All skills
openshift avatar

/build-cpo-image

@cfb745e official
by openshiftopenshift/hypershift543 stars
576

Build and push control-plane-operator container image. Auto-applies when testing CPO changes that require deploying to a live cluster.

Use this Skill: https://skilld.dev/gh/openshift/hypershift/build-cpo-image

This session only. Nothing lands on disk.

SKILL.md

≈38 tokens always: the name and description. ≈743 when used: this file.

Build Control-Plane-Operator Image

This skill enables building and pushing custom control-plane-operator (CPO) images for testing changes in a live HyperShift environment.

When to Use This Skill

This skill automatically applies when:

  • You've made changes to code in control-plane-operator/
  • You need to test CPO changes against a live cluster
  • The user asks to build/push a CPO image
  • You need to iterate on CPO fixes with e2e tests

Prerequisites

Source the environment file before using this skill:

source dev/claude-env.sh

Image Registry Configuration

Environment variables from dev/claude-env.sh:

Variable Description
CPO_IMAGE_REPO Container registry for CPO images
RUNTIME Container runtime (podman/docker)

Building the CPO Image

Step 1: Generate a Unique Tag

Use a tag that identifies the change (branch name, feature, or timestamp):

# Option 1: Use branch name
TAG=$(git rev-parse --abbrev-ref HEAD | tr '/' '-')

# Option 2: Use short commit hash
TAG=$(git rev-parse --short HEAD)

# Option 3: Use descriptive name + number for iterations
TAG="feature-name-1"

Step 2: Build the Image

The CPO image uses Dockerfile.control-plane:

$RUNTIME build -f Dockerfile.control-plane --platform linux/amd64 -t $CPO_IMAGE_REPO:$TAG .

Note: The build runs make control-plane-operator and make control-plane-pki-operator inside the container, so you don't need to pre-build locally.

Step 3: Push the Image

$RUNTIME push $CPO_IMAGE_REPO:$TAG

Quick One-Liner

Build and push in one command:

TAG="my-fix-1" && $RUNTIME build -f Dockerfile.control-plane --platform linux/amd64 -t $CPO_IMAGE_REPO:$TAG . && $RUNTIME push $CPO_IMAGE_REPO:$TAG

Iteration Workflow

When iterating on CPO fixes:

  1. Make code changes in control-plane-operator/
  2. Build and push image with incremented tag (e.g., fix-1, fix-2, fix-3)
  3. Run e2e test with new image
  4. Analyze results
  5. Repeat until test passes

What Gets Built

The Dockerfile.control-plane builds:

  • control-plane-operator binary
  • control-plane-pki-operator binary

Both are included in the final image.

Image Labels

The CPO image includes important capability labels that HyperShift uses:

  • io.openshift.hypershift.control-plane-operator-subcommands=true
  • io.openshift.hypershift.control-plane-operator.v2-isdefault=true
  • Various other feature capability labels

Troubleshooting

Build Fails

  • Check that vendored dependencies are up to date: go mod vendor
  • Ensure code compiles locally: make control-plane-operator

Push Fails

  • Verify registry login: $RUNTIME login quay.io
  • Check repository permissions

Image Not Used by Cluster

  • Verify the image tag is correct in e2e flags
  • Check that the image was pushed successfully
  • Ensure the cluster can pull from the registry (public or authenticated)

Source: SKILL.md on GitHub

No alerts3mo3 checks · Risk SAFE
  • Gen Agent Trust Hub3mo

    The skill provides instructions for building and pushing OpenShift Control Plane Operator (CPO) container images using standard container tools (podman/docker) and local environment configuration. No security issues were detected.

  • Socket3mo

    No alerts

  • Snyk3mo

    Risk: LOW · No issues

Signed by skilld at cfb745e. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 8 months ago
  • hypershift
  • container-image
  • openshift
  • control-plane-operator
  • docker
  • podman
  • registry
  • cpo

README badge

README badge for openshift/hypershift/build-cpo-image

Builds and pushes a custom control-plane-operator container image for HyperShift, compiling the control-plane-operator and control-plane-pki-operator binaries inside the container. Use this skill when iterating on CPO code changes that need testing against a live cluster.

Generated from the current SKILL.md.

What environment setup is required before building the CPO image?
Source the dev/claude-env.sh file first, which provides CPO_IMAGE_REPO and RUNTIME environment variables needed for the build and push commands.
Does this skill handle local binary compilation or does the container build it?
The container build handles all compilation. The Dockerfile.control-plane runs make control-plane-operator and make control-plane-pki-operator inside the container, so you don't need to pre-build locally.
What container runtime does this skill support?
Both podman and docker are supported via the RUNTIME environment variable from dev/claude-env.sh.
Can I use this skill to build images for architectures other than amd64?
The documented commands specify --platform linux/amd64. Building for other architectures would require modifying the platform flag, which is not covered in this skill's primary workflow.
What happens if the image push fails?
Check registry login (e.g., podman login quay.io), verify repository permissions, and confirm the cluster can pull from the registry either publicly or with authentication.

Generated from the current SKILL.md. These answers refresh after source changes.