Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 3 additions & 3 deletions ansible/roles/bootstrap/tasks/main.yml
Original file line number Diff line number Diff line change
Expand Up @@ -18,11 +18,11 @@

- name: download kustomize lib
shell:
curl -s "https://raw.githubusercontent.com/kubernetes-sigs/kustomize/master/hack/install_kustomize.sh" | bash
curl -s "https://raw.githubusercontent.com/kubernetes-sigs/kustomize/master/hack/install_kustomize.sh" | bash 2> /dev/null || if [ ! -x /usr/bin/kustomize ] ; then exit "install_kustomize.sh download failed" ; fi

- name: move the kustomize to usr-bin
shell:
mv kustomize /usr/bin/.
if [ -x kustomize ] ; then mv kustomize /usr/bin/. ; fi
Comment on lines +21 to +25

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🩺 Stability & Availability | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/sh
set -eu
command -v bash >/dev/null
command -v curl >/dev/null
if bash -o pipefail -c 'false | true'; then
  echo "pipefail is not being honored" >&2
  exit 1
fi

Repository: redhat-performance/JetBrew

Length of output: 164


🏁 Script executed:

#!/bin/bash
set -euo pipefail

# Locate the bootstrap task file and inspect the relevant section with line numbers.
file="ansible/roles/bootstrap/tasks/main.yml"
wc -l "$file"
sed -n '1,120p' "$file" | cat -n

# Inspect any later kustomize usage that depends on this install.
rg -n "kustomize|install_kustomize" ansible/roles -S

Repository: redhat-performance/JetBrew

Length of output: 4819


🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo "bash on empty stdin:"
bash -c '' </dev/null
printf 'status=%s\n' "$?"

echo "pipeline with failing curl substitute and bash reading EOF:"
false | bash
printf 'status=%s\n' "$?"

echo "non-numeric exit argument:"
bash -c 'exit "install_kustomize.sh download failed"'
printf 'status=%s\n' "$?"

Repository: redhat-performance/JetBrew

Length of output: 254


🏁 Script executed:

#!/bin/bash
set -u

printf '1) bash alone on EOF\n'
bash </dev/null
printf 'status=%s\n' "$?"

printf '\n2) false | bash (capture pipeline status)\n'
false | bash </dev/null
printf 'status=%s\n' "$?"

printf '\n3) simulate curl failure with stderr suppressed and no script body\n'
python3 - <<'PY' | bash 2>/dev/null
import sys
sys.exit(22)
PY
printf 'status=%s\n' "$?"

printf '\n4) non-numeric exit in bash\n'
bash -c 'exit "install_kustomize.sh download failed"'
printf 'status=%s\n' "$?"

Repository: redhat-performance/JetBrew

Length of output: 445


Don’t let the kustomize install task succeed without a usable binary.
curl -s … | bash can still exit 0 when the download fails, and the fallback if [ ! -x /usr/bin/kustomize ] doesn’t make the task fail if neither binary exists. Make the pipeline fail on HTTP errors and explicitly exit 1 when no executable kustomize is available.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@ansible/roles/bootstrap/tasks/main.yml` around lines 21 - 25, Update the
kustomize installation shell command in the bootstrap task to make curl fail on
HTTP errors and explicitly return exit status 1 when neither a newly downloaded
executable nor /usr/bin/kustomize exists. Ensure the task cannot report success
without a usable kustomize binary, while preserving the existing move step.

Source: Path instructions


- name: Download or load OCP inventory
include_tasks: includes/download_ocp_inventory.yml
Expand Down Expand Up @@ -53,4 +53,4 @@
- name: Wait for observability operator to be available
shell: |
oc wait deployments/observability-operator --for condition=Available --timeout=300s -n openshift-operators
when: telemetry | default(true)
when: telemetry | default(true)
Loading