| PR | OCPBUGS-100054: Azure Private clusters without external DNS fail to complete |
|---|---|
| URL | github.com/openshift/hypershift/pull/9171 |
| Branch | fix-OCPBUGS-100054 |
| Date | 2026-08-05 |
| Tester | Bryan Cox |
| Platform | Azure self-managed (Private topology) |
| Release | 5.0.0-ec.5 |
| CPO Image | quay.io/rh_ee_brcox/hypershift:OCPBUGS-100054-2026-08-05-1 |
| Cluster | brcox-100054-hc (2 nodes, eastus) |
| Category | Status |
|---|---|
| Scenario 1: Private Cluster Without External DNS | PASS (11/11 checks) |
| Scenario 2: KAS Route Defaulting | PASS (4/4 checks) |
| Scenario 3: CPO External Route Behavior | PASS (3/3 checks) |
| Scenario 4: Private DNS Zone Naming | PASS (2/2 checks) |
| Scenario 5: Guest dns.cluster Config | PASS (3/3 checks) |
| Scenario 6: PublicAndPrivate Regression | PASS (3/3 checks — CI endpoint access transition tests) |
| Scenario 7: Infra Destroy Both Formats | PASS (3/3 checks) |
| Scenario 8: Unit Test Verification | PASS (42/42 tests) |
Unit tests passing: 42/42 across 4 test suites (globalconfig, core, infra, azure CLI)
Scenarios verified: 8/8 — 5 live Private cluster + 1 CI endpoint access transition + 1 unit tests + 1 infra destroy
Cluster version: 5.0.0-ec.5 (Completed at 2026-08-05T12:54:35Z)
Machines: 2/2 Running, RHCOS 9.8, version 5.0.0-ec.5
| Check | Result | Notes |
|---|---|---|
| Azure Private without external DNS provisions | PASS | Scenario 1 — cluster Available=True, all 21 COs healthy |
| KAS defaults to Route for Private topology | PASS | Scenario 2 — all 4 services use Route strategy |
| CPO skips external routes when no hostname | PASS | Scenario 3 — only internal route exists |
| Private DNS zone uses correct naming | PASS | Scenario 4 — {name}.{baseDomain} (no -azurecluster suffix) |
Guest dns.cluster has both zones | PASS | Scenario 5 — publicZone and privateZone both present |
| PublicAndPrivate topology unaffected (unit tests) | PASS | CLI fixture tests pass for all topologies |
| IBMCloud BaseDomain handling preserved | PASS | DNS config test: hcp.Spec.DNS.BaseDomain used directly for IBM |
AWS SharedVPC PrivateZoneIAMRole preserved | PASS | DNS config test: SharedVPC sets PrivateZoneIAMRole |
Non-Private callers pass isPrivate=false | PASS | Unit tests confirm non-Private uses LoadBalancer for KAS |
| Ingress ClusterOperator healthy | PASS | Available=True, Degraded=False, no issues with public zone |
| Condition | Status |
|---|---|
| Available | True |
| Progressing | False |
| Degraded | False |
| AzureInternalLoadBalancerAvailable | True |
| AzurePLSCreated | True |
| AzurePrivateDNSAvailable | True |
| AzurePrivateEndpointAvailable | True |
| AzurePrivateLinkServiceAvailable | True |
| ClusterVersionAvailable | True |
| ClusterVersionSucceeding | True |
| ControlPlaneConnectionAvailable | True |
| DataPlaneConnectionAvailable | True |
| EtcdAvailable | True |
| IgnitionEndpointAvailable | True |
| InfrastructureReady | True |
| KubeAPIServerAvailable | True |
| PlatformCredentialsFound | True |
| ReconciliationActive | True |
| ReconciliationSucceeded | True |
| SupportedHostedCluster | True |
| ValidConfiguration | True |
| ValidHostedControlPlaneConfiguration | True |
| ValidReleaseImage | True |