Skip to content

backport: automate archival of expired .backports.yml entries #19264

Description

@mrodm

Summary

Issue #19210 defines the `maintained_until` field and the active-branch logic in `backport_check_active.sh`, but provides no mechanism to act on expired entries. Without this, entries whose `maintained_until` date has passed remain `archived: false` indefinitely and continue to be targeted by `auto-backport.yml` until someone edits the file by hand.

Background

The active-branch logic in `backport_check_active.sh` already treats an entry as inactive when `maintained_until < today`. The missing piece is surfacing that state proactively: today the only way to know an entry has expired is to run the script manually or notice a spurious backport attempt against a dead branch.

As the number of tracked packages and branches grows, silent drift in `.backports.yml` will compound — stale entries accumulate, and the automation silently targets branches that are no longer maintained.

Deliverables

`backports-housekeeping.yml`

A GitHub Actions workflow running on a weekly schedule:

Trigger: `schedule` (weekly, e.g. Monday 09:00 UTC)

Permissions: `contents: write`, `pull-requests: write`

Flow:

  1. Reads `.backports.yml`
  2. Calls `backport_check_active.sh` for each entry with `archived: false`
  3. Collects entries that are inactive solely due to `maintained_until < today` (not already `archived: true`)
  4. If none found: exit silently
  5. Opens a PR setting `archived: true` on each expired entry; PR body lists every affected branch with its `maintained_until` date so the reviewer can confirm the dates are correct before merging
  6. Deduplication: checks for an open PR with head branch `backports/housekeeping` before opening a new one; skips if one exists

The PR is a review gate — a human on `@elastic/ecosystem` confirms before any branch is marked archived, in case a `maintained_until` date was set incorrectly or a support window was extended.

Considerations

  • Dependency on backport: introduce .backports.yml inventory and active-branch check script #19210: requires `backport_check_active.sh` and a populated `.backports.yml` to exist first.
  • Manual archival is still valid: `archived: true` can be set directly in a regular PR at any time (e.g. a package is fully dropped). This workflow only handles the date-driven case.
  • Auto-merge option: if the review gate turns out to be unnecessary friction in practice, a follow-up can enable auto-merge on these PRs. Leaving it as a human-reviewed PR is the safer default.

Acceptance criteria

  • Workflow opens a PR when any `.backports.yml` entry has `maintained_until < today` and `archived: false`
  • PR body identifies each affected branch and its expiry date
  • No duplicate PR is opened on subsequent runs while a housekeeping PR is still open
  • Workflow is a no-op when no entries have expired

Activity

  1. github-actions commented on May 28, 2026

    @github-actions
    Contributor

    TL;DR: this should move forward as the next slice after #19210 lands; the repo currently has no .backports.yml/backport_check_active.sh, so the housekeeping workflow in this issue is currently blocked on that dependency.

    Recommendation

    Implement this as a follow-up to #19210 (not a duplicate), and wire it to the same automation style already used in repo workflows: add .github/workflows/backports-housekeeping.yml with weekly schedule + workflow_dispatch, detect expired non-archived entries, and open/update a single PR from head branch backports/housekeeping.

    Findings

    Evidence from current codebase and issue history
    1. Dependency is explicit in issue set:

      • #19264 states dependency on #19210.
      • #19016 is the parent effort and has related open sub-issues (#19210, #19214, #19215, #19262, #19264).
    2. The required artifacts do not exist yet:

      • glob **/.backports.yml → no matches
      • glob **/backport_check_active.sh → no matches
      • rg -n "maintained_until" (repo) → no matches
    3. Backport process is still manual/Buildkite-driven today:

      • docs/extend/developer-workflow-support-old-package.md:12-15 (manual workflow overview)
      • docs/extend/developer-workflow-support-old-package.md:119 (manual main changelog update)
      • .buildkite/pipeline.backport.yml:20-54 (UI input + branch creation script)
      • .buildkite/scripts/backport_branch.sh:292-297 (checks only if branch exists, no active/expiry logic)
    4. Existing workflow patterns to reuse for this issue:

      • Scheduled workflow shape: .github/workflows/sweep-httpjson-pagination.yml:2-5
      • Job-level write permissions for PR automation: .github/workflows/bump-elastic-stack-version.yml:19-21
      • gh CLI usage pattern in workflows: .github/workflows/docs-edit-automation.yml:29-37, 151-152
    5. There is no existing housekeeping PR/workflow for this:

      • GitHub search is:pr backports-housekeeping → total_count: 0
      • glob .github/workflows/*backport*.yml → no matches

    Verification

    Commands and output
    $ git ls-remote --heads origin 'backport-*' | head -n 10
    ed21ff84b14f166f75524f5196c933cc4069b99a	refs/heads/backport-apm-8.15
    275902537f94d8347bf4c4faf3cea0a5da88a4f5	refs/heads/backport-aws-1.51
    4e8c8f5f466e9115162c1f74c057647ab965d79f	refs/heads/backport-aws-2.24
    8a88b2c60a29542a9943c525948cd0045d2e7435	refs/heads/backport-aws-2.25
    383ea812539d5242a60f8b9ed06762588c348aea	refs/heads/backport-aws-2.30
    50adf104817cf6e6b142e4aaa1999e22fef65d1a	refs/heads/backport-aws-3.13
    efa3658aa5e01e232318d090469a0dcc9a1e97ba	refs/heads/backport-aws-3.17
    2fee549a71fea6ad3428478016e0afdb67a4dcf4	refs/heads/backport-aws-7.15.0
    04c340f4c500a6fd32c30e2c04e3bb8fecbdb1ee	refs/heads/backport-cloud_asset_inventory-1.1
    e73e648943872f464a8a99368542f74617ce2e12	refs/heads/backport-cloud_asset_inventory-1.3
    
    $ glob **/.backports.yml
    No files matched the pattern.
    
    $ glob **/backport_check_active.sh
    No files matched the pattern.
    
    $ rg -n "backport|\.backports\.yml|maintained_until" .github/workflows
    No matches found.
    
    $ github-search_pull_requests "is:pr backports-housekeeping" (elastic/integrations)
    {"total_count":0,"incomplete_results":false}

    Detailed Action Plan

    Implementation steps
    1. Gate on #19210 completion

      • Require .backports.yml and dev/scripts/backport_check_active.sh from #19210 before implementing this issue.
    2. Add workflow file

      • Create .github/workflows/backports-housekeeping.yml with:
        • on.schedule (weekly) + workflow_dispatch (pattern from .github/workflows/sweep-httpjson-pagination.yml:2-5)
        • job permissions contents: write and pull-requests: write (pattern from .github/workflows/bump-elastic-stack-version.yml:19-21)
    3. Detect expired entries

      • Iterate .backports.yml entries where archived: false.
      • For each branch, call dev/scripts/backport_check_active.sh --branch <name> --json.
      • Select only entries inactive because maintained_until < today.
    4. Apply archival edits

      • Update only matching entries to archived: true in .backports.yml.
      • Build PR body table with branch + maintained_until for reviewer verification.
    5. Deduplicate PR creation

      • Before creating PR, check for existing open PR from head backports/housekeeping.
      • If open PR exists: exit successfully with no new PR.
      • If none exists: push branch + open PR (reuse gh workflow usage style seen in .github/workflows/docs-edit-automation.yml:29-37, 151-152).
    6. No-op behavior

      • If no expired entries are found, exit with success and no PR.
    7. Integration sanity check with sibling backport automation

      • Confirm compatibility with #19214/#19215/#19262 assumptions (especially around automation labels and branch naming), so the housekeeping PR does not interfere with auto-backport flows.

    Related Items

    Issues, files, and references
    Type Link Relevance
    Issue #19264 Current triage target
    Issue #19210 Hard dependency: inventory + active check script
    Issue #19016 Parent backport tooling initiative
    Issue #19214 Auto-backport flow that will consume active/inactive logic
    Issue #19215 Backport changelog sync automation
    Issue #19262 Migration of sync workflow to active backport branches
    File docs/extend/developer-workflow-support-old-package.md:12-15 Current manual process
    File docs/extend/developer-workflow-support-old-package.md:119 Manual main-branch changelog update step
    File .buildkite/pipeline.backport.yml:20-54 Current backport branch creation entrypoint
    File .buildkite/scripts/backport_branch.sh:292-297 Existing branch-exists check only
    File .github/workflows/sweep-httpjson-pagination.yml:2-5 Schedule/workflow_dispatch example
    File .github/workflows/bump-elastic-stack-version.yml:19-21 Permissions example for PR automation
    File .github/workflows/docs-edit-automation.yml:29-37 gh CLI usage in CI
    File .github/workflows/docs-edit-automation.yml:151-152 PR comment/interaction pattern

    Note

    🔒 Integrity filter blocked 2 items

    The following items were blocked because they don't meet the GitHub integrity level.

    • #12046 search_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
    • #11984 search_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".

    To allow these resources, lower min-integrity in your GitHub frontmatter:

    tools:
      github:
        min-integrity: approved  # merged | approved | unapproved | none

    What is this? | From workflow: Issue Triage

    Give us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.

  2. self-assigned this
    on Aug 6, 2026
  3. mrodm commented on Aug 6, 2026

    @mrodm
    CollaboratorAuthor

    After tracing the implementation with all the latest changes introduced for backport automation: the maintained_until field is fully integrated into the active-branch logic shared by all backport workflows. Entries with a past maintained_until date are already silently skipped — the original risk of automation targeting stale branches does not exist.

    The remaining deliverable (a weekly (or daily) job to create PRs to set archived: true) adds cosmetic tidiness but no functional value. Not worth the maintenance overhead. Closing as won't do.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Team:EcosystemPackages Ecosystem team [elastic/ecosystem]

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions