Skip to content

Conversation

nammn
Copy link
Collaborator

@nammn nammn commented Sep 1, 2025

Summary

Python environment and version management:

  • The ensure_required_python function in recreate_python_venv.sh now installs a specific, pinned Python version (3.13.7 by default) for consistency across runs, instead of installing the latest version in a major/minor series. It also removes redundant logic and streamlines the installation process.
  • The script now checks for and installs the python3-venv package on Debian/Ubuntu systems before attempting to set up Python with pyenv, improving compatibility on those platforms.

Virtual environment activation and AWS CLI setup:

  • The AWS CLI installation script (setup_aws.sh) has been updated to require and activate the Python venv before installing AWS CLI with pip, ensuring all installations are isolated and reproducible. It also verifies AWS CLI functionality within the venv and reinstalls if necessary.
  • The container authentication configuration script (configure_container_auth.sh) now automatically activates the venv if it exists, which is necessary for AWS CLI usage on IBM architectures.

Proof of Work

  • green ci
  • smoke test run (the test failure is because staging doesn't work - so the images are not build on multi-arch but aws setup is working as shown there. It has been re-run to show it works on the same machine multiple times)

Checklist

  • Have you linked a jira ticket and/or is the ticket in the title?
  • Have you checked whether your jira ticket required DOCSP changes?
  • Have you added changelog file?

@nammn nammn changed the title Fix aws setup 222 fix aws setup for ibm smoke tests Sep 1, 2025
@nammn nammn added the skip-changelog Use this label in Pull Request to not require new changelog entry file label Sep 1, 2025
Copy link

github-actions bot commented Sep 1, 2025

⚠️ (this preview might not be accurate if the PR is not rebased on current master branch)

MCK 1.3.0 Release Notes

New Features

Multi-Architecture Support

We've added comprehensive multi-architecture support for the kubernetes operator. This enhancement enables deployment on IBM Power (ppc64le) and IBM Z (s390x) architectures alongside
existing x86_64 support. Core images (operator, agent, init containers, database, readiness probe) now support multiple architectures. We do not add support IBM and ARM support for Ops-Manager and the init-ops-manager image.

  • MongoDB Agent images have been migrated to new container repository: quay.io/mongodb/mongodb-agent.
    • the agents in the new repository will support the x86-64, ARM64, s390x, and ppc64le architectures. More can be read in the public docs.
    • operator running >=MCK1.3.0 and static cannot use the agent images from the old container repository quay.io/mongodb/mongodb-agent-ubi.
  • quay.io/mongodb/mongodb-agent-ubi should not be used anymore, it's only there for backwards compatibility.

Bug Fixes

  • This change fixes the current complex and difficult-to-maintain architecture for stateful set containers, which relies on an "agent matrix" to map operator and agent versions which led to a sheer amount of images.
  • We solve this by shifting to a 3-container setup. This new design eliminates the need for the operator-version/agent-version matrix by adding one additional container containing all required binaries. This architecture maps to what we already do with the mongodb-database container.
  • Fixed an issue where the readiness probe reported the node as ready even when its authentication mechanism was not in sync with the other nodes, potentially causing premature restarts.

Other Changes

  • Optional permissions for PersistentVolumeClaim moved to a separate role. When managing the operator with Helm it is possible to disable permissions for PersistentVolumeClaim resources by setting operator.enablePVCResize value to false (true by default). When enabled, previously these permissions were part of the primary operator role. With this change, permissions have a separate role.
  • subresourceEnabled Helm value was removed. This setting used to be true by default and made it possible to exclude subresource permissions from the operator role by specifying false as the value. We are removing this configuration option, making the operator roles always have subresource permissions. This setting was introduced as a temporary solution for this OpenShift issue. The issue has since been resolved and the setting is no longer needed.
  • We have deliberately not published the container images for OpsManager versions 7.0.16, 8.0.8, 8.0.9 and 8.0.10 due to a bug in the OpsManager which prevents MCK customers to upgrade their OpsManager deployments to those versions.

@nammn nammn marked this pull request as ready for review September 1, 2025 11:40
@nammn nammn requested a review from a team as a code owner September 1, 2025 11:40
Copy link
Contributor

@lucian-tosa lucian-tosa left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, just one question

@nammn nammn merged commit 34f1910 into master Sep 2, 2025
35 of 38 checks passed
@nammn nammn deleted the fix-aws-setup-222 branch September 2, 2025 08:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
skip-changelog Use this label in Pull Request to not require new changelog entry file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants