Commit Graph
6943 Commits
Author SHA1 Message Date
9d2e00e2e1 fix: use env var for PR number in shell script; add changelog
Run the E2E test on kind / setup-test-matrix (push) Failing after 4s
e2e-test-kind.yaml / extract (push) Failing after 7s
Run the E2E test on kind / get-go-version (push) Failing after 8s
Run the E2E test on kind / build (push) Skipped
Run the E2E test on kind / run-e2e-test (push) Skipped
Co-authored-by: kaovilai <11228024+kaovilai@users.noreply.github.com>
Signed-off-by: Tiger Kaovilai <tkaovila@redhat.com>
2026-09-29 21:29:29 +08:00
7b71eaf233 fix: privilege-separate re-request-review to support fork PRs
Co-authored-by: kaovilai <11228024+kaovilai@users.noreply.github.com>
Signed-off-by: Tiger Kaovilai <tkaovila@redhat.com>
2026-09-29 21:29:29 +08:00
Xun Jiang/Bruce JiangandGitHub db929b332a Merge pull request #10463 from wangyusheng1985/repo-agent/bcf4e6c6-auto
Run the E2E test on kind / setup-test-matrix (push) Failing after 3s
e2e-test-kind.yaml / extract (push) Failing after 6s
Run the E2E test on kind / get-go-version (push) Failing after 8s
Run the E2E test on kind / build (push) Skipped
Run the E2E test on kind / run-e2e-test (push) Skipped
push.yml / extract (push) Failing after 7s
Main CI / get-go-version (push) Failing after 8s
Main CI / Build (push) Skipped
Scorecard supply-chain security / Scorecard analysis (push) Skipped
Fix stale contributor documentation link
2026-09-29 18:00:38 +08:00
yusheng.wang c51f74b8f6 Fix stale contributor documentation link
Signed-off-by: wangyusheng1985 <wangyusheng1985@users.noreply.github.com>
Signed-off-by: yusheng.wang <yusheng.wang@chaitin.com>
2026-09-29 16:53:26 +08:00
Xun Jiang/Bruce JiangandGitHub dafc4d3254 Merge pull request #10077 from velero-io/copilot/dependabot-auto-approve-action
Add Dependabot auto-approve workflow
2026-09-29 16:36:13 +08:00
copilot-swe-agent[bot]andXun Jiang/Bruce Jiang b56d6c33ef Add Dependabot auto-approve workflow
Run the E2E test on kind / setup-test-matrix (push) Failing after 3s
e2e-test-kind.yaml / extract (push) Failing after 7s
Run the E2E test on kind / get-go-version (push) Failing after 8s
Run the E2E test on kind / build (push) Skipped
Run the E2E test on kind / run-e2e-test (push) Skipped
Signed-off-by: Tiger Kaovilai <tkaovila@redhat.com>
2026-09-29 16:26:31 +08:00
lyndon-liandGitHub ba2765b451 Merge pull request #10603 from Lyndon-Li/fix-prepare-queue-length-doc-issue
Modify the sample in prepare queue length doc
2026-09-29 13:49:41 +08:00
Lyndon-Li b259e7cc1e modify the sample in prepare queue length doc
Signed-off-by: Lyndon-Li <lyonghui@vmware.com>
2026-09-29 13:38:15 +08:00
54e6150e67 docs: fix broken internal links and anchors in main docs (#10590)
locations.md linked to customize-locations.md, which does not exist; the page is customize-installation.md (same heading, and the same line already links there). minio.md linked debugging-install.md without the ../ the rest of that file uses, resolving to a nonexistent contributions/debugging-install.md. restore-reference.md had two dead same-page anchors: #resource-restore-order (heading is Restore order) and #durable-snapshot-pv-restore (heading is Snapshot PV Restore).

Signed-off-by: avneetbansal-aws <284363899+avneetbansal-aws@users.noreply.github.com>
Co-authored-by: avneetbansal-aws <284363899+avneetbansal-aws@users.noreply.github.com>
2026-09-28 23:10:51 -04:00
Kaizhe HuangandGitHub 0f54eefe6f Fix unchecked type assertion panic in ChangeImageNameAction (#10574)
e2e-test-kind.yaml / extract (push) Failing after 9s
Run the E2E test on kind / get-go-version (push) Failing after 10s
Run the E2E test on kind / build (push) Skipped
Run the E2E test on kind / setup-test-matrix (push) Failing after 3s
Run the E2E test on kind / run-e2e-test (push) Skipped
push.yml / extract (push) Failing after 6s
Main CI / get-go-version (push) Failing after 6s
Main CI / Build (push) Skipped
Scorecard supply-chain security / Scorecard analysis (push) Skipped
* Fix unchecked type assertion panic in ChangeImageNameAction

replaceImageName reads a restored container's image field out of the
unstructured object and asserts it to string without checking ok. The
comma-ok map lookup on the line above only confirms the "image" key is
present -- it says nothing about the value's type. A restored resource
whose image field is present but not a JSON string (e.g. a number,
bool, null, array, or object) causes an unrecovered
"interface conversion: interface {} is not string" panic in this
RestoreItemAction plugin whenever the optional image-remapping
ConfigMap feature is configured.

Switch to the comma-ok form of the assertion and skip (with a log
message) any container whose image field isn't a string, instead of
panicking.

Signed-off-by: Kaizhe Huang <derek0405@gmail.com>

* Add regression test for non-string image field panic

Covers the comma-ok assertion fix: replaceImageName operates on
generic unstructured content decoded from a backup tarball, which
isn't validated against the Pod schema before this code runs, so
"image" isn't guaranteed to be a string.

Signed-off-by: Kaizhe Huang <derek0405@gmail.com>

* Guard container-entry type assertion, use unstructured.NestedString

Addresses reviewer feedback: container.(map[string]any) was also an
unchecked assertion, and unstructured.NestedString gives safer,
more idiomatic type-checking than a manual comma-ok assertion. Also
switches the skip-path logging from Info to Warn per review.

Signed-off-by: Kaizhe Huang <derek0405@gmail.com>

---------

Signed-off-by: Kaizhe Huang <derek0405@gmail.com>
2026-09-28 15:29:50 +08:00
Abhayraj JaiswalandGitHub 400aa25475 fix(uploader): align block and kopia snapshot error messages with Velero lowercase standards (#10558)
Signed-off-by: Abhayraj Jaiswal <abhayraj916146@gmail.com>
2026-09-28 15:29:00 +08:00
lyndon-liandGitHub 8b272e6b0e Merge pull request #10585 from officialasishkumar/fix-pvb-node-printcolumn
Point the PodVolumeBackup Node print column at .spec.node
2026-09-28 14:22:32 +08:00
dependabot[bot]GitHubdependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
9ff78a5065 Bump the github-actions group with 3 updates (#10589)
Bumps the github-actions group with 3 updates: [korthout/backport-action](https://github.com/korthout/backport-action), [github/codeql-action](https://github.com/github/codeql-action) and [jpmcb/prow-github-actions](https://github.com/jpmcb/prow-github-actions).


Updates `korthout/backport-action` from 4.6.0 to 4.6.1
- [Release notes](https://github.com/korthout/backport-action/releases)
- [Commits](https://github.com/korthout/backport-action/compare/2e830a1d0b8269505846ddd407a70876913ad1f8...6b65649031ac6d18ffdfd0c0820e9436f3fde22b)

Updates `github/codeql-action` from 4.38.0 to 4.38.1
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](https://github.com/github/codeql-action/compare/v4.38.0...v4.38.1)

Updates `jpmcb/prow-github-actions` from 2.0.0 to 3.0.1
- [Release notes](https://github.com/jpmcb/prow-github-actions/releases)
- [Commits](https://github.com/jpmcb/prow-github-actions/compare/c44ac3a57d67639e39e4a4988b52049ef45b80dd...187c5e3cd95a329c43448e1bdb3b1f5249232e44)

---
updated-dependencies:
- dependency-name: korthout/backport-action
  dependency-version: 4.6.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: github/codeql-action
  dependency-version: 4.38.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: jpmcb/prow-github-actions
  dependency-version: 3.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-28 13:56:20 +08:00
lyndon-liandGitHub e2003dbf0d Merge pull request #10591 from Lyndon-Li/doc-expose-prepare-queue-length
Add node-agent prepare queue length to main page
2026-09-28 11:39:49 +08:00
Lyndon-Li 3391987882 add node-agent prepare queue length to main page
Signed-off-by: Lyndon-Li <lyonghui@vmware.com>
2026-09-28 11:24:33 +08:00
lyndon-liandGitHub 1acecf8754 enable VGDP soothing by default and set queue length as 5 (#10578)
Signed-off-by: Lyndon-Li <lyonghui@vmware.com>
2026-09-28 11:18:50 +08:00
Asish Kumar 1d53a815ca Point the PodVolumeBackup Node print column at .spec.node
PodVolumeBackupStatus has no Node field, so the Node column was always
empty. The node is recorded in the spec.

Fixes #10444

Signed-off-by: Asish Kumar <officialasishkumar@gmail.com>
2026-09-25 23:34:04 +05:30
lyndon-liandGitHub 8e9f66addf Merge pull request #10579 from Lyndon-Li/change-kopia-hashing-alg
Run the E2E test on kind / setup-test-matrix (push) Failing after 4s
e2e-test-kind.yaml / extract (push) Failing after 9s
Run the E2E test on kind / get-go-version (push) Failing after 10s
Run the E2E test on kind / build (push) Skipped
Run the E2E test on kind / run-e2e-test (push) Skipped
push.yml / extract (push) Failing after 6s
Scorecard supply-chain security / Scorecard analysis (push) Skipped
Main CI / get-go-version (push) Failing after 6s
Main CI / Build (push) Skipped
Change hashing algorithm to HMAC-SHA256-128 for kopia repo
2026-09-25 10:06:30 +08:00
KrishhnaTandGitHub 4562c75dd0 e2e: add kind VolumeGroupSnapshotClass test data (#10582)
Run the E2E test on kind / setup-test-matrix (push) Failing after 3s
Scorecard supply-chain security / Scorecard analysis (push) Skipped
e2e-test-kind.yaml / extract (push) Failing after 10s
Run the E2E test on kind / get-go-version (push) Failing after 15s
Run the E2E test on kind / build (push) Skipped
Run the E2E test on kind / run-e2e-test (push) Skipped
push.yml / extract (push) Failing after 9s
Main CI / get-go-version (push) Failing after 10s
Main CI / Build (push) Skipped
* e2e: add kind VolumeGroupSnapshotClass test data

Velero selects a VolumeGroupSnapshotClass by the
velero.io/csi-volumegroupsnapshot-class label, and csi-driver-host-path
ships no VolumeGroupSnapshotClass at all, so there is nothing for the
selector to find on a kind cluster. Any VolumeGroupSnapshot e2e coverage
needs a class to exist first.

Add the kind entry alongside the existing volume-snapshot-class test
data, following the same layout and naming. Verified against a kind
cluster running external-snapshotter v8.6.0 and csi-driver-host-path:
applying this file and creating a VolumeGroupSnapshot that selects two
labelled PVCs reaches readyToUse with both member snapshots ready.

Nothing applies this file yet. It is a prerequisite for the
VolumeGroupSnapshot specs tracked in #7507, kept separate so the class
can be reviewed on its own.

Signed-off-by: krishhna24 <krishhnatupedev@gmail.com>

* Add changelog for #10582

Signed-off-by: krishhna24 <krishhnatupedev@gmail.com>

---------

Signed-off-by: krishhna24 <krishhnatupedev@gmail.com>
2026-09-24 16:21:52 -07:00
43c5aade35 docs: fix --use-volume-snapshots=false in Tencent Cloud guide (#10580)
Signed-off-by: Zain <43629888+ZainnQureshii@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-09-24 18:26:12 -04:00
a9e1f5b383 Add e2e test for namespace selection by label in resource policy (#10565)
* Add e2e test for namespace selection by label in resource policy

Covers design step 8 of #9772: a backup with no explicit
--include-namespaces (the same shape a Schedule with no
includedNamespaces produces), relying entirely on a ResourcePolicy
ConfigMap's includedNamespacesByLabel to select which namespaces to
back up.

Creates labeled and unlabeled namespaces, backs up with a
ResourcePolicy ConfigMap setting includedNamespacesByLabel, and
verifies only the labeled namespaces are restored - closing the e2e
coverage gap #10275 deferred to velero-io/velero#10564.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Signed-off-by: Tiger Kaovilai <tkaovila@redhat.com>

* Add changelog entry for e2e test PR

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Signed-off-by: Tiger Kaovilai <tkaovila@redhat.com>

* Fix e2e test: create Backup directly, not via CLI's implicit --include-namespaces=*

The kind e2e run showed every unlabeled namespace getting backed up
and restored anyway. velero backup create's --include-namespaces flag
defaults to ["*"] when omitted (pkg/cmd/cli/backup/create.go), so
skipping the flag still sent an *explicit* wildcard - and
mergeNamespacesByLabel deliberately leaves an explicit "*" untouched
rather than narrowing it, so includedNamespacesByLabel never got a
chance to replace anything.

Create the Backup object directly via the controller-runtime client
instead, leaving BackupSpec.IncludedNamespaces genuinely unset - the
only way to exercise the "defaulted empty" narrowing path the CLI's
own default makes unreachable.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Signed-off-by: Tiger Kaovilai <tkaovila@redhat.com>

---------

Signed-off-by: Tiger Kaovilai <tkaovila@redhat.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-24 16:26:11 -04:00
Lyndon-Li 0171e17b5c change hashing algorithm to HMAC-SHA256-128 for kopia repo
Signed-off-by: Lyndon-Li <lyonghui@vmware.com>
2026-09-24 16:57:39 +08:00
Daniel JiangandGitHub dfabab70bf Dedup the entries in backuprequest.spec.excludeNamespaces (#10562)
Run the E2E test on kind / setup-test-matrix (push) Failing after 4s
e2e-test-kind.yaml / extract (push) Failing after 8s
Run the E2E test on kind / get-go-version (push) Failing after 9s
Run the E2E test on kind / build (push) Skipped
Run the E2E test on kind / run-e2e-test (push) Skipped
push.yml / extract (push) Failing after 5s
Scorecard supply-chain security / Scorecard analysis (push) Skipped
Main CI / get-go-version (push) Failing after 6s
Main CI / Build (push) Skipped
This commit fixes the issue that when a namespace with label velero.io/exclude-from-backup: "true"
is added to the exludeNamespaces of a backup CR.  There will be
duplicated entries of the namespace in the spec of the backup.

Signed-off-by: Daniel Jiang <daniel.jiang@broadcom.com>
2026-09-24 15:02:47 +08:00
Xun Jiang/Bruce JiangandGitHub 4407481a9b Merge pull request #10561 from git-jxj/docs/restore-filter-source
docs: specify backup source in restore filter examples
2026-09-24 11:47:42 +08:00
7adda843e4 Fix broken links in design docs (#10573)
Links to plugin-versioning.md and general-progress-monitoring.md broke when
those docs moved to design/Implemented/; two other relative paths had one
directory level wrong.

Signed-off-by: Zain <43629888+ZainnQureshii@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-24 11:41:03 +08:00
xinjun.jiang 42d9bebe47 docs: specify backup source in restore filter examples
Signed-off-by: xinjun.jiang <xinjun.jiang@daocloud.io>
2026-09-24 09:32:54 +08:00
Shubham PampattiwarandGitHub 8f438e0b8e Document maintainer contact info and shared responsibility (#10568)
Run the E2E test on kind / setup-test-matrix (push) Failing after 3s
e2e-test-kind.yaml / extract (push) Failing after 8s
Run the E2E test on kind / get-go-version (push) Failing after 8s
Run the E2E test on kind / build (push) Skipped
Run the E2E test on kind / run-e2e-test (push) Skipped
push.yml / extract (push) Failing after 7s
Scorecard supply-chain security / Scorecard analysis (push) Skipped
Main CI / get-go-version (push) Failing after 7s
Main CI / Build (push) Skipped
Add the maintainer information required by the CNCF Incubation criteria:

- State that all maintainers share collective responsibility for the entire
  project, consistent with CODEOWNERS assigning ownership to the maintainer
  group as a whole (no siloed per-area owners).
- Add a Contacting the maintainers section listing GitHub, Slack, the mailing
  list, and the security disclosure process.

This makes MAINTAINERS.md cover names, contact information, domain of
responsibility, and affiliation as required for the Incubation application.

Signed-off-by: Shubham Pampattiwar <spampatt@redhat.com>
2026-09-23 09:59:40 -04:00
Xun Jiang/Bruce JiangandGitHub 00788053ae Customize the tolerations of maintenance job. (#10553)
Run the E2E test on kind / setup-test-matrix (push) Failing after 3s
Scorecard supply-chain security / Scorecard analysis (push) Skipped
e2e-test-kind.yaml / extract (push) Failing after 8s
Run the E2E test on kind / get-go-version (push) Failing after 9s
Run the E2E test on kind / build (push) Skipped
Run the E2E test on kind / run-e2e-test (push) Skipped
push.yml / extract (push) Failing after 6s
Main CI / get-go-version (push) Failing after 7s
Main CI / Build (push) Skipped
Signed-off-by: Xun Jiang <xun.jiang@broadcom.com>
2026-09-23 13:28:06 +08:00
Adam ZhangandGitHub 2b1f1dba73 Merge pull request #10559 from adam-jian-zhang/fix-backup-test
Fix SkippedPVTracker reference in backup tests
2026-09-23 11:09:55 +08:00
57bddf7f23 Fix backup-finalizer: do not set backup phase to Completed before PutBackupMetadata succeeds (#9646)
Run the E2E test on kind / setup-test-matrix (push) Failing after 3s
Scorecard supply-chain security / Scorecard analysis (push) Skipped
e2e-test-kind.yaml / extract (push) Failing after 9s
Run the E2E test on kind / get-go-version (push) Failing after 10s
Run the E2E test on kind / build (push) Skipped
Run the E2E test on kind / run-e2e-test (push) Skipped
push.yml / extract (push) Failing after 6s
Main CI / get-go-version (push) Failing after 7s
Main CI / Build (push) Skipped
* Fix backup-finalizer: do not set backup phase to Completed before PutBackupMetadata succeeds

Previously, the backup finalizer controller set backup.Status.Phase to
Completed/PartiallyFailed in-memory BEFORE calling PutBackupMetadata and
PutBackupContents. When these uploads failed (e.g., due to object lock
or immutability), the deferred patch function still wrote the terminal
phase to the Kubernetes API server, preventing the controller from
retrying the upload on the next reconcile.

This fix moves the phase assignment to AFTER both uploads succeed. A
DeepCopy of the backup is used to encode the JSON with the final phase
for object storage, while the in-memory backup object retains the
Finalizing phase until uploads complete.

Caveats:
- CompletionTimestamp is now captured before upload but only committed to
  the API server after upload succeeds. On retry after a transient
  failure, a new timestamp is generated, so the completion time reflects
  when the upload finally succeeded rather than when finalization
  processing completed.
- Metrics (RegisterBackupSuccess/RegisterBackupPartialFailure) are now
  recorded after uploads succeed, so they accurately reflect only fully
  persisted backups.
- The metadata uploaded to object storage contains the final phase and
  completion timestamp via DeepCopy, so storage state is correct even
  before the API server is patched.

Fixes #9645

Generated with [Claude Code](https://claude.ai/code)
via [Happy](https://happy.engineering)

Co-Authored-By: Claude <noreply@anthropic.com>
Co-Authored-By: Happy <yesreply@happy.engineering>
Signed-off-by: Tiger Kaovilai <tkaovila@redhat.com>

* Add changelog for #9646

Generated with [Claude Code](https://claude.ai/code)
via [Happy](https://happy.engineering)

Co-Authored-By: Claude <noreply@anthropic.com>
Co-Authored-By: Happy <yesreply@happy.engineering>
Signed-off-by: Tiger Kaovilai <tkaovila@redhat.com>

* Fix testifylint: use require.Error instead of assert.Error

Generated with [Claude Code](https://claude.ai/code)
via [Happy](https://happy.engineering)

Co-Authored-By: Claude <noreply@anthropic.com>
Co-Authored-By: Happy <yesreply@happy.engineering>
Signed-off-by: Tiger Kaovilai <tkaovila@redhat.com>

* Address review feedback on backup-finalizer fix

- Add default guard for unhandled phase values in finalPhase switch
- Add retry with DefaultBackoff for PutBackupMetadata per reviewer request
- Replace brittle framework.BackupItemActionResolverV2{} mock with mock.Anything
- Add FinalizingPartiallyFailed test case for PutBackupContents failure

Generated with [Claude Code](https://claude.ai/code)
via [Happy](https://happy.engineering)

Co-Authored-By: Claude <noreply@anthropic.com>
Co-Authored-By: Happy <yesreply@happy.engineering>
Signed-off-by: Tiger Kaovilai <tkaovila@redhat.com>

* Use bounded, object-storage-tuned backoff for backup-finalizer uploads

retry.DefaultBackoff is tuned for API server optimistic-concurrency
conflicts (4 steps, ~1.25s total) and gives up far too quickly for
object storage calls, which can see longer transient outages or
throttling (review feedback from blackpiglet). Replace it with a
dedicated, bounded backoff (1s base, 2x factor, 5 steps, ~31s total)
applied to both PutBackupMetadata and PutBackupContents.

Being bounded (rather than retrying forever) means a persistent
failure, e.g. an object-lock/immutability policy denying every write,
surfaces as an error within a bounded time instead of hanging the
reconcile indefinitely; controller-runtime requeues on error, so
retries continue across reconciles (review feedback from priyansh17).

Signed-off-by: Tiger Kaovilai <tkaovila@redhat.com>

* Fix PutBackupMetadata retry to re-read backupJSON each attempt

backupJSON is a bytes.Buffer, so passing it directly to
PutBackupMetadata drains it on the first read attempt. A retry after
a transient failure would then upload empty content instead of the
backup metadata. Wrap it in bytes.NewReader(backupJSON.Bytes()) inside
the retry closure so every attempt gets a fresh reader.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Signed-off-by: Tiger Kaovilai <tkaovila@redhat.com>

---------

Signed-off-by: Tiger Kaovilai <tkaovila@redhat.com>
Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Happy <yesreply@happy.engineering>
2026-09-22 20:06:46 -04:00
Xun Jiang/Bruce JiangandGitHub 2aea706117 Merge pull request #10441 from Ralthos/bsl-printcolumns
Run the E2E test on kind / setup-test-matrix (push) Failing after 5s
e2e-test-kind.yaml / extract (push) Failing after 7s
Run the E2E test on kind / get-go-version (push) Failing after 7s
Run the E2E test on kind / build (push) Skipped
Run the E2E test on kind / run-e2e-test (push) Skipped
push.yml / extract (push) Failing after 5s
Main CI / get-go-version (push) Failing after 6s
Main CI / Build (push) Skipped
Scorecard supply-chain security / Scorecard analysis (push) Skipped
Add printer columns for BackupStorageLocation provider and access mode
2026-09-22 17:23:07 +08:00
Adam ZhangandGitHub c3fe97745a Merge pull request #10549 from shoemoney/fix/schedule-create-drops-annotations
Fix schedule create dropping annotations
2026-09-22 16:40:28 +08:00
Adam Zhang 1ffa24c055 Fix SkippedPVTracker reference in backup tests
Update Request struct initialization in backup_test.go to use
SkippedVolumeTracker and NewSkipVolumeTracker following the rename
from SkippedPVTracker.

Signed-off-by: Adam Zhang <adam.zhang@broadcom.com>
2026-09-22 14:26:26 +08:00
lyndon-liandGitHub 0a2f5278b2 Move the progress messages to activities (#10552)
Run the E2E test on kind / setup-test-matrix (push) Failing after 3s
Scorecard supply-chain security / Scorecard analysis (push) Skipped
e2e-test-kind.yaml / extract (push) Failing after 8s
Run the E2E test on kind / get-go-version (push) Failing after 10s
Run the E2E test on kind / build (push) Skipped
Run the E2E test on kind / run-e2e-test (push) Skipped
push.yml / extract (push) Failing after 6s
Main CI / get-go-version (push) Failing after 7s
Main CI / Build (push) Skipped
* move the progress messages to activities

Signed-off-by: Lyndon-Li <lyonghui@vmware.com>

* update doc for activities in data mover CR

Signed-off-by: Lyndon-Li <lyonghui@vmware.com>

---------

Signed-off-by: Lyndon-Li <lyonghui@vmware.com>
2026-09-22 14:24:05 +08:00
Chlins ZhangandGitHub 3793d9ab4a Fail the in-place restore pre-flight check when the backed-up pod already exists on the file system restore path (#10550)
PodVolumeRestores are only created for pods that Velero creates, so when
the pod already exists in the cluster the PVC-not-in-use pre-flight check
never runs and the volume data restore is skipped silently, while the
existing pod keeps consuming the PVC. Report an explicit pre-flight error
for such pods, aligned with the PVC CSI RIA behavior.

Signed-off-by: chlins <chlins.zhang@gmail.com>
2026-09-22 11:53:35 +08:00
Adam ZhangandGitHub 36935902b9 Merge pull request #10536 from abhayrajjais01/fix/kube-node-context-propagation
fix(kube): propagate context to node client in GetNodeOS
2026-09-22 11:25:25 +08:00
lyndon-liandGitHub b66f12024c Merge pull request #10554 from pujitha24/auto/issue-10551
Propagate caller context in repository manager Forget/BatchForget
2026-09-22 11:25:05 +08:00
lyndon-liandGitHub 5f14d304c1 Merge pull request #10275 from kaovilai/namespace-selection-by-label
Implement namespace selection by label in resource policy
2026-09-22 09:22:38 +08:00
dependabot[bot]GitHubdependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
b81d820e6f Bump codecov/codecov-action in the github-actions group (#10548)
Run the E2E test on kind / setup-test-matrix (push) Failing after 3s
Scorecard supply-chain security / Scorecard analysis (push) Skipped
e2e-test-kind.yaml / extract (push) Failing after 10s
Run the E2E test on kind / get-go-version (push) Failing after 11s
Run the E2E test on kind / build (push) Skipped
Run the E2E test on kind / run-e2e-test (push) Skipped
push.yml / extract (push) Failing after 6s
Main CI / get-go-version (push) Failing after 9s
Main CI / Build (push) Skipped
Bumps the github-actions group with 1 update: [codecov/codecov-action](https://github.com/codecov/codecov-action).


Updates `codecov/codecov-action` from 7.0.0 to 7.1.1
- [Release notes](https://github.com/codecov/codecov-action/releases)
- [Commits](https://github.com/codecov/codecov-action/compare/v7...v7.1.1)

---
updated-dependencies:
- dependency-name: codecov/codecov-action
  dependency-version: 7.1.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-21 13:54:01 -04:00
Xun Jiang/Bruce JiangandGitHub 22a9d783cb Merge pull request #10538 from blackpiglet/jxun/10505_fix
e2e-test-kind.yaml / extract (push) Failing after 8s
Run the E2E test on kind / get-go-version (push) Failing after 9s
Run the E2E test on kind / build (push) Skipped
Run the E2E test on kind / setup-test-matrix (push) Failing after 2s
Run the E2E test on kind / run-e2e-test (push) Skipped
push.yml / extract (push) Failing after 6s
Scorecard supply-chain security / Scorecard analysis (push) Skipped
Main CI / get-go-version (push) Failing after 7s
Main CI / Build (push) Skipped
Reset the PVC bound PV when it references PVB
2026-09-21 23:11:27 +08:00
dependabot[bot]GitHubdependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
52d7b2eb4d Bump go.opentelemetry.io/otel/sdk from 1.44.0 to 1.45.0 (#10542)
Bumps [go.opentelemetry.io/otel/sdk](https://github.com/open-telemetry/opentelemetry-go) from 1.44.0 to 1.45.0.
- [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md)
- [Commits](https://github.com/open-telemetry/opentelemetry-go/compare/v1.44.0...v1.45.0)

---
updated-dependencies:
- dependency-name: go.opentelemetry.io/otel/sdk
  dependency-version: 1.45.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-21 10:55:11 -04:00
Pujitha Paladugu 8a2d9db687 Add changelog for PR 10554
CI's changelog check requires a changelogs/unreleased/<PR#>-<login>
file; this PR didn't have one since the PR number wasn't known until
after it was opened.

Signed-off-by: Pujitha Paladugu <10557236+pujitha24@users.noreply.github.com>
2026-09-21 07:37:08 -07:00
Pujitha Paladugu b9047d1e27 Propagate caller context in repository manager Forget/BatchForget
Motivation:
Forget and BatchForget in pkg/repository/manager/manager.go accept a
caller-provided context.Context but ignore it, hardcoding
context.Background() when calling into the repository provider. This
means cancellation and timeouts set by callers (e.g. the backup
deletion controller) are silently dropped during repository connection
and snapshot deletion. Additionally, BatchForget returned a wrapped nil
instead of the real connection error when prd.BoostRepoConnect failed,
because it referenced an unrelated, already-nil err variable instead of
connectErr.

Approach:
Pass the caller's ctx through to prd.BoostRepoConnect, prd.Forget, and
prd.BatchForget in both Forget and BatchForget, instead of substituting
context.Background(). Fix BatchForget's connection-failure branch to
wrap and return connectErr instead of the stale err. Other methods on
manager (InitRepo, ConnectToRepo, PrepareRepo, PruneRepo, UnlockRepo)
don't accept a ctx parameter at all, so they are unaffected and out of
scope for this change.

Validation:
- go build ./pkg/repository/... and go build ./... pass.
- go vet ./pkg/repository/... is clean.
- go test ./pkg/repository/... passes, including three new tests added
  to pkg/repository/manager/manager_test.go.
- golangci-lint run ./pkg/repository/... is clean.
- Confirmed the new tests reproduce both bugs: temporarily reverting
  only manager.go and re-running go test ./pkg/repository/manager/...
  made all three new tests fail (missing propagated context value and
  cancellation, and a nil error returned where the real connect error
  was expected); re-applying the fix makes them pass. This is a silent
  behavior bug (broken context propagation and a swallowed error), not
  a crash.

Report: https://github.com/velero-io/velero/issues/10551
Signed-off-by: Pujitha Paladugu <10557236+pujitha24@users.noreply.github.com>
Assisted-by: claude-sonnet-5 (via Claude Code)
2026-09-21 03:15:56 -07:00
Abhayraj Jaiswal b9a662d672 fix(kube): propagate context to node client in GetNodeOS
Signed-off-by: Abhayraj Jaiswal <abhayraj916146@gmail.com>
2026-09-21 05:29:26 +00:00
Xun Jiang a71bc4befc Reset the PVC binding information in pvc_action.go when it has referenced PVB.
Signed-off-by: Xun Jiang <xun.jiang@broadcom.com>
2026-09-21 10:54:59 +08:00
Xun Jiang/Bruce JiangandGitHub 54d5243923 Merge pull request #10525 from blackpiglet/jxun/9527_fix
e2e-test-kind.yaml / extract (push) Failing after 7s
Run the E2E test on kind / get-go-version (push) Failing after 10s
Run the E2E test on kind / build (push) Skipped
Run the E2E test on kind / setup-test-matrix (push) Failing after 2s
Run the E2E test on kind / run-e2e-test (push) Skipped
Scorecard supply-chain security / Scorecard analysis (push) Skipped
push.yml / extract (push) Failing after 6s
Main CI / get-go-version (push) Failing after 6s
Main CI / Build (push) Skipped
Support skipped PVC in VolumeInfos.
2026-09-20 10:12:20 +08:00
Jeremy Schoemaker e41ba0cafa Add changelog for schedule create annotations fix
Signed-off-by: Jeremy Schoemaker <jeremy@shoemoney.com>
2026-09-19 17:34:06 -05:00
Jeremy Schoemaker 8206b79673 Fix schedule create dropping annotations
velero schedule create registers --annotations through BackupOptions.BindFlags,
but the Schedule ObjectMeta it builds only sets Labels, so the flag was accepted
and silently discarded.

This matters beyond the Schedule object itself: BackupBuilder.FromSchedule
falls back to schedule.Annotations when the template carries none, so every
backup generated by the schedule lost the annotations too. velero schedule
describe already prints these fields and the Schedule CRD already carries them,
so the create path was the only gap.

Same shape as #10526, which fixed the backup type being dropped on the same
struct literal.

Signed-off-by: Jeremy Schoemaker <jeremy@shoemoney.com>
2026-09-19 17:32:48 -05:00
Tiger KaovilaiandClaude Sonnet 5 40af5efdd0 Implement namespace selection by label in resource policy
Add includedNamespacesByLabel, excludedNamespacesByLabel, and
labelSelectorLogic to IncludeExcludePolicy in the ResourcePolicy
ConfigMap (realizes design in velero-io/velero#9772), letting a backup
select or exclude namespaces by label instead of (or in addition to)
name/wildcard.

The backup controller resolves label selectors against the live
namespace list once per backup, merges the results into
spec.includedNamespaces/excludedNamespaces, then proceeds through the
existing name-based filtering unchanged. A defaulted "*" include list
is replaced by the resolved set; an explicitly-configured include list
(including an explicit "*") is unioned with it instead, and stays
canonical rather than widening. Namespaces matching an exclude
selector are always subtracted from the merged includes, regardless of
how the includes were populated.

Because Velero's namespace-includes/excludes model requires at least
one name (an empty list means "match everything"), a selector that
resolves to zero namespaces is represented with a sentinel glob
pattern ("[-]*") guaranteed to match no real namespace, rather than an
empty list that would silently fall back to including/excluding
everything.

labelSelectorLogic ("AND"/"OR", case-insensitive) controls whether
multiple included/excluded label selectors are combined by
intersection or union; it is validated up front, including inside
ResolveNamespacesByLabel itself, so an invalid value fails fast instead
of silently falling through to OR semantics.

Namespace-selection-by-label and resource-selection-by-label act as
independent axes and do not affect each other, matching the design
discussion in #9772.

Known limitations:
- Selectors are evaluated once per backup against the namespace list
  at that point in time; namespaces created or relabeled mid-backup
  are not picked up.
- Backup-only for now; restore-side namespace mapping is unaffected.

Testing:
- Unit coverage in internal/resourcepolicies for validation, selector
  resolution (including AND/OR logic, case-insensitivity, and
  malformed-selector/invalid-logic error paths), and the no-match
  sentinel.
- Unit coverage in pkg/controller for the merge logic between resolved
  label selections and explicit/defaulted includes and excludes.
- End-to-end coverage in pkg/backup exercising the full backup
  pipeline with label-selected namespaces, including the
  velero.io/exclude-from-backup hard-exclusion interaction and the
  zero-match/fully-excluded sentinel path.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Signed-off-by: Tiger Kaovilai <tkaovila@redhat.com>
2026-09-18 23:04:55 -04:00
Xun JiangandCursor f5982b4278 Add test case for skipped volume with empty PV name but with PVC info
Co-authored-by: Cursor <cursoragent@cursor.com>
Signed-off-by: Xun Jiang <xun.jiang@broadcom.com>
2026-09-18 17:10:07 +08:00