* Merge commit from fork
* fix: prevent unbounded read in Terraform remote configuration loader (GHSA-fmgp-q6jx-gg3x)
* fix: bound remote Terraform clone and invalidate cache on rejection
Follow-up hardening for GHSA-fmgp-q6jx-gg3x.
Bound the clone of the attacker-supplied repository: shallow Depth:1, a
2-minute fetch timeout via PlainCloneContext, and post-clone caps on the
retained tree size (64 MiB) and file count, rejecting and removing a clone
that exceeds them.
Invalidate the clone cache: re-clone when the recorded remote URL changes,
and remove the cache on a failed clone or a rejected read so a corrected
repository is re-fetched instead of a poisoned or stale tree being reused.
Validate the module name before building the cache path, and log clone,
rejection, and eviction events.
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
* Fix: resolve gosec G304 lint failure in Terraform module cache check (#7190)
Wrap the cache remote marker read in filepath.Clean, the same pattern
other os.ReadFile call sites in this repo use to satisfy gosec. The
path is built from filepath.Join and a constant suffix, with the module
name validated beforehand, so behavior is unchanged.
The finding surfaced on master after the GHSA-fmgp-q6jx-gg3x merge
because the advisory workflow did not run the full lint job.
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
* Chore: bump actions/cache to v4 in CI workflows
GitHub has closed down actions/cache v1 and v2. Any job pinned to the old
SHA (704facf57e6136b1bc63b828d79edcd491f0ee84) is now automatically failed
at job setup, before any step runs. On this branch that broke check-diff,
check-windows, and unit-tests (each failing in a few seconds with no logs).
Bump the three references in go.yml and unit-test.yml to actions/cache@v4,
matching the version already used on master, so these jobs can run again.
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
* Chore: install envtest binaries via setup-envtest in unit tests
The RyanSiu1995/kubebuilder-action step fetched kube-apiserver and kubectl
from the kubernetes-release and kubebuilder-tools storage buckets, which have
since been retired. Those downloads now return small 404 error pages that get
saved as the binaries, so envtest cannot start the control plane (exec format
error) and the unit-test BeforeSuite panics.
Replace that step with the official prebuilt setup-envtest, which pulls the
matching envtest bundle (etcd, kube-apiserver, kubectl) for Kubernetes 1.26.1
from the current controller-runtime release index and exports its path through
KUBEBUILDER_ASSETS.
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
* Chore: pin cache action and harden envtest install per review
Address automated review feedback on the CI changes:
- Pin actions/cache to a commit SHA (v4.3.0, 0057852) in go.yml and
unit-test.yml instead of the mutable v4 tag, matching how every other
action in these workflows is pinned.
- Add curl -f to the setup-envtest download so an HTTP error fails the step
immediately instead of saving an error page as the binary.
- Verify the downloaded setup-envtest against a known SHA-256 before running it.
- Capture the envtest asset path into a variable and fail fast when it is empty
or not a directory, rather than letting a failed command substitution slip
through and surface later as a confusing make test error.
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
* Fix: load 0.2.0 helm test chart from local file instead of dead repo
The helm helper test fixture pointed version 0.2.0 at
https://charts.kubevela.net/example/autoscalertrait-0.1.0.tgz, but that host
no longer resolves. Once the unit-test suite could run again, "Test getValues
from chart" failed with "cannot load chart from chart repo".
Point the 0.2.0 entry at the local autoscalertrait-0.2.0.tgz that already
ships in testdata, matching how master resolves this chart, so the test no
longer depends on an external network endpoint.
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
* Fix: point addon CLI tests at the live KubeVela registry
The addon listing and status tests registered https://addons.kubevela.net,
which no longer resolves, so the three "addon in the registry" cases failed
once the suite could run again.
Point them at https://kubevela.github.io/catalog/official, the registry that
master already uses for these same tests. The only difference between this
file and master was this URL (the assertions are identical), and that host
still serves the addons the assertions expect.
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
* Chore: re-trigger CI for stuck e2e jobs
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
* Fix: run release-1.9 e2e jobs on GitHub-hosted runners
The e2e-tests and e2e-multi-cluster-tests jobs targeted self-hosted runners,
which GitHub does not assign to pull requests from forks. The jobs sat queued
until the 24h ceiling and were cancelled, so they never ran on this PR (the
original run shows no runner assigned and zero steps executed).
Switch both to ubuntu-22.04, the GitHub-hosted runner that release-1.10 and
master already use for these jobs, where the same fork-based backport runs
them successfully. These workflows are self-contained (they install their own
tools and create the kind cluster inline), so no other change is needed.
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
* Fix: wait for flux controllers before enabling the terraform e2e addon
The e2e post-hook enabled the terraform addon right after fluxcd. The
terraform addon's controller is a flux HelmRelease that needs the flux
source-controller and helm-controller pods running to reconcile, but flux
readiness was only checked after every addon had been enabled. On the
GitHub-hosted runner (slower than the self-hosted one this hook was written
for) the terraform addon enable timed out after 600s waiting on a reconcile
that could not happen until flux was up.
Add the flux-system readiness checks before the terraform addon enable so
flux is reconciling before the addon that depends on it is applied.
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
* Fix: enable terraform e2e addon with terraform-controller 0.8.0
The terraform addon enable timed out after 600s on the GitHub-hosted runner.
A previous attempt that waited for the flux controllers to be Ready before
enabling the addon did not help: the run logs confirm source-controller and
helm-controller were Ready and the terraform addon still timed out, so flux
readiness was not the cause. Revert that wait.
The real difference from master, where this addon enables cleanly, is the
terraform-controller chart: release-1.9 pinned 0.2.11 from charts.kubevela.net,
while master uses 0.8.0 from kubevela.github.io/charts with the ghcr image.
Backport that chart version and image override so the addon controller becomes
healthy in time.
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
* Fix: do not log or persist credentials embedded in Terraform module remote URLs
GetTerraformConfigurationFromRemote logged the raw remote URL and wrote it to
the .remote-url cache marker. An authenticated Git URL such as
https://user:token@host/repo.git embeds credentials in its userinfo, so the
raw value leaked secrets into controller logs and onto disk.
Strip any embedded userinfo with a new redactURLCredentials helper before the
URL is logged or recorded, and compare against the stripped form when checking
the cache marker so cache reuse still works. scp-style SSH URLs authenticate
with keys and carry no secret, so they pass through unchanged.
See GHSA-fmgp-q6jx-gg3x.
Signed-off-by: Ayush Kumar <65535504+roguepikachu@users.noreply.github.com>
* Fix: discover traits from a reachable registry in the e2e raw-url test
The e2e registry test discovered traits from oss://registry.kubevela.net,
whose TLS certificate expired in May 2025, so e2e-tests failed with a
certificate verification error. The default-registry listing test hits the
same expired endpoint.
Match release-1.10: point raw-url discovery at the GitHub-hosted registry,
and disable the default-registry listing until the default registry is updated.
Signed-off-by: Ayush Kumar <65535504+roguepikachu@users.noreply.github.com>
---------
Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
Signed-off-by: Ayush Kumar <65535504+roguepikachu@users.noreply.github.com>
* Feat: support to manage the integrations by the CLI and the workflow
Signed-off-by: barnettZQG <barnett.zqg@gmail.com>
* Fix: remove the xml
Signed-off-by: barnettZQG <barnett.zqg@gmail.com>
* Fix: add the unit test for the nacos writer
Signed-off-by: barnettZQG <barnett.zqg@gmail.com>
* Feat: add the integration API
Signed-off-by: barnettZQG <barnett.zqg@gmail.com>
* Feat: make the provider commands to be deprecated
Signed-off-by: barnettZQG <barnett.zqg@gmail.com>
* Fix: make the unit test work
Signed-off-by: barnettZQG <barnett.zqg@gmail.com>
* Feat: rename the integration to the config
Signed-off-by: barnettZQG <barnett.zqg@gmail.com>
* Fix: make the unit test cases work
Signed-off-by: barnettZQG <barnett.zqg@gmail.com>
* Feat: refactor the config commands
Signed-off-by: barnettZQG <barnett.zqg@gmail.com>
* Feat: add the distribution status for the config
Signed-off-by: barnettZQG <barnett.zqg@gmail.com>
* Fix: sort the import packages
Signed-off-by: barnettZQG <barnett.zqg@gmail.com>
* Fix: refine the code style
Signed-off-by: barnettZQG <barnett.zqg@gmail.com>
* Fix: refine the code style
Signed-off-by: barnettZQG <barnett.zqg@gmail.com>
* Fix: get the content format before render the content
Signed-off-by: barnettZQG <barnett.zqg@gmail.com>
* Feat: add some examples
Signed-off-by: barnettZQG <barnett.zqg@gmail.com>
* Fix: the command test cases
Signed-off-by: barnettZQG <barnett.zqg@gmail.com>
* Feat: add the definitions of the workflow step
Signed-off-by: barnettZQG <barnett.zqg@gmail.com>
* Fix: add some tests
Signed-off-by: barnettZQG <barnett.zqg@gmail.com>
* Fix: add some tests
Signed-off-by: barnettZQG <barnett.zqg@gmail.com>
* Fix: change the name
Signed-off-by: barnettZQG <barnett.zqg@gmail.com>
* Fix: retry the CI
Signed-off-by: barnettZQG <barnett.zqg@gmail.com>
* Fix: refine some words
Signed-off-by: barnettZQG <barnett.zqg@gmail.com>
Signed-off-by: barnettZQG <barnett.zqg@gmail.com>
* Fix: provider can't be added since 1.4 as context abused
Signed-off-by: Jianbo Sun <jianbo.sjb@alibaba-inc.com>
* Feat: add cache for remote terraform module in vela show
Signed-off-by: Jianbo Sun <jianbo.sjb@alibaba-inc.com>
* Fix: add message for terraform resource in error state
Signed-off-by: Jianbo Sun <jianbo.sjb@alibaba-inc.com>
* Fix: The policy controller generate the OpenAPI schema (#3683)
Signed-off-by: DESKTOP-FV8IFEC\10690 <1069029381@qq.com>
* Feat(lang): The policy controller generate the OpenAPI schema (#3683)
The policy controller does not generate the OpenAPI schema #3683
add CapabilityPolicyDefinition struct comment
add StoreOpenAPISchema of CapabilityPolicyDefinition comment
Signed-off-by: fengkang <fengkangb@digitalchina.com>
* Feat(lang): The policy controller generate the OpenAPI schema (#3683)
The policy controller does not generate the OpenAPI schema #3683
fix unit-test
Signed-off-by: fengkang <fengkangb@digitalchina.com>
* Feat(lang): The policy controller generate the OpenAPI schema (#3683)
fix unit-test about policydefinition_controller_test.go
The policy controller does not generate the OpenAPI schema #3683
fix unit-test
Signed-off-by: fengkang <fengkangb@digitalchina.com>
* Feat(lang): The policy controller generate the OpenAPI schema (#3683)
fix unit-test about policydefinition_controller_test.go
Signed-off-by: fengkang <fengkangb@digitalchina.com>
* Feat(lang): The policy controller generate the OpenAPI schema (#3683) gen crd
Signed-off-by: fengkang <fengkangb@digitalchina.com>
* Feat(lang): The policy controller generate the OpenAPI schema (#3683) make reviewable
Signed-off-by: fengkang01 <fengkangb@digitalchina.com>
Co-authored-by: DESKTOP-FV8IFEC\10690 <1069029381@qq.com>
The UT `TestGetOpenAPISchemaFromTerraformComponentDefinition` won't
succeed 100%. The required variables in the generated isn't in the expected
order all the time.
Signed-off-by: Zheng Xi Zhou <zzxwill@gmail.com>
Add another unit test when the configuration of Terraform locates
in a subpath of a git remote repository
Signed-off-by: Zheng Xi Zhou <zzxwill@gmail.com>
* Fix: retrieve Terraform variables from variables.tf
If Terraform modules/resources are stored in remote git repos, get
variables from file `varialbes.tf`, or from `main.tf`.
Signed-off-by: Zheng Xi Zhou <zzxwill@gmail.com>
* Fix: Generate doc for Terraform typed ComponentDefinition
When the configuration of a Terraform Typed ComponentDefinition is in
remote Git, generate the properties for it. And generated outputs for
all Terraform ComponentDefinition
Signed-off-by: Zheng Xi Zhou <zzxwill@gmail.com>
* Fix: add more fields for Terraform types definitions in api schema
Added `writeConnectionStringSecrecto`, `region` and `deleteResoruce`
fields for Terraform types definitions in OpenAPI schema
* fix ci issue
* fix header
* Feat(rollout): fill rolloutBatches if empty when scale up/down (#2569)
* Feat: fill rolloutBatches if empty
* Fix: fix unit-test
* Test: add more test
Fix: lint
Fix: fix lint
* Update release.yml (#2537)
* Feat: add registry, merge registry and cap center (#2528)
* Feat: add registry command
* Refactor: comp/trait command combine with registry
* Feat: refactor `vela comp/trait`
* Fix: import
* Fix: fix if type is autodetects.core.oam.dev
* Fix: fix list from url
* Fix: test
* Feat: add test
* Fix: remove dup test
* Fix: test
* Fix: test
* Fix: fix label filter
* Fix: reviewable
* Fix test
* fix personal repo in test
* Fix test
* Fix test
* add some boundary check
* reviewable
* Fix: fix nocalhost trait (#2577)
* fix incorrect addon status (#2576)
* Fix(cli): client-side throttling in vela CLI (#2581)
* fix cli throttling
* fix import
* set to a lower value
* remove addon with no defs (#2574)
* Feat: vela logs support multicluster (#2593)
* Feat: add basic multiple cluster logs
* fix context
* Fix select style
* Fix select style
* remove useless env
* fix naming
* Feat: vela cluster support use ocm to join/list/detach cluster (#2599)
* Feat: add render component and apply component remaining (#2587)
* Feat: add render component and apply component remaining
* fix ut
* fix e2e
* allow import package in custom status cue template (#2585)
Co-authored-by: chwetion <chwetion@foxmail.com>
* Fix: abnormal aux name (#2612)
* Feat: store workflow step def properties in cm (#2592)
* Fix: fix notification def
* Feat: store workflow step def properties in cm
* fix ci
* fix data race
* Fix: change Initializer to Application for addon Observability (#2615)
In this doc, updated the Observability implementation from initializer
to Application. I also store definitions as it's not well stored in
vela-templates/addons/observability
* Fix: fix backport param (#2611)
* Fix: add owner reference in workflow context cm (#2573)
* Fix: add owner reference in workflow context cm
* fix ci
* delete useless test case
* Fix: op.delete bugs (#2622)
* Fix: op.delete some bugs
* Fix: app status update error
Fix: make reviewable
* Fix: show reconcile error log (#2626)
* Feat: add reconcile timeout configuration for vela-core (#2630)
* Fix: patch status retry while conflict happens (#2629)
* Fix: allow definition schema cm can be same name in different definition type (#2618)
* Fix: fix definition schema cm name
* fix ut
* fix ut
* fix show
* add switch default case
* Feat: remove envbinding policy into workflow (#2556)
Fix: add more test
* Feat: add vela prob to test cluster (#2635)
* Fix: upgrade stern lib to avoid panic for vela logs (#2650)
* Fix: filter loggable workload in vela logs (#2651)
* Fix: filter loggable workload in vela logs
* reviewable
* Feat: add vela exec for multi cluster (#2299)
fix
support vela exec
* Fix: health check will check for multiclusters (#2645)
* Fix: minor fix for vela cli printing (#2655)
* Fix: minor fix for vela cli printing
* add dockerfile go mod cache
* Feat: support apiserver-related multicluster features (#2625)
* Feat: remove envbinding policy into workflow
Feat: add support for env change (env gc)
Fix: fix rollout timeout setting bug
* Feat: support disable trait and env without workflow
* Fix: add hint for replaced value
Co-authored-by: wyike <wangyike_wyk@163.com>
Co-authored-by: basefas <basefas@hotmail.com>
Co-authored-by: qiaozp <47812250+chivalryq@users.noreply.github.com>
Co-authored-by: Tianxin Dong <dongtianxin.tx@alibaba-inc.com>
Co-authored-by: yangsoon <yangsoonlx@gmail.com>
Co-authored-by: Chwetion <137953601@qq.com>
Co-authored-by: chwetion <chwetion@foxmail.com>
Co-authored-by: Jian.Li <74582607+leejanee@users.noreply.github.com>
Co-authored-by: Zheng Xi Zhou <zzxwill@gmail.com>
Co-authored-by: Jianbo Sun <jianbo.sjb@alibaba-inc.com>
* Feat(trait): annotation and labels trait should also affect the workload object along with pod
* Feat(trait): annotation and labels trait should also affect the workload object along with pod
* Feat(trait): annotation and labels trait should also affect the workload object along with pod
* Feat(trait): annotation and labels trait should also affect the workload object along with pod
* Chore: deprecate containerized workload
* Chore: deprecate containerized workload
* Chore: run make reviewable as per review comment
* Chore: fix import
* Chore: merge with master
* Chore: merge with master
* Chore: remove references for containerized workload
* Chore: fix failiing e2e test
* Chore: fix failing e2e test
* Chore: fix failing e2e test
* Chore: fix failing e2e test
* Chore: fix e2e tests
* Chore: fix e2e tests
* Chore: fix e2e tests
* Chore: fix e2e tests
* Chore: fix e2e tests
* Chore: merge with upstream
Co-authored-by: Reeta Singh <reetas@twitter.com>
* Fix: add e2e plugin test back
* Fix: e2e rollout test and try change port to 37081
* Fix: add rollout plan test back
* Refactor: change the workflow state machine and add workflow succeed state
* Refactor: refine definition controller and fix e2e of app revision
* Refactor: unlock all the normal cases
* Fix: add helm schematic logic back into workflow
The io/ioutil package has been deprecated as of Go 1.16, see
https://golang.org/doc/go1.16#ioutil. This commit replaces the existing
io/ioutil functions with their new definitions in io and os packages.
Signed-off-by: Eng Zer Jun <zerjun@beatchain.co>