Skip to content

Commit 82180de

Browse files
committed
Merge remote-tracking branch 'upstream/master' into fix-debian-conffiles
2 parents 675b0f7 + 9aee1f5 commit 82180de

304 files changed

Lines changed: 14981 additions & 2419 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎.github/CODEOWNERS‎

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,13 @@
11
* @vectordotdev/vector
22

3-
.github/workflows/regression.yml @vectordotdev/vector @vectordotdev/single-machine-performance
4-
regression/config.yaml @vectordotdev/vector @vectordotdev/single-machine-performance
3+
/.github/workflows/regression.yml @vectordotdev/vector @vectordotdev/single-machine-performance
4+
/regression/config.yaml @vectordotdev/vector @vectordotdev/single-machine-performance
55

6-
tests/antithesis/ @vectordotdev/vector @vectordotdev/single-machine-performance
6+
/tests/antithesis/ @vectordotdev/vector @vectordotdev/single-machine-performance
77

88
# Keep documentation team paths in sync with .github/workflows/add_docs_review_label.yml
99
/*.md @vectordotdev/vector @vectordotdev/documentation
10-
docs/ @vectordotdev/vector @vectordotdev/documentation
11-
deprecation.d/ @vectordotdev/vector @vectordotdev/documentation
12-
website/content @vectordotdev/vector @vectordotdev/documentation
13-
website/cue/reference @vectordotdev/vector @vectordotdev/documentation
10+
/docs/ @vectordotdev/vector @vectordotdev/documentation
11+
/deprecation.d/ @vectordotdev/vector @vectordotdev/documentation
12+
/website/content/ @vectordotdev/vector @vectordotdev/documentation
13+
/website/cue/reference/ @vectordotdev/vector @vectordotdev/documentation

‎.github/ISSUE_TEMPLATE/minor-release.md‎

Lines changed: 28 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -16,15 +16,22 @@ export RELEASE_BRANCH="v${NEW_VECTOR_VERSION%.*}"
1616

1717
- [ ] Cut a new release of [VRL](https://github.com/vectordotdev/vrl) if needed.
1818
- VRL release steps: https://github.com/vectordotdev/vrl/blob/main/release/README.md
19-
- [ ] Set the `Release freeze` ruleset to **Active** in [repository rulesets](https://github.com/vectordotdev/vector/settings/rules).
2019
- [ ] Run the [Prepare release](https://github.com/vectordotdev/vector/actions/workflows/release_prepare.yml)
2120
workflow from `master` with `version` set to the stable Vector version and `vrl_version` to the exact released VRL version.
21+
- The workflow activates the `RELEASE_FREEZE_RULESET_ID` ruleset and grants `vectordotdev-bot` an **Always** bypass
22+
to some of `master`'s rulesets (`RELEASE_FREEZE_BOT_BYPASS`).
23+
- If preparation fails after activation, the freeze remains active. Retry, or run
24+
[Unfreeze master](https://github.com/vectordotdev/vector/actions/workflows/release_unfreeze.yml)
25+
with `workflow_dispatch` to unfreeze the repository.
2226
- [ ] Review the bot-authored `prepare-v-<major>-<minor>-<patch>-website` PR: edit the release description,
2327
changelog, upgrade guidance, and release date as needed. Review deprecations with
2428
`cargo vdev deprecation show --version "${NEW_VECTOR_VERSION}"`.
2529

26-
Keep the freeze active until housekeeping has merged. Maintainers with bypass access must also
27-
respect this window: do not merge unrelated PRs into `master`.
30+
Keep the freeze active until **both** the release workflow has pushed its post-release housekeeping
31+
to `master` **and** the Kubernetes manifests push below has completed. Maintainers with
32+
bypass access must also respect this window: do not merge unrelated PRs into `master`.
33+
[Unfreeze master](https://github.com/vectordotdev/vector/actions/workflows/release_unfreeze.yml)
34+
closes the window automatically once both are done.
2835

2936
# Publish the release
3037

@@ -46,12 +53,26 @@ The tag starts the release workflow; do not create the tag or release branch man
4653
- The Vector release workflow starts [Helm release preparation](https://github.com/vectordotdev/helm-charts/actions/workflows/release-prepare.yml)
4754
automatically for the latest stable Vector release.
4855
- See [releasing Helm chart](https://github.com/vectordotdev/helm-charts/blob/develop/RELEASING.md) for the review steps.
49-
- [ ] Release Homebrew. Refer to the internal releasing doc.
56+
- [ ] Wait for the [Homebrew release](https://github.com/vectordotdev/homebrew-brew/actions/workflows/release.yml) to complete.
57+
- The Vector release workflow starts it automatically after publishing a stable release.
58+
It updates the ARM64 formula and commits directly to the tap's default branch, without a PR.
5059
- [ ] Update the latest [release tag](https://github.com/vectordotdev/vector/releases) description with the release announcement.
5160

5261
# Post-release housekeeping
5362

54-
- [ ] Wait for the release workflow to merge its housekeeping PR after checks pass.
63+
- [ ] Wait for the release workflow to push its post-release housekeeping directly to `master`.
5564
It begins the next minor `-dev` version, restores VRL `main`, and refreshes licenses and documentation.
56-
- [ ] Set the `Release freeze` ruleset back to **Disabled**.
57-
- [ ] Run `cargo vdev build manifests` after the Helm chart release and open a separate PR with the changes.
65+
- [ ] Wait for the Helm chart release to push the Kubernetes manifests directly to `master`.
66+
- The chart release triggers [Refresh Kubernetes manifests](https://github.com/vectordotdev/vector/actions/workflows/release_manifests.yml),
67+
which runs `cargo vdev build manifests` and, when the generated manifests differ,
68+
commits and pushes them to `master` itself as the `vectordotdev-bot` — no PR, no review,
69+
no merge queue. If the run reports no changes, the manifests already match the chart.
70+
- [ ] Wait for the [Unfreeze master](https://github.com/vectordotdev/vector/actions/workflows/release_unfreeze.yml)
71+
workflow to close the direct-push window after the manifests run succeeds.
72+
- It removes the temporary `vectordotdev-bot` **Always** bypass from every ruleset in
73+
`RELEASE_FREEZE_BOT_BYPASS`, then sets the `RELEASE_FREEZE_RULESET_ID` ruleset back to **Disabled**.
74+
It waits for the "Release Suite" run and any pending release workflow first,
75+
and gives up after ten minutes, leaving the freeze active.
76+
- Run it manually with `workflow_dispatch` if the release never starts the manifests workflow, if that
77+
run fails, or to retry a failed closeout.
78+
A manual run makes the same checks unless you set `force`, which closes the window anyway.

‎.github/ISSUE_TEMPLATE/patch-release.md‎

Lines changed: 15 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -61,8 +61,21 @@ export PREP_BRANCH=prepare-v-0-"${CURRENT_MINOR_VERSION}"-"${NEW_PATCH_VERSION}"
6161
- The Vector release workflow starts [Helm release preparation](https://github.com/vectordotdev/helm-charts/actions/workflows/release-prepare.yml)
6262
automatically for the latest stable Vector release.
6363
- See [releasing Helm chart](https://github.com/vectordotdev/helm-charts/blob/develop/RELEASING.md) for the review steps.
64-
- [ ] Once Helm chart is released, updated Vector manifests
65-
- Run `cargo vdev build manifests` and open a PR with changes
64+
- [ ] Once the Helm chart is released, wait for the Kubernetes manifests push to `master`.
65+
- The chart release triggers [Refresh Kubernetes manifests](https://github.com/vectordotdev/vector/actions/workflows/release_manifests.yml),
66+
which runs `cargo vdev build manifests` and, when the generated manifests differ,
67+
commits and pushes them to `master` itself as the `vectordotdev-bot` — no PR, no review,
68+
no merge queue. If the run reports no changes, the manifests already match the chart.
69+
- [ ] Wait for the [Unfreeze master](https://github.com/vectordotdev/vector/actions/workflows/release_unfreeze.yml)
70+
workflow to close the direct-push window after the manifests run succeeds.
71+
- It removes the temporary `vectordotdev-bot` **Always** bypass from every ruleset in
72+
`RELEASE_FREEZE_BOT_BYPASS`, then sets the `RELEASE_FREEZE_RULESET_ID` ruleset back to **Disabled**.
73+
It waits for any pending release or manifests run and for open `vectordotdev-bot` PRs first,
74+
and gives up after ten minutes, leaving the freeze active.
75+
- Run it manually with `workflow_dispatch` if the release never starts the manifests workflow, if that
76+
run fails, or to retry a failed closeout.
77+
A manual run makes the same checks unless you set `force`, which closes the window anyway.
78+
6679
- [ ] Cherry-pick any release commits from the release branch that are not on `master`, to `master`
6780
- [ ] Wait for the release workflow to reset the `website` branch to the release commit
6881
(`refs/heads/website` is force-pushed to the release branch HEAD) to update

‎.github/actionlint.yaml‎

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
self-hosted-runner:
2+
labels:
3+
- ubuntu-24.04-8core
4+
- ubuntu-24.04-8core-arm
5+
- release-builder-linux
6+
- windows-2025-8core
Lines changed: 132 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,132 @@
1+
name: Activate release freeze
2+
description: Freeze master and grant the release bot temporary direct-push bypasses.
3+
inputs:
4+
app-client-id:
5+
description: Client ID of the vectordotdev-bot GitHub App, which requires Administration write permission.
6+
required: true
7+
app-private-key:
8+
description: Private key of the vectordotdev-bot GitHub App.
9+
required: true
10+
freeze-ruleset-id:
11+
description: Repository variable RELEASE_FREEZE_RULESET_ID (the vars context is unavailable in composite actions).
12+
required: true
13+
bot-bypass-ruleset-ids:
14+
description: Repository variable RELEASE_FREEZE_BOT_BYPASS, comma-separated ruleset IDs (the vars context is unavailable in composite actions).
15+
required: true
16+
runs:
17+
using: composite
18+
steps:
19+
# Keep ruleset administration separate from tokens used to push release commits.
20+
- name: Create Vector bot token for ruleset updates
21+
id: bot-token
22+
uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0
23+
with:
24+
client-id: ${{ inputs.app-client-id }}
25+
private-key: ${{ inputs.app-private-key }}
26+
permission-administration: write
27+
permission-contents: read
28+
29+
- name: Activate freeze and configure bot bypasses
30+
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
31+
env:
32+
BOT_APP_SLUG: ${{ steps.bot-token.outputs.app-slug }}
33+
RELEASE_FREEZE_RULESET_ID: ${{ inputs.freeze-ruleset-id }}
34+
RELEASE_FREEZE_BOT_BYPASS: ${{ inputs.bot-bypass-ruleset-ids }}
35+
with:
36+
github-token: ${{ steps.bot-token.outputs.token }}
37+
script: |
38+
if (process.env.BOT_APP_SLUG !== "vectordotdev-bot") {
39+
throw new Error("Release freeze activation requires the vectordotdev-bot GitHub App.");
40+
}
41+
const { readRulesetIds, isBotActor, hasBotBypass, restrictsMasterUpdates, canManageReleaseBypass } =
42+
require("./.github/actions/require-release-freeze/rulesets.js");
43+
const { freezeId, bypassIds } = readRulesetIds(process.env);
44+
const { data: app } = await github.request("GET /apps/{app_slug}", {
45+
app_slug: process.env.BOT_APP_SLUG,
46+
});
47+
const { data: repository } = await github.request("GET /repos/{owner}/{repo}", context.repo);
48+
const branchRules = () => github.paginate(
49+
"GET /repos/{owner}/{repo}/rules/branches/{branch}",
50+
{ ...context.repo, branch: "master" },
51+
);
52+
const rules = await branchRules();
53+
// Include configured IDs even when disabled or not effective on master,
54+
// so invalid configuration fails instead of silently skipping a ruleset.
55+
const ids = new Set([freezeId, ...bypassIds, ...rules.map((rule) => rule.ruleset_id)]);
56+
const details = await Promise.all([...ids].map(async (id) => {
57+
const { data } = await github.request(
58+
"GET /repos/{owner}/{repo}/rulesets/{ruleset_id}",
59+
{ ...context.repo, ruleset_id: id, includes_parents: true },
60+
);
61+
return data;
62+
}));
63+
const byId = new Map(details.map((ruleset) => [ruleset.id, ruleset]));
64+
const freeze = byId.get(freezeId);
65+
if (!["active", "disabled"].includes(freeze.enforcement) ||
66+
!restrictsMasterUpdates(freeze, repository.default_branch) || !hasBotBypass(freeze, app.id)) {
67+
throw new Error(`Ruleset ${freezeId} must restrict master updates and already permit direct bot pushes.`);
68+
}
69+
for (const type of ["non_fast_forward", "deletion"]) {
70+
if (!rules.some((rule) => rule.type === type && byId.get(rule.ruleset_id)?.bypass_actors?.length === 0)) {
71+
throw new Error(`master must retain an active ${type} rule without bypass actors.`);
72+
}
73+
}
74+
75+
const pushSafe = new Set(["creation", "deletion", "non_fast_forward", "required_linear_history"]);
76+
const updates = [];
77+
for (const id of bypassIds) {
78+
const ruleset = byId.get(id);
79+
// A ruleset bypass applies to every rule and branch in that ruleset.
80+
// Do not broaden it to other branches, inherited policy, or safety rules.
81+
if (!canManageReleaseBypass(ruleset, repository.default_branch) || !rules.some((rule) => rule.ruleset_id === id)) {
82+
throw new Error(`Cannot safely grant a release bypass to configured ruleset ${id} (${ruleset.name}). It must be active and contain only master release policy.`);
83+
}
84+
if (!Array.isArray(ruleset.bypass_actors)) {
85+
throw new Error(`Cannot read bypass actors for ruleset ${id} (${ruleset.name}).`);
86+
}
87+
if (!hasBotBypass(ruleset, app.id)) {
88+
updates.push(ruleset);
89+
}
90+
}
91+
for (const rule of rules) {
92+
if (!pushSafe.has(rule.type) && rule.ruleset_id !== freezeId &&
93+
!bypassIds.includes(rule.ruleset_id) && !hasBotBypass(byId.get(rule.ruleset_id), app.id)) {
94+
throw new Error(`Ruleset ${rule.ruleset_id} blocks direct pushes but is missing from RELEASE_FREEZE_BOT_BYPASS.`);
95+
}
96+
}
97+
98+
// Freeze first. If a later update fails, leave master frozen; a retry
99+
// completes the remaining bypasses without duplicating existing actors.
100+
// Only toggle enforcement: Release freeze keeps its existing bypass actors.
101+
if (freeze.enforcement !== "active") {
102+
await github.request("PUT /repos/{owner}/{repo}/rulesets/{ruleset_id}", {
103+
...context.repo,
104+
ruleset_id: freeze.id,
105+
enforcement: "active",
106+
});
107+
}
108+
if (!(await branchRules()).some((rule) => rule.ruleset_id === freeze.id && rule.type === "update")) {
109+
throw new Error("Release freeze must restrict updates to master before granting bot bypasses.");
110+
}
111+
for (const ruleset of updates) {
112+
// Update only the bot's bypass, never the freeze or safety policies.
113+
await github.request("PUT /repos/{owner}/{repo}/rulesets/{ruleset_id}", {
114+
...context.repo,
115+
ruleset_id: ruleset.id,
116+
bypass_actors: [
117+
...ruleset.bypass_actors.filter((actor) => !isBotActor(actor, app.id)),
118+
{ actor_id: app.id, actor_type: "Integration", bypass_mode: "always" },
119+
],
120+
});
121+
core.info(`Granted release bypass on ruleset ${ruleset.id} (${ruleset.name}).`);
122+
}
123+
124+
# Check effective permissions with a contents-only token, not the privileged
125+
# administration token used above. This also checks inherited rulesets.
126+
- name: Verify active release freeze
127+
uses: ./.github/actions/require-release-freeze
128+
with:
129+
app-client-id: ${{ inputs.app-client-id }}
130+
app-private-key: ${{ inputs.app-private-key }}
131+
freeze-ruleset-id: ${{ inputs.freeze-ruleset-id }}
132+
bot-bypass-ruleset-ids: ${{ inputs.bot-bypass-ruleset-ids }}

‎.github/actions/install-vrl-doc-builder/action.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@ name: "Install vector-vrl-doc-builder"
22
description: "Install vector-vrl-doc-builder CLI tool with caching based on source code changes"
33

44
branding:
5-
icon: tool
5+
icon: package
66
color: purple
77

88
runs:

0 commit comments

Comments
 (0)