Skip to content

Rebase to v1.14.7 for OCP DNS/Ingress - #201

Draft
bentito wants to merge 663 commits into
openshift:mainfrom
bentito:rebase-v1.14.7
Draft

Rebase to v1.14.7 for OCP DNS/Ingress#201
bentito wants to merge 663 commits into
openshift:mainfrom
bentito:rebase-v1.14.7

Conversation

@bentito

@bentito bentito commented Aug 20, 2026

Copy link
Copy Markdown

⚠️ WARNING: Local verification builds/tests failed on initial rebase. Please inspect CI.

Upstream Rebase Report: v1.13.1 to v1.14.7

This report was automatically generated by the NI&D Rebase Manager. It details the release delta, domain-grouped carry commits, and designated follow-up actions. This document serves as the official agenda for the Rebase Approval meeting and will populate the Draft PR description.

Upstream Changelog

  • Release Tag: v1.14.7
  • Changelog Comparison: v1.13.1 ... v1.14.7

Key Upstream Changes

The team should summarize major upstream features, API deprecations, and breaking changes here before finalizing.


Domain-Grouped Carry Commit Agenda

Below is the structured analysis of the 50 downstream carry commits currently maintained on main. High-level configuration sections have been condensed, while critical code changes remain expanded for developer review.

1. Toolchain & Dependencies (go.mod, vendor tree, Go version)

Review Focus: Build & Dependency alignment owners to ensure offline builds and toolchains remain viable.

  • Summary: We are carrying 3 dependency and toolchain alignment commits. These are highly repetitive configuration changes (such as pinning Go versions, tracking vendor/ tree ignores, and pulling in CVE security updates).
  • Action Required: Redo go mod vendor post-rebase and ensure GOTOOLCHAIN=local is set to compile with the downstream environment.
🔍 Click to expand itemized commits audit table (Toolchain & Dependencies)
Carry SHA Commit Message Default Action Reason
583929976 UPSTREAM: : Address CVE-2023-49295 and CVE-2024-22189 squash Configuration carry candidate for squashing into core files carry
f26970141 UPSTREAM: 6836: Bump .go-version squash Configuration carry candidate for squashing into core files carry
b06f0e0cb UPSTREAM: : openshift: add ocp_dnsnameresolver plugin squash Configuration carry candidate for squashing into core files carry

2. Build, CI, and Packaging (Dockerfiles, Prow config, Make targets)

Review Focus: Release, ART, & CI/operator owners to sign off on packaging and automation toggles.

  • Summary: We are carrying 36 packaging, Dockerfile, and Prow configuration commits. These represent standard OpenShift releases metadata, make target shims, and base-image overrides (e.g. updating base images to match ocp-build-data config).
  • Action Required: Reconcile downstream Dockerfiles with any upstream base-image changes, and verify make test targets align with CI rehearsals.
🔍 Click to expand itemized commits audit table (Build, CI, and Packaging)
Carry SHA Commit Message Default Action Reason
6961254ef UPSTREAM: : openshift: Changed the OWNERS to OpenShift ones squash Configuration carry candidate for squashing into core files carry
6ab418926 UPSTREAM: : openshift: Add a product build pipeline Dockerfile squash Configuration carry candidate for squashing into core files carry
225d3a35d UPSTREAM: : openshift: Update metadata squash Configuration carry candidate for squashing into core files carry
2c53ec989 UPSTREAM: : openshift: Use multistage builds squash Configuration carry candidate for squashing into core files carry
a8cac43c4 UPSTREAM: : openshift: Add a RHEL7 Dockerfile and standardize format squash Configuration carry candidate for squashing into core files carry
78dc38111 UPSTREAM: : openshift: Optimize COPY directive squash Configuration carry candidate for squashing into core files carry
acf1e3312 UPSTREAM: : openshift: Add a make test target squash Configuration carry candidate for squashing into core files carry
8ef04d79a UPSTREAM: : openshift: Set Dockerfiles to use vendor squash Configuration carry candidate for squashing into core files carry
cae06b4bc UPSTREAM: : openshift: Make coredns exclusion more specific squash Configuration carry candidate for squashing into core files carry
7d3b0d2fe UPSTREAM: : openshift: Vendor required modules squash Configuration carry candidate for squashing into core files carry
532d55088 UPSTREAM: : openshift: OWNERS: Add component squash Configuration carry candidate for squashing into core files carry
48fadedfa UPSTREAM: : openshift: Updating Dockerfile.openshift.rhel7 baseimages to mach ocp-build-data config squash Configuration carry candidate for squashing into core files carry
c017c6ef7 UPSTREAM: : openshift: Update owners squash Configuration carry candidate for squashing into core files carry
a4a0530cd UPSTREAM: : openshift: Updating coredns builder & base images to be consistent with ART Reconciling with https://github.com/openshift/ocp-build-data/tree/ac81dd4ff0bd57c4e75058d25b40615b92948259/images/coredns.yml squash Configuration carry candidate for squashing into core files carry
0df6a4cb8 UPSTREAM: : openshift: .gitignore: Properly ignore coredns binary squash Configuration carry candidate for squashing into core files carry
3f329badb UPSTREAM: : openshift: addowner-candita squash Configuration carry candidate for squashing into core files carry
960001974 UPSTREAM: : openshift: Add rfredette to OWNERS squash Configuration carry candidate for squashing into core files carry
e27b1500e UPSTREAM: : openshift: Updating coredns builder & base images to be consistent with ART Reconciling with https://github.com/openshift/ocp-build-data/tree/b0ab44b419faae6b18e639e780a1fa50a1df8521/images/coredns.yml squash Configuration carry candidate for squashing into core files carry
e7d8e58f8 UPSTREAM: : openshift: Updating coredns builder & base images to be consistent with ART Reconciling with https://github.com/openshift/ocp-build-data/tree/5a1293dd0f380abf50c12d65c36655486d7745d0/images/coredns.yml squash Configuration carry candidate for squashing into core files carry
02ea47f29 UPSTREAM: : openshift: Updating coredns images to be consistent with ART Reconciling with https://github.com/openshift/ocp-build-data/tree/0c10ae924af72f1c759cf8b24b50de94c02e6268/images/coredns.yml squash Configuration carry candidate for squashing into core files carry
a80f04ac9 UPSTREAM: : openshift: Updating .ci-operator.yaml build_root_image from openshift/release squash Configuration carry candidate for squashing into core files carry
1bce8b227 UPSTREAM: : openshift: Updating coredns images to be consistent with ART Reconciling with https://github.com/openshift/ocp-build-data/tree/691e628254f318ce56efda5edc7448ec743c37b8/images/coredns.yml squash Configuration carry candidate for squashing into core files carry
213249c83 UPSTREAM: : openshift: Disable dependabot squash Configuration carry candidate for squashing into core files carry
a82419240 UPSTREAM: : openshift: Add OWNERS squash Configuration carry candidate for squashing into core files carry
b1601880b UPSTREAM: : openshift: Update builder images squash Configuration carry candidate for squashing into core files carry
90d7eed7b UPSTREAM: : openshift: Add product build config squash Configuration carry candidate for squashing into core files carry
c0451cddd UPSTREAM: : openshift: Address CVE-2023-39325 squash Configuration carry candidate for squashing into core files carry
7a4db4ba4 UPSTREAM: : openshift: Add ocp_dnsnameresolver external plugin squash Configuration carry candidate for squashing into core files carry
8eab9cb1d UPSTREAM: : openshift: Bump the version of ocp_dnsnameresolver external plugin squash Configuration carry candidate for squashing into core files carry
b4f5b8edc UPSTREAM: : openshift: restore automation metadata squash Configuration carry candidate for squashing into core files carry
9908fdc83 UPSTREAM: : openshift: document downstream OWNERS metadata squash Configuration carry candidate for squashing into core files carry
551de3c44 UPSTREAM: : openshift: disable dependabot squash Configuration carry candidate for squashing into core files carry
1457b2e54 UPSTREAM: : openshift: pin Go toolchain to 1.24.6 drop Marked explicitly to drop
a38f2c9ee UPSTREAM: : openshift: keep make test target for ci-operator squash Configuration carry candidate for squashing into core files carry
8f57c4ffe UPSTREAM: : openshift: document vendor tree ignore rules squash Configuration carry candidate for squashing into core files carry
0fa99d9b6 UPSTREAM: : openshift: vendor deps + track vendor tree squash Configuration carry candidate for squashing into core files carry

3. Core DNS & Custom Extensions (ocp_dnsnameresolver, other plugins)

Review Focus: DNS Operator sub-team to vet custom DNS extensions and routing plugins.

  • Description: Integrates OpenShift-specific CoreDNS external plugins (e.g., ocp_dnsnameresolver, coredns-mdns) and custom plugin-chaining configuration rules. These represent critical custom logic that must be reviewed carefully during the meeting.
Carry SHA Commit Message Default Action Reason
a19338c74 UPSTREAM: : openshift: Add github.com/openshift/coredns-mdns plugin cherry-pick Standard downstream carry
5e1e5be0e UPSTREAM: : openshift: Fix HostPortOrFile to support IPv6 addresses with zone (coredns#3527) cherry-pick Standard downstream carry
912fc2628 UPSTREAM: : openshift: Revert "remove wildcard query functionality (coredns#5019)" cherry-pick Standard downstream carry
b912bfdb7 UPSTREAM: : openshift: Revert "Revert "add wildcard warnings (coredns#5030)" (coredns#5167)" cherry-pick Standard downstream carry
47040eaf9 UPSTREAM: : openshift: Remove UDP Payload size hardcoding to 2048 on cache upstream refreshes. Don't override EDNS0 OPT RR, created by the bufsize plugin. Also, set default upstream UDP Payload to 512 if EDNS0 OPT RR doesn't exist. cherry-pick Standard downstream carry
59f7d2f51 UPSTREAM: 6354: openshift: Fix OCPBUGS-15755 cherry-pick Standard downstream carry
37a9afe69 UPSTREAM: 6277: openshift: Fix OCPBUGS-27397 cherry-pick Standard downstream carry
6b897ee50 UPSTREAM: : openshift: Move ocp_dnsnameresolver before cache in plugin chaining order cherry-pick Standard downstream carry
486112b6c UPSTREAM: 8227: fix(tls): use Go TLS defaults cherry-pick Standard downstream carry

4. Standard Code Carries & Bug Fixes (downstream code patches)

Review Focus: Principal reviewers and feature owners to vet behavioral regressions.

  • Description: Downstream-specific Go code modifications, temporary hotfixes, and custom features not covered by plugins. These require direct code reviews to check for duplication or obsolescence against upstream changes.
Carry SHA Commit Message Default Action Reason
a66edec93 UPSTREAM: 6692: openshift: Fix OCPBUGS-34619 cherry-pick Standard downstream carry
c48716dfb UPSTREAM: 7083: Fix unit test TestZoneExternalCNAMELookupWithProxy cherry-pick Standard downstream carry

Rebase Action Plan

Status legend: ⬜️ pending · 🔄 in progress · ✅ complete

Status Task Notes
⬜️ Produce and audit carry commits (commits.tsv) Phase 1 State Store
⬜️ Review and customize carry decisions Manual developer adjustments
⬜️ Execute local rebase branch & ours-merge baseline Phase 2 local checkout
⬜️ Port and resolve conflict on carries Applying squashes / cherry-picks
⬜️ Align vendoring tree (go mod tidy && vendor) Offline build alignment
⬜️ Pass local verification tests (make && make test) Build & Unit validation
⬜️ Push branch and open Draft PR Description serves as meeting agenda
⬜️ Address review comments & PR feedback Iterative feedback loop
⬜️ Move PR out of Draft ("Ready for Review") Human approval trigger
⬜️ Verify Prow CI checks succeed Phase 3 CI Monitoring
⬜️ Final merge and environment cleanup Phase 4 complete

Edit .rebase/commits.tsv locally to adjust decisions, then re-run to execute Phase 2.

yongtang and others added 30 commits June 8, 2026 16:26
…ormed PROXY packets (coredns#8154)

Avoid a potential nil pointer dereference in PacketConn.ReadFrom() when malformed PROXY protocol headers cause readFrom() to return a nil address.

Signed-off-by: Yong Tang <yong.tang.github@outlook.com>
Bumps the go-etcd-io group with 2 updates: [go.etcd.io/etcd/api/v3](https://github.com/etcd-io/etcd) and [go.etcd.io/etcd/client/v3](https://github.com/etcd-io/etcd).


Updates `go.etcd.io/etcd/api/v3` from 3.6.11 to 3.6.12
- [Release notes](https://github.com/etcd-io/etcd/releases)
- [Commits](etcd-io/etcd@v3.6.11...v3.6.12)

Updates `go.etcd.io/etcd/client/v3` from 3.6.11 to 3.6.12
- [Release notes](https://github.com/etcd-io/etcd/releases)
- [Commits](etcd-io/etcd@v3.6.11...v3.6.12)

---
updated-dependencies:
- dependency-name: go.etcd.io/etcd/api/v3
  dependency-version: 3.6.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-etcd-io
- dependency-name: go.etcd.io/etcd/client/v3
  dependency-version: 3.6.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-etcd-io
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…coredns#8168)

Bumps [github.com/aws/aws-sdk-go-v2](https://github.com/aws/aws-sdk-go-v2) from 1.41.7 to 1.41.11.
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](aws/aws-sdk-go-v2@v1.41.7...v1.41.11)

---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go-v2
  dependency-version: 1.41.11
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [golang.org/x/sys](https://github.com/golang/sys) from 0.45.0 to 0.46.0.
- [Commits](golang/sys@v0.45.0...v0.46.0)

---
updated-dependencies:
- dependency-name: golang.org/x/sys
  dependency-version: 0.46.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…coredns#8164)

Bumps [github.com/aws/aws-sdk-go-v2/service/secretsmanager](https://github.com/aws/aws-sdk-go-v2) from 1.41.7 to 1.42.1.
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](aws/aws-sdk-go-v2@v1.41.7...service/s3/v1.42.1)

---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go-v2/service/secretsmanager
  dependency-version: 1.42.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…oredns#8163)

Bumps [github.com/prometheus/common](https://github.com/prometheus/common) from 0.67.5 to 0.68.1.
- [Release notes](https://github.com/prometheus/common/releases)
- [Changelog](https://github.com/prometheus/common/blob/main/CHANGELOG.md)
- [Commits](prometheus/common@v0.67.5...v0.68.1)

---
updated-dependencies:
- dependency-name: github.com/prometheus/common
  dependency-version: 0.68.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [github.com/aws/aws-sdk-go-v2/config](https://github.com/aws/aws-sdk-go-v2) from 1.32.18 to 1.32.22.
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](aws/aws-sdk-go-v2@config/v1.32.18...config/v1.32.22)

---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go-v2/config
  dependency-version: 1.32.22
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
… server block (coredns#8169)

Signed-off-by: Jonathan Tooker <jonathan.tooker@netprotect.com>
…ns#8165)

Bumps [github.com/aws/aws-sdk-go-v2/service/route53](https://github.com/aws/aws-sdk-go-v2) from 1.62.7 to 1.63.1.
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](aws/aws-sdk-go-v2@service/iot/v1.62.7...service/s3/v1.63.1)

---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go-v2/service/route53
  dependency-version: 1.63.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Includes bug and security fixes.

Signed-off-by: Ville Vesilehto <ville@vesilehto.fi>
* chore(pkg/proxy): prepare for DoH implementation

Signed-off-by: Thomas Gosteli <thomas.gosteli@protonmail.ch>

* chore(pkg/proxy): prepare for DoH implementation

Signed-off-by: Thomas Gosteli <thomas.gosteli@protonmail.ch>

* feat(proxy): implement basic DoH resolution

Signed-off-by: Thomas Gosteli <thomas.gosteli@protonmail.ch>

* feat(forward): implement DoH forwarding

Signed-off-by: Thomas Gosteli <thomas.gosteli@protonmail.ch>

* feat(proxy): add basic DoH health checker

Signed-off-by: Thomas Gosteli <thomas.gosteli@protonmail.ch>

* chore: align http transport with Go's DefaultTransport

and resolve some of the TODOs

Signed-off-by: Thomas Gosteli <thomas.gosteli@protonmail.ch>

* docs(forward): add basic documentation for DoH

Signed-off-by: Thomas Gosteli <thomas.gosteli@protonmail.ch>

* chore: add basic tests to cover DoH

Signed-off-by: Thomas Gosteli <thomas.gosteli@protonmail.ch>

* chore(health): unify default timeout to 1s

Signed-off-by: Thomas Gosteli <thomas.gosteli@protonmail.ch>

* feat(forward): make doh method configurable

Signed-off-by: Thomas Gosteli <thomas.gosteli@protonmail.ch>

* chore: remove maxIdleConnsPerHost setting & update docs

Signed-off-by: Thomas Gosteli <thomas.gosteli@protonmail.ch>

* chore(forward): reject https upstreams with path

Signed-off-by: Thomas Gosteli <thomas.gosteli@protonmail.ch>

---------

Signed-off-by: Thomas Gosteli <thomas.gosteli@protonmail.ch>
…ns#8172)

Bumps [github.com/aws/aws-sdk-go-v2/service/route53](https://github.com/aws/aws-sdk-go-v2) from 1.63.1 to 1.63.3.
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](aws/aws-sdk-go-v2@service/s3/v1.63.1...service/s3/v1.63.3)

---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go-v2/service/route53
  dependency-version: 1.63.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…coredns#8175)

Bumps [github.com/aws/aws-sdk-go-v2/service/secretsmanager](https://github.com/aws/aws-sdk-go-v2) from 1.42.1 to 1.42.3.
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](aws/aws-sdk-go-v2@service/s3/v1.42.1...service/amp/v1.42.3)

---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go-v2/service/secretsmanager
  dependency-version: 1.42.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…dns#8179)

Bumps [github.com/aws/aws-sdk-go-v2/feature/ec2/imds](https://github.com/aws/aws-sdk-go-v2) from 1.18.27 to 1.18.29.
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](aws/aws-sdk-go-v2@config/v1.18.27...config/v1.18.29)

---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go-v2/feature/ec2/imds
  dependency-version: 1.18.29
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
)

Bumps [github.com/aws/aws-sdk-go-v2/credentials](https://github.com/aws/aws-sdk-go-v2) from 1.19.21 to 1.19.24.
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](aws/aws-sdk-go-v2@credentials/v1.19.21...credentials/v1.19.24)

---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go-v2/credentials
  dependency-version: 1.19.23
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [github.com/aws/aws-sdk-go-v2/config](https://github.com/aws/aws-sdk-go-v2) from 1.32.22 to 1.32.25.
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](aws/aws-sdk-go-v2@config/v1.32.22...config/v1.32.25)

---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go-v2/config
  dependency-version: 1.32.24
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…h no OPT record (coredns#8190)

* plugin/rewrite: Fix nil-pointer panic in EDNS0 response reversion with no OPT record

This PR fix a nil-pointer panic in EDNS0 response reversion when downstream responses do not contain an OPT record,

Signed-off-by: Yong Tang <yong.tang.github@outlook.com>

* Fix

Signed-off-by: Yong Tang <yong.tang.github@outlook.com>

---------

Signed-off-by: Yong Tang <yong.tang.github@outlook.com>
* plugin/hosts: add wildcard support for owner names

Signed-off-by: youknowforsearch <amirhebrahimzader@gmail.com>

* plugin/hosts: document wildcard owner name support

Signed-off-by: youknowforsearch <amirhebrahimzader@gmail.com>

* plugin/hosts: remove unused lookupStaticHost

Signed-off-by: Amirhossein Ebrahimzade <amirhossein.e@smartech.ir>

---------

Signed-off-by: youknowforsearch <amirhebrahimzader@gmail.com>
Signed-off-by: Amirhossein Ebrahimzade <amirhossein.e@smartech.ir>
Co-authored-by: Amirhossein Ebrahimzade <amirhossein.e@smartech.ir>
Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.3 to 7.0.0.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@df4cb1c...9c091bb)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…oredns#8195)

Bumps [github.com/prometheus/common](https://github.com/prometheus/common) from 0.68.1 to 0.69.0.
- [Release notes](https://github.com/prometheus/common/releases)
- [Changelog](https://github.com/prometheus/common/blob/main/CHANGELOG.md)
- [Commits](prometheus/common@v0.68.1...v0.69.0)

---
updated-dependencies:
- dependency-name: github.com/prometheus/common
  dependency-version: 0.69.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
knobunc and others added 23 commits August 21, 2026 14:22
1. Why is this pull request needed and what does it do?

Put OpenShift users in the OWNERS file so that we can maintain this fork.
Also add a RHEL7 Dockerfile.

Co-authored-by: Antoni Segura Puimedon <antoni@redhat.com>
Co-authored-by: Dan Mace <ironcladlou@gmail.com>
Previous coredns versions had a `make test` target and our ci-operator
currently uses this target to kick off the tests. So, at least to get
tests running against this PR without requiring changes to the
openshift/release ci-operator setup, I'm adding that target back.

This just runs the full litany of tests that Travis would run except
for the coverage targets and the tests that require a running etcd
server.
The coredns exclusion in .gitignore was ignoring anything that was named
coredns. This patch makes it specifically just the binary in the main dir.
…eimages to mach ocp-build-data config

This PR is autogenerated by the [ocp-build-data-enforcer][1].
It updates the baseimages in the Dockerfile used for promotion in order to ensure it
matches the configuration in the [ocp-build-data repository][2] used
for producing release artifacts.

If you believe the content of this PR is incorrect, please contact the dptp team in

[1]: https://github.com/openshift/ci-tools/tree/master/cmd/ocp-build-data-enforcer
[2]: https://github.com/openshift/ocp-build-data/tree/openshift-4.6-rhel-8/images
Add sgreene70, frobware, candita, rfredette, and alebedev87 to the
approvers section of the OWNERS file.
…image` from openshift/release

This is an autogenerated PR that updates the `.ci-operator.yaml`
to reference the `build_root_image` found in the [ci-operator-config](https://github.com/openshift/release/tree/master/ci-operator/config)
in the [openshift/release](https://github.com/openshift/release) repository.

This is done in preparation for enabling reading the `build_root` from
your repository rather than the central config in [openshift/release](https://github.com/openshift/release).
This allows to update the `build_root` in lockstep with code changes. For details, please
refer to the [docs](https://docs.ci.openshift.org/docs/architecture/ci-operator/#build-root-image).

Note that enabling this feature is mandatory for all OCP components that have an ART build config.

A second autogenerated PR to the [openshift/release repository](https://github.com/openshift/release)
will enable reading the `build_root` from your repository once this PR was merged.

If you have any questions, please feel free to reach out in the #forum-testplatform
channel in the CoreOS Slack.
Disable dependabot in the openshift fork
Add an OWNERS file so that we can maintain this fork.

Co-authored-by: Andrey Lebedev <alebedev@redhat.com>
Co-authored-by: Benjamin Bennett <bbennett@redhat.com>
Co-authored-by: Miciah Dashiel Butler Masters <mmasters@redhat.com>
Co-authored-by: Stephen Greene <sgreene@redhat.com>
Co-authored-by: Grant Spence <gspence@redhat.com>
Co-authored-by: AOS Automation Release Team <noreply@redhat.com>
Co-authored-by: Justin Pierce <jupierce@redhat.com>
Co-authored-by: openshift-bot <openshift-bot@users.noreply.github.com>
Co-authored-by: openshift-ci-robot <openshift-ci-robot@users.noreply.github.com>
Add Dockerfiles and .ci-operator.yaml.

Co-authored-by: Antoni Segura Puimedon <antoni@redhat.com>
Co-authored-by: Dan Mace <ironcladlou@gmail.com>
Co-authored-by: AOS Automation Release Team <noreply@redhat.com>
Co-authored-by: Justin Pierce <jupierce@redhat.com>
Co-authored-by: openshift-bot <openshift-bot@users.noreply.github.com>
Co-authored-by: openshift-ci-robot <openshift-ci-robot@users.noreply.github.com>
Modified-by: Grant Spence <gspence@redhat.com>
Downstream policy (carried since 213249c/1b37b38eb) disables Dependabot in the
OpenShift forks because ART curates dependencies centrally and the automated PRs
get closed immediately.

This commit removes `.github/dependabot.yml` and documents the policy in
`carry_consolidation/dependabot_policy.md` so future rebases know why we do not
re-enable it even though upstream keeps the workflow enabled.

Co-authored-by: Ryan Fredette <rfredette@redhat.com>
Co-authored-by: Grant Spence <gspence@redhat.com>
@coderabbitai

coderabbitai Bot commented Aug 21, 2026

Copy link
Copy Markdown

Caution

CodeRabbit couldn't post its review summary.

Error details
Validation Failed: {"resource":"IssueComment","code":"unprocessable","field":"data","message":"Body is too long (maximum is 65536 characters)"} - https://docs.github.com/rest/issues/comments#create-an-issue-comment

@coderabbitai

coderabbitai Bot commented Aug 21, 2026

Copy link
Copy Markdown

Caution

CodeRabbit couldn't post its review summary.

Error details
Validation Failed: {"resource":"IssueComment","code":"unprocessable","field":"data","message":"Body is too long (maximum is 65536 characters)"} - https://docs.github.com/rest/issues/comments#create-an-issue-comment

@openshift-ci openshift-ci Bot added the do-not-merge/invalid-owners-file Indicates that a PR should not merge because it has an invalid OWNERS file in it. label Aug 21, 2026
@openshift-ci

openshift-ci Bot commented Aug 21, 2026

Copy link
Copy Markdown

The OWNERS file contains untrusted users, which makes it INVALID. The following users are mentioned in OWNERS file(s) but are untrusted for the following reasons. One way to make the user trusted is to add them as members of the openshift org. You can then trigger verification by writing /verify-owners in a comment.

  • smarterclayton
    • User is not a member of the org. User is not a collaborator. Satisfy at least one of these conditions to make the user trusted.
  • danehans
    • User is not a member of the org. User is not a collaborator. Satisfy at least one of these conditions to make the user trusted.
  • sgreene570
    • User is not a member of the org. User is not a collaborator. Satisfy at least one of these conditions to make the user trusted.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

do-not-merge/invalid-owners-file Indicates that a PR should not merge because it has an invalid OWNERS file in it. do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress.

Projects

None yet

Development

Successfully merging this pull request may close these issues.