Skip to content

Conversation

@rwsu
Copy link
Contributor

@rwsu rwsu commented Dec 19, 2025

Adds support for using pre-mirrored OCP release images instead of running
oc-mirror during the build process. This is useful when images have already
been mirrored in a separate step, avoiding redundant mirroring operations.

Changes:

  • Add --mirror-path command-line flag to build command
  • Fix custom registry support with IDMS and image reference parsing
  • Add --registry-config to oc commands for custom registry authentication

When using custom registries instead of official OpenShift release images,
oc commands need authentication credentials to pull images. This adds the
--registry-config flag to all oc commands and --authfile to skopeo.

  • Use singleton asset store to preserve EnvConfig state. By caching the asset
    store instance and reusing it throughout the command execution, we ensure
    EnvConfig is only generated once with the correct values and not overwritten.

Assisted-by: Claude Sonnet 4.5 noreply@anthropic.com

@openshift-ci openshift-ci bot added the do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. label Dec 19, 2025
@openshift-ci openshift-ci bot requested review from avishayt and oourfali December 19, 2025 23:39
@openshift-merge-robot openshift-merge-robot added the needs-rebase Indicates a PR cannot be merged because it has merge conflicts with HEAD. label Dec 25, 2025
@rwsu rwsu force-pushed the AGENT-1193-v2 branch 2 times, most recently from be9a81e to c10ba39 Compare January 14, 2026 23:03
@openshift-merge-robot openshift-merge-robot removed the needs-rebase Indicates a PR cannot be merged because it has merge conflicts with HEAD. label Jan 14, 2026
@rwsu rwsu changed the title WIP: Add mirror-path support to appliance builder AGENT-1193: Add --mirror-path flag to support pre-mirrored images Jan 14, 2026
@openshift-ci openshift-ci bot removed the do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. label Jan 14, 2026
@openshift-ci-robot openshift-ci-robot added the jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. label Jan 14, 2026
@openshift-ci-robot
Copy link

openshift-ci-robot commented Jan 14, 2026

@rwsu: This pull request references AGENT-1193 which is a valid jira issue.

Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the task to target the "4.22.0" version, but no target version was set.

Details

In response to this:

  • Add --mirror-path flag to build command
  • Support using pre-mirrored registry data instead of running oc-mirror
  • Add debug logging in genisoimage

🤖 Generated with Claude Code

Assisted-by: Claude Sonnet 4.5 noreply@anthropic.com

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-ci-robot
Copy link

openshift-ci-robot commented Jan 14, 2026

@rwsu: This pull request references AGENT-1193 which is a valid jira issue.

Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the task to target the "4.22.0" version, but no target version was set.

Details

In response to this:

Adds support for using pre-mirrored OCP release images instead of running
oc-mirror during the build process. This is useful when images have already
been mirrored in a separate step, avoiding redundant mirroring operations.

Changes:

  • Add --mirror-path command-line flag to build command
  • Fix custom registry support with IDMS and image reference parsing
  • Add --registry-config to oc commands for custom registry authentication

When using custom registries instead of official OpenShift release images,
oc commands need authentication credentials to pull images. This adds the
--registry-config flag to all oc commands and --authfile to skopeo.

  • Fix EnvConfig persistence to preserve runtime flags

Without persistence, when EnvConfig is loaded as a dependency by other
assets, it creates a new instance with empty values for these runtime
flags. This caused MirrorPath to be lost when DataISO needed EnvConfig,
breaking the --mirror-path functionality.

Assisted-by: Claude Sonnet 4.5 noreply@anthropic.com

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-ci-robot
Copy link

openshift-ci-robot commented Jan 23, 2026

@rwsu: This pull request references AGENT-1193 which is a valid jira issue.

Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the task to target the "4.22.0" version, but no target version was set.

Details

In response to this:

Adds support for using pre-mirrored OCP release images instead of running
oc-mirror during the build process. This is useful when images have already
been mirrored in a separate step, avoiding redundant mirroring operations.

Changes:

  • Add --mirror-path command-line flag to build command
  • Fix custom registry support with IDMS and image reference parsing
  • Add --registry-config to oc commands for custom registry authentication

When using custom registries instead of official OpenShift release images,
oc commands need authentication credentials to pull images. This adds the
--registry-config flag to all oc commands and --authfile to skopeo.

  • Use singleton asset store to preserve EnvConfig state. By caching the asset store instance and reusing it throughout the command execution, we ensure EnvConfig is only generated once with the correct values and not overwritten.

Assisted-by: Claude Sonnet 4.5 noreply@anthropic.com

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-ci-robot
Copy link

openshift-ci-robot commented Jan 23, 2026

@rwsu: This pull request references AGENT-1193 which is a valid jira issue.

Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the task to target the "4.22.0" version, but no target version was set.

Details

In response to this:

Adds support for using pre-mirrored OCP release images instead of running
oc-mirror during the build process. This is useful when images have already
been mirrored in a separate step, avoiding redundant mirroring operations.

Changes:

  • Add --mirror-path command-line flag to build command
  • Fix custom registry support with IDMS and image reference parsing
  • Add --registry-config to oc commands for custom registry authentication

When using custom registries instead of official OpenShift release images,
oc commands need authentication credentials to pull images. This adds the
--registry-config flag to all oc commands and --authfile to skopeo.

  • Use singleton asset store to preserve EnvConfig state. By caching the asset
    store instance and reusing it throughout the command execution, we ensure
    EnvConfig is only generated once with the correct values and not overwritten.

Assisted-by: Claude Sonnet 4.5 noreply@anthropic.com

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@rwsu
Copy link
Contributor Author

rwsu commented Feb 3, 2026

/cc @danielerez

@openshift-ci openshift-ci bot requested a review from danielerez February 3, 2026 16:29
cmd/build.go Outdated
// is reused throughout command execution. This prevents EnvConfig from
// being regenerated with default values when setupApplianceConfig() fetches
// ApplianceConfig, which would overwrite runtime flags like IsLiveISO.
assetStoreInstance asset.Store
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This change probably worth a different PR, as it's not directly related to the new support, right?
Also, in which scenario it's required? I don't recall a specific flow that flags were overridden:/

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yes, I retested and it is not needed. I will remove.

# When provided, skips image mirroring and uses the pre-mirrored registry data.
# The path should point to an oc-mirror workspace directory containing a 'data' subdirectory.
# [Optional]
# mirrorPath: /path/to/mirror/workspace
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

probably worth adding also to the user-guide

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done.

}
releaseVersion = strings.Trim(releaseVersion, "'")
logrus.Debugf("Release version: %s", releaseVersion)
logrus.Debugf("Got release version: '%s'", releaseVersion)
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

not directly to change, and not sure this convention is cleaner:)

}
releaseDigest = strings.Trim(releaseDigest, "'")
releaseImage = fmt.Sprintf("%s@%s", strings.Split(releaseImage, ":")[0], releaseDigest)
releaseImage = fmt.Sprintf("%s@%s", releaseImage, releaseDigest)
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

is this change needed?

}

// CleanupPullSecret removes the temporary pull secret file
func (a *ApplianceConfig) CleanupPullSecret() error {
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

where is it used?

coreosImagePath := envConfig.FindInCache(coreosImagePattern)

// Add bootstrap scripts to ignition
logrus.Debugf("BootstrapIgnition rendering templates with IsLiveISO=%v", envConfig.IsLiveISO)
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

we already log this in env_config. isn't it enough?

newYaml := strings.ReplaceAll(string(yamlBytes), buildRegistryURI, internalRegistryURI)

// Add IDMS entry for local registry mirror if using a custom release URL
if filepath.Base(yamlPath) == "idms-oc-mirror.yaml" {
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

isn't it generated by oc-mirror?

configPath := filepath.Join(homeDir, ".docker", "config.json")
if err = os.MkdirAll(filepath.Dir(configPath), os.ModePerm); err != nil {
return err
// Write pull secret to temp file
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

why is it needed? we already store it in .docker/config.json, where oc can use it.
I mean, why not to keep lines 564-565?

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It is not needed. Will be removed.

Add support for using pre-mirrored images from oc-mirror workspace by
specifying the mirror path in appliance-config.yaml. When mirrorPath is
configured, the appliance skips running oc-mirror and uses the pre-mirrored
registry data directly.

Also fixes issues when using custom registries (non-quay.io) where oc adm
release info may return incomplete image references missing port and
repository path. Adds IDMS entries to ensure the cluster redirects pulls
from custom registries to the appliance's internal registry.

Changes:
- Add MirrorPath field to top level of ApplianceConfig in types
- Update appliance-config.yaml template to document the new field
- Update code to read mirrorPath from ApplianceConfig.Config.MirrorPath
- Add validateMirrorPath() to ApplianceConfig with comprehensive validation
- Use pre-mirrored images when mirrorPath is provided
- Add fixImageReference() to repair incomplete image refs from oc commands
  Example: registry.example.com@sha256:... becomes
           registry.example.com:5000/repo/image@sha256:...
- Add addLocalRegistryIDMS() to generate IDMS for custom registry mirrors
- Fix release image tag parsing to preserve port in registry URLs
- Update documentation to describe mirrorPath parameter and usage

The mirror-path can be specified in appliance-config.yaml as:
  mirrorPath: /path/to/oc-mirror/workspace

Assisted-by: Claude Sonnet 4.5 <noreply@anthropic.com>
@openshift-ci
Copy link

openshift-ci bot commented Feb 10, 2026

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: rwsu

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci openshift-ci bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Feb 10, 2026
@openshift-ci
Copy link

openshift-ci bot commented Feb 10, 2026

@rwsu: all tests passed!

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. jira/valid-reference Indicates that this PR references a valid Jira ticket of any type.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants