Files
pinniped/.github/ISSUE_TEMPLATE/release_checklist.md
T
2026-07-02 20:10:34 -07:00

4.2 KiB

name, about, title, labels, assignees
name about title labels assignees
Release checklist Checklist for maintainers to prepare for an upcoming release Release checklist for vX.X.X

Release checklist

  • Ensure that Pinniped's dependencies have been upgraded, to the extent desired by the team (refer to PRs created by the all-golang-deps-updated CI job)
    • If you are updating golang in Pinniped, be sure to update golang in CI as well. Do a search-and-replace to update the version number everywhere in the pinniped ci branch.
    • If the Fosite library is being updated and the format of the content of the Supervisor's storage Secrets are changed, or if any change to our own code changes the format of the content of the Supervisor's session storage Secrets, then be sure to update the accessTokenStorageVersion, authorizeCodeStorageVersion, oidcStorageVersion, pkceStorageVersion, refreshTokenStorageVersion, variables in files such as internal/fositestorage/accesstoken/accesstoken.go. Failing tests should signal the need to update these values.
    • Evaluate all replace directives in the go.mod file. Are those versions up-to-date? Can any replace directives be removed?
    • Evaluate all overrides in the hack/update-go-mod/overrides.conf file. Are those versions up-to-date? Can those overrides be removed?
  • Ensure that the k8s-code-generator CI job definitions are up-to-date with the latest Go, K8s, and controller-gen versions. Update the pipeline. Trigger the jobs again after updating them by running hack/rebuild-codegen-images.sh from the ci branch. After they finish, use hack/update.sh to update the generated source code and then make a PR.
  • Ensure that Pinniped's codegen is up-to-date with the latest Kubernetes releases by making sure this file is updated compared to the latest releases listed here for active branches and here for non-active branches. Run hack/update.sh after changing the file to update the generated source code and then make a PR.
  • Ensure that the pull-requests and main CI pipelines are using the latest patch releases of Kind for each minor version that are available from https://hub.docker.com/r/kindest/node/tags
  • All relevant dependency bump, feature, and docs PRs are merged
    • Waiting for any PRs? Add them here as new items. No? Just check this box.
  • The main pipeline is green, up to and including the ready-to-release job. Check that the expected git commit has passed the ready-to-release job.
  • Manually trigger these jobs in the main pipeline to run other pre-release tests. Depending on the number of Concourse workers, you may need to run these one at a time. Manually check that the resulting job runs passed.
    • run-int-misc
    • run-int-cloud-providers
    • run-int-k8s-versions
  • Optional: a blog post for the release is written and submitted as a PR but not merged yet
  • All merged user stories are accepted (manually tested)
  • Only after all stories are accepted, manually trigger the release job to create a draft GitHub release
  • Manually edit the draft release notes on the GitHub release to describe the contents of the release, using the format which was automatically added to the draft release
  • Publish (i.e. make public) the draft release
  • After making the release public, the jobs in the main pipeline beyond the release job should auto-trigger, so check to make sure that they passed. One of them submits a PR. Merge it.
  • If you wrote a blog post PR, edit the blog post's date to make it match the actual release date, and merge the blog post PR to make it live on the website
  • Publicize the release via Kubernetes Slack, etc.
  • Close this issue