From 7571f501e27f1c3ee24bce59e3f146a3d5606257 Mon Sep 17 00:00:00 2001 From: Praveen Kumar Shanmugam <58961022+spraveenio@users.noreply.github.com> Date: Wed, 23 Sep 2026 16:00:03 -0700 Subject: [PATCH 1/2] [NO-JIRA] build: resolve kubectl version dynamically via stable.txt (#1681) Replace the hardcoded kubectl pin (v1.36.2) in Dockerfile.build with a dynamic lookup against https://dl.k8s.io/release/stable.txt, matching the pattern already used in Dockerfile and tests/k8s-e2e/Dockerfile.e2e. Plan: docs-internal/knowledge/plans/2026-09-22-bump-kubectl-oc-versions.md Co-authored-by: Claude (cherry picked from commit 8adebb8619c8c306e96bfe2052dd06002afd54a9) --- Dockerfile.build | 3 +- .../2026-09-22-bump-kubectl-oc-versions.md | 47 +++++++++++++++++++ 2 files changed, 49 insertions(+), 1 deletion(-) create mode 100644 docs-internal/knowledge/plans/2026-09-22-bump-kubectl-oc-versions.md diff --git a/Dockerfile.build b/Dockerfile.build index 1dc958ca..6c885f84 100644 --- a/Dockerfile.build +++ b/Dockerfile.build @@ -68,7 +68,8 @@ RUN curl -sSL https://github.com/arttor/helmify/releases/download/v0.4.13/helmif tar -C /usr/local/bin/ -xzf helmify_Linux_x86_64.tar.gz && \ rm helmify_Linux_x86_64.tar.gz -RUN curl -o /usr/local/bin/kubectl -LO 'https://dl.k8s.io/release/v1.36.2/bin/linux/amd64/kubectl' && \ +RUN KUBECTL_VERSION=$(curl -Ls https://dl.k8s.io/release/stable.txt) && \ + curl -o /usr/local/bin/kubectl -LO "https://dl.k8s.io/release/${KUBECTL_VERSION}/bin/linux/amd64/kubectl" && \ chmod +x /usr/local/bin/kubectl ARG INSECURE_REGISTRY diff --git a/docs-internal/knowledge/plans/2026-09-22-bump-kubectl-oc-versions.md b/docs-internal/knowledge/plans/2026-09-22-bump-kubectl-oc-versions.md new file mode 100644 index 00000000..6473269f --- /dev/null +++ b/docs-internal/knowledge/plans/2026-09-22-bump-kubectl-oc-versions.md @@ -0,0 +1,47 @@ +# Make kubectl dynamic (stable.txt) in Dockerfile.build + +- **Date:** 2026-09-22 +- **Author:** spraveenio +- **Related PR(s):** TBD + +## Context + +`Dockerfile.build` had a hardcoded kubectl version (`v1.36.2`), requiring a manual +bump PR every time a new minor release ships. The other Dockerfiles in the repo +already resolve kubectl dynamically via `https://dl.k8s.io/release/stable.txt`, +so `Dockerfile.build` was the only outlier. + +## Approach + +Replace the hardcoded pin with a dynamic lookup at build time: + +```dockerfile +RUN KUBECTL_VERSION=$(curl -Ls https://dl.k8s.io/release/stable.txt) && \ + curl -o /usr/local/bin/kubectl -LO "https://dl.k8s.io/release/${KUBECTL_VERSION}/bin/linux/amd64/kubectl" && \ + chmod +x /usr/local/bin/kubectl +``` + +This matches the pattern already used in `Dockerfile` and `tests/k8s-e2e/Dockerfile.e2e`. + +### Alternatives considered + +- Keep a pin but bump it to current (`v1.37.0`) — rejected; still requires a manual + PR for every upstream kubectl release, with no benefit over dynamic resolution. + +## Scope + +- **In scope:** `Dockerfile.build` kubectl install line. +- **Out of scope:** oc version changes (already dynamic via `ocp/latest`), other + Dockerfiles (already dynamic), Go toolchain updates. + +## Validation + +- `docker build -f Dockerfile.build .` succeeds. +- `kubectl version --client` inside the resulting image reports the current stable release. +- CI Dockerfile lint passes. + +## Risks / Rollback + +- **Risk:** A new upstream kubectl stable release breaks a CI script at the time + `Dockerfile.build` is rebuilt. Low probability; kubectl is backwards-compatible. +- **Rollback:** Revert to a pinned version in `Dockerfile.build`. From 95abb312e3de084b1fcf878b0f6dd888fe32e5ac Mon Sep 17 00:00:00 2001 From: Praveen Kumar Shanmugam <58961022+spraveenio@users.noreply.github.com> Date: Wed, 23 Sep 2026 16:07:59 -0700 Subject: [PATCH 2/2] Delete docs-internal/knowledge/plans/2026-09-22-bump-kubectl-oc-versions.md --- .../2026-09-22-bump-kubectl-oc-versions.md | 47 ------------------- 1 file changed, 47 deletions(-) delete mode 100644 docs-internal/knowledge/plans/2026-09-22-bump-kubectl-oc-versions.md diff --git a/docs-internal/knowledge/plans/2026-09-22-bump-kubectl-oc-versions.md b/docs-internal/knowledge/plans/2026-09-22-bump-kubectl-oc-versions.md deleted file mode 100644 index 6473269f..00000000 --- a/docs-internal/knowledge/plans/2026-09-22-bump-kubectl-oc-versions.md +++ /dev/null @@ -1,47 +0,0 @@ -# Make kubectl dynamic (stable.txt) in Dockerfile.build - -- **Date:** 2026-09-22 -- **Author:** spraveenio -- **Related PR(s):** TBD - -## Context - -`Dockerfile.build` had a hardcoded kubectl version (`v1.36.2`), requiring a manual -bump PR every time a new minor release ships. The other Dockerfiles in the repo -already resolve kubectl dynamically via `https://dl.k8s.io/release/stable.txt`, -so `Dockerfile.build` was the only outlier. - -## Approach - -Replace the hardcoded pin with a dynamic lookup at build time: - -```dockerfile -RUN KUBECTL_VERSION=$(curl -Ls https://dl.k8s.io/release/stable.txt) && \ - curl -o /usr/local/bin/kubectl -LO "https://dl.k8s.io/release/${KUBECTL_VERSION}/bin/linux/amd64/kubectl" && \ - chmod +x /usr/local/bin/kubectl -``` - -This matches the pattern already used in `Dockerfile` and `tests/k8s-e2e/Dockerfile.e2e`. - -### Alternatives considered - -- Keep a pin but bump it to current (`v1.37.0`) — rejected; still requires a manual - PR for every upstream kubectl release, with no benefit over dynamic resolution. - -## Scope - -- **In scope:** `Dockerfile.build` kubectl install line. -- **Out of scope:** oc version changes (already dynamic via `ocp/latest`), other - Dockerfiles (already dynamic), Go toolchain updates. - -## Validation - -- `docker build -f Dockerfile.build .` succeeds. -- `kubectl version --client` inside the resulting image reports the current stable release. -- CI Dockerfile lint passes. - -## Risks / Rollback - -- **Risk:** A new upstream kubectl stable release breaks a CI script at the time - `Dockerfile.build` is rebuilt. Low probability; kubectl is backwards-compatible. -- **Rollback:** Revert to a pinned version in `Dockerfile.build`.