Mitigate intermittent curl failures to external page - #48
Conversation
Mitigate intermittent curl failures to external page Attempt to pull latest kustomize, if it fails then continue if previous download exists in /usr/bin/. If both checks fail then automation will fail. If newer download exists then move to /usr/bin .
📝 WalkthroughWalkthroughThe bootstrap role now reports Kustomize installation failures, moves the binary only when executable, and keeps the observability task conditional on the telemetry setting. ChangesBootstrap task hardening
Estimated code review effort: 2 (Simple) | ~10 minutes Suggested reviewers: 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@ansible/roles/bootstrap/tasks/main.yml`:
- Around line 21-25: Update the kustomize installation shell command in the
bootstrap task to make curl fail on HTTP errors and explicitly return exit
status 1 when neither a newly downloaded executable nor /usr/bin/kustomize
exists. Ensure the task cannot report success without a usable kustomize binary,
while preserving the existing move step.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Enterprise
Run ID: e1f628a2-d025-4fe0-bde1-1d6635861848
📒 Files selected for processing (1)
ansible/roles/bootstrap/tasks/main.yml
| curl -s "https://raw.githubusercontent.com/kubernetes-sigs/kustomize/master/hack/install_kustomize.sh" | bash 2> /dev/null || if [ ! -x /usr/bin/kustomize ] ; then exit "install_kustomize.sh download failed" ; fi | ||
|
|
||
| - name: move the kustomize to usr-bin | ||
| shell: | ||
| mv kustomize /usr/bin/. | ||
| if [ -x kustomize ] ; then mv kustomize /usr/bin/. ; fi |
There was a problem hiding this comment.
🩺 Stability & Availability | 🟠 Major | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
#!/bin/sh
set -eu
command -v bash >/dev/null
command -v curl >/dev/null
if bash -o pipefail -c 'false | true'; then
echo "pipefail is not being honored" >&2
exit 1
fiRepository: redhat-performance/JetBrew
Length of output: 164
🏁 Script executed:
#!/bin/bash
set -euo pipefail
# Locate the bootstrap task file and inspect the relevant section with line numbers.
file="ansible/roles/bootstrap/tasks/main.yml"
wc -l "$file"
sed -n '1,120p' "$file" | cat -n
# Inspect any later kustomize usage that depends on this install.
rg -n "kustomize|install_kustomize" ansible/roles -SRepository: redhat-performance/JetBrew
Length of output: 4819
🏁 Script executed:
#!/bin/bash
set -euo pipefail
echo "bash on empty stdin:"
bash -c '' </dev/null
printf 'status=%s\n' "$?"
echo "pipeline with failing curl substitute and bash reading EOF:"
false | bash
printf 'status=%s\n' "$?"
echo "non-numeric exit argument:"
bash -c 'exit "install_kustomize.sh download failed"'
printf 'status=%s\n' "$?"Repository: redhat-performance/JetBrew
Length of output: 254
🏁 Script executed:
#!/bin/bash
set -u
printf '1) bash alone on EOF\n'
bash </dev/null
printf 'status=%s\n' "$?"
printf '\n2) false | bash (capture pipeline status)\n'
false | bash </dev/null
printf 'status=%s\n' "$?"
printf '\n3) simulate curl failure with stderr suppressed and no script body\n'
python3 - <<'PY' | bash 2>/dev/null
import sys
sys.exit(22)
PY
printf 'status=%s\n' "$?"
printf '\n4) non-numeric exit in bash\n'
bash -c 'exit "install_kustomize.sh download failed"'
printf 'status=%s\n' "$?"Repository: redhat-performance/JetBrew
Length of output: 445
Don’t let the kustomize install task succeed without a usable binary.
curl -s … | bash can still exit 0 when the download fails, and the fallback if [ ! -x /usr/bin/kustomize ] doesn’t make the task fail if neither binary exists. Make the pipeline fail on HTTP errors and explicitly exit 1 when no executable kustomize is available.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@ansible/roles/bootstrap/tasks/main.yml` around lines 21 - 25, Update the
kustomize installation shell command in the bootstrap task to make curl fail on
HTTP errors and explicitly return exit status 1 when neither a newly downloaded
executable nor /usr/bin/kustomize exists. Ensure the task cannot report success
without a usable kustomize binary, while preserving the existing move step.
Source: Path instructions
Mitigate intermittent curl failures to external page
Attempt to pull latest kustomize, if it fails then continue if previous download exists in /usr/bin/. If both checks fail then automation will fail.
If newer download exists then move to /usr/bin .