Sitelet https://github.com/kubernetes/kops/commit/fdc3db67fef2a907c2103ad517a1a84f14c95cec
Skip to content

Commit fdc3db6

Browse files
committed
TEMPORARY: ignore KUBE_SSH_USER on GCE
DO NOT MERGE. Revert this commit before merging the PR. Every GCE job sets KUBE_SSH_USER=prow, and that takes precedence over discovery, so the presubmits on this PR would never reach resolveSSHUserFromCluster and the new code path would go unexercised. Ignoring the variable for GCE makes those jobs derive the user instead -- "ubuntu" on the Ubuntu jobs, "admin" on COS -- which is what the change does once a job opts in by dropping the variable for real. This works with the key those jobs already have: kops installs whatever it is given as --ssh-public-key into GCE instance metadata under that same derived username, so the preset-k8s-ssh key is authorized for "prow" and for "ubuntu"/"admin" alike. Scoped to gce so the AWS, Azure and DigitalOcean presubmits are unaffected. No test changes are needed, since the unit tests do not go through initialize().
1 parent 28e30ce commit fdc3db6

1 file changed

Lines changed: 14 additions & 1 deletion

File tree

‎tests/e2e/kubetest2-kops/deployer/common.go‎

Lines changed: 14 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -137,7 +137,20 @@ func (d *deployer) initialize() error {
137137
}
138138
}
139139

140-
if d.SSHUser == "" {
140+
// TEMPORARY - DO NOT MERGE. Revert this block before merging.
141+
//
142+
// Every GCE job sets KUBE_SSH_USER=prow, which takes precedence over discovery, so the
143+
// presubmits on this PR would never exercise resolveSSHUserFromCluster. Ignoring the variable
144+
// for GCE makes them derive the user instead: "ubuntu" on the Ubuntu jobs, "admin" on COS.
145+
//
146+
// This is safe with the key the jobs already have. kops installs whatever it is given as
147+
// --ssh-public-key into GCE instance metadata under that same derived username, so the
148+
// preset-k8s-ssh key is authorized for both "prow" and "ubuntu"/"admin".
149+
//
150+
// Scoped to gce so the AWS, Azure and DigitalOcean presubmits are unaffected.
151+
if d.CloudProvider == "gce" {
152+
klog.Warning("TEMPORARY: ignoring KUBE_SSH_USER so that SSH user discovery can be validated")
153+
} else if d.SSHUser == "" {
141154
d.SSHUser = os.Getenv("KUBE_SSH_USER")
142155
}
143156
klog.V(1).Infof("Using SSH user: [%s]", d.SSHUser)

0 commit comments

Comments
 (0)