Commit Graph

10559 Commits

Author SHA1 Message Date
Ed Bartosh
75ccd69bab migrate pkg/kubelet/kubeletconfig to contextual logging 2025-07-17 10:16:03 +03:00
Ed Bartosh
7dad9e2af6 migrate pkg/kubelet/apis to contextual logging 2025-07-17 10:15:58 +03:00
Kubernetes Prow Robot
5df27c4922 Merge pull request #132833 from saschagrunert/kms-gogo
Convert `k8s.io/kms/apis` from gogo to protoc
2025-07-16 12:12:24 -07:00
Sascha Grunert
8e6651520e Convert k8s.io/kms/apis from gogo to protoc
Use standard protoc for the kms APIs instead of gogo.

Part of kubernetes#96564

Signed-off-by: Sascha Grunert <sgrunert@redhat.com>
2025-07-16 16:46:39 +02:00
Patrick Ohly
6e1875fac9 local-up-cluster.sh: don't require to be invoked in the root
It's normal for shell scripts to change the current directory if they expect to
run in the repo root.
2025-07-15 12:54:40 +02:00
Patrick Ohly
356be5ae30 DRA E2E: move upgrade/downgrade test into test/e2e_dra
It's similar to test/e2e_kubeadm in the sense that it is a test which must be
excluded from both "make test" and "make integration" by default.
2025-07-15 12:54:40 +02:00
Davanum Srinivas
ebc1ccc491 Bump k8s.io/kube-openapi to latest SHA (f3f2b991d03b)
Signed-off-by: Davanum Srinivas <davanum@gmail.com>
2025-07-14 07:24:48 -04:00
Kubernetes Prow Robot
d9f93d9e9d Merge pull request #132867 from pohly/local-up-cluster-enhancements
local-up-cluster: cleanup, support automated upgrade/downgrade testing
2025-07-10 09:45:28 -07:00
Ed Bartosh
bbab594110 local-up-cluster: stop running Docker
It's been a long time since Kubernetes stopped to use Docker
as a runtime. Modified script to stop Docker as Kubelet is using
containerd directly. Removed Docker-specific logic and variables,
adjusted comments and configuration.
2025-07-10 15:30:56 +02:00
Ed Bartosh
f57662856f local-up-cluster: store logs in artifacts directory
Store logs in a temporary subdirectory under the artifacts directory
when running in CI. This ensures logs are available in the prow
web UI for easier access and debugging.
2025-07-10 15:30:56 +02:00
Ed Bartosh
81b6e1d3a3 local-up-cluster: start containerd before Docker
Configure and start containerd before starting Docker, ensuring that
Docker detects and uses the running containerd instance instead of
launching its own. This allows us to customize containerd’s
configuration, such as enabling CDI support, which is not possible when
Docker manages containerd itself.

Set root and state paths for containerd to make it working the same way
as when Docker runs it.
2025-07-10 15:30:56 +02:00
Ed Bartosh
27a77370dd local-up-cluster: simplify installing packages
- Don't reinstall docker, containerd and runc as kubekins image
  already has their recent versions.
- Avoid breaking dependencies when installing nfttables and kmod.
- Install only packages that don't exist in the image.
2025-07-10 15:30:56 +02:00
Patrick Ohly
ddda1dca33 local-up-cluster.sh: add dry-run mode
This may be useful during manual invocations to see what commands would be
executed and with which parameters, without actually running them.

But the main purpose is to use this mode in automated upgrade/downgrade testing
where the caller parses the output to execute those commands under its own
control. Such a caller can then replaced individual component binaries with
those from other releases.
2025-07-10 15:30:56 +02:00
Patrick Ohly
bc5aa94d8d local-up-cluster.sh: allow configuring all ports
Some ports (apiserver, one kubelet port) were already configurable.
Several others were not.

Primarily this is done to document the ports which are in used by the different
components.
2025-07-10 13:09:19 +02:00
Patrick Ohly
a4b1d26b14 local-up-cluster.sh: dump config on KUBE_VERBOSE >= 2
Showing the configuration (= variable assignments) without going all the way to
KUBE_VERBOSE > 4 is useful.
2025-07-10 13:09:18 +02:00
Kubernetes Prow Robot
9a50e30636 Merge pull request #132668 from dims/fix-todos-from-sorted-features-original-pr
Fix todos from sorted features golangci-lint plugin PR
2025-07-09 13:15:26 -07:00
ArkaSaha30
621482d68b update pause version to 3.10.1
This commit will update the pause version to 3.10.1 as per thread: https://kubernetes.slack.com/archives/CJH2GBF7Y/p1741674313893029

Signed-off-by: ArkaSaha30 <arkasaha30@gmail.com>
2025-07-09 16:38:14 +05:30
Kubernetes Prow Robot
4fedef93d1 Merge pull request #132820 from dims/update-to-v1.1.4-for-golang.org/x/vuln/cmd/govulncheck
Update to v1.1.4 for golang.org/x/vuln/cmd/govulncheck
2025-07-08 20:01:33 -07:00
Kubernetes Prow Robot
b0e1a16e94 Merge pull request #132155 from vekarpov/132153
feat verify-goluncheck: add -q flag for git worktree command
2025-07-08 11:45:27 -07:00
Davanum Srinivas
637bf55cbc bump golang.org/x/vuln/cmd/govulncheck to v1.1.4
Signed-off-by: Davanum Srinivas <davanum@gmail.com>
2025-07-08 13:48:26 -04:00
Sascha Grunert
841886df76 Convert externaljwt from gogo to protoc
Use standard protoc for the `externaljwt` package instead of gogo.

Part of https://github.com/kubernetes/kubernetes/issues/96564

Signed-off-by: Sascha Grunert <sgrunert@redhat.com>
2025-07-08 08:08:30 +02:00
Patrick Ohly
b22ffdb48f golangci-lint: exclude naming convention check for swagger docs
This started to show up now as linter hints at the start of the 1.34 cycle in
all PRs which modify the API. We don't want to enforce that convention in that
generated code, so suppressing it.
2025-07-06 16:54:04 +02:00
Sascha Grunert
b464bbeb8f Remove gogo-protobuf from CRI
Signed-off-by: Sascha Grunert <sgrunert@redhat.com>
2025-07-04 08:55:57 +02:00
Davanum Srinivas
1514568ddf rename sortedfeatures -> sorted
Signed-off-by: Davanum Srinivas <davanum@gmail.com>
2025-07-01 22:12:26 -04:00
Davanum Srinivas
9e1a21816d update README
Signed-off-by: Davanum Srinivas <davanum@gmail.com>
2025-07-01 22:03:22 -04:00
Davanum Srinivas
5cebe66b64 update log line
Signed-off-by: Davanum Srinivas <davanum@gmail.com>
2025-07-01 21:57:50 -04:00
Jefftree
ec6471f63e Remove gnostic-models gopkg.in/yaml.v3 unwanted dependency 2025-07-01 15:56:40 +00:00
Kubernetes Prow Robot
c6539bc785 Merge pull request #132284 from ArkaSaha30/bump-etcd-3.6.1
Bump etcd to v3.6.1
2025-06-30 11:00:35 -07:00
Davanum Srinivas
f2d8b7ec2c Add linter to report on unsorted feature gates
Signed-off-by: Davanum Srinivas <davanum@gmail.com>
2025-06-27 11:05:13 -04:00
Kubernetes Prow Robot
ec1803cab8 Merge pull request #132509 from yongruilin/fix-make-vet
chore: Remove vet target and associated script from Makefile and hack directory
2025-06-26 00:26:34 -07:00
Kubernetes Prow Robot
b3e438aef9 Merge pull request #132220 from BenTheElder/a-little-owners-cleanup
emeritus spiffxp and backfill OWNERS
2025-06-25 19:16:28 -07:00
yongruilin
8b2eb9090e chore: Remove vet target and associated script from Makefile and hack directory 2025-06-25 17:39:14 +00:00
Patrick Ohly
49ebabb54e verify: additional validation of e2e.test --list-images output
If the command failed in the <( ... ) expression, the return code was ignored
and the script continued with potentially no output. Not likely, but it's still
better to invoke the command where pipefail will catch a non-zero exit
code. For example, broken test registration could cause this.

There should be no log output, but if there is, failing explicitly is better
than ignoring it (on stderr) or treating it like an image (on stdout). Found
when experimenting with the logging configuration of e2e.test, currently there
is no such unwanted log output.
2025-06-25 10:30:45 +02:00
Patrick Ohly
73627dd663 verify: improve output of verify-e2e-images.sh
Before:

    Diffing e2e image list ...
    --- /dev/fd/63	2025-06-24 09:32:43.736397729 +0200
    +++ /dev/fd/62	2025-06-24 09:32:43.736397729 +0200
    @@ -5,7 +5,7 @@ invalid.registry.k8s.io/invalid/alpine
     registry.k8s.io/build-image/distroless-iptables
     registry.k8s.io/cloud-provider-gcp/gcp-compute-persistent-disk-csi-driver
     registry.k8s.io/e2e-test-images/agnhost
    -registry.k8s.io/e2e-test-images/apparmor-loader
    +registry.k8s.io/e2e-test-images/apparmor-no-such-image
     registry.k8s.io/e2e-test-images/busybox
     registry.k8s.io/e2e-test-images/httpd
     registry.k8s.io/e2e-test-images/ipc-utils
    FAIL: e2e images do not match the approved list!

For this test, apparmor-loader was commented out in .permitted-images (making
it a forbidden unknown image) and apparmor-no-such-image was added (making it
an obsolete image).

Problems with the output:
- The position of old and new image lists was reversed.
- It's not clear what is being diffed. Not referencing .permitted-images
  directly probably was meant to discourage using some image other than
  agnhost, but developers can easily find the file anyway and are shown
  some other images in the diff context.

After:

    Diffing e2e image list ...
    obsolete image: registry.k8s.io/e2e-test-images/apparmor-no-such-image
    forbidden image: registry.k8s.io/e2e-test-images/apparmor-loader
    FAIL: current e2e images do not match the approved list in test/images/.permitted-images!

This mentions test/images/.permitted-images because developers might have to
edit it if some image really becomes obsolete.
2025-06-25 10:30:45 +02:00
Kubernetes Prow Robot
8d2a5a2c9c Merge pull request #132499 from liggitt/unwanted-json-patch-v5
Add json-patch v4 compatibility test
2025-06-24 09:54:35 -07:00
Stephen Kitt
2ca4ffe653 Add evanphx/json-patch/v5 to unwanted dependencies
This comes up periodically; bumping to v5 introduces issues with
replace operations in JSON patches. k/k relies on non-RFC-compliant
operations which v5 no longer allows.

Signed-off-by: Stephen Kitt <skitt@redhat.com>
2025-06-24 09:18:04 -04:00
Davanum Srinivas
138e363e41 cleanup shellcheck for temporary HOME directory
Signed-off-by: Davanum Srinivas <davanum@gmail.com>
2025-06-19 11:48:15 -04:00
Davanum Srinivas
cfff359b41 fix for gimme when $HOME is not writable
Signed-off-by: Davanum Srinivas <davanum@gmail.com>
2025-06-18 18:01:28 -04:00
Kubernetes Prow Robot
aeaec76893 Merge pull request #132290 from dims/script-to-enforce-dead-code-elimination
add script for verifying dead code elimination
2025-06-17 13:30:52 -07:00
Kubernetes Prow Robot
805898e09c Merge pull request #132241 from BenTheElder/disable-selinux-relabel
disable selinux relabeling when mounting sourcedir to shellcheck
2025-06-17 07:29:01 -07:00
Davanum Srinivas
2a5e4d5582 add script for verifying dead code elimination
Signed-off-by: Davanum Srinivas <davanum@gmail.com>
2025-06-17 03:35:12 +00:00
Kubernetes Prow Robot
3e39d1074f Merge pull request #132221 from dims/new-cmp-diff-impl
New implementation for `Diff` (drop in replacement for `cmp.Diff`)
2025-06-16 18:02:58 -07:00
Davanum Srinivas
03afe6471b Add a replacement for cmp.Diff using json+go-difflib
Co-authored-by: Jordan Liggitt <jordan@liggitt.net>
Signed-off-by: Davanum Srinivas <davanum@gmail.com>
2025-06-16 17:10:42 -04:00
Pierre Gimalac
40c718864b chore(apiserver): avoid using html template which disables dce 2025-06-13 15:28:55 +02:00
ArkaSaha30
e09b042d34 Bump etcd to v3.6.1
This commit will bump etcd to v3.6.1
Release: https://github.com/etcd-io/etcd/releases/tag/v3.6.1
Issue: https://github.com/etcd-io/etcd/issues/20047

Signed-off-by: ArkaSaha30 <arkasaha30@gmail.com>
2025-06-13 16:28:35 +05:30
Kubernetes Prow Robot
0001a8aeff Merge pull request #132210 from dims/add-a-toggle-adding-disabling-grpcnotrace-tag
Adding `grpcnotrace` tag for production (non-debug) builds
2025-06-11 15:58:54 -07:00
Benjamin Elder
b86b4632b3 disable selinux relabeling when mounting sourcedir to shellcheck 2025-06-11 15:35:56 -07:00
Davanum Srinivas
5a2844a766 Update to etcd v3.6.1 in vendor/
Signed-off-by: Davanum Srinivas <davanum@gmail.com>
2025-06-11 16:46:03 -04:00
Davanum Srinivas
a9108e8f53 Adding grpcnotrace tag for production (non-debug) builds
If someone really wants to do golang diagnostics:
https://go.dev/doc/diagnostics#tracing

then they will only be able to do that in debug builds (`DBG`).

Signed-off-by: Davanum Srinivas <davanum@gmail.com>
2025-06-11 15:52:40 -04:00
Benjamin Elder
ad68a4b4cd emeritus spiffxp
spiffxp moved on from the project years ago, he is still missed
2025-06-10 20:05:40 -07:00