Skip to content

Modernize: Go modules + libbeat v7.17.29, and full SDLC/CI hygiene#2

Merged
cjimti merged 3 commits into
masterfrom
modernize-deps-and-sdlc
Jun 16, 2026
Merged

Modernize: Go modules + libbeat v7.17.29, and full SDLC/CI hygiene#2
cjimti merged 3 commits into
masterfrom
modernize-deps-and-sdlc

Conversation

@cjimti

@cjimti cjimti commented Jun 16, 2026

Copy link
Copy Markdown
Member

Modernizes this repo from its glide/GOPATH + Travis era to current tooling, in two reviewable commits. The rxtx wire format and the beat's runtime behavior are preserved.

1. Dependency / Go modules migration (99133ac)

  • glide + the libbeat-generated Makefile + vendor/ → standard Go modules, Go 1.26.
  • Elastic libbeat v7.0.0-alpha → v7.17.29 (last maintained v7 line; keeps the libbeat/... import paths). Refreshed gin, prometheus client, zap.
  • The libbeat gotcha: Go modules don't apply a dependency's replace directives transitively, so libbeat's are mirrored into our go.mod (sarama, fsnotify, gopacket, goja, go-winio).
  • Wire format preserved: txn2/rxtx pinned to the exact prod revision (v1.3.2); its 2018-era transitive deps coreos/bbolt and satori/go.uuid pinned to the commits prod ran, because newer tags renamed the bbolt package / changed uuid.NewV4's signature and break rtq's source.
  • libbeat v7.17 API drift fixed: ACKCountacker.RawCounting, GenRootCmdGenRootCmdWithSettings, logp.Error → zap. Plus io/ioutilio, lost-cancel fix, nil-guarded test flag lookups.

2. SDLC / project hygiene (26ecacb) — mirrors txn2/kubefwd

  • GitHub Actions (all action refs SHA-pinned): CI (golangci-lint v2, test matrix ubuntu+macos with -race+coverage, build + goreleaser check), Release (GoReleaser v2 + Cosign + SBOM + multi-arch Docker + SLSA provenance), CodeQL, OpenSSF Scorecard, Dependabot, MkDocs→Pages.
  • make verify Makefile mirroring CI; .golangci.yml v2 with a clean baseline; scripts/validate-action-shas.sh.
  • .goreleaser.yml rewritten to v2 (static CGO_ENABLED=0, version stamped into libbeat/version); modern multi-arch Dockerfile replaces the per-arch ones.
  • SECURITY.md, CODE_OF_CONDUCT.md, CONTRIBUTING.md, CHANGELOG.md, CLAUDE.md, CODEOWNERS, issue/PR templates, codecov.yml, MkDocs docs, modernized README.
  • Retired .travis.yml, the libbeat Makefile, glide files, per-arch dockerfiles; stopped tracking the libbeat runtime data/meta.json.

Verification

  • make verify passes (go-version + tidy-check + lint 0 issues + go test -race + action-pin check).
  • go build / go vet clean; binary reports rtbeat version 7.17.29.
  • Static CGO_ENABLED=0 cross-builds for linux/darwin amd64+arm64 succeed.
  • mkdocs build --strict passes.

Reviewer notes

  • CI secrets are inherited from txn2 org-level Actions secrets — no per-repo setup needed. The workflows reference CODECOV_TOKEN, DOCKERHUB_USERNAME, DOCKERHUB_TOKEN, and HOMEBREW_TAP_TOKEN; just confirm those names match the org definitions.
  • Do not casually bump elastic/beats/v7, coreos/bbolt, or satori/go.uuid — see CLAUDE.md / CONTRIBUTING.md for why (dependabot is set to ignore the beats bump for this reason).

cjimti and others added 2 commits June 16, 2026 14:01
Replace the abandoned glide + libbeat-Makefile vendoring with a
standard Go module targeting Go 1.26 and Elastic libbeat v7.17.29
(the last maintained v7 line, keeping the libbeat/... import paths).

Dependency notes:
- Mirror elastic/beats' own replace directives into go.mod; Go modules
  do not apply a dependency's replaces transitively, so consumers of
  libbeat must copy them (Shopify/sarama, fsnotify, gopacket, etc.).
- Pin txn2/rxtx to v1.3.2 (the exact prod revision) to preserve the
  rtq.MessageBatch wire format. Pin its 2018-era transitive deps
  coreos/bbolt and satori/go.uuid to the commits prod ran, since the
  newer tags renamed the bbolt package and changed uuid.NewV4's
  signature, breaking rtq's source under modern MVS.

libbeat v7.17 API drift:
- beat.ClientConfig.ACKCount removed; use acker.RawCounting.
- cmd.GenRootCmd removed; use GenRootCmdWithSettings + instance.Settings.
- logp.Error removed; route the unmarshal error to the zap logger.

Housekeeping in the same pass:
- io/ioutil -> io, fix the lost context cancel in shutdown.
- Guard main_test.go flag lookups against nil (test flags register
  lazily on modern Go, which panicked at init()).

Build, vet, and tests pass; binary reports libbeat 7.17.29.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Bring rtbeat in line with the txn2/kubefwd and mcp-data-platform
conventions, replacing the abandoned beats/Travis tooling.

CI/CD (GitHub Actions, all action refs SHA-pinned):
- ci.yml: lint (golangci-lint v2.12.1), test matrix (ubuntu+macos,
  -race + coverage to Codecov), build + goreleaser check.
- release.yml: GoReleaser v2 on tag push — Cosign keyless signing,
  SBOMs, multi-arch Docker, SLSA provenance.
- codeql.yml, scorecard.yml, docs.yml (MkDocs to GitHub Pages),
  dependabot.yml.

Tooling/config:
- .golangci.yml (v2) with a clean lint baseline; fixed the findings in
  beater/rtbeat.go (errcheck, gocritic, ineffassign, revive, staticcheck).
- Makefile: `make verify` mirrors CI (go-version + tidy-check + lint +
  test + validate-actions); auto-installs the pinned linter to .tools/.
- scripts/validate-action-shas.sh enforces SHA-pinned actions.
- .goreleaser.yml rewritten to v2 (static CGO-free builds, version
  stamped into libbeat/version); modern multi-arch Dockerfile replaces
  the per-arch dockerfiles/.
- codecov.yml, .gitignore updates; stop tracking the libbeat runtime
  data/meta.json.

Docs & community:
- SECURITY.md, CODE_OF_CONDUCT.md, CONTRIBUTING.md, CHANGELOG.md,
  CLAUDE.md, CODEOWNERS, issue/PR templates.
- MkDocs site (mkdocs.yml + docs/) and a modernized README.

Retired: .travis.yml, the libbeat-generated Makefile, glide-era and
per-arch Docker tooling.

make verify passes; mkdocs build --strict passes.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

Two fixes surfaced by an adversarial review of the modernization:

- go.mod: mirror the full 15-directive replace block from
  elastic/beats/v7@v7.17.29 (previously only 7). We import few libbeat
  packages today, but keeping the complete upstream set means a future
  dependency bump that pulls in more of beats won't break against a
  fork-expecting package (e.g. docker/docker => docker/engine).
- .goreleaser.yml: document that `brews:` is valid on the CI-pinned
  goreleaser line (~> v2.13) but deprecated as of v2.16, so the key must
  be migrated before bumping the goreleaser-action pin.

make verify passes; binary still reports libbeat 7.17.29.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@cjimti
cjimti merged commit eaeb111 into master Jun 16, 2026
9 checks passed
@cjimti
cjimti deleted the modernize-deps-and-sdlc branch June 16, 2026 22:24
cjimti added a commit that referenced this pull request Jun 16, 2026
* Migrate from glide/GOPATH vendoring to Go modules

Replace the abandoned glide + libbeat-Makefile vendoring with a
standard Go module targeting Go 1.26 and Elastic libbeat v7.17.29
(the last maintained v7 line, keeping the libbeat/... import paths).

Dependency notes:
- Mirror elastic/beats' own replace directives into go.mod; Go modules
  do not apply a dependency's replaces transitively, so consumers of
  libbeat must copy them (Shopify/sarama, fsnotify, gopacket, etc.).
- Pin txn2/rxtx to v1.3.2 (the exact prod revision) to preserve the
  rtq.MessageBatch wire format. Pin its 2018-era transitive deps
  coreos/bbolt and satori/go.uuid to the commits prod ran, since the
  newer tags renamed the bbolt package and changed uuid.NewV4's
  signature, breaking rtq's source under modern MVS.

libbeat v7.17 API drift:
- beat.ClientConfig.ACKCount removed; use acker.RawCounting.
- cmd.GenRootCmd removed; use GenRootCmdWithSettings + instance.Settings.
- logp.Error removed; route the unmarshal error to the zap logger.

Housekeeping in the same pass:
- io/ioutil -> io, fix the lost context cancel in shutdown.
- Guard main_test.go flag lookups against nil (test flags register
  lazily on modern Go, which panicked at init()).

Build, vet, and tests pass; binary reports libbeat 7.17.29.

* Add modern SDLC and project hygiene

Bring rtbeat in line with the txn2/kubefwd and mcp-data-platform
conventions, replacing the abandoned beats/Travis tooling.

CI/CD (GitHub Actions, all action refs SHA-pinned):
- ci.yml: lint (golangci-lint v2.12.1), test matrix (ubuntu+macos,
  -race + coverage to Codecov), build + goreleaser check.
- release.yml: GoReleaser v2 on tag push — Cosign keyless signing,
  SBOMs, multi-arch Docker, SLSA provenance.
- codeql.yml, scorecard.yml, docs.yml (MkDocs to GitHub Pages),
  dependabot.yml.

Tooling/config:
- .golangci.yml (v2) with a clean lint baseline; fixed the findings in
  beater/rtbeat.go (errcheck, gocritic, ineffassign, revive, staticcheck).
- Makefile: `make verify` mirrors CI (go-version + tidy-check + lint +
  test + validate-actions); auto-installs the pinned linter to .tools/.
- scripts/validate-action-shas.sh enforces SHA-pinned actions.
- .goreleaser.yml rewritten to v2 (static CGO-free builds, version
  stamped into libbeat/version); modern multi-arch Dockerfile replaces
  the per-arch dockerfiles/.
- codecov.yml, .gitignore updates; stop tracking the libbeat runtime
  data/meta.json.

Docs & community:
- SECURITY.md, CODE_OF_CONDUCT.md, CONTRIBUTING.md, CHANGELOG.md,
  CLAUDE.md, CODEOWNERS, issue/PR templates.
- MkDocs site (mkdocs.yml + docs/) and a modernized README.

Retired: .travis.yml, the libbeat-generated Makefile, glide-era and
per-arch Docker tooling.

make verify passes; mkdocs build --strict passes.

* Harden deps from adversarial review

Two fixes surfaced by an adversarial review of the modernization:

- go.mod: mirror the full 15-directive replace block from
  elastic/beats/v7@v7.17.29 (previously only 7). We import few libbeat
  packages today, but keeping the complete upstream set means a future
  dependency bump that pulls in more of beats won't break against a
  fork-expecting package (e.g. docker/docker => docker/engine).
- .goreleaser.yml: document that `brews:` is valid on the CI-pinned
  goreleaser line (~> v2.13) but deprecated as of v2.16, so the key must
  be migrated before bumping the goreleaser-action pin.

make verify passes; binary still reports libbeat 7.17.29.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants