Repository navigation
test(tmachine): use K3s ClusterIP, wait for gateway, add failure diagnostics - #4258
Merged
Merged
Conversation
Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>
|
Auto-sync is disabled for draft pull requests in this repository. Workflows must be run manually. Contributors can view more details about this message here. |
matthewgrossman
marked this pull request as ready for review
October 9, 2026 16:34
matthewgrossman
requested review from
a team,
derekwaynecarr,
mrunalp and
sjenning
as code owners
October 9, 2026 16:34
Replace the K3s-specific boot readiness hook with one shared gateway wait in the conformance playbook. Skip conformance and collect the existing diagnostics when the gateway never connects. Discover the gateway Service port with its ClusterIP, and capture both iptables backends in K3s diagnostics. Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>
Member
Author
|
/ok to test b14566a |
|
Label |
matthewgrossman
commented
Oct 9, 2026
matthewgrossman
commented
Oct 9, 2026
matthewgrossman
commented
Oct 9, 2026
matthewgrossman
commented
Oct 9, 2026
matthewgrossman
commented
Oct 9, 2026
matthewgrossman
commented
Oct 9, 2026
Move failure diagnostics into one openshell_diagnostics role that collects the systemd gateway journal and, when K3s is installed, the K3s diagnostics. Drop install-time diagnostics so the K3s installer change stays minimal, revert unrelated skill edits, and shorten the CI.md note. Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>
Member
Author
|
/ok to test 1767ec0 |
TaylorMutch
approved these changes
Oct 9, 2026
6 tasks done
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Connect tmachine K3s conformance clients directly to the gateway's ClusterIP Service, removing the long-lived
kubectl port-forwardprocess. The CLI runs on the K3s node inside the guest, so no external exposure is needed.This PR also adds two net-new behaviors:
openshell statusto report a connected gateway. Every test boot restarts the gateway; installers that are already up pass immediately. If the gateway never connects, conformance is skipped, diagnostics are collected, and the run fails with a clear message instead of per-scenario preflight failures.openshell_diagnosticsrole collects the systemd gateway journal (moved fromcli.yaml) and, when K3s is installed, bounded K3s diagnostics: K3s journal, API readiness, nodes, gateway Pod state, Services, EndpointSlices, iptables Service rules (nft and legacy), gateway events and current/previous logs, and CLI status.Integration Testsuploads the K3s diagnostics astmachine-diagnostics-*artifacts.Related Issue
Closes #4254. Replaces the closed NodePort draft #4255.
Changes
openshell-k3s.yaml: replace the port-forward unit with ClusterIP and gRPC port discovery, registered once through the existingopenshell_clientrole. Recreating the Service requires reprovisioning the fixture.conformance/cli.yaml: add the shared gateway wait; replace inline gateway-log tasks with the shared diagnostics role behind a singleconformance_failedcondition.roles/openshell_diagnostics/: new shared diagnostics role and K3s collection script.integration-runner.yml: upload diagnostics artifacts.CI.md: short note on the K3s lane, the shared wait and diagnostics.No chart, runtime or tmachine Rust changes. Install-time diagnostics are intentionally out of scope; Helm install failures surface through normal Ansible output.
Testing
openshell-k3s.yaml,conformance/cli.yaml,conformance/policy-advisor.yaml) and shellcheck pass.10.43.206.224:8080; headlessNone:8080rejected).1767ec0passed, including all four conformance integration lanes (ubuntu-k3s, deb, rpm rootful, rpm rootless) and the feature- and driver-specific lanes. Failure diagnostics do not run on a passing run; the failure path is covered by the local stub check above.Checklist