Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
21 changes: 19 additions & 2 deletions .github/workflows/create-demo-clusters.yml
Original file line number Diff line number Diff line change
Expand Up @@ -31,6 +31,14 @@ on:
kube-burner-config-repo:
description: The repository where the kube-burner config files can be found
type: string
berserker-config-repo:
description: The repository where the berserker kube-burner config files can be found
type: string
default: JoukoVirtanen/kube-burner-ocp
berserker-config-ref:
description: Ref of where the berserker kube-burner config files can be found
type: string
default: jv-fix-runOnce
cluster-with-fake-load-name:
description: "The name of the long running cluster where the central deployment is run with a sensor that creates its own fake workload. Must comply to the regex: [a-z][a-z0-9-]{1,26}[a-z0-9]"
type: string
Expand All @@ -46,7 +54,7 @@ env:
GH_TOKEN: ${{ github.token }}
GH_NO_UPDATE_NOTIFIER: 1
TIMEOUT_WAIT_FOR_IMAGES_SECONDS: 3600
LONG_RUNNING_CLUSTER_LIFESPAN: "168h"
LONG_RUNNING_CLUSTER_LIFESPAN: "6h"
METRICS_COLLECTION_TIME: "30m"

jobs:
Expand Down Expand Up @@ -480,6 +488,12 @@ jobs:
repository: stackrox/${{ inputs.kube-burner-config-repo }}
path: .kube-burner-config
ref: ${{ needs.parse-refs.outputs.burner-ref }}
- name: Check out berserker config repository code
uses: actions/checkout@v4
with:
repository: ${{ inputs.berserker-config-repo }}
path: .berserker-config
ref: ${{ inputs.berserker-config-ref }}
# TODO(ROX-29223): Remove once old versions don't use the benchmark-operator
Comment on lines +491 to 497

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟡 Minor | ⚡ Quick win

Checkout missing persist-credentials: false.

Static analysis (zizmor) flags this checkout for credential persistence via GITHUB_TOKEN on disk (artipacked). Since artifacts/workspace can be exposed downstream, consider disabling credential persistence unless it's needed by a later step.

Suggested fix
       - name: Check out berserker config repository code
         uses: actions/checkout@v4
         with:
           repository: ${{ inputs.berserker-config-repo }}
           path: .berserker-config
           ref: ${{ inputs.berserker-config-ref }}
+          persist-credentials: false
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
- name: Check out berserker config repository code
uses: actions/checkout@v4
with:
repository: ${{ inputs.berserker-config-repo }}
path: .berserker-config
ref: ${{ inputs.berserker-config-ref }}
# TODO(ROX-29223): Remove once old versions don't use the benchmark-operator
- name: Check out berserker config repository code
uses: actions/checkout@v4
with:
repository: ${{ inputs.berserker-config-repo }}
path: .berserker-config
ref: ${{ inputs.berserker-config-ref }}
persist-credentials: false
# TODO(ROX-29223): Remove once old versions don't use the benchmark-operator
🧰 Tools
🪛 zizmor (1.26.1)

[warning] 483-489: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false

(artipacked)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/create-demo-clusters.yml around lines 483 - 489, Add
persist-credentials: false to the with block of the actions/checkout@v4 step
checking out the berserker config repository, ensuring the checkout does not
persist GITHUB_TOKEN credentials for downstream steps.

Source: Linters/SAST tools

- name: Check out cloud-bulldozer/benchmark-operator code
run: |
Expand Down Expand Up @@ -509,9 +523,12 @@ jobs:
REGISTRY_USERNAME: ${{ secrets.QUAY_RHACS_ENG_RO_USERNAME }}
REGISTRY_PASSWORD: ${{ secrets.QUAY_RHACS_ENG_RO_PASSWORD }}
ELASTICSEARCH_URL: "https://${{ secrets.K6_ELASTICSEARCH_USER }}:${{ secrets.K6_ELASTICSEARCH_PASSWORD }}@${{ secrets.K6_ELASTICSEARCH_URL }}"
BERSERKER_CONFIGMAP_TEMPLATE: "https://raw.githubusercontent.com/${{ inputs.berserker-config-repo }}/${{ inputs.berserker-config-ref }}/cmd/config/berserker-load/berserker-configmap.yml"
BERSERKER_SERVICE_TEMPLATE: "https://raw.githubusercontent.com/${{ inputs.berserker-config-repo }}/${{ inputs.berserker-config-ref }}/cmd/config/berserker-load/service.yml"
BERSERKER_CONTAINERS_FILE: "berserker-default-containers.yml"
uses: ./.actions/release/start-kube-burner
with:
kube-burner-config-dir: ./.kube-burner-config/scripts/release-tools/kube-burner-configs/berserker-load
kube-burner-config-dir: ./.berserker-config/cmd/config/berserker-load
benchmark-operator-dir: ${{ github.workspace }}/benchmark-operator

start-kube-burner-for-central:
Expand Down
89 changes: 85 additions & 4 deletions release/start-kube-burner/kube-burner.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -15,23 +15,47 @@ spec:
spec:
containers:
- name: kube-burner
image: quay.io/kube-burner/kube-burner:v1.4.3
image: quay.io/kube-burner/kube-burner:v2.6.2
command: ["/bin/sh", "-c"]
args:
- |
get_epoch_time() {
curl -G --silent http://monitoring.stackrox.svc.cluster.local:9090/api/v1/query --data-urlencode 'query=time()' | sed 's|.*\[||' | sed 's|\..*||'
}
cd /etc/kube-burner
config=config.yml
config=berserker-load.yml
metrics_profile=/etc/kube-burner-metrics/metrics.yml
prometheus_url="http://monitoring.stackrox.svc.cluster.local:9090"
(kube-burner init --config="$config" --metrics-profile="$metrics_profile" --prometheus-url="$prometheus_url" --timeout=1000h || true) &
cat > /tmp/vars.yml <<VARSEOF
GC: $GC
GC_METRICS: $GC_METRICS
DELETION_STRATEGY: $DELETION_STRATEGY
POD_READY_THRESHOLD: $POD_READY_THRESHOLD
ES_SERVER: "$ES_SERVER"
ES_INDEX: "$ES_INDEX"
LOCAL_INDEXING: $LOCAL_INDEXING
METRICS: $METRICS
ALERTS: "$ALERTS"
UUID: $UUID
JOB_ITERATIONS: $JOB_ITERATIONS
JOB_PAUSE: $JOB_PAUSE
QPS: $QPS
BURST: $BURST
CHURN_CYCLES: $CHURN_CYCLES
CHURN_DURATION: $CHURN_DURATION
CHURN_DELAY: $CHURN_DELAY
CHURN_PERCENT: $CHURN_PERCENT
CHURN_MODE: $CHURN_MODE
MAX_WAIT_TIMEOUT: $MAX_WAIT_TIMEOUT
DAEMONSET_REPLICAS: $DAEMONSET_REPLICAS
SERVICE_REPLICAS: $SERVICE_REPLICAS
VARSEOF
(kube-burner init --config="$config" --user-data=/tmp/vars.yml --skip-log-file --timeout=1000h || true) &
while true; do
start="$(get_epoch_time)"
sleep "$METRICS_COLLECTION_TIME"
end="$(get_epoch_time)"
kube-burner index --config="$config" --metrics-profile="$metrics_profile" --prometheus-url="$prometheus_url" --start "$start" --end "$end" --step "$METRICS_TIME_STEP" --uuid="$UUID"
kube-burner index --metrics-profile="$metrics_profile" --prometheus-url="$prometheus_url" --start "$start" --end "$end" --step "$METRICS_TIME_STEP" --uuid="$UUID" --es-server "$ELASTICSEARCH_URL" --es-index kube-burner-long-running-test
done
volumeMounts:
- name: config
Expand Down Expand Up @@ -60,6 +84,63 @@ spec:
secretKeyRef:
name: kube-burner-secret
key: METRICS_TIME_STEP
- name: GC
value: "true"
- name: GC_METRICS
value: "false"
- name: DELETION_STRATEGY
value: "gvr"
- name: POD_READY_THRESHOLD
value: "0"
- name: ES_SERVER
value: ""
- name: ES_INDEX
value: ""
- name: LOCAL_INDEXING
value: "false"
- name: METRICS
value: "metrics.yml"
- name: ALERTS
value: ""
- name: JOB_ITERATIONS
value: "5"
- name: JOB_PAUSE
value: "0s"
- name: QPS
value: "20"
- name: BURST
value: "20"
- name: CHURN_CYCLES
value: "0"
- name: CHURN_DURATION
value: "1000h"
- name: CHURN_DELAY
value: "10m0s"
- name: CHURN_PERCENT
value: "80"
- name: CHURN_MODE
value: "namespaces"
- name: MAX_WAIT_TIMEOUT
value: "12m0s"
- name: DAEMONSET_REPLICAS
value: "6"
- name: SERVICE_REPLICAS
value: "6"
- name: BERSERKER_CONFIGMAP_TEMPLATE
valueFrom:
secretKeyRef:
name: kube-burner-secret
key: BERSERKER_CONFIGMAP_TEMPLATE
- name: BERSERKER_SERVICE_TEMPLATE
valueFrom:
secretKeyRef:
name: kube-burner-secret
key: BERSERKER_SERVICE_TEMPLATE
- name: BERSERKER_CONTAINERS_FILE
valueFrom:
secretKeyRef:
name: kube-burner-secret
key: BERSERKER_CONTAINERS_FILE
volumes:
- name: config
configMap:
Expand Down
9 changes: 7 additions & 2 deletions release/start-kube-burner/start-kube-burner.sh
Original file line number Diff line number Diff line change
Expand Up @@ -20,8 +20,10 @@ dockerconfigjson="$(kubectl -n stackrox get secret stackrox -o yaml | grep docke
secret_template="${KUBE_BURNER_CONFIG_DIR_BASE}/secret_template.yml"
secret_file="${KUBE_BURNER_CONFIG_DIR}/secret.yml"

gh_log notice "Patching $secret_template"
sed "s|__DOCKERCONFIGJSON__|$dockerconfigjson|" "$secret_template" > "$secret_file"
if [ -f "$secret_template" ]; then
gh_log notice "Patching $secret_template"
sed "s|__DOCKERCONFIGJSON__|$dockerconfigjson|" "$secret_template" > "$secret_file"
fi

kubectl create ns kube-burner

Expand All @@ -43,6 +45,9 @@ kubectl create secret generic kube-burner-secret \
--from-literal=UUID="$uuid" \
--from-literal=METRICS_COLLECTION_TIME="$METRICS_COLLECTION_TIME" \
--from-literal=METRICS_TIME_STEP="5m" \
--from-literal=BERSERKER_CONFIGMAP_TEMPLATE="${BERSERKER_CONFIGMAP_TEMPLATE}" \
--from-literal=BERSERKER_SERVICE_TEMPLATE="${BERSERKER_SERVICE_TEMPLATE}" \
--from-literal=BERSERKER_CONTAINERS_FILE="${BERSERKER_CONTAINERS_FILE}" \
--namespace=kube-burner

kubectl create -f "${DIR}"/kube-burner.yaml
Loading