From ce2b2e4d93961ee261794fb59a554098e9561edb Mon Sep 17 00:00:00 2001 From: Durable Workflow Date: Tue, 6 Oct 2026 17:45:14 +0000 Subject: [PATCH 1/3] Add a bounded operator dashboard read endpoint --- app/Http/Controllers/Api/SystemController.php | 12 +++++++- docs/server-reference.md | 1 + routes/api.php | 1 + .../ControlPlaneVersionCoverageTest.php | 1 + tests/Feature/SystemOperatorMetricsTest.php | 29 +++++++++++++++++++ 5 files changed, 43 insertions(+), 1 deletion(-) diff --git a/app/Http/Controllers/Api/SystemController.php b/app/Http/Controllers/Api/SystemController.php index 1d5f53c9..1b208d5c 100644 --- a/app/Http/Controllers/Api/SystemController.php +++ b/app/Http/Controllers/Api/SystemController.php @@ -176,13 +176,23 @@ public function operatorMetrics(Request $request): JsonResponse } public function operatorDashboard(Request $request): JsonResponse + { + return $this->dashboardResponse($request, includeHistoryAudits: true); + } + + public function boundedOperatorDashboard(Request $request): JsonResponse + { + return $this->dashboardResponse($request, includeHistoryAudits: false); + } + + private function dashboardResponse(Request $request, bool $includeHistoryAudits): JsonResponse { if ($response = ControlPlaneProtocol::rejectUnsupported($request)) { return $response; } $namespace = (string) $request->attributes->get('namespace'); - $dashboard = OperatorDashboardSummary::snapshot(null, $namespace); + $dashboard = OperatorDashboardSummary::snapshot(null, $namespace, $includeHistoryAudits); $dashboard['operator_metrics']['worker_sessions'] = $this->workerSessions->metrics($namespace); $dashboard['operator_metrics']['runtime_external_payload_cleanup'] = RuntimeExternalPayloadCleanupMetrics::snapshot($namespace); diff --git a/docs/server-reference.md b/docs/server-reference.md index 704d1caf..3270d947 100644 --- a/docs/server-reference.md +++ b/docs/server-reference.md @@ -568,6 +568,7 @@ workflow-task command payload. - `GET /api/system/health` — Full rollout-safety health snapshot for the requested namespace, including check status, categories, routing-drain state, operator metrics, and structural limits - `GET /api/system/metrics` — Server metrics including bounded stuck workflow-task diagnostics - `GET /api/system/operator-metrics` — Full operator metrics snapshot (runs, tasks, backlog, repair, workers/fleet, backend, structural limits) for namespace-scoped rollout-safety coordination health +- `GET /api/system/operator-dashboard/bounded` returns dashboard aggregates without decoding fleet-wide histories. History-audit counts are `null` and `operator_metrics.history_audit_evaluation` is `not_requested`. Use `/api/system/operator-dashboard` or `/api/system/operator-metrics` when a full history audit is needed. Both dashboard routes require operator authentication, the control-plane version header and a namespace. - `GET /api/system/repair` — Task repair diagnostics - `POST /api/system/repair/pass` — Run task repair sweep - `GET /api/system/activity-timeouts` — Expired activity execution diagnostics diff --git a/routes/api.php b/routes/api.php index e8b87409..a9c08544 100644 --- a/routes/api.php +++ b/routes/api.php @@ -405,6 +405,7 @@ Route::get('/health', [SystemController::class, 'health']); Route::match(['get', 'post'], '/metrics', [SystemController::class, 'metrics']); Route::get('/operator-dashboard', [SystemController::class, 'operatorDashboard']); + Route::get('/operator-dashboard/bounded', [SystemController::class, 'boundedOperatorDashboard']); Route::get('/operator-metrics', [SystemController::class, 'operatorMetrics']); Route::get('/prometheus-metrics', [SystemController::class, 'prometheusMetrics']); Route::get('/repair', [SystemController::class, 'repairStatus']); diff --git a/tests/Feature/ControlPlaneVersionCoverageTest.php b/tests/Feature/ControlPlaneVersionCoverageTest.php index 47149553..2c4db9c3 100644 --- a/tests/Feature/ControlPlaneVersionCoverageTest.php +++ b/tests/Feature/ControlPlaneVersionCoverageTest.php @@ -150,6 +150,7 @@ public static function controlPlaneEndpointProvider(): array 'system.metrics' => ['method' => 'get', 'path' => '/api/system/metrics'], 'system.metrics_post' => ['method' => 'post', 'path' => '/api/system/metrics'], 'system.operator_dashboard' => ['method' => 'get', 'path' => '/api/system/operator-dashboard'], + 'system.bounded_operator_dashboard' => ['method' => 'get', 'path' => '/api/system/operator-dashboard/bounded'], 'system.operator_metrics' => ['method' => 'get', 'path' => '/api/system/operator-metrics'], 'system.repair_status' => ['method' => 'get', 'path' => '/api/system/repair'], 'system.repair_pass' => ['method' => 'post', 'path' => '/api/system/repair/pass'], diff --git a/tests/Feature/SystemOperatorMetricsTest.php b/tests/Feature/SystemOperatorMetricsTest.php index 242cd1e4..e267ee43 100644 --- a/tests/Feature/SystemOperatorMetricsTest.php +++ b/tests/Feature/SystemOperatorMetricsTest.php @@ -381,6 +381,35 @@ public function test_operator_metrics_requires_control_plane_version_header(): v ->assertJsonPath('reason', 'missing_control_plane_version'); } + public function test_bounded_dashboard_defers_history_audits_without_claiming_zero_drift(): void + { + $this->getJson('/api/system/operator-dashboard/bounded', $this->controlPlaneHeadersWithWorkerProtocol()) + ->assertOk() + ->assertHeader(ControlPlaneProtocol::HEADER, ControlPlaneProtocol::VERSION) + ->assertJsonPath('namespace', 'default') + ->assertJsonPath('dashboard.flows', 0) + ->assertJsonPath('dashboard.operator_metrics.history_audit_evaluation', 'not_requested') + ->assertJsonPath('dashboard.operator_metrics.command_contracts.backfill_needed_runs', null) + ->assertJsonPath('dashboard.operator_metrics.projections.run_waits.needs_rebuild', null) + ->assertJsonPath('dashboard.operator_metrics.projections.run_timeline_entries.needs_rebuild', null) + ->assertJsonPath('dashboard.operator_metrics.projections.run_timer_entries.needs_rebuild', null) + ->assertJsonPath('dashboard.operator_metrics.projections.run_lineage_entries.needs_rebuild', null); + + $this->getJson('/api/system/operator-dashboard', $this->controlPlaneHeadersWithWorkerProtocol()) + ->assertOk() + ->assertJsonMissingPath('dashboard.operator_metrics.history_audit_evaluation') + ->assertJsonPath('dashboard.operator_metrics.projections.run_waits.needs_rebuild', 0); + } + + public function test_bounded_dashboard_requires_control_plane_version_header(): void + { + $this->getJson('/api/system/operator-dashboard/bounded', [ + 'X-Namespace' => 'default', + ]) + ->assertStatus(400) + ->assertJsonPath('reason', 'missing_control_plane_version'); + } + public function test_operator_dashboard_requires_control_plane_version_header(): void { $this->getJson('/api/system/operator-dashboard', [ From ed22d3e7935bf8964b35ac4fe310bcc0b5357fbe Mon Sep 17 00:00:00 2001 From: Durable Workflow Date: Tue, 6 Oct 2026 17:51:00 +0000 Subject: [PATCH 2/3] Include bounded capacity evidence for observer capability reads --- app/Http/Controllers/Api/SystemController.php | 3 +++ tests/Feature/SystemOperatorMetricsTest.php | 2 ++ 2 files changed, 5 insertions(+) diff --git a/app/Http/Controllers/Api/SystemController.php b/app/Http/Controllers/Api/SystemController.php index 1b208d5c..08a06c99 100644 --- a/app/Http/Controllers/Api/SystemController.php +++ b/app/Http/Controllers/Api/SystemController.php @@ -193,6 +193,9 @@ private function dashboardResponse(Request $request, bool $includeHistoryAudits) $namespace = (string) $request->attributes->get('namespace'); $dashboard = OperatorDashboardSummary::snapshot(null, $namespace, $includeHistoryAudits); + if (! $includeHistoryAudits) { + $dashboard['operator_metrics']['capacity_evidence'] = $this->capacityEvidence->snapshot($namespace); + } $dashboard['operator_metrics']['worker_sessions'] = $this->workerSessions->metrics($namespace); $dashboard['operator_metrics']['runtime_external_payload_cleanup'] = RuntimeExternalPayloadCleanupMetrics::snapshot($namespace); diff --git a/tests/Feature/SystemOperatorMetricsTest.php b/tests/Feature/SystemOperatorMetricsTest.php index e267ee43..39b21db9 100644 --- a/tests/Feature/SystemOperatorMetricsTest.php +++ b/tests/Feature/SystemOperatorMetricsTest.php @@ -389,6 +389,8 @@ public function test_bounded_dashboard_defers_history_audits_without_claiming_ze ->assertJsonPath('namespace', 'default') ->assertJsonPath('dashboard.flows', 0) ->assertJsonPath('dashboard.operator_metrics.history_audit_evaluation', 'not_requested') + ->assertJsonPath('dashboard.operator_metrics.capacity_evidence.namespace', 'default') + ->assertJsonPath('dashboard.operator_metrics.capacity_evidence.cardinality.bounded', true) ->assertJsonPath('dashboard.operator_metrics.command_contracts.backfill_needed_runs', null) ->assertJsonPath('dashboard.operator_metrics.projections.run_waits.needs_rebuild', null) ->assertJsonPath('dashboard.operator_metrics.projections.run_timeline_entries.needs_rebuild', null) From c4b5bbe4e0f16ceb6f3253aedadecb5812bb55d3 Mon Sep 17 00:00:00 2001 From: Durable Workflow Date: Tue, 6 Oct 2026 18:14:07 +0000 Subject: [PATCH 3/3] Pin published Native 2.4.3 and prepare Server 2.5.3 --- composer.json | 4 ++-- composer.lock | 16 ++++++++-------- docker-compose.dedicated-matching.yml | 4 ++-- docker-compose.memo-rolling.yml | 4 ++-- docker-compose.published.yml | 4 ++-- docker-compose.small-cluster.yml | 2 +- docker-compose.yml | 8 ++++---- k8s/README.md | 10 +++++----- k8s/helm/durable-workflow/Chart.yaml | 6 +++--- k8s/helm/durable-workflow/README.md | 2 +- .../ci/existing-secrets-values.yaml | 2 +- .../ci/ingress-and-hpa-values.yaml | 2 +- .../ci/inline-secrets-values.yaml | 2 +- k8s/helm/durable-workflow/templates/_helpers.tpl | 2 +- k8s/helm/durable-workflow/values.yaml | 2 +- k8s/helm/examples/values-dev.yaml | 2 +- .../values-external-secrets-operator.yaml | 2 +- .../values-production-existing-secrets.yaml | 2 +- k8s/migration-job.yaml | 2 +- k8s/scheduler-cronjob.yaml | 2 +- k8s/secret.yaml | 2 +- k8s/server-deployment.yaml | 2 +- k8s/worker-deployment.yaml | 2 +- resources/release/source-release.json | 4 ++-- scripts/k8s-kind-smoke.sh | 2 +- 25 files changed, 46 insertions(+), 46 deletions(-) diff --git a/composer.json b/composer.json index 31dde257..3ee91354 100644 --- a/composer.json +++ b/composer.json @@ -6,7 +6,7 @@ "require": { "php": "^8.2", "apache/avro": "^1.12", - "durable-workflow/workflow": "2.4.2", + "durable-workflow/workflow": "2.4.3", "laravel/framework": "^13.30", "laravel/tinker": "^3.0", "league/flysystem-aws-s3-v3": "^3.35.3" @@ -48,7 +48,7 @@ }, "extra": { "durable-workflow": { - "product-train": "2.5.2" + "product-train": "2.5.3" }, "laravel": { "dont-discover": [] diff --git a/composer.lock b/composer.lock index ff082995..171b9797 100644 --- a/composer.lock +++ b/composer.lock @@ -4,7 +4,7 @@ "Read more about it at https://getcomposer.org/doc/01-basic-usage.md#installing-dependencies", "This file is @generated automatically" ], - "content-hash": "cc7ae73233d712aa7dc1aef66c1989d7", + "content-hash": "0528380eb427ffc6cf5874e5b689e7b0", "packages": [ { "name": "apache/avro", @@ -655,16 +655,16 @@ }, { "name": "durable-workflow/workflow", - "version": "2.4.2", + "version": "2.4.3", "source": { "type": "git", "url": "https://github.com/durable-workflow/workflow.git", - "reference": "4fcb23622147dd2c1f92e461e927577092120bb8" + "reference": "8fcfb002de337e341ef19e601d73e9e1424e09ec" }, "dist": { "type": "zip", - "url": "https://api.github.com/repos/durable-workflow/workflow/zipball/4fcb23622147dd2c1f92e461e927577092120bb8", - "reference": "4fcb23622147dd2c1f92e461e927577092120bb8", + "url": "https://api.github.com/repos/durable-workflow/workflow/zipball/8fcfb002de337e341ef19e601d73e9e1424e09ec", + "reference": "8fcfb002de337e341ef19e601d73e9e1424e09ec", "shasum": "" }, "require": { @@ -697,7 +697,7 @@ "dev-main": "2.0.x-dev" }, "durable-workflow": { - "product-train": "2.4.2", + "product-train": "2.4.3", "laravel-embedded-upgrade-contract": "resources/laravel-embedded-upgrade-contract.json", "laravel-dependency-security-policy": "resources/laravel-dependency-security-policy.json" } @@ -724,9 +724,9 @@ "description": "Embedded durable workflow runtime and orchestration engine for Laravel applications.", "support": { "issues": "https://github.com/durable-workflow/workflow/issues", - "source": "https://github.com/durable-workflow/workflow/tree/2.4.2" + "source": "https://github.com/durable-workflow/workflow/tree/2.4.3" }, - "time": "2026-10-06T14:26:58+00:00" + "time": "2026-10-06T17:56:06+00:00" }, { "name": "egulias/email-validator", diff --git a/docker-compose.dedicated-matching.yml b/docker-compose.dedicated-matching.yml index d43f54f6..216a7e2d 100644 --- a/docker-compose.dedicated-matching.yml +++ b/docker-compose.dedicated-matching.yml @@ -32,13 +32,13 @@ name: durable-workflow-server # daemon reports `shape: dedicated`. # Generated by scripts/ci/sync-source-release.mjs. Do not edit the fallback. -x-server-image: &server-image ${DW_SERVER_IMAGE:-durableworkflow/server:${DW_SERVER_TAG:-2.5.2}} +x-server-image: &server-image ${DW_SERVER_IMAGE:-durableworkflow/server:${DW_SERVER_TAG:-2.5.3}} x-server-environment: &server-environment APP_NAME: "Durable Workflow Server" APP_ENV: ${APP_ENV:-local} DW_SERVER_KEY: ${DW_SERVER_KEY:-} - APP_VERSION: ${APP_VERSION:-${DW_SERVER_TAG:-2.5.2}} + APP_VERSION: ${APP_VERSION:-${DW_SERVER_TAG:-2.5.3}} APP_DEBUG: ${APP_DEBUG:-false} DB_CONNECTION: mysql DB_HOST: mysql diff --git a/docker-compose.memo-rolling.yml b/docker-compose.memo-rolling.yml index 3d226bb4..1ada3692 100644 --- a/docker-compose.memo-rolling.yml +++ b/docker-compose.memo-rolling.yml @@ -49,14 +49,14 @@ services: command: ["server-bootstrap"] environment: <<: *runtime-environment - APP_VERSION: ${APP_VERSION:-2.5.2} + APP_VERSION: ${APP_VERSION:-2.5.3} successor: image: ${DW_MEMO_SUCCESSOR_IMAGE:-durable-workflow/server-memo-rolling:local} ports: !override [] environment: <<: *runtime-environment - APP_VERSION: ${APP_VERSION:-2.5.2} + APP_VERSION: ${APP_VERSION:-2.5.3} DW_SERVER_ID: memo-successor DW_SERVER_TOPOLOGY_SHAPE: standalone_server DW_SERVER_PROCESS_CLASS: server_http_node diff --git a/docker-compose.published.yml b/docker-compose.published.yml index 2e1eb8b6..3c10d7d7 100644 --- a/docker-compose.published.yml +++ b/docker-compose.published.yml @@ -1,13 +1,13 @@ name: durable-workflow-server # Generated by scripts/ci/sync-source-release.mjs. Do not edit the fallback. -x-server-image: &server-image ${DW_SERVER_IMAGE:-durableworkflow/server:${DW_SERVER_TAG:-2.5.2}} +x-server-image: &server-image ${DW_SERVER_IMAGE:-durableworkflow/server:${DW_SERVER_TAG:-2.5.3}} x-server-environment: &server-environment APP_NAME: "Durable Workflow Server" APP_ENV: ${APP_ENV:-local} DW_SERVER_KEY: ${DW_SERVER_KEY:-} - APP_VERSION: ${APP_VERSION:-${DW_SERVER_TAG:-2.5.2}} + APP_VERSION: ${APP_VERSION:-${DW_SERVER_TAG:-2.5.3}} APP_DEBUG: ${APP_DEBUG:-false} LOG_CHANNEL: ${LOG_CHANNEL:-stderr} LOG_LEVEL: ${LOG_LEVEL:-info} diff --git a/docker-compose.small-cluster.yml b/docker-compose.small-cluster.yml index 3aaf91b5..805e0436 100644 --- a/docker-compose.small-cluster.yml +++ b/docker-compose.small-cluster.yml @@ -12,7 +12,7 @@ x-server-build: &server-build x-server-environment: &server-environment APP_NAME: "Durable Workflow Server" APP_ENV: testing - APP_VERSION: ${APP_VERSION:-2.5.2} + APP_VERSION: ${APP_VERSION:-2.5.3} APP_DEBUG: "false" DW_SERVER_KEY: ${DW_SERVER_KEY:-base64:5Zt4nUhlCm3DD0nLXZJQdHiwPfb56yGo9gNV/g3jYbY=} DB_CONNECTION: ${DW_SMALL_CLUSTER_DB:-mysql} diff --git a/docker-compose.yml b/docker-compose.yml index 31485b60..080a50ab 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -15,7 +15,7 @@ services: DW_SERVER_KEY: "${DW_SERVER_KEY:-}" DW_SERVER_TOPOLOGY_SHAPE: standalone_server DW_SERVER_PROCESS_CLASS: server_http_node - APP_VERSION: "${APP_VERSION:-2.5.2}" + APP_VERSION: "${APP_VERSION:-2.5.3}" APP_DEBUG: "false" DB_CONNECTION: mysql DB_HOST: mysql @@ -62,7 +62,7 @@ services: APP_NAME: "Durable Workflow Server" APP_ENV: local DW_SERVER_KEY: "${DW_SERVER_KEY:-}" - APP_VERSION: "${APP_VERSION:-2.5.2}" + APP_VERSION: "${APP_VERSION:-2.5.3}" APP_DEBUG: "false" DB_CONNECTION: mysql DB_HOST: mysql @@ -124,7 +124,7 @@ services: DW_SERVER_KEY: "${DW_SERVER_KEY:-}" DW_SERVER_TOPOLOGY_SHAPE: standalone_server DW_SERVER_PROCESS_CLASS: worker_node - APP_VERSION: "${APP_VERSION:-2.5.2}" + APP_VERSION: "${APP_VERSION:-2.5.3}" DB_CONNECTION: mysql DB_HOST: mysql DB_PORT: 3306 @@ -178,7 +178,7 @@ services: DW_SERVER_KEY: "${DW_SERVER_KEY:-}" DW_SERVER_TOPOLOGY_SHAPE: standalone_server DW_SERVER_PROCESS_CLASS: scheduler_node - APP_VERSION: "${APP_VERSION:-2.5.2}" + APP_VERSION: "${APP_VERSION:-2.5.3}" DB_CONNECTION: mysql DB_HOST: mysql DB_PORT: 3306 diff --git a/k8s/README.md b/k8s/README.md index cd3bae73..17484aac 100644 --- a/k8s/README.md +++ b/k8s/README.md @@ -13,7 +13,7 @@ The checked-in manifests are synchronized with the repository's stable source release and pin its Docker Hub tag: ```text -durableworkflow/server:2.5.2 +durableworkflow/server:2.5.3 ``` Before production use, patch every workload image to the exact published tag or @@ -21,15 +21,15 @@ digest you intend to run: ```bash kubectl set image -n durable-workflow deploy/durable-workflow-server \ - server=durableworkflow/server:2.5.2 + server=durableworkflow/server:2.5.3 kubectl set image -n durable-workflow deploy/durable-workflow-worker \ - worker=durableworkflow/server:2.5.2 + worker=durableworkflow/server:2.5.3 kubectl set image -n durable-workflow cronjob/durable-workflow-scheduler \ - scheduler=durableworkflow/server:2.5.2 + scheduler=durableworkflow/server:2.5.3 ``` GitHub Container Registry publishes the same release line at -`ghcr.io/durable-workflow/server:2.5.2`. Digest pinning is preferred for strict +`ghcr.io/durable-workflow/server:2.5.3`. Digest pinning is preferred for strict change control. The manifests expect you to provide: diff --git a/k8s/helm/durable-workflow/Chart.yaml b/k8s/helm/durable-workflow/Chart.yaml index 9985301d..10e1941d 100644 --- a/k8s/helm/durable-workflow/Chart.yaml +++ b/k8s/helm/durable-workflow/Chart.yaml @@ -5,11 +5,11 @@ type: application # The chart's own semver version. Bumped on every chart release; treated as # independent of the server image version (appVersion). Breaking-change rules # for this version live in docs/helm-upgrading.md alongside the chart. -version: 0.1.139 +version: 0.1.140 # The immutable Durable Workflow Server identity this chart release packages. # The onboarding default in values.yaml and appVersion are generated from the # checked-in source release record. -appVersion: "2.5.2" +appVersion: "2.5.3" kubeVersion: ">=1.27.0-0" home: https://durable-workflow.github.io/docs/2.0/deployment sources: @@ -30,7 +30,7 @@ annotations: # exact commit that most recently changed the packaged chart. org.opencontainers.image.source: https://github.com/durable-workflow/server dev.durable-workflow.source-revision: "unreleased" - dev.durable-workflow.image-reference: "docker.io/durableworkflow/server:2.5.2" + dev.durable-workflow.image-reference: "docker.io/durableworkflow/server:2.5.3" artifacthub.io/license: MIT artifacthub.io/category: integration-delivery # Free-form changelog for the current chart release shown by Artifact Hub. diff --git a/k8s/helm/durable-workflow/README.md b/k8s/helm/durable-workflow/README.md index 448b9837..a02886b4 100644 --- a/k8s/helm/durable-workflow/README.md +++ b/k8s/helm/durable-workflow/README.md @@ -63,7 +63,7 @@ helm install durable-workflow ./k8s/helm/durable-workflow \ ```yaml image: - tag: "2.5.2" + tag: "2.5.3" # Pin a digest in production: # digest: "sha256:abc123..." # memoPayloadStorage: "raw-json-v1" # Required for a digest or custom image. diff --git a/k8s/helm/durable-workflow/ci/existing-secrets-values.yaml b/k8s/helm/durable-workflow/ci/existing-secrets-values.yaml index 6df8a8b2..72711e85 100644 --- a/k8s/helm/durable-workflow/ci/existing-secrets-values.yaml +++ b/k8s/helm/durable-workflow/ci/existing-secrets-values.yaml @@ -1,7 +1,7 @@ # CI fixture: GitOps / externally-managed-secret path. The chart consumes # existing Secrets and renders no Secret resources of its own. image: - tag: "2.5.2" + tag: "2.5.3" externalDatabase: connection: pgsql diff --git a/k8s/helm/durable-workflow/ci/ingress-and-hpa-values.yaml b/k8s/helm/durable-workflow/ci/ingress-and-hpa-values.yaml index a628239e..b9142739 100644 --- a/k8s/helm/durable-workflow/ci/ingress-and-hpa-values.yaml +++ b/k8s/helm/durable-workflow/ci/ingress-and-hpa-values.yaml @@ -1,6 +1,6 @@ # CI fixture: ingress + autoscaling enabled. Exercises optional templates. image: - tag: "2.5.2" + tag: "2.5.3" externalDatabase: connection: mysql diff --git a/k8s/helm/durable-workflow/ci/inline-secrets-values.yaml b/k8s/helm/durable-workflow/ci/inline-secrets-values.yaml index 95dd0f7c..201a50e3 100644 --- a/k8s/helm/durable-workflow/ci/inline-secrets-values.yaml +++ b/k8s/helm/durable-workflow/ci/inline-secrets-values.yaml @@ -2,7 +2,7 @@ # chart's render path is exercised end-to-end. Real deployments should use # existingSecret instead. image: - tag: "2.5.2" + tag: "2.5.3" externalDatabase: connection: mysql diff --git a/k8s/helm/durable-workflow/templates/_helpers.tpl b/k8s/helm/durable-workflow/templates/_helpers.tpl index 736a0995..d58eb020 100644 --- a/k8s/helm/durable-workflow/templates/_helpers.tpl +++ b/k8s/helm/durable-workflow/templates/_helpers.tpl @@ -88,7 +88,7 @@ resolved by an explicit capability declaration or an existing workload marker. {{- define "durable-workflow.memoPayloadStorageForImage" -}} {{- $image := toString . -}} {{- $normalized := regexReplaceAll "^index\\.docker\\.io/" $image "docker.io/" -}} -{{- if eq $normalized "docker.io/durableworkflow/server:2.5.2" -}} +{{- if eq $normalized "docker.io/durableworkflow/server:2.5.3" -}} dual-v1 {{- else if regexMatch "^docker\\.io/durableworkflow/server:2\\.0\\.0-rc\\.[0-9]+$" $normalized -}} {{- $releaseCandidate := atoi (regexFind "[0-9]+$" $normalized) -}} diff --git a/k8s/helm/durable-workflow/values.yaml b/k8s/helm/durable-workflow/values.yaml index 5e2349f3..9a5c3876 100644 --- a/k8s/helm/durable-workflow/values.yaml +++ b/k8s/helm/durable-workflow/values.yaml @@ -21,7 +21,7 @@ image: registry: docker.io repository: durableworkflow/server # Generated by scripts/ci/sync-source-release.mjs. Do not edit this default. - tag: "2.5.2" + tag: "2.5.3" # Optional digest pin. When set, takes precedence over tag for change control. # Example: "sha256:abc123..." digest: "" diff --git a/k8s/helm/examples/values-dev.yaml b/k8s/helm/examples/values-dev.yaml index e5881ff6..8eed021c 100644 --- a/k8s/helm/examples/values-dev.yaml +++ b/k8s/helm/examples/values-dev.yaml @@ -3,7 +3,7 @@ # shape in production. image: - tag: "2.5.2" + tag: "2.5.3" externalDatabase: connection: mysql diff --git a/k8s/helm/examples/values-external-secrets-operator.yaml b/k8s/helm/examples/values-external-secrets-operator.yaml index 1d76a264..98e926d0 100644 --- a/k8s/helm/examples/values-external-secrets-operator.yaml +++ b/k8s/helm/examples/values-external-secrets-operator.yaml @@ -5,7 +5,7 @@ # concern. image: - tag: "2.5.2" + tag: "2.5.3" externalDatabase: connection: pgsql diff --git a/k8s/helm/examples/values-production-existing-secrets.yaml b/k8s/helm/examples/values-production-existing-secrets.yaml index 92fed9c9..8b40fff8 100644 --- a/k8s/helm/examples/values-production-existing-secrets.yaml +++ b/k8s/helm/examples/values-production-existing-secrets.yaml @@ -10,7 +10,7 @@ image: repository: durable-workflow/server # Pin a digest in production for change-control auditability. digest: "" # e.g. "sha256:abc123..." - tag: "2.5.2" + tag: "2.5.3" externalDatabase: connection: pgsql diff --git a/k8s/migration-job.yaml b/k8s/migration-job.yaml index 62fdabe3..6beab458 100644 --- a/k8s/migration-job.yaml +++ b/k8s/migration-job.yaml @@ -13,7 +13,7 @@ spec: restartPolicy: OnFailure containers: - name: migrate - image: durableworkflow/server:2.5.2 + image: durableworkflow/server:2.5.3 command: ["server-entrypoint"] args: ["server-bootstrap"] envFrom: diff --git a/k8s/scheduler-cronjob.yaml b/k8s/scheduler-cronjob.yaml index 484c5b30..0c00949a 100644 --- a/k8s/scheduler-cronjob.yaml +++ b/k8s/scheduler-cronjob.yaml @@ -24,7 +24,7 @@ spec: restartPolicy: Never containers: - name: scheduler - image: durableworkflow/server:2.5.2 + image: durableworkflow/server:2.5.3 command: ["server-entrypoint"] args: - sh diff --git a/k8s/secret.yaml b/k8s/secret.yaml index a2e154f3..cbecb0f9 100644 --- a/k8s/secret.yaml +++ b/k8s/secret.yaml @@ -12,7 +12,7 @@ metadata: app.kubernetes.io/name: durable-workflow data: APP_NAME: "Durable Workflow Server" - APP_VERSION: "2.5.2" + APP_VERSION: "2.5.3" APP_ENV: production APP_DEBUG: "false" DB_CONNECTION: mysql diff --git a/k8s/server-deployment.yaml b/k8s/server-deployment.yaml index bf521160..5bb827bf 100644 --- a/k8s/server-deployment.yaml +++ b/k8s/server-deployment.yaml @@ -23,7 +23,7 @@ spec: spec: containers: - name: server - image: durableworkflow/server:2.5.2 + image: durableworkflow/server:2.5.3 ports: - containerPort: 8080 name: http diff --git a/k8s/worker-deployment.yaml b/k8s/worker-deployment.yaml index 1b39fd1f..eb278bfd 100644 --- a/k8s/worker-deployment.yaml +++ b/k8s/worker-deployment.yaml @@ -19,7 +19,7 @@ spec: spec: containers: - name: worker - image: durableworkflow/server:2.5.2 + image: durableworkflow/server:2.5.3 command: ["server-entrypoint"] args: ["php", "artisan", "queue:work", "--sleep=1", "--tries=3", "--max-time=3600"] envFrom: diff --git a/resources/release/source-release.json b/resources/release/source-release.json index d85033e3..de4d62ba 100644 --- a/resources/release/source-release.json +++ b/resources/release/source-release.json @@ -1,9 +1,9 @@ { "schema": "durable-workflow.server.source-release/v1", "server": { - "version": "2.5.2" + "version": "2.5.3" }, "helm_chart": { - "version": "0.1.139" + "version": "0.1.140" } } diff --git a/scripts/k8s-kind-smoke.sh b/scripts/k8s-kind-smoke.sh index 89f42da8..dd104b26 100755 --- a/scripts/k8s-kind-smoke.sh +++ b/scripts/k8s-kind-smoke.sh @@ -7,7 +7,7 @@ cluster="${K8S_SMOKE_CLUSTER:-durable-workflow-server-smoke}" image="${K8S_SMOKE_IMAGE:-durableworkflow/server:k8s-smoke}" # Generated by scripts/ci/sync-source-release.mjs so the smoke replaces the # same default shipped by the public manifests. -manifest_image="durableworkflow/server:2.5.2" +manifest_image="durableworkflow/server:2.5.3" kind_node_image="${K8S_SMOKE_KIND_NODE_IMAGE:-kindest/node:v1.29.4}" artifact_dir="${K8S_SMOKE_ARTIFACT_DIR:-/tmp/durable-workflow-k8s-kind-smoke-artifacts}" rendered_dir="${artifact_dir}/rendered-manifests"