Skip to content

[backport-aws-7.1] Sync CI configuration with main branch - #21150

Merged
mrodm merged 1 commit into
elastic:backport-aws-7.1from
mrodm:sync-ci-configuration-aws-7.1
Sep 9, 2026
Merged

mrodm merged 1 commit into
elastic:backport-aws-7.1from
mrodm:sync-ci-configuration-aws-7.1

Conversation

@mrodm

@mrodm mrodm commented Sep 9, 2026

Copy link
Copy Markdown
Collaborator

TL;DR

Syncs .buildkite CI configuration and GitHub Actions workflows from main to the
backport-aws-7.1 backport branch, ensuring automated workflows and tooling
improvements are consistent across all supported branches.

Proposed commit message

[backport-aws-7.1] Sync CI configuration with main branch

Keep CI pipelines, GitHub Actions, and tooling consistent between active backport
branches and `main`, so that automated backport workflows and tooling improvements
land on all supported branches.

WHY:
GitHub Actions resolves workflow files from the branch where the event occurs,
not from `main`. Backport-branch workflows (changelog sync, post-backport
checklist, owner checks, auto-backport) must be present on the backport branch
itself to fire correctly.

Changes include:
- Add ELASTIC_PACKAGE_SERVERLESS_KIBANA_SKIP_UPLOAD_PACKAGE_VALIDATION env var
  to pipeline.serverless.yml
- Extend backport_branch.sh to also preserve K8S_VERSION/KIND_VERSION from
  pipeline.serverless.yml (not just pipeline.yml)
- Fix pipeline.backport-dispatch.yml to watch cmd/backport/** instead of the
  old dev/backports/** path
- Allow "maintain" permission level in auto-backport and sync-backport-changelog
  workflows (in addition to write/admin)
- Update cmd/backport go.mod/go.sum and fix test references

Author's Checklist

  • CI configuration files have been synced from main.
  • KIND_VERSION and K8S_VERSION remain at v0.32.0 / v1.36.1 (same as main — no version-specific pins needed for this branch).
  • pipeline.backport-dispatch.yml now watches cmd/backport/** (renamed from dev/backports/**).
  • maintain permission level accepted in GitHub Actions workflows alongside write/admin.

How to test this PR locally

Verify that the CI pipeline files reflect the synced configuration:

grep -E 'KIND_VERSION|K8S_VERSION' .buildkite/pipeline.yml .buildkite/pipeline.serverless.yml
# Expected: KIND_VERSION: 'v0.32.0' / K8S_VERSION: 'v1.36.1' in both files

grep 'cmd/backport' .buildkite/pipeline.backport-dispatch.yml
# Expected: - "cmd/backport/**"

grep 'maintain' .github/workflows/auto-backport.yml .github/workflows/sync-backport-changelog.yml
# Expected: "maintain" present in permission checks

Related issues


This PR was generated with the assistance of Claude (claude-sonnet-4-6).

🤖 Generated with Claude Code

@mrodm mrodm self-assigned this Sep 9, 2026
@mrodm
mrodm changed the base branch from main to backport-aws-7.1 September 9, 2026 09:39
@mrodm

mrodm commented Sep 9, 2026

Copy link
Copy Markdown
Collaborator Author

/test

@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

🚀 Benchmarks report

Package aws 👍(11) 💚(9) 💔(2)

Expand to view
Data stream Previous EPS New EPS Diff (%) Result
firewall_logs 4464.29 3424.66 -1039.63 (-23.29%) 💔
apigateway_logs 28571.43 17241.38 -11330.05 (-39.66%) 💔

To see the full report comment with /test benchmark fullreport

@infra-vault-gh-plugin-prod

Copy link
Copy Markdown

💚 Build Succeeded

History

cc @mrodm

@mrodm
mrodm marked this pull request as ready for review September 9, 2026 12:55
@mrodm
mrodm requested a review from a team as a code owner September 9, 2026 12:55
Copilot AI lite review requested due to automatic review settings September 9, 2026 12:55

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

.buildkite/scripts/backport_branch.sh uses \s in grep -E/sed patterns, which won’t match the indented YAML keys and can prevent preserving/restoring the version pins.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Pull request overview

This PR backports CI and automation updates from main onto the backport-aws-7.1 branch so that branch-scoped Buildkite and GitHub Actions workflows continue to run correctly on active backport branches.

Changes:

  • Sync Buildkite pipelines/scripts and GitHub Actions workflows with main (including updated permission checks and path watches).
  • Update the backport CLI module dependencies and adjust backport-tool tests/docs references to the new cmd/backport/** layout.
  • Improve package detection in Buildkite scripts by cross-referencing mage listPackages output (handles nested package roots).
File summaries
File Description
dev/citools/logsdb_test.go Fix test-case string typo and remove trailing blank lines.
dev/citools/kibana_test.go Fix test-case string typo.
cmd/backport/go.mod Bump go-gh / safeexec versions.
cmd/backport/go.sum Update sums for bumped and newly pulled transitive dependencies.
cmd/backport/backports/packages/detect_test.go Update test references from dev/backports/** to cmd/backport/**.
cmd/backport/backports/owners/check.go Update comment reference to new package-index location.
cmd/backport/backports/apply/apply.go Update comment reference for branch-name regex source.
cmd/backport/backports/apply/apply_test.go Update comment reference for owners logic location.
.github/workflows/sync-backport-changelog.yml Allow maintain permission in actor permission gate and update message.
.github/workflows/auto-backport.yml Allow maintain permission in actor permission gate and update message.
.buildkite/scripts/trigger_integrations_in_parallel.sh Use mage listPackages output to correctly detect nested package roots impacted by diffs.
.buildkite/scripts/test_integrations_with_serverless.sh Same nested-package detection improvement for serverless test pipeline.
.buildkite/scripts/backport_branch.sh Preserve/restore K8S/KIND pins from pipeline.serverless.yml as well as pipeline.yml.
.buildkite/pipeline.serverless.yml Add ELASTIC_PACKAGE_SERVERLESS_KIBANA_SKIP_UPLOAD_PACKAGE_VALIDATION env var.
.buildkite/pipeline.backport-dispatch.yml Update watched path from dev/backports/** to cmd/backport/**.
Review details

Suppressed comments (2)

.buildkite/scripts/backport_branch.sh:168

  • grep -E doesn’t treat \s as whitespace, so these lookups won’t match the indented K8S_VERSION: / KIND_VERSION: lines in .buildkite/pipeline.serverless.yml, and the values won’t be preserved.
  if [ -f "${pipeline_serverless_yml}" ]; then
    serverless_k8s_version_line=$(grep -E '^\s*K8S_VERSION:' "${pipeline_serverless_yml}" || true)
    serverless_kind_version_line=$(grep -E '^\s*KIND_VERSION:' "${pipeline_serverless_yml}" || true)
    echo "Preserving from backport branch (pipeline.serverless.yml): ${serverless_k8s_version_line}, ${serverless_kind_version_line}"
  fi

.buildkite/scripts/backport_branch.sh:184

  • The sed search regex uses \s, which isn’t a portable whitespace matcher and won’t match the indented K8S_VERSION: / KIND_VERSION: lines in the current pipeline YAMLs. That can prevent restoring the version pins after syncing the .buildkite directory.
    echo "--- Restoring KIND_VERSION in ${pipeline_yml}..."
    sed -i "s|^\s*KIND_VERSION:.*|${kind_version_line}|" "${pipeline_yml}"
  fi
  if [ -n "${serverless_k8s_version_line}" ]; then
    echo "--- Restoring K8S_VERSION in ${pipeline_serverless_yml}..."
  • Files reviewed: 14/15 changed files
  • Comments generated: 1
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment on lines 159 to +163
if [ -f "${pipeline_yml}" ]; then
k8s_version_line=$(grep -E '^\s*K8S_VERSION:' "${pipeline_yml}" || true)
kind_version_line=$(grep -E '^\s*KIND_VERSION:' "${pipeline_yml}" || true)
echo "Preserving from backport branch: ${k8s_version_line}, ${kind_version_line}"
echo "Preserving from backport branch (pipeline.yml): ${k8s_version_line}, ${kind_version_line}"
fi
@mergify

mergify Bot commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

Tick the box to add this pull request to the merge queue (same as @mergifyio queue).

  • Queue this pull request

@mrodm
mrodm merged commit 1c3a67d into elastic:backport-aws-7.1 Sep 9, 2026
5 checks passed
@mrodm
mrodm deleted the sync-ci-configuration-aws-7.1 branch September 9, 2026 14:22
@github-actions

github-actions Bot commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

Changelog sync skipped — all changelog versions are already present on main.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants