Skip to content

[backport-kubernetes-1.83] Sync CI configuration with main branch - #20430

Merged
mrodm merged 6 commits into
elastic:backport-kubernetes-1.83from
mrodm:sync-ci-configuration-kubernetes-1.83
Sep 8, 2026
Merged

mrodm merged 6 commits into
elastic:backport-kubernetes-1.83from
mrodm:sync-ci-configuration-kubernetes-1.83

Conversation

@mrodm

@mrodm mrodm commented Jul 31, 2026

Copy link
Copy Markdown
Collaborator

TL;DR

Syncs .buildkite and .ci CI configuration from main to the
backport-kubernetes-1.83 backport branch, while preserving the Kubernetes
and kind versions specific to this branch.

Proposed commit message

Sync CI configuration with main branch for backport-kubernetes-1.83.

Keep CI pipelines, GitHub Actions, and tooling consistent between active backport
branches and `main`, so that automated backport workflows and tooling improvements
land on all supported branches.

WHY:
GitHub Actions resolves workflow files from the branch where the event occurs,
not from `main`. Backport-branch workflows (changelog sync, post-backport
checklist, owner checks, auto-backport) must be present on the backport branch
itself to fire correctly.

KIND_VERSION and K8S_VERSION are reverted to the values defined in
backport-kubernetes-1.83 (v0.27.0 and v1.33.0 respectively) to avoid testing
against versions incompatible with the Kubernetes 1.83 package stream.

Author's Checklist

  • CI configuration files have been synced verbatim from main.
  • KIND_VERSION is set to v0.27.0 as defined in backport-kubernetes-1.83 (not the main value v0.32.0).
  • K8S_VERSION is set to v1.33.0 as defined in backport-kubernetes-1.83 (not the main value v1.36.1).

How to test this PR locally

Verify that the kind and k8s versions in .buildkite/pipeline.yml match the values expected for the backport-kubernetes-1.83 branch:

grep -E 'KIND_VERSION|K8S_VERSION' .buildkite/pipeline.yml
# Expected:
#   KIND_VERSION: 'v0.27.0'
#   K8S_VERSION: 'v1.33.0'

Related issues


This PR was generated with the assistance of Claude (claude-sonnet-4-6).

@elastic-vault-github-plugin-prod

elastic-vault-github-plugin-prod Bot commented Jul 31, 2026 •

Copy link
Copy Markdown
Contributor

🚀 Benchmarks report

To see the full report comment with /test benchmark fullreport

@botelastic

botelastic Bot commented Aug 30, 2026

Copy link
Copy Markdown

Hi! We just realized that we haven't looked into this PR in a while. We're sorry! We're labeling this issue as Stale to make it hit our filters and make sure we get back to it as soon as possible. In the meantime, it'd be extremely helpful if you could take a look at it as well and confirm its relevance. A simple comment with a nice emoji will be enough :+1. Thank you for your contribution!

@botelastic botelastic Bot added the Stalled label Aug 30, 2026
@botelastic botelastic Bot removed the Stalled label Sep 7, 2026
@mrodm
mrodm marked this pull request as ready for review September 8, 2026 10:34
@mrodm
mrodm requested a review from a team as a code owner September 8, 2026 10:34
Copilot AI lite review requested due to automatic review settings September 8, 2026 10:34

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

It removes the ReportFailedTests mage target still invoked by CI and updates the serverless pipeline’s KIND/K8S versions contrary to the branch-specific version requirements stated in the PR.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Pull request overview

Syncs CI/configuration and backport-branch automation from main into the backport-kubernetes-1.83 branch, adding the branch-resident GitHub Actions workflows and Buildkite scripting needed for backport automation and validation.

Changes:

  • Adds new GitHub Actions workflows/actions for backport changelog sync and post-backport checklist automation.
  • Introduces/updates the standalone cmd/backport Go sub-module plus supporting utilities (CODEOWNERS parsing, package detection, changelog helpers).
  • Updates Buildkite pipelines/scripts to support new backport flows and improved package-selection logic.
File summaries
File Description
magefile.go Removes the ReportFailedTests mage target and related deps.
go.sum Removes root-module deps no longer referenced after CI/tooling sync.
go.mod Removes root-module deps no longer referenced after CI/tooling sync.
dev/testsreporter/xunit.go Removes legacy tests reporter implementation.
dev/testsreporter/testsreporter.go Removes legacy tests reporter implementation.
dev/testsreporter/testdata/sql_system_1718901944954979316.xml Removes testsreporter fixture data.
dev/testsreporter/testdata/nats_1718676056733968706.xml Removes testsreporter fixture data.
dev/testsreporter/testdata/fortinet_fortigate_1718675058322143368.xml Removes testsreporter fixture data.
dev/testsreporter/testdata/fortinet_fortigate_1718675052813006253.xml Removes testsreporter fixture data.
dev/testsreporter/testdata/elastic_package_registry_1718676502022628094.xml Removes testsreporter fixture data.
dev/testsreporter/testdata/CODEOWNERS-default-tests Removes testsreporter fixture data.
dev/testsreporter/testdata/cisco_umbrella_1718676502022628093.xml Removes testsreporter fixture data.
dev/testsreporter/testdata/cisco_umbrella_1718675095255991383.xml Removes testsreporter fixture data.
dev/testsreporter/testdata/cisco_umbrella_1718675095080627646.xml Removes testsreporter fixture data.
dev/testsreporter/testdata/cisco_umbrella_1718675092421310216.xml Removes testsreporter fixture data.
dev/testsreporter/packageerror.go Removes legacy tests reporter implementation.
dev/testsreporter/packageerror_test.go Removes testsreporter unit tests.
dev/testsreporter/githubissue.go Removes legacy tests reporter implementation.
dev/testsreporter/github.go Removes legacy tests reporter implementation (go-gh client usage).
dev/testsreporter/github_test.go Removes testsreporter unit tests.
dev/testsreporter/format.go Removes testsreporter formatting/templates integration.
dev/testsreporter/errorlinks.go Removes testsreporter supporting types.
dev/testsreporter/dataerror.go Removes testsreporter supporting types.
dev/testsreporter/builderror.go Removes testsreporter supporting types.
dev/testsreporter/builderror_test.go Removes testsreporter unit tests.
dev/testsreporter/_static/summary.tmpl Removes testsreporter templates.
dev/testsreporter/_static/description.tmpl Removes testsreporter templates.
dev/scripts/README.md Documents dev/scripts/ purpose and CI trigger behavior.
dev/scripts/backport_apply.sh Adds wrapper script around backport apply.
dev/packagenames/packagenames.go Replaces slices.Sort with sort.Strings for duplicate listing.
dev/import-beats/README.md Fixes grammar in docs.
dev/gitutil/git.go Adds small git command wrapper utility for tooling.
dev/codeowners/codeowners.go Adds cached CODEOWNERS parser/lookup helpers and refactors scanning to accept an io.Reader.
dev/citools/packages.go Adds ListPackagesWithNames + refactors ListPackages; switches sorting away from slices.
dev/citools/packagemanifest.go Extends manifest parsing (requires/owner) and parses via os.ReadFile.
dev/citools/logsdb_test.go Fixes test title typo and formatting.
dev/citools/kibana_test.go Fixes test title typo.
dev/citools/gomod_test.go Makes go.mod fixture version compatible with older Go toolchains.
cmd/backport/tools.go Converts previous content into a tools-only file for the backport sub-module.
cmd/backport/magefile.go Adds mage targets for building/testing/formatting the backport sub-module.
cmd/backport/go.mod Adds standalone Go module for the backport tool.
cmd/backport/gitutil/git.go Adds a local git utility copy for the standalone module.
cmd/backport/codeowners/codeowners.go Adds a local CODEOWNERS parser copy for the standalone module.
cmd/backport/citools/packages.go Adds local package discovery helper for the standalone module.
cmd/backport/citools/packagemanifest.go Adds local manifest parsing helpers for the standalone module.
cmd/backport/backports/packages/detect.go Implements mapping changed files → package names.
cmd/backport/backports/packages/detect_test.go Adds tests for package detection logic.
cmd/backport/backports/owners/compare.go Adds owner-compare logic (worktree vs remote ref).
cmd/backport/backports/owners/compare_integration_test.go Adds integration tests for owner comparison logic.
cmd/backport/backports/owners/check.go Adds owner-check aggregation for a set of packages.
cmd/backport/backports/owners/check_test.go Adds unit tests for owner mismatch team-deduping.
cmd/backport/backports/changelog/update.go Adds changelog link update helper.
cmd/backport/backports/changelog/update_test.go Adds tests for changelog link update helper.
cmd/backport/backports/changelog/sync.go Adds changelog sync PR creation logic (branch + PR creation).
cmd/backport/backports/changelog/sync_test.go Adds tests for TSV parsing and message/title construction.
cmd/backport/backports/changelog/resolve.go Adds package name → path index builder.
cmd/backport/backports/changelog/resolve_test.go Adds tests for package index resolution.
cmd/backport/backports/changelog/insert.go Adds semver-ordered changelog entry insertion helper.
cmd/backport/backports/changelog/insert_test.go Adds tests for entry insertion behavior.
cmd/backport/backports/changelog/extract.go Adds diff parser to extract newly-added changelog entry blocks.
cmd/backport/backports/changelog/extract_test.go Adds tests for diff extraction.
cmd/backport/backports/changelog/comment.go Adds PR comment posting/rendering logic for sync outcomes.
cmd/backport/.go-version Pins Go toolchain for the backport sub-module.
.gitignore Updates Claude state ignores + ignores Buildkite CI venv.
.github/workflows/validate-yaml-dashboards.yml Updates checkout action version.
.github/workflows/validate-package-docs.yml Updates checkout action version.
.github/workflows/vale-lint.yml Updates checkout action version.
.github/workflows/trigger-text-auditor.yml Adds permissions + disables job via if: false and removes COPILOT secret wiring.
.github/workflows/trigger-stale-issues.yml Adds permissions + disables job via if: false and removes COPILOT secret wiring.
.github/workflows/trigger-pr-review.yml Adds permissions + disables job via if: false and removes COPILOT secret wiring.
.github/workflows/trigger-pr-actions-detective.yml Adds permissions and removes COPILOT secret wiring.
.github/workflows/trigger-package-tests-security-ml.yml Tightens permissions and bumps fetch-github-token action version.
.github/workflows/trigger-newbie-contributor-patrol.yml Adds permissions + disables job via if: false and removes COPILOT secret wiring.
.github/workflows/trigger-mention-in-pr.yml Adds permissions + disables job via if: false and removes COPILOT secret wiring.
.github/workflows/trigger-mention-in-issue.yml Adds permissions + disables job via if: false and removes COPILOT secret wiring.
.github/workflows/trigger-issue-triage.yml Adds permissions + disables job via if: false and removes COPILOT secret wiring.
.github/workflows/trigger-duplicate-issue-detector.yml Adds permissions + disables job via if: false and removes COPILOT secret wiring.
.github/workflows/trigger-docs-patrol.yml Adds permissions + disables job via if: false and removes COPILOT secret wiring.
.github/workflows/trigger-bug-hunter.yml Adds permissions + disables job via if: false and removes COPILOT secret wiring.
.github/workflows/trigger-breaking-change-detector.yml Adds permissions + disables job via if: false, removes COPILOT secret wiring, adds additional instructions.
.github/workflows/sync-backport-changelog.yml Adds new workflow to sync backport changelog changes back to main.
.github/workflows/sweep-pipeline-error-handling.yml Adds permissions + disables job via if: false and removes COPILOT secret wiring.
.github/workflows/sweep-ingest-pipeline-safety.yml Adds permissions + disables job via if: false and removes COPILOT secret wiring.
.github/workflows/sweep-httpjson-pagination.yml Adds permissions + disables job via if: false and removes COPILOT secret wiring.
.github/workflows/sweep-field-mapping-conflicts.yml Adds permissions + disables job via if: false and removes COPILOT secret wiring.
.github/workflows/sweep-dashboard-data-scope.yml Adds permissions + disables job via if: false and removes COPILOT secret wiring.
.github/workflows/requires-update.yml Adds scheduled/manual workflow to update required package versions.
.github/workflows/pr-buildkite-detective.yml Adds a gating job to only run detective when an open PR exists for the failing commit.
.github/workflows/post-backport-checklist.yml Adds workflow_run job to post/update backport checklist comment.
.github/workflows/notify-package-docs-failure.yml Tightens permissions for docs failure notifier.
.github/workflows/docs-edit-automation.yml Tightens permissions + updates checkout action version.
.github/workflows/catalog-info.yml Updates checkout action version.
.github/workflows/bump-elastic-stack-version.yml Updates checkout/setup-go action versions and bumps Updatecli action pin.
.github/workflows/backport-packages-detect.yml Adds PR workflow to detect touched packages and upload artifact for checklist.
.github/actions/sync-backport-changelog/action.yml Adds composite action used by sync-backport-changelog workflow.
.buildkite/scripts/trigger_integrations_in_parallel.sh Changes package selection to compute affected packages from git diff.
.buildkite/scripts/trigger_backport.sh Adds Buildkite script to trigger backport dry-runs/creates on .backports.yml change.
.buildkite/scripts/trigger_backport_lib.sh Adds shared library for trigger_backport.sh (diffing inventory, generating triggers).
.buildkite/scripts/test_non_package_patterns.sh Adds unit tests for non-package path classification.
.buildkite/scripts/test_integrations_with_serverless.sh Changes package selection to compute affected packages from git diff (serverless pipeline).
.buildkite/scripts/test_helpers.sh Adds file-content assertion helpers for shell tests.
.buildkite/scripts/test_check_backport_owners.sh Adds unit tests for backport owner check comment rendering.
.buildkite/scripts/run_dev_scripts_tests.sh Simplifies dev script tests runner invocation.
.buildkite/scripts/run_buildkite_scripts_tests.sh Adds more Buildkite script test invocations and yq bootstrapping.
.buildkite/scripts/packages/crowdstrike.sh Adds per-package CI check to ensure generated pipelines remain in sync.
.buildkite/scripts/notify_backport_pr.sh Adds PR notification script for backport branch creation outcome.
.buildkite/scripts/non_package_patterns.txt Adds centralized non-package patterns list used by common.sh.
.buildkite/scripts/check_changelog_versions_in_main.sh Adds backport-only check to ensure changelog versions aren’t already on main.
.buildkite/scripts/check_changelog_entries.sh Improves changelog link checking (sentinel detection + soft-fail separation).
.buildkite/scripts/check_backports_inventory.sh Adds inventory validation + git-diff cleanliness check.
.buildkite/scripts/check_backport_tool.sh Adds cmd/backport sub-module mage check step for CI.
.buildkite/scripts/check_backport_owners.sh Adds Buildkite PR check to detect owner drift vs main for backport PRs.
.buildkite/scripts/backport_branch_lib.sh Adds helper functions for backport branch creation scripts.
.buildkite/pull-requests.json Updates skip-CI patterns and adds pipeline config block for backport dispatch.
.buildkite/pipeline.yml Adds/updates steps for backport tool checks, inventory validation, changelog checks, and owner checks.
.buildkite/pipeline.serverless.yml Updates serverless pipeline environment (incl. KIND/K8S versions).
.buildkite/pipeline.schedule-weekly.yml Updates scheduled stack versions.
.buildkite/pipeline.schedule-daily.yml Updates scheduled stack versions.
.buildkite/pipeline.backport.yml Tightens trigger conditions, adds UI guardrails, adds PR notification step and email notify.
.buildkite/pipeline.backport-dispatch.yml Adds new dispatch pipeline to create backport branches on main pushes.
Review details
  • Files reviewed: 142/145 changed files
  • Comments generated: 2
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread magefile.go
Comment on lines 145 to 151
func ModTidy() error {
return sh.RunV("go", "mod", "tidy")
}

func ReportFailedTests(ctx context.Context, testResultsFolder string) error {
stackVersion := os.Getenv("STACK_VERSION")
serverlessEnv := os.Getenv("SERVERLESS")
dryRunEnv := os.Getenv("DRY_RUN")
serverlessProjectEnv := os.Getenv("SERVERLESS_PROJECT")
buildURL := os.Getenv("BUILDKITE_BUILD_URL")
subscription := os.Getenv("ELASTIC_SUBSCRIPTION")

serverless := false
if serverlessEnv != "" {
var err error
serverless, err = strconv.ParseBool(serverlessEnv)
if err != nil {
return fmt.Errorf("failed to parse SERVERLESS value: %w", err)
}
if serverlessProjectEnv == "" {
serverlessProjectEnv = defaultServerlessProjectType
}
}

logsDBEnabled := false
if v, found := os.LookupEnv("STACK_LOGSDB_ENABLED"); found && v == "true" {
logsDBEnabled = true
}

verboseMode := false
if v, found := os.LookupEnv("VERBOSE_MODE_ENABLED"); found && v == "true" {
verboseMode = true
}

maxIssuesString := os.Getenv("CI_MAX_TESTS_REPORTED")
maxIssues := defaultMaximumTestsReported
if maxIssuesString != "" {
var err error
maxIssues, err = strconv.Atoi(maxIssuesString)
if err != nil {
return fmt.Errorf("failed to convert env. variable CI_MAX_TESTS_REPORTED to int (%s): %w", maxIssuesString, err)
}
}

dryRun := false
if dryRunEnv != "" {
var err error
dryRun, err = strconv.ParseBool(dryRunEnv)
if err != nil {
return fmt.Errorf("failed to parse DRY_RUN value: %w", err)
}
}

options := testsreporter.CheckOptions{
Serverless: serverless,
ServerlessProject: serverlessProjectEnv,
LogsDB: logsDBEnabled,
StackVersion: stackVersion,
Subscription: subscription,
BuildURL: buildURL,
MaxPreviousLinks: defaultPreviousLinksNumber,
MaxTestsReported: maxIssues,
DryRun: dryRun,
Verbose: verboseMode,
}
return testsreporter.Check(ctx, testResultsFolder, options)
}

// ListPackages lists all packages found under the packages directory.
func ListPackages() error {
const packagesDir = "packages"
Comment thread .buildkite/pipeline.serverless.yml Outdated
Comment on lines +6 to +9
DOCKER_COMPOSE_VERSION: "v2.24.1"
DOCKER_VERSION: "false" # not required to set since system tests are not running yet
KIND_VERSION: 'v0.27.0'
K8S_VERSION: 'v1.33.0'
KIND_VERSION: 'v0.32.0'
K8S_VERSION: 'v1.36.1'
Copilot AI review requested due to automatic review settings September 8, 2026 10:40

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

It introduces broad CI/workflow and automation changes across Buildkite + GitHub Actions plus new tooling, and should receive a final human validation pass for correctness and operational impact.

Review details

Suppressed comments (4)

Previously missed (4) — in code that hasn't changed since the last review.

.buildkite/pipeline.backport.yml:18

  • $${BUILDKITE_PIPELINE_SLUG} is likely to expand incorrectly in the shell command (e.g., $$ → PID) and differs from the previous $BUILDKITE_PIPELINE_SLUG usage; use normal shell expansion to avoid a confusing/incorrect annotation message.
    .buildkite/scripts/non_package_patterns.txt:4
  • The header comment says these patterns "do NOT trigger package tests", but the file includes ^packages/ (which should still run package tests for affected packages). This reads as if package changes would skip testing entirely, which is misleading given how pr_has_package_related_files is used (deciding full-matrix vs scoped testing).
    .buildkite/scripts/test_integrations_with_serverless.sh:86
  • Same as trigger_integrations_in_parallel.sh: the message "Non-package files changed" doesn’t match what pr_has_package_related_files actually checks (any change not matched by non_package_patterns.txt). Updating the wording would make CI behavior easier to reason about.
    .buildkite/scripts/trigger_integrations_in_parallel.sh:55
  • The log message says "Non-package files changed" when the condition is pr_has_package_related_files, which is based on whether any changed path is not covered by non_package_patterns.txt. Since that file includes ^packages/ and other non-test-affecting paths, the current message is misleading for debugging.
  • Files reviewed: 141/144 changed files
  • Comments generated: 0 new
  • Review effort level: Lite

@infra-vault-gh-plugin-prod

Copy link
Copy Markdown

💚 Build Succeeded

History

cc @mrodm

@mrodm
mrodm merged commit cbcd579 into elastic:backport-kubernetes-1.83 Sep 8, 2026
9 checks passed
@github-actions

github-actions Bot commented Sep 8, 2026

Copy link
Copy Markdown
Contributor

Changelog sync skipped — all changelog versions are already present on main.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants