'
operator_name='foo bar'
set -x
echo "catalog=\"${operator_source}\""
printf '%s\n' "metadata.name==\"${operator_name}\""
set +x

Repository: openshift/release

Length of output: 212


🏁 Script executed:

#!/bin/bar

Repository: openshift/release

Length of output: 155


🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo 'Unquoted expansions'
operator_source='source name *'
operator_name='foo bar'
set -x
echo "catalog=${operator_source}"
printf '%s\n' "metadata.name==\""${operator_name}\"""
set +x

echo
echo 'Quoted expansions'
operator_source='source name *'
operator_name='foo bar'
set -x
echo "catalog=\"${operator_source}\""
printf '%s\n' "metadata.name==\"${operator_name}\""
set +x

Repository: openshift/release

Length of output: 460


Quote the packagemanifest lookup labels and jsonpath.

If operator_name contains whitespace, the unquoted expansion inside the jsonpath expression is split before oc reads it, which can make the packagemanifest lookup fail. Apply the same quoting to operator_source to keep glob values stable in the label expression. Apply the fix to both the default-channel lookup and the fallback lookup.

🧰 Tools
🪛 Shellcheck (0.11.0)

[info] 83-83: Double quote to prevent globbing and word splitting.

(SC2086)


[info] 84-84: Double quote to prevent globbing and word splitting.

(SC2086)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@ci-operator/step-registry/install-operators/install-operators-commands.sh`
around lines 83 - 84, Quote the packagemanifest lookup arguments in both the
default-channel and fallback lookup paths: preserve operator_name as a single
value inside the jsonpath expression and quote operator_source in the catalog
label expression so glob characters remain literal. Update the corresponding oc
invocations without changing their lookup behavior.

Source: Linters/SAST tools

@rdiazcam

Copy link
Copy Markdown
Contributor

/lgtm

@openshift-ci openshift-ci Bot added the lgtm Indicates that a PR is ready to be merged. label Aug 10, 2026
@openshift-merge-bot

Copy link
Copy Markdown
Contributor

@eifrach: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel.

@openshift-merge-bot openshift-merge-bot Bot added the rehearsals-ack Signifies that rehearsal jobs have been acknowledged label Aug 10, 2026

@sg-rh sg-rh left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/approve

@openshift-ci

openshift-ci Bot commented Aug 10, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: eifrach, rdiazcam, sg-rh

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci openshift-ci Bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Aug 10, 2026
@openshift-ci

openshift-ci Bot commented Aug 10, 2026

Copy link
Copy Markdown
Contributor

@eifrach: all tests passed!

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

@openshift-merge-bot
openshift-merge-bot Bot merged commit 47597c3 into openshift:main Aug 10, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. lgtm Indicates that a PR is ready to be merged. rehearsals-ack Signifies that rehearsal jobs have been acknowledged

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants