573 Commits
Author SHA1 Message Date
Ayush KumarandGitHub 7a4e59b295 [Backport release-1.9] Fix: prevent unbounded read in Terraform remote configuration loader (GHSA-fmgp-q6jx-gg3x) (#7192)
* Merge commit from fork

* fix: prevent unbounded read in Terraform remote configuration loader (GHSA-fmgp-q6jx-gg3x)

* fix: bound remote Terraform clone and invalidate cache on rejection

Follow-up hardening for GHSA-fmgp-q6jx-gg3x.

Bound the clone of the attacker-supplied repository: shallow Depth:1, a
2-minute fetch timeout via PlainCloneContext, and post-clone caps on the
retained tree size (64 MiB) and file count, rejecting and removing a clone
that exceeds them.

Invalidate the clone cache: re-clone when the recorded remote URL changes,
and remove the cache on a failed clone or a rejected read so a corrected
repository is re-fetched instead of a poisoned or stale tree being reused.

Validate the module name before building the cache path, and log clone,
rejection, and eviction events.

Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>

* Fix: resolve gosec G304 lint failure in Terraform module cache check (#7190)

Wrap the cache remote marker read in filepath.Clean, the same pattern
other os.ReadFile call sites in this repo use to satisfy gosec. The
path is built from filepath.Join and a constant suffix, with the module
name validated beforehand, so behavior is unchanged.

The finding surfaced on master after the GHSA-fmgp-q6jx-gg3x merge
because the advisory workflow did not run the full lint job.

Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>

* Chore: bump actions/cache to v4 in CI workflows

GitHub has closed down actions/cache v1 and v2. Any job pinned to the old
SHA (704facf57e6136b1bc63b828d79edcd491f0ee84) is now automatically failed
at job setup, before any step runs. On this branch that broke check-diff,
check-windows, and unit-tests (each failing in a few seconds with no logs).

Bump the three references in go.yml and unit-test.yml to actions/cache@v4,
matching the version already used on master, so these jobs can run again.

Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>

* Chore: install envtest binaries via setup-envtest in unit tests

The RyanSiu1995/kubebuilder-action step fetched kube-apiserver and kubectl
from the kubernetes-release and kubebuilder-tools storage buckets, which have
since been retired. Those downloads now return small 404 error pages that get
saved as the binaries, so envtest cannot start the control plane (exec format
error) and the unit-test BeforeSuite panics.

Replace that step with the official prebuilt setup-envtest, which pulls the
matching envtest bundle (etcd, kube-apiserver, kubectl) for Kubernetes 1.26.1
from the current controller-runtime release index and exports its path through
KUBEBUILDER_ASSETS.

Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>

* Chore: pin cache action and harden envtest install per review

Address automated review feedback on the CI changes:

- Pin actions/cache to a commit SHA (v4.3.0, 0057852) in go.yml and
  unit-test.yml instead of the mutable v4 tag, matching how every other
  action in these workflows is pinned.
- Add curl -f to the setup-envtest download so an HTTP error fails the step
  immediately instead of saving an error page as the binary.
- Verify the downloaded setup-envtest against a known SHA-256 before running it.
- Capture the envtest asset path into a variable and fail fast when it is empty
  or not a directory, rather than letting a failed command substitution slip
  through and surface later as a confusing make test error.

Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>

* Fix: load 0.2.0 helm test chart from local file instead of dead repo

The helm helper test fixture pointed version 0.2.0 at
https://charts.kubevela.net/example/autoscalertrait-0.1.0.tgz, but that host
no longer resolves. Once the unit-test suite could run again, "Test getValues
from chart" failed with "cannot load chart from chart repo".

Point the 0.2.0 entry at the local autoscalertrait-0.2.0.tgz that already
ships in testdata, matching how master resolves this chart, so the test no
longer depends on an external network endpoint.

Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>

* Fix: point addon CLI tests at the live KubeVela registry

The addon listing and status tests registered https://addons.kubevela.net,
which no longer resolves, so the three "addon in the registry" cases failed
once the suite could run again.

Point them at https://kubevela.github.io/catalog/official, the registry that
master already uses for these same tests. The only difference between this
file and master was this URL (the assertions are identical), and that host
still serves the addons the assertions expect.

Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>

* Chore: re-trigger CI for stuck e2e jobs

Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>

* Fix: run release-1.9 e2e jobs on GitHub-hosted runners

The e2e-tests and e2e-multi-cluster-tests jobs targeted self-hosted runners,
which GitHub does not assign to pull requests from forks. The jobs sat queued
until the 24h ceiling and were cancelled, so they never ran on this PR (the
original run shows no runner assigned and zero steps executed).

Switch both to ubuntu-22.04, the GitHub-hosted runner that release-1.10 and
master already use for these jobs, where the same fork-based backport runs
them successfully. These workflows are self-contained (they install their own
tools and create the kind cluster inline), so no other change is needed.

Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>

* Fix: wait for flux controllers before enabling the terraform e2e addon

The e2e post-hook enabled the terraform addon right after fluxcd. The
terraform addon's controller is a flux HelmRelease that needs the flux
source-controller and helm-controller pods running to reconcile, but flux
readiness was only checked after every addon had been enabled. On the
GitHub-hosted runner (slower than the self-hosted one this hook was written
for) the terraform addon enable timed out after 600s waiting on a reconcile
that could not happen until flux was up.

Add the flux-system readiness checks before the terraform addon enable so
flux is reconciling before the addon that depends on it is applied.

Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>

* Fix: enable terraform e2e addon with terraform-controller 0.8.0

The terraform addon enable timed out after 600s on the GitHub-hosted runner.
A previous attempt that waited for the flux controllers to be Ready before
enabling the addon did not help: the run logs confirm source-controller and
helm-controller were Ready and the terraform addon still timed out, so flux
readiness was not the cause. Revert that wait.

The real difference from master, where this addon enables cleanly, is the
terraform-controller chart: release-1.9 pinned 0.2.11 from charts.kubevela.net,
while master uses 0.8.0 from kubevela.github.io/charts with the ghcr image.
Backport that chart version and image override so the addon controller becomes
healthy in time.

Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>

* Fix: do not log or persist credentials embedded in Terraform module remote URLs

GetTerraformConfigurationFromRemote logged the raw remote URL and wrote it to
the .remote-url cache marker. An authenticated Git URL such as
https://user:token@host/repo.git embeds credentials in its userinfo, so the
raw value leaked secrets into controller logs and onto disk.

Strip any embedded userinfo with a new redactURLCredentials helper before the
URL is logged or recorded, and compare against the stripped form when checking
the cache marker so cache reuse still works. scp-style SSH URLs authenticate
with keys and carry no secret, so they pass through unchanged.

See GHSA-fmgp-q6jx-gg3x.

Signed-off-by: Ayush Kumar <65535504+roguepikachu@users.noreply.github.com>

* Fix: discover traits from a reachable registry in the e2e raw-url test

The e2e registry test discovered traits from oss://registry.kubevela.net,
whose TLS certificate expired in May 2025, so e2e-tests failed with a
certificate verification error. The default-registry listing test hits the
same expired endpoint.

Match release-1.10: point raw-url discovery at the GitHub-hosted registry,
and disable the default-registry listing until the default registry is updated.

Signed-off-by: Ayush Kumar <65535504+roguepikachu@users.noreply.github.com>

---------

Signed-off-by: Ayush Kumar <ayushshyamkumar888@gmail.com>
Signed-off-by: Ayush Kumar <65535504+roguepikachu@users.noreply.github.com>
2026-06-25 20:50:35 -07:00
Daniel HigueroandGitHub 1a001e5b29 Address GolangCI lint 1.55 errors (#6453)
Signed-off-by: Daniel Higuero <daniel@napptive.com>
2024-02-07 17:27:32 +08:00
Tyler GillsonandGitHub 86dc53afab Fix: load local ComponentDefinitions recursively (#6414)
* fix: load local componentdefinitions recursively

Signed-off-by: Tyler Gillson <tyler.gillson@gmail.com>

* test: add dry-run offline def dir test

Signed-off-by: Tyler Gillson <tyler.gillson@gmail.com>

* test: fix unit tests

Signed-off-by: Tyler Gillson <tyler.gillson@gmail.com>

---------

Signed-off-by: Tyler Gillson <tyler.gillson@gmail.com>
2024-01-04 08:47:59 -08:00
McdullerandGitHub d3581b9189 Fix: fix the vela show error when format the output markdown (#6356)
Signed-off-by: Mcduller <1596582524@qq.com>
2023-09-25 14:34:37 +08:00
a07acc02c9 Feat: Add command to list all workflows in vela-cli (#6326)
- fixes #6326

Signed-off-by: Muralicharan Gurumoorthy <muralicharan.gurumoorthy@gmail.com>
Co-authored-by: Muralicharan Gurumoorthy <muralicharan.gurumoorthy@gmail.com>
2023-09-20 10:19:08 +08:00
JohnJanandGitHub d787e95a08 Feat: apply-component supports namespace (#6248) 2023-08-31 14:08:48 +08:00
qiaozpandGitHub 94cbcad471 Chore: tidy appHandler (#6300) 2023-08-28 11:01:33 +08:00
yyzxwandGitHub 15c0b1e218 Feat: enable unknown flags (#6303)
Signed-off-by: yyzxw <1020938856@qq.com>
2023-08-27 17:20:25 +08:00
意琦行andGitHub faf5502fae fix: hide msg when no cluster uninstall (#6294) 2023-08-25 12:27:40 +08:00
c315e81757 Fix: Print command output using stdout channel #6268 (#6273)
Co-authored-by: Priyanaka Kotturi
2023-08-22 09:55:20 +08:00
qiaozpandGitHub bab5bb2caf Refactor: capabilities and workload in appfile parsing (#6250) 2023-08-10 14:41:20 +08:00
qiaozpandGitHub 307d1db36d Chore: revert "Feat: apply-component supports namespace" (#6247) 2023-08-07 15:44:20 +08:00
qiaozpandGitHub 00ae0c9494 Feat: support offline dryrun with deploy step (#6234) 2023-07-26 18:09:01 +08:00
JohnJanandGitHub f0357fdc8f Feat: apply-component supports namespace (#6228)
* Feat: apply-component supports namespace

Signed-off-by: wuzhongjian <wuzhongjian_yewu@cmss.chinamobile.com>

* Feat: apply-component supports namespace

Signed-off-by: wuzhongjian <wuzhongjian_yewu@cmss.chinamobile.com>

---------

Signed-off-by: wuzhongjian <wuzhongjian_yewu@cmss.chinamobile.com>
2023-07-25 10:31:18 +08:00
JohnJanandGitHub b9f1cc97a9 Feat: add container-ports trait for hostPort and hostIP (#6187)
* Feat: add container-ports trait for hostPort and hostIP

Signed-off-by: wuzhongjian <wuzhongjian_yewu@cmss.chinamobile.com>

* Feat: add container-ports trait for hostPort and hostIP

Signed-off-by: wuzhongjian <wuzhongjian_yewu@cmss.chinamobile.com>

* Feat: add container-ports trait for hostPort and hostIP

Signed-off-by: wuzhongjian <wuzhongjian_yewu@cmss.chinamobile.com>

* Feat: add container-ports trait for hostPort and hostIP

Signed-off-by: wuzhongjian <wuzhongjian_yewu@cmss.chinamobile.com>

* Feat: add container-ports trait for hostPort and hostIP

Signed-off-by: wuzhongjian <wuzhongjian_yewu@cmss.chinamobile.com>

---------

Signed-off-by: wuzhongjian <wuzhongjian_yewu@cmss.chinamobile.com>
2023-07-11 18:44:05 +08:00
qiaozpandGitHub dabaf03e73 Chore: swtich between old and new registry in vela install (#6173)
* Chore: swtich between old and new registry in vela install

Signed-off-by: Qiaozp <qiaozhongpei.qzp@alibaba-inc.com>

* add comments

Signed-off-by: Qiaozp <qiaozhongpei.qzp@alibaba-inc.com>

* minor fix

Signed-off-by: Qiaozp <qiaozhongpei.qzp@alibaba-inc.com>

---------

Signed-off-by: Qiaozp <qiaozhongpei.qzp@alibaba-inc.com>
2023-07-04 12:15:30 +08:00
iyearandGitHub 64e4ab813d Fix: top command abnormal render (#6174)
* Fix: top command abnormal render

Signed-off-by: iyear <ljyngup@gmail.com>

* Fix: imports

Signed-off-by: iyear <ljyngup@gmail.com>

* Fix: gomod

Signed-off-by: iyear <ljyngup@gmail.com>

---------

Signed-off-by: iyear <ljyngup@gmail.com>
2023-07-04 12:09:02 +08:00
48cf6fb10e Fix: vela install chart switch place (#6153)
* Fix: vela install chart switch place

Signed-off-by: Somefive <Somefive@foxmail.com>

* Fix: test case replace url

Signed-off-by: Jianbo Sun <jianbo.sjb@alibaba-inc.com>

---------

Signed-off-by: Somefive <Somefive@foxmail.com>
Signed-off-by: Jianbo Sun <jianbo.sjb@alibaba-inc.com>
Co-authored-by: Jianbo Sun <jianbo.sjb@alibaba-inc.com>
2023-06-29 17:48:12 +08:00
StevenLeiZhangandGitHub 90246065d9 Fix: vela dry-run can not render Applicaiton, if x-definition(Compnent/Trait) is not installed to vela-system namespace (#6135)
Signed-off-by: StevenLeiZhang <zhangleiic@163.com>
2023-06-27 23:08:23 +08:00
SomefiveandGitHub c4f14ad261 Fix: remove forbid redirect for http get (#6147) 2023-06-21 13:46:44 +08:00
SomefiveandGitHub 257695f073 Fix: addon registry use kubevela.github.io and support redirect (#6133) 2023-06-20 16:30:27 +08:00
StevenLeiZhangandGitHub 28004bc26f Fix: vela top crash, when view Application topology (#6127)
Signed-off-by: StevenLeiZhang <zhangleiic@163.com>
2023-06-18 10:20:46 +08:00
SomefiveandGitHub a513029ec8 Fix: vela addon registry add allow redirect (#6120)
Signed-off-by: Somefive <yd219913@alibaba-inc.com>
2023-06-14 14:22:12 +08:00
zhaohuiweixiaoandGitHub 95fa62164a Fix: addon status list addon info error when there are mulitiple registries (#6073)
Signed-off-by: zhaohuihui <zhaohuihui_yewu@cmss.chinamobile.com>
2023-06-13 10:34:52 +08:00
SomefiveandGitHub f1bae16723 Chore: remove schematic kube and helm (#6099)
* Chore: remove unused code

Signed-off-by: Somefive <yd219913@alibaba-inc.com>

* Chore: remove schematic Kube & Helm

Signed-off-by: Somefive <yd219913@alibaba-inc.com>

---------

Signed-off-by: Somefive <yd219913@alibaba-inc.com>
2023-06-12 10:41:02 +08:00
SomefiveandGitHub c255d21ad6 Chore: remove unnecessary go mod (#6093)
Signed-off-by: Somefive <yd219913@alibaba-inc.com>
2023-06-08 15:32:57 +08:00
SomefiveandGitHub f15eba2c5f Chore: remove legacy rollout and scope (#6068)
* Chore: remove legacy rollout & scope

Signed-off-by: Somefive <yd219913@alibaba-inc.com>

* remove outdated params

Signed-off-by: Somefive <yd219913@alibaba-inc.com>

* fix

Signed-off-by: Somefive <yd219913@alibaba-inc.com>

---------

Signed-off-by: Somefive <yd219913@alibaba-inc.com>
2023-06-05 10:57:38 +08:00
SomefiveandGitHub eb4b1a8161 Fix: vela def vet can be used without Kubernetes (#6063) 2023-06-01 14:15:45 +08:00
SomefiveandGitHub dd899c2b39 Chore: remove outdated apis(v1alppha2 ApplicationConfiguration Component, and HealthScope, Rollout) (#6041)
* remove outdated api

Signed-off-by: Somefive <yd219913@alibaba-inc.com>

* fix rt test: no component rt

Signed-off-by: Somefive <yd219913@alibaba-inc.com>

* recover context.revision to component hash

Signed-off-by: Somefive <yd219913@alibaba-inc.com>

---------

Signed-off-by: Somefive <yd219913@alibaba-inc.com>
2023-06-01 09:32:49 +08:00
SomefiveandGitHub 057441bc76 Chore: set CLI verbose output to be hidden by default (#6016)
Signed-off-by: Somefive <yd219913@alibaba-inc.com>
2023-05-30 14:53:41 +08:00
SomefiveandGitHub ef4bb07fb3 Chore: remove dm (#6036)
Signed-off-by: Somefive <yd219913@alibaba-inc.com>
2023-05-25 13:54:35 +08:00
SomefiveandGitHub 4d81ba8909 Feat: support force resource location with dispatch (#6033)
Signed-off-by: Somefive <yd219913@alibaba-inc.com>
2023-05-25 10:18:50 +08:00
SomefiveandGitHub e109d4e525 Chore: upgrade kubebuilder installation in unit-test ci (#6018)
* Chore: upgrade kubebuilder installation in unit-test ci

Signed-off-by: Somefive <yd219913@alibaba-inc.com>

* upgrade ingress in kuebuilder test

Signed-off-by: Somefive <yd219913@alibaba-inc.com>

---------

Signed-off-by: Somefive <yd219913@alibaba-inc.com>
2023-05-23 14:46:22 +08:00
caiqi1111andGitHub 3a933780de Fix: add cluster information for vela adopt help (#6015)
Signed-off-by: caiqi <caiqi_yewu@cmss.chinamobile.com>
2023-05-22 16:32:33 +08:00
SomefiveandGitHub 1b9bdffd06 fix multicluster adopt (#5988)
Signed-off-by: Somefive <yd219913@alibaba-inc.com>
2023-05-18 10:44:25 +08:00
iyearandGitHub f3f2af81b4 Refactor: transparent and extensible cuegen decl (#6006)
Signed-off-by: iyear <ljyngup@gmail.com>
2023-05-18 10:00:49 +08:00
SomefiveandGitHub 530d7c5bd6 Feat: support resource update policy (#6003) 2023-05-17 16:11:06 +08:00
zhaohuiweixiaoandGitHub eaa7f5821e Fix: list addon commond displays only the first 20 entries when addon registry is gitlab type (#5999)
* Fix: list addon commond displays only the first 20 entries when addon registry is gitlab type

Signed-off-by: zhaohuihui <zhaohuihui_yewu@cmss.chinamobile.com>

* Fix: add tips for registry addon command

Signed-off-by: zhaohuihui <zhaohuihui_yewu@cmss.chinamobile.com>

* Fix: modify the addon registry command tip

Signed-off-by: zhaohuihui <zhaohuihui_yewu@cmss.chinamobile.com>

---------

Signed-off-by: zhaohuihui <zhaohuihui_yewu@cmss.chinamobile.com>
2023-05-17 15:32:14 +08:00
1af82cd282 cleanup: remove unused code and fix typo (#5986)
Signed-off-by: yyzxw <1020938856@qq.com>
Signed-off-by: xiaowu.zhu <xiaowu.zhu@daocloud.io>
Co-authored-by: xiaowu.zhu <xiaowu.zhu@daocloud.io>
2023-05-16 12:37:00 +08:00
SomefiveandGitHub e0d106024b Feat: remove vela install version requirement upper bound (#5996)
* Feat: relax vela install requirement upper bound

Signed-off-by: Somefive <yd219913@alibaba-inc.com>

* Fix: typo

Signed-off-by: Somefive <yd219913@alibaba-inc.com>

---------

Signed-off-by: Somefive <yd219913@alibaba-inc.com>
2023-05-16 11:57:40 +08:00
SomefiveandGitHub d59b116d06 Feat: upgrade ginkgo to v2 (#5940)
Signed-off-by: Somefive <yd219913@alibaba-inc.com>
2023-05-15 16:07:51 +08:00
Siege LionandGitHub d19bb89ce7 Fix: fix the typo error in vela top (#5982) 2023-05-12 22:41:41 +08:00
iyearandGitHub e5b9dca03c Feat: support def gen-doc command (#5975)
* Feat: support def gen-doc command

Signed-off-by: iyear <ljyngup@gmail.com>

* Fix: ci error

Signed-off-by: iyear <ljyngup@gmail.com>

* Fix: typo

Signed-off-by: iyear <ljyngup@gmail.com>

---------

Signed-off-by: iyear <ljyngup@gmail.com>
2023-05-12 14:24:49 +08:00
iyearandGitHub 01e4dcb667 Feat: only print to stdout (#5958) 2023-05-10 14:17:16 +08:00
iyearandGitHub af0556a52b Feat: provider doc generator (#5968)
Signed-off-by: iyear <ljyngup@gmail.com>
2023-05-10 10:25:35 +08:00
iyearandGitHub e675cdafc4 Feat: add vela def gen-cue command (#5956)
* Feat: add vela def gen-cue command

Signed-off-by: iyear <ljyngup@gmail.com>

* Fix: golangci-lint G304 error

Signed-off-by: iyear <ljyngup@gmail.com>

* Chore: remove useless stat

Signed-off-by: iyear <ljyngup@gmail.com>

* Chore: remove useless log

Signed-off-by: iyear <ljyngup@gmail.com>

* Chore: type alias

Signed-off-by: iyear <ljyngup@gmail.com>

---------

Signed-off-by: iyear <ljyngup@gmail.com>
2023-05-05 20:26:13 +09:00
SomefiveandGitHub fb79ee433c Chore: refactor vela cli entrance (#5909)
Signed-off-by: Somefive <yd219913@alibaba-inc.com>
2023-04-27 10:02:47 +08:00
iyearandGitHub 5b8c38ad3e Feat: initial provider generator (#5839)
* Feat: initial provider generator

Signed-off-by: iyear <ljyngup@gmail.com>

* Fix: distinguish any and ellipsis type

Signed-off-by: iyear <ljyngup@gmail.com>

---------

Signed-off-by: iyear <ljyngup@gmail.com>
2023-04-25 10:30:23 +08:00
3de9e391ee Feat: vela cuex eval (#5562)
* Feat: vela cuex render

Signed-off-by: Somefive <yd219913@alibaba-inc.com>

* feat: CLI command `vela cuex eval <file>`

Signed-off-by: Zhenghao Lou <rhzx3519@gmail.com>

* responsive writer

Signed-off-by: Somefive <yd219913@alibaba-inc.com>

---------

Signed-off-by: Somefive <yd219913@alibaba-inc.com>
Signed-off-by: Zhenghao Lou <rhzx3519@gmail.com>
Co-authored-by: Zhenghao Lou <rhzx3519@gmail.com>
2023-04-23 10:21:11 +08:00
iyearandGitHub 9042ed078b Fix: make any as top value in cue (#5893)
* Fix: make any as top value in cue

Signed-off-by: iyear <ljyngup@gmail.com>

* Feat: support different cue special type in type option

Signed-off-by: iyear <ljyngup@gmail.com>

* Fix: unit test type option

Signed-off-by: iyear <ljyngup@gmail.com>

---------

Signed-off-by: iyear <ljyngup@gmail.com>
2023-04-21 16:45:34 +08:00