Skip to content

feat(test): ui e2e testing, w/ pr cluster - #1756

Draft
davdhacs wants to merge 10 commits into
masterfrom
rox-29520-ui-testing-verifyprcluster
Draft

feat(test): ui e2e testing, w/ pr cluster#1756
davdhacs wants to merge 10 commits into
masterfrom
rox-29520-ui-testing-verifyprcluster

Conversation

@davdhacs

Copy link
Copy Markdown
Contributor

verify the pr cluster deploy auth fails for cypress

@davdhacs
davdhacs requested review from a team and rhacs-bot as code ownersJanuary 7, 2026 20:39
@rhacs-bot

Copy link
Copy Markdown
Contributor

A single node development cluster (infra-pr-1756) was allocated in production infra for this PR.

CI will attempt to deploy quay.io/rhacs-eng/infra-server: to it.

🔌 You can connect to this cluster with:

gcloud container clusters get-credentials infra-pr-1756 --zone us-central1-a --project acs-team-temp-dev

🛠️ And pull infractl from the deployed dev infra-server with:

nohup kubectl -n infra port-forward svc/infra-server-service 8443:8443 &
make pull-infractl-from-dev-server

🚲 You can then use the dev infra instance e.g.:

bin/infractl -k -e localhost:8443 whoami

⚠️Any clusters that you start using your dev infra instance should have a lifespan shorter then the development cluster instance. Otherwise they will not be destroyed when the dev infra instance ceases to exist when the development cluster is deleted.⚠️

Further Development

☕ If you make changes, you can commit and push and CI will take care of updating the development cluster.

🚀 If you only modify configuration (chart/infra-server/configuration) or templates (chart/infra-server/{static,templates}), you can get a faster update with:

make helm-deploy

Logs

Logs for the development infra depending on your @redhat.com authuser:

Or:

kubectl -n infra logs -l app=infra-server --tail=1 -f

@davdhacs
davdhacs marked this pull request as draft January 7, 2026 22:04
@davdhacs
davdhacsforce-pushed the rox-29520-ui-testing-verifyprcluster branch 4 times, most recently from 322676b to 9cfde1dCompareJanuary 19, 2026 17:21
This commit enables UI E2E tests to run against ephemeral GKE clusters
in GitHub Actions, similar to how Go E2E tests work.
Changes:
1. **TEST_MODE deployment support**:
- Fix Helm template conditional in secrets.yaml to prevent duplicate
secret creation when testMode=true
- Generate self-signed certificates at deployment time for TEST_MODE
- Delete and recreate secrets to force correct template application
- Add test-mode-values.yaml to explicitly set testMode=true
2. **Session secret handling**:
- Generate random session secrets for PR cluster deployments
- Pass session secret from deploy job to UI E2E test job via outputs
- Update Cypress commands to read SESSION_SECRET from environment
- Update Makefile to generate and display session secret for local dev
3. **Runtime fixes**:
- Handle invalid GCS credentials gracefully in TEST_MODE
- Add wait for cluster readiness before deployment
4. **Test improvements**:
- Add API error logging to Cypress tests for debugging
- Use dynamic session secrets instead of hardcoded local-dev secret
- Run UI E2E tests before Go E2E tests (UI tests are faster)
- Go E2E tests use port-forward approach like PR 1735
This allows UI E2E tests to authenticate and run against PR clusters
that don't have production secrets, enabling automated UI testing in CI.
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
@davdhacs
davdhacsforce-pushed the rox-29520-ui-testing-verifyprcluster branch from 9cfde1d to 9149c97CompareJanuary 19, 2026 18:55
davdhacsand others added 2 commits January 19, 2026 14:32
Add 'if: success() || failure()' to ui-e2e-test-pr-cluster job so it runs
even when deploy-and-test fails (due to Go e2e test failures). This allows
us to:
- See Go e2e failures as RED in GitHub UI (shows real status)
- Still run and test UI E2E functionality independently
- Get results for both test suites
Don't create invalid empty Signer struct in TEST_MODE. Instead, leave
gcsSigner as nil which is the proper way to indicate GCS signing is
disabled.
The previous approach of creating &signer.Signer{} was causing workflow
creation failures in go e2e tests.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@davdhacs@rhacs-bot@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
feat(test): ui e2e testing, w/ pr cluster by davdhacs · Pull Request #1756 · stackrox/infra · GitHub
Skip to content

feat(test): ui e2e testing, w/ pr cluster - #1756

Draft
davdhacs wants to merge 10 commits into
masterfrom
rox-29520-ui-testing-verifyprcluster
Draft

feat(test): ui e2e testing, w/ pr cluster#1756
davdhacs wants to merge 10 commits into
masterfrom
rox-29520-ui-testing-verifyprcluster

Conversation

@davdhacs

Copy link
Copy Markdown
Contributor

verify the pr cluster deploy auth fails for cypress

@davdhacs
davdhacs requested review from a team and rhacs-bot as code ownersJanuary 7, 2026 20:39
@rhacs-bot

Copy link
Copy Markdown
Contributor

A single node development cluster (infra-pr-1756) was allocated in production infra for this PR.

CI will attempt to deploy quay.io/rhacs-eng/infra-server: to it.

🔌 You can connect to this cluster with:

gcloud container clusters get-credentials infra-pr-1756 --zone us-central1-a --project acs-team-temp-dev

🛠️ And pull infractl from the deployed dev infra-server with:

nohup kubectl -n infra port-forward svc/infra-server-service 8443:8443 &
make pull-infractl-from-dev-server

🚲 You can then use the dev infra instance e.g.:

bin/infractl -k -e localhost:8443 whoami

⚠️Any clusters that you start using your dev infra instance should have a lifespan shorter then the development cluster instance. Otherwise they will not be destroyed when the dev infra instance ceases to exist when the development cluster is deleted.⚠️

Further Development

☕ If you make changes, you can commit and push and CI will take care of updating the development cluster.

🚀 If you only modify configuration (chart/infra-server/configuration) or templates (chart/infra-server/{static,templates}), you can get a faster update with:

make helm-deploy

Logs

Logs for the development infra depending on your @redhat.com authuser:

Or:

kubectl -n infra logs -l app=infra-server --tail=1 -f

@davdhacs
davdhacs marked this pull request as draft January 7, 2026 22:04
@davdhacs
davdhacsforce-pushed the rox-29520-ui-testing-verifyprcluster branch 4 times, most recently from 322676b to 9cfde1dCompareJanuary 19, 2026 17:21
This commit enables UI E2E tests to run against ephemeral GKE clusters
in GitHub Actions, similar to how Go E2E tests work.
Changes:
1. **TEST_MODE deployment support**:
- Fix Helm template conditional in secrets.yaml to prevent duplicate
secret creation when testMode=true
- Generate self-signed certificates at deployment time for TEST_MODE
- Delete and recreate secrets to force correct template application
- Add test-mode-values.yaml to explicitly set testMode=true
2. **Session secret handling**:
- Generate random session secrets for PR cluster deployments
- Pass session secret from deploy job to UI E2E test job via outputs
- Update Cypress commands to read SESSION_SECRET from environment
- Update Makefile to generate and display session secret for local dev
3. **Runtime fixes**:
- Handle invalid GCS credentials gracefully in TEST_MODE
- Add wait for cluster readiness before deployment
4. **Test improvements**:
- Add API error logging to Cypress tests for debugging
- Use dynamic session secrets instead of hardcoded local-dev secret
- Run UI E2E tests before Go E2E tests (UI tests are faster)
- Go E2E tests use port-forward approach like PR 1735
This allows UI E2E tests to authenticate and run against PR clusters
that don't have production secrets, enabling automated UI testing in CI.
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
@davdhacs
davdhacsforce-pushed the rox-29520-ui-testing-verifyprcluster branch from 9cfde1d to 9149c97CompareJanuary 19, 2026 18:55
davdhacsand others added 2 commits January 19, 2026 14:32
Add 'if: success() || failure()' to ui-e2e-test-pr-cluster job so it runs
even when deploy-and-test fails (due to Go e2e test failures). This allows
us to:
- See Go e2e failures as RED in GitHub UI (shows real status)
- Still run and test UI E2E functionality independently
- Get results for both test suites
Don't create invalid empty Signer struct in TEST_MODE. Instead, leave
gcsSigner as nil which is the proper way to indicate GCS signing is
disabled.
The previous approach of creating &signer.Signer{} was causing workflow
creation failures in go e2e tests.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@davdhacs@rhacs-bot@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' feat(test): ui e2e testing, w/ pr cluster by davdhacs · Pull Request #1756 · stackrox/infra · GitHub
Skip to content

feat(test): ui e2e testing, w/ pr cluster - #1756

Draft
davdhacs wants to merge 10 commits into
masterfrom
rox-29520-ui-testing-verifyprcluster
Draft

feat(test): ui e2e testing, w/ pr cluster#1756
davdhacs wants to merge 10 commits into
masterfrom
rox-29520-ui-testing-verifyprcluster

Conversation

@davdhacs

Copy link
Copy Markdown
Contributor

verify the pr cluster deploy auth fails for cypress

@davdhacs
davdhacs requested review from a team and rhacs-bot as code ownersJanuary 7, 2026 20:39
@rhacs-bot

Copy link
Copy Markdown
Contributor

A single node development cluster (infra-pr-1756) was allocated in production infra for this PR.

CI will attempt to deploy quay.io/rhacs-eng/infra-server: to it.

🔌 You can connect to this cluster with:

gcloud container clusters get-credentials infra-pr-1756 --zone us-central1-a --project acs-team-temp-dev

🛠️ And pull infractl from the deployed dev infra-server with:

nohup kubectl -n infra port-forward svc/infra-server-service 8443:8443 &
make pull-infractl-from-dev-server

🚲 You can then use the dev infra instance e.g.:

bin/infractl -k -e localhost:8443 whoami

⚠️Any clusters that you start using your dev infra instance should have a lifespan shorter then the development cluster instance. Otherwise they will not be destroyed when the dev infra instance ceases to exist when the development cluster is deleted.⚠️

Further Development

☕ If you make changes, you can commit and push and CI will take care of updating the development cluster.

🚀 If you only modify configuration (chart/infra-server/configuration) or templates (chart/infra-server/{static,templates}), you can get a faster update with:

make helm-deploy

Logs

Logs for the development infra depending on your @redhat.com authuser:

Or:

kubectl -n infra logs -l app=infra-server --tail=1 -f

@davdhacs
davdhacs marked this pull request as draft January 7, 2026 22:04
@davdhacs
davdhacsforce-pushed the rox-29520-ui-testing-verifyprcluster branch 4 times, most recently from 322676b to 9cfde1dCompareJanuary 19, 2026 17:21
This commit enables UI E2E tests to run against ephemeral GKE clusters
in GitHub Actions, similar to how Go E2E tests work.
Changes:
1. **TEST_MODE deployment support**:
- Fix Helm template conditional in secrets.yaml to prevent duplicate
secret creation when testMode=true
- Generate self-signed certificates at deployment time for TEST_MODE
- Delete and recreate secrets to force correct template application
- Add test-mode-values.yaml to explicitly set testMode=true
2. **Session secret handling**:
- Generate random session secrets for PR cluster deployments
- Pass session secret from deploy job to UI E2E test job via outputs
- Update Cypress commands to read SESSION_SECRET from environment
- Update Makefile to generate and display session secret for local dev
3. **Runtime fixes**:
- Handle invalid GCS credentials gracefully in TEST_MODE
- Add wait for cluster readiness before deployment
4. **Test improvements**:
- Add API error logging to Cypress tests for debugging
- Use dynamic session secrets instead of hardcoded local-dev secret
- Run UI E2E tests before Go E2E tests (UI tests are faster)
- Go E2E tests use port-forward approach like PR 1735
This allows UI E2E tests to authenticate and run against PR clusters
that don't have production secrets, enabling automated UI testing in CI.
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
@davdhacs
davdhacsforce-pushed the rox-29520-ui-testing-verifyprcluster branch from 9cfde1d to 9149c97CompareJanuary 19, 2026 18:55
davdhacsand others added 2 commits January 19, 2026 14:32
Add 'if: success() || failure()' to ui-e2e-test-pr-cluster job so it runs
even when deploy-and-test fails (due to Go e2e test failures). This allows
us to:
- See Go e2e failures as RED in GitHub UI (shows real status)
- Still run and test UI E2E functionality independently
- Get results for both test suites
Don't create invalid empty Signer struct in TEST_MODE. Instead, leave
gcsSigner as nil which is the proper way to indicate GCS signing is
disabled.
The previous approach of creating &signer.Signer{} was causing workflow
creation failures in go e2e tests.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@davdhacs@rhacs-bot@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' feat(test): ui e2e testing, w/ pr cluster by davdhacs · Pull Request #1756 · stackrox/infra · GitHub
Skip to content

feat(test): ui e2e testing, w/ pr cluster - #1756

Draft
davdhacs wants to merge 10 commits into
masterfrom
rox-29520-ui-testing-verifyprcluster
Draft

feat(test): ui e2e testing, w/ pr cluster#1756
davdhacs wants to merge 10 commits into
masterfrom
rox-29520-ui-testing-verifyprcluster

Conversation

@davdhacs

Copy link
Copy Markdown
Contributor

verify the pr cluster deploy auth fails for cypress

@davdhacs
davdhacs requested review from a team and rhacs-bot as code ownersJanuary 7, 2026 20:39
@rhacs-bot

Copy link
Copy Markdown
Contributor

A single node development cluster (infra-pr-1756) was allocated in production infra for this PR.

CI will attempt to deploy quay.io/rhacs-eng/infra-server: to it.

🔌 You can connect to this cluster with:

gcloud container clusters get-credentials infra-pr-1756 --zone us-central1-a --project acs-team-temp-dev

🛠️ And pull infractl from the deployed dev infra-server with:

nohup kubectl -n infra port-forward svc/infra-server-service 8443:8443 &
make pull-infractl-from-dev-server

🚲 You can then use the dev infra instance e.g.:

bin/infractl -k -e localhost:8443 whoami

⚠️Any clusters that you start using your dev infra instance should have a lifespan shorter then the development cluster instance. Otherwise they will not be destroyed when the dev infra instance ceases to exist when the development cluster is deleted.⚠️

Further Development

☕ If you make changes, you can commit and push and CI will take care of updating the development cluster.

🚀 If you only modify configuration (chart/infra-server/configuration) or templates (chart/infra-server/{static,templates}), you can get a faster update with:

make helm-deploy

Logs

Logs for the development infra depending on your @redhat.com authuser:

Or:

kubectl -n infra logs -l app=infra-server --tail=1 -f

@davdhacs
davdhacs marked this pull request as draft January 7, 2026 22:04
@davdhacs
davdhacsforce-pushed the rox-29520-ui-testing-verifyprcluster branch 4 times, most recently from 322676b to 9cfde1dCompareJanuary 19, 2026 17:21
This commit enables UI E2E tests to run against ephemeral GKE clusters
in GitHub Actions, similar to how Go E2E tests work.
Changes:
1. **TEST_MODE deployment support**:
- Fix Helm template conditional in secrets.yaml to prevent duplicate
secret creation when testMode=true
- Generate self-signed certificates at deployment time for TEST_MODE
- Delete and recreate secrets to force correct template application
- Add test-mode-values.yaml to explicitly set testMode=true
2. **Session secret handling**:
- Generate random session secrets for PR cluster deployments
- Pass session secret from deploy job to UI E2E test job via outputs
- Update Cypress commands to read SESSION_SECRET from environment
- Update Makefile to generate and display session secret for local dev
3. **Runtime fixes**:
- Handle invalid GCS credentials gracefully in TEST_MODE
- Add wait for cluster readiness before deployment
4. **Test improvements**:
- Add API error logging to Cypress tests for debugging
- Use dynamic session secrets instead of hardcoded local-dev secret
- Run UI E2E tests before Go E2E tests (UI tests are faster)
- Go E2E tests use port-forward approach like PR 1735
This allows UI E2E tests to authenticate and run against PR clusters
that don't have production secrets, enabling automated UI testing in CI.
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
@davdhacs
davdhacsforce-pushed the rox-29520-ui-testing-verifyprcluster branch from 9cfde1d to 9149c97CompareJanuary 19, 2026 18:55
davdhacsand others added 2 commits January 19, 2026 14:32
Add 'if: success() || failure()' to ui-e2e-test-pr-cluster job so it runs
even when deploy-and-test fails (due to Go e2e test failures). This allows
us to:
- See Go e2e failures as RED in GitHub UI (shows real status)
- Still run and test UI E2E functionality independently
- Get results for both test suites
Don't create invalid empty Signer struct in TEST_MODE. Instead, leave
gcsSigner as nil which is the proper way to indicate GCS signing is
disabled.
The previous approach of creating &signer.Signer{} was causing workflow
creation failures in go e2e tests.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@davdhacs@rhacs-bot@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' feat(test): ui e2e testing, w/ pr cluster by davdhacs · Pull Request #1756 · stackrox/infra · GitHub
Skip to content

feat(test): ui e2e testing, w/ pr cluster - #1756

Draft
davdhacs wants to merge 10 commits into
masterfrom
rox-29520-ui-testing-verifyprcluster
Draft

feat(test): ui e2e testing, w/ pr cluster#1756
davdhacs wants to merge 10 commits into
masterfrom
rox-29520-ui-testing-verifyprcluster

Conversation

@davdhacs

Copy link
Copy Markdown
Contributor

verify the pr cluster deploy auth fails for cypress

@davdhacs
davdhacs requested review from a team and rhacs-bot as code ownersJanuary 7, 2026 20:39
@rhacs-bot

Copy link
Copy Markdown
Contributor

A single node development cluster (infra-pr-1756) was allocated in production infra for this PR.

CI will attempt to deploy quay.io/rhacs-eng/infra-server: to it.

🔌 You can connect to this cluster with:

gcloud container clusters get-credentials infra-pr-1756 --zone us-central1-a --project acs-team-temp-dev

🛠️ And pull infractl from the deployed dev infra-server with:

nohup kubectl -n infra port-forward svc/infra-server-service 8443:8443 &
make pull-infractl-from-dev-server

🚲 You can then use the dev infra instance e.g.:

bin/infractl -k -e localhost:8443 whoami

⚠️Any clusters that you start using your dev infra instance should have a lifespan shorter then the development cluster instance. Otherwise they will not be destroyed when the dev infra instance ceases to exist when the development cluster is deleted.⚠️

Further Development

☕ If you make changes, you can commit and push and CI will take care of updating the development cluster.

🚀 If you only modify configuration (chart/infra-server/configuration) or templates (chart/infra-server/{static,templates}), you can get a faster update with:

make helm-deploy

Logs

Logs for the development infra depending on your @redhat.com authuser:

Or:

kubectl -n infra logs -l app=infra-server --tail=1 -f

@davdhacs
davdhacs marked this pull request as draft January 7, 2026 22:04
@davdhacs
davdhacsforce-pushed the rox-29520-ui-testing-verifyprcluster branch 4 times, most recently from 322676b to 9cfde1dCompareJanuary 19, 2026 17:21
This commit enables UI E2E tests to run against ephemeral GKE clusters
in GitHub Actions, similar to how Go E2E tests work.
Changes:
1. **TEST_MODE deployment support**:
- Fix Helm template conditional in secrets.yaml to prevent duplicate
secret creation when testMode=true
- Generate self-signed certificates at deployment time for TEST_MODE
- Delete and recreate secrets to force correct template application
- Add test-mode-values.yaml to explicitly set testMode=true
2. **Session secret handling**:
- Generate random session secrets for PR cluster deployments
- Pass session secret from deploy job to UI E2E test job via outputs
- Update Cypress commands to read SESSION_SECRET from environment
- Update Makefile to generate and display session secret for local dev
3. **Runtime fixes**:
- Handle invalid GCS credentials gracefully in TEST_MODE
- Add wait for cluster readiness before deployment
4. **Test improvements**:
- Add API error logging to Cypress tests for debugging
- Use dynamic session secrets instead of hardcoded local-dev secret
- Run UI E2E tests before Go E2E tests (UI tests are faster)
- Go E2E tests use port-forward approach like PR 1735
This allows UI E2E tests to authenticate and run against PR clusters
that don't have production secrets, enabling automated UI testing in CI.
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
@davdhacs
davdhacsforce-pushed the rox-29520-ui-testing-verifyprcluster branch from 9cfde1d to 9149c97CompareJanuary 19, 2026 18:55
davdhacsand others added 2 commits January 19, 2026 14:32
Add 'if: success() || failure()' to ui-e2e-test-pr-cluster job so it runs
even when deploy-and-test fails (due to Go e2e test failures). This allows
us to:
- See Go e2e failures as RED in GitHub UI (shows real status)
- Still run and test UI E2E functionality independently
- Get results for both test suites
Don't create invalid empty Signer struct in TEST_MODE. Instead, leave
gcsSigner as nil which is the proper way to indicate GCS signing is
disabled.
The previous approach of creating &signer.Signer{} was causing workflow
creation failures in go e2e tests.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@davdhacs@rhacs-bot@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' feat(test): ui e2e testing, w/ pr cluster by davdhacs · Pull Request #1756 · stackrox/infra · GitHub
Skip to content

feat(test): ui e2e testing, w/ pr cluster - #1756

Draft
davdhacs wants to merge 10 commits into
masterfrom
rox-29520-ui-testing-verifyprcluster
Draft

feat(test): ui e2e testing, w/ pr cluster#1756
davdhacs wants to merge 10 commits into
masterfrom
rox-29520-ui-testing-verifyprcluster

Conversation

@davdhacs

Copy link
Copy Markdown
Contributor

verify the pr cluster deploy auth fails for cypress

@davdhacs
davdhacs requested review from a team and rhacs-bot as code ownersJanuary 7, 2026 20:39
@rhacs-bot

Copy link
Copy Markdown
Contributor

A single node development cluster (infra-pr-1756) was allocated in production infra for this PR.

CI will attempt to deploy quay.io/rhacs-eng/infra-server: to it.

🔌 You can connect to this cluster with:

gcloud container clusters get-credentials infra-pr-1756 --zone us-central1-a --project acs-team-temp-dev

🛠️ And pull infractl from the deployed dev infra-server with:

nohup kubectl -n infra port-forward svc/infra-server-service 8443:8443 &
make pull-infractl-from-dev-server

🚲 You can then use the dev infra instance e.g.:

bin/infractl -k -e localhost:8443 whoami

⚠️Any clusters that you start using your dev infra instance should have a lifespan shorter then the development cluster instance. Otherwise they will not be destroyed when the dev infra instance ceases to exist when the development cluster is deleted.⚠️

Further Development

☕ If you make changes, you can commit and push and CI will take care of updating the development cluster.

🚀 If you only modify configuration (chart/infra-server/configuration) or templates (chart/infra-server/{static,templates}), you can get a faster update with:

make helm-deploy

Logs

Logs for the development infra depending on your @redhat.com authuser:

Or:

kubectl -n infra logs -l app=infra-server --tail=1 -f

@davdhacs
davdhacs marked this pull request as draft January 7, 2026 22:04
@davdhacs
davdhacsforce-pushed the rox-29520-ui-testing-verifyprcluster branch 4 times, most recently from 322676b to 9cfde1dCompareJanuary 19, 2026 17:21
This commit enables UI E2E tests to run against ephemeral GKE clusters
in GitHub Actions, similar to how Go E2E tests work.
Changes:
1. **TEST_MODE deployment support**:
- Fix Helm template conditional in secrets.yaml to prevent duplicate
secret creation when testMode=true
- Generate self-signed certificates at deployment time for TEST_MODE
- Delete and recreate secrets to force correct template application
- Add test-mode-values.yaml to explicitly set testMode=true
2. **Session secret handling**:
- Generate random session secrets for PR cluster deployments
- Pass session secret from deploy job to UI E2E test job via outputs
- Update Cypress commands to read SESSION_SECRET from environment
- Update Makefile to generate and display session secret for local dev
3. **Runtime fixes**:
- Handle invalid GCS credentials gracefully in TEST_MODE
- Add wait for cluster readiness before deployment
4. **Test improvements**:
- Add API error logging to Cypress tests for debugging
- Use dynamic session secrets instead of hardcoded local-dev secret
- Run UI E2E tests before Go E2E tests (UI tests are faster)
- Go E2E tests use port-forward approach like PR 1735
This allows UI E2E tests to authenticate and run against PR clusters
that don't have production secrets, enabling automated UI testing in CI.
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
@davdhacs
davdhacsforce-pushed the rox-29520-ui-testing-verifyprcluster branch from 9cfde1d to 9149c97CompareJanuary 19, 2026 18:55
davdhacsand others added 2 commits January 19, 2026 14:32
Add 'if: success() || failure()' to ui-e2e-test-pr-cluster job so it runs
even when deploy-and-test fails (due to Go e2e test failures). This allows
us to:
- See Go e2e failures as RED in GitHub UI (shows real status)
- Still run and test UI E2E functionality independently
- Get results for both test suites
Don't create invalid empty Signer struct in TEST_MODE. Instead, leave
gcsSigner as nil which is the proper way to indicate GCS signing is
disabled.
The previous approach of creating &signer.Signer{} was causing workflow
creation failures in go e2e tests.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@davdhacs@rhacs-bot@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' feat(test): ui e2e testing, w/ pr cluster by davdhacs · Pull Request #1756 · stackrox/infra · GitHub
Skip to content

feat(test): ui e2e testing, w/ pr cluster - #1756

Draft
davdhacs wants to merge 10 commits into
masterfrom
rox-29520-ui-testing-verifyprcluster
Draft

feat(test): ui e2e testing, w/ pr cluster#1756
davdhacs wants to merge 10 commits into
masterfrom
rox-29520-ui-testing-verifyprcluster

Conversation

@davdhacs

Copy link
Copy Markdown
Contributor

verify the pr cluster deploy auth fails for cypress

@davdhacs
davdhacs requested review from a team and rhacs-bot as code ownersJanuary 7, 2026 20:39
@rhacs-bot

Copy link
Copy Markdown
Contributor

A single node development cluster (infra-pr-1756) was allocated in production infra for this PR.

CI will attempt to deploy quay.io/rhacs-eng/infra-server: to it.

🔌 You can connect to this cluster with:

gcloud container clusters get-credentials infra-pr-1756 --zone us-central1-a --project acs-team-temp-dev

🛠️ And pull infractl from the deployed dev infra-server with:

nohup kubectl -n infra port-forward svc/infra-server-service 8443:8443 &
make pull-infractl-from-dev-server

🚲 You can then use the dev infra instance e.g.:

bin/infractl -k -e localhost:8443 whoami

⚠️Any clusters that you start using your dev infra instance should have a lifespan shorter then the development cluster instance. Otherwise they will not be destroyed when the dev infra instance ceases to exist when the development cluster is deleted.⚠️

Further Development

☕ If you make changes, you can commit and push and CI will take care of updating the development cluster.

🚀 If you only modify configuration (chart/infra-server/configuration) or templates (chart/infra-server/{static,templates}), you can get a faster update with:

make helm-deploy

Logs

Logs for the development infra depending on your @redhat.com authuser:

Or:

kubectl -n infra logs -l app=infra-server --tail=1 -f

@davdhacs
davdhacs marked this pull request as draft January 7, 2026 22:04
@davdhacs
davdhacsforce-pushed the rox-29520-ui-testing-verifyprcluster branch 4 times, most recently from 322676b to 9cfde1dCompareJanuary 19, 2026 17:21
This commit enables UI E2E tests to run against ephemeral GKE clusters
in GitHub Actions, similar to how Go E2E tests work.
Changes:
1. **TEST_MODE deployment support**:
- Fix Helm template conditional in secrets.yaml to prevent duplicate
secret creation when testMode=true
- Generate self-signed certificates at deployment time for TEST_MODE
- Delete and recreate secrets to force correct template application
- Add test-mode-values.yaml to explicitly set testMode=true
2. **Session secret handling**:
- Generate random session secrets for PR cluster deployments
- Pass session secret from deploy job to UI E2E test job via outputs
- Update Cypress commands to read SESSION_SECRET from environment
- Update Makefile to generate and display session secret for local dev
3. **Runtime fixes**:
- Handle invalid GCS credentials gracefully in TEST_MODE
- Add wait for cluster readiness before deployment
4. **Test improvements**:
- Add API error logging to Cypress tests for debugging
- Use dynamic session secrets instead of hardcoded local-dev secret
- Run UI E2E tests before Go E2E tests (UI tests are faster)
- Go E2E tests use port-forward approach like PR 1735
This allows UI E2E tests to authenticate and run against PR clusters
that don't have production secrets, enabling automated UI testing in CI.
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
@davdhacs
davdhacsforce-pushed the rox-29520-ui-testing-verifyprcluster branch from 9cfde1d to 9149c97CompareJanuary 19, 2026 18:55
davdhacsand others added 2 commits January 19, 2026 14:32
Add 'if: success() || failure()' to ui-e2e-test-pr-cluster job so it runs
even when deploy-and-test fails (due to Go e2e test failures). This allows
us to:
- See Go e2e failures as RED in GitHub UI (shows real status)
- Still run and test UI E2E functionality independently
- Get results for both test suites
Don't create invalid empty Signer struct in TEST_MODE. Instead, leave
gcsSigner as nil which is the proper way to indicate GCS signing is
disabled.
The previous approach of creating &signer.Signer{} was causing workflow
creation failures in go e2e tests.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@davdhacs@rhacs-bot@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); feat(test): ui e2e testing, w/ pr cluster by davdhacs · Pull Request #1756 · stackrox/infra · GitHub
Skip to content

feat(test): ui e2e testing, w/ pr cluster - #1756

Draft
davdhacs wants to merge 10 commits into
masterfrom
rox-29520-ui-testing-verifyprcluster
Draft

feat(test): ui e2e testing, w/ pr cluster#1756
davdhacs wants to merge 10 commits into
masterfrom
rox-29520-ui-testing-verifyprcluster

Conversation

@davdhacs

Copy link
Copy Markdown
Contributor

verify the pr cluster deploy auth fails for cypress

@davdhacs
davdhacs requested review from a team and rhacs-bot as code ownersJanuary 7, 2026 20:39
@rhacs-bot

Copy link
Copy Markdown
Contributor

A single node development cluster (infra-pr-1756) was allocated in production infra for this PR.

CI will attempt to deploy quay.io/rhacs-eng/infra-server: to it.

🔌 You can connect to this cluster with:

gcloud container clusters get-credentials infra-pr-1756 --zone us-central1-a --project acs-team-temp-dev

🛠️ And pull infractl from the deployed dev infra-server with:

nohup kubectl -n infra port-forward svc/infra-server-service 8443:8443 &
make pull-infractl-from-dev-server

🚲 You can then use the dev infra instance e.g.:

bin/infractl -k -e localhost:8443 whoami

⚠️Any clusters that you start using your dev infra instance should have a lifespan shorter then the development cluster instance. Otherwise they will not be destroyed when the dev infra instance ceases to exist when the development cluster is deleted.⚠️

Further Development

☕ If you make changes, you can commit and push and CI will take care of updating the development cluster.

🚀 If you only modify configuration (chart/infra-server/configuration) or templates (chart/infra-server/{static,templates}), you can get a faster update with:

make helm-deploy

Logs

Logs for the development infra depending on your @redhat.com authuser:

Or:

kubectl -n infra logs -l app=infra-server --tail=1 -f

@davdhacs
davdhacs marked this pull request as draft January 7, 2026 22:04
@davdhacs
davdhacsforce-pushed the rox-29520-ui-testing-verifyprcluster branch 4 times, most recently from 322676b to 9cfde1dCompareJanuary 19, 2026 17:21
This commit enables UI E2E tests to run against ephemeral GKE clusters
in GitHub Actions, similar to how Go E2E tests work.
Changes:
1. **TEST_MODE deployment support**:
- Fix Helm template conditional in secrets.yaml to prevent duplicate
secret creation when testMode=true
- Generate self-signed certificates at deployment time for TEST_MODE
- Delete and recreate secrets to force correct template application
- Add test-mode-values.yaml to explicitly set testMode=true
2. **Session secret handling**:
- Generate random session secrets for PR cluster deployments
- Pass session secret from deploy job to UI E2E test job via outputs
- Update Cypress commands to read SESSION_SECRET from environment
- Update Makefile to generate and display session secret for local dev
3. **Runtime fixes**:
- Handle invalid GCS credentials gracefully in TEST_MODE
- Add wait for cluster readiness before deployment
4. **Test improvements**:
- Add API error logging to Cypress tests for debugging
- Use dynamic session secrets instead of hardcoded local-dev secret
- Run UI E2E tests before Go E2E tests (UI tests are faster)
- Go E2E tests use port-forward approach like PR 1735
This allows UI E2E tests to authenticate and run against PR clusters
that don't have production secrets, enabling automated UI testing in CI.
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
@davdhacs
davdhacsforce-pushed the rox-29520-ui-testing-verifyprcluster branch from 9cfde1d to 9149c97CompareJanuary 19, 2026 18:55
davdhacsand others added 2 commits January 19, 2026 14:32
Add 'if: success() || failure()' to ui-e2e-test-pr-cluster job so it runs
even when deploy-and-test fails (due to Go e2e test failures). This allows
us to:
- See Go e2e failures as RED in GitHub UI (shows real status)
- Still run and test UI E2E functionality independently
- Get results for both test suites
Don't create invalid empty Signer struct in TEST_MODE. Instead, leave
gcsSigner as nil which is the proper way to indicate GCS signing is
disabled.
The previous approach of creating &signer.Signer{} was causing workflow
creation failures in go e2e tests.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@davdhacs@rhacs-bot@claude