Add TLS Scanner Component#71526
Conversation
|
Skipping CI for Draft Pull Request. |
|
/pj-rehearse pull-ci-openshift-tls-scanner-main-run-scanner-on-cluster |
|
@richardsonnick: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
|
@richardsonnick, Interacting with pj-rehearseComment: Once you are satisfied with the results of the rehearsals, comment: |
|
@richardsonnick, |
|
/pj-rehearse pull-ci-openshift-tls-scanner-main-run-scanner-on-cluster |
|
@richardsonnick: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
|
/pj-rehearse pull-ci-openshift-tls-scanner-main-run-scanner-on-cluster |
|
@richardsonnick: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
|
/pj-rehearse pull-ci-openshift-tls-scanner-main-run-scanner-on-cluster |
|
@richardsonnick: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
|
/pj-rehearse pull-ci-openshift-tls-scanner-main-run-scanner-on-cluster |
|
@richardsonnick: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
|
/pj-rehearse pull-ci-openshift-tls-scanner-main-run-scanner-on-cluster |
|
@richardsonnick: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
|
@richardsonnick, Interacting with pj-rehearseComment: Once you are satisfied with the results of the rehearsals, comment: |
|
/pj-rehearse pull-ci-openshift-tls-scanner-main-run-scanner-on-cluster |
|
@richardsonnick: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
|
/pj-rehearse pull-ci-openshift-tls-scanner-main-run-scanner-on-cluster |
|
@richardsonnick: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
|
/pj-rehearse pull-ci-openshift-tls-scanner-main-run-scanner-on-cluster |
|
@richardsonnick: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
|
/pj-rehearse pull-ci-openshift-tls-scanner-main-run-scanner-on-cluster |
|
@richardsonnick: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
|
/pj-rehearse pull-ci-openshift-tls-scanner-main-run-scanner-on-cluster |
|
@richardsonnick: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
|
/pj-rehearse pull-ci-openshift-tls-scanner-main-run-scanner-on-cluster |
|
@richardsonnick: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
|
New changes are detected. LGTM label has been removed. |
|
Looks like a |
|
/retest |
|
[REHEARSALNOTIFIER]
Interacting with pj-rehearseComment: Once you are satisfied with the results of the rehearsals, comment: |
Naming is hard, but we could do: Feature = So something like: Would something like that make sense? |
|
To summarize the discussion regarding periodic job names. We have two options.
The first option will be cheaper in that we get two signals in one job. Potential names for the first option:
Potential names for the second option:
Stashing these recommendations here for future reference when we go to add those jobs. |
|
/pj-rehearse auto-ack |
|
/lgtm |
|
/assign @jupierce |
|
/lgtm |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: deepsm007, jupierce, rhmdnd, richardsonnick The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
|
/pj-rehearse |
|
@richardsonnick: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
|
@richardsonnick: The following tests failed, say
Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
|
/pj-rehearse ack |
|
@richardsonnick: now processing your pj-rehearse request. Please allow up to 10 minutes for jobs to trigger or cancel. |
7ee0a3e
into
openshift:master
|
@richardsonnick: Updated the following 2 configmaps:
DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
* Add tls-scanner step registry for scanning TLS configurations * Add CI configuration for openshift/tls-scanner repository * Add OWNERS files for tls step registry directories * Add pqc-readiness informing job for TLS 1.3 scanning * Mark pqc-readiness job as optional * make release-controllers * Use openshift 4.22 * Rename pqc-readiness to post-quantum-crypto-readiness * Remove post-quantum crypto readiness job and related configurations from nightly 4.21 release files. * [Attempt] Add xml junit output for spyglass * Reformat workflow name to be less redundant * make jobs
* Add tls-scanner step registry for scanning TLS configurations * Add CI configuration for openshift/tls-scanner repository * Add OWNERS files for tls step registry directories * Add pqc-readiness informing job for TLS 1.3 scanning * Mark pqc-readiness job as optional * make release-controllers * Use openshift 4.22 * Rename pqc-readiness to post-quantum-crypto-readiness * Remove post-quantum crypto readiness job and related configurations from nightly 4.21 release files. * [Attempt] Add xml junit output for spyglass * Reformat workflow name to be less redundant * make jobs
* Add tls-scanner step registry for scanning TLS configurations * Add CI configuration for openshift/tls-scanner repository * Add OWNERS files for tls step registry directories * Add pqc-readiness informing job for TLS 1.3 scanning * Mark pqc-readiness job as optional * make release-controllers * Use openshift 4.22 * Rename pqc-readiness to post-quantum-crypto-readiness * Remove post-quantum crypto readiness job and related configurations from nightly 4.21 release files. * [Attempt] Add xml junit output for spyglass * Reformat workflow name to be less redundant * make jobs
* Add tls-scanner step registry for scanning TLS configurations * Add CI configuration for openshift/tls-scanner repository * Add OWNERS files for tls step registry directories * Add pqc-readiness informing job for TLS 1.3 scanning * Mark pqc-readiness job as optional * make release-controllers * Use openshift 4.22 * Rename pqc-readiness to post-quantum-crypto-readiness * Remove post-quantum crypto readiness job and related configurations from nightly 4.21 release files. * [Attempt] Add xml junit output for spyglass * Reformat workflow name to be less redundant * make jobs
Adds a CI step that runs the OpenShift tls scanner against either a default openshift or one configured to use minVersionTLS 13. Produces a csv in the prow artifacts that details minVersionTLS and ciphersuite compliance against the apiserver CRD.
Complete cluster scans take ~3 hours. This time can be reduced via the namespace filter.