Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions hack/run-linter
Original file line number Diff line number Diff line change
Expand Up @@ -38,6 +38,10 @@ if [ "$check" != "" ]; then
echo "$check"
echo ""
fi

# Validate release notes
hack/validate-release-notes.sh || rc=1

set -e

exit $rc
78 changes: 78 additions & 0 deletions hack/validate-release-notes.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,78 @@
#!/usr/bin/env bash

# Validate that commits reference LOG-XXXX or CVE and that references are in release notes
# Checks commits since the 6.5.3 release
# Usage: validate-release-notes.sh [base-ref]
# Default base-ref: last commit with "Update version to 6.5.3"

set -euo pipefail

RELEASE_NOTES="${RELEASE_NOTES:-release-notes.adoc}"
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
REPO_ROOT="$(cd "${SCRIPT_DIR}/.." && pwd)"

cd "${REPO_ROOT}"

# Check if release notes file exists
if [[ ! -f "${RELEASE_NOTES}" ]]; then
echo "ERROR: Release notes file not found: ${RELEASE_NOTES}"
exit 1
fi

# If no base-ref provided, find the 6.5.3 release
if [[ -z "${1:-}" ]]; then
LAST_6_5_3=$(git log --all --oneline | grep "Update version to 6.5.3" | head -1 | cut -d' ' -f1)
if [[ -z "${LAST_6_5_3}" ]]; then
echo "ERROR: Could not find 6.5.3 release"
exit 1
fi
BASE_REF="${LAST_6_5_3}"
else
BASE_REF="${1}"
fi

echo "Validating commits since: ${BASE_REF}"

FAILED=0
COMMITS=$(git rev-list "${BASE_REF}..HEAD" 2>/dev/null || echo "")

if [[ -z "${COMMITS}" ]]; then
echo "No commits to validate against ${BASE_REF}"
exit 0
fi

for COMMIT in ${COMMITS}; do
MSG=$(git log -1 --pretty=format:"%B" "${COMMIT}")
SUBJECT=$(git log -1 --pretty=format:"%s" "${COMMIT}")

# Extract LOG-XXXX and CVE references from commit message
REFS=$(echo "${MSG}" | grep -oE "(LOG-[0-9]+|CVE-[0-9]{4}-[0-9]+)" || true)

if [[ -z "${REFS}" ]]; then
echo "ERROR [${COMMIT:0:7}]: Commit does not reference a LOG-XXXX or CVE identifier"
echo " Subject: ${SUBJECT}"
FAILED=1
continue
fi

# Check that each reference exists in release notes
while IFS= read -r REF; do
if ! grep -q "${REF}" "${RELEASE_NOTES}"; then
echo "ERROR [${COMMIT:0:7}]: Reference ${REF} not found in ${RELEASE_NOTES}"
echo " Subject: ${SUBJECT}"
FAILED=1
fi
done <<< "${REFS}"
done

if [[ ${FAILED} -eq 1 ]]; then
echo ""
echo "Release notes validation failed."
echo "Please ensure:"
echo " 1. All commits reference a LOG-XXXX or CVE identifier"
echo " 2. All references are documented in ${RELEASE_NOTES}"
exit 1
fi

echo "✓ Release notes validation passed"
exit 0
73 changes: 73 additions & 0 deletions release-notes.adoc
Original file line number Diff line number Diff line change
@@ -0,0 +1,73 @@
= Cluster Logging Operator 6.5 Release Notes

== 6.5.3

=== Bug Fixes

* *LOG-9424* - Before this update, when MultiClusterLogForwarder resources shared the same serviceAccount, the cluster-logging-operator updated the Role resource in a loop, alternating ownerReferences between resources. With this update, the operator prevents this continuous cycle, resolving API server flooding and cluster instability.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

to make it nicer, it would be good to add a link to the jira.


* *LOG-9584* - Before this update, null values in log events caused the match_any function to fail during remap transformations under the following conditions: when log metadata from deleted pods was missing. With this update, null-safe validation in the remap engine resolves the issue and logs are processed successfully without errors.

=== Security

* *CVE-2026-27136 (LOG-9617)* - Bump golang.org/x/net to v0.55.0 for CVE-2026-27136

* *CVE-2026-33813* - Upgrade golang.org/x/image to 0.42.0

== 6.5.2

=== Bug Fixes

* *LOG-8769* - Before this update, specifying compression: none in the S3 output tuning configuration was ignored, causing logs to be forwarded as gzip-compressed files. With this update, the operator correctly honors the compression: none setting and forwards uncompressed logs to S3.

* *LOG-8982* - Before this update, the ClusterLogForwarderDeprecations alert was triggered even though the deprecated features were promoted to GA in v6.4, causing administrators to silence warnings upon upgrade. With this update, the alert is removed, resolving unnecessary noise for users running supported configurations.

=== Security

* *CVE-2026-33813 (LOG-9379)* - Fix CVE-2026-33813 and refactor Go versioning

== 6.5.1

=== Features

* *LOG-5843* - Before this update, logs forwarded over OTLP lacked tracing attributes needed to correlate logs with other observability signals. With this update, adding traceid, spanid, and sampled flag attributes using OpenTelemetry semantic conventions resolves the issue and users can now correlate logs with traces successfully.

* *LOG-7892* - Before this update, HTTP sinks could not forward logs in NDJSON format, preventing integration with vendor-neutral log ingestors like VictoriaLogs. With this update, adding NDJSON format support to the HTTP sink resolves the issue and logs can be sent in line-delimited JSON format successfully.

* *LOG-8645* - Before this update, the Loki output did not support HTTP proxy configuration, limiting deployment options in environments with proxy requirements. With this update, adding ProxyURL setting to the Loki output following HTTP output syntax resolves the issue and users can configure proxies for Loki outputs.

=== Bug Fixes

* *LOG-8241* - Before this update, socket-level transport outputs (syslog, kafka) could be created without specifying a port, causing configuration errors at runtime. With this update, declarative validation requires port specifications on socket-level transports, and administrators receive immediate feedback during resource admission.

* *LOG-8578* - Before this update, OpenTelemetry forwarding required a feature gate and carried tech-preview restrictions, limiting adoption of the logging data model. With this update, removing feature gate requirements and marking OTLP as GA resolves the issue and users can forward logs to OTLP endpoints without restrictions.

* *LOG-8581* - Before this update, duplicate case-variant header names (Accept and accept) in CLF outputs caused Elasticsearch to reject requests with a media_type_header_exception. With this update, header deduplication logic resolves the issue and logs can be forwarded to Elasticsearch successfully.

* *LOG-8713* - Before this update, linting failures existed in the codebase due to Go 1.24 linter updates, preventing clean builds. With this update, updating code to satisfy the latest linter rules resolves the issue and all linting checks pass without exceptions.

* *LOG-8876* - Before this update, logs with non-standard trace context formats (from Zipkin, AWS X-Ray, SkyWalking) were rejected by LokiStack and OpenTelemetry Collector when IDs did not comply with W3C standards. With this update, implementing validation that strips non-compliant trace attributes resolves the issue and logs with custom trace formats can be successfully ingested.

== 6.5.0

Initial release of Cluster Logging Operator 6.5.

=== Features

* *LOG-5843* - Before this update, logs forwarded over OTLP lacked tracing attributes needed to correlate logs with other observability signals. With this update, adding traceid, spanid, and sampled flag attributes using OpenTelemetry semantic conventions resolves the issue and users can now correlate logs with traces successfully.

* *LOG-7892* - Before this update, HTTP sinks could not forward logs in NDJSON format, preventing integration with vendor-neutral log ingestors like VictoriaLogs. With this update, adding NDJSON format support to the HTTP sink resolves the issue and logs can be sent in line-delimited JSON format successfully.

* *LOG-8645* - Before this update, the Loki output did not support HTTP proxy configuration, limiting deployment options in environments with proxy requirements. With this update, adding ProxyURL setting to the Loki output following HTTP output syntax resolves the issue and users can configure proxies for Loki outputs.

=== Bug Fixes

* *LOG-8241* - Before this update, socket-level transport outputs (syslog, kafka) could be created without specifying a port, causing configuration errors at runtime. With this update, declarative validation requires port specifications on socket-level transports, and administrators receive immediate feedback during resource admission.

* *LOG-8578* - Before this update, OpenTelemetry forwarding required a feature gate and carried tech-preview restrictions, limiting adoption of the logging data model. With this update, removing feature gate requirements and marking OTLP as GA resolves the issue and users can forward logs to OTLP endpoints without restrictions.

* *LOG-8581* - Before this update, duplicate case-variant header names (Accept and accept) in CLF outputs caused Elasticsearch to reject requests with a media_type_header_exception. With this update, header deduplication logic resolves the issue and logs can be forwarded to Elasticsearch successfully.

* *LOG-8713* - Before this update, linting failures existed in the codebase due to Go 1.24 linter updates, preventing clean builds. With this update, updating code to satisfy the latest linter rules resolves the issue and all linting checks pass without exceptions.

* *LOG-8876* - Before this update, logs with non-standard trace context formats (from Zipkin, AWS X-Ray, SkyWalking) were rejected by LokiStack and OpenTelemetry Collector when IDs did not comply with W3C standards. With this update, implementing validation that strips non-compliant trace attributes resolves the issue and logs with custom trace formats can be successfully ingested.