Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
168 commits
Select commit Hold shift + click to select a range
595010a
fix: per-endpoint hostname override blocked by auto-generated wildcad…
zirain Mar 22, 2026
4b72902
feat/mtls add ClientValidationMode (#8325)
Julien-Beezeelinx Mar 23, 2026
c11f0c2
fix(tcp): add SNI-based filter chain matching for TLS passthrough emp…
OliverBailey Mar 23, 2026
205e455
ci: fix netlify build (#8571)
zirain Mar 23, 2026
dd0c09f
feat: upstream access log (#8397)
zirain Mar 23, 2026
674f13b
chore: refactor JSONPatch (#8497)
zirain Mar 23, 2026
1005160
docs: fix terminology inconsistencies for External Authorization (#8539)
haruyama480 Mar 23, 2026
c4db7cf
docs: ignore blog.envoyproxy.io (#8574)
zirain Mar 23, 2026
ef8f744
feat(loadbalancer): Add LoadBalancerType Client Side Weighted Round R…
altaiezior Mar 23, 2026
12de3c5
build(deps): bump loki from 6.54.0 to 6.55.0 in /charts/gateway-addon…
dependabot[bot] Mar 23, 2026
e633c08
fix bug with grpcroute mirror filter (#8541)
aburanrbx Mar 23, 2026
9cac348
fix: normalize CRLF line endings in htpasswd basic auth secrets (#8557)
stekole Mar 23, 2026
a049df2
build(deps): bump the gomod group across 5 directories with 6 updates…
dependabot[bot] Mar 23, 2026
d640a6d
chore: update release schedule (#8584)
zhaohuabing Mar 24, 2026
3c2fc03
feat: GeoIP (#8453)
zhaohuabing Mar 24, 2026
2de2611
Bump version (#8587)
jukie Mar 24, 2026
a5535c4
chore: update grpc to fix osv scan (#8586)
zhaohuabing Mar 25, 2026
b8392b2
build(deps): bump busybox from `b3255e7` to `1487d0a` in /tools/docke…
dependabot[bot] Mar 25, 2026
485decc
build(deps): bump the actions group across 1 directory with 2 updates…
dependabot[bot] Mar 25, 2026
18b3fcb
build(deps): bump the gomod group across 1 directory with 2 updates (…
dependabot[bot] Mar 25, 2026
d35bf70
build(deps): bump the helm group across 1 directory with 3 updates (#…
dependabot[bot] Mar 25, 2026
4aa6c37
build(deps): bump the k8s-io group across 1 directory with 6 updates …
dependabot[bot] Mar 25, 2026
80b2762
[xds] stabilize listener-level Lua XDS filters to avoid listener drai…
arkodg Mar 26, 2026
df99196
docs: fix typos in RELEASING.md (#8601)
archy-rock3t-cloud Mar 26, 2026
69b91e9
chore: update basic auth error status (#8589)
zhaohuabing Mar 27, 2026
7bff34c
chore: update request buffer docs (#8604)
zhaohuabing Mar 27, 2026
703a3b4
docs: add note on case-insensitivity of header names (#8596)
lextiz Mar 28, 2026
fae7f19
Add Pollinate to Envoy Gateway adopters (#8607)
shavmohin Mar 28, 2026
b1d7302
fix: reject incompatible requestBuffer + httpUpgrade CTP (#8605)
zhaohuabing Mar 29, 2026
945fe9f
geoip docs (#8585)
zhaohuabing Mar 29, 2026
99bc7ef
chore: update Performance Benchmark Report (#8613)
zhaohuabing Mar 30, 2026
4f300b7
feat: support invert in source match (#8407)
rudrakhp Mar 30, 2026
41d15ba
chore: fix osv scan (#8615)
zhaohuabing Mar 30, 2026
4768ca7
fix json report (#8614)
zhaohuabing Mar 30, 2026
b4c15b7
chore: add benchmark report to the release process (#8617)
zhaohuabing Mar 30, 2026
47a167a
feat: implement remote source dynamic modules (#8579)
jukie Mar 30, 2026
f4aef87
chore: fix e2e tests (#8450)
zirain Mar 31, 2026
91f46ae
feat: JSON log encoder uses abbreviated field keys (#8555)
zirain Mar 31, 2026
c86eb78
test: add unit tests for route sort precedence (#8603)
archy-rock3t-cloud Mar 31, 2026
dc8e6fc
feat(translator): make append_x_forwarded_host configurable in HTTPRo…
rborale5 Mar 31, 2026
7a2a4ec
fix: avoid metric increments on no-op delete reconcile paths (#8480)
felipesabadini Mar 31, 2026
fdc3128
chore: cswrr cleanup and e2e (#8582)
jukie Mar 31, 2026
87b8d14
chore: add make target for benchmark dashboard (#8621)
zhaohuabing Apr 1, 2026
4dcb964
feat(telemetry): add sampler config for OpenTelemetry tracing (#8529)
codefromthecrypt Apr 1, 2026
990e720
feat(ctp): add IgnoredUpgradeTypes to HTTP1Settings (#8599)
michalskalski Apr 1, 2026
9c7a9d7
build(deps): bump npm-check-updates from 19.6.6 to 20.0.0 in /site (#…
dependabot[bot] Apr 1, 2026
2b265ab
chore: fix metrics check in the rate limit e2e tests (#8636)
zhaohuabing Apr 1, 2026
304e38b
build(deps): bump the gomod group across 1 directory with 2 updates (…
dependabot[bot] Apr 1, 2026
e5e1dfe
build(deps): bump the actions group across 2 directories with 7 updat…
dependabot[bot] Apr 1, 2026
f5905b3
enterprise support: Add Procedure Technologies (#8643)
harshita375 Apr 1, 2026
a0cd31f
fix typo (#8629)
Alireza-Mim Apr 1, 2026
c773478
build(deps): bump the helm group across 1 directory with 2 updates (#…
dependabot[bot] Apr 1, 2026
8986e16
chore: bump API version (#8644)
zirain Apr 1, 2026
ac18feb
fix(telemetry): support BackendTLSPolicy for telemetry backends (#8545)
codefromthecrypt Apr 2, 2026
dd79a83
ci(fix): ensure Go binaries in published Docker images have correct m…
shahar-h Apr 2, 2026
2a5bfd0
fix: restore failure-path metric recording for delete and HPA reconci…
felipesabadini Apr 2, 2026
f1fedb1
fix for duplicate cidr local rate limit rules (#8650)
erik-hunter Apr 2, 2026
77965c3
feat: impl gateway tls.frontend/tls.backend (#8380)
zirain Apr 2, 2026
2bbe061
docs: fix `Protol` -> `Protocol` typo (#8657)
wiktor-k Apr 2, 2026
b4b5cab
chore: remove cluster.LbPolicy usage (#8637)
jukie Apr 2, 2026
e802fd4
chore: align all helm calls to use go tool (#8659)
shahar-h Apr 2, 2026
e8dd1a5
ci: remove codecov workaround (#8664)
shahar-h Apr 2, 2026
66958e2
ci: remove hardcoded KIND_NODE_TAG from release benchmark (#8661)
shahar-h Apr 3, 2026
2620fea
chore: add lint check to enforce ubuntu-latest in workflow runs-on (#…
shahar-h Apr 3, 2026
6d06f23
Publish chart and docker image for rc.0 tags (#8658)
jukie Apr 3, 2026
d35803f
ci: fix broken go-benchmark-test (#8663)
shahar-h Apr 4, 2026
17ff01a
chore: fix cve (#8669)
zirain Apr 5, 2026
b64158c
ci: remove continue-on-error from go-benchmark-test (#8670)
shahar-h Apr 5, 2026
3644512
ci: pin checkout action (#8674)
shahar-h Apr 5, 2026
eae5a7d
docs: clarify supported HTTP redirect status codes (#8566)
Aditya7880900936 Apr 5, 2026
76f79f5
feat: support grpc stats settings (#8158)
kkk777-7 Apr 6, 2026
42e3999
Fix link to Tasks section in quickstart.md (#8618)
xCyberxx Apr 6, 2026
2ecab60
chore: pin npm tools (#8672)
shahar-h Apr 6, 2026
fa81778
fix: status for mirror backend (#8675)
kkk777-7 Apr 6, 2026
3352b2a
ci: add github action for codex review on PRs (#8679)
arkodg Apr 6, 2026
10dbf34
build(deps): bump the actions group across 1 directory with 2 updates…
dependabot[bot] Apr 6, 2026
b35a84f
build(deps): bump sigs.k8s.io/mcs-api from 0.4.0 to 0.4.1 (#8683)
dependabot[bot] Apr 6, 2026
c8376fb
build(deps): bump the helm group across 1 directory with 2 updates (#…
dependabot[bot] Apr 6, 2026
3b4de6d
fix(gatewayapi): add deprecated warning for clientValidation.optional…
officialasishkumar Apr 6, 2026
0e26106
feat: add support for contrpl plane tracer (#8551)
zirain Apr 7, 2026
c3d06fa
build(deps): bump the gomod group across 5 directories with 11 update…
dependabot[bot] Apr 7, 2026
ee3091a
api: dynamic module lb (#8638)
jukie Apr 8, 2026
6524e19
build(deps): bump actions/checkout from 6.0.1 to 6.0.2 in the actions…
dependabot[bot] Apr 8, 2026
da22db2
build(deps): bump the gomod group across 2 directories with 4 updates…
dependabot[bot] Apr 8, 2026
082b038
build(deps): bump the helm group across 1 directory with 2 updates (#…
dependabot[bot] Apr 8, 2026
c7e21fa
fix: client certificate secret never delivered when it is exclusively…
zirain Apr 9, 2026
9d84fa8
bump golang for CVE (#8709)
zirain Apr 10, 2026
828cd01
set the status when EPP target to a MergeGateways with wrong kind (#7…
fabian4 Apr 10, 2026
f404a9c
chore: update testdata to covered multiple listener in one gateway (#…
zirain Apr 10, 2026
40b3dbf
fix: disable http3 when client tls is configured (#8583)
zhaohuabing Apr 12, 2026
95c3a79
fix: client certificate secret never delivered when it is exclusively…
zirain Apr 13, 2026
bd5f162
chore: fix release issue gen (#8722)
rudrakhp Apr 13, 2026
8d2f190
remove DFP filter (#8655)
zhaohuabing Apr 13, 2026
52bafc6
build(deps): bump the gomod group across 1 directory with 2 updates (…
dependabot[bot] Apr 13, 2026
1595743
api for id token forwarding (#8691)
zhaohuabing Apr 13, 2026
0a81122
oidc: native oauth2 per-route config (#8703)
zhaohuabing Apr 13, 2026
ad6da44
chore: add review skill (#8237)
zhaohuabing Apr 13, 2026
d030772
feat: Support for merged EnvoyProxy settings (#8169)
mgs255 Apr 13, 2026
8e858e5
[ci] rm codex review action (#8726)
arkodg Apr 13, 2026
bbdb718
build(site): use npm ci and clean up docs CI pipeline (#8694)
shahar-h Apr 13, 2026
9f25066
fix: followup for #8380 (#8666)
zirain Apr 13, 2026
66c746e
chore: fix release issue WF (#8727)
rudrakhp Apr 13, 2026
d938c3c
docs: rename Contributions section to Community (#8427)
antonio-mazzini Apr 13, 2026
fa31928
chore: update Go tools and resolve golangci-lint warnings (#8740)
shahar-h Apr 13, 2026
8e813bd
refactor: replace ptr.To with Go 1.26 new() builtin (#8718)
shahar-h Apr 14, 2026
beb9fec
fix: ContextExtensions merge behavior (#8747)
zhaohuabing Apr 15, 2026
c48a346
fix: helm secrets rbac for gateway namespace with watch list of names…
cnvergence Apr 15, 2026
a62230e
build(deps): bump the actions group across 1 directory with 3 updates…
dependabot[bot] Apr 15, 2026
faf7a99
build(deps-dev): bump autoprefixer from 10.4.27 to 10.5.0 in /site (#…
dependabot[bot] Apr 15, 2026
1baf309
build(deps): bump npm-check-updates from 20.0.0 to 21.0.0 in /site (#…
dependabot[bot] Apr 16, 2026
e2aa3e6
build(deps): bump the helm group across 1 directory with 3 updates (#…
dependabot[bot] Apr 16, 2026
8dc1846
[release/v1.6] add release notes for v1.6.6 (#8765)
rudrakhp Apr 16, 2026
12a3e6d
ExtAuth: allow passing Route metadata to Ext Auth (#8723)
zhaohuabing Apr 16, 2026
8c5b67f
[release/v1.6] add benchmark report for v1.6.6 (#8772)
rudrakhp Apr 16, 2026
4747557
[release/v1.6] update docs + release announcement for v1.6.6 (#8774)
rudrakhp Apr 16, 2026
7d2267e
docs: fix typo in page for http-request-headers (#8752)
picccard Apr 17, 2026
e777f63
[release/v1.7] add release notes and docs announcement for v1.7.2 (#8…
cnvergence Apr 17, 2026
7b606c9
[release/v1.7] add benchmark report for v1.7.2 (#8779)
cnvergence Apr 17, 2026
5ed1c4c
ci: optimize binary builds in build_and_test workflow (#8777)
shahar-h Apr 17, 2026
a3b541c
feat: support GatewayStaticAddresses conformance test (#8395)
cnvergence Apr 17, 2026
d80fb5b
Fix rc.0 publish (#8782)
jukie Apr 17, 2026
3f70a89
fix: deep copy status in translator layer to avoid race (#8778)
rudrakhp Apr 19, 2026
c97626e
feat: add per-rule XRateLimitOption to BackendTrafficPolicy (#8742)
zirain Apr 20, 2026
56cc3f7
chore: add missing labels for the rl service account (#8793)
zhaohuabing Apr 20, 2026
28033f9
chore: OSV scanner (#8794)
zirain Apr 21, 2026
a7545ce
fix: bound BackendTrafficPolicy rateLimit requests to uint32 max (#8798)
PatilHrushikesh Apr 21, 2026
85e62dd
fix: use per-route ratelimit filter (#8741)
zirain Apr 21, 2026
a056d44
feat: add extraEnv support to envoy-gateway controller deployment (#8…
girikuncoro Apr 22, 2026
00d0895
api: add cel validation of MaxEjectionPercent (#8804)
kkk777-7 Apr 22, 2026
7633125
fix: force HTTP1 for upstream connections for WS and WSS backends (#8…
zhaohuabing Apr 22, 2026
e5af3e0
build(deps): bump the gomod group across 2 directories with 4 updates…
dependabot[bot] Apr 22, 2026
7e41346
build(deps): bump the actions group across 1 directory with 2 updates…
dependabot[bot] Apr 22, 2026
f4a212e
chore: fix race and panic (#8795)
zirain Apr 22, 2026
b8eb202
build(deps): bump npm-check-updates from 21.0.0 to 21.0.3 in /site (#…
dependabot[bot] Apr 22, 2026
f33ec41
build(deps): bump sigs.k8s.io/gateway-api-inference-extension from 1.…
dependabot[bot] Apr 22, 2026
028ce99
build(deps): bump opentelemetry-collector from 0.150.0 to 0.150.1 in …
dependabot[bot] Apr 22, 2026
30fa914
feat: add support for certificate fetching via SDS ref secret (#8745)
zirain Apr 22, 2026
c050634
docs: note ETag handling in response compression task (#8824)
alliasgher Apr 23, 2026
669d714
chore: bump docsy (#8819)
zirain Apr 23, 2026
7b14b5b
build(deps): bump aquasecurity/trivy-action from 0.35.0 to 0.36.0 in …
dependabot[bot] Apr 23, 2026
9d919e5
fix: correct duration dashboard panels to use proper PromQL queries (…
felipesabadini Apr 23, 2026
f394346
test: use registry.k8s.io instead of staging (#8831)
jukie Apr 23, 2026
78380e4
feat: Add BackendUtilization + WeightedZones support (WrrLocality Lb …
jukie Apr 23, 2026
18bd6c5
build(deps): bump opentelemetry-collector from 0.150.1 to 0.152.0 in …
dependabot[bot] Apr 23, 2026
c8573c4
docs(cors): show allowCredentials in the CORS task (#8611)
officialasishkumar Apr 23, 2026
874d43f
Add support for extraVolumes and extraVolumeMounts to EG deployment (…
mkhpalm Apr 23, 2026
b47bc2b
api: add cel validation of GrpcStatus (#8803)
kkk777-7 Apr 23, 2026
63c5b5b
conformance: update skipped features (#8837)
zirain Apr 24, 2026
cab6837
e2e: add test for watched namespace (#8786)
zhaohuabing Apr 24, 2026
30cdc61
performance: use cached kube client for the infra runner (#8764)
zhaohuabing Apr 25, 2026
e098718
api: add bandwidth limit (#8630)
kkk777-7 Apr 25, 2026
7811d86
fix: reason with multiple errors rejected validation (#8859)
zirain Apr 25, 2026
dd203e5
feat: support overriding ext_auth path (#8612)
rudrakhp Apr 26, 2026
99fbb76
[release/v1.6] update docs for v1.6.7 (#8865)
rudrakhp Apr 27, 2026
8570285
feat(chart): Allow configuring envoy proxy image via helm chart (#8785)
mgs255 Apr 27, 2026
6b8ac52
[release/v1.6] add v1.6.7 benchmark data (#8874)
rudrakhp Apr 28, 2026
c68d38c
feat(extensionManager): add support for multiple ExtensionManagers wi…
toffentoffen Apr 28, 2026
65d0663
[release/v1.6] bump v1.6 in docs to v1.6.7 (#8875)
rudrakhp Apr 28, 2026
de1ae65
chore: update api docs for the default EnvoyProxy (#8866)
zhaohuabing Apr 28, 2026
6774309
feat: bandwidth limit (#8862)
kkk777-7 Apr 28, 2026
6e1fd5b
fix: dpanic in logger (#8880)
rudrakhp Apr 28, 2026
c16ddd3
feat: Add source to responseOverride (#8391)
lboynton Apr 29, 2026
d48292b
build(deps): bump npm-check-updates from 21.0.3 to 22.0.1 in /site (#…
dependabot[bot] Apr 29, 2026
4628260
build(deps): bump go.uber.org/zap from 1.27.1 to 1.28.0 (#8884)
dependabot[bot] Apr 29, 2026
b966472
build(deps): bump the helm group across 1 directory with 4 updates (#…
dependabot[bot] Apr 29, 2026
56f4976
chore: update JSONPatch testdata (#8877)
zirain Apr 29, 2026
bef5ed1
feat: cross ns policy attachment (#8676)
zhaohuabing Apr 30, 2026
8fa767a
feat: add admission control to BackendTrafficPolicy (#8872)
jukie Apr 30, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
55 changes: 55 additions & 0 deletions .agents/skills/pr-review/SKILL.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,55 @@
---
name: review-envoy-gateway-pr
description: Review an Envoy Gateway pull request for essential API, implementation, status, and test coverage requirements.
metadata:
short-description: Envoy Gateway PR review workflow
version: "0.1"
---

# Envoy Gateway PR Review Skill

## Inputs
- GitHub PR URL (e.g. review PR: https://github.com/envoyproxy/gateway/pull/8237), or
- A local diff between commits (e.g. review change: git diff 4927877a HEAD)

## Output
- Lead with findings ordered by severity.
- Include exact file and line references.
- Separate required fixes from optional follow-ups.
- If there are no findings, say that clearly and mention residual test or release-note risk.

## Review
- Check API changes, implementation changes, feature coverage, and release notes as applicable.
- Keep findings concise and actionable, with file references when possible.

## Checklist

### API changes
- Make sure changes under `api/` align with https://github.com/kubernetes/community/blob/master/contributors/devel/sig-architecture/api-conventions.md
- Make sure changes under `api/` are consistent with existing API patterns in the Gateway API project: https://github.com/kubernetes-sigs/gateway-api/tree/main/apis
- Make sure changes under `api/` are consistent with existing API patterns in this project.
- Try to reuse existing types.
- Keep naming consistent with this project.
- Try to add kubebuilder and CEL validations to catch errors.
- Make sure API validations are tested in `/test/cel-validation`.
- Check backward compatibility for API shape, CRD schema, defaults, versioned structs, and upgrade behavior.
- If a PR mixes API and implementation changes, say whether it should be split into separate PRs.

### Implementation changes
- For changes under `internal/gatewayapi`, check that user-visible errors are surfaced in status.
- For changes under `internal/gatewayapi`, check that status conditions follow the conventions in the Gateway API spec: https://gateway-api.sigs.k8s.io/geps/gep-1364/index.html
- For changes under `internal/gatewayapi`, check that `internal/gatewayapi/testdata` has coverage.
- For changes under `internal/xds/translator`, check that `internal/xds/translator/testdata` has coverage.

### Feature coverage
- For new user-facing features, check that `test/e2e` has coverage.
- For bug fixes, check that `test/e2e` has coverage if the bug is in user-facing code or has user-facing impact.

### Release notes
Release notes should be added to `release-notes/current.yaml` for any of the following changes:
- Bug fixes should be noted as "bug fix" and include a brief description of the issue and the fix.
- New features should be noted as "new feature" and include a brief description of the feature.
- Any breaking changes should be noted as "breaking change" and include a clear description of the change and its impact on users.
- Any change to generated Envoy config (xDS) that moves, removes, or modifies existing config content would break EnvoyPatchPolicies and Extension Servers, so it should be noted as a breaking change. Additions to generated xDS config do not need to be called out.
- Existing API changes should be noted.
- Existing behavior changes should be noted.
7 changes: 5 additions & 2 deletions .github/ISSUE_TEMPLATE/release.md
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,10 @@ assignees: ''
- [ ] push tag
- [ ] Push tag https://github.com/envoyproxy/gateway/releases/tag/v1.x.x
- [ ] wait for release CI
- [ ] update benchmark dashboard
- [ ] `make sync-benchmark-dashboard VERSION=v1.x.x`
- [ ] open and merge PR with generated `site/tools/benchmark-dashboard/src/data/**` and `site/static/**` changes
- [ ] verify quickstart
- [ ] update doc
- [ ] update release [announcement](https://github.com/envoyproxy/gateway/releases/tag/v1.x.x)
- [ ] GH Release, Slack announcement, [google group](https://groups.google.com/g/envoy-gateway-announce) announcement
- [ ] update release [announcement](https://github.com/envoyproxy/gateway/releases/tag/v1.x.x)
- [ ] GH Release, Slack announcement, [google group](https://groups.google.com/g/envoy-gateway-announce) announcement
2 changes: 1 addition & 1 deletion .github/PULL_REQUEST_TEMPLATE.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@ Examples:
* "chore: change ci & build tools etc"
* "api: add xxx fields in ClientTrafficPolicy"

Before raising a PR, please go through this section of the developer guide, https://gateway.envoyproxy.io/contributions/develop/#raising-a-pr
Before raising a PR, please go through this section of the developer guide, https://gateway.envoyproxy.io/community/develop/#raising-a-pr
-->

<!--
Expand Down
4 changes: 4 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -61,8 +61,12 @@ updates:
- package-ecosystem: npm
directories:
- /site
- /tools
schedule:
interval: weekly
ignore:
# fortawesome/fontawesome-free should be updated with docsy.
- dependency-name: "@fortawesome/fontawesome-free"
- package-ecosystem: pip
directories:
- /tools/src/codespell
Expand Down
112 changes: 77 additions & 35 deletions .github/workflows/build_and_test.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -39,9 +39,9 @@ jobs:
- ".github/workflows/build_and_test.yaml"

lint:
runs-on: ubuntu-22.04
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- uses: ./tools/github-actions/setup-deps
# Generate the installation manifests first, so it can check
# for errors while running `make -k lint`
Expand All @@ -50,16 +50,16 @@ jobs:
- run: make -k lint

gen-check:
runs-on: ubuntu-22.04
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- uses: ./tools/github-actions/setup-deps
- run: make -k gen-check

license-check:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- uses: ./tools/github-actions/setup-deps
- run: make -k licensecheck

Expand All @@ -72,20 +72,20 @@ jobs:
- changes
if: ${{ github.event_name != 'pull_request' || needs.changes.outputs.run_test_workflow == 'true' }}
steps:
- uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- uses: ./tools/github-actions/setup-deps

# test
- name: Run Coverage Tests
run: make go.test.coverage
- name: Upload coverage to Codecov
uses: codecov/codecov-action@671740ac38dd9b0130fbe1cec585b89eea48d3de # v5.5.2
uses: codecov/codecov-action@57e3a136b779b570ffcdbf80b3bdc90e7fab3de2 # v6.0.0
with:
fail_ci_if_error: true
files: ./coverage.xml
name: codecov-envoy-gateway
verbose: true
use_oidc: ${{ !(github.event_name == 'pull_request' && github.event.pull_request.head.repo.fork) }}
use_oidc: true

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Keep tokenless fallback for forked PR coverage uploads

Setting use_oidc: true unconditionally makes the Codecov step depend on an OIDC token for every pull_request run. Forked PR workflows typically cannot rely on that token path, so with fail_ci_if_error: true this can fail the entire coverage-test job for external contributors even when tests pass. The previous conditional guarded this exact case; restoring a fork-aware condition avoids blocking community PRs.

Useful? React with 👍 / 👎.


go-benchmark-test:
runs-on: ubuntu-latest
Expand All @@ -94,12 +94,11 @@ jobs:
- build
if: ${{ github.event_name != 'pull_request' || needs.changes.outputs.run_test_workflow == 'true' }}
steps:
- uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
fetch-depth: 0 # Need main branch access for benchmark comparison
- uses: ./tools/github-actions/setup-deps
- name: Run Benchmark Comparison
continue-on-error: true
run: |
if [[ "${{ github.event_name }}" == "pull_request" ]]; then
./tools/hack/go-benchmark-compare.sh
Expand All @@ -112,18 +111,41 @@ jobs:
needs: [changes, lint, gen-check, license-check, coverage-test]
if: ${{ github.event_name != 'pull_request' || needs.changes.outputs.run_test_workflow == 'true' }}
steps:
- uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
# For main branch builds, we need to fetch tags so go binary will be built with
# the recent vX.Y.Z-rc.0 tag, which helps avoid false positives in vulnerability scans.
# `fetch-tags: true` doesn't work: https://github.com/actions/checkout/issues/1471
# As a workaround `filter: tree:0` is used to create a treeless clone.
# See:
# https://github.com/actions/checkout/issues/1471#issuecomment-1755639487
# https://github.blog/open-source/git/get-up-to-speed-with-partial-clone-and-shallow-clone/
with:
fetch-depth: ${{ github.ref == 'refs/heads/main' && '0' || '1' }}
filter: ${{ github.ref == 'refs/heads/main' && 'tree:0' || '' }}
- uses: ./tools/github-actions/setup-deps

- name: Build EG Multiarch Binaries
run: make build-multiarch PLATFORMS="linux_amd64 linux_arm64"
# Build both linux/amd64 and linux/arm64 on main (needed for multi-arch image publish),
# and only linux/amd64 on PRs and release branches.
- name: Build EG Binaries
run: make build-multiarch BINS="envoy-gateway" PLATFORMS="${{ github.ref == 'refs/heads/main' && 'linux_amd64 linux_arm64' || 'linux_amd64' }}"

- name: Upload EG Binaries
uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7.0.0
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: envoy-gateway
path: bin/

build-egctl:
runs-on: ubuntu-latest
needs: [changes, lint, gen-check, license-check, coverage-test]
if: ${{ github.event_name != 'pull_request' || needs.changes.outputs.run_test_workflow == 'true' }}
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- uses: ./tools/github-actions/setup-deps

- name: Build egctl Binary
run: make build BINS="egctl" PLATFORM="linux_amd64"

conformance-test:
runs-on: ubuntu-latest
needs:
Expand Down Expand Up @@ -159,8 +181,12 @@ jobs:
ipFamily: ipv4
profile: xds-name-scheme-v2
gwapiChannel: experimental
- version: v1.35.0
ipFamily: ipv4
profile: watch-namespaces
gwapiChannel: experimental
steps:
- uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- uses: ./tools/github-actions/setup-deps

- name: Download EG Binaries
Expand All @@ -170,9 +196,7 @@ jobs:
path: bin/

- name: Give Privileges To EG Binaries
run: |
chmod +x bin/linux/amd64/envoy-gateway
chmod +x bin/linux/arm64/envoy-gateway
run: chmod +x bin/linux/*/envoy-gateway

# conformance
- name: Run Standard Conformance Tests
Expand All @@ -185,6 +209,7 @@ jobs:
# set ACTIONS_STEP_DEBUG to true if context runner.debug is '1',
# which means to dump the current state when there's a case failed.
ACTIONS_STEP_DEBUG: ${{ runner.debug == '1' }}
SKIP_GO_BUILD: "true"
run: make conformance

e2e-test:
Expand Down Expand Up @@ -216,9 +241,12 @@ jobs:
- version: v1.35.0
ipFamily: ipv4
profile: xds-name-scheme-v2
- version: v1.35.0
ipFamily: ipv4
profile: watch-namespaces

steps:
- uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- uses: ./tools/github-actions/setup-deps
- uses: ./tools/github-actions/reclaim-storage

Expand All @@ -229,9 +257,7 @@ jobs:
path: bin/

- name: Give Privileges To EG Binaries
run: |
chmod +x bin/linux/amd64/envoy-gateway
chmod +x bin/linux/arm64/envoy-gateway
run: chmod +x bin/linux/*/envoy-gateway

# E2E
- name: Run E2E Tests
Expand All @@ -251,6 +277,7 @@ jobs:
# set ACTIONS_STEP_DEBUG to true if context runner.debug is '1',
# which means to dump the current state when there's a case failed.
ACTIONS_STEP_DEBUG: ${{ runner.debug == '1' }}
SKIP_GO_BUILD: "true"
run: make e2e

benchmark-test:
Expand All @@ -262,9 +289,17 @@ jobs:
# So we need to check if this is a pull request and changes.
if: ${{ github.event_name == 'pull_request' && needs.changes.outputs.run_test_workflow == 'true' }}
steps:
- uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- uses: ./tools/github-actions/setup-deps

- name: Download EG Binaries
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: envoy-gateway
path: bin/

- name: Give Privileges To EG Binaries
run: chmod +x bin/linux/*/envoy-gateway

# Benchmark
- name: Run Benchmark tests
Expand All @@ -278,10 +313,11 @@ jobs:
BENCHMARK_MEMORY_LIMITS: 2000Mi
BENCHMARK_REPORT_DIR: benchmark_report
BENCHMARK_RENDER_PNG: "false"
SKIP_GO_BUILD: "true"
run: make benchmark

- name: Upload Benchmark report
uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7.0.0
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: benchmark_report
path: ./test/benchmark/benchmark_report/
Expand All @@ -293,19 +329,31 @@ jobs:
- build
- changes
steps:
- uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- uses: ./tools/github-actions/setup-deps

- name: Download EG Binaries
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: envoy-gateway
path: bin/

- name: Give Privileges To EG Binaries
run: chmod +x bin/linux/*/envoy-gateway

- name: Resilience Test
env:
IMAGE_PULL_POLICY: IfNotPresent
CUSTOM_CNI: "true"
SKIP_GO_BUILD: "true"
run: make resilience

publish:
runs-on: ubuntu-latest
needs: [conformance-test, e2e-test]
if: github.event_name == 'push' && github.ref == 'refs/heads/main'
steps:
- uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- uses: ./tools/github-actions/setup-deps

- name: Download EG Binaries
Expand All @@ -315,34 +363,27 @@ jobs:
path: bin/

- name: Give Privileges To EG Binaries
run: |
chmod +x bin/linux/amd64/envoy-gateway
chmod +x bin/linux/arm64/envoy-gateway
run: chmod +x bin/linux/*/envoy-gateway

# build and push image
- name: Login to DockerHub
if: github.event_name == 'push'
uses: docker/login-action@b45d80f862d83dbcd57f89517bcf500b2ab88fb2 # v4.0.0
uses: docker/login-action@4907a6ddec9925e35a0a9e82d7399ccc52663121 # v4.1.0
with:
username: ${{ vars.DOCKERHUB_USERNAME }}
password: ${{ secrets.DOCKERHUB_PASSWORD }}

- name: Setup Multiarch Environment
if: github.event_name == 'push'
run: make image.multiarch.setup

- name: Build and Push EG Commit Image
if: github.event_name == 'push'
# tag is set to the short SHA of the commit
run: make image.push.multiarch PLATFORMS="linux_amd64 linux_arm64" IMAGE=envoyproxy/gateway-dev

- name: Build and Push EG Latest Image
if: github.event_name == 'push' && github.ref == 'refs/heads/main'
# tag is set to `latest` when pushing to main branch
run: make image.push.multiarch TAG=latest PLATFORMS="linux_amd64 linux_arm64" IMAGE=envoyproxy/gateway-dev

- name: Build and Push EG Latest Helm Chart
if: github.event_name == 'push' && github.ref == 'refs/heads/main'
# use `0.0.0` as the default latest version.
# use `Always` image pull policy for latest version.
run: |
Expand All @@ -358,6 +399,7 @@ jobs:
- license-check
- coverage-test
- build
- build-egctl
- conformance-test
- e2e-test
- benchmark-test
Expand Down
Loading
Loading