Skip to content

[backport-cloud_security_posture-1.7] Sync CI configuration with main branch - #21259

Merged
mrodm merged 6 commits into
elastic:backport-cloud_security_posture-1.7from
mrodm:sync-ci-configuration-cloud_security_posture-1.7
Sep 15, 2026
Merged

mrodm merged 6 commits into
elastic:backport-cloud_security_posture-1.7from
mrodm:sync-ci-configuration-cloud_security_posture-1.7

Conversation

@mrodm

@mrodm mrodm commented Sep 15, 2026

Copy link
Copy Markdown
Collaborator

TL;DR

Syncs .buildkite and .github CI configuration from main to the
backport-cloud_security_posture-1.7 backport branch.

This brings automated backport workflows, new CI scripts, Go tooling, and
GitHub Actions that only work when they are present on the target branch itself.
It also includes several follow-up fixes discovered after the initial sync.

Proposed commit message

```
Sync CI configuration with main branch for backport-cloud_security_posture-1.7.

Keep CI pipelines, GitHub Actions, and tooling consistent between active backport
branches and `main`, so that automated backport workflows and tooling improvements
land on all supported branches.

WHY:
GitHub Actions resolves workflow files from the branch where the event occurs,
not from `main`. Backport-branch workflows (changelog sync, post-backport
checklist, owner checks, auto-backport) must be present on the backport branch
itself to fire correctly.

Additional fixes included in this sync:

  • Update missing CODEOWNERS for data streams (copied from main)
  • Remove --coverage-format parameter
  • Add --fail to curl in with_docker_compose to enable retries on HTTP errors
  • Restore with_docker_compose to pin standalone binary for elastic-package v0.79.0
  • Restore docker-compose version
    ```

Author's Checklist

  • CI configuration files have been synced verbatim from `main`.

How to test this PR locally

N/A — CI-only changes. Validate by confirming GitHub Actions workflows trigger
correctly on the `backport-cloud_security_posture-1.7` branch after merge.

Related issues


This PR was generated with the assistance of Claude (claude-sonnet-4-6).

🤖 Generated with Claude Code

mrodm and others added 6 commits September 15, 2026 10:59
…-package v0.79.0

The CI sync (elastic#20542) replaced with_docker_compose (standalone binary
installed into BIN_FOLDER) with with_docker_compose_plugin (CLI plugin
installed into ~/.docker/cli-plugins). This caused elastic-package
v0.79.0, which hardcodes exec.Command("docker-compose", ...), to pick
up the system's docker-compose v2.24.7 (bundled with Docker 26.1.2)
instead of the pinned version.

Docker Compose v2.23+ changed the YAML output of `docker compose config`
so that the environment field is serialized as a sequence instead of a
map, which elastic-package v0.79.0 cannot unmarshal (map[string]string).

Restore with_docker_compose so the pinned standalone binary is placed
in BIN_FOLDER (first in PATH) and called before the system version.
Call it from test_one_package.sh and test_integrations_with_serverless.sh
alongside the existing plugin installation.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
…TTP errors

Without --fail, curl exits 0 even on 4xx responses, saving the HTML
error body silently. This caused the docker-compose binary to contain
an HTML page, making it fail at execution time. With --fail, HTTP
errors produce a non-zero exit code so retry 5 can kick in properly.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This parameter was not available until elastic-package v0.96.0
@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

✅ Package owners are in sync with main.

@mrodm
mrodm marked this pull request as ready for review September 15, 2026 14:25
@mrodm
mrodm requested a review from a team as a code owner September 15, 2026 14:25
Copilot AI lite review requested due to automatic review settings September 15, 2026 14:25

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Unresolved critical and moderate findings block safe approval.

Get a fresh assessment by requesting another Copilot review.

Pull request overview

This PR synchronizes CI configuration and backport tooling from main to backport-cloud_security_posture-1.7.

Changes:

  • Adds Buildkite and GitHub Actions backport automation.
  • Adds the standalone backport CLI and supporting scripts.
  • Updates package validation, coverage tooling, dependencies, and fixtures.

The review identified unresolved critical and moderate issues in automation, synchronization, path handling, and helper scripts, along with documentation and help-command nits.

File summaries
File Summary
tools.go Go tooling declarations
go.mod Go module dependencies
dev/scripts/README.md Developer script documentation
dev/scripts/get_release_commit.sh Release commit lookup script
dev/scripts/backport_apply.sh Backport application wrapper
dev/packagenames/testdata/no_duplicates/p2/manifest.yml Package validation fixture
dev/packagenames/testdata/no_duplicates/p1/manifest.yml Package validation fixture
dev/packagenames/testdata/nested/no_duplicates/technology/p2/manifest.yml Nested package fixture
dev/packagenames/testdata/nested/no_duplicates/technology/p1/manifest.yml Nested package fixture
dev/packagenames/testdata/nested/no_duplicates/p3/manifest.yml Nested package fixture
dev/packagenames/testdata/nested/duplicates/technology/p2/manifest.yml Duplicate package fixture
dev/packagenames/testdata/nested/duplicates/technology/p1/manifest.yml Duplicate package fixture
dev/packagenames/testdata/nested/duplicates/p3/manifest.yml Duplicate package fixture
dev/packagenames/testdata/invalid_manifests/p2/manifest.yml Invalid manifest fixture
dev/packagenames/testdata/invalid_manifests/p1/manifest.yml Invalid manifest fixture
dev/packagenames/testdata/duplicates/p2/manifest.yml Duplicate package fixture
dev/packagenames/testdata/duplicates/p1/manifest.yml Duplicate package fixture
dev/packagenames/packagenames.go Package-name validation
dev/packagenames/packagenames_test.go Package-name validation tests
dev/import-beats/variables.go Import-beats variables
dev/import-beats/variables_compact.go Compact variable handling
dev/import-beats/README.md Import-beats documentation
dev/import-beats/packages.go Import-beats package handling
dev/import-beats/fields.go Import-beats field handling
dev/import-beats/elasticsearch.go Elasticsearch integration
dev/gitutil/git.go Git utility helpers
dev/coverage/testdata/test-coverage-3.xml Coverage fixture
dev/coverage/testdata/test-coverage-2.xml Coverage fixture
dev/coverage/testdata/test-coverage-1.xml Coverage fixture
dev/coverage/testdata/expected-test-coverage.xml Expected coverage output
dev/coverage/coverage.go Coverage merging
dev/coverage/coverage_test.go Coverage tests
dev/codeowners/testdata/test_packages/package_1/manifest.yml CODEOWNERS fixture
dev/codeowners/testdata/test_packages/package_1/data_stream/stream_2/.keep Data stream fixture
dev/codeowners/testdata/test_packages/package_1/data_stream/stream_1/.keep Data stream fixture
dev/codeowners/testdata/nested_packages/package_top/manifest.yml Nested package fixture
dev/codeowners/testdata/nested_packages/category/package_nested_2/manifest.yml Nested package fixture
dev/codeowners/testdata/nested_packages/category/package_nested_1/manifest.yml Nested package fixture
dev/codeowners/testdata/nested_packages/category/package_nested_1/data_stream/stream_2/.keep Data stream fixture
dev/codeowners/testdata/nested_packages/category/package_nested_1/data_stream/stream_1/.keep Data stream fixture
dev/codeowners/testdata/devexp/manifest.yml CODEOWNERS fixture
dev/codeowners/testdata/CODEOWNERS-streams-valid Valid CODEOWNERS fixture
dev/codeowners/testdata/CODEOWNERS-streams-multiple-owners Multiple-owner fixture
dev/codeowners/testdata/CODEOWNERS-streams-missing-owners Missing-owner fixture
dev/codeowners/testdata/CODEOWNERS-owners-trailing-slash CODEOWNERS path fixture
dev/codeowners/testdata/CODEOWNERS-owners-packages-datastreams Package/data-stream fixture
dev/codeowners/testdata/CODEOWNERS-nested-valid Nested CODEOWNERS fixture
dev/codeowners/testdata/CODEOWNERS-nested-streams-valid Nested stream fixture
dev/codeowners/testdata/CODEOWNERS-nested-streams-missing-owners Nested missing-owner fixture
dev/codeowners/testdata/CODEOWNERS-nested-missing-owner Nested owner fixture
dev/codeowners/testdata/CODEOWNERS-nested-category-owner Nested category fixture
dev/citools/subscription.go Subscription utilities
dev/citools/packages.go Package utilities
dev/citools/packagemanifest.go Package manifest utilities
dev/citools/logsdb.go Logs database utilities
dev/citools/logsdb_test.go Logs database tests
dev/citools/kibana.go Kibana utilities
dev/citools/kibana_test.go Kibana tests
dev/citools/gomod.go Go module utilities
dev/citools/gomod_test.go Go module tests
cmd/backport/tools.go Backport CLI tooling
cmd/backport/magefile.go Backport Mage targets
cmd/backport/go.mod Backport module dependencies
cmd/backport/gitutil/git.go Backport Git utilities
cmd/backport/citools/packages.go Backport package utilities
cmd/backport/citools/packagemanifest.go Backport manifest utilities
cmd/backport/backports/packages/detect.go Changed-package detection
cmd/backport/backports/owners/check.go Owner validation
cmd/backport/backports/owners/check_test.go Owner validation tests
cmd/backport/backports/changelog/update.go Changelog updates
cmd/backport/backports/changelog/update_test.go Changelog update tests
cmd/backport/backports/changelog/sync_test.go Changelog sync tests
cmd/backport/backports/changelog/resolve.go Changelog resolution
cmd/backport/backports/changelog/resolve_test.go Changelog resolution tests
cmd/backport/backports/changelog/insert.go Changelog insertion
cmd/backport/backports/changelog/insert_test.go Changelog insertion tests
cmd/backport/backports/changelog/extract.go Changelog extraction
cmd/backport/backports/changelog/extract_test.go Changelog extraction tests
cmd/backport/backports/changelog/comment.go Changelog comments
cmd/backport/.go-version Backport Go version
.gitignore Ignore configuration
.github/workflows/validate-yaml-dashboards.requirements.txt Dashboard workflow requirements
.github/workflows/validate-package-docs.yml Package documentation workflow
.github/workflows/vale-report.yml Vale reporting workflow
.github/workflows/vale-lint.yml Vale lint workflow
.github/workflows/updatecli/values.d/scm.yml Updatecli SCM configuration
.github/workflows/updatecli/updatecli.d/sync-packages-to-bug-issue-template.yml Issue-template synchronization
.github/workflows/updatecli/updatecli.d/bump-latest-9x-snapshot-version.yml Version update configuration
.github/workflows/updatecli/updatecli.d/bump-latest-8x-snapshot-version.yml Version update configuration
.github/workflows/updatecli/updatecli.d/bump-latest-7x-version.yml Version update configuration
.github/workflows/trigger-text-auditor.yml Text auditor workflow
.github/workflows/trigger-stale-issues.yml Stale issue workflow
.github/workflows/trigger-pr-review.yml PR review workflow
.github/workflows/trigger-pr-actions-detective.yml Actions detective workflow
.github/workflows/trigger-package-tests-security-ml.yml Package test workflow
.github/workflows/trigger-newbie-contributor-patrol.yml Contributor patrol workflow
.github/workflows/trigger-mention-in-pr.yml PR mention workflow
.github/workflows/trigger-mention-in-issue.yml Issue mention workflow
.github/workflows/trigger-issue-triage.yml Issue triage workflow
.github/workflows/trigger-duplicate-issue-detector.yml Duplicate detection workflow
.github/workflows/trigger-docs-patrol.yml Documentation patrol workflow
.github/workflows/trigger-bug-hunter.yml Bug hunter workflow
.github/workflows/trigger-breaking-change-detector.yml Breaking-change workflow
.github/workflows/sweep-ingest-pipeline-safety.yml Ingest safety workflow
.github/workflows/sweep-field-mapping-conflicts.yml Field mapping workflow
.github/workflows/sweep-dashboard-data-scope.yml Dashboard scope workflow
.github/workflows/requires-update.yml Update requirement workflow
.github/workflows/pr-buildkite-detective.yml Buildkite detective workflow
.github/workflows/notify-package-docs-failure.yml Documentation failure notification
.github/workflows/docs-preview-cleanup.yml Preview cleanup workflow
.github/workflows/docs-deploy.yml Documentation deployment
.github/workflows/docs-build.yml Documentation build
.github/workflows/ci-comment.yml CI comment workflow
.github/workflows/catalog-info.yml Catalog metadata workflow
.github/workflows/bump-elastic-stack-version.yml Stack version updates
.github/workflows/backport-packages-detect.yml Backport package detection
.github/actions/sync-backport-changelog/action.yml Changelog synchronization action
.buildkite/scripts/trigger_backport.sh Backport trigger script
.buildkite/scripts/test_one_package.sh Single-package test script
.buildkite/scripts/test_integrations_with_serverless.sh Serverless integration tests
.buildkite/scripts/test_helpers.sh Buildkite test helpers
.buildkite/scripts/test_check_backport_owners.sh Backport owner checks
.buildkite/scripts/run_dev_scripts_tests.sh Developer script tests
.buildkite/scripts/run_buildkite_scripts_tests.sh Buildkite script tests
.buildkite/scripts/requirements-ci-python-scripts.txt CI Python dependencies
.buildkite/scripts/report_issues.sh Issue reporting script
.buildkite/scripts/process_benchmarks.sh Benchmark processing
.buildkite/scripts/packages/security_detection_engine.sh Security package testing
.buildkite/scripts/packages/crowdstrike.sh CrowdStrike package testing
.buildkite/scripts/notify_backport_pr.sh Backport PR notifications
.buildkite/scripts/non_package_patterns.txt Non-package path patterns
.buildkite/scripts/find_oldest_supported_version.py Supported-version detection
.buildkite/scripts/check_sources.sh Source validation
.buildkite/scripts/check_changelog_versions_in_main.sh Changelog version checks
.buildkite/scripts/check_backports_inventory.sh Backport inventory checks
.buildkite/scripts/check_backport_tool.sh Backport tool checks
.buildkite/scripts/build_packages.sh Package builds
.buildkite/scripts/backport_branch_lib.sh Backport branch helpers
.buildkite/pull-requests.json Pull request configuration
.buildkite/pipeline.serverless.yml Serverless pipeline
.buildkite/pipeline.schedule-weekly.yml Weekly scheduled pipeline
.buildkite/pipeline.schedule-daily.yml Daily scheduled pipeline
.buildkite/pipeline.publish.yml Publishing pipeline
.buildkite/pipeline.backport.yml Backport pipeline
.buildkite/pipeline.backport-dispatch.yml Backport dispatch pipeline
.buildkite/hooks/pre-exit Buildkite exit hook
.buildkite/hooks/post-checkout Buildkite checkout hook
Review details

Suppressed comments (18)

.buildkite/pipeline.yml:168

  • This makes the owner check non-blocking: check_backport_owners.sh exits 1 when it finds mismatches, but soft_fail: true lets the Buildkite build (and therefore the backport PR) pass anyway. Since this check is intended to enforce owner synchronization on PRs targeting backport branches, remove the soft-fail setting or set it to false.
    .buildkite/scripts/backport_branch.sh:172
  • git rm --cached removes only the index entry and leaves backport-only tracked files in the worktree; the following git add .buildkite stages those stale files again. This means the branch is not synced verbatim from main and obsolete CI scripts can persist. Remove the tracked directory from both index and worktree before checking out main (and apply the same change to the other directory syncs below).
    .buildkite/scripts/backport_branch.sh:214
  • As with the .buildkite sync above, --cached leaves tracked files that exist only on the backport branch in the worktree, and git add cmd/backport re-adds them. Obsolete files can therefore survive the supposed copy from main; remove the directory from the worktree as well before checking it out.
    .buildkite/scripts/backport_branch.sh:219
  • --cached leaves tracked files absent from main in the worktree, and the later git add dev stages them again. The dev/ tree can consequently retain obsolete scripts despite this sync; remove the tracked directory from the worktree before checking out main.
    .buildkite/scripts/backport_branch.sh:245
  • --cached leaves tracked workflows that were removed from main in the worktree, and git add .github/workflows stages them back into the branch. This can preserve obsolete workflows and violates the stated verbatim sync; remove the tracked directory from the worktree before checking out main.
    .buildkite/scripts/backport_branch.sh:250
  • --cached leaves tracked actions absent from main in the worktree, and the subsequent git add .github/actions stages them again. Obsolete actions can therefore survive this sync; remove the tracked directory from the worktree before checking out main.
    .buildkite/scripts/test_integrations_with_serverless.sh:102
  • This duplicates the same grep -q/pipefail hazard in the serverless matrix: a sufficiently large changed-file list can cause SIGPIPE and silently drop the matching package. Replace both quiet greps with non-quiet greps redirected to /dev/null, as done elsewhere in common.sh.
    .buildkite/scripts/trigger_integrations_in_parallel.sh:70
  • These grep -q pipelines run with pipefail; when a large changed-file list exceeds the pipe buffer, grep can exit after the first match and echo can receive SIGPIPE, making the condition false. That can omit an affected package from the generated test matrix. Use the existing no--q pattern (grep -E ... > /dev/null) here.
    .github/workflows/auto-backport.yml:108
  • The issue-comment path never verifies that the merged PR targets main (the push path does). A marker-containing comment on a merged PR targeting another branch can therefore enter the backport processor and use that PR's merge commit as the source. Include baseRefName in this query and skip unless it is main.
    .github/workflows/post-backport-checklist.yml:107
  • When the last active branch disappears, render-checklist intentionally returns an empty body, but this early exit leaves COMMENT_ID untouched. The old checklist can then continue to show stale checked branches and remain eligible for auto-backport processing; delete the existing comment when COMMENT_ID is non-empty before exiting.
    .github/workflows/validate-yaml-dashboards.yml:172
  • This extracts only the first path segment after packages/. For a supported nested package such as packages/technology/p1/_dev/shared/kibana, it compiles into packages/technology/kibana/dashboard instead of packages/technology/p1/kibana/dashboard, so valid nested-package dashboards are reported as out of sync. Derive the package root by removing /_dev/... from input_dir.
    cmd/backport/backports/apply/apply.go:703
  • commitOwnerSync stages manifest.yml before it stages CODEOWNERS and may fail after either operation. git checkout -- restores the worktree from the index, so it preserves any staged owner changes instead of restoring HEAD; a best-effort sync failure can therefore leave a partial staged change and prevent the caller from returning to a clean branch. Restore both the index and worktree from HEAD (for example with git restore --source=HEAD --staged --worktree -- ...).
    cmd/backport/backports/apply/apply.go:943
  • A full branch target is accepted based only on the generic regex; it is never checked against packageName. This allows --package aws --target backport-prometheus-6.14 to resolve and apply an AWS commit onto Prometheus' backport branch. Validate full targets with backports.ValidateBranchName(packageName, target) before returning them.
    cmd/backport/backports/apply/apply.go:214
  • On the successful non-dry-run path this checks out the original branch but never deletes workingBranch, even though the cleanup comment says retries should not fail with “branch already exists” and the next comment says local presence is no longer needed. A second invocation with the same SHA in the same checkout therefore fails at checkout -b; delete the local working branch after successfully restoring the original branch.
    cmd/backport/backports/packages/detect.go:35
  • The changed paths passed by git diff --name-only use /, while filepath.Separator is \ on Windows and ListPackagesWithNames returns OS-native paths. On Windows this makes every strings.HasPrefix check fail, so detect-packages and check-owners can silently report no packages; normalize both sides with filepath.ToSlash before comparing.
    cmd/backport/main.go:51
  • The documented order allows backport check-active <branch> --json, but Go's flag.FlagSet stops parsing when it reaches <branch>, so --json is treated as an extra positional argument and JSON output is silently disabled. Document the supported flag-before-argument order (or use a parser that accepts both orders).
    cmd/backport/main.go:56
  • The usage text places --json after the positional arguments, but runDetectPackages uses Go's flag.FlagSet, which stops parsing at the first positional argument. Following this documented form therefore emits plain output instead of JSON; show the supported flag-before-argument order (or change parsing to accept both).
    dev/scripts/backport_apply.sh:53
  • usage() always exits 1, so -h|--help reports failure and the wrapper's help command cannot succeed. Pass an explicit zero status for the help case (while retaining status 1 for invalid/missing arguments).
  • Files reviewed: 174/193 changed files
  • Comments generated: 5
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

PR_AUTHOR: ${{ steps.resolve.outputs.pr_author }}
COMMENT_ID: ${{ steps.find-comment.outputs.comment_id }}
BODY_FILE: ${{ steps.find-comment.outputs.body_file }}
run: .github/scripts/backport/process-checked-branches.sh
}

// branchRE matches valid backport branch names (mirrors cmd/backport/backports/inventory.go).
var branchRE = regexp.MustCompile(`^backport-[a-zA-Z0-9_]+-[0-9][0-9.]*x?$`)
Comment on lines +157 to +160
if echo "${stripped}" | grep -qE '^.+-[0-9]+\.[0-9]+(\.[0-9]+)?$'; then
pkg="$(echo "${stripped}" | sed -E 's/-([0-9]+\.[0-9]+(\.[0-9]+)?)$//')"
ver_suffix="$(echo "${stripped}" | sed -E 's/^.*-([0-9]+\.[0-9]+(\.[0-9]+)?)$/\1/')"
fi
Comment on lines +7 to +22
usage() {
echo "Usage: $0 -p <package_name> -v <version>" >&2
exit 1
}

PACKAGE_NAME=""
VERSION=""

while getopts ":p:v:h" opt; do
case "${opt}" in
p) PACKAGE_NAME="${OPTARG}" ;;
v) VERSION="${OPTARG}" ;;
h)
usage
exit 0
;;
@@ -0,0 +1,85 @@
#!/usr/bin/env bash
# Finds the commit on main where a package version was released.
# Usage: ./get_release_commit.sh <package_name> <version>
@mrodm
mrodm merged commit 5418dd4 into elastic:backport-cloud_security_posture-1.7 Sep 15, 2026
9 of 10 checks passed
@mrodm
mrodm deleted the sync-ci-configuration-cloud_security_posture-1.7 branch September 15, 2026 14:57
@github-actions

Copy link
Copy Markdown
Contributor

Changelog sync skipped — all changelog versions are already present on main.

@qcorporation qcorporation added the documentation Improvements or additions to documentation. Applied to PRs that modify *.md files. label Sep 15, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation. Applied to PRs that modify *.md files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants