Skip to content

plugin container hermetic build - #3676

Open
gazarenkov wants to merge 2 commits into
redhat-developer:mainfrom
gazarenkov:plugin-installer-prod
Open

gazarenkov wants to merge 2 commits into
redhat-developer:mainfrom
gazarenkov:plugin-installer-prod

Conversation

@gazarenkov

Copy link
Copy Markdown
Member

Description

Which issue(s) does this PR fix or relate to

https://redhat.atlassian.net/browse/RHIDP-17476

PR acceptance criteria

  • Tests
  • Documentation

How to test changes / Special notes to the reviewer

make dp-installer-hermetic-build

Container Images

Container images are built and pushed to Quay automatically when relevant files change.
Image links will be posted in a PR comment once the push completes.

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

✅ PR images built and pushed successfully!

Images are available for testing (expires in 7 days):

Image Full tag PR tag
Operator quay.io/rhdh-community/operator:2.2.0-pr-3676-6adab84 quay.io/rhdh-community/operator:2.2.0-pr-3676
Bundle quay.io/rhdh-community/operator-bundle:2.2.0-pr-3676-6adab84 quay.io/rhdh-community/operator-bundle:2.2.0-pr-3676
Catalog quay.io/rhdh-community/operator-catalog:2.2.0-pr-3676-6adab84 quay.io/rhdh-community/operator-catalog:2.2.0-pr-3676

@codecov

codecov Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 60.43%. Comparing base (fca2a35) to head (6d49efb).
⚠️ Report is 7 commits behind head on main.

Additional details and impacted files

Impacted file tree graph

@@           Coverage Diff           @@
##             main    #3676   +/-   ##
=======================================
  Coverage   60.43%   60.43%           
=======================================
  Files          52       52           
  Lines        3672     3672           
=======================================
  Hits         2219     2219           
  Misses       1257     1257           
  Partials      196      196           
Flag Coverage Δ
nightly ?
unittests 60.43% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@sonarqubecloud

sonarqubecloud Bot commented Oct 6, 2026

Copy link
Copy Markdown

@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

✅ PR images built and pushed successfully!

Images are available for testing (expires in 7 days):

Image Full tag PR tag
Operator quay.io/rhdh-community/operator:2.2.0-pr-3676-6d49efb quay.io/rhdh-community/operator:2.2.0-pr-3676
Bundle quay.io/rhdh-community/operator-bundle:2.2.0-pr-3676-6d49efb quay.io/rhdh-community/operator-bundle:2.2.0-pr-3676
Catalog quay.io/rhdh-community/operator-catalog:2.2.0-pr-3676-6d49efb quay.io/rhdh-community/operator-catalog:2.2.0-pr-3676

@gazarenkov
gazarenkov marked this pull request as ready for review October 6, 2026 12:10
@gazarenkov
gazarenkov requested a review from a team as a code owner October 6, 2026 12:10
@rhdh-qodo-merge

Copy link
Copy Markdown

PR Summary by Qodo

Prepare plugin installer for local hermetic container builds

✨ Enhancement 📝 Documentation ⚙️ Configuration changes 🕐 20-40 Minutes

Grey Divider

AI Description

• Adjust the plugin installer Dockerfile for offline builds with prefetched Go and RPM dependencies.
• Add build-context exclusions and document local hermetic testing before Konflux builds.
• Add a Make target for the build, but its new recipe references a nonexistent script.
Diagram

graph TD
  Make["Make target"] --> Helper["Hermeto helper"] --> Cache[("Dependency cache")] --> Build["Offline Podman build"] --> Image["Installer image"]
  Dockerfile["Installer Dockerfile"] --> Build
  Make --> Missing["Missing script path"]
Loading
High-Level Assessment

The following are alternative approaches to this PR:

1. Reuse the existing Hermeto Make target
  • ➕ Uses the existing helper and configured Hermeto image.
  • ➕ Avoids duplicate recipes and a nonexistent script path.
  • ➖ Requires removing the newly added recipe rather than retaining it as written.

Recommendation: Keep the Dockerfile and documentation changes, but consolidate the Make target around its existing hack/local-hermeto-build.sh recipe. The added recipe duplicates that target and calls scripts/local-hermeto-build.sh, which is not present.

Files changed (4) +77 / -10

Enhancement (1) +9 / -5
DockerfileAdapt installer build stages for hermetic execution +9/-5

Adapt installer build stages for hermetic execution

• Runs the Go builder as root in the go-toolset workdir and updates the binary copy path. Separates certificate-stage directory creation from RPM installation and adds --nogpgcheck to that installation.

plugin-installer/Dockerfile

Documentation (1) +48 / -2
README.mdDocument standard and local hermetic image builds +48/-2

Document standard and local hermetic image builds

• Adds local prerequisites, the hermetic-build command, and an explanation of dependency prefetching and Konflux. Corrects the custom-image variable in the buildx example.

plugin-installer/README.md

Other (2) +20 / -3
.dockerignoreExclude repository metadata, editor files, and build artifacts +16/-3

Exclude repository metadata, editor files, and build artifacts

• Adds Git and IDE exclusions and omits dist/ from the container build context. Existing binary and hermetic-artifact exclusions remain.

.dockerignore

MakefileAdd a second plugin installer hermetic-build recipe +4/-0

Add a second plugin installer hermetic-build recipe

• Adds a dp-installer-hermetic-build recipe that selects the plugin installer Dockerfile and image name. An earlier recipe already defines the same target using hack/local-hermeto-build.sh; the new recipe calls a nonexistent scripts/local-hermeto-build.sh.

Makefile

@rhdh-qodo-merge

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (3) 📘 Rule violations (0) 🔗 Cross-repo conflicts (0) 📜 Skill insights (0)

Grey Divider


Action required

1. The plugin hermetic build cannot start 🐞 Bug ≡ Correctness
Description
dp-installer-hermetic-build is defined a second time with a recipe that calls
scripts/local-hermeto-build.sh, which does not exist. Make uses that later recipe instead of the
existing one that calls hack/local-hermeto-build.sh, so the documented command fails before
fetching dependencies or building an image.
Code

Makefile[293]

+	CONTAINERFILE=plugin-installer/Dockerfile scripts/local-hermeto-build.sh -d . -i $(RELATED_IMAGE_plugin_installer)
Relevance

●●● Strong

Duplicate target invokes a nonexistent script, directly breaking the documented hermetic build
command.

PR-#3290

ⓘ Recommendations generated based on similar findings in past PRs

Evidence
The Makefile contains two recipes for the same target; the earlier one names the script present in
the repository, while the added, later one names a nonexistent path.

Makefile[279-281]
Makefile[291-293]
hack/local-hermeto-build.sh[1-3]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
The new target overrides an existing working hermetic-build target and invokes a script that does not exist.
## Fix Focus Areas
- Makefile[279-293]
## Recommended Fix
Remove the duplicate target at lines 291–293 and retain the existing recipe that invokes `hack/local-hermeto-build.sh`.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools

Dismiss ↗ | View ↗



Remediation recommended

2. Certificate packages lose signature checks 🐞 Bug ⛨ Security
Description
The certs-stage dnf install now passes --nogpgcheck, disabling RPM signature verification for
ca-certificates and its installed dependencies. If a package supplied to that stage is substituted
after prefetch, the build can install it without an RPM signature check and copy its PKI files into
the runtime image.
Code

plugin-installer/Dockerfile[29]

+        --releasever 9 --setopt=install_weak_deps=0 --nogpgcheck --nodocs -y && \
Relevance

●●● Strong

Disabling RPM signature verification is a clear security regression in the certificate installation
stage.

PR-#3466

ⓘ Recommendations generated based on similar findings in past PRs

Evidence
The added flag bypasses RPM signature checking; the hermetic script configures the prefetched RPM
repository for the install, and the Dockerfile copies the resulting PKI files into the final image.

plugin-installer/Dockerfile[27-30]
hack/local-hermeto-build.sh[132-146]
plugin-installer/Dockerfile[38-40]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
The certs stage disables RPM signature verification for packages whose PKI files enter the runtime image.
## Fix Focus Areas
- plugin-installer/Dockerfile[27-30]
## Recommended Fix
Remove `--nogpgcheck` and make the required trusted RPM signing keys available to the offline install.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools

Dismiss ↗ | View ↗



Informational

3. The cache cleanup command removes nothing 🐞 Bug ≡ Correctness
Description
The README instructs users to remove hermeto-cache from the repository directory, but
local-hermeto-build.sh stores its cache under /tmp/hermeto-cache. When a user follows the new
cleanup instruction, the plugin-installer cache remains in place.
Code

plugin-installer/README.md[53]

+sudo rm -rf hermeto-cache
Relevance

●●● Strong

Documentation cleanup command targets the wrong cache location and leaves the generated cache
untouched.

ⓘ Recommendations generated based on similar findings in past PRs

Evidence
The script sets its cache base to /tmp/hermeto-cache and derives the plugin-installer subdirectory
from the containerfile path, unlike the repository-relative path in the new README command.

plugin-installer/README.md[49-54]
hack/local-hermeto-build.sh[22-24]
hack/local-hermeto-build.sh[103-114]
hack/local-hermeto-build.sh[327-339]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
The documented cleanup command targets a directory the hermetic-build script does not use.
## Fix Focus Areas
- plugin-installer/README.md[52-53]
## Recommended Fix
Replace the command with one that removes `/tmp/hermeto-cache/plugin-installer`, the plugin-installer cache directory derived by the script.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools

Dismiss ↗ | View ↗


Grey Divider

Context sources
⚠️ Tickets: not configured — ticket URL found in PR but could not be fetched — check ticket provider credentials
✅ Compliance rules (platform): 14 rules
✅ Cross-repo context — repo relationships
Review mode: Auto: ⚖️ Balanced: Build configuration and hermetic supply-chain behavior require careful review.
ⓘ  1 issues published inline · 3 in summary

Grey Divider

Tip of the day
💡 Did you know, you can add REVIEW.md to your repo root and Qodo follows it on every PR

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

Comment thread Makefile

.PHONY: dp-installer-hermetic-build
dp-installer-hermetic-build: ## Build plugin installer hermetically using Hermeto (local simulation of Konflux)
CONTAINERFILE=plugin-installer/Dockerfile scripts/local-hermeto-build.sh -d . -i $(RELATED_IMAGE_plugin_installer)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Action required

1. The plugin hermetic build cannot start 🐞 Bug ≡ Correctness

dp-installer-hermetic-build is defined a second time with a recipe that calls
scripts/local-hermeto-build.sh, which does not exist. Make uses that later recipe instead of the
existing one that calls hack/local-hermeto-build.sh, so the documented command fails before
fetching dependencies or building an image.
Agent Prompt
## Issue description
The new target overrides an existing working hermetic-build target and invokes a script that does not exist.
## Fix Focus Areas
- Makefile[279-293]
## Recommended Fix
Remove the duplicate target at lines 291–293 and retain the existing recipe that invokes `hack/local-hermeto-build.sh`.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools

Dismiss ↗ | View ↗

@rhdh-qodo-merge rhdh-qodo-merge Bot added documentation Improvements or additions to documentation enhancement New feature or request labels Oct 6, 2026
@rhdh-qodo-merge

Copy link
Copy Markdown

Important

The /generate_labels command by Qodo is sunsetting on the 1st of October 2026 and will no longer be available. We recommend switching to the latest Qodo review capabilities. Learn more

@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

✅ PR images built and pushed successfully!

Images are available for testing (expires in 7 days):

Image Full tag PR tag
Operator quay.io/rhdh-community/operator:2.2.0-pr-3676-6d49efb quay.io/rhdh-community/operator:2.2.0-pr-3676
Bundle quay.io/rhdh-community/operator-bundle:2.2.0-pr-3676-6d49efb quay.io/rhdh-community/operator-bundle:2.2.0-pr-3676
Catalog quay.io/rhdh-community/operator-catalog:2.2.0-pr-3676-6d49efb quay.io/rhdh-community/operator-catalog:2.2.0-pr-3676

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant