Skip to content

Conversation

@leandroberetta
Copy link
Contributor

@leandroberetta leandroberetta commented Nov 18, 2025

Description

Add trackedKinds parameter to FLP config

How to test

With this change, Deployment and Gateway can owners, in the case of gateway API:

ReplicaSet -> Deployment -> Gateway

To test this, we can use Istio that uses the gateway API for ingress traffic into the cluster.

To install Service Mesh 3:

oc apply -f - <<'EOF'
---
apiVersion: operators.coreos.com/v1alpha1
kind: Subscription
metadata:
  name: servicemeshoperator3
  namespace: openshift-operators
spec:
  channel: stable
  name: servicemeshoperator3
  source: redhat-operators
  sourceNamespace: openshift-marketplace
  installPlanApproval: Automatic

---
apiVersion: v1
kind: Namespace
metadata:
  name: istio-cni

---
apiVersion: sailoperator.io/v1
kind: IstioCNI
metadata:
  name: default
spec:
  version: v1.24.6
  namespace: istio-cni

---
apiVersion: v1
kind: Namespace
metadata:
  name: istio-system

---
apiVersion: sailoperator.io/v1
kind: Istio
metadata:
  name: default
spec:
  version: v1.24.6
  namespace: istio-system
EOF

After these commands, we will get Istio working on the cluster. Now we need to install Bookinfo, the sample application and a gateway to get traffic into the mesh.

oc new-project bookinfo
oc label namespace bookinfo istio-discovery=enabled istio-injection=enabled
oc apply -f https://raw.githubusercontent.com/openshift-service-mesh/istio/release-1.24/samples/bookinfo/platform/kube/bookinfo.yaml -n bookinfo
oc apply -f https://raw.githubusercontent.com/openshift-service-mesh/istio/release-1.24/samples/bookinfo/gateway-api/bookinfo-gateway.yaml -n bookinfo

Finally, to test the UI, we can generate traffic using the following script:

./generate-bookinfo-traffic.sh

Dependencies

netobserv/flowlogs-pipeline#1125

Checklist

If you are not familiar with our processes or don't know what to answer in the list below, let us know in a comment: the maintainers will take care of that.

  • Is this PR backed with a JIRA ticket? If so, make sure it is written as a title prefix (in general, PRs affecting the NetObserv/Network Observability product should be backed with a JIRA ticket - especially if they bring user facing changes).
  • Does this PR require product documentation?
    • If so, make sure the JIRA epic is labeled with "documentation" and provides a description relevant for doc writers, such as use cases or scenarios. Any required step to activate or configure the feature should be documented there, such as new CRD knobs.
  • Does this PR require a product release notes entry?
    • If so, fill in "Release Note Text" in the JIRA.
  • Is there anything else the QE team should know before testing? E.g: configuration changes, environment setup, etc.
    • If so, make sure it is described in the JIRA ticket.
  • QE requirements (check 1 from the list):
    • Standard QE validation, with pre-merge tests unless stated otherwise.
    • Regression tests only (e.g. refactoring with no user-facing change).
    • No QE (e.g. trivial change with high reviewer's confidence, or per agreement with the QE team).

@openshift-ci-robot
Copy link
Collaborator

openshift-ci-robot commented Nov 18, 2025

@leandroberetta: This pull request references NETOBSERV-2146 which is a valid jira issue.

Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the story to target the "4.21.0" version, but no target version was set.

In response to this:

Description

Add trackedKinds parameter to FLP config

Dependencies

netobserv/flowlogs-pipeline#1125

Checklist

If you are not familiar with our processes or don't know what to answer in the list below, let us know in a comment: the maintainers will take care of that.

  • Is this PR backed with a JIRA ticket? If so, make sure it is written as a title prefix (in general, PRs affecting the NetObserv/Network Observability product should be backed with a JIRA ticket - especially if they bring user facing changes).
  • Does this PR require product documentation?
  • If so, make sure the JIRA epic is labeled with "documentation" and provides a description relevant for doc writers, such as use cases or scenarios. Any required step to activate or configure the feature should be documented there, such as new CRD knobs.
  • Does this PR require a product release notes entry?
  • If so, fill in "Release Note Text" in the JIRA.
  • Is there anything else the QE team should know before testing? E.g: configuration changes, environment setup, etc.
  • If so, make sure it is described in the JIRA ticket.
  • QE requirements (check 1 from the list):
  • Standard QE validation, with pre-merge tests unless stated otherwise.
  • Regression tests only (e.g. refactoring with no user-facing change).
  • No QE (e.g. trivial change with high reviewer's confidence, or per agreement with the QE team).

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-ci
Copy link

openshift-ci bot commented Nov 18, 2025

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
Once this PR has been reviewed and has the lgtm label, please ask for approval from leandroberetta. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@jotak jotak added the ok-to-test To set manually when a PR is safe to test. Triggers image build on PR. label Nov 18, 2025
@github-actions
Copy link

New images:

  • quay.io/netobserv/network-observability-operator:aca011b
  • quay.io/netobserv/network-observability-operator-bundle:v0.0.0-sha-aca011b
  • quay.io/netobserv/network-observability-operator-catalog:v0.0.0-sha-aca011b

They will expire after two weeks.

To deploy this build:

# Direct deployment, from operator repo
IMAGE=quay.io/netobserv/network-observability-operator:aca011b make deploy

# Or using operator-sdk
operator-sdk run bundle quay.io/netobserv/network-observability-operator-bundle:v0.0.0-sha-aca011b

Or as a Catalog Source:

apiVersion: operators.coreos.com/v1alpha1
kind: CatalogSource
metadata:
  name: netobserv-dev
  namespace: openshift-marketplace
spec:
  sourceType: grpc
  image: quay.io/netobserv/network-observability-operator-catalog:v0.0.0-sha-aca011b
  displayName: NetObserv development catalog
  publisher: Me
  updateStrategy:
    registryPoll:
      interval: 1m

@github-actions github-actions bot removed the ok-to-test To set manually when a PR is safe to test. Triggers image build on PR. label Nov 19, 2025
@leandroberetta leandroberetta added the ok-to-test To set manually when a PR is safe to test. Triggers image build on PR. label Nov 19, 2025
@github-actions
Copy link

New images:

  • quay.io/netobserv/network-observability-operator:f10ef84
  • quay.io/netobserv/network-observability-operator-bundle:v0.0.0-sha-f10ef84
  • quay.io/netobserv/network-observability-operator-catalog:v0.0.0-sha-f10ef84

They will expire after two weeks.

To deploy this build:

# Direct deployment, from operator repo
IMAGE=quay.io/netobserv/network-observability-operator:f10ef84 make deploy

# Or using operator-sdk
operator-sdk run bundle quay.io/netobserv/network-observability-operator-bundle:v0.0.0-sha-f10ef84

Or as a Catalog Source:

apiVersion: operators.coreos.com/v1alpha1
kind: CatalogSource
metadata:
  name: netobserv-dev
  namespace: openshift-marketplace
spec:
  sourceType: grpc
  image: quay.io/netobserv/network-observability-operator-catalog:v0.0.0-sha-f10ef84
  displayName: NetObserv development catalog
  publisher: Me
  updateStrategy:
    registryPoll:
      interval: 1m

@openshift-ci
Copy link

openshift-ci bot commented Nov 19, 2025

@leandroberetta: The following test failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test name Commit Details Required Rerun command
ci/prow/e2e-operator a01d124 link false /test e2e-operator

Full PR test history. Your PR dashboard.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

@openshift-ci-robot
Copy link
Collaborator

openshift-ci-robot commented Nov 19, 2025

@leandroberetta: This pull request references NETOBSERV-2146 which is a valid jira issue.

Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the story to target the "4.21.0" version, but no target version was set.

In response to this:

Description

Add trackedKinds parameter to FLP config

How to test

With this change, Deployment and Gateway can owners, in the case of gateway API:

ReplicaSet -> Deployment -> Gateway

To test this, we can use Istio that uses the gateway API for ingress traffic into the cluster.

To install Service Mesh 3:

oc apply -f - <<'EOF'
---
apiVersion: operators.coreos.com/v1alpha1
kind: Subscription
metadata:
 name: servicemeshoperator3
 namespace: openshift-operators
spec:
 channel: stable
 name: servicemeshoperator3
 source: redhat-operators
 sourceNamespace: openshift-marketplace
 installPlanApproval: Automatic

---
apiVersion: v1
kind: Namespace
metadata:
 name: istio-cni

---
apiVersion: sailoperator.io/v1
kind: IstioCNI
metadata:
 name: default
spec:
 version: v1.24.6
 namespace: istio-cni

---
apiVersion: v1
kind: Namespace
metadata:
 name: istio-system

---
apiVersion: sailoperator.io/v1
kind: Istio
metadata:
 name: default
spec:
 version: v1.24.6
 namespace: istio-system
EOF

After these commands, we will get Istio working on the cluster. Now we need to install Bookinfo, the sample application and a gateway to get traffic into the mesh.

oc new-project bookinfo
oc label namespace bookinfo istio-discovery=enabled istio-injection=enabled
oc apply -f https://raw.githubusercontent.com/openshift-service-mesh/istio/release-1.24/samples/bookinfo/platform/kube/bookinfo.yaml -n bookinfo
oc apply -f https://raw.githubusercontent.com/openshift-service-mesh/istio/release-1.24/samples/bookinfo/gateway-api/bookinfo-gateway.yaml -n bookinfo

Finally, to test the UI, we can generate traffic using the following script:

./generate-bookinfo-traffic.sh

Dependencies

netobserv/flowlogs-pipeline#1125

Checklist

If you are not familiar with our processes or don't know what to answer in the list below, let us know in a comment: the maintainers will take care of that.

  • Is this PR backed with a JIRA ticket? If so, make sure it is written as a title prefix (in general, PRs affecting the NetObserv/Network Observability product should be backed with a JIRA ticket - especially if they bring user facing changes).
  • Does this PR require product documentation?
  • If so, make sure the JIRA epic is labeled with "documentation" and provides a description relevant for doc writers, such as use cases or scenarios. Any required step to activate or configure the feature should be documented there, such as new CRD knobs.
  • Does this PR require a product release notes entry?
  • If so, fill in "Release Note Text" in the JIRA.
  • Is there anything else the QE team should know before testing? E.g: configuration changes, environment setup, etc.
  • If so, make sure it is described in the JIRA ticket.
  • QE requirements (check 1 from the list):
  • Standard QE validation, with pre-merge tests unless stated otherwise.
  • Regression tests only (e.g. refactoring with no user-facing change).
  • No QE (e.g. trivial change with high reviewer's confidence, or per agreement with the QE team).

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-ci-robot
Copy link
Collaborator

openshift-ci-robot commented Nov 19, 2025

@leandroberetta: This pull request references NETOBSERV-2146 which is a valid jira issue.

Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the story to target the "4.21.0" version, but no target version was set.

In response to this:

Description

Add trackedKinds parameter to FLP config

How to test

With this change, Deployment and Gateway can owners, in the case of gateway API:

ReplicaSet -> Deployment -> Gateway

To test this, we can use Istio that uses the gateway API for ingress traffic into the cluster.

To install Service Mesh 3:

oc apply -f - <<'EOF'
---
apiVersion: operators.coreos.com/v1alpha1
kind: Subscription
metadata:
 name: servicemeshoperator3
 namespace: openshift-operators
spec:
 channel: stable
 name: servicemeshoperator3
 source: redhat-operators
 sourceNamespace: openshift-marketplace
 installPlanApproval: Automatic

---
apiVersion: v1
kind: Namespace
metadata:
 name: istio-cni

---
apiVersion: sailoperator.io/v1
kind: IstioCNI
metadata:
 name: default
spec:
 version: v1.24.6
 namespace: istio-cni

---
apiVersion: v1
kind: Namespace
metadata:
 name: istio-system

---
apiVersion: sailoperator.io/v1
kind: Istio
metadata:
 name: default
spec:
 version: v1.24.6
 namespace: istio-system
EOF

After these commands, we will get Istio working on the cluster. Now we need to install Bookinfo, the sample application and a gateway to get traffic into the mesh.

oc new-project bookinfo
oc label namespace bookinfo istio-discovery=enabled istio-injection=enabled
oc apply -f https://raw.githubusercontent.com/openshift-service-mesh/istio/release-1.24/samples/bookinfo/platform/kube/bookinfo.yaml -n bookinfo
oc apply -f https://raw.githubusercontent.com/openshift-service-mesh/istio/release-1.24/samples/bookinfo/gateway-api/bookinfo-gateway.yaml -n bookinfo

Finally, to test the UI, we can generate traffic using the following script:

./generate-bookinfo-traffic.sh

Dependencies

netobserv/flowlogs-pipeline#1125

Checklist

If you are not familiar with our processes or don't know what to answer in the list below, let us know in a comment: the maintainers will take care of that.

  • Is this PR backed with a JIRA ticket? If so, make sure it is written as a title prefix (in general, PRs affecting the NetObserv/Network Observability product should be backed with a JIRA ticket - especially if they bring user facing changes).
  • Does this PR require product documentation?
  • If so, make sure the JIRA epic is labeled with "documentation" and provides a description relevant for doc writers, such as use cases or scenarios. Any required step to activate or configure the feature should be documented there, such as new CRD knobs.
  • Does this PR require a product release notes entry?
  • If so, fill in "Release Note Text" in the JIRA.
  • Is there anything else the QE team should know before testing? E.g: configuration changes, environment setup, etc.
  • If so, make sure it is described in the JIRA ticket.
  • QE requirements (check 1 from the list):
  • Standard QE validation, with pre-merge tests unless stated otherwise.
  • Regression tests only (e.g. refactoring with no user-facing change).
  • No QE (e.g. trivial change with high reviewer's confidence, or per agreement with the QE team).

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-ci-robot
Copy link
Collaborator

openshift-ci-robot commented Nov 19, 2025

@leandroberetta: This pull request references NETOBSERV-2146 which is a valid jira issue.

Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the story to target the "4.21.0" version, but no target version was set.

In response to this:

Description

Add trackedKinds parameter to FLP config

How to test

With this change, Deployment and Gateway can owners, in the case of gateway API:

ReplicaSet -> Deployment -> Gateway

To test this, we can use Istio that uses the gateway API for ingress traffic into the cluster.

To install Service Mesh 3:

oc apply -f - <<'EOF'
---
apiVersion: operators.coreos.com/v1alpha1
kind: Subscription
metadata:
 name: servicemeshoperator3
 namespace: openshift-operators
spec:
 channel: stable
 name: servicemeshoperator3
 source: redhat-operators
 sourceNamespace: openshift-marketplace
 installPlanApproval: Automatic

---
apiVersion: v1
kind: Namespace
metadata:
 name: istio-cni

---
apiVersion: sailoperator.io/v1
kind: IstioCNI
metadata:
 name: default
spec:
 version: v1.24.6
 namespace: istio-cni

---
apiVersion: v1
kind: Namespace
metadata:
 name: istio-system

---
apiVersion: sailoperator.io/v1
kind: Istio
metadata:
 name: default
spec:
 version: v1.24.6
 namespace: istio-system
EOF

After these commands, we will get Istio working on the cluster. Now we need to install Bookinfo, the sample application and a gateway to get traffic into the mesh.

oc new-project bookinfo
oc label namespace bookinfo istio-discovery=enabled istio-injection=enabled
oc apply -f https://raw.githubusercontent.com/openshift-service-mesh/istio/release-1.24/samples/bookinfo/platform/kube/bookinfo.yaml -n bookinfo
oc apply -f https://raw.githubusercontent.com/openshift-service-mesh/istio/release-1.24/samples/bookinfo/gateway-api/bookinfo-gateway.yaml -n bookinfo

Finally, to test the UI, we can generate traffic using the following script:

./generate-bookinfo-traffic.sh

Dependencies

netobserv/flowlogs-pipeline#1125

Checklist

If you are not familiar with our processes or don't know what to answer in the list below, let us know in a comment: the maintainers will take care of that.

  • Is this PR backed with a JIRA ticket? If so, make sure it is written as a title prefix (in general, PRs affecting the NetObserv/Network Observability product should be backed with a JIRA ticket - especially if they bring user facing changes).
  • Does this PR require product documentation?
  • If so, make sure the JIRA epic is labeled with "documentation" and provides a description relevant for doc writers, such as use cases or scenarios. Any required step to activate or configure the feature should be documented there, such as new CRD knobs.
  • Does this PR require a product release notes entry?
  • If so, fill in "Release Note Text" in the JIRA.
  • Is there anything else the QE team should know before testing? E.g: configuration changes, environment setup, etc.
  • If so, make sure it is described in the JIRA ticket.
  • QE requirements (check 1 from the list):
  • Standard QE validation, with pre-merge tests unless stated otherwise.
  • Regression tests only (e.g. refactoring with no user-facing change).
  • No QE (e.g. trivial change with high reviewer's confidence, or per agreement with the QE team).

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

SubnetLabels: flpLabels,
KubeConfig: api.NetworkTransformKubeConfig{
SecondaryNetworks: secondaryNetworks,
TrackedKinds: []string{"ReplicaSet", "Deployment", "Gateway"},
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

So we should remove "Gateway" from there, right? (according to netobserv/flowlogs-pipeline#1125 (comment) )

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@jotak thanks for reviewing.

That is still require given the tracking logic, which wasn't require anymore was the informer (because with n+1 is ok, in this case, Deployments informer).

If we remove Gateway from that list, the ownership tracking will stop at Deployment.

The logic looks for valid parents, and Gateway is a valid one.

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ah, I see, thanks for the explanation

Copy link
Member

@jotak jotak left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm
/hold

(on hold, to remove the replace directive before merging)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

do-not-merge/hold jira/valid-reference lgtm ok-to-test To set manually when a PR is safe to test. Triggers image build on PR.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants