|
| 1 | +--- |
| 2 | +apiVersion: batch/v1 |
| 3 | +kind: Job |
| 4 | +metadata: |
| 5 | + name: approve-openstack-installplan |
| 6 | + namespace: openshift-gitops |
| 7 | + annotations: |
| 8 | + argocd.argoproj.io/sync-wave: "1" |
| 9 | +spec: |
| 10 | + backoffLimit: 1 |
| 11 | + template: |
| 12 | + spec: |
| 13 | + containers: |
| 14 | + - name: installplan-approver |
| 15 | + image: registry.redhat.io/openshift4/ose-tools-rhel9:latest |
| 16 | + env: |
| 17 | + - name: OS_OPERATORS_NAMESPACE |
| 18 | + value: "openstack-operators" |
| 19 | + - name: OS_NAMESPACE |
| 20 | + value: "openstack" |
| 21 | + - name: RETRIES |
| 22 | + value: "30" |
| 23 | + - name: DELAY |
| 24 | + value: "10" |
| 25 | + - name: INSTALL_PLAN_RETRIES |
| 26 | + value: "60" |
| 27 | + - name: DEBUG |
| 28 | + value: "true" |
| 29 | + command: |
| 30 | + - /bin/bash |
| 31 | + - -c |
| 32 | + - | |
| 33 | + set -eo pipefail |
| 34 | + if [ "${DEBUG}" = "true" ]; then |
| 35 | + set -x |
| 36 | + fi |
| 37 | + # --- Configuration with defaults --- |
| 38 | + # Namespace where the OpenStack operators are installed. |
| 39 | + OS_OPERATORS_NAMESPACE=${OS_OPERATORS_NAMESPACE:-"openstack-operators"} |
| 40 | + # Namespace where the OpenStack control plane is deployed and the OpenStackVersion CR exists. |
| 41 | + OS_NAMESPACE=${OS_NAMESPACE:-"openstack"} |
| 42 | + # Default number of retries for most checks. |
| 43 | + RETRIES=${RETRIES:-60} |
| 44 | + # Number of retries specifically for waiting for the InstallPlan to complete. |
| 45 | + # This is longer because pulling operator images and starting pods can take a significant amount of time. |
| 46 | + INSTALL_PLAN_RETRIES=${INSTALL_PLAN_RETRIES:-60} |
| 47 | + # Delay in seconds between retries. |
| 48 | + DELAY=${DELAY:-10} |
| 49 | + # --- |
| 50 | +
|
| 51 | + log() { |
| 52 | + echo "$(date -u +%Y-%m-%dT%H:%M:%SZ) $@" >&2 |
| 53 | + } |
| 54 | +
|
| 55 | + find_and_approve_installplan() { |
| 56 | + log "Waiting for unapproved InstallPlan..." |
| 57 | + for i in $(seq 1 $RETRIES); do |
| 58 | + install_plan_name=$(oc get installplan -n $OS_OPERATORS_NAMESPACE -o json | jq -r '.items[] | select(.spec.approval=="Manual" and .spec.approved==false) | .metadata.name' | head -n1) || true |
| 59 | + [ -n "$install_plan_name" ] && break |
| 60 | + log "Attempt $i/$RETRIES: No InstallPlan found, retrying..." |
| 61 | + sleep $DELAY |
| 62 | + done |
| 63 | +
|
| 64 | + if [ -z "$install_plan_name" ]; then |
| 65 | + log "Error: No manual InstallPlan found to approve within the time limit." |
| 66 | + exit 1 |
| 67 | + fi |
| 68 | +
|
| 69 | + log "Found InstallPlan: $install_plan_name, approving..." |
| 70 | + oc patch installplan $install_plan_name -n $OS_OPERATORS_NAMESPACE --type merge -p '{"spec":{"approved":true}}' >&2 |
| 71 | + echo "$install_plan_name" |
| 72 | + } |
| 73 | +
|
| 74 | + wait_for_installplan_completion() { |
| 75 | + local install_plan_name=$1 |
| 76 | + for i in $(seq 1 $INSTALL_PLAN_RETRIES); do |
| 77 | + phase=$(oc get installplan $install_plan_name -n $OS_OPERATORS_NAMESPACE -o jsonpath='{.status.phase}') |
| 78 | + if [ "$phase" == "Complete" ]; then |
| 79 | + log "InstallPlan completed successfully." |
| 80 | + return 0 |
| 81 | + fi |
| 82 | + if [ $i -eq $INSTALL_PLAN_RETRIES ]; then |
| 83 | + log "Error: InstallPlan did not complete in time." |
| 84 | + exit 1 |
| 85 | + fi |
| 86 | + log "Attempt $i/$INSTALL_PLAN_RETRIES: Status is $phase, retrying..." |
| 87 | + sleep $DELAY |
| 88 | + done |
| 89 | + } |
| 90 | +
|
| 91 | + wait_for_crd() { |
| 92 | + log "Waiting for OpenStack CRD to become available..." |
| 93 | + for i in $(seq 1 $RETRIES); do |
| 94 | + if oc get crd openstacks.operator.openstack.org -o jsonpath='{.status.conditions[?(@.type=="Established")].status}' | grep -q True; then |
| 95 | + log "OpenStack CRD is Established." |
| 96 | + return 0 |
| 97 | + fi |
| 98 | + if [ $i -eq $RETRIES ]; then |
| 99 | + log "Error: OpenStack CRD did not become Established in time." |
| 100 | + exit 1 |
| 101 | + fi |
| 102 | + log "Attempt $i/$RETRIES: CRD not Established, retrying..." |
| 103 | + sleep $DELAY |
| 104 | + done |
| 105 | + } |
| 106 | +
|
| 107 | + wait_for_new_version() { |
| 108 | + log "Waiting for a new OpenStack version to become available..." |
| 109 | +
|
| 110 | + local deployed_version="" |
| 111 | + for i in $(seq 1 $RETRIES); do |
| 112 | + # There should be only one openstackversion CR |
| 113 | + deployed_version=$(oc get openstackversion -n $OS_NAMESPACE -o jsonpath='{.items[0].status.deployedVersion}' 2>/dev/null) || true |
| 114 | + if [ -n "$deployed_version" ]; then |
| 115 | + log "Current deployed version is: $deployed_version" |
| 116 | + break |
| 117 | + fi |
| 118 | + if [ $i -eq $RETRIES ]; then |
| 119 | + log "Error: Could not get current deployed version in time." |
| 120 | + exit 1 |
| 121 | + fi |
| 122 | + log "Attempt $i/$RETRIES: Waiting for OpenStackVersion resource to get deployedVersion. Retrying..." |
| 123 | + sleep $DELAY |
| 124 | + done |
| 125 | +
|
| 126 | + for i in $(seq 1 $RETRIES); do |
| 127 | + available_version=$(oc get openstackversion -n $OS_NAMESPACE -o jsonpath='{.items[0].status.availableVersion}' 2>/dev/null) || true |
| 128 | + if [ -n "$available_version" ] && [ "$available_version" != "$deployed_version" ]; then |
| 129 | + log "New available version found: $available_version" |
| 130 | + return 0 |
| 131 | + fi |
| 132 | + if [ $i -eq $RETRIES ]; then |
| 133 | + log "Error: New version did not become available in time." |
| 134 | + exit 1 |
| 135 | + fi |
| 136 | + log "Attempt $i/$RETRIES: No new version available yet. Current available is '$available_version'. Retrying..." |
| 137 | + sleep $DELAY |
| 138 | + done |
| 139 | + } |
| 140 | +
|
| 141 | + # --- Main execution --- |
| 142 | + log "Starting install_plan_approval" |
| 143 | + install_plan_name=$(find_and_approve_installplan) |
| 144 | +
|
| 145 | + log "Waiting for InstallPlan '$install_plan_name' to complete..." |
| 146 | +
|
| 147 | + wait_for_installplan_completion "$install_plan_name" |
| 148 | +
|
| 149 | + log "Checking if this is an initial installation or an update..." |
| 150 | + if oc get openstack openstack -n $OS_OPERATORS_NAMESPACE; then |
| 151 | + log "OpenStack CR 'openstack' exists. This is an update." |
| 152 | + wait_for_new_version |
| 153 | + else |
| 154 | + log "OpenStack CR 'openstack' does not exist. This is an initial installation." |
| 155 | + wait_for_crd |
| 156 | + fi |
| 157 | +
|
| 158 | + log "Job completed successfully." |
| 159 | + restartPolicy: Never |
| 160 | + serviceAccountName: openshift-gitops-argocd-application-controller |
0 commit comments