Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
84 commits
Select commit Hold shift + click to select a range
0d4691b
chore(release): prepare v2 maintenance on branch 2
alexey-igrychev Sep 24, 2026
1db6225
test(docs): include source links in documentation checks
alexey-igrychev Sep 24, 2026
6e73257
fix(release): relabel only merged releases of the current branch
alexey-igrychev Sep 24, 2026
ab86be8
chore(release): merge main into 2
alexey-igrychev Sep 24, 2026
a60c257
chore(release): prepare v2 maintenance on branch 2 (#7912)
alexey-igrychev Sep 24, 2026
521f6a1
chore(release): merge main into 2 (#7917)
alexey-igrychev Sep 24, 2026
2913ffe
chore(2): release 2.79.2
flant-team-sysdev Sep 24, 2026
d0a519c
chore(2): release 2.79.2 (#7916)
alexey-igrychev Sep 25, 2026
51c0d31
feat(build): collect operations statistics for the whole command run …
Fral738 Sep 25, 2026
ace2677
chore(2): release 2.80.0 (#7927)
flant-team-sysdev Sep 28, 2026
9c1345c
docs(skills): warn that a probe must reproduce production wiring (#7936)
alexey-igrychev Sep 28, 2026
6cbed57
chore(dev): remove release-specific migration history (#7939)
alexey-igrychev Sep 28, 2026
f591663
fix(build): use versioned base images in documentation examples (#7942)
alexey-igrychev Sep 28, 2026
48fbd9e
fix(build): keep provenance disabled in parallel Dockerfile builds (#…
alexey-igrychev Sep 28, 2026
97367c9
fix(build): reject invalid imports with a scratch base (#7944)
alexey-igrychev Sep 28, 2026
8412d4e
fix(build): rebuild images after renaming git-tracked files (#7940)
alexey-igrychev Sep 28, 2026
6ba82d0
fix(build): keep deploy keys separate across SSH aliases (#7945)
alexey-igrychev Sep 28, 2026
8a9d42c
fix(build): use a tagged Go image in the documentation example (#7946)
alexey-igrychev Sep 28, 2026
2b46672
fix(build): rebuild images when git mappings swap content (#7947)
alexey-igrychev Sep 28, 2026
f42ae0d
chore(ci): run CI tooling on werf 3 dev (#7950)
alexey-igrychev Sep 28, 2026
154df22
chore(ci): skip cleanup for the disabled ACR test registry (#7954)
alexey-igrychev Sep 29, 2026
e42b929
chore(ci): support werf 3 in v2 documentation builds (#7948)
alexey-igrychev Sep 28, 2026
08dd45b
fix(build): reduce repeated registry token requests (#7955)
Ivelok Sep 29, 2026
f2eab7e
fix(build): reuse unchanged Dockerfile contexts without extra copies …
alexey-igrychev Sep 29, 2026
a1292d1
test(build): strengthen bearer cache regression checks (#7957)
alexey-igrychev Sep 29, 2026
81587cf
fix(deploy): preserve resources with live retention policies (#7958)
alexey-igrychev Sep 29, 2026
e19f8b1
fix(build): export cached images with local and final repositories (#…
alexey-igrychev Sep 29, 2026
189ff24
fix(cleanup): keep dry-run metadata unchanged (#7960)
alexey-igrychev Sep 29, 2026
d4cc45f
fix(deploy): keep release output machine-readable by default (#7961)
alexey-igrychev Sep 29, 2026
d3aa339
docs(deploy): correct v3 installation and migration guidance (#7962)
alexey-igrychev Sep 29, 2026
0226f5d
chore(2): release 2.80.1 (#7956)
flant-team-sysdev Sep 29, 2026
c9d7d50
chore(release): 2 all
alexey-igrychev Sep 29, 2026
cd6fcf1
chore(release): merge branch 2 into main
alexey-igrychev Sep 29, 2026
9aa85c1
chore(release): integrate current main into branch 2 upmerge
alexey-igrychev Sep 29, 2026
d89124a
chore(release): record latest branch 2 release ancestry
alexey-igrychev Sep 29, 2026
a84a30b
fix(build): refresh rejected tokens after registry redirects
alexey-igrychev Sep 29, 2026
d8e43ee
chore(release): merge branch 2 into main (#7963)
alexey-igrychev Sep 29, 2026
870a276
fix(build): export final-repository images from build reports
alexey-igrychev Sep 29, 2026
4a27ec0
fix(git): preserve warm caches on cancellation
alexey-igrychev Sep 29, 2026
1191bf1
fix(build): honor introspection on content-cache hits
alexey-igrychev Sep 29, 2026
2377615
fix(storage): remember stage tags after publishing
alexey-igrychev Sep 29, 2026
885fb23
test(build): initialize inspection config across platforms
alexey-igrychev Sep 29, 2026
666afe1
fix(cleanup): purge platform Stapel containers with their volumes
alexey-igrychev Sep 29, 2026
7aa2265
fix(build): export final-repository images from build reports (#7964)
alexey-igrychev Sep 30, 2026
d7da627
fix(build): honor introspection on content-cache hits (#7967)
alexey-igrychev Sep 30, 2026
ec099be
fix(storage): remember stage tags after publishing (#7965)
alexey-igrychev Sep 30, 2026
9d2ef8c
fix(git): preserve warm caches on cancellation (#7966)
alexey-igrychev Sep 30, 2026
83cab69
fix(cleanup): purge platform Stapel containers with their volumes (#7…
alexey-igrychev Sep 30, 2026
fdbffff
docs(deploy): use v3 installation for GitHub cleanup
alexey-igrychev Sep 29, 2026
129a0ec
docs(release): use v3 stable throughout current documentation
alexey-igrychev Sep 30, 2026
a98887e
docs(release): use v3 stable throughout current documentation (#7968)
alexey-igrychev Sep 30, 2026
b9ca56d
fix(build): respect remote Docker contexts and SSH hosts
alexey-igrychev Sep 30, 2026
4df8c09
fix(build): respect remote Docker contexts and SSH hosts (#7971)
alexey-igrychev Sep 30, 2026
f447c2c
fix(deploy): honor OCI credentials in chart-only converge
alexey-igrychev Sep 30, 2026
52c9706
fix(deploy): honor OCI credentials in chart-only converge (#7974)
alexey-igrychev Sep 30, 2026
152ee34
fix(build): honor git mapping ownership with Docker (#7972)
alexey-igrychev Sep 30, 2026
31e31e3
fix(cleanup): preserve concurrently published final images (#7975)
alexey-igrychev Sep 30, 2026
fbb7e62
fix(build): require Docker 19.03+ for Docker backend operations (#7973)
alexey-igrychev Sep 30, 2026
262d2eb
docs(deploy): cover nelm v2 deploy changes in the migration guide (#7…
dmmordvi Sep 30, 2026
082baeb
fix(build, docker): stop container backend init hanging on a mute soc…
alexey-igrychev Sep 30, 2026
ae5a5be
fix(build, stapel): set owner/group on dirs added by incremental buil…
alexey-igrychev Sep 30, 2026
ee4f4ae
fix(build): rebuild a rejected stage instead of exhausting retries (#…
alexey-igrychev Sep 30, 2026
6104d14
fix(host-cleanup): purge every stapel container and volume werf owns …
alexey-igrychev Sep 30, 2026
ac62101
fix(build, dockerfile): stop copying the build context per image (#7980)
alexey-igrychev Sep 30, 2026
a2efb5f
fix(build): export multi-platform images from the final repository (#…
alexey-igrychev Sep 30, 2026
851e641
fix(build): report when ssh connection multiplexing cannot be enabled…
alexey-igrychev Sep 30, 2026
f81d0e7
chore(ci): comment out acr in the registry cleanup matrix (#7982)
alexey-igrychev Sep 30, 2026
a10017a
fix(build): reduce repetitive service output (#7985)
alexey-igrychev Sep 30, 2026
0f38e5b
docs(deploy): correct Helm config migration paths (#7986)
alexey-igrychev Sep 30, 2026
2c8339c
fix(build): keep registry requests out of stage counts (#7987)
alexey-igrychev Sep 30, 2026
1eadf7c
fix(build, docker): keep chart-only commands independent of Docker (#…
alexey-igrychev Oct 1, 2026
4e27b5f
fix(build): release temporary containers after staged COPY (#7938)
Fral738 Oct 1, 2026
29abab1
fix(build): report invalid .dockerignore patterns without panicking (…
alexey-igrychev Oct 1, 2026
a0128c4
fix(deploy): recreate StatefulSet and other custom-validated kinds on…
dmmordvi Oct 1, 2026
bfaad77
fix(build): prevent duplicate images from concurrent builders (#7989)
alexey-igrychev Oct 1, 2026
9151158
chore(main): release 3.6.2 (#7943)
flant-team-sysdev Oct 1, 2026
0ba8703
chore(release): 2 alpha,beta, 3 dev
alexey-igrychev Oct 1, 2026
8b4011a
chore(release): merge werf upstream into delivery-kit
alexey-igrychev Oct 1, 2026
be6deca
chore: force release 3.6.2-dk.1
alexey-igrychev Oct 1, 2026
b533f90
docs(dev): regenerate after werf upstream merge
alexey-igrychev Oct 1, 2026
cfb2553
test(build, dockerfile): recompute context checksum digests after ups…
alexey-igrychev Oct 1, 2026
a1cafa8
test(build): cover SBOM synchronization flags
alexey-igrychev Oct 1, 2026
662de1b
test(build, cleaning, config, docker): adapt tests after upstream merge
alexey-igrychev Oct 1, 2026
7a9a7f5
fix(sbom): collect statistics across the whole get command
alexey-igrychev Oct 1, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions .agents/skills/test-the-tests/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -52,6 +52,12 @@ seen fail.
of externally observable behavior.
- **Coverage number, not falsifiability.** A line being executed says nothing about whether
a wrong value on that line would be caught.
- **It proves the lab, not production wiring.** A probe on a bare context "proved" that
cancellation panics past a branch — but production wraps commands in
`graceful.WithTermination`, where `Terminate` returns normally and the branch executes.
Before concluding "X cannot reach this code", rebuild the exact wiring production uses
(context construction, env, entry point); a conclusion drawn from simplified wiring
describes the probe, not the system.
- **An extended test quietly drops what the old one proved.** Adding cases to a fixture can
remove the conflict that made an earlier property observable. After editing an existing
test, re-run the mutations the previous version caught, not only the new ones.
Expand Down
7 changes: 6 additions & 1 deletion .github/workflows/docs_cleanup_pr.yml
Original file line number Diff line number Diff line change
Expand Up @@ -28,7 +28,12 @@ jobs:
ref: ${{ github.event_name == 'workflow_dispatch' && github.ref || github.event.pull_request.base.ref }}

- name: Install werf
uses: werf/actions/install@v2
uses: werf/trdl/actions/setup-app@v0.13.0
with:
preset: werf
group: "3"
channel: dev
force: false

- name: Dismiss preview
run: |
Expand Down
36 changes: 28 additions & 8 deletions .github/workflows/docs_deploy_test_versions.yml
Original file line number Diff line number Diff line change
Expand Up @@ -34,12 +34,17 @@ jobs:
ref: main

- name: Install werf
uses: werf/actions/install@v2
uses: werf/trdl/actions/setup-app@v0.13.0
with:
preset: werf
group: "3"
channel: dev
force: false

- name: Deploy v3 docs to test
run: |
. $(werf ci-env github --as-file)
werf converge --virtual-merge=false
werf converge
env:
WERF_NAMESPACE: werfio-test
WERF_DIR: docs
Expand All @@ -64,12 +69,17 @@ jobs:
ref: "2"

- name: Install werf
uses: werf/actions/install@v2
uses: werf/trdl/actions/setup-app@v0.13.0
with:
preset: werf
group: "3"
channel: dev
force: false

- name: Deploy v2 docs to test
run: |
. $(werf ci-env github --as-file)
werf converge --virtual-merge=false
werf converge
env:
WERF_NAMESPACE: werfio-test
WERF_DIR: docs
Expand All @@ -94,12 +104,17 @@ jobs:
ref: "1.2"

- name: Install werf
uses: werf/actions/install@v2
uses: werf/trdl/actions/setup-app@v0.13.0
with:
preset: werf
group: "3"
channel: dev
force: false

- name: Deploy v1.2 docs to test
run: |
. $(werf ci-env github --as-file)
werf converge --virtual-merge=false
werf converge
env:
WERF_NAMESPACE: werfio-test
WERF_DIR: docs
Expand All @@ -124,12 +139,17 @@ jobs:
ref: main

- name: Install werf
uses: werf/actions/install@v2
uses: werf/trdl/actions/setup-app@v0.13.0
with:
preset: werf
group: "3"
channel: dev
force: false

- name: Deploy latest docs to test
run: |
. $(werf ci-env github --as-file)
werf converge --virtual-merge=false
werf converge
env:
WERF_NAMESPACE: werfio-test
WERF_DIR: docs
Expand Down
2 changes: 1 addition & 1 deletion CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ For small changes, such as few lines bugfixes or documentation improvements, fee

For easy first issues, check the [good first issue](https://github.com/werf/werf/issues?q=is%3Aissue%20state%3Aopen%20label%3A%22good%20first%20issue%22) tag.

You can also check the existing [issues](https://github.com/werf/werf/issues), [discussion threads](https://github.com/werf/werf/discussions), and [documentation](https://werf.io/docs/v2/) — there may already be a discussion or solution on your topic. If not, choose the appropriate way to address the issue on [the new issue form](https://github.com/werf/werf/issues/new/choose).
You can also check the existing [issues](https://github.com/werf/werf/issues), [discussion threads](https://github.com/werf/werf/discussions), and [documentation](https://werf.io/docs/v3/) — there may already be a discussion or solution on your topic. If not, choose the appropriate way to address the issue on [the new issue form](https://github.com/werf/werf/issues/new/choose).

## Contributing code

Expand Down
11 changes: 10 additions & 1 deletion cmd/werf/build/main.go
Original file line number Diff line number Diff line change
Expand Up @@ -94,6 +94,11 @@ func NewCmd(ctx context.Context) *cobra.Command {
common.SetupLogOptions(&commonCmdData, cmd)
common.SetupLogProjectDir(&commonCmdData, cmd)

common.SetupSynchronization(&commonCmdData, cmd)
common.SetupKubeConfigBase64(&commonCmdData, cmd)
common.SetupLegacyKubeConfigPath(&commonCmdData, cmd)
common.SetupKubeContextCurrent(&commonCmdData, cmd)

common.SetupSaveBuildReport(&commonCmdData, cmd)
common.SetupBuildReportPath(&commonCmdData, cmd)
common.SetupBuildReportOperations(&commonCmdData, cmd)
Expand Down Expand Up @@ -124,6 +129,9 @@ func NewCmd(ctx context.Context) *cobra.Command {
}

func runMain(ctx context.Context, imageNameListFromArgs []string) error {
ctx, logOperationsSummaryFn := common.InitOperationsStatistics(ctx, &commonCmdData)
defer logOperationsSummaryFn()

commonManager, ctx, err := common.InitCommonComponents(ctx, common.InitCommonComponentsOptions{
Cmd: &commonCmdData,
InitWerf: true,
Expand All @@ -135,6 +143,7 @@ func runMain(ctx context.Context, imageNameListFromArgs []string) error {
},
InitDockerRegistry: true,
InitProcessContainerBackend: true,
RequireDockerDaemon: true,
InitSSHAgent: true,
})
if err != nil {
Expand Down Expand Up @@ -217,7 +226,7 @@ func run(ctx context.Context, containerBackend container_backend.ContainerBacken

logboek.LogOptionalLn()

conveyorWithRetry := build.NewConveyorWithRetryWrapper(werfConfig, giterminismManager, giterminismManager.ProjectDir(), projectTmpDir, containerBackend, storageManager, conveyorOptions)
conveyorWithRetry := build.NewConveyorWithRetryWrapper(werfConfig, giterminismManager, giterminismManager.ProjectDir(), projectTmpDir, containerBackend, storageManager, storageManager.StorageLockManager, conveyorOptions)
defer conveyorWithRetry.Terminate()

if err := conveyorWithRetry.WithRetryBlock(ctx, func(c *build.Conveyor) error {
Expand Down
64 changes: 39 additions & 25 deletions cmd/werf/bundle/publish/publish.go
Original file line number Diff line number Diff line change
Expand Up @@ -33,6 +33,7 @@ import (
"github.com/werf/werf/v3/cmd/werf/common"
"github.com/werf/werf/v3/pkg/build"
"github.com/werf/werf/v3/pkg/config"
"github.com/werf/werf/v3/pkg/container_backend"
"github.com/werf/werf/v3/pkg/deploy"
"github.com/werf/werf/v3/pkg/deploy/bundles"
"github.com/werf/werf/v3/pkg/image"
Expand Down Expand Up @@ -109,6 +110,10 @@ func NewCmd(ctx context.Context) *cobra.Command {
common.SetupLogOptions(&commonCmdData, cmd)
common.SetupLogProjectDir(&commonCmdData, cmd)

common.SetupSynchronization(&commonCmdData, cmd)
common.SetupKubeConfigBase64(&commonCmdData, cmd)
common.SetupLegacyKubeConfigPath(&commonCmdData, cmd)
common.SetupKubeContextCurrent(&commonCmdData, cmd)
common.SetupDenoBinaryPath(&commonCmdData, cmd)

common.SetupSaveBuildReport(&commonCmdData, cmd)
Expand Down Expand Up @@ -160,31 +165,32 @@ func NewCmd(ctx context.Context) *cobra.Command {
}

func runPublish(ctx context.Context, imageNameListFromArgs []string) error {
ctx, logOperationsSummaryFn := common.InitOperationsStatistics(ctx, &commonCmdData)
defer logOperationsSummaryFn()
commonManager, ctx, err := common.InitCommonComponents(ctx, common.InitCommonComponentsOptions{
Cmd: &commonCmdData,
InitTrueGitWithOptions: &common.InitTrueGitOptions{
Options: true_git.Options{LiveGitOutput: *commonCmdData.LogDebug},
},
InitDockerRegistry: true,
InitProcessContainerBackend: true,
InitWerf: true,
InitGitDataManager: true,
InitManifestCache: true,
InitLRUImagesCache: true,
InitSSHAgent: true,
InitDockerRegistry: true,
InitWerf: true,
InitGitDataManager: true,
InitManifestCache: true,
InitLRUImagesCache: true,
InitSSHAgent: true,
})
if err != nil {
return fmt.Errorf("component init error: %w", err)
}

containerBackend := commonManager.ContainerBackend()

defer func() {
if err := tmp_manager.DelegateCleanup(ctx); err != nil {
logboek.Context(ctx).Warn().LogF("Temporary files cleanup preparation failed: %s\n", err)
}
if err := common.RunAutoHostCleanup(ctx, &commonCmdData, containerBackend); err != nil {
logboek.Context(ctx).Error().LogF("Auto host cleanup failed: %s\n", err)
if containerBackend, ok := commonManager.TryContainerBackend(); ok {
if err := common.RunAutoHostCleanup(ctx, &commonCmdData, containerBackend); err != nil {
logboek.Context(ctx).Error().LogF("Auto host cleanup failed: %s\n", err)
}
}
}()

Expand All @@ -209,6 +215,16 @@ func runPublish(ctx context.Context, imageNameListFromArgs []string) error {
return err
}

var containerBackend container_backend.ContainerBackend
if !imagesToProcess.WithoutImages {
var newCtx context.Context
containerBackend, newCtx, err = commonManager.EnsureContainerBackend(ctx, &commonCmdData, common.EnsureContainerBackendOptions{InitDockerRegistry: true, RequireDockerDaemon: true})
if err != nil {
return fmt.Errorf("container backend initialization error: %w", err)
}
ctx = newCtx
}

projectName := werfConfig.Meta.Project

projectTmpDir, err := tmp_manager.CreateProjectDir(ctx)
Expand All @@ -223,17 +239,22 @@ func runPublish(ctx context.Context, imageNameListFromArgs []string) error {

logboek.LogOptionalLn()

stagesStorage, err := common.GetStagesStorage(ctx, containerBackend, &commonCmdData, common.GetStagesStorageOpts{
CleanupDisabled: werfConfig.Meta.Cleanup.DisableCleanup,
GitHistoryBasedCleanupDisabled: werfConfig.Meta.Cleanup.DisableGitHistoryBasedPolicy,
})
bundleRepo, err := commonCmdData.Repo.GetAddress()
if err != nil {
return err
}
finalStagesStorage, err := common.GetOptionalFinalStagesStorage(ctx, containerBackend, &commonCmdData)
if err != nil {
if err := common.ValidateRepoContainerRegistry(commonCmdData.Repo.GetContainerRegistry(ctx)); err != nil {
return err
}
if *commonCmdData.FinalRepo.Address != "" {
if err := common.ValidateRepoContainerRegistry(commonCmdData.FinalRepo.GetContainerRegistry(ctx)); err != nil {
return err
}
bundleRepo, err = commonCmdData.FinalRepo.GetAddress()
if err != nil {
return err
}
}

var imagesInfoGetters []*image.InfoGetter
var imagesRepo string
Expand Down Expand Up @@ -263,7 +284,7 @@ func runPublish(ctx context.Context, imageNameListFromArgs []string) error {
return err
}

conveyorWithRetry := build.NewConveyorWithRetryWrapper(werfConfig, giterminismManager, giterminismManager.ProjectDir(), projectTmpDir, containerBackend, storageManager, conveyorOptions)
conveyorWithRetry := build.NewConveyorWithRetryWrapper(werfConfig, giterminismManager, giterminismManager.ProjectDir(), projectTmpDir, containerBackend, storageManager, storageManager.StorageLockManager, conveyorOptions)
defer conveyorWithRetry.Terminate()

if err := conveyorWithRetry.WithRetryBlock(ctx, func(c *build.Conveyor) error {
Expand Down Expand Up @@ -429,13 +450,6 @@ func runPublish(ctx context.Context, imageNameListFromArgs []string) error {
return fmt.Errorf("create bundle: %w", err)
}

var bundleRepo string
if finalStagesStorage != nil {
bundleRepo = finalStagesStorage.Address()
} else {
bundleRepo = stagesStorage.Address()
}

opts.ChartLoadOpts.ChartType = nelmcommon.LegacyChartTypeBundle

return bundles.Publish(ctx, bundleTmpDir, fmt.Sprintf("%s:%s", bundleRepo, cmdData.Tag), bundlesRegistryClient, bundles.PublishOptions{
Expand Down
9 changes: 2 additions & 7 deletions cmd/werf/cleanup/cleanup.go
Original file line number Diff line number Diff line change
Expand Up @@ -90,6 +90,7 @@ func NewCmd(ctx context.Context) *cobra.Command {
common.SetupLogOptions(&commonCmdData, cmd)
common.SetupLogProjectDir(&commonCmdData, cmd)

common.SetupSynchronization(&commonCmdData, cmd)
common.SetupWithoutKube(&commonCmdData, cmd)
common.SetupKeepStagesBuiltWithinLastNHours(&commonCmdData, cmd)

Expand Down Expand Up @@ -210,12 +211,6 @@ func runCleanup(ctx context.Context, cmd *cobra.Command) error {
storageManager.EnableParallel(int(common.GetParallelTasksLimit(&commonCmdData)))
}

imagesNames, err := common.GetManagedImagesNames(ctx, projectName, storageManager.GetMetaStorage(), werfConfig)
if err != nil {
return err
}
logboek.Debug().LogF("Managed images names: %v\n", imagesNames)

var kubernetesContextClients []*cleaning.ContextClient
var kubernetesNamespacesByContext map[string][]string
if !(*commonCmdData.WithoutKube || werfConfig.Meta.Cleanup.DisableKubernetesBasedPolicy) {
Expand Down Expand Up @@ -251,7 +246,7 @@ func runCleanup(ctx context.Context, cmd *cobra.Command) error {
}

cleanupOptions := cleaning.CleanupOptions{
ImageNameList: imagesNames,
ImageNameList: werfConfig.GetImageNameList(false),
LocalGit: giterminismManager.LocalGitRepo().(*git_repo.Local),
KubernetesContextClients: kubernetesContextClients,
KubernetesNamespacesByContext: kubernetesNamespacesByContext,
Expand Down
Loading
Loading