Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
83 commits
Select commit Hold shift + click to select a range
6e2a484
update components/mintmaker/staging/base/kustomization.yaml (#11798)
rh-tap-build-team[bot] May 14, 2026
7516ee8
policies: rollout queue-config policy to prod (#11787)
sadlerap May 14, 2026
7f71f2f
info: announce maintenance on Friday, May 15th (#11792)
sadlerap May 14, 2026
ea766a8
update opentelemetry-collector for KubeArchive prod config (#11776)
olegbet May 14, 2026
75f41ae
update components/mintmaker/production/base/kustomization.yaml (#11802)
rh-tap-build-team[bot] May 14, 2026
679275d
Add k8s groups component (#11786)
enkeefe00 May 14, 2026
37f7983
Fix k8s-groups to not deploy in cluster (#11809)
hugares May 14, 2026
0d52da0
bump build-service (#11810)
rcerven May 14, 2026
6eee61d
Promoting component build-service from stage to prod (#11815)
rcerven May 14, 2026
21caa25
Add self-healing to k8s-groups apps (#11822)
enkeefe00 May 14, 2026
3f92379
Delete group-sync-operator from staging (#11816)
enkeefe00 May 14, 2026
b774a53
Deploy k8s-groups to production clusters (#11824)
enkeefe00 May 14, 2026
1f5d9c9
feat(KONFLUX-13961): Update perf in-cluster dashboards (#11758)
jhutar May 15, 2026
cb4df72
add tokens in tekton-kueue (#10850)
filariow May 15, 2026
0b360fb
Change Fedora k8s-group to use FAS folder (#11833)
hugares May 15, 2026
afce8d0
KONFLUX-13356: upgrade kueue operator and tekton-kueue for prod ring …
glevi-rh May 17, 2026
c3c14bf
fix: token resource sanitized name (#11854)
filariow May 18, 2026
fce7eee
KFLUXINFRA-3786: revoke Role write permissions from tenant admins (st…
manish-jangra May 19, 2026
80cc5a0
feat(KONFLUX-14043): Enable appsre-stonesoup-vault for perfscale-2 an…
jhutar May 19, 2026
0976a8a
KONFLUX-13356: migrate kueue CRs to v1beta2 for prod ring 1 (#11842)
glevi-rh May 19, 2026
8c65afd
feat(KONFLUX-14043): Enable appsre-stonesoup-vault for perfscale-2 an…
jhutar May 19, 2026
afca921
Remove group-sync from production environments (#11835)
enkeefe00 May 19, 2026
9f2749f
chore: bump konflux-ui (production) ed23c9b83394 => 1e667c457a66 (#11…
sahil143 May 19, 2026
7d40a95
chore(STONEINTG-1594): add endpoint params for image_rbac_proxy (#11888)
jencull May 19, 2026
c9929cd
update components/konflux-operator/development/invariant/kustomizatio…
rh-tap-build-team[bot] May 20, 2026
2eb48fe
test(KFLUXVNGD-924): placeholder for openshift CI operator tests (#11…
yftacherzog May 20, 2026
b8899ab
SPRE-5349: add kube_deployment_status_replicas_updated metric for tek…
asafaviv-devops May 20, 2026
8d4af6b
update components/mintmaker/staging/base/kustomization.yaml (#11908)
rh-tap-build-team[bot] May 20, 2026
231af8a
Upgrade kubearchive to v1.21.4 in stone-prod-p02 (#11895)
maruiz93 May 20, 2026
f28ded3
Ring 0: promote dummy-deployment to development and staging (#11911)
flacatus May 20, 2026
3fd3996
SPRE-5349: add kube_deployment_status_replicas_updated metric for tek…
asafaviv-devops May 20, 2026
eabc1e9
feat(KONFLUX-13961): Update perf in-cluster dashboards on Prod (#11873)
jhutar May 20, 2026
cb2daa2
mintmaker update (#11886)
rh-tap-build-team[bot] May 20, 2026
cf2bb22
KAR-639: set up kubearchive-logging dev monitoring (#11694)
olegbet May 20, 2026
00c028f
update components/mintmaker/staging/base/kustomization.yaml (#11913)
rh-tap-build-team[bot] May 20, 2026
c34464d
Update from release-service (#11925)
rh-tap-build-team[bot] May 20, 2026
773796e
Feat: reduce kubearchive vector replicas to 1 in development (#11922)
flacatus May 20, 2026
6ab5252
KFLUXVNGD-999: increase cache TTL and add service traffic distributio…
amisstea May 20, 2026
a7ad997
Update MintMaker code owners (#11920)
staticf0x May 21, 2026
fd33c76
Update image-controller notification-resetter cronjob resources in pr…
mantomas May 21, 2026
04c0215
release-service update (#11931)
rh-tap-build-team[bot] May 21, 2026
776f5a2
update components/mintmaker/production/base/kustomization.yaml (#11921)
rh-tap-build-team[bot] May 21, 2026
3fba4af
remove kueue-external-admission from dev/stg (#11827)
filariow May 21, 2026
450d905
KONFLUX-13356: Upgrade kueue operator from stable-v1.2 to stable-v1.3…
glevi-rh May 25, 2026
5bc6189
KONFLUX-13356: migrate kueue CRs from v1beta1 to v1beta2 for prod rin…
glevi-rh May 25, 2026
76ae582
chore(STONEINTG-1594a): add prod endpoint params for image_rbac-proxy…
jencull May 25, 2026
944eeff
fix ClusterQueue in stg-rh01 (#11961)
filariow May 25, 2026
f7da7c8
KFLUXINFRA-3732: add AGENTS.md (#11843)
glevi-rh May 25, 2026
40592eb
chore: replace appstudio-utils by task-runner in konflux ui stage (#1…
JoaoPedroPP May 25, 2026
1c94039
KFLUXINFRA-3786: revoke Role write permissions from tenant admins (pr…
manish-jangra May 25, 2026
91ebbbc
remove kueue-external-admission from prod (#11828)
filariow May 25, 2026
17317b7
Fix image-controller and image-rbac-proxy Quay org for kflux-fedora-0…
manish-jangra May 26, 2026
09f6e57
KFLUXINFRA-3732: address AGENTS.md review feedback (#11986)
glevi-rh May 26, 2026
14c78ba
feat(SPRE-5169): Add konflux-ui probes (staging) (#11980)
aurelbalteaux May 26, 2026
b05a9f8
update components/mintmaker/staging/base/kustomization.yaml (#11971)
rh-tap-build-team[bot] May 26, 2026
bf7aa7b
Add event-reading RBAC to perf-team-prometheus-reader production (#11…
jhutar May 26, 2026
cdcaa5f
Allow konflux-performance group to create SA tokens in perf-team-prom…
jhutar May 26, 2026
39cb692
chore(KFLUXVNGD-994): increase artifact-registry-proxy cache volume t…
hmariset May 26, 2026
f3867bd
feat(SPRE-5381): Include label severity for blackbox monitoring in pr…
gcpsoares May 26, 2026
58512ae
Switch back to ppc in us-east (#11995)
hugares May 26, 2026
e83cbd9
Delete all group-sync resources (#11891)
enkeefe00 May 26, 2026
e9bd620
chore: bump kubearchive staging to v1.22.1 (#12008)
maruiz93 May 27, 2026
2457241
KONFLUX-13356: upgrade kueue operator and tekton-kueue for prod ring …
glevi-rh May 27, 2026
0f71d0c
Allow konflux-performance group to create SA tokens in production (#1…
jhutar May 27, 2026
1e90a22
Update from release-service (#12010)
rh-tap-build-team[bot] May 27, 2026
72bea85
Promote release-service and grafana-dashboard from development to sta…
seanconroy2021 May 27, 2026
0d0e140
chore: replace appstudio-utils by task-runner in konflux ui prod (#11…
JoaoPedroPP May 27, 2026
0b50863
Add docs for perf-team-prometheus-reader component (#12016)
jhutar May 27, 2026
a169b9c
Update pipelines to next nightly build in dev/staging 5.0.5-830 (#12009)
mathur07 May 27, 2026
ffcf908
KONFLUX-13356: ring 3 CRs migration v1beta1 → v1beta2 + base cleanup …
glevi-rh May 28, 2026
3c4f963
Update from release-service (#12041)
rh-tap-build-team[bot] May 28, 2026
b935c4f
feat(KFLUXVNGD-907): add konflux operator CR (#11900)
yftacherzog May 28, 2026
3ce44b5
mintmaker update (#11968)
rh-tap-build-team[bot] May 28, 2026
0c23446
UI proxy: replace long-lived token with rotated short-lived tokens (p…
mshaposhnik May 28, 2026
6603ad7
Upgrade kubearchive to v1.22.1 in stone-prd-rh01 (#12040)
maruiz93 May 28, 2026
dd9b60a
KFLUXVNGD-1000 Restructure squid production overlay ring 1 (#12018)
hmariset May 28, 2026
e03fd93
KFLUXVNGD-1024 Restructure squid production overlay ring 2 (#12050)
hmariset May 28, 2026
b3ca3e2
KFLUXVNGD-1024 Restructure squid production overlay - ring 3 (#12051)
hmariset May 28, 2026
e62ac9b
Update from release-service (#12028)
rh-tap-build-team[bot] May 28, 2026
07246ca
KFLUXVNGD-994 Increase nginx cache volume to 1TB for ring 1 productio…
hmariset May 28, 2026
c9b9b70
Allow hotfixes to target both staging and prod (#12056)
p8r-the-gr8 May 29, 2026
08a094e
fix(KONFLUX-14215): update otel collector to 0.153.0 on staging (#12048)
olegbet May 29, 2026
501093c
UI proxy: migrate ring 2 clusters and remove base-ring2 (production r…
mshaposhnik May 14, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
35 changes: 29 additions & 6 deletions .github/workflows/enforce-ring-deployment.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@ name: Enforce Ring Deployment

on:
pull_request_target:
types: [opened, synchronize, reopened]
types: [opened, synchronize, reopened, labeled, unlabeled]
branches: [main]
paths:
- 'components/**'
Expand All @@ -19,35 +19,46 @@ jobs:
pull-requests: write
issues: write
steps:
- name: Check for hotfix label
id: hotfix
if: contains(github.event.pull_request.labels.*.name, 'skip-ring-deployment/hotfix')
run: echo "skip=true" >> "$GITHUB_OUTPUT"

# Check out the BASE branch (trusted code) so we never execute PR code.
- uses: actions/checkout@v6
if: steps.hotfix.outputs.skip != 'true'
with:
fetch-depth: 0

- uses: actions/setup-go@v5
if: steps.hotfix.outputs.skip != 'true'
with:
go-version-file: infra-tools/go.mod
cache-dependency-path: infra-tools/go.sum

- name: Setup Kustomize
if: steps.hotfix.outputs.skip != 'true'
uses: multani/action-setup-kustomize@v1
with:
version: 5.6.0

# Build from the trusted base branch before switching to PR code.
- name: Build env-detector (from base branch)
if: steps.hotfix.outputs.skip != 'true'
working-directory: infra-tools
run: go build -o bin/env-detector ./cmd/env-detector

# Fetch the GitHub-synthesized merge commit so the tool analyses the
# post-merge state, while the binary remains the trusted base build.
- name: Checkout PR merge ref
if: steps.hotfix.outputs.skip != 'true'
run: |
git fetch origin pull/${{ github.event.pull_request.number }}/merge:pr-merge
git checkout pr-merge

- name: Check ring deployment policy
id: ring-check
if: steps.hotfix.outputs.skip != 'true'
continue-on-error: true
working-directory: infra-tools
run: |
Expand All @@ -59,25 +70,37 @@ jobs:
--dry-run

- name: Post or update PR comment
if: always() && steps.ring-check.outcome != 'skipped'
if: always() && (steps.ring-check.outcome != 'skipped' || steps.hotfix.outputs.skip == 'true')
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
COMMENT_MARKER="<!-- ring-deployment-check -->"

# Delete any previous comment from this workflow
gh api "repos/${{ github.repository }}/issues/${{ github.event.pull_request.number }}/comments" \
--paginate --jq ".[] | select(.body | contains(\"${COMMENT_MARKER}\")) | .id" \
| xargs -r -I {} gh api "repos/${{ github.repository }}/issues/comments/{}" -X DELETE

# Post a new comment only if the report file was generated
if [ -s /tmp/ring-report.md ]; then
if [ "${{ steps.hotfix.outputs.skip }}" = "true" ]; then
cat > /tmp/ring-report.md <<'BODY'
## ✅ Ring Deployment Check — Passed (Hotfix Override)

This check **passed** because the `skip-ring-deployment/hotfix` label is applied.
The normal ring deployment policy has been bypassed for this PR.

> **Note:** This override should only be used for emergency hotfixes.
> The label application is tracked in the PR timeline for audit purposes.
BODY
echo "${COMMENT_MARKER}" >> /tmp/ring-report.md
gh pr comment ${{ github.event.pull_request.number }} \
--repo ${{ github.repository }} \
--body-file /tmp/ring-report.md
elif [ -s /tmp/ring-report.md ]; then
echo "${COMMENT_MARKER}" >> /tmp/ring-report.md
gh pr comment ${{ github.event.pull_request.number }} \
--repo ${{ github.repository }} \
--body-file /tmp/ring-report.md
fi

- name: Fail on ring deployment violation
if: always() && steps.ring-check.outcome == 'failure'
if: always() && steps.hotfix.outputs.skip != 'true' && steps.ring-check.outcome == 'failure'
run: exit 1
37 changes: 37 additions & 0 deletions AGENTS.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,37 @@
# infra-deployments

GitOps monorepo deploying 50+ Kubernetes components across multiple clusters via Kustomize and ArgoCD ApplicationSets.

## Quick Commands

| Action | Command |
|----------------|--------------------------------------------|
| Build overlay | `kustomize build components/<name>/<env>/` |
| Lint YAML | `yamllint .` |
| K8s lint | `kube-linter lint <path>` |
| Chainsaw tests | `./hack/chainsaw/chainsaw-prepare.sh` and `chainsaw test <path to .chainsaw-test folder>` |
| infra-tools | `cd infra-tools && make build test lint` |

## Project Layout

- `components/<name>/{base,development,staging,production}/` — per-component Kustomize overlays; staging and production are often further split per-cluster
- `argo-cd-apps/overlays/` — maps to deployment targets (development, staging-downstream, production-downstream, etc.)
- `configs/` — cluster-level configurations (etcd-defrag, kubelet settings)
- `hack/` — deployment and utility scripts
- `infra-tools/` — Go CLI tools (env-detector, render-diff) with their own Makefile

## Key Conventions

- Prefer using scripts in `hack/` over manual steps when available
- Promotion order: development/staging → production; changes must be validated in dev/staging before promoting to production
- Production has per-cluster overlay directories; rollouts must be split into rings (subsets of clusters), not applied to all at once
- All changes via PR; CODEOWNERS approval required
- Production PRs must include `## Risk Assessment` (level, description, rollback plan) and `## Validation` (staging evidence if applicable)
- Commits - Jira ID at start (e.g., `KFLUXINFRA-1234 description`). Interactive sessions: Use the -s flag and `Assisted-by:` trailer. Agentic workflow: `Authored-by:` trailer. Include agent name and tool.

## Gotchas

- E2E tests are designed to validate in an isolated environment in GitHub Actions CI and should not be run locally
- E2E tests are conditional — they only run on dev/staging PRs when specific files change. Production PRs do not run E2E; rely on prior dev/staging validation
- E2E tests frequently fail due to intermittent infrastructure issues. If the PR looks correct and E2E logs show no relevant errors, comment `/retest` to re-trigger
- When updating component images, also update image references in `hack/new-cluster/templates/` as part of the production ring deployments — new clusters are bootstrapped from these and won't get ArgoCD-synced versions
1 change: 1 addition & 0 deletions CLAUDE.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
@AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -33,7 +33,7 @@ spec:
repoURL: https://github.com/redhat-appstudio/infra-deployments.git
targetRevision: main
destination:
namespace: group-sync-operator
namespace: authentication
server: '{{server}}'
syncPolicy:
automated:
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,43 @@
apiVersion: argoproj.io/v1alpha1
kind: ApplicationSet
metadata:
name: k8s-groups
spec:
generators:
- merge:
mergeKeys:
- nameNormalized
generators:
- clusters:
values:
sourceRoot: components/k8s-groups
environment: staging
useCaseDir: rover
- list:
elements:
- nameNormalized: kflux-fedora-01
values.useCaseDir: fas
template:
metadata:
name: k8s-groups-{{nameNormalized}}
spec:
project: default
source:
path: '{{values.sourceRoot}}/{{values.environment}}/{{values.useCaseDir}}'
repoURL: '' # will be added by kustomization
targetRevision: main
destination:
namespace: k8s-groups
server: '{{server}}'
syncPolicy:
automated:
prune: true
selfHeal: true
syncOptions:
- CreateNamespace=true
retry:
limit: -1
backoff:
duration: 10s
factor: 2
maxDuration: 3m
Original file line number Diff line number Diff line change
@@ -1,5 +1,4 @@
---
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- monitor.yaml
- k8s-groups.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- k8s-groups
components:
- ../../../k-components/inject-internal-infra-deployments-repo-details
1 change: 1 addition & 0 deletions argo-cd-apps/base/all-clusters/kustomization.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,7 @@ apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- infra-deployments
- internal-infra-deployments
components:
- ../../k-components/inject-argocd-namespace
- ../../k-components/deploy-to-all-clusters
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,8 @@ spec:
elements:
- nameNormalized: stone-prd-rh01
values.clusterDir: stone-prd-rh01
- nameNormalized: kflux-fedora-01
values.clusterDir: kflux-fedora-01
template:
metadata:
name: image-controller-{{nameNormalized}}
Expand Down
20 changes: 19 additions & 1 deletion argo-cd-apps/base/member/infra-deployments/squid/squid.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,25 @@ spec:
environment: staging
clusterDir: ""
- list:
elements: []
elements:
- nameNormalized: kflux-ocp-p01
values.clusterDir: kflux-ocp-p01
- nameNormalized: kflux-prd-rh02
values.clusterDir: kflux-prd-rh02
- nameNormalized: stone-prod-p01
values.clusterDir: stone-prod-p01
- nameNormalized: kflux-osp-p01
values.clusterDir: kflux-osp-p01
- nameNormalized: kflux-prd-rh03
values.clusterDir: kflux-prd-rh03
- nameNormalized: stone-prod-p02
values.clusterDir: stone-prod-p02
- nameNormalized: kflux-fedora-01
values.clusterDir: kflux-fedora-01
- nameNormalized: kflux-rhel-p01
values.clusterDir: kflux-rhel-p01
- nameNormalized: stone-prd-rh01
values.clusterDir: stone-prd-rh01
template:
metadata:
name: squid-{{nameNormalized}}
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
---
- op: replace
path: /spec/source/repoURL
value: https://github.com/redhat-appstudio/internal-infra-deployments.git
- op: replace
path: /spec/source/targetRevision
value: main
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
---
- op: replace
path: /spec/template/spec/source/repoURL
value: https://github.com/redhat-appstudio/internal-infra-deployments.git
- op: replace
path: /spec/template/spec/source/targetRevision
value: main
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
---
apiVersion: kustomize.config.k8s.io/v1alpha1
kind: Component
patches:
- path: application-set-patch.yaml
target:
group: argoproj.io
version: v1alpha1
kind: ApplicationSet
labelSelector: noSourceTransform != true
- path: application-patch.yaml
target:
group: argoproj.io
version: v1alpha1
kind: Application
labelSelector: noSourceTransform != true
Original file line number Diff line number Diff line change
Expand Up @@ -3,17 +3,24 @@
# policies, pipeline-service, etc.) and deletes only the legacy Konflux
# microservice ApplicationSets listed in delete-legacy-konflux-member-appsets.yaml
# so those workloads are not deployed alongside the operator-managed stack.
# pipeline-service uses components/pipeline-service/development-operator/ (no
# appstudio-pipelines-scc); the operator build-service component owns that SCC.
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ../development
- ../../base/member/infra-deployments/konflux-operator
patchesStrategicMerge:
- delete-legacy-konflux-member-appsets.yaml
namespace: openshift-gitops
patches:
- path: development-operator-generator-patch.yaml
target:
kind: ApplicationSet
version: v1alpha1
name: konflux-operator
namespace: openshift-gitops
- path: pipeline-service-operator-patch.yaml
target:
kind: ApplicationSet
version: v1alpha1
name: pipeline-service
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
---
- op: replace
path: /spec/generators/0/merge/generators/0/clusters/values/environment
value: development-operator
6 changes: 6 additions & 0 deletions argo-cd-apps/overlays/development/delete-applications.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -102,3 +102,9 @@ kind: ApplicationSet
metadata:
name: monitoring-workload-grafana
$patch: delete
---
apiVersion: argoproj.io/v1alpha1
kind: ApplicationSet
metadata:
name: k8s-groups
$patch: delete
Original file line number Diff line number Diff line change
Expand Up @@ -241,7 +241,7 @@ patches:
kind: ApplicationSet
version: v1alpha1
name: pulp-access-controller
- path: production-overlay-patch.yaml
- path: squid-production-overlay-patch.yaml
target:
kind: ApplicationSet
version: v1alpha1
Expand Down Expand Up @@ -281,3 +281,8 @@ patches:
kind: ApplicationSet
version: v1alpha1
name: perf-team-prometheus-reader
- path: production-overlay-patch.yaml
target:
kind: ApplicationSet
version: v1alpha1
name: k8s-groups
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
---
- op: add
path: /spec/generators/0/merge/generators/0/clusters/values/environment
value: production
- op: add
path: /spec/generators/0/merge/generators/0/clusters/values/clusterDir
value: empty-base
Original file line number Diff line number Diff line change
Expand Up @@ -255,7 +255,7 @@ patches:
kind: ApplicationSet
version: v1alpha1
name: pulp-access-controller
- path: production-overlay-patch.yaml
- path: squid-production-overlay-patch.yaml
target:
kind: ApplicationSet
version: v1alpha1
Expand Down Expand Up @@ -295,3 +295,8 @@ patches:
kind: ApplicationSet
version: v1alpha1
name: perf-team-prometheus-reader
- path: production-overlay-patch.yaml
target:
kind: ApplicationSet
version: v1alpha1
name: k8s-groups
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
---
- op: add
path: /spec/generators/0/merge/generators/0/clusters/values/environment
value: production
- op: add
path: /spec/generators/0/merge/generators/0/clusters/values/clusterDir
value: empty-base
Loading
Loading