Skip to content

feat(p3-sandbox-lifecycle-base): timestamp lifecycle logs - #9

Merged
jdavv merged 1 commit into
mainfrom
feat/cert-19793-lifecycle-timestamps
Jul 21, 2026
Merged

jdavv merged 1 commit into
mainfrom
feat/cert-19793-lifecycle-timestamps

Conversation

@jdavv

@jdavv jdavv commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

What

  • Add pinned jq support to p3-sandbox-lifecycle-base.
  • Emit setup-hook output as compact JSON with top-level epoch-millisecond timestamp and message fields.
  • Preserve stdout/stderr separation and the original hook exit status.
  • Keep score-hook output raw so sandbox-operator can continue parsing its top-level output_version report.

Why

CERT-19793 implements part of CERT-19730: lifecycle pod logs need application timestamps so Datadog can attribute provisioning activity accurately.

How to review

  • Check run_timestamped stream and exit-status handling.
  • Confirm setup output is timestamped while the score script remains unwrapped.
  • Confirm missing and invalid hook errors remain nonzero and are emitted as timestamped JSON.

Testing

  • devbox run -- make lint
  • Built the image for linux/amd64.
  • Local smoke test: setup stdout/stderr were timestamped independently.
  • Local smoke test: setup exit 37 propagated without false success messages.
  • Local smoke test: the raw score report remained parseable between timestamped lifecycle messages.
  • Staging OKE test with sc1000001 version 20260721.main-2843552-29833433104-1: 24/24 setup lines were timestamped JSON, the score Job succeeded, and sandbox-operator recorded a successful five-check score result. Full logs are attached to CERT-19793 comments 116042 and 116043.

The image changelog and v1.1.0 tag will be generated through the repository release procedure after merge.

- Added jq to the base image and updated the description to reflect the new runtime dependency.
- Switched the entrypoint to Bash and wrapped setup hook execution so stdout and stderr were emitted as structured millisecond timestamps.
- Kept the score hook output unwrapped so sandbox-operator parsing still consumed the raw report.

Signed-off-by: Jean-Luc Davern <jdavern@linuxfoundation.org>
@jdavv

jdavv commented Jul 21, 2026

Copy link
Copy Markdown
Contributor Author

Release verification

The lifecycle image itself passed the available build and runtime checks:

  • The successful build (images/p3-sandbox-lifecycle-base) job published both linux/amd64 and linux/arm64 under immutable tag dev-feat-cert-19793-lifecycle-timestamps-18251c8.
  • Published manifest digest: sha256:69ee88f499fb939b3cf22e9d73369c4424bb5e7a973bb2939040d1d712b31c82.
  • Local smoke tests confirmed timestamped setup stdout/stderr, setup failure-code propagation, and unmodified score output.
  • Staging sandbox SC1000001 completed setup and score jobs successfully; the operator parsed the score report. Evidence is recorded on CERT-19793.

Repository CI exceptions

Two repository-level workflow defects prevent a clean aggregate status and are unrelated to this diff:

  1. PR checks run 29854040579 failed before creating jobs because .github/workflows/pr-checks.yml calls a reusable workflow that GitHub cannot find: LF-Certification/reusable-github-workflows/.github/workflows/pr-title-lint.yml@v0.
  2. On the branch's first push, the change detector treated --json as its base ref when github.event.before was all zeroes, then fell back to all tracked images. I canceled dev build run 29854012909 after the lifecycle image job succeeded to avoid unnecessary builds.

Proceeding with the lifecycle release based on the successful image job plus local and staging evidence, per the release decision.

@jdavv
jdavv merged commit a558fa3 into main Jul 21, 2026
13 of 14 checks passed
@jdavv
jdavv deleted the feat/cert-19793-lifecycle-timestamps branch July 21, 2026 17:52
@jdavv

jdavv commented Jul 21, 2026

Copy link
Copy Markdown
Contributor Author

Released

p3-sandbox-lifecycle-base-v1.1.0 is published.

  • Release workflow 29854893574: all five jobs passed.
  • GHCR manifest digest: sha256:eb7b706190f2272d527a1e23c6e73195aa3095fff95a49753f4701d534da47f4.
  • v1.1.0, v1.1, v1, and latest resolve to that digest with linux/amd64 and linux/arm64 manifests.
  • A digest-pinned runtime smoke test confirmed timestamped setup output, raw score output, and exact setup failure-code propagation (37).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant