)]}'
{"id":"openstack%2Fopenstack-helm~998206","triplet_id":"openstack%2Fopenstack-helm~master~I7e155962b7cd82f7d85847a2c70137cfbf5d7020","project":"openstack/openstack-helm","branch":"master","attention_set":{},"removed_from_attention_set":{"3009":{"account":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"last_update":"2026-07-21 22:23:15.000000000","reason":"Change was submitted"}},"hashtags":[],"change_id":"I7e155962b7cd82f7d85847a2c70137cfbf5d7020","subject":"deploy: survive transient admission-webhook races in CI","status":"MERGED","created":"2026-07-21 18:22:24.000000000","updated":"2026-07-21 22:24:10.000000000","submitted":"2026-07-21 22:23:15.000000000","submitter":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"total_comment_count":0,"unresolved_comment_count":0,"has_review_started":true,"submission_id":"998206","meta_rev_id":"d7d5c109890a2a3c42f4b39dd1849047005a2052","_number":998206,"virtual_id_number":998206,"owner":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"actions":{},"labels":{"Verified":{"approved":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"value":0,"_account_id":5890,"name":"Doug Goldstein","email":"cardoe@cardoe.com","username":"cardoe"},{"value":0,"_account_id":34520,"name":"Sergiy Markin","email":"smarkin@mirantis.com","username":"sm515x"},{"tag":"autogenerated:zuul:gate","value":2,"date":"2026-07-21 22:23:15.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","default_value":0,"optional":true},"Code-Review":{"approved":{"_account_id":5890,"name":"Doug Goldstein","email":"cardoe@cardoe.com","username":"cardoe"},"all":[{"value":2,"date":"2026-07-21 21:37:47.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":5890,"name":"Doug Goldstein","email":"cardoe@cardoe.com","username":"cardoe"},{"value":2,"date":"2026-07-21 21:19:31.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":34520,"name":"Sergiy Markin","email":"smarkin@mirantis.com","username":"sm515x"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","default_value":0,"optional":true},"Workflow":{"approved":{"_account_id":5890,"name":"Doug Goldstein","email":"cardoe@cardoe.com","username":"cardoe"},"all":[{"value":1,"date":"2026-07-21 21:37:47.000000000","permitted_voting_range":{"min":1,"max":1},"_account_id":5890,"name":"Doug Goldstein","email":"cardoe@cardoe.com","username":"cardoe"},{"value":0,"_account_id":34520,"name":"Sergiy Markin","email":"smarkin@mirantis.com","username":"sm515x"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":5890,"name":"Doug Goldstein","email":"cardoe@cardoe.com","username":"cardoe"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"_account_id":34520,"name":"Sergiy Markin","email":"smarkin@mirantis.com","username":"sm515x"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2026-07-21 21:16:43.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"},{"updated":"2026-07-21 21:19:31.000000000","updated_by":{"_account_id":34520,"name":"Sergiy Markin","email":"smarkin@mirantis.com","username":"sm515x"},"reviewer":{"_account_id":34520,"name":"Sergiy Markin","email":"smarkin@mirantis.com","username":"sm515x"},"state":"REVIEWER"},{"updated":"2026-07-21 21:37:47.000000000","updated_by":{"_account_id":5890,"name":"Doug Goldstein","email":"cardoe@cardoe.com","username":"cardoe"},"reviewer":{"_account_id":5890,"name":"Doug Goldstein","email":"cardoe@cardoe.com","username":"cardoe"},"state":"REVIEWER"}],"messages":[{"id":"ce080a57372b1072b39d1a21f8511de47d0d8a26","tag":"autogenerated:gerrit:newWipPatchSet","author":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"date":"2026-07-21 18:22:24.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"56d8ed861ce7b37e117744b24a13f6a9f2d3f54f","tag":"autogenerated:gerrit:newWipPatchSet","author":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"date":"2026-07-21 18:25:36.000000000","message":"Uploaded patch set 2: Commit message was updated.","accounts_in_message":[],"_revision_number":2},{"id":"233b57295cbad99979f0b099423da1445950774b","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"date":"2026-07-21 18:27:12.000000000","message":"Uploaded patch set 3: New patch set was added with same tree, parent tree, and commit message as Patch Set 2.","accounts_in_message":[],"_revision_number":3},{"id":"6406bf849077cd0f01b0d62851507e304bc46718","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"date":"2026-07-21 19:22:41.000000000","message":"Uploaded patch set 4.","accounts_in_message":[],"_revision_number":4},{"id":"768ec7494c6dd2aea9cc4c202148e0d57932cf2d","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-07-21 21:16:43.000000000","message":"Patch Set 4: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/fa6e071cbcba4b76ac4fcc2867bac400\n\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/8fad0189a07a498c9977fc1acd7521b0 : SUCCESS in 2m 21s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/c46ac0a697ec49ccb98d84df42eeb691 : SUCCESS in 2m 47s\n- openstack-helm-linter https://zuul.opendev.org/t/openstack/build/7538d412ef59414fa84b771d19317582 : SUCCESS in 3m 23s\n- openstack-helm-pre-commit https://zuul.opendev.org/t/openstack/build/814661638e9942f3b5c1a7b0fde7b6d6 : SUCCESS in 2m 08s\n- openstack-helm-build-charts https://zuul.opendev.org/t/openstack/build/ffb15bd5d2504de2a334de8dfce990c5 : SUCCESS in 2m 13s\n- openstack-helm-cinder-2025-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/e04c2a891f124927b2dfededd5334548 : SUCCESS in 47m 59s\n- openstack-helm-compute-kit-2025-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/b7dbc9a5900b4c96923ec98a672da5ed : SUCCESS in 1h 13m 05s\n- openstack-helm-cinder-2025-2-ubuntu_noble https://zuul.opendev.org/t/openstack/build/d60eb9c90d504170b621f4887f95da58 : SUCCESS in 36m 52s\n- openstack-helm-compute-kit-2025-2-ubuntu_noble https://zuul.opendev.org/t/openstack/build/adff2aa20b25419da974558551da42ff : SUCCESS in 1h 14m 02s\n- openstack-helm-cinder-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/e4e9bbe716084b318f1ee78938069237 : SUCCESS in 30m 30s\n- openstack-helm-compute-kit-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/770ac7c8b70d430c92f8a90a8df85cd1 : SUCCESS in 1h 12m 52s\n- openstack-helm-tls-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/3eb2f74b729945b38296983540c5a47f : SUCCESS in 1h 41m 40s\n- openstack-helm-compute-kit-dpdk-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/1fe4c62e6013487cb5559287860f6915 : SUCCESS in 54m 49s\n- openstack-helm-octavia-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/dd389f8c15be473f998a7fb0956d5071 : SUCCESS in 59m 09s\n- openstack-helm-logging https://zuul.opendev.org/t/openstack/build/bcc98646888a43d48219b9e76329efc8 : SUCCESS in 25m 05s\n- openstack-helm-monitoring https://zuul.opendev.org/t/openstack/build/31cec7b2aba1485a9208dfa3c4f9e66f : SUCCESS in 25m 34s","accounts_in_message":[],"_revision_number":4},{"id":"45e7829c9d8bc01fa019a5dd4ff3368dd417e05c","author":{"_account_id":34520,"name":"Sergiy Markin","email":"smarkin@mirantis.com","username":"sm515x"},"date":"2026-07-21 21:19:31.000000000","message":"Patch Set 4: Code-Review+2","accounts_in_message":[],"_revision_number":4},{"id":"96680a44ff8f835489b8d15285be5bf6965b9ee6","author":{"_account_id":5890,"name":"Doug Goldstein","email":"cardoe@cardoe.com","username":"cardoe"},"date":"2026-07-21 21:37:47.000000000","message":"Patch Set 4: Code-Review+2 Workflow+1","accounts_in_message":[],"_revision_number":4},{"id":"924db86545a5a5b106541da1dc32013b4d095df9","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-07-21 21:38:00.000000000","message":"Patch Set 4: -Verified\n\nStarting gate jobs.","accounts_in_message":[],"_revision_number":4},{"id":"04279ad9b746d2a7f9f3df7b2c952f9082a3f1ea","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-07-21 22:23:15.000000000","message":"Patch Set 4: Verified+2\n\nBuild succeeded (gate pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/42c6cbb882f74c5eabb6e25132601375\n\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/6fbe1a5c0cc540f6a020d6b8ce418a2c : SUCCESS in 3m 33s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/e13a83dbfdab46d1a0e37b3407e3a4e9 : SUCCESS in 2m 06s\n- openstack-helm-linter https://zuul.opendev.org/t/openstack/build/28b287061b7945519f045b9d156cd79e : SUCCESS in 3m 01s\n- openstack-helm-cinder-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/62d295b6085c48fb9ec09ec71e9a0d76 : SUCCESS in 28m 17s\n- openstack-helm-compute-kit-2026-1-ubuntu_noble https://zuul.opendev.org/t/openstack/build/f5d0c1ee3fe245a7804be91d9a3fe644 : SUCCESS in 44m 29s\n- openstack-helm-logging https://zuul.opendev.org/t/openstack/build/6f6ecbdeadde4b0292cca02b7bbada69 : SUCCESS in 39m 06s\n- openstack-helm-monitoring https://zuul.opendev.org/t/openstack/build/f0883da5788b44eb83f01050b0afbf5b : SUCCESS in 25m 01s","accounts_in_message":[],"_revision_number":4},{"id":"551398da775bd8cdb4a2b75f54fd75a8273601d4","tag":"autogenerated:gerrit:merged","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-07-21 22:23:15.000000000","message":"Change has been successfully merged","accounts_in_message":[],"_revision_number":4},{"id":"d7d5c109890a2a3c42f4b39dd1849047005a2052","tag":"autogenerated:zuul:promote","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-07-21 22:24:10.000000000","message":"Patch Set 4:\n\nBuild succeeded (promote pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/fb9c8e7ed5fa46f3bcdf240758d51680\n\n- promote-openstack-tox-docs https://zuul.opendev.org/t/openstack/build/3eb3b62382234a03bb60c48cd79a9ee1 : SUCCESS in 43s","accounts_in_message":[],"_revision_number":4}],"current_revision_number":4,"current_revision":"46fb913f1b158998d215abdde3126ae54a8de7c0","revisions":{"dbd464736c846ee15c1ec09248e840aac6060fb9":{"kind":"REWORK","_number":1,"created":"2026-07-21 18:22:24.000000000","uploader":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"ref":"refs/changes/06/998206/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-helm","ref":"refs/changes/06/998206/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/06/998206/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/06/998206/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/06/998206/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-helm refs/changes/06/998206/1"}}},"commit":{"parents":[{"commit":"d03dd061a8112c468e2f6529cb0663873f96b50f","subject":"Merge \"Change 2026.1-ubuntu_jammy to 2026.1-ubuntu_noble\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/d03dd061a8112c468e2f6529cb0663873f96b50f"}]}],"author":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-07-21 18:21:48.000000000","tz":-300},"committer":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-07-21 18:22:21.000000000","tz":-300},"subject":"[WIP] deploy-env: fix silent MetalLB IPAddressPool loss","message":"[WIP] deploy-env: fix silent MetalLB IPAddressPool loss\n\nThe \"Create MetalLB address pool\" task applies the IPAddressPool and then\nthe L2Advertisement in a single shell block without `set -e`. Right after\nMetalLB is installed its validating webhook is intermittently unreachable\n(\"failed calling webhook ipaddresspoolvalidationwebhook.metallb.io: ...\ncontext deadline exceeded\"), so the IPAddressPool apply fails. Without\n`set -e` the block continues, applies the L2Advertisement (which succeeds),\nand the block\u0027s exit code is that of the last command (0). The task\u0027s\n`until metallb_pool_result.rc \u003d\u003d 0` therefore passes on the first attempt\nand the `retries: 6` loop never re-runs, leaving the cluster with an\nL2Advertisement but no IPAddressPool.\n\nWith no address pool MetalLB cannot assign LoadBalancer IPs, so the Envoy\ngateway Service stays \u003cpending\u003e. Because *.openstack-helm.org is statically\nmapped to the expected gateway IP, every public endpoint (keystone first)\nbecomes unreachable and deploys fail much later with\n\"Request to http://keystone.openstack-helm.org/v3/auth/tokens timed out\".\nThis is intermittent per environment and has been the cause of the rotating\n~1/3 gate job failures.\n\nAdd `set -e` so a failed IPAddressPool apply fails the task and the existing\nretry loop waits for the webhook to become reachable, after which both\nresources apply successfully (verified: re-applying the pool on an affected\nenv succeeds and the gateway immediately gets its IP).\n\nChange-Id: I7e155962b7cd82f7d85847a2c70137cfbf5d7020\nSigned-off-by: Vladimir Kozhukalov \u003ckozhukalov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/dbd464736c846ee15c1ec09248e840aac6060fb9"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/dbd464736c846ee15c1ec09248e840aac6060fb9"}]},"branch":"refs/heads/master"},"b739121a7a837336466792d1bf69a07142b0dfe0":{"kind":"NO_CODE_CHANGE","_number":2,"created":"2026-07-21 18:25:36.000000000","uploader":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"ref":"refs/changes/06/998206/2","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-helm","ref":"refs/changes/06/998206/2","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/06/998206/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/06/998206/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/06/998206/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-helm refs/changes/06/998206/2"}}},"commit":{"parents":[{"commit":"d03dd061a8112c468e2f6529cb0663873f96b50f","subject":"Merge \"Change 2026.1-ubuntu_jammy to 2026.1-ubuntu_noble\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/d03dd061a8112c468e2f6529cb0663873f96b50f"}]}],"author":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-07-21 18:21:48.000000000","tz":-300},"committer":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-07-21 18:25:25.000000000","tz":-300},"subject":"deploy-env: fix silent MetalLB IPAddressPool loss","message":"deploy-env: fix silent MetalLB IPAddressPool loss\n\nThe \"Create MetalLB address pool\" task applies the IPAddressPool\nand then the L2Advertisement in one shell block without `set -e`.\nRight after MetalLB is installed its validating webhook is\nintermittently unreachable (\"failed calling webhook\nipaddresspoolvalidationwebhook.metallb.io: ... context deadline\nexceeded\"), so the IPAddressPool apply fails. Without `set -e` the\nblock continues, applies the L2Advertisement (which succeeds), and\nthe block exit code is that of the last command (0). The task\u0027s\n`until metallb_pool_result.rc \u003d\u003d 0` passes on the first attempt and\nthe `retries: 6` loop never re-runs, leaving the cluster with an\nL2Advertisement but no IPAddressPool.\n\nWith no address pool MetalLB cannot assign LoadBalancer IPs, so the\nEnvoy gateway Service stays \u003cpending\u003e. Because *.openstack-helm.org\nis statically mapped to the expected gateway IP, every public\nendpoint (keystone first) becomes unreachable and deploys fail much\nlater with a keystone /v3/auth/tokens request timeout. This is\nintermittent per environment and has caused the rotating ~1/3 gate\njob failures.\n\nAdd `set -e` so a failed IPAddressPool apply fails the task and the\nexisting retry loop waits for the webhook to become reachable, after\nwhich both resources apply successfully.\n\nChange-Id: I7e155962b7cd82f7d85847a2c70137cfbf5d7020\nSigned-off-by: Vladimir Kozhukalov \u003ckozhukalov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/b739121a7a837336466792d1bf69a07142b0dfe0"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/b739121a7a837336466792d1bf69a07142b0dfe0"}]},"branch":"refs/heads/master"},"d4182bb31e765acd298be1184f4453e6e02ac5a0":{"kind":"NO_CHANGE","_number":3,"created":"2026-07-21 18:27:12.000000000","uploader":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"ref":"refs/changes/06/998206/3","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-helm","ref":"refs/changes/06/998206/3","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/06/998206/3 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/06/998206/3 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/06/998206/3 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-helm refs/changes/06/998206/3"}}},"commit":{"parents":[{"commit":"d03dd061a8112c468e2f6529cb0663873f96b50f","subject":"Merge \"Change 2026.1-ubuntu_jammy to 2026.1-ubuntu_noble\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/d03dd061a8112c468e2f6529cb0663873f96b50f"}]}],"author":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-07-21 18:21:48.000000000","tz":-300},"committer":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-07-21 18:27:11.000000000","tz":-300},"subject":"deploy-env: fix silent MetalLB IPAddressPool loss","message":"deploy-env: fix silent MetalLB IPAddressPool loss\n\nThe \"Create MetalLB address pool\" task applies the IPAddressPool\nand then the L2Advertisement in one shell block without `set -e`.\nRight after MetalLB is installed its validating webhook is\nintermittently unreachable (\"failed calling webhook\nipaddresspoolvalidationwebhook.metallb.io: ... context deadline\nexceeded\"), so the IPAddressPool apply fails. Without `set -e` the\nblock continues, applies the L2Advertisement (which succeeds), and\nthe block exit code is that of the last command (0). The task\u0027s\n`until metallb_pool_result.rc \u003d\u003d 0` passes on the first attempt and\nthe `retries: 6` loop never re-runs, leaving the cluster with an\nL2Advertisement but no IPAddressPool.\n\nWith no address pool MetalLB cannot assign LoadBalancer IPs, so the\nEnvoy gateway Service stays \u003cpending\u003e. Because *.openstack-helm.org\nis statically mapped to the expected gateway IP, every public\nendpoint (keystone first) becomes unreachable and deploys fail much\nlater with a keystone /v3/auth/tokens request timeout. This is\nintermittent per environment and has caused the rotating ~1/3 gate\njob failures.\n\nAdd `set -e` so a failed IPAddressPool apply fails the task and the\nexisting retry loop waits for the webhook to become reachable, after\nwhich both resources apply successfully.\n\nChange-Id: I7e155962b7cd82f7d85847a2c70137cfbf5d7020\nSigned-off-by: Vladimir Kozhukalov \u003ckozhukalov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/d4182bb31e765acd298be1184f4453e6e02ac5a0"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/d4182bb31e765acd298be1184f4453e6e02ac5a0"}]},"branch":"refs/heads/master"},"46fb913f1b158998d215abdde3126ae54a8de7c0":{"kind":"REWORK","_number":4,"created":"2026-07-21 19:22:41.000000000","uploader":{"_account_id":3009,"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","username":"kozhukalov"},"ref":"refs/changes/06/998206/4","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/openstack-helm","ref":"refs/changes/06/998206/4","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/06/998206/4 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/06/998206/4 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/openstack-helm refs/changes/06/998206/4 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/openstack-helm refs/changes/06/998206/4"}}},"commit":{"parents":[{"commit":"d03dd061a8112c468e2f6529cb0663873f96b50f","subject":"Merge \"Change 2026.1-ubuntu_jammy to 2026.1-ubuntu_noble\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/d03dd061a8112c468e2f6529cb0663873f96b50f"}]}],"author":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-07-21 18:21:48.000000000","tz":-300},"committer":{"name":"Vladimir Kozhukalov","email":"kozhukalov@gmail.com","date":"2026-07-21 19:22:23.000000000","tz":-300},"subject":"deploy: survive transient admission-webhook races in CI","message":"deploy: survive transient admission-webhook races in CI\n\nCI deploys intermittently fail because Kubernetes admission\nwebhooks are briefly unreachable right after their controller is\ninstalled. Two spots did not tolerate this; both are fixed here.\n\n1) MetalLB IPAddressPool silently lost (roles/deploy-env)\nThe \"Create MetalLB address pool\" task applies the IPAddressPool\nand then the L2Advertisement in one shell block without `set -e`.\nWhen the MetalLB validating webhook is briefly unreachable\n(\"failed calling webhook ipaddresspoolvalidationwebhook.metallb.io\n... context deadline exceeded\") the IPAddressPool apply fails, but\nthe block keeps going, applies the L2Advertisement (which succeeds)\nand exits 0. The task\u0027s `until rc \u003d\u003d 0` then passes on the first\ntry and the `retries: 6` loop never runs, leaving the cluster with\nan L2Advertisement but no IPAddressPool. With no pool MetalLB\ncannot assign LoadBalancer IPs, the Envoy gateway Service stays\n\u003cpending\u003e, and every *.openstack-helm.org endpoint (keystone\nfirst) times out much later in the deploy. Add `set -e` so the\nfailed apply fails the task and the existing retry loop waits for\nthe webhook.\n\n2) Chart install not retried on webhook failure (roles/deploy-charts)\nThe \"Run helm command\" task had no retry, so a transient\ncert-manager webhook failure while a chart creates a Certificate\n(e.g. rabbitmq in the TLS job: \"failed calling webhook\nwebhook.cert-manager.io ... TLS handshake timeout\") hard-failed\nthe whole job. Add a retry loop; helm upgrade --install is\nidempotent so re-running is safe.\n\nChange-Id: I7e155962b7cd82f7d85847a2c70137cfbf5d7020\nSigned-off-by: Vladimir Kozhukalov \u003ckozhukalov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/46fb913f1b158998d215abdde3126ae54a8de7c0"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/openstack-helm/commit/46fb913f1b158998d215abdde3126ae54a8de7c0"}]},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[{"rule_name":"gerrit~DefaultSubmitRule","status":"CLOSED","labels":[{"label":"Verified","status":"MAY","applied_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}},{"label":"Code-Review","status":"MAY","applied_by":{"_account_id":5890,"name":"Doug Goldstein","email":"cardoe@cardoe.com","username":"cardoe"}},{"label":"Workflow","status":"MAY","applied_by":{"_account_id":5890,"name":"Doug Goldstein","email":"cardoe@cardoe.com","username":"cardoe"}}]}],"submit_requirements":[{"name":"Verified","description":"Verified in gate by CI","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Verified\u003dMAX AND -label:Verified\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Verified\u003dMAX"],"failing_atoms":["label:Verified\u003dMIN"],"atom_explanations":{"label:Verified\u003dMAX":"","label:Verified\u003dMIN":""}}},{"name":"Code-Review","description":"Code reviewed by core reviewer","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Code-Review\u003dMAX AND -label:Code-Review\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Code-Review\u003dMAX"],"failing_atoms":["label:Code-Review\u003dMIN"],"atom_explanations":{"label:Code-Review\u003dMAX":"","label:Code-Review\u003dMIN":""}}},{"name":"Workflow","description":"Approved for gate by core reviewer","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Workflow\u003dMAX AND -label:Workflow\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Workflow\u003dMAX"],"failing_atoms":["label:Workflow\u003dMIN"],"atom_explanations":{"label:Workflow\u003dMAX":"","label:Workflow\u003dMIN":""}}}]}
