Skip to content

Commit 0be8559

Browse files
author
Bhautik Vala
committed
[patch] Create secret for storing entitlement and artifactory token and remove it from param
1 parent 8b852ac commit 0be8559

7 files changed

Lines changed: 121 additions & 84 deletions

‎src/mas/devops/tekton.py‎

Lines changed: 121 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -843,17 +843,28 @@ def prepareAiServicePipelinesNamespace(
843843
logger.info(f"Storage class {storageClass} uses volumeBindingMode={volumeBindingMode}, skipping PVC bind wait")
844844

845845

846-
def prepareRestoreSecrets(dynClient: DynamicClient, namespace: str, restoreConfigs: dict = None):
846+
def prepareRestoreSecrets(
847+
dynClient: DynamicClient,
848+
namespace: str,
849+
restoreConfigs: dict = None,
850+
ibm_entitlement_key: str = None,
851+
artifactory_token: str = None,
852+
artifactory_username: str = None,
853+
):
847854
"""
848855
Create or update secret required for MAS Restore pipeline.
849856
850-
Creates secret in the specified namespace:
857+
Creates secrets in the specified namespace:
851858
- pipeline-restore-configs
859+
- mas-devops-credentials (only when credentials are provided)
852860
853861
Parameters:
854862
dynClient (DynamicClient): OpenShift Dynamic Client
855863
namespace (str): The namespace to create secrets in
856864
restoreConfigs (dict, optional): configuration data for restore. Defaults to None (empty secret).
865+
ibm_entitlement_key (str, optional): IBM entitlement key for registry access. Defaults to None.
866+
artifactory_token (str, optional): Artifactory token for dev catalog access. Defaults to None.
867+
artifactory_username (str, optional): Artifactory username for dev catalog access. Defaults to None.
857868
858869
Returns:
859870
None
@@ -880,6 +891,37 @@ def prepareRestoreSecrets(dynClient: DynamicClient, namespace: str, restoreConfi
880891
}
881892
secretsAPI.create(body=restoreConfigs, namespace=namespace)
882893

894+
# 2. Secret/mas-devops-credentials
895+
# -------------------------------------------------------------------------
896+
credentials_data = {}
897+
898+
if ibm_entitlement_key:
899+
credentials_data["IBM_ENTITLEMENT_KEY"] = base64.b64encode(ibm_entitlement_key.encode()).decode()
900+
901+
if artifactory_token:
902+
credentials_data["ARTIFACTORY_TOKEN"] = base64.b64encode(artifactory_token.encode()).decode()
903+
904+
if artifactory_username:
905+
credentials_data["ARTIFACTORY_USERNAME"] = base64.b64encode(artifactory_username.encode()).decode()
906+
907+
if credentials_data:
908+
try:
909+
secretsAPI.delete(name="mas-devops-credentials", namespace=namespace)
910+
except NotFoundError:
911+
pass
912+
913+
secretsAPI.create(
914+
body={
915+
"apiVersion": "v1",
916+
"kind": "Secret",
917+
"type": "Opaque",
918+
"metadata": {"name": "mas-devops-credentials"},
919+
"data": credentials_data,
920+
},
921+
namespace=namespace,
922+
)
923+
logger.info(f"Created mas-devops-credentials secret in namespace {namespace}")
924+
883925

884926
def prepareInstallSecrets(
885927
dynClient: DynamicClient,
@@ -893,13 +935,17 @@ def prepareInstallSecrets(
893935
aiserviceConfig: str = None,
894936
db2LicenseFile: dict | None = None,
895937
facilitiesProperties: dict | None = None,
938+
ibm_entitlement_key: str = None,
939+
artifactory_token: str = None,
940+
artifactory_username: str = None,
896941
) -> None:
897942
"""
898943
Create or update secrets required for MAS installation pipelines.
899944
900-
Creates secrets in the specified namespace: mas-devops-slack, pipeline-additional-configs,
901-
pipeline-sls-entitlement, pipeline-certificates, pipeline-pod-templates, pipeline-aiservice-config,
902-
pipeline-db2-license, and pipeline-facilities-properties.
945+
Creates secrets in the specified namespace: mas-devops-slack, mas-devops-credentials,
946+
pipeline-additional-configs, pipeline-sls-entitlement, pipeline-certificates,
947+
pipeline-pod-templates, pipeline-aiservice-config, pipeline-db2-license, and
948+
pipeline-facilities-properties.
903949
904950
Parameters:
905951
dynClient (DynamicClient): OpenShift Dynamic Client
@@ -913,6 +959,9 @@ def prepareInstallSecrets(
913959
slack_channel (str, optional): Slack channel ID for notifications. Defaults to None.
914960
aiserviceConfig (str, optional): AI Service tenant config data. Defaults to None (empty secret).
915961
facilitiesProperties (dict, optional): Facilities properties file content. Defaults to None (empty secret).
962+
ibm_entitlement_key (str, optional): IBM entitlement key for registry access. Defaults to None.
963+
artifactory_token (str, optional): Artifactory token for dev catalog access. Defaults to None.
964+
artifactory_username (str, optional): Artifactory username for dev catalog access. Defaults to None.
916965
917966
Returns:
918967
None
@@ -959,6 +1008,40 @@ def prepareInstallSecrets(
9591008
secretsAPI.create(body=mas_devops_secret, namespace=namespace)
9601009
logger.info(f"Created mas-devops-slack secret with MAS_INSTANCE_ID={instance_id} in namespace {namespace}")
9611010

1011+
# 1. Secret/mas-devops-credentials
1012+
# -------------------------------------------------------------------------
1013+
# New secret holding registry credentials sourced from secret instead of pipeline params.
1014+
# Only created when at least one credential is provided — all keys are optional.
1015+
if instance_id:
1016+
credentials_data = {}
1017+
1018+
if ibm_entitlement_key:
1019+
credentials_data["IBM_ENTITLEMENT_KEY"] = base64.b64encode(ibm_entitlement_key.encode()).decode()
1020+
1021+
if artifactory_token:
1022+
credentials_data["ARTIFACTORY_TOKEN"] = base64.b64encode(artifactory_token.encode()).decode()
1023+
1024+
if artifactory_username:
1025+
credentials_data["ARTIFACTORY_USERNAME"] = base64.b64encode(artifactory_username.encode()).decode()
1026+
1027+
if credentials_data:
1028+
try:
1029+
secretsAPI.delete(name="mas-devops-credentials", namespace=namespace)
1030+
except NotFoundError:
1031+
pass
1032+
1033+
secretsAPI.create(
1034+
body={
1035+
"apiVersion": "v1",
1036+
"kind": "Secret",
1037+
"type": "Opaque",
1038+
"metadata": {"name": "mas-devops-credentials"},
1039+
"data": credentials_data,
1040+
},
1041+
namespace=namespace,
1042+
)
1043+
logger.info(f"Created mas-devops-credentials secret in namespace {namespace}")
1044+
9621045
# 1. Secret/pipeline-additional-configs
9631046
# -------------------------------------------------------------------------
9641047
# Must exist, but can be empty
@@ -1074,17 +1157,22 @@ def prepareUpdateSecrets(
10741157
slack_token: str = None,
10751158
slack_channel: str = None,
10761159
db2LicenseFile: dict | None = None,
1160+
artifactory_token: str = None,
1161+
artifactory_username: str = None,
10771162
) -> None:
10781163
"""
10791164
Create or update mas-devops-slack secret in mas-pipelines namespace for update pipeline.
10801165
10811166
Creates the slack secret in mas-pipelines namespace if it exists and slack credentials are provided.
1167+
Also creates mas-devops-credentials secret if artifactory credentials are provided.
10821168
10831169
Parameters:
10841170
dynClient (DynamicClient): OpenShift Dynamic Client
10851171
slack_token (str, optional): Slack bot token for notifications. Defaults to None.
10861172
slack_channel (str, optional): Slack channel ID for notifications. Defaults to None.
10871173
db2LicenseFile (dict, optional): Db2 license file content. Defaults to None (empty secret).
1174+
artifactory_token (str, optional): Artifactory token for dev catalog access. Defaults to None.
1175+
artifactory_username (str, optional): Artifactory username for dev catalog access. Defaults to None.
10881176
10891177
Returns:
10901178
None
@@ -1152,6 +1240,34 @@ def prepareUpdateSecrets(
11521240
secretsAPI.create(body=mas_devops_secret, namespace=namespace)
11531241
logger.info(f"Created mas-devops-slack secret in namespace {namespace}")
11541242

1243+
# Create mas-devops-credentials if artifactory credentials are provided
1244+
# Note: update pipeline does not use ibm_entitlement_key (skipped via skip_entitlement_key_flag)
1245+
credentials_data = {}
1246+
1247+
if artifactory_token:
1248+
credentials_data["ARTIFACTORY_TOKEN"] = base64.b64encode(artifactory_token.encode()).decode()
1249+
1250+
if artifactory_username:
1251+
credentials_data["ARTIFACTORY_USERNAME"] = base64.b64encode(artifactory_username.encode()).decode()
1252+
1253+
if credentials_data:
1254+
try:
1255+
secretsAPI.delete(name="mas-devops-credentials", namespace=namespace)
1256+
except NotFoundError:
1257+
pass
1258+
1259+
secretsAPI.create(
1260+
body={
1261+
"apiVersion": "v1",
1262+
"kind": "Secret",
1263+
"type": "Opaque",
1264+
"metadata": {"name": "mas-devops-credentials"},
1265+
"data": credentials_data,
1266+
},
1267+
namespace=namespace,
1268+
)
1269+
logger.info(f"Created mas-devops-credentials secret in namespace {namespace}")
1270+
11551271

11561272
def testCLI() -> None:
11571273
pass

‎src/mas/devops/templates/pipelinerun-aiservice-upgrade.yml.j2‎

Lines changed: 0 additions & 15 deletions
Original file line numberDiff line numberDiff line change
@@ -22,27 +22,12 @@ spec:
2222
- name: aiservice_channel
2323
value: "{{ aiservice_channel }}"
2424

25-
# IBM Entitlement Key
26-
# -------------------------------------------------------------------------
27-
- name: ibm_entitlement_key
28-
value: "{{ ibm_entitlement_key }}"
29-
3025
{%- if skip_pre_check is defined and skip_pre_check != "" %}
3126
# Skip pre-check
3227
# -------------------------------------------------------------------------
3328
- name: skip_pre_check
3429
value: "{{ skip_pre_check }}"
3530
{%- endif %}
36-
{%- if artifactory_username is defined and artifactory_username != "" %}
37-
38-
# Enable development catalogs
39-
# -------------------------------------------------------------------------
40-
- name: artifactory_username
41-
value: "{{ artifactory_username }}"
42-
- name: artifactory_token
43-
value: "{{ artifactory_token }}"
44-
{%- endif %}
45-
4631
workspaces:
4732
# The generated configuration files
4833
# -------------------------------------------------------------------------

‎src/mas/devops/templates/pipelinerun-backup.yml.j2‎

Lines changed: 0 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -74,16 +74,6 @@ spec:
7474
value: "{{ cert_manager_provider }}"
7575
{% endif %}
7676

77-
# Development Build Support
78-
{% if artifactory_username is defined and artifactory_username != "" %}
79-
- name: artifactory_username
80-
value: "{{ artifactory_username }}"
81-
{% endif %}
82-
{% if artifactory_token is defined and artifactory_token != "" %}
83-
- name: artifactory_token
84-
value: "{{ artifactory_token }}"
85-
{% endif %}
86-
8777
# Upload Configuration
8878
{% if upload_backup is defined and upload_backup != "" %}
8979
- name: upload_backup

‎src/mas/devops/templates/pipelinerun-install.yml.j2‎

Lines changed: 0 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -19,10 +19,6 @@ spec:
1919
pipeline: "0"
2020

2121
params:
22-
# IBM Entitlement Key
23-
# -------------------------------------------------------------------------
24-
- name: ibm_entitlement_key
25-
value: "{{ ibm_entitlement_key }}"
2622
{%- if skip_pre_check is defined and skip_pre_check != "" %}
2723

2824
# Pipeline config
@@ -44,15 +40,6 @@ spec:
4440
- name: ocp_ingress_tls_secret_name
4541
value: "{{ ocp_ingress_tls_secret_name }}"
4642
{%- endif %}
47-
{%- if artifactory_username is defined and artifactory_username != "" %}
48-
49-
# Enable development catalogs
50-
# -------------------------------------------------------------------------
51-
- name: artifactory_username
52-
value: "{{ artifactory_username }}"
53-
- name: artifactory_token
54-
value: "{{ artifactory_token }}"
55-
{%- endif %}
5643
{%- if ibmcloud_apikey is defined and ibmcloud_resourcegroup != "" %}
5744

5845
# IBM Cloud

‎src/mas/devops/templates/pipelinerun-restore.yml.j2‎

Lines changed: 0 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -99,10 +99,6 @@ spec:
9999
- name: dro_contact_lastname
100100
value: "{{ dro_contact_lastname }}"
101101
{% endif %}
102-
{% if ibm_entitlement_key is defined and ibm_entitlement_key != "" %}
103-
- name: ibm_entitlement_key
104-
value: "{{ ibm_entitlement_key }}"
105-
{% endif %}
106102
{% if dro_namespace is defined and dro_namespace != "" %}
107103
- name: dro_namespace
108104
value: "{{ dro_namespace }}"
@@ -148,16 +144,6 @@ spec:
148144
value: "{{ cert_manager_provider }}"
149145
{% endif %}
150146

151-
# Development Build Support
152-
{% if artifactory_username is defined and artifactory_username != "" %}
153-
- name: artifactory_username
154-
value: "{{ artifactory_username }}"
155-
{% endif %}
156-
{% if artifactory_token is defined and artifactory_token != "" %}
157-
- name: artifactory_token
158-
value: "{{ artifactory_token }}"
159-
{% endif %}
160-
161147
# Download Configuration
162148
{% if backup_archive_name is defined and backup_archive_name != "" %}
163149
- name: backup_archive_name

‎src/mas/devops/templates/pipelinerun-update.yml.j2‎

Lines changed: 0 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -28,19 +28,6 @@ spec:
2828
- name: mas_catalog_version
2929
value: "{{ mas_catalog_version }}"
3030

31-
{%- if ibm_entitlement_key is defined and ibm_entitlement_key != "" %}
32-
# TODO: What even uses this, nothing in the update pipeline should be using this
33-
- name: ibm_entitlement_key
34-
value: "{{ ibm_entitlement_key }}"
35-
{%- endif %}
36-
{%- if artifactory_username is defined and artifactory_username != "" %}
37-
# Enable development catalogs
38-
# -------------------------------------------------------------------------
39-
- name: artifactory_username
40-
value: "{{ artifactory_username }}"
41-
- name: artifactory_token
42-
value: "{{ artifactory_token }}"
43-
{%- endif %}
4431
{%- if skip_pre_check is defined and skip_pre_check != "" %}
4532
# Skip pre-check
4633
# -------------------------------------------------------------------------

‎src/mas/devops/templates/pipelinerun-upgrade.yml.j2‎

Lines changed: 0 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -30,26 +30,12 @@ spec:
3030
- name: mas_channel
3131
value: "{{ mas_channel }}"
3232

33-
# IBM Entitlement Key
34-
# -------------------------------------------------------------------------
35-
- name: ibm_entitlement_key
36-
value: "{{ ibm_entitlement_key }}"
37-
3833
{%- if skip_pre_check is defined and skip_pre_check != "" %}
3934
# Skip pre-check
4035
# -------------------------------------------------------------------------
4136
- name: skip_pre_check
4237
value: "{{ skip_pre_check }}"
4338
{%- endif %}
44-
{%- if artifactory_username is defined and artifactory_username != "" %}
45-
46-
# Enable development catalogs
47-
# -------------------------------------------------------------------------
48-
- name: artifactory_username
49-
value: "{{ artifactory_username }}"
50-
- name: artifactory_token
51-
value: "{{ artifactory_token }}"
52-
{%- endif %}
5339
{%- if db2_action_system == "install" or db2_action_manage == "install" %}
5440

5541
# Dependencies - Db2 - Actions

0 commit comments

Comments
 (0)