{"id":13618692,"url":"https://github.com/openshift-kni/cnf-features-deploy","last_synced_at":"2026-01-14T20:22:33.862Z","repository":{"id":36958656,"uuid":"232859931","full_name":"openshift-kni/cnf-features-deploy","owner":"openshift-kni","description":"Kustomize configs for installing CNF features and e2e functional tests for verifying feature deployment/integration","archived":false,"fork":false,"pushed_at":"2026-01-12T14:09:13.000Z","size":49462,"stargazers_count":64,"open_issues_count":157,"forks_count":145,"subscribers_count":8,"default_branch":"master","last_synced_at":"2026-01-12T15:41:17.974Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/openshift-kni.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2020-01-09T16:59:54.000Z","updated_at":"2026-01-12T13:46:21.000Z","dependencies_parsed_at":"2023-12-24T21:32:27.893Z","dependency_job_id":"8394fe7f-f335-4fd9-b2ce-b5e155f1b8e9","html_url":"https://github.com/openshift-kni/cnf-features-deploy","commit_stats":null,"previous_names":[],"tags_count":1,"template":false,"template_full_name":null,"purl":"pkg:github/openshift-kni/cnf-features-deploy","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/openshift-kni%2Fcnf-features-deploy","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/openshift-kni%2Fcnf-features-deploy/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/openshift-kni%2Fcnf-features-deploy/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/openshift-kni%2Fcnf-features-deploy/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/openshift-kni","download_url":"https://codeload.github.com/openshift-kni/cnf-features-deploy/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/openshift-kni%2Fcnf-features-deploy/sbom","scorecard":{"id":476132,"data":{"date":"2025-08-11","repo":{"name":"github.com/openshift-kni/cnf-features-deploy","commit":"e132e468e409577d84e5094eb6d55f0c85a86e0d"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":5.5,"checks":[{"name":"Code-Review","score":10,"reason":"all changesets reviewed","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Maintained","score":10,"reason":"30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Dangerous-Workflow","score":-1,"reason":"no workflows found","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Token-Permissions","score":-1,"reason":"No tokens found","details":null,"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: Apache License 2.0: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Branch-Protection","score":-1,"reason":"internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration","details":null,"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"Security-Policy","score":10,"reason":"security policy file detected","details":["Info: security policy file detected: github.com/openshift-kni/.github/SECURITY.md:1","Info: Found linked content: github.com/openshift-kni/.github/SECURITY.md:1","Info: Found disclosure, vulnerability, and/or timelines in security policy: github.com/openshift-kni/.github/SECURITY.md:1","Info: Found text in security policy: github.com/openshift-kni/.github/SECURITY.md:1"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"SAST","score":0,"reason":"SAST tool is not run on all commits -- score normalized to 0","details":["Warn: 0 commits out of 30 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}},{"name":"Vulnerabilities","score":0,"reason":"10 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: GO-2022-0635","Warn: Project is vulnerable to: GO-2022-0646","Warn: Project is vulnerable to: GO-2022-0451 / GHSA-hj57-j5cw-2mwp","Warn: Project is vulnerable to: GO-2025-3487 / GHSA-hcg3-q754-cr77","Warn: Project is vulnerable to: GO-2025-3503 / GHSA-qxp5-gwg8-xv66","Warn: Project is vulnerable to: GO-2025-3595 / GHSA-vvgc-356p-c3xw","Warn: Project is vulnerable to: GO-2025-3488 / GHSA-6v2p-p543-phr9","Warn: Project is vulnerable to: GO-2024-2687 / GHSA-4v7x-pqxf-cx7m","Warn: Project is vulnerable to: GO-2024-3333","Warn: Project is vulnerable to: GO-2024-2611 / GHSA-8r3f-844c-mc37"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}},{"name":"Pinned-Dependencies","score":0,"reason":"dependency not pinned by hash detected -- score normalized to 0","details":["Info: Possibly incomplete results: error parsing shell code: reached $ without matching [ with ]: hack/common.sh:0","Info: Possibly incomplete results: error parsing shell code: reached $ without matching [ with ]: hack/run-functests.sh:0","Info: Possibly incomplete results: error parsing shell code: \"foo(\" must be followed by ): vendor/sigs.k8s.io/controller-runtime/Makefile:0","Warn: containerImage not pinned by hash: cnf-tests/.konflux/Dockerfile:3","Warn: containerImage not pinned by hash: cnf-tests/.konflux/Dockerfile:5","Warn: containerImage not pinned by hash: cnf-tests/.konflux/Dockerfile:14","Warn: containerImage not pinned by hash: cnf-tests/.konflux/Dockerfile:23","Warn: containerImage not pinned by hash: cnf-tests/.konflux/Dockerfile:32","Warn: containerImage not pinned by hash: cnf-tests/.konflux/Dockerfile:43","Warn: containerImage not pinned by hash: cnf-tests/.konflux/Dockerfile:48","Warn: containerImage not pinned by hash: cnf-tests/Dockerfile.openshift:2","Warn: containerImage not pinned by hash: cnf-tests/Dockerfile.openshift:17","Warn: containerImage not pinned by hash: cnf-tests/Dockerfile.openshift:32","Warn: containerImage not pinned by hash: cnf-tests/Dockerfile.openshift:46","Warn: containerImage not pinned by hash: cnf-tests/Dockerfile.openshift:60","Warn: containerImage not pinned by hash: cnf-tests/Dockerfile.openshift:76","Warn: containerImage not pinned by hash: cnf-tests/Dockerfile.openshift:82","Warn: containerImage not pinned by hash: cnf-tests/Dockerfile.openshift:96","Warn: containerImage not pinned by hash: cnf-tests/Dockerfile.openshift:99","Warn: containerImage not pinned by hash: openshift-ci/Dockerfile.tools:2: pin your Docker image by updating quay.io/fedora/fedora:41 to quay.io/fedora/fedora:41@sha256:3b490e19a2006f0f0fcb6aa576209f3c65891fffc1d5f80459496b732f0fdc1d","Warn: containerImage not pinned by hash: tools/buildingsctp/src/Dockerfile.sctp:1","Warn: containerImage not pinned by hash: tools/buildingsctp/src/Dockerfile.sctp:20: pin your Docker image by updating registry.access.redhat.com/ubi8/ubi to registry.access.redhat.com/ubi8/ubi@sha256:4f0a4e4deb450583408a06165e92a4dcd4f0740a23815f3326fc5c97ee9ca768","Warn: containerImage not pinned by hash: tools/oot-driver/Dockerfile.source:1: pin your Docker image by updating registry.access.redhat.com/ubi8:latest to registry.access.redhat.com/ubi8:latest@sha256:4f0a4e4deb450583408a06165e92a4dcd4f0740a23815f3326fc5c97ee9ca768","Warn: containerImage not pinned by hash: tools/oot-driver/charts/dpdk-kni-driver-0.0.1/Dockerfile-driver.SRO:4","Warn: containerImage not pinned by hash: tools/oot-driver/charts/dpdk-kni-driver-0.0.1/Dockerfile-driver.SRO:60","Warn: containerImage not pinned by hash: tools/oot-driver/charts/iavf-driver-0.0.1/Dockerfile-driver.SRO:4","Warn: containerImage not pinned by hash: tools/oot-driver/charts/iavf-driver-0.0.1/Dockerfile-driver.SRO:50","Warn: containerImage not pinned by hash: tools/oot-driver/charts/ice-driver-0.0.1/Dockerfile-driver.SRO:4","Warn: containerImage not pinned by hash: tools/oot-driver/charts/ice-driver-0.0.1/Dockerfile-driver.SRO:50","Warn: containerImage not pinned by hash: tools/s2i-dpdk/Dockerfile:1: pin your Docker image by updating quay.io/centos/centos:stream9 to quay.io/centos/centos:stream9@sha256:11e44d30c45661567009402629a7eeb3579739957fe3827d469a353d0fe1801f","Warn: goCommand not pinned by hash: openshift-ci/Dockerfile.tools:26-38","Warn: pipCommand not pinned by hash: tools/oot-driver/charts/dpdk-kni-driver-0.0.1/Dockerfile-driver.SRO:47","Warn: goCommand not pinned by hash: cnf-tests/hack/lint.sh:8","Warn: goCommand not pinned by hash: vendor/github.com/json-iterator/go/build.sh:10","Warn: goCommand not pinned by hash: ztp/tools/pgt2acmpg/vendor/github.com/json-iterator/go/build.sh:10","Info:   2 out of   6 goCommand dependencies pinned","Info:   0 out of   1 pipCommand dependencies pinned","Info:   0 out of  27 containerImage dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}}]},"last_synced_at":"2025-08-19T15:21:24.017Z","repository_id":36958656,"created_at":"2025-08-19T15:21:24.017Z","updated_at":"2025-08-19T15:21:24.017Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":28434427,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-01-14T18:57:19.464Z","status":"ssl_error","status_checked_at":"2026-01-14T18:52:48.501Z","response_time":107,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.6:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-01T21:00:29.170Z","updated_at":"2026-01-14T20:22:33.851Z","avatar_url":"https://github.com/openshift-kni.png","language":"Go","funding_links":[],"categories":["NF Development Projects"],"sub_categories":["Blogs and Websites"],"readme":"# Overview\n\nThis repo contains example kustomize configs used to installed openshift features required for CNF workloads and a e2e functional test suite used to verify CNF related features.\n\n## Contributing kustomize configs\n\nAll kustomize configs should be entirely declarative in nature. This means no bash plugin modules performing imperative tasks. Features should be installed simply by posting manifests to the cluster. After posting manifests, determining when the cluster has converged on those manifests successully should be observable.\n\n## Usage\n\n### Prerequisites\n\n- You need a running OCP 4.4 (or later) cluster and a valid KUBECONFIG.\n- You need at least one node with the `node-role.kubernetes.io/worker-cnf=\"\"` label and a `MachineConfigPool` matching `worker-cnf` machine configurations\n- You need to install `jq` (a command line tool for parsing JSON) on the local machine.\n\nYou can run `make setup-test-cluster` to have the first two (or the first in case of only one) workers labeled as `worker-cnf` and to have the `MachineConfigPool` created.\n\n### Configuring\n\nAll the Makefile rules depend on two environment variable, either for deploying, waiting and choosing what tests to run.\n\n##### FEATURES\n\ne.g. `FEATURES=\"sctp ptp sriov\"`, drives what features are going to be deployed using kustomize, and what tests are going to be run.\n\nThe current default values is `\"sctp performance\"`\n\n- optionally set `FOCUS_TESTS` variable also to run specific tests.\n\ne.g. `FEATURES=\"sriov\" FOCUS_TESTS=\"operator.Generic.SriovNetworkNodePolicy.Resource.Injector operator.Generic.SriovNetworkNodePolicy.VF.flags\"`, drives sriov deployment using kustomize, and two sriov tests are going to be run.\n\n##### FEATURES_ENVIRONMENT\n\ni.e. `FEATURES_ENVIRONMENT=demo` determines the kustomization layer that will be used to deploy the choosen features.\n\nThe current default value is `e2e-gcp`\n\n### Deployment\n\nFor each feature choosen via `FEATURES` we expect to have a layer either in [feature-configs/deploy](feature-configs/deploy) or in [feature-configs/$FEATURES_ENVIRONMENT](feature-configs/demo).\n\n- run `FEATURES_ENVIRONMENT=demo make feature-deploy`.  \n  This will try to apply all manifests in a loop until all deployments succeeded, or until it runs into a timeout.\n- optionally run `FEATURES_ENVIRONMENT=demo make feature-wait` to be notified of when the features are deployed.\n\n### Testing\n\nWe expect to have a section of [the test suite](cnf-tests/testsuites/e2esuite/test_suite_test.go) named after each feature we want to test (for example [sctp](cnf-tests/testsuites/e2esuite/sctp.go) named after the sctp feature).\n\nExternal tests are consumed as dependencies and ran as part of this same suite.\n\n### origin-tests\n\nVerifies behavior of an OCP cluster by running remote tests against the cluster API that exercise functionality.\nThese tests may be disruptive.\n\nRunning a dockerized version of origin-tests from [quay.io/openshift/origin-tests](https://quay.io/openshift/origin-tests).\nThe full test suite can be found at [https://github.com/openshift/openshift-tests](https://github.com/openshift/openshift-tests).\n\n- run `ORIGIN_TESTS_FILTER=openshift/conformance/serial make origin-tests`.\n  The current default values is `openshift/conformance/parallel`\n\n- optionally set `ORIGIN_TESTS_IN_DISCONNECTED_ENVIRONMENT=true` and `ORIGIN_TESTS_REPOSITORY=test.repository.com:5000/origin-tests` to run origin-tests in a disconnected environment.\n\n- optionally run `ORIGIN_TESTS_REPOSITORY=test.repository.com:5000/origin-tests make mirror-origin-tests` to mirror all the required test images to a container image repository.\n\n- optionally run `ORIGIN_TESTS_REPOSITORY=test.repository.com:5000/origin-tests make origin-tests-disconnected-environment` to mirror all the required test images to a container image repository and source required test images from your repository when running origin-tests in a disconnected environment.\n\n### Custom RPMs\nThe custom RPMs utility allows to install RPMs from an external source on an OCP node.\nRPMS_SRC (RPMs download source URL) must be provided.\nREMOVE_PACKAGES should be set when installing RT kernel RPMs to override the installed kernel packages (no need to set it when replacing a regular kernel with a different regular kernel or a RT kernel with a different RT kernel).\nRPMS_NODE_ROLE is optional and defaults to `node-role.kubernetes.io/worker`.\n\n- run `RPMS_SRC=\"http://test.download.com/example1.rpm http://test.download.com/example2.rpm\" make custom-rpms`.  \n  This will install all the RPMs listed in RPMS_SRC on the selected nodes.\n\n- optionally run `RPMS_SRC=\"http://test.download.com/rt-kernel-package1.rpm http://test.download.com/rt-kernel-package1.rpm http://test.download.com/rt-kernel-package3.rpm\" REMOVE_PACKAGES=\"kernel kernel-core kernel-modules kernel-modules-extra\" make custom-rpms` to install RT kernel RPMs listed in RPMS_SRC on the selected nodes and override the installed kernel packages listed in REMOVE_PACKAGES.\n\n### The CNF-Tests Container (Latency Tests)\n\nA dockerized version of the Node Tuning Operator latency test suite available at [quay.io/openshift-kni/cnf-tests](https://quay.io/openshift-kni/cnf-tests).\nFor more details on how to use it, please check the [official docs](https://docs.openshift.com/container-platform/4.14/scalability_and_performance/cnf-performing-platform-verification-latency-tests.html).\n\n### The Conformance tests\n\nThe conformance test suites verify that the operators we maintain are working properly on CNF enabled cluster. Nightly upstream ci jobs are using those tests, triggered from the openshift/release ci-operator [link](https://github.com/openshift/release/blob/master/ci-operator/step-registry/telco5g/cnf/tests/telco5g-cnf-tests-commands.sh). For more details, see [cnf-tests/README.md](cnf-tests/README.md)\n\n### Zero-Touch Provisioning for RAN\n\nZero-touch provisioning enables a gitops-based flow for deploying and configuring OpenShift for RAN applications.\n\nFor an overview, see [ztp/gitops-subscriptions/argocd/README.md](ztp/gitops-subscriptions/argocd/README.md)\n\n## Release Branching\n\nThis repository follows the same version numbering and release branching schedule as OpenShift: https://docs.ci.openshift.org/docs/architecture/branching/\n\n### Branching\n\n1. Before creating a new `release-x.y` branch ensure the new `x.y`version is reflected in the following sources:\n   - `cnf-tests/Dockerfile.openshift`:\n     1. Check image tags used.\n     2. `OCP_VERSION`.\n\n   - `cnf-tests/.konflux/Dockerfile`:\n     1. Check image tags used.\n     2. `OCP_VERSION`.\n     3. Check the tags in the strings of `RUN sed` commands.\n\n    - `cnf-tests/mirror/images.json`\n    - `cnf-tests/testsuites/pkg/images/images.go`\n    - `hack/common.sh`\n\n2. If any sources require updates, create a pull request against the master branch with the necessary changes. Merge this PR before proceeding to the next steps.\n2. Create a new `release-x.y` branch and push it to git\n3. Advance the CI configuration in openshift/release to create new lanes for the release branch and move the master along to the next release version number\n    - Example: https://github.com/openshift/release/pull/26172\n4. Change the ZTP templates examples label `du-profile: latest` under [gitops-subscriptions/argocd/example](https://github.com/openshift-kni/cnf-features-deploy/tree/master/ztp/gitops-subscriptions/argocd/example) to match the branch release-x.y\n    - PGT Example: https://github.com/openshift-kni/cnf-features-deploy/pull/1063\n    - SiteConfig Example: https://github.com/openshift-kni/cnf-features-deploy/pull/1064\n5. Pin all midstream branches to the new release branch, and create new midstream branches for the next release\n   - [cnf-tests](https://code.engineering.redhat.com/gerrit/admin/repos/cnf-tests)\n   - [ztp-site-generate](https://code.engineering.redhat.com/gerrit/admin/repos/ztp-site-generate)\n6. Create a PR to the master branch updating the references from the first step to version `x.y+1`","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fopenshift-kni%2Fcnf-features-deploy","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fopenshift-kni%2Fcnf-features-deploy","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fopenshift-kni%2Fcnf-features-deploy/lists"}