Skip to content

chore(e2e): ignore the artifacts the sandbox bringup writes to the repo root - #3891

Merged
Aleksei Sviridkin (lexfrei) merged 1 commit into
mainfrom
chore/ignore-e2e-bringup-artifacts
Aug 18, 2026
Merged

Aleksei Sviridkin (lexfrei) merged 1 commit into
mainfrom
chore/ignore-e2e-bringup-artifacts

Conversation

@lexfrei

@lexfrei Aleksei Sviridkin (lexfrei) commented Aug 18, 2026 •

Copy link
Copy Markdown
Contributor

What this PR does

Adds a .gitignore block for the files hack/e2e-prepare-cluster.bats writes to the repository root when the e2e sandbox is brought up outside CI: the Talos secrets bundle, the rendered machine configs, the kubeconfigs, the boot image and the per-VM srv1..3/ directories.

None of these was matched by anything in .gitignore (git check-ignore answers "not ignored" for every one), so in a tree that once ran the bringup a broad git add stages a credentials bundle -- secrets.yaml holds the cluster's private keys. This came one pre-push check away from landing in a PR once, which is what moved it from a hypothetical to a standing trap worth closing.

All patterns are anchored to the repository root, so files with the same names elsewhere in the tree stay visible to git.

Summary by CodeRabbit

  • Chores
    • Added ignore rules for sensitive Talos cluster files, kubeconfig files, generated machine configurations, boot images, and temporary VM directories.
    • Prevents generated deployment and test artifacts from being accidentally included in version control.

…po root

hack/e2e-prepare-cluster.bats leaves the Talos secrets bundle, the rendered
machine configs, the kubeconfigs, the boot image and the per-VM directories
in the repository root, and nothing in .gitignore matched any of them. In a
tree that once ran the bringup, a broad git add stages a credentials bundle;
this was caught in review once and is a standing trap rather than a one-off.

Assisted-By: Claude <[email protected]>
Signed-off-by: Aleksei Sviridkin <[email protected]>
@github-actions github-actions Bot added area/testing Issues or PRs related to testing (e2e, bats, unit tests) kind/cleanup Categorizes issue or PR as related to cleanup of code, process, or technical debt size/S This PR changes 10-29 lines, ignoring generated files labels Aug 18, 2026
@lexfrei
Aleksei Sviridkin (lexfrei) merged commit ca9a930 into main Aug 18, 2026
9 of 11 checks passed
@lexfrei
Aleksei Sviridkin (lexfrei) deleted the chore/ignore-e2e-bringup-artifacts branch August 18, 2026 04:32
@coderabbitai

coderabbitai Bot commented Aug 18, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 5144f77a-861b-4916-b5e1-ed5b1cb84777

📥 Commits

Reviewing files that changed from the base of the PR and between 974c280 and 6ac97db.

📒 Files selected for processing (1)
  • .gitignore

📝 Walkthrough

Walkthrough

The .gitignore file now excludes Talos cluster secrets, kubeconfig files, rendered machine configuration, boot images, and /srv1/–/srv3/ directories.

Changes

Cluster artifact ignore rules

Layer / File(s) Summary
Add cluster artifact patterns
.gitignore
Added ignore rules for generated cluster credentials, configuration artifacts, boot images, and per-VM directories.

Estimated code review effort: 1 (Trivial) | ~2 minutes

Suggested reviewers: kvaps

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch chore/ignore-e2e-bringup-artifacts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

myasnikovdaniil added a commit that referenced this pull request Sep 24, 2026
…ringup writes to the repo root (#4438)

Backport of #3891 to `release-1.6`.

`hack/e2e-prepare-cluster.bats` on this branch writes the Talos secrets
bundle, machine configs, kubeconfig, boot image and `srv*/` dirs to the
repo root when the sandbox is brought up outside CI, and nothing in
`.gitignore` matches them, so `git add -A` after a local e2e run picks
up `secrets.yaml` with the cluster private keys.
`hack/run-kubernetes-schedulable_test.bats` from #4435 also leaves
`tenantkubeconfig-test-latest-version` in the root on every `make
unit-tests`.

Cherry-picked clean with `-x`, `.gitignore` only.

```release-note
NONE
```
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/testing Issues or PRs related to testing (e2e, bats, unit tests) kind/cleanup Categorizes issue or PR as related to cleanup of code, process, or technical debt size/S This PR changes 10-29 lines, ignoring generated files

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant