058a31d Merge pull request #301 from kubernetes-csi/dependabot/github_actions/aquasecurity/trivy-action-0.36.0 50b1a35 Bump aquasecurity/trivy-action from 0.35.0 to 0.36.0 9092527 Merge pull request #298 from torredil/trivy-schedule-trigger 2c9aed3 Merge pull request #299 from andyzhangx/patch-12 507ea1e chore: fix broken gcb-docker-gcloud image ab1da0e Run Trivy scan on schedule instead of pull requests de06a09 Merge pull request #297 from andyzhangx/patch-11 fc719f3 fix: Update Go version from 1.25.8 to 1.25.9 c24a730 Merge pull request #296 from jsafrane/pin-github-actions-sha 59b456b fix: pin github action to exact SHA 061f6ee Merge pull request #295 from kubernetes-csi/security/update-trivy-action-v0.35.0 6c16f30 security: Update trivy-action to v0.35.0 119a53c Merge pull request #294 from andyzhangx/patch-10 7c9aa9b fix: upgrade to go1.25.7 to fix CVE-2026-25679 1e81e75 Merge pull request #293 from andyzhangx/patch-9 4dc1850 fix: upgrade to go1.25.7 to fix CVE-2025-61727 b60b9a5 Merge pull request #292 from andyzhangx/patch-8 0e4e2ed Update Go version from 1.25.5 to 1.25.6 to fix CVE 707a99e Merge pull request #291 from dfajmon/logcheck a9d2b0f Bump logcheck to v0.10.0 d684663 Merge pull request #290 from dfajmon/go-1.25.5 55e527c Bump golang to 1.25.5 b12e407 Merge pull request #289 from nixpanic/k8s-v1.34 bbe5e54 Use Kubernetes v1.34 and Kind v0.30 by default 4e9eb2c Merge pull request #288 from gnufied/add-gnufied-for-csi-approver 064e260 Add myself as csi approver c852fa7 Merge pull request #287 from andyzhangx/patch-7 bce16c1 fix: upgrade to go1.24.11 to fix CVE-2025-61727 8d1258c Merge pull request #286 from kubernetes-csi/dependabot/github_actions/actions/checkout-6 91e3598 Bump actions/checkout from 5 to 6 2941381 Merge pull request #285 from andyzhangx/patch-6 fa8b339 fix: upgrade to go1.24.9 to fix CVEs 74502e5 Merge pull request #278 from liangyuanpeng/migrate_k8s_testimages 5334430 Merge pull request #281 from kubernetes-csi/dependabot/github_actions/actions/checkout-5 458ce14 Bump actions/checkout from 4 to 5 5f38a90 Merge pull request #282 from rhrmo/update-go-1.24.6 579f624 Update go to 1.24.6 5ec1a52 use gcr.io/k8s-staging-test-infra instead of gcr.io/k8s-testimages 74e066a Merge pull request #279 from Aishwarya-Hebbar/update-csi-prow-version 6f236be Update CSI prow driver version to v1.17.0 0ee5589 Merge pull request #280 from xing-yang/update_go_1.24.4 9af1015 update to go 1.24.4 f5fec3e Merge pull request #275 from chrishenzie/emeritus c5d285d Remove chrishenzie from kubernetes-csi-reviewers 0a435bf Merge pull request #274 from andyzhangx/patch-5 cd7b4bb Bump golang to 1.24.2 to fix CVE-2025-22871 701dc34 Merge pull request #273 from andyzhangx/patch-4 aeebd30 Bump golang to 1.24.0 f277d56 Merge pull request #270 from carlory/update-kind-version 90efb2c Merge pull request #272 from andyzhangx/patch-3 9b616fe Bump golang to 1.23.6 to fix CVE-2024-45336, CVE-2025-22866 6dcb96a update default kind version to v0.25.0 0496593 Merge pull request #268 from huww98/cloudbuild 119aee1 Merge pull request #266 from jsafrane/bump-sanity-5.3.1 0ae5e52 Update cloudbuild image with go 1.21+ 406a79a Merge pull request #267 from huww98/gomodcache 9cec273 Set GOMODCACHE to avoid re-download toolchain 98f2307 Merge pull request #260 from TerryHowe/update-csi-driver-version e9d8712 Merge pull request #259 from stmcginnis/deprecated-kind-kube-root faf79ff Remove --kube-root deprecated kind argument 734c2b9 Merge pull request #265 from Rakshith-R/consider-main-branch 43bde06 Bump csi-sanity to 5.3.1 f95c855 Merge pull request #262 from huww98/golang-toolchain 3c8d966 Treat main branch as equivalent to master branch e31de52 Merge pull request #261 from huww98/golang fd153a9 Bump golang to 1.23.1 a8b3d05 pull-test.sh: fix "git subtree pull" errors 6b05f0f use new GOTOOLCHAIN env to manage go version 18b6ac6 chore: update CSI driver version to 1.15 227577e Merge pull request #258 from gnufied/enable-race-detection e1ceee2 Always enable race detection while running tests 988496a Merge pull request #257 from jakobmoellerdev/csi-prow-sidecar-e2e-path 028f8c6 chore: bump to Go 1.22.5 69bd71e chore: add CSI_PROW_SIDECAR_E2E_PATH f40f0cc Merge pull request #256 from solumath/master cfa9210 Instruction update 379a1bb Merge pull request #255 from humblec/sidecar-md a5667bb fix typo in sidecar release process 4967685 Merge pull request #254 from bells17/add-github-actions d9bd160 Update skip list in codespell GitHub Action adb3af9 Merge pull request #252 from bells17/update-go-version f5aebfc Add GitHub Actions workflows b82ee38 Merge pull request #253 from bells17/fix-typo c317456 Fix typo 0a78505 Bump to Go 1.22.3 edd89ad Merge pull request #251 from jsafrane/add-logcheck 043fd09 Add test-logcheck target d7535ae Merge pull request #250 from jsafrane/go-1.22 b52e7ad Update go to 1.22.2 14fdb6f Merge pull request #247 from msau42/prow dc4d0ae Merge pull request #249 from jsafrane/use-go-version e681b17 Use .go-version to get Kubernetes go version 9b4352e Update release playbook c7bb972 Fix release notes script to use fixed tags 463a0e9 Add script to update specific go modules b54c1ba Merge pull request #246 from xing-yang/go_1.21 5436c81 Change go version to 1.21.5 267b40e Merge pull request #244 from carlory/sig-storage b42e5a2 nominate self (carlory) as kubernetes-csi reviewer a17f536 Merge pull request #210 from sunnylovestiramisu/sidecar 011033d Use set -x instead of die 5deaf66 Add wrapper script for sidecar release f8c8cc4 Merge pull request #237 from msau42/prow b36b5bf Merge pull request #240 from dannawang0221/upgrade-go-version adfddcc Merge pull request #243 from pohly/git-subtree-pull-fix c465088 pull-test.sh: avoid "git subtree pull" error 7b175a1 Update csi-test version to v5.2.0 987c90c Update go version to 1.21 to match k/k 2c625d4 Add script to generate patch release notes f9d5b9c Merge pull request #236 from mowangdk/feature/bump_csi-driver-host-path_version b01fd53 Bump csi-driver-host-path version up to v1.12.0 984feec Merge pull request #234 from siddhikhapare/csi-tools 1f7e605 fixed broken links of testgrid dashboard de2fba8 Merge pull request #233 from andyzhangx/andyzhangx-patch-1 cee895e remove windows 20H2 build since it's EOL long time ago 670bb0e Merge pull request #229 from marosset/fix-codespell-errors 35d5e78 Merge pull request #219 from yashsingh74/update-registry 63473cc Merge pull request #231 from coulof/bump-go-version-1.20.5 29a5c76 Merge pull request #228 from mowangdk/chore/adopt_kubernetes_recommand_labels 8dd2821 Update cloudbuild image with go 1.20.5 1df23db Merge pull request #230 from msau42/prow 1f92b7e Add ginkgo timeout to e2e tests to help catch any stuck tests 2b8b80e fixing some codespell errors c10b678 Merge pull request #227 from coulof/check-sidecar-supported-versions 72984ec chore: adopt kubernetes recommand label b055535 Header bd0a10b typo c39d73c Add comments f6491af Script to verify EOL sidecar version 4133d1d Merge pull request #226 from msau42/cloudbuild 8d519d2 Pin buildkit to v0.10.6 to workaround v0.11 bug with docker manifest 6e04a03 Merge pull request #224 from msau42/cloudbuild 26fdfff Update cloudbuild image 6613c39 Merge pull request #223 from sunnylovestiramisu/update 0e7ae99 Update k8s image repo url 77e47cc Merge pull request #222 from xinydev/fix-dep-version 155854b Fix dep version mismatch 8f83905 Merge pull request #221 from sunnylovestiramisu/go-update 1d3f94d Update go version to 1.20 to match k/k v1.27 e322ce5 Merge pull request #220 from andyzhangx/fix-golint-error b74a512 test: fix golint error 901bcb5 Update registry k8s.gcr.io -> registry.k8s.io aa61bfd Merge pull request #218 from xing-yang/update_csi_driver 7563d19 Update CSI_PROW_DRIVER_VERSION to v1.11.0 a2171be Merge pull request #216 from msau42/process cb98782 Merge pull request #217 from msau42/owners a11216e add new reviewers and remove inactive reviewers dd98675 Add step for checking builds b66c082 Merge pull request #214 from pohly/junit-fixes b9b6763 filter-junit.go: fix loss of testcases when parsing Ginkgo v2 JUnit d427783 filter-junit.go: preserve system error log 38e1146 prow.sh: publish individual JUnit files as separate artifacts git-subtree-dir: release-tools git-subtree-split: 058a31d3181dee31a4cd5de420108e6ce210d40e |
||
|---|---|---|
| .github | ||
| boilerplate | ||
| contrib | ||
| .prow.sh | ||
| CONTRIBUTING.md | ||
| KUBERNETES_CSI_OWNERS_ALIASES | ||
| LICENSE | ||
| OWNERS | ||
| OWNERS_ALIASES | ||
| README.md | ||
| RELEASE.md | ||
| SECURITY_CONTACTS | ||
| SIDECAR_RELEASE_PROCESS.md | ||
| build.make | ||
| cloudbuild.sh | ||
| cloudbuild.yaml | ||
| code-of-conduct.md | ||
| filter-junit.go | ||
| generate-patch-release-notes.sh | ||
| go-get-kubernetes.sh | ||
| go-modules-targeted-update.sh | ||
| go-modules-update.sh | ||
| prow.sh | ||
| pull-test.sh | ||
| update-vendor.sh | ||
| util.sh | ||
| verify-boilerplate.sh | ||
| verify-go-version.sh | ||
| verify-logcheck.sh | ||
| verify-shellcheck.sh | ||
| verify-spelling.sh | ||
| verify-subtree.sh | ||
| verify-vendor.sh | ||
README.md
csi-release-tools
These build and test rules can be shared between different Go projects without modifications. Customization for the different projects happen in the top-level Makefile.
The rules include support for building and pushing Docker images, with the following features:
- one or more command and image per project
- push canary and/or tagged release images
- automatically derive the image tag(s) from repo tags
- the source code revision is stored in a "revision" image label
- never overwrites an existing release image
Usage
The expected repository layout is:
cmd/*/*.go- source code for each commandcmd/*/Dockerfile- docker file for each command or Dockerfile in the root when only building a single commandMakefile- includesrelease-tools/build.makeand sets configuration variables.prow.shscript which importsrelease-tools/prow.shand may contain further customization.cloudbuild.shandcloudbuild.yamlas symlinks to the corresponding files inrelease-toolsor (if necessary) as custom files
To create a release, tag a certain revision with a name that
starts with v, for example v1.0.0, then make push
while that commit is checked out.
It does not matter on which branch that revision exists, i.e. it is possible to create releases directly from master. A release branch can still be created for maintenance releases later if needed.
Release branches are expected to be named release-x.y for releases
x.y.z. Building from such a branch creates x.y-canary
images. Building from master creates the main canary image.
Sharing and updating
git subtree
is the recommended way of maintaining a copy of the rules inside the
release-tools directory of a project. This way, it is possible to make
changes also locally, test them and then push them back to the shared
repository at a later time.
We no longer care about importing the full commit history, so --squash should be used
when submitting a release-tools update. Also make sure that the PR for that
contains the automatically generated commit message in the PR description.
It contains the list of individual commits that were squashed. The script from
https://github.com/kubernetes-csi/csi-release-tools/issues/7 can create such
PRs automatically.
Cheat sheet:
git subtree add --squash --prefix=release-tools https://github.com/kubernetes-csi/csi-release-tools.git master- add release tools to a repo which does not have them yet (only once)git subtree pull --squash --prefix=release-tools https://github.com/kubernetes-csi/csi-release-tools.git master- update local copy to latest upstream (whenever upstream changes)- edit,
git commit,git subtree push --prefix=release-tools git@github.com:<user>/csi-release-tools.git <my-new-or-existing-branch>- push to a new branch before submitting a PR
verify-shellcheck.sh
The verify-shellcheck.sh script in this repo
is a stripped down copy of the corresponding
script
in the Kubernetes repository. It can be used to check for certain
errors shell scripts, like missing quotation marks. The default
test-shellcheck target in build.make only checks the
scripts in this directory. Components can add more directories to
TEST_SHELLCHECK_DIRS to check also other scripts.
End-to-end testing
A repo that wants to opt into testing via Prow must set up a top-level
.prow.sh. Typically that will source prow.sh and then transfer
control to it:
#! /bin/bash -e
. release-tools/prow.sh
main
All Kubernetes-CSI repos are expected to switch to Prow. For details on what is enabled in Prow, see https://github.com/kubernetes/test-infra/tree/HEAD/config/jobs/kubernetes-csi
Test results for periodic jobs are visible in https://testgrid.k8s.io/sig-storage-csi-ci
It is possible to reproduce the Prow testing locally on a suitable machine:
- Linux host
- Docker installed
- code to be tested checkout out in
$GOPATH/src/<import path> cd $GOPATH/src/<import path> && ./.prow.sh
Beware that the script intentionally doesn't clean up after itself and
modifies the content of $GOPATH, in particular the kubernetes and
kind repositories there. Better run it in an empty, disposable
$GOPATH.
When it terminates, the following command can be used to get access to the Kubernetes cluster that was brought up for testing (assuming that this step succeeded):
export KUBECONFIG="$(kind get kubeconfig-path --name="csi-prow")"
It is possible to control the execution via environment variables. See
prow.sh for details. Particularly useful is testing against different
Kubernetes releases:
CSI_PROW_KUBERNETES_VERSION=1.13.3 ./.prow.sh
CSI_PROW_KUBERNETES_VERSION=latest ./.prow.sh
Dependencies and vendoring
Most projects will (eventually) use go mod to manage
dependencies. dep is also still supported by csi-release-tools,
but not documented here because it's not recommended anymore.
The usual instructions for using go modules apply. Here's a cheat sheet for some of the relevant commands:
- list available updates:
GO111MODULE=on go list -u -m all - update or add a single dependency:
GO111MODULE=on go get <package> - update all dependencies to their next minor or patch release:
GO111MODULE=on go get ./...(add-u=patchto limit to patch releases) - lock onto a specific version:
GO111MODULE=on go get <package>@<version> - clean up
go.mod:GO111MODULE=on go mod tidy - update vendor directory:
GO111MODULE=on go mod vendor
GO111MODULE=on can be left out when using Go >= 1.13 or when the
source is checked out outside of $GOPATH.
go mod tidy must be used to ensure that the listed dependencies are
really still needed. Changing import statements or a tentative go get can result in stale dependencies.
The test-vendor verifies that it was used when run locally or in a
pre-merge CI job. If a vendor directory is present, it will also
verify that it's content is up-to-date.
The vendor directory is optional. It is still present in projects
because it avoids downloading sources during CI builds. If this is no
longer deemed necessary, then a project can also remove the directory.
Conversion of a repository that uses dep to go mod can be done with:
GO111MODULE=on go mod init
release-tools/go-get-kubernetes.sh <current Kubernetes version from Gopkg.toml>
GO111MODULE=on go mod tidy
GO111MODULE=on go mod vendor
git rm -f Gopkg.toml Gopkg.lock
git add go.mod go.sum vendor
Updating Kubernetes dependencies
When using packages that are part of the Kubernetes source code, the
commands above are not enough because the lack of semantic
versioning
prevents go mod from finding newer releases. Importing directly from
kubernetes/kubernetes also needs replace statements to override
the fake v0.0.0 versions
(https://github.com/kubernetes/kubernetes/issues/79384). The
go-get-kubernetes.sh script can be used to update all packages in
lockstep to a different Kubernetes version. Example usage:
$ ./release-tools/go-get-kubernetes.sh 1.16.4