chore(e2e): ignore the artifacts the sandbox bringup writes to the repo root - #3891
Merged
Aleksei Sviridkin (lexfrei) merged 1 commit intoAug 18, 2026
Merged
Conversation
…po root hack/e2e-prepare-cluster.bats leaves the Talos secrets bundle, the rendered machine configs, the kubeconfigs, the boot image and the per-VM directories in the repository root, and nothing in .gitignore matched any of them. In a tree that once ran the bringup, a broad git add stages a credentials bundle; this was caught in review once and is a standing trap rather than a one-off. Assisted-By: Claude <[email protected]> Signed-off-by: Aleksei Sviridkin <[email protected]>
Aleksei Sviridkin (lexfrei)
requested review from
Andrei Kvapil (kvaps) and
Timofei Larkin (lllamnyp)
as code owners
August 18, 2026 04:32
Aleksei Sviridkin (lexfrei)
deleted the
chore/ignore-e2e-bringup-artifacts
branch
August 18, 2026 04:32
Contributor
|
Caution Review failedThe pull request is closed. ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (1)
📝 WalkthroughWalkthroughThe ChangesCluster artifact ignore rules
Estimated code review effort: 1 (Trivial) | ~2 minutes Suggested reviewers: ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
myasnikovdaniil
added a commit
that referenced
this pull request
Sep 24, 2026
…ringup writes to the repo root (#4438) Backport of #3891 to `release-1.6`. `hack/e2e-prepare-cluster.bats` on this branch writes the Talos secrets bundle, machine configs, kubeconfig, boot image and `srv*/` dirs to the repo root when the sandbox is brought up outside CI, and nothing in `.gitignore` matches them, so `git add -A` after a local e2e run picks up `secrets.yaml` with the cluster private keys. `hack/run-kubernetes-schedulable_test.bats` from #4435 also leaves `tenantkubeconfig-test-latest-version` in the root on every `make unit-tests`. Cherry-picked clean with `-x`, `.gitignore` only. ```release-note NONE ```
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What this PR does
Adds a .gitignore block for the files
hack/e2e-prepare-cluster.batswrites to the repository root when the e2e sandbox is brought up outside CI: the Talos secrets bundle, the rendered machine configs, the kubeconfigs, the boot image and the per-VMsrv1..3/directories.None of these was matched by anything in .gitignore (
git check-ignoreanswers "not ignored" for every one), so in a tree that once ran the bringup a broadgit addstages a credentials bundle --secrets.yamlholds the cluster's private keys. This came one pre-push check away from landing in a PR once, which is what moved it from a hypothetical to a standing trap worth closing.All patterns are anchored to the repository root, so files with the same names elsewhere in the tree stay visible to git.
Summary by CodeRabbit