Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
50 commits
Select commit Hold shift + click to select a range
6007156
chore: Upgrade go to 1.25.3 (#104)
wandb-kc Nov 20, 2025
e70f07f
chore: Upgrade helm to 3.19.2 (#105)
wandb-kc Nov 25, 2025
aa4ca21
fix: Upgrade helm to 3.19.2 (#106)
wandb-kc Dec 4, 2025
62ad6a4
chore(release): version 1.21.3 [skip ci]
semantic-release-bot Dec 4, 2025
802d886
chore: Need to create the workflow in main so it can be updated and r…
danielpanzella Feb 10, 2026
b272e14
chore: Add empty workflow so it can be run in a branch (#131)
danielpanzella Feb 11, 2026
f3abfed
remove aquasecurity (#142)
wandb-kc Mar 23, 2026
fcb72b8
feat: Add OCI Helm chart registry support and upgrade to Helm v4 (#147)
zacharyblasczyk Apr 30, 2026
899dd45
chore(release): version 1.22.0 [skip ci]
semantic-release-bot Apr 30, 2026
9754b3a
chore(security): move GitHub Actions updates to Renovate (#222)
shivawandb Jun 26, 2026
ff42719
chore(deps): pin dependencies (#226)
wandb-renovate[bot] Jun 29, 2026
726dfe6
Add standard labels to all pods, documentation
wnevis-cmyk Jul 8, 2026
e3c168e
Add docs, tests for labels
wnevis-cmyk Jul 8, 2026
f19b8e1
chore: Update CODEOWNERS to on-prem-team (#210)
jthakkar04 Jul 14, 2026
b02613e
feat: Prep main for v2 merge (#251)
casey-coreweave Jul 15, 2026
63bc726
feat: Promote Operator v2 to main (#261)
casey-coreweave Jul 15, 2026
681b7d7
feat: Creating a Beta Release (#262)
jthakkar04 Jul 15, 2026
b08c69c
fix: loosen release naming to allow subversions with semver (#266)
casey-coreweave Jul 15, 2026
75970ae
fix: Checkout tags in release pipelines (#267)
casey-coreweave Jul 15, 2026
5d439bd
fix: force tag checkouts in release pipeline (#269)
casey-coreweave Jul 15, 2026
9ed575a
fix: force tag checkout in release (#270)
casey-coreweave Jul 15, 2026
63c869a
fix: fixup chart dependencies
casey-coreweave Jul 15, 2026
79b1ae7
fix: update helm deps explicitly in release
casey-coreweave Jul 15, 2026
c60e3ac
fix: add chart-testing to release flow
casey-coreweave Jul 15, 2026
7da7c58
fix: check for existing artifacts in release flows
casey-coreweave Jul 15, 2026
6ba64d1
chore(deps): bump github.com/onsi/gomega from 1.39.1 to 1.42.1 (#254)
dependabot[bot] Jul 21, 2026
e0f10c3
chore(deps): bump github.com/maxbrunsfeld/counterfeiter/v6 from 6.11.…
dependabot[bot] Jul 21, 2026
be936fb
chore(deps): bump github.com/expr-lang/expr from 1.17.6 to 1.17.7 (#263)
dependabot[bot] Jul 21, 2026
6954485
chore(deps): bump github.com/containerd/containerd from 1.7.29 to 1.7…
dependabot[bot] Jul 21, 2026
b52159e
chore(deps): bump github.com/go-playground/validator/v10 from 10.28.0…
dependabot[bot] Jul 21, 2026
7759a8b
chore(deps): bump oras.land/oras-go/v2 from 2.6.0 to 2.6.2 (#257)
dependabot[bot] Jul 21, 2026
28f681a
chore(deps): bump go.opentelemetry.io/otel/exporters/otlp/otlptrace/o…
dependabot[bot] Jul 21, 2026
295e17a
feat(seaweed): Upgrade seaweed chart version, set readiness probe (#273)
casey-coreweave Jul 21, 2026
8f77f6d
fix: Emit FQDN for manifest service-source URLs (#283)
danielpanzella Jul 22, 2026
715b40a
feat: First class support for http proxy configs (#284)
danielpanzella Jul 22, 2026
0d0bd62
feat(backend): Add validator for hostname spec (#277)
wnevis-cmyk Jul 22, 2026
dc61599
fix(telemetry): Point Kafka dashboard panels at Bufstream metrics (#286)
jthakkar04 Jul 23, 2026
e19c7ae
fix: Resolve lint and image scan failures (#297)
casey-coreweave Jul 23, 2026
6f68c8b
fix: Support workload identity for managed storage clients (#293)
casey-coreweave Jul 27, 2026
6f8f6a4
fix: Report complete W&B readiness and migration status (#294)
casey-coreweave Jul 27, 2026
f88c6dd
fix: Reject incomplete external Redis connections (#292)
casey-coreweave Jul 27, 2026
2a5f0a3
feat(backend): Consolidate object storage connections (#272)
wnevis-cmyk Jul 27, 2026
fdd29ba
fix: Map external ClickHouse during v1->v2 conversion (#299)
wnevis-cmyk Jul 27, 2026
00700c9
fix: Parse Bucket Endpoint (#301)
jthakkar04 Jul 28, 2026
c1106d2
feat: Support custom CA's in operator v2 (#303)
danielpanzella Jul 28, 2026
81a4590
feat(operator): Create beta 3 release (#306)
casey-coreweave Jul 28, 2026
860356c
chore: Updating WandB Version (#307)
jthakkar04 Jul 29, 2026
2ddcad0
fix: Allowing a Release with duplication (#308)
jthakkar04 Jul 29, 2026
db6e8d9
fix: Update-images (#310)
collinol Aug 3, 2026
891d078
Merge conflict
wnevis-cmyk Aug 5, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/CODEOWNERS
Original file line number Diff line number Diff line change
@@ -1 +1 @@
* @wandb/delivery-tooling-team
* @wandb/on-prem-team
6 changes: 0 additions & 6 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -14,9 +14,3 @@ updates:
reviewers:
- wandb/delivery-tooling-team

- package-ecosystem: github-actions
directory: /.github/workflows
schedule:
interval: daily
reviewers:
- wandb/delivery-tooling-team
4 changes: 4 additions & 0 deletions .github/renovate.json5
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
{
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
"extends": ["github>wandb/renovate-config"]
}
71 changes: 71 additions & 0 deletions .github/workflows/chart-validation.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,71 @@
name: Chart Validation

on:
push:
branches: [v2, main]
pull_request:
branches: [v2, main]

jobs:
chart-validation:
name: Chart Validation
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4

- name: Install Helm
uses: azure/setup-helm@bf6a7d304bc2fdb57e0331155b7ebf2c504acf0a # v4
with:
version: v3.19.0

- name: Install chart-testing
uses: helm/chart-testing-action@e6669bcd63d7cb57cb4380c33043eebe5d111992 # v2.6.1
with:
version: v3.14.0

- name: Resolve chart dependencies
run: |
helm repo add ci-wandb https://charts.wandb.ai/
helm repo add ci-moco https://cybozu-go.github.io/moco/
helm repo add ci-ot-container-kit https://ot-container-kit.github.io/helm-charts
helm repo add ci-seaweedfs https://seaweedfs.github.io/seaweedfs-operator/
helm repo add ci-prometheus-community https://prometheus-community.github.io/helm-charts
helm repo add ci-altinity https://helm.altinity.com
helm repo add ci-victoria-metrics https://victoriametrics.github.io/helm-charts/
helm repo add ci-grafana https://grafana.github.io/helm-charts
helm dependency build deploy/operator
git diff --exit-code deploy/operator/Chart.lock

- name: Run chart-testing
run: ct lint --all --config deploy/ct.yaml

- name: Validate values schema
run: |
set -euo pipefail
helm lint --strict deploy/operator
for profile in deploy/operator/profiles/*.yaml; do
extra_args=()
if [[ "${profile}" == *telemetry-forward.yaml ]]; then
extra_args+=(--set-string telemetry.forwarding.otlp.endpoint=https://example.invalid:4317)
fi
helm lint --strict deploy/operator --values "${profile}" "${extra_args[@]}"
done

- name: Render representative configurations
run: |
set -euo pipefail
helm template wandb-operator deploy/operator \
--namespace wandb-operators \
--include-crds >/dev/null
for profile in deploy/operator/profiles/*.yaml; do
extra_args=()
if [[ "${profile}" == *telemetry-forward.yaml ]]; then
extra_args+=(--set-string telemetry.forwarding.otlp.endpoint=https://example.invalid:4317)
fi
helm template wandb-operator deploy/operator \
--namespace wandb-operators \
--include-crds \
--values "${profile}" \
"${extra_args[@]}" >/dev/null
done
12 changes: 6 additions & 6 deletions .github/workflows/docker-build-scan.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,22 +2,22 @@ name: Docker Build and Security Scan

on:
push:
branches: [main]
branches: [v2, main]
pull_request:
branches: [main]
branches: [v2, main]

jobs:
build-and-scan:
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@v4
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4

- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3

- name: Build Docker image
uses: docker/build-push-action@v5
uses: docker/build-push-action@10e90e3645eae34f1e60eeb005ba3a3d33f178e8 # v6
with:
context: .
push: false
Expand All @@ -27,7 +27,7 @@ jobs:
cache-to: type=gha,mode=max

- name: Run Trivy vulnerability scanner
uses: aquasecurity/trivy-action@master
uses: aquasecurity/trivy-action@c07df6fec6fa692e6fd1200d50aaa1fdd66f03c8 # master
with:
image-ref: wandb/operator:${{ github.sha }}
format: "table"
Expand Down
105 changes: 59 additions & 46 deletions .github/workflows/internal-chart-publish.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -5,75 +5,88 @@ on:

jobs:
release:
name: Release
name: Publish prerelease chart
runs-on: ubuntu-latest
permissions:
contents: 'read'
id-token: 'write'
contents: read
id-token: write
env:
CHART_REPOSITORY: us-docker.pkg.dev/wandb-production/public/wandb/charts
steps:
- name: Checkout
uses: actions/checkout@v4
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
with:
persist-credentials: false
fetch-depth: 0
persist-credentials: false

- name: Validate prerelease chart version
id: chart
shell: bash
run: |
set -euo pipefail
version="$(awk '$1 == "version:" { print $2; exit }' deploy/operator/Chart.yaml | tr -d '\"')"
if [[ ! "${version}" =~ ^2\.[0-9]+\.[0-9]+-[0-9A-Za-z][0-9A-Za-z.-]*$ ]]; then
echo "Internal chart publishing requires a v2 prerelease version; got ${version}" >&2
exit 1
fi
echo "version=${version}" >> "${GITHUB_OUTPUT}"

- name: Install Helm
uses: azure/setup-helm@bf6a7d304bc2fdb57e0331155b7ebf2c504acf0a # v4
with:
version: v3.19.0

- name: Set up QEMU
uses: docker/setup-qemu-action@v2
- name: Install chart-testing
uses: helm/chart-testing-action@e6669bcd63d7cb57cb4380c33043eebe5d111992 # v2.6.1
with:
version: v3.14.0

- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v2
- name: Lint charts
run: ct lint --all --config deploy/ct.yaml

- name: Set up Cloud SDK
uses: google-github-actions/setup-gcloud@v3.0.1
uses: google-github-actions/setup-gcloud@aa5489c8933f4cc7a4f7d45035b3b1440c9c10db # v3.0.1

- id: auth
name: Authenticate to Google Cloud
uses: google-github-actions/auth@v3
uses: google-github-actions/auth@7c6bc770dae815cd3e89ee6cdf493a5fab2cc093 # v3
with:
create_credentials_file: 'true'
token_format: access_token
project_id: wandb-production
workload_identity_provider: ${{ secrets.CI_WORKLOAD_IDENTITY_PROVIDER }}
service_account: ${{ secrets.CI_WORKLOAD_IDENTITY_SERVICE_ACCOUNT }}

- name: Authorize Docker to use Google Container Registry
run: |
gcloud auth configure-docker us-docker.pkg.dev

- uses: actions/setup-go@v4
with:
go-version: 1.25
- name: Authorize Docker for Artifact Registry
run: gcloud auth configure-docker us-docker.pkg.dev --quiet

- name: Install Helm
uses: azure/setup-helm@v4
with:
version: v3.19.0

- name: Set up chart-testing
uses: helm/chart-testing-action@v2.6.1
with:
version: v3.14.0

- name: Run chart-testing (list-changed)
id: list-changed
- name: Reject existing chart version
env:
VERSION: ${{ steps.chart.outputs.version }}
shell: bash
run: |
changed=$(ct list-changed --config deploy/ct.yaml || true)
if [[ -n "$changed" ]]; then
echo "changed=true" >> $GITHUB_OUTPUT
set -euo pipefail
artifact="${CHART_REPOSITORY}/operator:${VERSION}"
set +e
output="$(gcloud artifacts docker images describe "${artifact}" --format='value(image_summary.digest)' 2>&1)"
status=$?
set -e
if [[ ${status} -eq 0 ]]; then
echo "Refusing to overwrite existing chart ${artifact}" >&2
exit 1
fi
if ! grep -Eqi 'NOT_FOUND|not found' <<< "${output}"; then
echo "Could not safely determine whether ${artifact} exists:" >&2
echo "${output}" >&2
exit 1
fi

- name: Run chart-testing (lint)
run: ct lint --config deploy/ct.yaml

- name: Install Ginkgo
run: go install github.com/onsi/ginkgo/v2/ginkgo@latest

- name: Build and Push to GAR
if: steps.list-changed.outputs.changed == 'true'
- name: Package and publish prerelease chart
env:
VERSION: ${{ steps.chart.outputs.version }}
run: |
VERSION=$(grep "^version:" deploy/operator/Chart.yaml | awk '{print $2}')
set -euo pipefail
helm dependency build deploy/operator
helm package deploy/operator
helm push operator-${VERSION}.tgz oci://$REPOSITORY
env:
REPOSITORY: us-docker.pkg.dev/wandb-production/public/wandb/charts
mkdir -p dist
helm package deploy/operator --destination dist
helm push "dist/operator-${VERSION}.tgz" "oci://${CHART_REPOSITORY}"
53 changes: 23 additions & 30 deletions .github/workflows/internal-image-publish.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -5,57 +5,50 @@ on:
inputs:
image_tag:
type: string
description: 'Tags for Images in GAR'
description: 'Development tag in the form dev-<name>-<7-to-40-character-sha>'
required: true

jobs:
release:
name: Release
name: Publish development image
runs-on: ubuntu-latest
permissions:
contents: 'read'
id-token: 'write'
contents: read
id-token: write
steps:
- name: Validate development tag
env:
VERSION: ${{ inputs.image_tag }}
run: |
if [[ ! "${VERSION}" =~ ^dev-[a-z0-9][a-z0-9._-]*-[0-9a-f]{7,40}$ ]]; then
echo "Development tags must use dev-<name>-<7-to-40-character-sha>" >&2
exit 1
fi

- name: Checkout
uses: actions/checkout@v4
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
with:
persist-credentials: false
fetch-depth: 0

- name: Set up QEMU
uses: docker/setup-qemu-action@v2

- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v2
persist-credentials: false

- name: Set up Cloud SDK
uses: google-github-actions/setup-gcloud@v3.0.1
uses: google-github-actions/setup-gcloud@aa5489c8933f4cc7a4f7d45035b3b1440c9c10db # v3.0.1

- id: auth
name: Authenticate to Google Cloud
uses: google-github-actions/auth@v3
uses: google-github-actions/auth@7c6bc770dae815cd3e89ee6cdf493a5fab2cc093 # v3
with:
create_credentials_file: 'true'
token_format: access_token
project_id: wandb-production
workload_identity_provider: ${{ secrets.CI_WORKLOAD_IDENTITY_PROVIDER }}
service_account: ${{ secrets.CI_WORKLOAD_IDENTITY_SERVICE_ACCOUNT }}

- name: Authorize Docker to use Google Container Registry
run: |
gcloud auth configure-docker us-docker.pkg.dev

- uses: actions/setup-go@v4
with:
go-version: 1.25

- name: Install Ginkgo
run: go install github.com/onsi/ginkgo/v2/ginkgo@latest
- name: Authorize Docker for Artifact Registry
run: gcloud auth configure-docker us-docker.pkg.dev --quiet

- name: Build and Push to GAR
run: |
export IMG=$IMAGE_TAG_BASE:$VERSION
make docker-build docker-push
- name: Build and publish development image
env:
IMAGE_TAG_BASE: us-docker.pkg.dev/wandb-production/public/wandb/operator
VERSION: ${{ github.event.inputs.image_tag }}
IMAGE_REPOSITORY: us-docker.pkg.dev/wandb-production/public/wandb/operator
VERSION: ${{ inputs.image_tag }}
run: make docker-build docker-push IMG="${IMAGE_REPOSITORY}:${VERSION}"
2 changes: 1 addition & 1 deletion .github/workflows/pr-title.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ jobs:
runs-on: ubuntu-latest
steps:
# https://github.com/amannn/action-semantic-pull-request/releases
- uses: amannn/action-semantic-pull-request@v4.2.0
- uses: amannn/action-semantic-pull-request@0eb081bc9c35210408951834a444794406eff6f8 # v4.2.0
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
with:
Expand Down
Loading
Loading