Go to file
retornam bca0a9f535 Squashed 'release-tools/' changes from 78c0fb7..de06a09
de06a09 Merge pull request #297 from andyzhangx/patch-11
fc719f3 fix: Update Go version from 1.25.8 to 1.25.9
c24a730 Merge pull request #296 from jsafrane/pin-github-actions-sha
59b456b fix: pin github action to exact SHA
061f6ee Merge pull request #295 from kubernetes-csi/security/update-trivy-action-v0.35.0
6c16f30 security: Update trivy-action to v0.35.0
119a53c Merge pull request #294 from andyzhangx/patch-10
7c9aa9b fix: upgrade to go1.25.7 to fix CVE-2026-25679
1e81e75 Merge pull request #293 from andyzhangx/patch-9
4dc1850 fix: upgrade to go1.25.7 to fix CVE-2025-61727
b60b9a5 Merge pull request #292 from andyzhangx/patch-8
0e4e2ed Update Go version from 1.25.5 to 1.25.6 to fix CVE
707a99e Merge pull request #291 from dfajmon/logcheck
a9d2b0f Bump logcheck to v0.10.0
d684663 Merge pull request #290 from dfajmon/go-1.25.5
55e527c Bump golang to 1.25.5
b12e407 Merge pull request #289 from nixpanic/k8s-v1.34
bbe5e54 Use Kubernetes v1.34 and Kind v0.30 by default
4e9eb2c Merge pull request #288 from gnufied/add-gnufied-for-csi-approver
064e260 Add myself as csi approver
c852fa7 Merge pull request #287 from andyzhangx/patch-7
bce16c1 fix: upgrade to go1.24.11 to fix CVE-2025-61727
8d1258c Merge pull request #286 from kubernetes-csi/dependabot/github_actions/actions/checkout-6
91e3598 Bump actions/checkout from 5 to 6
2941381 Merge pull request #285 from andyzhangx/patch-6
fa8b339 fix: upgrade to go1.24.9 to fix CVEs
74502e5 Merge pull request #278 from liangyuanpeng/migrate_k8s_testimages
5334430 Merge pull request #281 from kubernetes-csi/dependabot/github_actions/actions/checkout-5
458ce14 Bump actions/checkout from 4 to 5
5f38a90 Merge pull request #282 from rhrmo/update-go-1.24.6
579f624 Update go to 1.24.6
5ec1a52 use gcr.io/k8s-staging-test-infra instead of gcr.io/k8s-testimages
74e066a Merge pull request #279 from Aishwarya-Hebbar/update-csi-prow-version
6f236be Update CSI prow driver version to v1.17.0
0ee5589 Merge pull request #280 from xing-yang/update_go_1.24.4
9af1015 update to go 1.24.4
f5fec3e Merge pull request #275 from chrishenzie/emeritus
c5d285d Remove chrishenzie from kubernetes-csi-reviewers
0a435bf Merge pull request #274 from andyzhangx/patch-5
cd7b4bb Bump golang to 1.24.2 to fix CVE-2025-22871
701dc34 Merge pull request #273 from andyzhangx/patch-4
aeebd30 Bump golang to 1.24.0
f277d56 Merge pull request #270 from carlory/update-kind-version
90efb2c Merge pull request #272 from andyzhangx/patch-3
9b616fe Bump golang to 1.23.6 to fix CVE-2024-45336, CVE-2025-22866
6dcb96a update default kind version to v0.25.0
0496593 Merge pull request #268 from huww98/cloudbuild
119aee1 Merge pull request #266 from jsafrane/bump-sanity-5.3.1
0ae5e52 Update cloudbuild image with go 1.21+
406a79a Merge pull request #267 from huww98/gomodcache
9cec273 Set GOMODCACHE to avoid re-download toolchain
98f2307 Merge pull request #260 from TerryHowe/update-csi-driver-version
e9d8712 Merge pull request #259 from stmcginnis/deprecated-kind-kube-root
faf79ff Remove --kube-root deprecated kind argument
734c2b9 Merge pull request #265 from Rakshith-R/consider-main-branch
43bde06 Bump csi-sanity to 5.3.1
f95c855 Merge pull request #262 from huww98/golang-toolchain
3c8d966 Treat main branch as equivalent to master branch
e31de52 Merge pull request #261 from huww98/golang
fd153a9 Bump golang to 1.23.1
a8b3d05 pull-test.sh: fix "git subtree pull" errors
6b05f0f use new GOTOOLCHAIN env to manage go version
18b6ac6 chore: update CSI driver version to 1.15
227577e Merge pull request #258 from gnufied/enable-race-detection
e1ceee2 Always enable race detection while running tests
988496a Merge pull request #257 from jakobmoellerdev/csi-prow-sidecar-e2e-path
028f8c6 chore: bump to Go 1.22.5
69bd71e chore: add CSI_PROW_SIDECAR_E2E_PATH
f40f0cc Merge pull request #256 from solumath/master
cfa9210 Instruction update
379a1bb Merge pull request #255 from humblec/sidecar-md
a5667bb fix typo in sidecar release process
4967685 Merge pull request #254 from bells17/add-github-actions
d9bd160 Update skip list in codespell GitHub Action
adb3af9 Merge pull request #252 from bells17/update-go-version
f5aebfc Add GitHub Actions workflows
b82ee38 Merge pull request #253 from bells17/fix-typo
c317456 Fix typo
0a78505 Bump to Go 1.22.3
edd89ad Merge pull request #251 from jsafrane/add-logcheck
043fd09 Add test-logcheck target
d7535ae Merge pull request #250 from jsafrane/go-1.22
b52e7ad Update go to 1.22.2
14fdb6f Merge pull request #247 from msau42/prow
dc4d0ae Merge pull request #249 from jsafrane/use-go-version
e681b17 Use .go-version to get Kubernetes go version
9b4352e Update release playbook
c7bb972 Fix release notes script to use fixed tags
463a0e9 Add script to update specific go modules
b54c1ba Merge pull request #246 from xing-yang/go_1.21
5436c81 Change go version to 1.21.5
267b40e Merge pull request #244 from carlory/sig-storage
b42e5a2 nominate self (carlory) as kubernetes-csi reviewer
a17f536 Merge pull request #210 from sunnylovestiramisu/sidecar
011033d Use set -x instead of die
5deaf66 Add wrapper script for sidecar release
f8c8cc4 Merge pull request #237 from msau42/prow
b36b5bf Merge pull request #240 from dannawang0221/upgrade-go-version
adfddcc Merge pull request #243 from pohly/git-subtree-pull-fix
c465088 pull-test.sh: avoid "git subtree pull" error
7b175a1 Update csi-test version to v5.2.0
987c90c Update go version to 1.21 to match k/k
2c625d4 Add script to generate patch release notes
f9d5b9c Merge pull request #236 from mowangdk/feature/bump_csi-driver-host-path_version
b01fd53 Bump csi-driver-host-path version up to v1.12.0
984feec Merge pull request #234 from siddhikhapare/csi-tools
1f7e605 fixed broken links of testgrid dashboard
de2fba8 Merge pull request #233 from andyzhangx/andyzhangx-patch-1
cee895e remove windows 20H2 build since it's EOL long time ago
670bb0e Merge pull request #229 from marosset/fix-codespell-errors
35d5e78 Merge pull request #219 from yashsingh74/update-registry
63473cc Merge pull request #231 from coulof/bump-go-version-1.20.5
29a5c76 Merge pull request #228 from mowangdk/chore/adopt_kubernetes_recommand_labels
8dd2821 Update cloudbuild image with go 1.20.5
1df23db Merge pull request #230 from msau42/prow
1f92b7e Add ginkgo timeout to e2e tests to help catch any stuck tests
2b8b80e fixing some codespell errors
c10b678 Merge pull request #227 from coulof/check-sidecar-supported-versions
72984ec chore: adopt kubernetes recommand label
b055535 Header
bd0a10b typo
c39d73c Add comments
f6491af Script to verify EOL sidecar version
4133d1d Merge pull request #226 from msau42/cloudbuild
8d519d2 Pin buildkit to v0.10.6 to workaround v0.11 bug with docker manifest
6e04a03 Merge pull request #224 from msau42/cloudbuild
26fdfff Update cloudbuild image
6613c39 Merge pull request #223 from sunnylovestiramisu/update
0e7ae99 Update k8s image repo url
77e47cc Merge pull request #222 from xinydev/fix-dep-version
155854b Fix dep version mismatch
8f83905 Merge pull request #221 from sunnylovestiramisu/go-update
1d3f94d Update go version to 1.20 to match k/k v1.27
e322ce5 Merge pull request #220 from andyzhangx/fix-golint-error
b74a512 test: fix golint error
901bcb5 Update registry k8s.gcr.io -> registry.k8s.io
aa61bfd Merge pull request #218 from xing-yang/update_csi_driver
7563d19 Update CSI_PROW_DRIVER_VERSION to v1.11.0
a2171be Merge pull request #216 from msau42/process
cb98782 Merge pull request #217 from msau42/owners
a11216e add new reviewers and remove inactive reviewers
dd98675 Add step for checking builds
b66c082 Merge pull request #214 from pohly/junit-fixes
b9b6763 filter-junit.go: fix loss of testcases when parsing Ginkgo v2 JUnit
d427783 filter-junit.go: preserve system error log
38e1146 prow.sh: publish individual JUnit files as separate artifacts

git-subtree-dir: release-tools
git-subtree-split: de06a09a7a68bc8da0a275094ade1f5ea7a1a995
2026-04-10 15:54:10 -07:00
.github Squashed 'release-tools/' changes from 78c0fb7..de06a09 2026-04-10 15:54:10 -07:00
boilerplate Squashed 'release-tools/' changes from 3b6d17b..5489de6 2021-09-20 14:59:10 -07:00
contrib Squashed 'release-tools/' changes from 78c0fb7..de06a09 2026-04-10 15:54:10 -07:00
.prow.sh Squashed 'release-tools/' changes from 3b6d17b..5489de6 2021-09-20 14:59:10 -07:00
CONTRIBUTING.md Initial commit from kubernetes-template-project 2019-01-16 10:47:35 -08:00
KUBERNETES_CSI_OWNERS_ALIASES Squashed 'release-tools/' changes from 78c0fb7..de06a09 2026-04-10 15:54:10 -07:00
LICENSE Initial commit from kubernetes-template-project 2019-01-16 10:47:35 -08:00
OWNERS Squashed 'release-tools/' changes from 3b6d17b..5489de6 2021-09-20 14:59:10 -07:00
OWNERS_ALIASES Squashed 'release-tools/' changes from 3b6d17b..5489de6 2021-09-20 14:59:10 -07:00
README.md Squashed 'release-tools/' changes from 3b6d17b..5489de6 2021-09-20 14:59:10 -07:00
RELEASE.md RELEASE.md: clarify release process 2019-01-21 10:18:56 +01:00
SECURITY_CONTACTS Squashed 'release-tools/' changes from 3b6d17b..5489de6 2021-09-20 14:59:10 -07:00
SIDECAR_RELEASE_PROCESS.md Squashed 'release-tools/' changes from 78c0fb7..de06a09 2026-04-10 15:54:10 -07:00
build.make Squashed 'release-tools/' changes from 78c0fb7..de06a09 2026-04-10 15:54:10 -07:00
cloudbuild.sh Squashed 'release-tools/' changes from 3b6d17b..5489de6 2021-09-20 14:59:10 -07:00
cloudbuild.yaml Squashed 'release-tools/' changes from 78c0fb7..de06a09 2026-04-10 15:54:10 -07:00
code-of-conduct.md Initial commit from kubernetes-template-project 2019-01-16 10:47:35 -08:00
filter-junit.go Squashed 'release-tools/' changes from 78c0fb7..de06a09 2026-04-10 15:54:10 -07:00
generate-patch-release-notes.sh Squashed 'release-tools/' changes from 78c0fb7..de06a09 2026-04-10 15:54:10 -07:00
go-get-kubernetes.sh Squashed 'release-tools/' changes from e4dab7f..31a3f38 2022-08-05 17:41:28 +02:00
go-modules-targeted-update.sh Squashed 'release-tools/' changes from 78c0fb7..de06a09 2026-04-10 15:54:10 -07:00
go-modules-update.sh Squashed 'release-tools/' changes from 78c0fb7..de06a09 2026-04-10 15:54:10 -07:00
prow.sh Squashed 'release-tools/' changes from 78c0fb7..de06a09 2026-04-10 15:54:10 -07:00
pull-test.sh Squashed 'release-tools/' changes from 78c0fb7..de06a09 2026-04-10 15:54:10 -07:00
update-vendor.sh better handling of Go version 2019-10-31 11:59:34 +01:00
util.sh verify-shellcheck.sh: make it usable in csi-release-tools 2019-04-02 09:00:48 +02:00
verify-boilerplate.sh Squashed 'release-tools/' changes from 3b6d17b..5489de6 2021-09-20 14:59:10 -07:00
verify-go-version.sh Squashed 'release-tools/' changes from 3b6d17b..5489de6 2021-09-20 14:59:10 -07:00
verify-logcheck.sh Squashed 'release-tools/' changes from 78c0fb7..de06a09 2026-04-10 15:54:10 -07:00
verify-shellcheck.sh Squashed 'release-tools/' changes from 3b6d17b..5489de6 2021-09-20 14:59:10 -07:00
verify-spelling.sh Squashed 'release-tools/' changes from 335339f..37d1104 2022-04-04 12:45:54 +02:00
verify-subtree.sh Squashed 'release-tools/' changes from 3b6d17b..5489de6 2021-09-20 14:59:10 -07:00
verify-vendor.sh better handling of Go version 2019-10-31 11:59:34 +01:00

README.md

csi-release-tools

These build and test rules can be shared between different Go projects without modifications. Customization for the different projects happen in the top-level Makefile.

The rules include support for building and pushing Docker images, with the following features:

  • one or more command and image per project
  • push canary and/or tagged release images
  • automatically derive the image tag(s) from repo tags
  • the source code revision is stored in a "revision" image label
  • never overwrites an existing release image

Usage

The expected repository layout is:

  • cmd/*/*.go - source code for each command
  • cmd/*/Dockerfile - docker file for each command or Dockerfile in the root when only building a single command
  • Makefile - includes release-tools/build.make and sets configuration variables
  • .prow.sh script which imports release-tools/prow.sh and may contain further customization
  • .cloudbuild.sh and cloudbuild.yaml as symlinks to the corresponding files in release-tools or (if necessary) as custom files

To create a release, tag a certain revision with a name that starts with v, for example v1.0.0, then make push while that commit is checked out.

It does not matter on which branch that revision exists, i.e. it is possible to create releases directly from master. A release branch can still be created for maintenance releases later if needed.

Release branches are expected to be named release-x.y for releases x.y.z. Building from such a branch creates x.y-canary images. Building from master creates the main canary image.

Sharing and updating

git subtree is the recommended way of maintaining a copy of the rules inside the release-tools directory of a project. This way, it is possible to make changes also locally, test them and then push them back to the shared repository at a later time.

We no longer care about importing the full commit history, so --squash should be used when submitting a release-tools update. Also make sure that the PR for that contains the automatically generated commit message in the PR description. It contains the list of individual commits that were squashed. The script from https://github.com/kubernetes-csi/csi-release-tools/issues/7 can create such PRs automatically.

Cheat sheet:

  • git subtree add --squash --prefix=release-tools https://github.com/kubernetes-csi/csi-release-tools.git master - add release tools to a repo which does not have them yet (only once)
  • git subtree pull --squash --prefix=release-tools https://github.com/kubernetes-csi/csi-release-tools.git master - update local copy to latest upstream (whenever upstream changes)
  • edit, git commit, git subtree push --prefix=release-tools git@github.com:<user>/csi-release-tools.git <my-new-or-existing-branch> - push to a new branch before submitting a PR

verify-shellcheck.sh

The verify-shellcheck.sh script in this repo is a stripped down copy of the corresponding script in the Kubernetes repository. It can be used to check for certain errors shell scripts, like missing quotation marks. The default test-shellcheck target in build.make only checks the scripts in this directory. Components can add more directories to TEST_SHELLCHECK_DIRS to check also other scripts.

End-to-end testing

A repo that wants to opt into testing via Prow must set up a top-level .prow.sh. Typically that will source prow.sh and then transfer control to it:

#! /bin/bash -e

. release-tools/prow.sh
main

All Kubernetes-CSI repos are expected to switch to Prow. For details on what is enabled in Prow, see https://github.com/kubernetes/test-infra/tree/HEAD/config/jobs/kubernetes-csi

Test results for periodic jobs are visible in https://testgrid.k8s.io/sig-storage-csi-ci

It is possible to reproduce the Prow testing locally on a suitable machine:

  • Linux host
  • Docker installed
  • code to be tested checkout out in $GOPATH/src/<import path>
  • cd $GOPATH/src/<import path> && ./.prow.sh

Beware that the script intentionally doesn't clean up after itself and modifies the content of $GOPATH, in particular the kubernetes and kind repositories there. Better run it in an empty, disposable $GOPATH.

When it terminates, the following command can be used to get access to the Kubernetes cluster that was brought up for testing (assuming that this step succeeded):

export KUBECONFIG="$(kind get kubeconfig-path --name="csi-prow")"

It is possible to control the execution via environment variables. See prow.sh for details. Particularly useful is testing against different Kubernetes releases:

CSI_PROW_KUBERNETES_VERSION=1.13.3 ./.prow.sh
CSI_PROW_KUBERNETES_VERSION=latest ./.prow.sh

Dependencies and vendoring

Most projects will (eventually) use go mod to manage dependencies. dep is also still supported by csi-release-tools, but not documented here because it's not recommended anymore.

The usual instructions for using go modules apply. Here's a cheat sheet for some of the relevant commands:

  • list available updates: GO111MODULE=on go list -u -m all
  • update or add a single dependency: GO111MODULE=on go get <package>
  • update all dependencies to their next minor or patch release: GO111MODULE=on go get ./... (add -u=patch to limit to patch releases)
  • lock onto a specific version: GO111MODULE=on go get <package>@<version>
  • clean up go.mod: GO111MODULE=on go mod tidy
  • update vendor directory: GO111MODULE=on go mod vendor

GO111MODULE=on can be left out when using Go >= 1.13 or when the source is checked out outside of $GOPATH.

go mod tidy must be used to ensure that the listed dependencies are really still needed. Changing import statements or a tentative go get can result in stale dependencies.

The test-vendor verifies that it was used when run locally or in a pre-merge CI job. If a vendor directory is present, it will also verify that it's content is up-to-date.

The vendor directory is optional. It is still present in projects because it avoids downloading sources during CI builds. If this is no longer deemed necessary, then a project can also remove the directory.

Conversion of a repository that uses dep to go mod can be done with:

GO111MODULE=on go mod init
release-tools/go-get-kubernetes.sh <current Kubernetes version from Gopkg.toml>
GO111MODULE=on go mod tidy
GO111MODULE=on go mod vendor
git rm -f Gopkg.toml Gopkg.lock
git add go.mod go.sum vendor

Updating Kubernetes dependencies

When using packages that are part of the Kubernetes source code, the commands above are not enough because the lack of semantic versioning prevents go mod from finding newer releases. Importing directly from kubernetes/kubernetes also needs replace statements to override the fake v0.0.0 versions (https://github.com/kubernetes/kubernetes/issues/79384). The go-get-kubernetes.sh script can be used to update all packages in lockstep to a different Kubernetes version. Example usage:

$ ./release-tools/go-get-kubernetes.sh 1.16.4