Commit Graph
3272 Commits
Author SHA1 Message Date
214b63f6f7 Do not assume a port name is a string when clearing node ports (#10132)
Run the E2E test on kind / setup-test-matrix (push) Failing after 2s
Scorecard supply-chain security / Scorecard analysis (push) Skipped
e2e-test-kind.yaml / extract (push) Failing after 6s
Run the E2E test on kind / get-go-version (push) Failing after 7s
Run the E2E test on kind / build (push) Skipped
Run the E2E test on kind / run-e2e-test (push) Skipped
push.yml / extract (push) Failing after 6s
Main CI / get-go-version (push) Failing after 7s
Main CI / Build (push) Skipped
* Do not assume a port name is a string when clearing node ports

deleteNodePorts reads the last-applied-configuration annotation, which
is free-form JSON controlled by whoever produced the backup, and cast
p["name"] to string without checking. A port whose name is a number
crashed the restore of that Service with an interface conversion panic.
Every sibling in the same loop already uses the comma-ok form.

Signed-off-by: Arpit Jain <arpitjain099@gmail.com>

* Add changelog file

Signed-off-by: Arpit Jain <arpitjain099@gmail.com>

* Convert name to string by Sprint.

Signed-off-by: Xun Jiang <xun.jiang@broadcom.com>

---------

Signed-off-by: Arpit Jain <arpitjain099@gmail.com>
Signed-off-by: Xun Jiang <xun.jiang@broadcom.com>
Co-authored-by: Xun Jiang <xun.jiang@broadcom.com>
2026-09-15 09:50:10 -04:00
Lyndon-Li 66d54af22c issue 10429: sync the calls to IsConstrained
Signed-off-by: Lyndon-Li <lyonghui@vmware.com>
2026-09-15 17:46:32 +08:00
Lyndon-Li 4acad69133 Merge branch 'main' into fix-issue-10429 2026-09-15 17:39:47 +08:00
Lyndon-Li a93e4769bc issue 10429: sync the calls to IsConstrained
Signed-off-by: Lyndon-Li <lyonghui@vmware.com>
2026-09-15 17:38:30 +08:00
Chlins ZhangandGitHub 96d46c5e8f Merge pull request #10480 from abhayrajjais01/fix/inplace-preflight-nil-check
fix(restore): guard against nil PVC in in-place restore preflight checks
2026-09-15 16:15:50 +08:00
Chlins ZhangandGitHub 53a6c37d2f Merge pull request #10449 from PratikMane0112/fix/snapshot-location-label-selector
Fix snapshot-location get --selector flag to actually filter VolumeSnapshotLocations by label
2026-09-15 16:04:34 +08:00
Chlins ZhangandGitHub 716e3e8233 Merge pull request #10027 from kaovilai/add-restore-notin-selector-tests
Add set-based label selector test and docs coverage for restore
2026-09-15 16:01:54 +08:00
lyndon-liandGitHub c5003e8651 Merge pull request #10494 from abhayrajjais01/fix/csi-pvc-action-context-and-errors
fix(restore): propagate context and standardize errors in CSI PVC restore action
2026-09-15 14:33:59 +08:00
lyndon-liandGitHub c4f73126e8 Merge pull request #10526 from Daniel-1600/fix/schedule-create-backup-type
Fix schedule create dropping backup type
2026-09-15 14:33:50 +08:00
872f903091 Add configurable tolerations for PodVolumeBackup and data mover pods (#9575)
Run the E2E test on kind / setup-test-matrix (push) Failing after 3s
Scorecard supply-chain security / Scorecard analysis (push) Skipped
e2e-test-kind.yaml / extract (push) Failing after 6s
Run the E2E test on kind / get-go-version (push) Failing after 7s
Run the E2E test on kind / build (push) Skipped
Run the E2E test on kind / run-e2e-test (push) Skipped
push.yml / extract (push) Failing after 6s
Main CI / get-go-version (push) Failing after 7s
Main CI / Build (push) Skipped
* Remove toleration whitelist for PodVolumeBackup and data mover pods

Instead of filtering tolerations through a hardcoded allowlist
(ThirdPartyTolerations), inherit all tolerations from the node-agent
daemonset for PodVolumeBackup/Restore and DataUpload/Download pods,
and from the Velero deployment for maintenance jobs.

This enables backups and restores on nodes with custom NoExecute taints,
which was previously impossible since only two specific toleration keys
were whitelisted.

Fixes #9476

Signed-off-by: Tiger Kaovilai <tkaovila@redhat.com>

Generated with [Claude Code](https://claude.ai/code)
via [Happy](https://happy.engineering)

Co-Authored-By: Claude <noreply@anthropic.com>
Co-Authored-By: Happy <yesreply@happy.engineering>

* Fix codespell: replace 'whitelist' with 'allowlist' in changelog

Signed-off-by: Tiger Kaovilai <tkaovila@redhat.com>

Generated with [Claude Code](https://claude.ai/code)
via [Happy](https://happy.engineering)

Co-Authored-By: Claude <noreply@anthropic.com>
Co-Authored-By: Happy <yesreply@happy.engineering>

* Implement deduplication of tolerations and add unit tests for the new function

Signed-off-by: Tiger Kaovilai <tkaovila@redhat.com>

* Merge node-agent-configmap tolerations with third-party allowlist

Add a `tolerations` field to the node-agent-configmap so operators can
declare hosting-pod tolerations explicitly, per blackpiglet's review
feedback that tolerations shouldn't be read from the DaemonSet alone.
These are merged with (and deduplicated against) DaemonSet tolerations
matching the existing third-party allowlist
(kubernetes.azure.com/scalesetpriority, CriticalAddonsOnly), restoring
that allowlist per the follow-up suggestion to keep inheriting it
alongside the new config option.

The toleration dedup helper is moved from pkg/exposer to
pkg/util/kube (exported as DeduplicateTolerations) so it can be
shared with pkg/nodeagent without an import cycle.

Signed-off-by: Tiger Kaovilai <tkaovila@redhat.com>

* Fix testifylint finding in TestGetTolerations

golangci-lint v2.12.0 (pinned in pr-linter-check.yml) flagged the
shared assert.Equal after the if/else as require-error: use require
for the error assertion so each branch is self-contained, matching
the pattern used elsewhere in this file.

Signed-off-by: Tiger Kaovilai <tkaovila@redhat.com>

* Document toleration merge priority in GetTolerations

Per blackpiglet's review feedback: clarify that configured tolerations
take priority over allowlisted daemonset tolerations because they're
appended first and DeduplicateTolerations keeps only the first
occurrence of each exact (Key, Operator, Value, Effect) combination.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Signed-off-by: Tiger Kaovilai <tkaovila@redhat.com>

---------

Signed-off-by: Tiger Kaovilai <tkaovila@redhat.com>
Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Happy <yesreply@happy.engineering>
2026-09-14 18:05:01 -04:00
Chlins ZhangandGitHub 2e38432244 Merge pull request #10512 from chlins/feat/inplace-preflight-check3
e2e-test-kind.yaml / extract (push) Failing after 6s
Run the E2E test on kind / get-go-version (push) Failing after 7s
Run the E2E test on kind / build (push) Skipped
Run the E2E test on kind / setup-test-matrix (push) Failing after 2s
Run the E2E test on kind / run-e2e-test (push) Skipped
push.yml / extract (push) Failing after 6s
Scorecard supply-chain security / Scorecard analysis (push) Skipped
Main CI / get-go-version (push) Failing after 7s
Main CI / Build (push) Skipped
Add in-place restore pre-flight check: PVC must be large enough for the backed-up data
2026-09-14 13:57:04 +08:00
Abhayraj JaiswalandGitHub e6d1c8d5e1 Merge branch 'main' into fix/csi-pvc-action-context-and-errors 2026-09-12 16:26:50 +05:30
Daniel Mungai 7d31c708e8 Fix schedule create dropping backup type
Signed-off-by: Daniel Mungai <chegedan699@gmail.com>
2026-09-11 14:25:45 +03:00
chlins bb01691e6b Add in-place restore pre-flight check: PVC must be large enough for the source volume
Compare the existing PVC's capacity against the source volume size
recorded in the backup volume info (#10506) before any side effect and
skip the volume when it is too small, so the restore fails early instead
of running out of space midway. For the block data mover the source size
is the device size; for the file system data movers it is the logical
size of the backed-up files, a lower bound since file system metadata is
not accounted for.

The file system path reads the size from the volume info already carried
in RestoreData. The PVC CSI RIA has no access to the volume info, so the
restore engine carries the size on the PVC item through a Velero-internal
annotation, the same mechanism as the selected-node carrier; both carrier
annotations are stripped before the item is created in the cluster.

The check is skipped when the source size is unknown (backups taken
before it was recorded) or the PVC's capacity is not reported.

Signed-off-by: chlins <chlins.zhang@gmail.com>
2026-09-11 17:10:14 +08:00
Lyndon-Li a827f607b5 update fallbackFull in restore finalizer
Signed-off-by: Lyndon-Li <lyonghui@vmware.com>
2026-09-11 16:59:51 +08:00
Lyndon-Li 13a630a15a Merge branch 'main' into add-fallback-full-to-volume-info 2026-09-11 16:19:27 +08:00
lyndon-liandGitHub 7e67f03796 Merge pull request #10513 from ywk253100/cli
Run the E2E test on kind / setup-test-matrix (push) Failing after 4s
Scorecard supply-chain security / Scorecard analysis (push) Skipped
e2e-test-kind.yaml / extract (push) Failing after 8s
Run the E2E test on kind / get-go-version (push) Failing after 9s
Run the E2E test on kind / build (push) Skipped
Run the E2E test on kind / run-e2e-test (push) Skipped
push.yml / extract (push) Failing after 6s
Main CI / get-go-version (push) Failing after 8s
Main CI / Build (push) Skipped
Update volume info in restore finalizing stage
2026-09-11 16:02:50 +08:00
lyndon-liandGitHub 34a9f500cc let uploader to control fallback centrally (#10523)
Signed-off-by: Lyndon-Li <lyonghui@vmware.com>
2026-09-11 00:34:13 -04:00
Lyndon-Li 6b3e7ef5dd add fallback to volume info and backup/restore describe
Signed-off-by: Lyndon-Li <lyonghui@vmware.com>
2026-09-10 18:22:35 +08:00
Abhayraj Jaiswal 770a251ed5 fix(restore): propagate context and standardize errors in CSI PVC restore action
Signed-off-by: Abhayraj Jaiswal <abhayraj916146@gmail.com>
2026-09-10 09:55:44 +00:00
Abhayraj Jaiswal b51a2b20d3 fix(restore): guard against nil PVC in in-place restore preflight checks
Signed-off-by: Abhayraj Jaiswal <abhayraj916146@gmail.com>
2026-09-10 09:54:50 +00:00
Lyndon-Li f9ebe14e16 add backup/restore type and fallback to backup/restore describe
Signed-off-by: Lyndon-Li <lyonghui@vmware.com>
2026-09-10 17:23:46 +08:00
Lyndon-Li f584d76b32 return fallback info from uploader
Signed-off-by: Lyndon-Li <lyonghui@vmware.com>
2026-09-10 16:40:02 +08:00
Lyndon-Li 55c756ed0f data path support fallbackFull
Signed-off-by: Lyndon-Li <lyonghui@vmware.com>
2026-09-10 16:12:22 +08:00
Lyndon-Li b273b78795 relocate the backup/restore types in volumeInfo
Signed-off-by: Lyndon-Li <lyonghui@vmware.com>
2026-09-10 15:50:39 +08:00
Wenkai Yin (尹文开) a3d744db6a Update volume info in restore finalizing stage
Update volume info in restore finalizing stage to record info from DataDownload result

Signed-off-by: Wenkai Yin (尹文开) <wenkai.yin@broadcom.com>
2026-09-10 15:04:54 +08:00
Lyndon-Li 159e98e906 add fallbackFull to DD and PVR
Signed-off-by: Lyndon-Li <lyonghui@vmware.com>
2026-09-10 15:02:52 +08:00
Lyndon-Li 23d4233c82 add fallbackFull to DU and PVB and volumeInfo
Signed-off-by: Lyndon-Li <lyonghui@vmware.com>
2026-09-10 14:44:52 +08:00
lyndon-liandGitHub 87b45ed7fd Merge pull request #10506 from Lyndon-Li/save-source-size-to-backup
Save source size to volume info
2026-09-10 14:29:48 +08:00
lyndon-liandGitHub e8af012ac5 Merge pull request #10479 from Lyndon-Li/report-incremental-fallback
Report incremental fallback message
2026-09-10 14:29:19 +08:00
Max Freedom PollardandGitHub 4c007c0af4 Scope schedule and repo CLI list calls to the Velero namespace (#10482)
Run the E2E test on kind / setup-test-matrix (push) Failing after 4s
e2e-test-kind.yaml / extract (push) Failing after 6s
Run the E2E test on kind / get-go-version (push) Failing after 7s
Run the E2E test on kind / build (push) Skipped
Run the E2E test on kind / run-e2e-test (push) Skipped
push.yml / extract (push) Failing after 6s
Main CI / get-go-version (push) Failing after 8s
Main CI / Build (push) Skipped
Scorecard supply-chain security / Scorecard analysis (push) Skipped
* Scope schedule and repo CLI list calls to the Velero namespace

velero schedule get, velero schedule describe, velero schedule
pause/unpause and velero repo get built a ctrlclient.ListOptions with a
LabelSelector but no Namespace, so the list ran across every namespace in
the cluster. Their single-name paths in the same functions already scope
to f.Namespace(), and every sibling command (backup get, restore get,
backup describe, restore describe, snapshot-location get, schedule
delete) passes Namespace too, so the omission was an oversight rather
than intent.

The read commands print another installation's Schedules and
BackupRepositories. runPause is worse: velero schedule pause --all and
velero schedule unpause --all fetch Schedules from every namespace and
then write Spec.Paused on each, so pausing one installation's schedules
pauses every other installation's schedules as well.

Add Namespace: f.Namespace() to the four List calls:

  pkg/cmd/cli/schedule/get.go:61
  pkg/cmd/cli/schedule/describe.go:59
  pkg/cmd/cli/schedule/pause.go:114
  pkg/cmd/cli/repo/get.go:61

Neither pkg/cmd/cli/schedule nor pkg/cmd/cli/repo had any tests, so the
regression tests are new files. Each seeds a fake client with one object
in the Velero namespace and one in another-velero, and asserts the second
is neither listed, described, nor paused.

Signed-off-by: Max Freedom Pollard <272618364+MaxFreedomPollard@users.noreply.github.com>

* Add changelog for PR 10482

Signed-off-by: Max Freedom Pollard <272618364+MaxFreedomPollard@users.noreply.github.com>

---------

Signed-off-by: Max Freedom Pollard <272618364+MaxFreedomPollard@users.noreply.github.com>
2026-09-09 16:52:11 -04:00
HeonJe LeeandGitHub cbd9059f80 Fix user version priorities parsing to handle CRLF line endings (#10496)
Run the E2E test on kind / setup-test-matrix (push) Failing after 3s
e2e-test-kind.yaml / extract (push) Failing after 6s
Run the E2E test on kind / get-go-version (push) Failing after 8s
Run the E2E test on kind / build (push) Skipped
Run the E2E test on kind / run-e2e-test (push) Skipped
push.yml / extract (push) Failing after 5s
Main CI / get-go-version (push) Failing after 6s
Main CI / Build (push) Skipped
formatUserPriorities stripped only spaces, so an enableapigroupversions
ConfigMap written with CRLF line endings (common for files edited on
Windows) kept a trailing carriage return in each version string, e.g.
"v2beta1\r". versionsContain compares versions with equality, so the
user priority never matched and was silently ignored. Trim the trailing
carriage return so stored versions match again.

Signed-off-by: HeonJe LEE <lhjnano@gmail.com>
2026-09-09 10:24:42 -04:00
Lyndon-Li daed42b1d8 save source size to volume info for DU and PVB
Signed-off-by: Lyndon-Li <lyonghui@vmware.com>
2026-09-09 17:34:17 +08:00
Lyndon-Li e0e600d715 save source size for PVB
Signed-off-by: Lyndon-Li <lyonghui@vmware.com>
2026-09-09 16:09:08 +08:00
Lyndon-Li e52bf08c99 refactor CBT retrievement to report the concrete error
Signed-off-by: Lyndon-Li <lyonghui@vmware.com>
2026-09-09 15:55:01 +08:00
Lyndon-Li 6b549f35b3 Merge branch 'main' into save-source-size-to-backup 2026-09-09 15:50:06 +08:00
Tiger KaovilaiandGitHub 193cfdc58f Fix datamover backup arg mismatch for CSI CBT service account name (#10318)
Run the E2E test on kind / setup-test-matrix (push) Failing after 3s
e2e-test-kind.yaml / extract (push) Failing after 6s
Run the E2E test on kind / get-go-version (push) Failing after 8s
Run the E2E test on kind / build (push) Skipped
Run the E2E test on kind / run-e2e-test (push) Skipped
push.yml / extract (push) Failing after 6s
Main CI / get-go-version (push) Failing after 8s
Main CI / Build (push) Skipped
* Fix datamover backup arg mismatch for CSI CBT service account name

The exposer built the pod command with --csi-snapshot-metadata-service-sa,
but the datamover backup command only registered --cbt-sa-name. cobra
rejects unknown flags, so the data mover pod exited immediately whenever
a dedicated CBT service account was configured -- and the reverse also
held: since the flags never matched, the SA name never actually reached
the pod, so any code path depending on it stayed unreachable.

Not limited to the block data mover: this line sits outside the
DataMoverTypeVeleroBlock gate and the cbtInfo != nil gate, so it fires
for any CSI snapshot data-movement backup.

Fix: emit --cbt-sa-name (already consumed by the backup command), naming
it consistently with the other CBT flags on the same line (--change-id,
--volume-id, --snapshot-id).

Add a regression test asserting the emitted flag string parses cleanly
against NewBackupCommand's own flag set, so the two sides can't drift
apart again without a test failure.

* Add changelog for #10318

Signed-off-by: Tiger Kaovilai <tkaovila@redhat.com>
2026-09-09 06:34:06 +00:00
Lyndon-Li 44f09189c2 Merge branch 'main' into report-incremental-fallback 2026-09-09 14:19:59 +08:00
Yonghui Li 9d85334d40 refactor CBT retrievement to report the concrete error
Signed-off-by: Yonghui Li <lyonghui@vmware.com>
2026-09-09 14:14:54 +08:00
Xun Jiang/Bruce JiangandGitHub c7a93be95a Add MustIncludeAdditionalItemPVCs to help track BIA added PVC's PVB creation. (#10501)
* Add MustIncludeAdditionalItemPVCs structure in backup. It's used to track PVCs returned by BIA with mustIncluded annotaion and PVC is excluded from backup by global filter.
* Modfiy the volumeHelper interface to add a parameter function for ShouldPerformFSBackup.
* Modify to support fine-grained backup filters.
* Modify according to comments. Use a read-only interface to replace the parameter function.

Signed-off-by: Xun Jiang <xun.jiang@broadcom.com>
2026-09-09 14:04:57 +08:00
lyndon-liandGitHub 88da86fb67 Merge pull request #10500 from Lyndon-Li/add-id-to-repo-snapshot
Add ID to repo snapshot
2026-09-09 11:02:49 +08:00
lyndon-liandGitHub 32c918b0fa Merge pull request #10307 from kaovilai/pr-bug4-gap6
Run the E2E test on kind / setup-test-matrix (push) Failing after 3s
e2e-test-kind.yaml / extract (push) Failing after 10s
Run the E2E test on kind / get-go-version (push) Failing after 11s
Run the E2E test on kind / build (push) Skipped
Run the E2E test on kind / run-e2e-test (push) Skipped
push.yml / extract (push) Failing after 7s
Main CI / get-go-version (push) Failing after 8s
Main CI / Build (push) Skipped
Fix generic CSI changeID retrieval and honor snapshot class deletion policy for CBT retention
2026-09-09 08:36:31 +08:00
Yonghui Li 8e604b17b2 add ID to repo snapshot
Signed-off-by: Yonghui Li <lyonghui@vmware.com>
2026-09-08 18:15:34 +08:00
Yonghui Li 9fedb48e9a Merge branch 'main' into report-incremental-fallback 2026-09-08 14:11:24 +08:00
0255c6b8bf Add block data mover support for Velero backup/restore describe CLI. (#10436)
e2e-test-kind.yaml / extract (push) Failing after 10s
Run the E2E test on kind / get-go-version (push) Failing after 11s
Run the E2E test on kind / build (push) Skipped
Run the E2E test on kind / setup-test-matrix (push) Failing after 3s
Run the E2E test on kind / run-e2e-test (push) Skipped
push.yml / extract (push) Failing after 7s
Main CI / get-go-version (push) Failing after 8s
Main CI / Build (push) Skipped
* Add block data mover support for Velero backup/restore describe CLI.

Update output tests to accommodate RestoreType in VolumeInfo
This commit addresses the compilation and assertion errors caused by the introduction of `RestoreType` in `VolumeInfo` and the separation of `SnapshotDataMovementInfo` / `PodVolumeInfo` into their backup and restore counterparts. It fixes references across the test fixtures and the print guard conditions in `restore_describer.go`.

* Modify according to comments
* Add missing JSON tag in the VolumeInfo structures.
* Get uploaderType from the DU and DD's dataMover for the data mover volume info.
* Add IncrementalSize in the data mover volume info.
* Add existingVolumeDataPolicy and restoreType in the restore describe CLI output
* Add more UTs.
* Add some fields value setting that were previously missed.
* Fix the timestamp compare error only found in the GitHub action.

Signed-off-by: Xun Jiang <xun.jiang@broadcom.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-07 14:48:41 +08:00
Lyndon-Li e1600caab3 record source size to volume info
Signed-off-by: Lyndon-Li <lyonghui@vmware.com>
2026-09-04 19:50:45 +08:00
Lyndon-Li 6c86921876 du support source size
Signed-off-by: Lyndon-Li <lyonghui@vmware.com>
2026-09-04 19:49:12 +08:00
Lyndon-Li d0884e7ce7 return source size from uploader
Signed-off-by: Lyndon-Li <lyonghui@vmware.com>
2026-09-04 19:45:12 +08:00
Lyndon-Li df709d39d6 report incremental fallback message
Signed-off-by: Lyndon-Li <lyonghui@vmware.com>
2026-09-04 17:21:57 +08:00
Lyndon-Li 9687d1e30e Merge branch 'main' into report-incremental-fallback 2026-09-04 16:15:06 +08:00