Repository navigation
backport: deploy backport-branch automation workflows to active backport branches #19262
Description
Activity
- addedTeam:EcosystemPackages Ecosystem team [elastic/ecosystem]Packages Ecosystem team [elastic/ecosystem]
on May 28, 2026 infra-vault-gh-plugin-prod commented
on May 28, 2026 More actionsPinging @elastic/ecosystem (Team:Ecosystem)
github-actions commented
on May 28, 2026 on May 28, 2026 – with GitHub ActionsContributorMore actionstl;dr: This should be sequenced as a post-
#19215migration, but it is not executable yet from currentmainbecause.backports.ymlis missing (no authoritative active-branch list) and the sync workflow file is not present in this checkout.Recommendation
Proceed with this issue, but gate execution on two prerequisites:
#19215is merged and the finalsync-backport-changelogfile set is known.- An authoritative active-branch inventory exists (the issue currently points to
.backports.yml, which is not in currentmain).
Then run a one-time per-branch PR migration (not force-push), label each PR
automation, and explicitly trigger CI for workflow-only changes.Findings
- No backport/changelog workflow exists in current checkout (so there is nothing to deploy yet from this branch state).
- Command:
ls .github/workflows | grep -E 'backport|changelog' || true(no output)
- Command:
.backports.ymldoes not exist in current checkout, so the acceptance criterion “branches listed in.backports.yml” cannot be executed yet.- Command:
test -f .backports.yml && echo present || echo missing→missing
- Command:
- There are many existing backport branches that would need targeting once inventory is defined.
- Command:
git ls-remote --heads origin 'backport-*' | wc -l→58
- Command:
- New branches are already covered by existing branch-creation flow, because the script copies workflows from
mainwhen creating backport branches..buildkite/scripts/backport_branch.sh:206-211
- Current docs still require manual changelog sync to main, which aligns with why
#19215/#19262are needed.docs/extend/developer-workflow-support-old-package.md:117-121
- Migration PRs touching only
.github/workflows/can skip default Buildkite PR CI unless manually triggered..buildkite/pull-requests.json:16,26,38
Verification
$ ls .github/workflows | grep -E "backport|changelog" || true $ test -f .backports.yml && echo present || echo missing missing $ git ls-remote --heads origin "backport-*" | wc -l 58 $ grep -nE "skip_ci_on_only_changed|always_require_ci_on_changed|\^\.github/workflows/" .buildkite/pull-requests.json 16: "skip_ci_on_only_changed": [ 26: "^.github/workflows/", 38: "always_require_ci_on_changed": []
Detailed Action Plan
-
Finalize dependencies from
#19215- Confirm exact migration payload (at minimum
.github/workflows/sync-backport-changelog.yml, plus any invoked scripts/actions). - Source:
#19262explicitly defers exact file set to#19215final implementation.
- Confirm exact migration payload (at minimum
-
Establish active branch source of truth
- If
.backports.ymlis intended, land/populate it first. - If another source is now canonical, update
#19262acceptance criteria to reference it explicitly.
- If
-
Generate one PR per active backport branch
- For each active branch, create a migration branch based on that backport branch.
- Copy the approved file set from
main. - Open PR targeting the backport branch.
- Apply
automationlabel at PR creation.
-
Prevent silent CI gaps for workflow-only PRs
- Because
.github/workflows/-only changes can skip default Buildkite PR CI (.buildkite/pull-requests.json:26), run the required PR checks explicitly (e.g., manual trigger policy used by the team).
- Because
-
Roll out and verify
- Merge migration PRs.
- Push a harmless test commit to at least one migrated backport branch to confirm
sync-backport-changelog.ymlis picked up from branch context.
-
Future-proof file propagation
- Add/maintain a small manifest of “files required on every backport branch” and use it both for branch creation and migration reruns.
Related Items
Type Link Relevance Issue #19262 This migration issue Issue #19215 Defines sync-backport-changelog workflow and dependency payload Issue #19214 Adjacent auto-backport/post-backport workflows; automationlabel behaviorIssue #19016 Umbrella backport automation effort PR #19104 Landed helper/docs groundwork for backport flow File .buildkite/scripts/backport_branch.sh:90-106Existing package name→path resolution helper File .buildkite/scripts/backport_branch.sh:206-211New backport branches copy .github/workflowsfrommainFile .buildkite/pull-requests.json:16,26,38Workflow-only changes can skip default Buildkite PR CI File docs/extend/developer-workflow-support-old-package.md:117-121Manual changelog sync step still documented Note
🔒 Integrity filter blocked 5 items
The following items were blocked because they don't meet the GitHub integrity level.
- #19024
search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved". - #17641
search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved". - #14306
search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved". - #10895
search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved". - #19171
pull_request_read: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
To allow these resources, lower
min-integrityin your GitHub frontmatter:tools: github: min-integrity: approved # merged | approved | unapproved | none
What is this? | From workflow: Issue Triage
Give us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.
@mrodm @jsoriano The blockers are both closed, is this issue ready to work on in next sprint?
@juliaElastic Yes, this could be done as part of the next sprint. We will need to check if all the CI scripts should be updated, maybe there are some backport branches that could have the CI pipeline broken now.
It could be worth also picking up #19213 in the same sprint; it's unblocked too.
Reacted by Julia BardiIt would be better to wait for this PR to be merged #19930 before starting with this issue
It also needs to be checked if it is needed to sync other changes from other backport workflows or scripts and mage targets used in the workflows. If so, it could be done at the same time.
post-backport-branch.ymlworkflow (to be introduced in #19214) has the same failure mode described here, just via a different trigger. It usespull_request: openedtargetingbackport-*, and non-pull_request_targetevents resolve the workflow definition from a merge of the PR's head and base branches — not frommain. Since the head branch (auto-backport/<package>-<major.minor>-<sha>) is always cut directly from the backport branch, and neither branch touches.github/workflows/, the file effectively has to already exist on the backport branch for GitHub to schedule the workflow at all. Existing active branches predate #19214, so they'd hit the same silent no-op this issue was written to fix forsync-backport-changelog.yml.Same happens once this issue #19686 would be fixed. It would require the scripts and mage targets to be present in the backport branches that were already created.
Given that, I think it would be better to update this issue related to sync scripts, workflows and mage targets instead of filing a separate follow-up issue later. If agreed, I'll broaden the title to something like
backport: deploy backport-branch automation workflows to active backport branchesand update the issue description to includepost-backport-branch.ymlin the migration scope. cc @elastic/ecosystem @bturquetDoing so, this issue would be blocked by #19214 and #19686 .
- changed the title
[-]backport: deploy sync-backport-changelog workflow to active backport branches[/-][+]backport: deploy backport-branch automation workflows to active backport branches[/+]on Jul 8, 2026 Talked offline with @teresaromero
Updated the title and description to describe that it should also be taken into account the changes in #19214 and #19686 for this sync for the backport branches that are already created. And mark it as blocked.
cc @bturquet
Active backport branches
Generated from
.backports.ymlon 2026-07-30. Includes branches wherearchived: falseandmaintained_untilis null or not yet passed.aws
-
backport-aws-7.3 -
backport-aws-7.2 -
backport-aws-7.1[backport-aws-7.1] Sync CI configuration with main branch #21150 -
backport-aws-7.0 -
backport-aws-6.x(maintained until 2027-01-16) [backport-aws-6.x] Sync CI configuration with main branch #20414 -
backport-aws-3.17[backport-aws-3.17] Sync CI configuration with main branch #20472 -
backport-aws-3.13[backport-aws-3.13] Sync CI configuration with main branch #21310 -
backport-aws-2.30[backport-aws-2.30] Sync CI configuration with main branch #21316 -
backport-aws-2.25[backport-aws-2.25] Sync CI configuration with main branch #21318 -
backport-aws-2.24[backport-aws-2.24] Sync CI configuration with main branch #21321 -
backport-aws-1.51[backport-aws-1.51] Sync CI configuration with main branch #21323- Required to apply some specific changes due to its using an old elastic-package version and it does not recognize some parameters
--coverage-formatparameter- restore the
elastic-package stack shellinitcommand - use docker-compose instead of docker compose, and version v2.17.2
- fix .github/CODEOWNERS for system (data streams)
- Required to apply some specific changes due to its using an old elastic-package version and it does not recognize some parameters
cloud_asset_inventory
-
backport-cloud_asset_inventory-1.4[backport-cloud_asset_inventory-1.4] Sync CI configuration with main branch #21191 -
backport-cloud_asset_inventory-1.3[backport-cloud_asset_inventory-1.3] Sync CI configuration with main branch #21192 -
backport-cloud_asset_inventory-1.1[backport-cloud_asset_inventory-1.1] Sync CI configuration with main branch #21193
cloud_security_posture
-
backport-cloud_security_posture-3.2[backport-cloud_security_posture-3.2] Sync CI configuration with main branch #20513 -
backport-cloud_security_posture-3.1[backport-cloud_security_posture-3.1] Sync CI configuration with main branch #20514 -
backport-cloud_security_posture-3.0[backport-cloud_security_posture-3.0] Sync CI configuration with main branch #21195 -
backport-cloud_security_posture-2.0[backport-cloud_security_posture-2.0] Sync CI configuration with main branch #21277 -
backport-cloud_security_posture-1.13[backport-cloud_security_posture-1.13] Sync CI configuration with main branch #21276 -
backport-cloud_security_posture-1.10[backport-cloud_security_posture-1.10] Sync CI configuration with main branch #21275 -
backport-cloud_security_posture-1.9[backport-cloud_security_posture-1.9] Sync CI configuration with main branch #21274- Required to apply some specific changes due to its using an old elastic-package version and it does not recognize some parameters
- fix .github/CODEOWNERS for aws, gcp, prometheus and system (data streams)
- Required to apply some specific changes due to its using an old elastic-package version and it does not recognize some parameters
-
backport-cloud_security_posture-1.8[backport-cloud_security_posture-1.8] Sync CI configuration with main branch #21273- Required to apply some specific changes due to its using an old elastic-package version and it does not recognize some parameters
- fix .github/CODEOWNERS for aws, gcp, prometheus and system (data streams)
- Required to apply some specific changes due to its using an old elastic-package version and it does not recognize some parameters
-
backport-cloud_security_posture-1.7[backport-cloud_security_posture-1.7] Sync CI configuration with main branch #21259- Required to apply some specific changes due to its using an old elastic-package version and it does not recognize some parameters
--coverage-formatparameter- use docker-compose instead of docker compose, and version v2.17.2
- fix .github/CODEOWNERS for aws, gcp, prometheus and system (data streams)
- Required to apply some specific changes due to its using an old elastic-package version and it does not recognize some parameters
-
backport-cloud_security_posture-1.5[backport-cloud_security_posture-1.5] Sync CI configuration with main branch #21245- Required to apply some specific changes due to its using an old elastic-package version and it does not recognize some parameters
--coverage-formatparameter- use docker-compose instead of docker compose, and version v2.17.2
- fix .github/CODEOWNERS for aws, gcp and system (data streams)
- Required to apply some specific changes due to its using an old elastic-package version and it does not recognize some parameters
-
backport-cloud_security_posture-1.4[backport-cloud_security_posture-1.4] Sync CI configuration with main branch #21241- Required to apply some specific changes due to its using an old elastic-package version and it does not recognize some parameters
--coverage-formatparameter- licenses environment variable required to be removed
- restore the
elastic-package stack shellinitcommand - use docker-compose instead of docker compose, and version v2.17.2
- fix script to detect whether or not stack is running
- Required to apply some specific changes due to its using an old elastic-package version and it does not recognize some parameters
-
backport-cloud_security_posture-1.3[backport-cloud_security_posture-1.3] Sync CI configuration with main branch #21235- Required to apply some specific changes due to its using an old elastic-package version and it does not recognize some parameters
--coverage-formatparameter- licenses environment variable required to be removed
- restore the
elastic-package stack shellinitcommand - use docker-compose instead of docker compose, and version v2.17.2
- fix script to detect whether or not stack is running
- Required to apply some specific changes due to its using an old elastic-package version and it does not recognize some parameters
-
backport-cloud_security_posture-1.2[backport-cloud_security_posture-1.2] Sync CI configuration with main branch #21234- Required to apply some specific changes due to its using an old elastic-package version and it does not recognize some parameters
--coverage-formatparameter- licenses environment variable required to be removed
- restore the
elastic-package stack shellinitcommand - use docker-compose instead of docker compose, and version v2.17.2
- fix script to detect whether or not stack is running
- Required to apply some specific changes due to its using an old elastic-package version and it does not recognize some parameters
-
backport-cloud_security_posture-1.1[backport-cloud_security_posture-1.1] Sync CI configuration with main branch #21233- Required to apply some specific changes due to its using an old elastic-package version and it does not recognize some parameters
--coverage-formatparameter- licenses environment variable required to be removed
- restore the
elastic-package stack shellinitcommand - use docker-compose instead of docker compose, and version v2.17.2
- fix script to detect whether or not stack is running
- Required to apply some specific changes due to its using an old elastic-package version and it does not recognize some parameters
-
backport-cloud_security_posture-1.0[backport-cloud_security_posture-1.0] Sync CI configuration with main branch #21194- Required to apply some specific changes due to its using an old elastic-package version and it does not recognize some parameters
--coverage-formatparameter- licenses environment variable required to be removed
- restore the
elastic-package stack shellinitcommand - use docker-compose instead of docker compose, and version v2.17.2
- fix script to detect whether or not stack is running
- Required to apply some specific changes due to its using an old elastic-package version and it does not recognize some parameters
crowdstrike
-
backport-crowdstrike-1.52[backport-crowdstrike-1.52] Sync CI configuration with main branch #21302 -
backport-crowdstrike-1.46[backport-crowdstrike-1.46] Sync CI configuration with main branch #21307
elastic_agent
-
backport-elastic_agent-2.5[backport-elastic_agent-2.5] Sync CI configuration with main branch #21189
gcp
-
backport-gcp-2.22[backport-gcp-2.22] Sync CI configuration with main branch #20555- Required to apply some specific changes due to its using an old elastic-package version and it does not recognize some parameters
--coverage-formatparameter- restore the
elastic-package stack shellinitcommand - use docker-compose instead of docker compose, and version v2.17.2
- fix script to detect whether or not stack is running
- Remove unused script [backport-gcp-2.22] Remove unused script file #21196
- Required to apply some specific changes due to its using an old elastic-package version and it does not recognize some parameters
google_workspace
-
backport-google_workspace-3.0[backport-google_workspace-3.0] Sync CI configuration with main branch #21168
kubernetes
-
backport-kubernetes-1.83[backport-kubernetes-1.83] Sync CI configuration with main branch #20430 -
backport-kubernetes-1.62[backport-kubernetes-1.62] Sync CI configuration with main branch #20434 -
backport-kubernetes-1.39[backport-kubernetes-1.39] Sync CI configuration with main branch #20542- Required to apply some specific changes due to its using an old elastic-package version and it does not recognize some parameters
--coverage-formatparameter- licenses environment variable required to be removed
- restore the
elastic-package stack shellinitcommand
- PR to fix some issues related to docker and elastic-package fix: restore with_docker_compose and detect legacy snapshot.yml for kubernetes-1.39 backport branch #21152
- Remove environment variable for publishing [backport-kubernetes-1.39] Remove ELASTIC_PACKAGE_REPOSITORY_LICENSE from publish pipeline #21197
- Required to apply some specific changes due to its using an old elastic-package version and it does not recognize some parameters
security_detection_engine
-
backport-security_detection_engine-9.4[backport-security_detection_engine-9.4] Sync CI configuration with main branch #20416 -
backport-security_detection_engine-9.3[backport-security_detection_engine-9.3] Sync CI configuration with main branch #20419 -
backport-security_detection_engine-9.2Set as archived [backport_branch]: copy .gitignore and preserve K8S_VERSION/KIND_VERSION #20432 -
backport-security_detection_engine-8.19[backport-security_detection_engine-8.19] Sync CI configuration with main branch #20426
sql
-
backport-sql-0.6[backport-sql-0.6] Sync CI configuration with main branch #21155
synthetics
-
backport-synthetics-1.0[synthetics-1.0] Sync CI configuration with main branch #21171- Required to apply some specific changes due to its using an old elastic-package version and it does not recognize some parameters
--coverage-formatparameter- restore the
elastic-package stack shellinitcommand - use docker-compose instead of docker compose, and version v2.17.2
- fix script to detect whether or not stack is running
- fix codeowners (data streams) for aws, gcp and system packages (copied from main).
- Required to apply some specific changes due to its using an old elastic-package version and it does not recognize some parameters
tenable_io
-
backport-tenable_io-3.10[backport-tenable_io-3.10] Sync CI configuration with main branch #21173
ti_abusech
-
backport-ti_abusech-2.6[backport-ti_abusech-2.6] Sync CI configuration with main branch #21176
wiz
-
backport-wiz-1.8[backport-wiz-1.8] Sync CI configuration with main branch #21188
Skipped:
backport-apm-8.15,backport-aws-7.15.0,backport-elastic_package_registry-0.2, and all archivedsecurity_detection_enginebranches (8.6 through 9.1 except 8.19).-
Created PRs to fix some issues found while deploying files into backport branches:
While syncing the new CI configuration into old backport branches I found several errors caused by mismatch of go versions and failures while running dependencies that were updated.
Trying to find a solution to keep the backport tool as much separated as possible , so it is easy to copy into old backport branches.
Trying to find a solution to keep the backport tool as much separated as possible , so it is easy to copy into old backport branches.
Created this PR #20556 that extracts the code necessary for backport automation into its own CLI binary at
cmd/backportwith its own go.mod. That will allow to copy that folder safely to other backport branches, and it will not update thego.modfrom the root of the working copy.Related PR to update the checklist comment #20605 to include more information for developers
Given the current branches that should be updated, there are some of these branches that their packages require to run Terraform for their tests.
One of the latest changes required to fix in elsatic-package was elastic/elastic-package#3876 . The Terraform Dockerfile required to be updated to fix the package names for google-cloud sdk.
This change should be backported to the backport branches that reuqire Terraform:
BRANCH PACKAGE ELASTIC-PACKAGE TERRAFORM -------------------------------------------------- ---------------------- ---------------------- -------- backport-aws-7.1 aws 0.126.1 yes (26 files) backport-aws-6.x aws 0.125.0 yes (26 files) backport-aws-3.17 aws 0.114.0 yes (26 files) backport-aws-3.13 aws 0.113.0 yes (26 files) backport-aws-2.30 aws 0.106.0 yes (26 files) backport-aws-2.25 aws 0.104.0 yes (26 files) backport-aws-2.24 aws 0.103.0 yes (26 files) backport-aws-1.51 aws 0.85.0 yes (4 files) backport-crowdstrike-1.52 crowdstrike 0.109.1 yes (3 files) backport-crowdstrike-1.46 crowdstrike 0.107.1 yes (3 files)- backport-aws-7.1 already fixed [aws] Add Instance/Pod IAM Role option to Setup Access selector (7.1.x) #21046 (using v0.126.1)
- backport-aws-6.x to be fixed in [aws] Add mandatory tags to system test terraform (backport #20698) #20973 (using v0.126.1)
All the other backport branches would not be easy to use the latest elastic-package version because they are too old and there could be unexpected changes. I'd try if possible to create new patch versions via backport/hotfixes branches.
EDIT:
And it would be needed to add the required labels in the terraform resources too.
Example for crowdstrike: #20706Reacted by Baptiste TurquetThis PR #21243 ensures that the Pull Requests created to keep the changelogs in sync (with the backported versions) have an assignee set.
Backport branches have been updated with all the CI changes to run the backport tool and workflows.
Moreover, the fix related to assigning an user to the sync changelog PR has been also backported to all branches #21243
There is a PR to include the assignment of the user in the Pull Requests created targeting backport branches (
auto-backport.ymlworkflow) #21379
As this workflow just runs on main, it should not be needed to backport it to all the backport branches.Once that last PR #21379 is merged, this issue could be closed.
Closing this issue, since all backport branches updated, and latest fixes found have also been merged into main.
Summary
Several workflows trigger on events scoped to
backport-*branches —sync-backport-changelog.yml(#19215) onpush,post-backport-branch.yml(#19214) onpull_request, and the owner-sync CI check (#19686) onpull_request— and GitHub Actions resolves both event types from the workflow files present on the branches involved in the event, not frommain:pushworkflows execute from the workflow file on the branch being pushed to.pull_request(non-pull_request_target) workflows execute from a merge of the PR's head and base branches.In both cases, if the workflow file is absent from the backport branch, GitHub never schedules it — the automation is silently skipped for every existing branch.
This issue covers the one-time migration to add these workflows (and any scripts they call) to all currently active branches.
This issue is a follow-up to #19215, #19214, and #19686 — existing branches will not benefit from this automation until the migration is run, but each of those issues can ship and be useful for all newly created branches immediately.
Background
The existing backport branches were created from commits that predate the backport automation work. The
backport_branch.shscript already copies the required files when creating new branches, so new branches are covered from day one. The gap is the existing active branches, which need a one-time migration after #19215, #19214, and #19686 ship.There is no workaround via
workflow_runorworkflow_dispatch— bothpushandpull_requestevents on a backport branch will only fire workflows that already exist on that branch (or, forpull_request, on the head branch cut from it).Deliverables
One-time migration script
A script (or documented manual procedure) that, for each active branch in
.backports.yml:.github/workflows/sync-backport-changelog.yml,.github/workflows/post-backport-branch.yml, the owner-sync CI check workflow introduced in Sync package owners between backport branches and main #19686, and any scripts they call (resolved at implementation time from each issue's deliverables) onto the branchautomationThe script can be run once by the ecosystem team after #19215, #19214, and #19686 ship. A migration PR per branch is preferred over a force-push so that the addition goes through CI and review.
Considerations
manifest.yml/CODEOWNERSat backport-PR-creation time lives inbackport_apply.sh, invoked by automation frommain's checkout — it is not branch-resident and needs no migration. The CI check enforcing owner sync on PRs targeting a backport branch is the part that matters here; confirm with Sync package owners between backport branches and main #19686's implementation whether it's a new workflow file (add to the copy list above) or a step added to an already-migrated file (the migration would then need to push updates to previously migrated branches, not just an initial copy).Acceptance criteria
.backports.ymlhavesync-backport-changelog.yml,post-backport-branch.yml, and the owner-sync CI check (and their dependencies) presentsync-backport-changelog.ymlcorrectlyauto-backportPR against any active branch after migration correctly triggerspost-backport-branch.ymlautomationand do not triggerauto-backport.ymlon merge