Skip to content

Mitigate intermittent curl failures to external page - #48

Merged
masco merged 1 commit into
redhat-performance:mainfrom
links84:mitigate_curl_failures
Jul 15, 2026
Merged

masco merged 1 commit into
redhat-performance:mainfrom
links84:mitigate_curl_failures

Conversation

@links84

@links84 links84 commented Jul 15, 2026

Copy link
Copy Markdown
Contributor

Mitigate intermittent curl failures to external page

Attempt to pull latest kustomize, if it fails then continue if previous download exists in /usr/bin/. If both checks fail then automation will fail.
If newer download exists then move to /usr/bin .

Mitigate intermittent curl failures to external page

Attempt to pull latest kustomize, if it fails then continue if
previous download exists in /usr/bin/. If both checks fail then
automation will fail.
If newer download exists then move to /usr/bin .
@coderabbitai

coderabbitai Bot commented Jul 15, 2026 •

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

The bootstrap role now reports Kustomize installation failures, moves the binary only when executable, and keeps the observability task conditional on the telemetry setting.

Changes

Bootstrap task hardening

Layer / File(s) Summary
Harden bootstrap task execution
ansible/roles/bootstrap/tasks/main.yml
Kustomize installation suppresses stderr, explicitly fails on installation errors, conditionally moves the executable, and retains telemetry gating for the observability task.

Estimated code review effort: 2 (Simple) | ~10 minutes

Suggested reviewers: masco

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title matches the curl-related Kustomize download hardening, though it is a bit broader than the exact implementation.
Description check ✅ Passed The description accurately describes the fallback-to-existing-Kustomize and conditional move behavior in the change.

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@ansible/roles/bootstrap/tasks/main.yml`:
- Around line 21-25: Update the kustomize installation shell command in the
bootstrap task to make curl fail on HTTP errors and explicitly return exit
status 1 when neither a newly downloaded executable nor /usr/bin/kustomize
exists. Ensure the task cannot report success without a usable kustomize binary,
while preserving the existing move step.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Enterprise

Run ID: e1f628a2-d025-4fe0-bde1-1d6635861848

📥 Commits

Reviewing files that changed from the base of the PR and between 54c90f1 and 82c3c85.

📒 Files selected for processing (1)
  • ansible/roles/bootstrap/tasks/main.yml

Comment on lines +21 to +25
curl -s "https://raw.githubusercontent.com/kubernetes-sigs/kustomize/master/hack/install_kustomize.sh" | bash 2> /dev/null || if [ ! -x /usr/bin/kustomize ] ; then exit "install_kustomize.sh download failed" ; fi

- name: move the kustomize to usr-bin
shell:
mv kustomize /usr/bin/.
if [ -x kustomize ] ; then mv kustomize /usr/bin/. ; fi

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🩺 Stability & Availability | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/sh
set -eu
command -v bash >/dev/null
command -v curl >/dev/null
if bash -o pipefail -c 'false | true'; then
  echo "pipefail is not being honored" >&2
  exit 1
fi

Repository: redhat-performance/JetBrew

Length of output: 164


🏁 Script executed:

#!/bin/bash
set -euo pipefail

# Locate the bootstrap task file and inspect the relevant section with line numbers.
file="ansible/roles/bootstrap/tasks/main.yml"
wc -l "$file"
sed -n '1,120p' "$file" | cat -n

# Inspect any later kustomize usage that depends on this install.
rg -n "kustomize|install_kustomize" ansible/roles -S

Repository: redhat-performance/JetBrew

Length of output: 4819


🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo "bash on empty stdin:"
bash -c '' </dev/null
printf 'status=%s\n' "$?"

echo "pipeline with failing curl substitute and bash reading EOF:"
false | bash
printf 'status=%s\n' "$?"

echo "non-numeric exit argument:"
bash -c 'exit "install_kustomize.sh download failed"'
printf 'status=%s\n' "$?"

Repository: redhat-performance/JetBrew

Length of output: 254


🏁 Script executed:

#!/bin/bash
set -u

printf '1) bash alone on EOF\n'
bash </dev/null
printf 'status=%s\n' "$?"

printf '\n2) false | bash (capture pipeline status)\n'
false | bash </dev/null
printf 'status=%s\n' "$?"

printf '\n3) simulate curl failure with stderr suppressed and no script body\n'
python3 - <<'PY' | bash 2>/dev/null
import sys
sys.exit(22)
PY
printf 'status=%s\n' "$?"

printf '\n4) non-numeric exit in bash\n'
bash -c 'exit "install_kustomize.sh download failed"'
printf 'status=%s\n' "$?"

Repository: redhat-performance/JetBrew

Length of output: 445


Don’t let the kustomize install task succeed without a usable binary.
curl -s … | bash can still exit 0 when the download fails, and the fallback if [ ! -x /usr/bin/kustomize ] doesn’t make the task fail if neither binary exists. Make the pipeline fail on HTTP errors and explicitly exit 1 when no executable kustomize is available.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@ansible/roles/bootstrap/tasks/main.yml` around lines 21 - 25, Update the
kustomize installation shell command in the bootstrap task to make curl fail on
HTTP errors and explicitly return exit status 1 when neither a newly downloaded
executable nor /usr/bin/kustomize exists. Ensure the task cannot report success
without a usable kustomize binary, while preserving the existing move step.

Source: Path instructions

@links84 links84 changed the title Signed-off-by: Jaison Raju <jraju@redhat.com> Mitigate intermittent curl failures to external page Jul 15, 2026
@masco
masco merged commit 4bd83c0 into redhat-performance:main Jul 15, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants