Skip to content

feat(tls): configure TLS curve preferences for gitops-plugin - #1347

Open
akhilnittala wants to merge 3 commits into
redhat-developer:masterfrom
akhilnittala:usr/akhil/configure_gitops_plugin_curve_preferences
Open

akhilnittala wants to merge 3 commits into
redhat-developer:masterfrom
akhilnittala:usr/akhil/configure_gitops_plugin_curve_preferences

Conversation

@akhilnittala

@akhilnittala akhilnittala commented Oct 8, 2026 •

Copy link
Copy Markdown
Member

What does this PR do?

https://redhat.atlassian.net/browse/GITOPS-11607
PR acceptance criteria:

  • Documentation was updated and verified using make serve-docs
  • Unit tests were updated
  • E2E tests were updated

What type of PR is this?

/kind enhancement

Special notes to the reviewer:

  • this pr configures curve preferences in gitops plugin component based on the central TLS profile CR

Signed-off-by: akhil nittala <nakhil@redhat.com>
@openshift-ci openshift-ci Bot added the kind/enhancement New feature or request label Oct 8, 2026
Signed-off-by: akhil nittala <nakhil@redhat.com>
@coderabbitai

coderabbitai Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository YAML (base), Organization UI (inherited)
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: e507ff76-b387-4945-8258-816e81e4650c
📥 Commits

Reviewing files that changed from the base of the PR and between a9c9ff0 and 3cbbe79.

⛔ Files ignored due to path filters (1)
  • go.sum is excluded by !**/*.sum
📒 Files selected for processing (5)
  • argocd-operator/pkg/tlsprofile/profile.go
  • cmd/main.go
  • controllers/consoleplugin.go
  • controllers/consoleplugin_test.go
  • go.mod
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

Included review availability: This review used your included allowance. Your plan provides up to 2 included reviews per hour; 1 remain after this review.


📝 Summary

Summary by CodeRabbit

  • New Features
    • TLS configuration now applies supported cluster curve preferences to the console plugin’s HTTPS settings. Unsupported preferences are ignored, and the setting is omitted when none are supported.

Walkthrough

The TLS profile now carries cluster curve preferences. The controller filters TLS groups against an allowlist and includes supported groups in the generated HTTPD configuration.

Changes

TLS curve preferences

Layer / File(s) Summary
TLS profile propagation
argocd-operator/pkg/tlsprofile/profile.go, cmd/main.go, go.mod
TLSConfigProfile adds CurvePreferences. main maps the cluster TLS groups to strings in their original order. go.mod adds github.com/samber/lo.
HTTPD group configuration
controllers/consoleplugin.go, controllers/consoleplugin_test.go
The controller filters TLS groups to supported values and joins them with colons. It adds SSLOpenSSLConfCmd Groups only when supported groups remain. Tests cover supported groups, filtering, and omission.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Feature

Merge Risk: ⚪ Minimal · up to 3cbbe

The console plugin's HTTPD configuration now follows the cluster TLS profile's curve preferences and ignores groups it does not support. The shipped images support the allowed groups, and configuration changes restart the plugin pods. No merge-blocking risk was found.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 25.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 4 functions across 4 files. (1 skipped: 1… Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title clearly describes configuring TLS curve preferences for the gitops-plugin, which matches the main change.
Description check ✅ Passed The description explains that the change configures curve preferences from the central TLS profile CR and links the related issue.
Full details: Docstring Coverage

Explanation

Docstring coverage is 25.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 4 functions across 4 files. (1 skipped: 1 unsupported.)


Comment @coderabbitai help to get the list of available commands.

@openshift-ci

openshift-ci Bot commented Oct 8, 2026

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
Once this PR has been reviewed and has the lgtm label, please assign chetan-rns for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci

openshift-ci Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

@akhilnittala: The following tests failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test name Commit Details Required Rerun command
ci/prow/v4.19-e2e 3cbbe79 link true /test v4.19-e2e
ci/prow/v4.19-kuttl-parallel 3cbbe79 link true /test v4.19-kuttl-parallel
ci/prow/v4.19-kuttl-sequential 3cbbe79 link true /test v4.19-kuttl-sequential
ci/prow/v4.14-kuttl-sequential 3cbbe79 link false /test v4.14-kuttl-sequential

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

@akhilnittala
akhilnittala requested review from jgwest and removed request for Rizwana777 and varshab1210 October 9, 2026 09:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

kind/enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant