From e2b1ac6e8b978f63e3f932912f19abaf9b6c8b4c Mon Sep 17 00:00:00 2001 From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com> Date: Thu, 24 Sep 2026 03:15:50 +0000 Subject: [PATCH 01/11] chore(deps): update kro to v0.9.4 --- component-settings.yaml | 2 +- test/e2e/go.mod | 46 +++++++-------- test/e2e/go.sum | 121 ++++++++++++++++++++-------------------- 3 files changed, 84 insertions(+), 85 deletions(-) diff --git a/component-settings.yaml b/component-settings.yaml index 1312d15..4004964 100644 --- a/component-settings.yaml +++ b/component-settings.yaml @@ -33,5 +33,5 @@ VICTORIA_LOGS_IMAGE_VERSION: "v1.6.0-victorialogs" OPENMCP_OPERATOR_VERSION: "v1.3.0" CLUSTER_PROVIDER_KIND_VERSION: "v0.6.0" PLATFORM_SERVICE_GATEWAY_VERSION: "v0.1.1" -KRO_VERSION: "0.9.3" +KRO_VERSION: "0.9.4" OCM_K8S_TOOLKIT_VERSION: "0.13.0" diff --git a/test/e2e/go.mod b/test/e2e/go.mod index d142741..0c0f56d 100644 --- a/test/e2e/go.mod +++ b/test/e2e/go.mod @@ -3,7 +3,7 @@ module github.com/openmcp-project/observability-stack go 1.27.1 require ( - github.com/kubernetes-sigs/kro v0.9.3 + github.com/kubernetes-sigs/kro v0.9.4 github.com/openmcp-project/controller-utils v0.33.1 github.com/openmcp-project/opencontrolplane-runtime v1.4.1 github.com/openmcp-project/openmcp-operator/api v1.4.1 @@ -58,25 +58,25 @@ require ( github.com/fluxcd/pkg/tar v1.2.0 // indirect github.com/fluxcd/source-controller/api v1.9.5 // indirect github.com/fsnotify/fsnotify v1.10.1 // indirect - github.com/fxamacker/cbor/v2 v2.9.2 // indirect + github.com/fxamacker/cbor/v2 v2.9.3 // indirect github.com/go-errors/errors v1.5.1 // indirect github.com/go-gorp/gorp/v3 v3.1.0 // indirect github.com/go-logr/logr v1.4.4 // indirect github.com/go-logr/zapr v1.3.0 // indirect github.com/go-openapi/jsonpointer v1.0.0 // indirect - github.com/go-openapi/jsonreference v1.0.0 // indirect - github.com/go-openapi/swag v0.27.3 // indirect - github.com/go-openapi/swag/cmdutils v0.27.3 // indirect - github.com/go-openapi/swag/conv v0.27.3 // indirect - github.com/go-openapi/swag/fileutils v0.27.3 // indirect - github.com/go-openapi/swag/jsonutils v0.27.3 // indirect - github.com/go-openapi/swag/loading v0.27.3 // indirect - github.com/go-openapi/swag/mangling v0.27.3 // indirect - github.com/go-openapi/swag/netutils v0.27.3 // indirect - github.com/go-openapi/swag/pools v0.27.3 // indirect - github.com/go-openapi/swag/stringutils v0.27.3 // indirect - github.com/go-openapi/swag/typeutils v0.27.3 // indirect - github.com/go-openapi/swag/yamlutils v0.27.3 // indirect + github.com/go-openapi/jsonreference v1.0.1 // indirect + github.com/go-openapi/swag v0.29.1 // indirect + github.com/go-openapi/swag/cmdutils v0.29.1 // indirect + github.com/go-openapi/swag/conv v0.29.1 // indirect + github.com/go-openapi/swag/fileutils v0.29.1 // indirect + github.com/go-openapi/swag/jsonutils v0.29.1 // indirect + github.com/go-openapi/swag/loading v0.29.1 // indirect + github.com/go-openapi/swag/mangling v0.29.1 // indirect + github.com/go-openapi/swag/netutils v0.29.1 // indirect + github.com/go-openapi/swag/pools v0.29.1 // indirect + github.com/go-openapi/swag/stringutils v0.29.1 // indirect + github.com/go-openapi/swag/typeutils v0.29.1 // indirect + github.com/go-openapi/swag/yamlutils v0.29.1 // indirect github.com/gobwas/glob v0.2.3 // indirect github.com/google/btree v1.1.3 // indirect github.com/google/gnostic-models v0.7.1 // indirect @@ -94,8 +94,8 @@ require ( github.com/lann/ps v0.0.0-20150810152359-62de8c46ede0 // indirect github.com/lib/pq v1.12.3 // indirect github.com/liggitt/tabwriter v0.0.0-20181228230101-89fcab3d43de // indirect - github.com/mattn/go-colorable v0.1.14 // indirect - github.com/mattn/go-isatty v0.0.20 // indirect + github.com/mattn/go-colorable v0.1.15 // indirect + github.com/mattn/go-isatty v0.0.24 // indirect github.com/mattn/go-runewidth v0.0.16 // indirect github.com/mitchellh/copystructure v1.2.0 // indirect github.com/mitchellh/go-wordwrap v1.0.1 // indirect @@ -113,21 +113,21 @@ require ( github.com/peterbourgon/diskv v2.0.1+incompatible // indirect github.com/pkg/errors v0.9.1 // indirect github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2 // indirect - github.com/prometheus/client_model v0.6.2 // indirect - github.com/prometheus/procfs v0.21.1 // indirect + github.com/prometheus/client_model v0.6.3 // indirect + github.com/prometheus/procfs v0.22.0 // indirect github.com/rivo/uniseg v0.2.0 // indirect github.com/rubenv/sql-migrate v1.8.1 // indirect github.com/russross/blackfriday/v2 v2.1.0 // indirect github.com/santhosh-tekuri/jsonschema/v6 v6.0.3 // indirect github.com/shopspring/decimal v1.4.0 // indirect - github.com/spf13/cast v1.7.0 // indirect + github.com/spf13/cast v1.10.0 // indirect github.com/spf13/cobra v1.10.2 // indirect github.com/spf13/pflag v1.0.10 // indirect github.com/vladimirvivien/gexe v0.5.0 // indirect github.com/x448/float16 v0.8.4 // indirect github.com/xlab/treeprint v1.2.0 // indirect - go.opentelemetry.io/otel v1.44.0 // indirect - go.opentelemetry.io/otel/trace v1.44.0 // indirect + go.opentelemetry.io/otel v1.46.0 // indirect + go.opentelemetry.io/otel/trace v1.46.0 // indirect go.uber.org/multierr v1.11.0 // indirect go.uber.org/zap v1.28.0 // indirect go.yaml.in/yaml/v2 v2.4.4 // indirect @@ -150,7 +150,7 @@ require ( k8s.io/apiserver v0.37.0 // indirect k8s.io/cli-runtime v0.37.0 // indirect k8s.io/component-base v0.37.0 // indirect - k8s.io/kube-openapi v0.0.0-20260721132016-d427ff9ee9ad // indirect + k8s.io/kube-openapi v0.0.0-20260821135717-be32def86098 // indirect k8s.io/kubectl v0.37.0 // indirect k8s.io/streaming v0.37.0 // indirect k8s.io/utils v0.0.0-20260707023825-cf1189d6abe3 // indirect diff --git a/test/e2e/go.sum b/test/e2e/go.sum index b3617a6..9b391e0 100644 --- a/test/e2e/go.sum +++ b/test/e2e/go.sum @@ -105,8 +105,8 @@ github.com/frankban/quicktest v1.14.6 h1:7Xjx+VpznH+oBnejlPUj8oUpdxnVs4f8XU8WnHk github.com/frankban/quicktest v1.14.6/go.mod h1:4ptaffx2x8+WTWXmUCuVU6aPUX1/Mz7zb5vbUoiM6w0= github.com/fsnotify/fsnotify v1.10.1 h1:b0/UzAf9yR5rhf3RPm9gf3ehBPpf0oZKIjtpKrx59Ho= github.com/fsnotify/fsnotify v1.10.1/go.mod h1:TLheqan6HD6GBK6PrDWyDPBaEV8LspOxvPSjC+bVfgo= -github.com/fxamacker/cbor/v2 v2.9.2 h1:X4Ksno9+x3cz0TZv69ec1hxP/+tymuR8PXQJyDwfh78= -github.com/fxamacker/cbor/v2 v2.9.2/go.mod h1:vM4b+DJCtHn+zz7h3FFp/hDAI9WNWCsZj23V5ytsSxQ= +github.com/fxamacker/cbor/v2 v2.9.3 h1:oQBnFATpNdY8gJHTndDDv5Xl4QqNaz51G5LLEPhng3Q= +github.com/fxamacker/cbor/v2 v2.9.3/go.mod h1:vM4b+DJCtHn+zz7h3FFp/hDAI9WNWCsZj23V5ytsSxQ= github.com/go-errors/errors v1.5.1 h1:ZwEMSLRCapFLflTpT7NKaAc7ukJ8ZPEjzlxt8rPN8bk= github.com/go-errors/errors v1.5.1/go.mod h1:sIVyrIiJhuEF+Pj9Ebtd6P/rEYROXFi3BopGUQ5a5Og= github.com/go-gorp/gorp/v3 v3.1.0 h1:ItKF/Vbuj31dmV4jxA1qblpSwkl9g1typ24xoe70IGs= @@ -121,38 +121,38 @@ github.com/go-logr/zapr v1.3.0 h1:XGdV8XW8zdwFiwOA2Dryh1gj2KRQyOOoNmBy4EplIcQ= github.com/go-logr/zapr v1.3.0/go.mod h1:YKepepNBd1u/oyhd/yQmtjVXmm9uML4IXUgMOwR8/Gg= github.com/go-openapi/jsonpointer v1.0.0 h1:kR9tHqY0CtZaOPVFm622dPVNhrvYpwr4uCxgL3h1H8s= github.com/go-openapi/jsonpointer v1.0.0/go.mod h1:Z3rw7dWu1p9IgitXCFamSlA5lmDiklEB6vkaxcNZW5Y= -github.com/go-openapi/jsonreference v1.0.0 h1:jlmTr6torcd1YgDQvSfNmRtKzYDO4FGBkrAdlAVWnpY= -github.com/go-openapi/jsonreference v1.0.0/go.mod h1:jtwdyGbJk0Xhe5Y+rwtglQP6Sb1WZST4rT32LWB+sv0= -github.com/go-openapi/swag v0.27.3 h1:i6oVKkGZeFgETHMiBHGtj9gIQ1aLtWDdJnT/SRZeets= -github.com/go-openapi/swag v0.27.3/go.mod h1:qEXs3GcyyQTDCFQ4ykqnLPDh8qT+zBcjbVWdxCAW0Us= -github.com/go-openapi/swag/cmdutils v0.27.3 h1:sjuL0TvW81i9R9GRMO/fy+c3mOW+7zxRYwy/7fobZt4= -github.com/go-openapi/swag/cmdutils v0.27.3/go.mod h1:Sm1MVFMkF6guJJ+pQqHnQA3N0j9qALV3NxzDSv6bETM= -github.com/go-openapi/swag/conv v0.27.3 h1:iqJFmGEjmX3AY0lSszABFqRVqOSt99XS0LzNIMJYuhU= -github.com/go-openapi/swag/conv v0.27.3/go.mod h1:nPRmN6jgNme99hpf+nM0auDZGALWIqlwhisKPK/bQhQ= -github.com/go-openapi/swag/fileutils v0.27.3 h1:3UVoZ2RLaIs1lt+2jcKzL8RM3Yk0rmsDE9FLA/HGxFE= -github.com/go-openapi/swag/fileutils v0.27.3/go.mod h1:VvJFZLTZS0AI854gEQz5tk7dBESdLjiNUMSZ/th2ry8= -github.com/go-openapi/swag/jsonutils v0.27.3 h1:1DEz+O82frtSMBcos/7XIn1GnpNTbsD4Bru4Dc/uhRc= -github.com/go-openapi/swag/jsonutils v0.27.3/go.mod h1:qiDCoQvzkMxrV3G8FLEdIU5L+EFYc0zcDOHWT3Yofvo= -github.com/go-openapi/swag/jsonutils/fixtures_test v0.27.3 h1:h/eT9kmGCDdFLJF29lOhzLtF0FmP1AX2MhLJWVebsb8= -github.com/go-openapi/swag/jsonutils/fixtures_test v0.27.3/go.mod h1:mofwUWx70wvskwESqRJ//k/9kURmCgyJl5m5Ppoh5kY= -github.com/go-openapi/swag/loading v0.27.3 h1:L9nQkEgzU7QgFQL+pLEMfGUKxeM4pWwGwbET9Z3weW0= -github.com/go-openapi/swag/loading v0.27.3/go.mod h1:rJ0NeaKsF4CVPnMGjPQl7JlSHzvD0bc2DKXLss1hiuE= -github.com/go-openapi/swag/mangling v0.27.3 h1:gRzzD1PAUoLTtGMgI3KpBmCSOlTuLTFWnviLxLcTnyg= -github.com/go-openapi/swag/mangling v0.27.3/go.mod h1:jtBE2+V+3pILxOR7Vgce+Cwp6A2PgZbvVqfNntbVs0w= -github.com/go-openapi/swag/netutils v0.27.3 h1:IoBvfCoprsE6E87kAIm9basnISqDDqB79mJ8MN+f5PU= -github.com/go-openapi/swag/netutils v0.27.3/go.mod h1:J+WYyFMLtvtCGqa6jLv+YNUmIKI3ZRQRrvfNDMoQoEQ= -github.com/go-openapi/swag/pools v0.27.3 h1:gXjImP3F6/56wRRcFgEPld084Y6u2gs21ikPBt8NKBk= -github.com/go-openapi/swag/pools v0.27.3/go.mod h1:kVQefhSK5RWuRe7BXsL8htgBPAMpN7HDGpGEknqugeE= -github.com/go-openapi/swag/stringutils v0.27.3 h1:Ru28hnbAvN5wycALQYy8IobHvASq+FUFMlp1QzLM0JI= -github.com/go-openapi/swag/stringutils v0.27.3/go.mod h1:lzRN95CxXmA03XcDWHLOb6nOMcxCqR5rGY0lOgsfRoM= -github.com/go-openapi/swag/typeutils v0.27.3 h1:l6SSrx5eR5/WVwrGNzN6bQ9WqL04mrxNBl9YgQ3rcJ4= -github.com/go-openapi/swag/typeutils v0.27.3/go.mod h1:Srm0xFNRZ1Y+vCxJclo5qzx8aj+1pAKda/YfFPrG0dQ= -github.com/go-openapi/swag/yamlutils v0.27.3 h1:cRFCAoYtslYn9L9T0xWryHy1t7c1MACC+DMj3CLvwvs= -github.com/go-openapi/swag/yamlutils v0.27.3/go.mod h1:6JYBGj8sw/NawMllyZY+cTA8Mzk2etS3ZBASdcyPsiU= -github.com/go-openapi/testify/enable/yaml/v2 v2.6.0 h1:gGHwAJ0R/5jU8BEGDbfRNR3hL68dAVi84WuOApp29B0= -github.com/go-openapi/testify/enable/yaml/v2 v2.6.0/go.mod h1:tY+St1SGq4NFl0QIqdTY4aEdbChAHxhyB77XQi9iJCo= -github.com/go-openapi/testify/v2 v2.6.0 h1:5PKH2HE7YJ/LuRPQGvSxBRlFXNQhSetBLlGAgUEu3ug= -github.com/go-openapi/testify/v2 v2.6.0/go.mod h1:SgsVHtfooshd0tublTtJ50FPKhujf47YRqauXXOUxfw= +github.com/go-openapi/jsonreference v1.0.1 h1:4zJ7AmYDKNmD3aSpfPnFNCFA5E80/xMHUNKgydaLh38= +github.com/go-openapi/jsonreference v1.0.1/go.mod h1:dYplQXa6p5lXprLcJ8LE2iU7vNpXsAHDQ5ZAgL+Qx3A= +github.com/go-openapi/swag v0.29.1 h1:C6EeWzUwQtcWEhE9eqBdUubGXxhWY4PlzHMLD7kLaiQ= +github.com/go-openapi/swag v0.29.1/go.mod h1:BzxEXKiPlSXRsRTv1KSBF/BpGKHxA/YciCnr4tv9bvA= +github.com/go-openapi/swag/cmdutils v0.29.1 h1:3DorPGfUdE80BogKY22EzoHBcHMrkVomZMoV7kS4ANY= +github.com/go-openapi/swag/cmdutils v0.29.1/go.mod h1:Sm1MVFMkF6guJJ+pQqHnQA3N0j9qALV3NxzDSv6bETM= +github.com/go-openapi/swag/conv v0.29.1 h1:AC4Eh/5c/eUDOUCzzsRC9ghmFgOSBHeRMGIngY0ZUGA= +github.com/go-openapi/swag/conv v0.29.1/go.mod h1:S1X7/ZrBEZOC0Wc8AGxjbcGS92l3WEjA7aPtpl+RaqM= +github.com/go-openapi/swag/fileutils v0.29.1 h1:ZcPzMceVhU1WPbK6N1G6sNQKdd1CWJlf3cA08UHuoM0= +github.com/go-openapi/swag/fileutils v0.29.1/go.mod h1:/wofKYckbtRl2p3+EwQsosie5CT1B38+dQ+PS579BzI= +github.com/go-openapi/swag/jsonutils v0.29.1 h1:AFCxs0eQZ24/QyfhVHM2t49rMz7Vv3XCsZQI6yrNy+c= +github.com/go-openapi/swag/jsonutils v0.29.1/go.mod h1:u3+sCfJpttDpcmS5kpm0yxL6GK0eWgODsx8Yw8fcqNM= +github.com/go-openapi/swag/jsonutils/fixtures_test v0.29.1 h1:BiiXE31Bx9SfpsMmOQj5KYpUhTZBpLVriVhJDuLuY2o= +github.com/go-openapi/swag/jsonutils/fixtures_test v0.29.1/go.mod h1:julgTUKZ9/D0j6O7GKajmRs+812FWxQg/mMpGunWSjg= +github.com/go-openapi/swag/loading v0.29.1 h1:FCv5fG8UhTdDJa2R7w+5O9Ekpcbw7tt0nFWvmDKGBjc= +github.com/go-openapi/swag/loading v0.29.1/go.mod h1:N0ESuem4p2oedKal8EJhciqnJ9Q9Wmt83L1CRB3Fouw= +github.com/go-openapi/swag/mangling v0.29.1 h1:lHALtvYCdxVnRl4GrHmFPwfBTZYIObqdGNSKyu/8D6I= +github.com/go-openapi/swag/mangling v0.29.1/go.mod h1:SAop9pB7PUjQ/CGCNf/JmCKTRK+GDO+RqE9UHqC/N6s= +github.com/go-openapi/swag/netutils v0.29.1 h1:IjIvdEP5duKcghFqJEPSUraRnkKYHoM65kTluTu+Jb4= +github.com/go-openapi/swag/netutils v0.29.1/go.mod h1:DUde7x4Bx00k5jYl2AdRpNAO0m7atUvD2x6X+bWkbno= +github.com/go-openapi/swag/pools v0.29.1 h1:NRogYxdEW9SjRM4mkAOji9iefO4MRXq3p/ZJcoQbUKg= +github.com/go-openapi/swag/pools v0.29.1/go.mod h1:leDcaghjkRAhCuCRv9NfJU5f0mjoU3cT/XZObhMk3pc= +github.com/go-openapi/swag/stringutils v0.29.1 h1:1ykunK7iJQk1uOO7+oUH1ukbsK85fFCOiCFMOVSY+F0= +github.com/go-openapi/swag/stringutils v0.29.1/go.mod h1:7fSqZ+z8Qc0tOfAAK0jVa5qFGrnIlRi6n7NeGGrr1vc= +github.com/go-openapi/swag/typeutils v0.29.1 h1:Nzv9nhnlLCRBPQqfOX+7lB6Guju370or8StT+lIOf6M= +github.com/go-openapi/swag/typeutils v0.29.1/go.mod h1:hxpgDZJVBkBsi/d3MIUosafoFdE5exaQRmVp0zwu3YE= +github.com/go-openapi/swag/yamlutils v0.29.1 h1:69w3tsBajm7MR/fejLy7HD/3J68Ys1SeeZMEzZ3w2sk= +github.com/go-openapi/swag/yamlutils v0.29.1/go.mod h1:rgsp3vT/QdWzKwn43CigDwjOGIenPyTZMKnxEM8jZOA= +github.com/go-openapi/testify/enable/yaml/v2 v2.6.1 h1:Jm+/ze2rMtbD98yen92AhATGLGREDYXG56Xr4gMjEtE= +github.com/go-openapi/testify/enable/yaml/v2 v2.6.1/go.mod h1:YDPnwCRDu38/oJBVMBVXOUDiJ9cIeBHWvfImHaXqnv4= +github.com/go-openapi/testify/v2 v2.6.1 h1:6CNJhTjMzgaeaH8WhshcsZNPIvRemiOcFpU7seO/y7Q= +github.com/go-openapi/testify/v2 v2.6.1/go.mod h1:SgsVHtfooshd0tublTtJ50FPKhujf47YRqauXXOUxfw= github.com/go-sql-driver/mysql v1.8.1 h1:LedoTUt/eveggdHS9qUFC1EFSa8bU2+1pZjSRpvNJ1Y= github.com/go-sql-driver/mysql v1.8.1/go.mod h1:wEBSXgmK//2ZFJyE+qWnIsVGmvmEKlqwuVSjsCm7DZg= github.com/go-task/slim-sprig/v3 v3.0.0 h1:sUs3vkvUymDpBKi3qH1YSqBQk9+9D/8M2mN1vB6EwHI= @@ -170,8 +170,8 @@ github.com/google/go-cmp v0.7.0/go.mod h1:pXiqmnSA92OHEEa9HXL2W4E7lf9JzCmGVUdgjX github.com/google/gofuzz v1.0.0/go.mod h1:dBl0BpW6vV/+mYPU4Po3pmUjxk6FQPldtuIdl/M65Eg= github.com/google/gofuzz v1.2.0 h1:xRy4A+RhZaiKjJ1bPfwQ8sedCA+YS2YcCHW6ec7JMi0= github.com/google/gofuzz v1.2.0/go.mod h1:dBl0BpW6vV/+mYPU4Po3pmUjxk6FQPldtuIdl/M65Eg= -github.com/google/pprof v0.0.0-20260604005048-7023385849c0 h1:h1QTMDl6q9wDvDCJVpKQSjgleGFYnd2fOxmg2K+6BGE= -github.com/google/pprof v0.0.0-20260604005048-7023385849c0/go.mod h1:MxpfABSjhmINe3F1It9d+8exIHFvUqtLIRCdOGNXqiI= +github.com/google/pprof v0.0.0-20260830191439-4932ad3515ea h1:nItRa0lOM9n5+PZiNPdBI2RjLCZoBrhWqKDJuB3+gSU= +github.com/google/pprof v0.0.0-20260830191439-4932ad3515ea/go.mod h1:jl5iWTm0/hd5PjEYEOuwAJ57L/CibdZfrqZ5XA5GrCk= github.com/google/shlex v0.0.0-20191202100458-e7afc7fbc510 h1:El6M4kTTCOh6aBiKaUGG7oYTSPP8MxqL4YI3kZKwcP4= github.com/google/shlex v0.0.0-20191202100458-e7afc7fbc510/go.mod h1:pupxD2MaaD3pAXIBCelhxNneeOaAeabZDe5s4K6zSpQ= github.com/google/uuid v1.6.0 h1:NIvaJDMOsjHA8n1jAhLSgzrAzy1Hgr+hNrb57e+94F0= @@ -213,8 +213,8 @@ github.com/kr/pretty v0.3.1 h1:flRD4NNwYAUpkphVc1HcthR4KEIFJ65n8Mw5qdRn3LE= github.com/kr/pretty v0.3.1/go.mod h1:hoEshYVHaxMs3cyo3Yncou5ZscifuDolrwPKZanG3xk= github.com/kr/text v0.2.0 h1:5Nx0Ya0ZqY2ygV366QzturHI13Jq95ApcVaJBhpS+AY= github.com/kr/text v0.2.0/go.mod h1:eLer722TekiGuMkidMxC/pM04lWEeraHUUmBw8l2grE= -github.com/kubernetes-sigs/kro v0.9.3 h1:jwKOvYh56xqUUEgmS8w7WwdMK4YDwMeZyCKiMjgI3FQ= -github.com/kubernetes-sigs/kro v0.9.3/go.mod h1:TOMajbRwtMzmomFqnR4h5pLYPAj7o7Z9SVNOx+xXu1E= +github.com/kubernetes-sigs/kro v0.9.4 h1:gynhldCLYW5x+M0c2Bf1ihoQTpNE68SKiXl1f6aX1kk= +github.com/kubernetes-sigs/kro v0.9.4/go.mod h1:41SwnJsWRNxbDM/iHwsdamnyPV/p7/nReiI1OckeVrk= github.com/kylelemons/godebug v1.1.0 h1:RPNrshWIDI6G2gRW9EHilWtl7Z6Sb1BR0xunSBf0SNc= github.com/kylelemons/godebug v1.1.0/go.mod h1:9/0rRGxNHcop5bhtWyNeEfOS8JIWk580+fNqagV/RAw= github.com/lann/builder v0.0.0-20180802200727-47ae307949d0 h1:SOEGU9fKiNWd/HOJuq6+3iTQz8KNCLtVX6idSoTLdUw= @@ -226,10 +226,10 @@ github.com/lib/pq v1.12.3 h1:tTWxr2YLKwIvK90ZXEw8GP7UFHtcbTtty8zsI+YjrfQ= github.com/lib/pq v1.12.3/go.mod h1:/p+8NSbOcwzAEI7wiMXFlgydTwcgTr3OSKMsD2BitpA= github.com/liggitt/tabwriter v0.0.0-20181228230101-89fcab3d43de h1:9TO3cAIGXtEhnIaL+V+BEER86oLrvS+kWobKpbJuye0= github.com/liggitt/tabwriter v0.0.0-20181228230101-89fcab3d43de/go.mod h1:zAbeS9B/r2mtpb6U+EI2rYA5OAXxsYw6wTamcNW+zcE= -github.com/mattn/go-colorable v0.1.14 h1:9A9LHSqF/7dyVVX6g0U9cwm9pG3kP9gSzcuIPHPsaIE= -github.com/mattn/go-colorable v0.1.14/go.mod h1:6LmQG8QLFO4G5z1gPvYEzlUgJ2wF+stgPZH1UqBm1s8= -github.com/mattn/go-isatty v0.0.20 h1:xfD0iDuEKnDkl03q4limB+vH+GxLEtL/jb4xVJSWWEY= -github.com/mattn/go-isatty v0.0.20/go.mod h1:W+V8PltTTMOvKvAeJH7IuucS94S2C6jfK/D7dTCTo3Y= +github.com/mattn/go-colorable v0.1.15 h1:+u9SLTRGnXv73cEsnsmoZBom+dMU88B2M0aDcWy0/jY= +github.com/mattn/go-colorable v0.1.15/go.mod h1:6LmQG8QLFO4G5z1gPvYEzlUgJ2wF+stgPZH1UqBm1s8= +github.com/mattn/go-isatty v0.0.24 h1:tGZZoVgT/KiqK1c8ocVLeDS8BSWMRd47J3Lbz7vsReI= +github.com/mattn/go-isatty v0.0.24/go.mod h1:nMCL3Zebbrt45jsMDgnfIwz6ydEQApk5oEI3HqDio6A= github.com/mattn/go-runewidth v0.0.16 h1:E5ScNMtiwvlvB5paMFdw9p4kSQzbXFikJ5SQO6TULQc= github.com/mattn/go-runewidth v0.0.16/go.mod h1:Jdepj2loyihRzMpdS35Xk/zdY8IAYHsh153qUoGf23w= github.com/mattn/go-sqlite3 v1.14.22 h1:2gZY6PC6kBnID23Tichd1K+Z0oS6nE/XwU+Vz/5o4kU= @@ -289,14 +289,14 @@ github.com/poy/onpar v1.1.2 h1:QaNrNiZx0+Nar5dLgTVp5mXkyoVFIbepjyEoGSnhbAY= github.com/poy/onpar v1.1.2/go.mod h1:6X8FLNoxyr9kkmnlqpK6LSoiOtrO6MICtWwEuWkLjzg= github.com/prometheus/client_golang v1.24.1 h1:JnJkREXzWxUdCuPFpIWZiPispT9xVV59uiuyR2bPlnU= github.com/prometheus/client_golang v1.24.1/go.mod h1:F+oSRECHg4sse5ucfYpYDeIv/hu68Zo0uoHKetWnzcE= -github.com/prometheus/client_model v0.6.2 h1:oBsgwpGs7iVziMvrGhE53c/GrLUsZdHnqNwqPLxwZyk= -github.com/prometheus/client_model v0.6.2/go.mod h1:y3m2F6Gdpfy6Ut/GBsUqTWZqCUvMVzSfMLjcu6wAwpE= +github.com/prometheus/client_model v0.6.3 h1:O0jaTVAYNxTHYInEPFJt5I3+sN8zqBtVMPTB1qyxiEo= +github.com/prometheus/client_model v0.6.3/go.mod h1:gpN5P9S7Rr6Yr92PiQ+Ixvhf6JZEkF1dnxsYL2aPBEM= github.com/prometheus/common v0.71.0 h1:9KDAKb7Mj3HEVKyFCK6Dc/HIwlBzZIN2l7/lrHl3KK8= github.com/prometheus/common v0.71.0/go.mod h1:CLJ5H8TEsGX8bl31BdMkfhIZ+QmZ9tBPPotUxUbfcmk= github.com/prometheus/otlptranslator v1.0.0 h1:s0LJW/iN9dkIH+EnhiD3BlkkP5QVIUVEoIwkU+A6qos= github.com/prometheus/otlptranslator v1.0.0/go.mod h1:vRYWnXvI6aWGpsdY/mOT/cbeVRBlPWtBNDb7kGR3uKM= -github.com/prometheus/procfs v0.21.1 h1:GljZCt+zSTS+NZq88cyQ1LjZ+RCHp3uVuabBWA5+OJI= -github.com/prometheus/procfs v0.21.1/go.mod h1:aB55Cww9pdSJVHk0hUf0inxWyyjPogFIjmHKYgMKmtY= +github.com/prometheus/procfs v0.22.0 h1:6q9+/JL9IKAPbCmBrv9n5O5Ty3NKnciV5X7YGw0oics= +github.com/prometheus/procfs v0.22.0/go.mod h1:CvmFr/GVhIjIvWJZW3tgkODBQMRIf0EyWMQLHCHab58= github.com/redis/go-redis/extra/rediscmd/v9 v9.0.5 h1:EaDatTxkdHG+U3Bk4EUr+DZ7fOGwTfezUiUJMaIcaho= github.com/redis/go-redis/extra/rediscmd/v9 v9.0.5/go.mod h1:fyalQWdtzDBECAQFBJuQe5bzQ02jGd5Qcbgb97Flm7U= github.com/redis/go-redis/extra/redisotel/v9 v9.0.5 h1:EfpWLLCyXw8PSM2/XNJLjI3Pb27yVE+gIAfeqp8LUCc= @@ -319,8 +319,8 @@ github.com/shopspring/decimal v1.4.0 h1:bxl37RwXBklmTi0C79JfXCEBD1cqqHt0bbgBAGFp github.com/shopspring/decimal v1.4.0/go.mod h1:gawqmDU56v4yIKSwfBSFip1HdCCXN8/+DMd9qYNcwME= github.com/sirupsen/logrus v1.9.4 h1:TsZE7l11zFCLZnZ+teH4Umoq5BhEIfIzfRDZ1Uzql2w= github.com/sirupsen/logrus v1.9.4/go.mod h1:ftWc9WdOfJ0a92nsE2jF5u5ZwH8Bv2zdeOC42RjbV2g= -github.com/spf13/cast v1.7.0 h1:ntdiHjuueXFgm5nzDRdOS4yfT43P5Fnud6DH50rz/7w= -github.com/spf13/cast v1.7.0/go.mod h1:ancEpBxwJDODSW/UG4rDrAqiKolqNNh2DX3mk86cAdo= +github.com/spf13/cast v1.10.0 h1:h2x0u2shc1QuLHfxi+cTJvs30+ZAHOGRic8uyGTDWxY= +github.com/spf13/cast v1.10.0/go.mod h1:jNfB8QC9IA6ZuY2ZjDp0KtFO2LZZlg4S/7bzP6qqeHo= github.com/spf13/cobra v1.10.2 h1:DMTTonx5m65Ic0GOoRY2c16WCbHxOOw6xxezuLaBpcU= github.com/spf13/cobra v1.10.2/go.mod h1:7C1pvHqHw5A4vrJfjNwvOdzYu0Gml16OCs2GRiTUUS4= github.com/spf13/pflag v1.0.9/go.mod h1:McXfInJRrz4CZXVZOBLb0bTZqETkiAhM9Iw0y3An2Bg= @@ -349,8 +349,8 @@ go.opentelemetry.io/contrib/exporters/autoexport v0.67.0 h1:4fnRcNpc6YFtG3zsFw9a go.opentelemetry.io/contrib/exporters/autoexport v0.67.0/go.mod h1:qTvIHMFKoxW7HXg02gm6/Wofhq5p3Ib/A/NNt1EoBSQ= go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.69.0 h1:8tvICD4vSTOOsNrsI4Ljf6C+6UKvpTEH5XY3JMoyPoo= go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.69.0/go.mod h1:z9+yiacE0IHRqM4qFfkbt/JYlmYXgss8GY/jXoNuPJI= -go.opentelemetry.io/otel v1.44.0 h1:JjwHmHpA4iZ3wBxluu2fbbE7j4kqlE8jXyAyPXH7HqU= -go.opentelemetry.io/otel v1.44.0/go.mod h1:BMgjTHL9WPRlRjL2oZCBTL4whCGtXch2H4BhOPIAyYc= +go.opentelemetry.io/otel v1.46.0 h1:FHt5/CDyVxi/8IM1CH7VE/rRgq3kLHa2mSTVMO8AWyc= +go.opentelemetry.io/otel v1.46.0/go.mod h1:Gj3SEScelsNC45tp4nSxRYlS+f5iez7W8XPMCt905kE= go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc v0.19.0 h1:Dn8rkudDzY6KV9dr/D/bTUuWgqDf9xe0rr4G2elrn0Y= go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc v0.19.0/go.mod h1:gMk9F0xDgyN9M/3Ed5Y1wKcx/9mlU91NXY2SNq7RQuU= go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp v0.19.0 h1:HIBTQ3VO5aupLKjC90JgMqpezVXwFuq6Ryjn0/izoag= @@ -375,16 +375,16 @@ go.opentelemetry.io/otel/exporters/stdout/stdouttrace v1.43.0 h1:mS47AX77OtFfKG4 go.opentelemetry.io/otel/exporters/stdout/stdouttrace v1.43.0/go.mod h1:PJnsC41lAGncJlPUniSwM81gc80GkgWJWr3cu2nKEtU= go.opentelemetry.io/otel/log v0.19.0 h1:KUZs/GOsw79TBBMfDWsXS+KZ4g2Ckzksd1ymzsIEbo4= go.opentelemetry.io/otel/log v0.19.0/go.mod h1:5DQYeGmxVIr4n0/BcJvF4upsraHjg6vudJJpnkL6Ipk= -go.opentelemetry.io/otel/metric v1.44.0 h1:1w0gILTcHdr3YI+ixLyjemwrVnsMURbTZFrSYCdDdmc= -go.opentelemetry.io/otel/metric v1.44.0/go.mod h1:8O7hanEPBNgEMmybD3s2VBKcgWOCsA6tzHBPODAiquo= +go.opentelemetry.io/otel/metric v1.46.0 h1:yBnkXvgV7AXFILZc5K6IZe/CBFF3OS7BJ8ov6/lj0K8= +go.opentelemetry.io/otel/metric v1.46.0/go.mod h1:iPmdWqifKUdzziPkvvzIJXITl56fQx2mGM/DHLB3/2o= go.opentelemetry.io/otel/sdk v1.44.0 h1:nHYwb9lK+fJPU/dnT6s7W7Z8itMWyqrnVfbheVYrZ58= go.opentelemetry.io/otel/sdk v1.44.0/go.mod h1:Osuydd3Se74nqjAKxid74N5eC+jfEqfTegHRnq58oK0= go.opentelemetry.io/otel/sdk/log v0.19.0 h1:scYVLqT22D2gqXItnWiocLUKGH9yvkkeql5dBDiXyko= go.opentelemetry.io/otel/sdk/log v0.19.0/go.mod h1:vFBowwXGLlW9AvpuF7bMgnNI95LiW10szrOdvzBHlAg= go.opentelemetry.io/otel/sdk/metric v1.44.0 h1:3LlKgI+VjbVsjNRFZJZAJ30WjXC5VkNRks6si09iEfI= go.opentelemetry.io/otel/sdk/metric v1.44.0/go.mod h1:5B5pMARnXxKhltooO4xUuCBorl65a4EpnTalObqOigA= -go.opentelemetry.io/otel/trace v1.44.0 h1:jxF5CsGYCe74MCRx2X4g7WsY/VBKRqqpNvXlX/6gtIk= -go.opentelemetry.io/otel/trace v1.44.0/go.mod h1:oLl1jrMQAVo6v3GAggN+1VH9VIz9iUSvW53sW1Q8PIE= +go.opentelemetry.io/otel/trace v1.46.0 h1:OULy7ccdJnZtJ0UDYFOIGaCmiWzJ8Vi2G/Rsu60qs1c= +go.opentelemetry.io/otel/trace v1.46.0/go.mod h1:J7GAXweO77XSFkB/rmAqk9D6ihszhFjLU+d9WuUxDLI= go.opentelemetry.io/proto/otlp v1.11.0 h1:5rrYs0Ykyj50sdU/JU0x8etU+LubXWb+gED6TbEdMIk= go.opentelemetry.io/proto/otlp v1.11.0/go.mod h1:SmVizdCOAm3XBtG1g1NnOdhW6jtddT72hLMhv8VwA8E= go.uber.org/goleak v1.3.0 h1:2K3zAYmnTNqV73imy9J1T3WC+gmCePx2hEGkimedGto= @@ -411,7 +411,6 @@ golang.org/x/oauth2 v0.36.0/go.mod h1:YDBUJMTkDnJS+A4BP4eZBjCqtokkg1hODuPjwiGPO7 golang.org/x/sync v0.23.0 h1:KameEIfc1IkluZyXWLn39Wd4tURc6GbCiISGiZm2bQk= golang.org/x/sync v0.23.0/go.mod h1:sUUOizhqBxiL6pEWpqNLUiaJn1ShEbZ6BBqskPbjZm0= golang.org/x/sys v0.0.0-20210616094352-59db8d763f22/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= -golang.org/x/sys v0.6.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= golang.org/x/sys v0.48.0 h1:bbX/i/6MgT9BVLM9RT1thmxL04yeTAhbEz4SyadbXoo= golang.org/x/sys v0.48.0/go.mod h1:hNLxWAXmnKAxqDtdwIYC4bM9oQPEecfsnNMuSxOs3og= golang.org/x/term v0.46.0 h1:3+OXuTbaKDgwk8jTi3aSLHRlmWqHEUDUtxnbFigO4YE= @@ -424,10 +423,10 @@ golang.org/x/tools v0.50.0 h1:c2ifzfcuY7L90lZ2aKd8S4K2NpASF08SZx9ZuJkHmSU= golang.org/x/tools v0.50.0/go.mod h1:7ulVMw3831Mwi5EZD6RomGyffr4VFjuNYXf2BbCEAV0= gomodules.xyz/jsonpatch/v2 v2.5.0 h1:JELs8RLM12qJGXU4u/TO3V25KW8GreMKl9pdkk14RM0= gomodules.xyz/jsonpatch/v2 v2.5.0/go.mod h1:AH3dM2RI6uoBZxn3LVrfvJ3E0/9dG4cSrbuBJT4moAY= -google.golang.org/genproto/googleapis/api v0.0.0-20260720211330-0afa2a65878a h1:97PfJ4tCxY5C7NzzgGqQEMZmXbISdvSArNNEOoUGKBg= -google.golang.org/genproto/googleapis/api v0.0.0-20260720211330-0afa2a65878a/go.mod h1:1brfde68Npq6+WA75c1EHWPijZEG1kMus61ygPZfn4A= -google.golang.org/genproto/googleapis/rpc v0.0.0-20260720211330-0afa2a65878a h1:qI/YMH1ep2qQtqcp00gMQyoU7mjvbhg88GJKCvfoLj0= -google.golang.org/genproto/googleapis/rpc v0.0.0-20260720211330-0afa2a65878a/go.mod h1:4Hqkh8ycfw05ld/3BWL7rJOSfebL2Q+DVDeRgYgxUU8= +google.golang.org/genproto/googleapis/api v0.0.0-20260831171406-18b4a7587f8a h1:i3TAXhpKc7TUP1VAPiBBrv45kamjoizCC3rOC0cAbOs= +google.golang.org/genproto/googleapis/api v0.0.0-20260831171406-18b4a7587f8a/go.mod h1:CvYJHpbzPlT0fb/PsgtAamdwru/GVxUsomFdXTpOTI8= +google.golang.org/genproto/googleapis/rpc v0.0.0-20260831171406-18b4a7587f8a h1:3Dnd1cDaZlB68lziofO+bJXpjOy8UfRv8Unt+yH8tQ4= +google.golang.org/genproto/googleapis/rpc v0.0.0-20260831171406-18b4a7587f8a/go.mod h1:DjtHYE8FKJLivXcBEjGwndXfIC23G0VpXiXKqG179uA= google.golang.org/grpc v1.82.1 h1:NnAxzGRA0677vCa4BUkOAnO5+FfQqVl9iUXeD0IqcGE= google.golang.org/grpc v1.82.1/go.mod h1:yzTZ1TB1Z3SG+LIYaI+WiE8D5+PZ3ArnrSp8zF3+/ZA= google.golang.org/protobuf v1.36.12 h1:pJOKDDOyeXErUroCihFAd5LQuwXBSpVnKGrj5o/fwxc= @@ -462,8 +461,8 @@ k8s.io/component-base v0.37.0 h1:3SdSa4+itMdFTDFTeR8CxKGmSTSMXFlKL4ky8OqjguM= k8s.io/component-base v0.37.0/go.mod h1:LjOebp4R9y6LODWZQv102ZQxGheLcDO2ZJLAw6bbh4I= k8s.io/klog/v2 v2.140.0 h1:Tf+J3AH7xnUzZyVVXhTgGhEKnFqye14aadWv7bzXdzc= k8s.io/klog/v2 v2.140.0/go.mod h1:o+/RWfJ6PwpnFn7OyAG3QnO47BFsymfEfrz6XyYSSp0= -k8s.io/kube-openapi v0.0.0-20260721132016-d427ff9ee9ad h1:oXImqH8mQNk7PmvzKhmN3ddJoY6OnyM225MXwGHPm0A= -k8s.io/kube-openapi v0.0.0-20260721132016-d427ff9ee9ad/go.mod h1:0/mqHCVhlumdJ3BhCfnjSZQE037nAhNodh1/hK0T8/I= +k8s.io/kube-openapi v0.0.0-20260821135717-be32def86098 h1:z5+pcu1jTyKK5mNTe2/+x+U6Uuv9jRVOJQLaBJJMpeI= +k8s.io/kube-openapi v0.0.0-20260821135717-be32def86098/go.mod h1:0/mqHCVhlumdJ3BhCfnjSZQE037nAhNodh1/hK0T8/I= k8s.io/kubectl v0.37.0 h1:cici6hiofx93ASldmprDmZF55SfhVt4o3HniltVLjTc= k8s.io/kubectl v0.37.0/go.mod h1:RSeEl8e/yqDx6srG8Azr0uAtVPNIZljA0PNh9HCBcdg= k8s.io/streaming v0.37.0 h1:iPBUZLZiKt5bV+lxJurASMOV07VuBhNpiwJt2//AWrM= From 04d558231454260e816e007bd44c2d1f8fc5fadc Mon Sep 17 00:00:00 2001 From: Michael Sprauer Date: Mon, 28 Sep 2026 20:28:51 +0200 Subject: [PATCH 02/11] fix: update ocm CLI flags and push-component mode for task test-e2e - Taskfile: add --copy-resources flag to push-component.py invocations (script now requires explicit mode: --copy-resources or --copy-local-resources) - build-component.py: clarify comment to reference open-component-model/ocm v0.48+ CLI Signed-off-by: Michael Sprauer --- Taskfile.yaml | 4 ++-- hack/build-component.py | 3 +-- 2 files changed, 3 insertions(+), 4 deletions(-) diff --git a/Taskfile.yaml b/Taskfile.yaml index eb843ff..8e85f6d 100644 --- a/Taskfile.yaml +++ b/Taskfile.yaml @@ -64,7 +64,7 @@ tasks: desc: Push OCM component to registry deps: [deps:python] cmds: - - python3 -u ./hack/push-component.py + - python3 -u ./hack/push-component.py --copy-resources env: PYTHONUNBUFFERED: "1" @@ -97,7 +97,7 @@ tasks: - echo "{{.DEV_VERSION}}" > VERSION - defer: git checkout VERSION - python3 -u ./hack/build-component.py - - python3 -u ./hack/push-component.py + - python3 -u ./hack/push-component.py --copy-resources - cd test/e2e && go test -v -timeout 45m ./... # ── release ─────────────────────────────────────────────────────────────── diff --git a/hack/build-component.py b/hack/build-component.py index 5c691f2..df3c172 100755 --- a/hack/build-component.py +++ b/hack/build-component.py @@ -169,7 +169,7 @@ def build_ocm_component( components_location = os.environ.get("COMPONENTS_LOCATION", "") - # Execute OCM command (ocm v0.48+ syntax) + # Execute OCM command (open-component-model/ocm v0.48+ syntax) cmd = [ "ocm", "add", "componentversions", "--create", @@ -178,7 +178,6 @@ def build_ocm_component( "--lookup", components_location, str(constructor_file), ] - run_command(cmd, env=env) From 8b40bc820c73a6902b7a08355136807048da486b Mon Sep 17 00:00:00 2001 From: Michael Sprauer Date: Tue, 29 Sep 2026 09:32:38 +0200 Subject: [PATCH 03/11] fix: explicitly set certManager.enabled in RemoteObservability template kro v0.9.4 has a regression (kubernetes-sigs/kro#1448) where includeWhen expressions referencing only static schema fields (schema.spec.*) are classified as data-pending and never resolve when the instance does not explicitly set those fields (even when a default is defined). The remote-observability RGD uses includeWhen: [${schema.spec.certManager.enabled}] on 8 resources. When the ObservabilityStack creates a RemoteObservability CR without explicitly setting certManager.enabled, kro v0.9.4 fails to evaluate these includeWhen conditions, leaving the instance stuck and never ready. Fix: explicitly pass certManager.enabled: true in the RemoteObservability template so the field is always present in the child CR spec. Signed-off-by: Michael Sprauer --- resource-graph-definitions/observability-stack.yaml | 2 ++ 1 file changed, 2 insertions(+) diff --git a/resource-graph-definitions/observability-stack.yaml b/resource-graph-definitions/observability-stack.yaml index 6708747..ff936da 100644 --- a/resource-graph-definitions/observability-stack.yaml +++ b/resource-graph-definitions/observability-stack.yaml @@ -266,6 +266,8 @@ spec: spec: componentRef: ${schema.spec.componentRef} imagePullSecretRef: ${schema.spec.imagePullSecretRef} + certManager: + enabled: true gateway: namespace: ${schema.spec.observabilityGateway.namespace} readyWhen: From 1c1330e495c57e0526f1f961e386107e29eac5b5 Mon Sep 17 00:00:00 2001 From: Michael Sprauer Date: Tue, 29 Sep 2026 10:55:52 +0200 Subject: [PATCH 04/11] fix(e2e): increase ObservabilityStack ready timeout to 35m for kro v0.9.4 kro v0.9.4 takes longer to reconcile the full ObservabilityStack (~25-30min) compared to v0.9.3 (~14min). The additional time is due to more HelmDeployment resources being reconciled on workload clusters (cert-manager, otel-operator, otel-collector-resource) now that certManager.enabled is explicitly set. The 20-minute timeout was sufficient for v0.9.3 but not for v0.9.4. Signed-off-by: Michael Sprauer --- test/e2e/obs_stack_test.go | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/test/e2e/obs_stack_test.go b/test/e2e/obs_stack_test.go index 6aa8006..5e8d763 100644 --- a/test/e2e/obs_stack_test.go +++ b/test/e2e/obs_stack_test.go @@ -150,7 +150,7 @@ func TestObsStack(t *testing.T) { } return ready, nil - }, wait.WithTimeout(20*time.Minute)); err != nil { + }, wait.WithTimeout(35*time.Minute)); err != nil { t.Errorf("%v", err) } From 42cf837a98309398e5e02e11ddd11d85b40416b7 Mon Sep 17 00:00:00 2001 From: Michael Sprauer Date: Tue, 29 Sep 2026 11:54:54 +0200 Subject: [PATCH 05/11] fix: remove metadata.generation comparison from remote-observability status kro v0.9.4 adds an 'internal.kro.run/apply-order' annotation to all managed resources via server-side apply on every reconcile. This bumps metadata.generation on HelmDeployment resources, while status.observedGeneration (updated by the HelmDeployment controller) lags behind. The result: the generation equality check otelOperatorHelmDeployment.status.observedGeneration == otelOperatorHelmDeployment.metadata.generation is permanently false in kro v0.9.4, preventing RemoteObservability.status.ready from ever becoming true, which blocks ObservabilityStack.status.ready. Fix: use only status.phase == 'Ready' as the readiness signal, which is stable and not affected by kro's annotation management. Also revert the 35m test timeout to 20m since the actual readiness delay was caused by this generation drift, not by genuine extra work. Signed-off-by: Michael Sprauer --- resource-graph-definitions/remote-observability.yaml | 8 ++++---- test/e2e/obs_stack_test.go | 2 +- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/resource-graph-definitions/remote-observability.yaml b/resource-graph-definitions/remote-observability.yaml index ec43672..2e369ee 100644 --- a/resource-graph-definitions/remote-observability.yaml +++ b/resource-graph-definitions/remote-observability.yaml @@ -63,12 +63,12 @@ spec: # Currently, referencing 'schema' is not possible in the status section, so we cannot determine whether the cert-manager is enabled or not. # This will be fixed with https://github.com/kubernetes-sigs/kro/pull/1300. # certManager: ${schema.spec.certManager.enabled ? ( certManagerHelmDeployment.status.observedGeneration == certManagerHelmDeployment.metadata.generation ? certManagerHelmDeployment.status.phase :"Outdated") :"Disabled"} - openTelemetryOperator: ${otelOperatorHelmDeployment.status.observedGeneration == otelOperatorHelmDeployment.metadata.generation ? otelOperatorHelmDeployment.status.phase :"Outdated"} - openTelemetryCollector: ${otelCollectorResourceHelmDeployment.status.observedGeneration == otelCollectorResourceHelmDeployment.metadata.generation ? otelCollectorResourceHelmDeployment.status.phase :"Outdated"} + openTelemetryOperator: ${otelOperatorHelmDeployment.status.phase} + openTelemetryCollector: ${otelCollectorResourceHelmDeployment.status.phase} ready: |- ${ - otelOperatorHelmDeployment.status.observedGeneration == otelOperatorHelmDeployment.metadata.generation && otelOperatorHelmDeployment.status.phase == "Ready" && - otelCollectorResourceHelmDeployment.status.observedGeneration == otelCollectorResourceHelmDeployment.metadata.generation && otelCollectorResourceHelmDeployment.status.phase == "Ready" + otelOperatorHelmDeployment.status.phase == "Ready" && + otelCollectorResourceHelmDeployment.status.phase == "Ready" } resources: diff --git a/test/e2e/obs_stack_test.go b/test/e2e/obs_stack_test.go index 5e8d763..6aa8006 100644 --- a/test/e2e/obs_stack_test.go +++ b/test/e2e/obs_stack_test.go @@ -150,7 +150,7 @@ func TestObsStack(t *testing.T) { } return ready, nil - }, wait.WithTimeout(35*time.Minute)); err != nil { + }, wait.WithTimeout(20*time.Minute)); err != nil { t.Errorf("%v", err) } From 6f38488acac656a058d6acd1b36aa25bb8700879 Mon Sep 17 00:00:00 2001 From: Michael Sprauer Date: Tue, 29 Sep 2026 12:38:32 +0200 Subject: [PATCH 06/11] debug: log ObservabilityStack status during readiness poll Temporary diagnostic to understand why status.ready never becomes true in kro v0.9.4. Will be removed after the root cause is identified. Signed-off-by: Michael Sprauer --- test/e2e/obs_stack_test.go | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/test/e2e/obs_stack_test.go b/test/e2e/obs_stack_test.go index 6aa8006..d1246d8 100644 --- a/test/e2e/obs_stack_test.go +++ b/test/e2e/obs_stack_test.go @@ -141,6 +141,11 @@ func TestObsStack(t *testing.T) { return false, err } + // Log status for diagnosis + if status, found, _ := unstructured.NestedMap(obsStack.Object, "status"); found { + t.Logf("ObservabilityStack status: %v", status) + } + ready, hasReady, err := unstructured.NestedBool(obsStack.Object, "status", "ready") if err != nil { return false, err From c181eaa0b50bff84f9e8c0592a1cc9d437aae230 Mon Sep 17 00:00:00 2001 From: Michael Sprauer Date: Tue, 29 Sep 2026 13:25:30 +0200 Subject: [PATCH 07/11] debug: also log RemoteObservability status during readiness poll Signed-off-by: Michael Sprauer --- test/e2e/obs_stack_test.go | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/test/e2e/obs_stack_test.go b/test/e2e/obs_stack_test.go index d1246d8..4c6f60f 100644 --- a/test/e2e/obs_stack_test.go +++ b/test/e2e/obs_stack_test.go @@ -146,6 +146,19 @@ func TestObsStack(t *testing.T) { t.Logf("ObservabilityStack status: %v", status) } + // Log RemoteObservability CR status + remoteObs := &unstructured.Unstructured{} + remoteObs.SetGroupVersionKind(schema.GroupVersionKind{Group: "kro.run", Version: "v1alpha1", Kind: "RemoteObservability"}) + remoteObs.SetName("remote-observability") + remoteObs.SetNamespace(obsStackNamespace) + if getErr := config.Client().Resources().Get(ctx, remoteObs.GetName(), remoteObs.GetNamespace(), remoteObs); getErr == nil { + if status, found, _ := unstructured.NestedMap(remoteObs.Object, "status"); found { + t.Logf("RemoteObservability status: %v", status) + } + } else { + t.Logf("RemoteObservability not found: %v", getErr) + } + ready, hasReady, err := unstructured.NestedBool(obsStack.Object, "status", "ready") if err != nil { return false, err From 4d9d738f6a7a6a98c6fee6de76c0516ef064f35d Mon Sep 17 00:00:00 2001 From: Michael Sprauer Date: Tue, 29 Sep 2026 14:17:51 +0200 Subject: [PATCH 08/11] fix: encode bytes values explicitly in remote-observability RGD kro v0.9.4 introduced stricter CEL value handling (PR #1346): accessing individual bytes fields from Kubernetes Secret.data (e.g. data["tls.crt"]) returns a CEL bytes type, which can no longer be used directly in resource templates. The error is: unsupported type: bytes value cannot be used directly in a resource template; encode it explicitly, e.g. base64.encode(...) kro v0.9.3 silently accepted bytes in templates (converting []byte directly); v0.9.4 rejects it, causing remoteClientCertSecret creation to fail with an error, preventing RemoteObservability from ever reaching status.ready=true. Fix: wrap the three Secret.data field accesses with base64.encode() to produce the base64 strings that Kubernetes Secret.data expects. Also remove temporary diagnostic logging added during investigation. Signed-off-by: Michael Sprauer --- .../remote-observability.yaml | 6 +++--- test/e2e/obs_stack_test.go | 18 ------------------ 2 files changed, 3 insertions(+), 21 deletions(-) diff --git a/resource-graph-definitions/remote-observability.yaml b/resource-graph-definitions/remote-observability.yaml index 2e369ee..d4c59c1 100644 --- a/resource-graph-definitions/remote-observability.yaml +++ b/resource-graph-definitions/remote-observability.yaml @@ -496,9 +496,9 @@ spec: namespace: ${remoteObsNamespace.metadata.name} type: Opaque data: - tls.crt: ${observabilityClientCertSecret.data["tls.crt"]} - tls.key: ${observabilityClientCertSecret.data["tls.key"]} - ca.crt: ${otlpLogsCertSecret.data["tls.crt"]} + tls.crt: ${base64.encode(observabilityClientCertSecret.data["tls.crt"])} + tls.key: ${base64.encode(observabilityClientCertSecret.data["tls.key"])} + ca.crt: ${base64.encode(otlpLogsCertSecret.data["tls.crt"])} - id: observabilityGateway externalRef: diff --git a/test/e2e/obs_stack_test.go b/test/e2e/obs_stack_test.go index 4c6f60f..6aa8006 100644 --- a/test/e2e/obs_stack_test.go +++ b/test/e2e/obs_stack_test.go @@ -141,24 +141,6 @@ func TestObsStack(t *testing.T) { return false, err } - // Log status for diagnosis - if status, found, _ := unstructured.NestedMap(obsStack.Object, "status"); found { - t.Logf("ObservabilityStack status: %v", status) - } - - // Log RemoteObservability CR status - remoteObs := &unstructured.Unstructured{} - remoteObs.SetGroupVersionKind(schema.GroupVersionKind{Group: "kro.run", Version: "v1alpha1", Kind: "RemoteObservability"}) - remoteObs.SetName("remote-observability") - remoteObs.SetNamespace(obsStackNamespace) - if getErr := config.Client().Resources().Get(ctx, remoteObs.GetName(), remoteObs.GetNamespace(), remoteObs); getErr == nil { - if status, found, _ := unstructured.NestedMap(remoteObs.Object, "status"); found { - t.Logf("RemoteObservability status: %v", status) - } - } else { - t.Logf("RemoteObservability not found: %v", getErr) - } - ready, hasReady, err := unstructured.NestedBool(obsStack.Object, "status", "ready") if err != nil { return false, err From ddae6cbef753f8454954d39b50d4d0893ce8c30b Mon Sep 17 00:00:00 2001 From: Michael Sprauer Date: Tue, 29 Sep 2026 14:40:53 +0200 Subject: [PATCH 09/11] fix: avoid bytes field access in remote-observability cert secret MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit kro v0.9.4 rejects bytes values in resource templates (EnsureJSONSafe check, PR #1346). The remoteClientCertSecret merged data from two secrets using individual field access (Secret.data["tls.crt"]), which returns CEL bytes type. Using base64.encode() to fix the runtime error causes a type-check failure (expected bytes but got string). Solution: eliminate the merged secret entirely. Instead, mount the two source secrets directly as separate volumes in the OTel collector: - observabilityClientCertSecret → /etc/otel/certs/client (tls.crt, tls.key) - otlpLogsCertSecret → /etc/otel/certs/ca (tls.crt as CA cert) This avoids any per-field bytes access while preserving the cert data needed for mutual TLS. The secretsToCopy list is updated to copy both source secrets to the workload cluster. Signed-off-by: Michael Sprauer --- .../remote-observability.yaml | 33 ++++++++----------- 1 file changed, 14 insertions(+), 19 deletions(-) diff --git a/resource-graph-definitions/remote-observability.yaml b/resource-graph-definitions/remote-observability.yaml index d4c59c1..a1eafd6 100644 --- a/resource-graph-definitions/remote-observability.yaml +++ b/resource-graph-definitions/remote-observability.yaml @@ -487,19 +487,6 @@ spec: name: otlp-logs-cert namespace: ${schema.spec.gateway.namespace} - - id: remoteClientCertSecret - template: - apiVersion: v1 - kind: Secret - metadata: - name: observability-client-cert - namespace: ${remoteObsNamespace.metadata.name} - type: Opaque - data: - tls.crt: ${base64.encode(observabilityClientCertSecret.data["tls.crt"])} - tls.key: ${base64.encode(observabilityClientCertSecret.data["tls.key"])} - ca.crt: ${base64.encode(otlpLogsCertSecret.data["tls.crt"])} - - id: observabilityGateway externalRef: apiVersion: gateway.networking.k8s.io/v1 @@ -559,17 +546,23 @@ spec: endpoint: "https://${observabilityGateway.spec.listeners.filter(elem, elem.name == 'otlp-logs')[0].hostname}:${string(observabilityGateway.spec.listeners.filter(elem, elem.name == 'otlp-logs')[0].port)}/insert/opentelemetry" tls: enabled: true - certFile: /etc/otel/certs/tls.crt - keyFile: /etc/otel/certs/tls.key - caFile: /etc/otel/certs/ca.crt + certFile: /etc/otel/certs/client/tls.crt + keyFile: /etc/otel/certs/client/tls.key + caFile: /etc/otel/certs/ca/tls.crt additionalVolumeMounts: - name: observability-client-cert - mountPath: /etc/otel/certs + mountPath: /etc/otel/certs/client + readOnly: true + - name: observability-ca-cert + mountPath: /etc/otel/certs/ca readOnly: true additionalVolumes: - name: observability-client-cert secret: - secretName: ${remoteClientCertSecret.metadata.name} + secretName: ${observabilityClientCertSecret.metadata.name} + - name: observability-ca-cert + secret: + secretName: ${otlpLogsCertSecret.metadata.name} serviceAccount: imagePullSecrets: - name: ${otelCollectorImagePullSecret.metadata.name} @@ -578,6 +571,8 @@ spec: - source: name: ${otelCollectorImagePullSecret.metadata.name} - source: - name: ${remoteClientCertSecret.metadata.name} + name: ${observabilityClientCertSecret.metadata.name} + - source: + name: ${otlpLogsCertSecret.metadata.name} readyWhen: - ${otelCollectorResourceHelmDeployment.status.phase == "Ready"} From 3f09cc8277b353acd8a21192ca34eea6ba7cca6e Mon Sep 17 00:00:00 2001 From: Michael Sprauer Date: Tue, 29 Sep 2026 15:34:35 +0200 Subject: [PATCH 10/11] fix: update remote-observability RGD for kro v0.9.4 compatibility kro v0.9.4 introduced two breaking changes affecting remote-observability: 1. metadata.generation drift: kro v0.9.4 adds an apply-order annotation to all managed resources on every reconcile, bumping metadata.generation. The status expressions compared observedGeneration == metadata.generation, which was never stable. Fixed by checking only status.phase == 'Ready'. 2. Bytes values in templates (kro v0.9.4 PR #1346): accessing individual fields from Secret.data (e.g. data["tls.crt"]) returns CEL bytes type which can no longer be used directly in resource templates (EnsureJSONSafe now rejects []byte). Using base64.encode() fails type-check (expected bytes but got string). Fixed by replacing the merged remoteClientCertSecret (which needed individual bytes field access) with two separate secrets using whole-map data copy: - clientCertSecretCopy: data: ${observabilityClientCertSecret.data} - caCertSecretCopy: data: ${otlpLogsCertSecret.data} Whole-map access uses convertMap's fast-path (raw Go map, no bytes decode). The OTel collector mounts both secrets at separate paths: - /etc/otel/certs/client/ (tls.crt, tls.key) - /etc/otel/certs/ca/ (tls.crt as CA cert) Signed-off-by: Michael Sprauer --- .../remote-observability.yaml | 28 ++++++++++++++++--- 1 file changed, 24 insertions(+), 4 deletions(-) diff --git a/resource-graph-definitions/remote-observability.yaml b/resource-graph-definitions/remote-observability.yaml index a1eafd6..d79de12 100644 --- a/resource-graph-definitions/remote-observability.yaml +++ b/resource-graph-definitions/remote-observability.yaml @@ -487,6 +487,26 @@ spec: name: otlp-logs-cert namespace: ${schema.spec.gateway.namespace} + - id: clientCertSecretCopy + template: + apiVersion: v1 + kind: Secret + metadata: + name: observability-client-cert + namespace: ${remoteObsNamespace.metadata.name} + type: Opaque + data: ${observabilityClientCertSecret.data} + + - id: caCertSecretCopy + template: + apiVersion: v1 + kind: Secret + metadata: + name: observability-ca-cert + namespace: ${remoteObsNamespace.metadata.name} + type: Opaque + data: ${otlpLogsCertSecret.data} + - id: observabilityGateway externalRef: apiVersion: gateway.networking.k8s.io/v1 @@ -559,10 +579,10 @@ spec: additionalVolumes: - name: observability-client-cert secret: - secretName: ${observabilityClientCertSecret.metadata.name} + secretName: ${clientCertSecretCopy.metadata.name} - name: observability-ca-cert secret: - secretName: ${otlpLogsCertSecret.metadata.name} + secretName: ${caCertSecretCopy.metadata.name} serviceAccount: imagePullSecrets: - name: ${otelCollectorImagePullSecret.metadata.name} @@ -571,8 +591,8 @@ spec: - source: name: ${otelCollectorImagePullSecret.metadata.name} - source: - name: ${observabilityClientCertSecret.metadata.name} + name: ${clientCertSecretCopy.metadata.name} - source: - name: ${otlpLogsCertSecret.metadata.name} + name: ${caCertSecretCopy.metadata.name} readyWhen: - ${otelCollectorResourceHelmDeployment.status.phase == "Ready"} From c6619f227db8714475eb7aa3cc61f4a04a892ca9 Mon Sep 17 00:00:00 2001 From: Michael Sprauer Date: Tue, 29 Sep 2026 16:06:50 +0200 Subject: [PATCH 11/11] fix: remove unnecessary certManager.enabled from RemoteObservability template Kubernetes applies the CRD default (enabled: true) when the CR is created, so setting it explicitly is redundant. Additionally, having cert-manager explicitly installed on workload clusters increased reconciliation load, causing the opencontrolplane_controlplane Prometheus metric to take longer to appear (beyond the 5-minute test timeout). Signed-off-by: Michael Sprauer --- resource-graph-definitions/observability-stack.yaml | 2 -- 1 file changed, 2 deletions(-) diff --git a/resource-graph-definitions/observability-stack.yaml b/resource-graph-definitions/observability-stack.yaml index ff936da..6708747 100644 --- a/resource-graph-definitions/observability-stack.yaml +++ b/resource-graph-definitions/observability-stack.yaml @@ -266,8 +266,6 @@ spec: spec: componentRef: ${schema.spec.componentRef} imagePullSecretRef: ${schema.spec.imagePullSecretRef} - certManager: - enabled: true gateway: namespace: ${schema.spec.observabilityGateway.namespace} readyWhen: