diff --git a/CHANGELOG.md b/CHANGELOG.md index 12225249..62811c0f 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -8,6 +8,7 @@ All notable changes to this project will be documented in this file. - Support floating tags for product images via the new `spec.image.stackableVersionPolicy` field ([#186]). +- Add support for OpenSearch 3.8.0, deprecate 3.6.0 and remove support for 3.4.0 ([#189]). ### Changed @@ -36,6 +37,7 @@ All notable changes to this project will be documented in this file. [#172]: https://github.com/stackabletech/opensearch-operator/pull/172 [#179]: https://github.com/stackabletech/opensearch-operator/pull/179 [#186]: https://github.com/stackabletech/opensearch-operator/pull/186 +[#189]: https://github.com/stackabletech/opensearch-operator/pull/189 ## [26.7.0] - 2026-07-21 diff --git a/docs/modules/opensearch/examples/getting_started/getting_started.sh b/docs/modules/opensearch/examples/getting_started/getting_started.sh index b3390b58..b006bfc9 100755 --- a/docs/modules/opensearch/examples/getting_started/getting_started.sh +++ b/docs/modules/opensearch/examples/getting_started/getting_started.sh @@ -142,7 +142,7 @@ kubectl create secret generic opensearch-credentials \ # Hide notes because they are very confusing in combination with the port forward below. helm install opensearch-dashboards opensearch-dashboards \ --repo https://opensearch-project.github.io/helm-charts \ - --version 3.6.0 \ + --version 3.8.0 \ --values opensearch-dashboards-values.yaml \ --hide-notes \ --wait diff --git a/docs/modules/opensearch/examples/getting_started/getting_started.sh.j2 b/docs/modules/opensearch/examples/getting_started/getting_started.sh.j2 index 8eb95b6d..0457ca50 100644 --- a/docs/modules/opensearch/examples/getting_started/getting_started.sh.j2 +++ b/docs/modules/opensearch/examples/getting_started/getting_started.sh.j2 @@ -142,7 +142,7 @@ kubectl create secret generic opensearch-credentials \ # Hide notes because they are very confusing in combination with the port forward below. helm install opensearch-dashboards opensearch-dashboards \ --repo https://opensearch-project.github.io/helm-charts \ - --version 3.6.0 \ + --version 3.8.0 \ --values opensearch-dashboards-values.yaml \ --hide-notes \ --wait diff --git a/docs/modules/opensearch/examples/getting_started/opensearch-dashboards-values.yaml b/docs/modules/opensearch/examples/getting_started/opensearch-dashboards-values.yaml index 8b4a322d..7969bac3 100644 --- a/docs/modules/opensearch/examples/getting_started/opensearch-dashboards-values.yaml +++ b/docs/modules/opensearch/examples/getting_started/opensearch-dashboards-values.yaml @@ -1,7 +1,7 @@ --- image: repository: oci.stackable.tech/sdp/opensearch-dashboards - tag: 3.6.0-stackable0.0.0-dev + tag: 3.8.0-stackable0.0.0-dev serviceAccount: create: false name: simple-opensearch-serviceaccount @@ -23,6 +23,11 @@ config: secure: true # See https://github.com/opensearch-project/helm-charts/blob/main/charts/opensearch-dashboards/templates/deployment.yaml#L122 opensearchHosts: "" +resources: + requests: + cpu: 500m + limits: + cpu: "1" extraEnvs: - name: OPENSEARCH_HOSTS valueFrom: diff --git a/docs/modules/opensearch/examples/getting_started/opensearch-dashboards-values.yaml.j2 b/docs/modules/opensearch/examples/getting_started/opensearch-dashboards-values.yaml.j2 index b1b20b5f..064751f9 100644 --- a/docs/modules/opensearch/examples/getting_started/opensearch-dashboards-values.yaml.j2 +++ b/docs/modules/opensearch/examples/getting_started/opensearch-dashboards-values.yaml.j2 @@ -1,7 +1,7 @@ --- image: repository: oci.stackable.tech/sdp/opensearch-dashboards - tag: 3.6.0-stackable{{ versions.opensearch }} + tag: 3.8.0-stackable{{ versions.opensearch }} serviceAccount: create: false name: simple-opensearch-serviceaccount @@ -23,6 +23,11 @@ config: secure: true # See https://github.com/opensearch-project/helm-charts/blob/main/charts/opensearch-dashboards/templates/deployment.yaml#L122 opensearchHosts: "" +resources: + requests: + cpu: 500m + limits: + cpu: "1" extraEnvs: - name: OPENSEARCH_HOSTS valueFrom: diff --git a/docs/modules/opensearch/examples/getting_started/opensearch.yaml b/docs/modules/opensearch/examples/getting_started/opensearch.yaml index e564100f..df2a476d 100644 --- a/docs/modules/opensearch/examples/getting_started/opensearch.yaml +++ b/docs/modules/opensearch/examples/getting_started/opensearch.yaml @@ -5,7 +5,7 @@ metadata: name: simple-opensearch spec: image: - productVersion: 3.6.0 + productVersion: 3.8.0 clusterConfig: security: settings: diff --git a/docs/modules/opensearch/pages/usage-guide/opensearch-dashboards.adoc b/docs/modules/opensearch/pages/usage-guide/opensearch-dashboards.adoc index dad172cc..3b01749a 100644 --- a/docs/modules/opensearch/pages/usage-guide/opensearch-dashboards.adoc +++ b/docs/modules/opensearch/pages/usage-guide/opensearch-dashboards.adoc @@ -13,7 +13,7 @@ A basic `values.yaml` file to deploy OpenSearch Dashboards with this chart might opensearchHosts: null # <1> image: # <2> repository: oci.stackable.tech/sdp/opensearch-dashboards - tag: 3.6.0-stackable0.0.0-dev + tag: 3.8.0-stackable0.0.0-dev serviceAccount: create: false name: opensearch-serviceaccount # <3> @@ -92,7 +92,7 @@ After the values are adjusted according to your deployment, especially `opensear ---- helm install opensearch-dashboards opensearch-dashboards \ --repo https://opensearch-project.github.io/helm-charts \ - --version 3.6.0 \ + --version 3.8.0 \ --values opensearch-dashboards-values.yaml \ --wait ---- diff --git a/docs/modules/opensearch/pages/usage-guide/opensearch-dashboards.adoc.j2 b/docs/modules/opensearch/pages/usage-guide/opensearch-dashboards.adoc.j2 index 230f35ca..e64a0398 100644 --- a/docs/modules/opensearch/pages/usage-guide/opensearch-dashboards.adoc.j2 +++ b/docs/modules/opensearch/pages/usage-guide/opensearch-dashboards.adoc.j2 @@ -13,7 +13,7 @@ A basic `values.yaml` file to deploy OpenSearch Dashboards with this chart might opensearchHosts: null # <1> image: # <2> repository: oci.stackable.tech/sdp/opensearch-dashboards - tag: 3.6.0-stackable{{ versions.opensearch }} + tag: 3.8.0-stackable{{ versions.opensearch }} serviceAccount: create: false name: opensearch-serviceaccount # <3> @@ -92,7 +92,7 @@ After the values are adjusted according to your deployment, especially `opensear ---- helm install opensearch-dashboards opensearch-dashboards \ --repo https://opensearch-project.github.io/helm-charts \ - --version 3.6.0 \ + --version 3.8.0 \ --values opensearch-dashboards-values.yaml \ --wait ---- diff --git a/docs/modules/opensearch/pages/usage-guide/security.adoc b/docs/modules/opensearch/pages/usage-guide/security.adoc index 58eb641a..84f77bbb 100644 --- a/docs/modules/opensearch/pages/usage-guide/security.adoc +++ b/docs/modules/opensearch/pages/usage-guide/security.adoc @@ -163,7 +163,7 @@ metadata: name: opensearch spec: image: - productVersion: 3.6.0 + productVersion: 3.8.0 clusterConfig: tls: serverSecretClass: tls # <1> diff --git a/docs/modules/opensearch/partials/supported-versions.adoc b/docs/modules/opensearch/partials/supported-versions.adoc index 19750b4f..97dd9dd7 100644 --- a/docs/modules/opensearch/partials/supported-versions.adoc +++ b/docs/modules/opensearch/partials/supported-versions.adoc @@ -3,5 +3,5 @@ // Stackable Platform documentation. - 3.1.0 (LTS) -- 3.6.0 -- 3.4.0 (deprecated) +- 3.8.0 +- 3.6.0 (deprecated) diff --git a/rust/operator-binary/src/controller.rs b/rust/operator-binary/src/controller.rs index 73a127db..7669a64f 100644 --- a/rust/operator-binary/src/controller.rs +++ b/rust/operator-binary/src/controller.rs @@ -610,14 +610,14 @@ mod tests { fn validated_cluster() -> ValidatedCluster { ValidatedCluster::new( ResolvedProductImage { - product_version: "3.6.0".to_owned(), - app_version_label_value: LabelValue::from_str("3.6.0-stackable0.0.0-dev") + product_version: "3.8.0".to_owned(), + app_version_label_value: LabelValue::from_str("3.8.0-stackable0.0.0-dev") .expect("should be a valid label value"), - image: "oci.stackable.tech/sdp/opensearch:3.6.0-stackable0.0.0-dev".to_string(), + image: "oci.stackable.tech/sdp/opensearch:3.8.0-stackable0.0.0-dev".to_string(), image_pull_policy: "Always".to_owned(), pull_secrets: None, }, - ProductVersion::from_str_unsafe("3.6.0"), + ProductVersion::from_str_unsafe("3.8.0"), ClusterName::from_str_unsafe("my-opensearch"), NamespaceName::from_str_unsafe("default"), uuid!("e6ac237d-a6d4-43a1-8135-f36506110912"), diff --git a/rust/operator-binary/src/controller/build.rs b/rust/operator-binary/src/controller/build.rs index e7a9041a..27278cba 100644 --- a/rust/operator-binary/src/controller/build.rs +++ b/rust/operator-binary/src/controller/build.rs @@ -177,14 +177,14 @@ mod tests { fn validated_cluster() -> ValidatedCluster { ValidatedCluster::new( ResolvedProductImage { - product_version: "3.6.0".to_owned(), - app_version_label_value: LabelValue::from_str("3.6.0-stackable0.0.0-dev") + product_version: "3.8.0".to_owned(), + app_version_label_value: LabelValue::from_str("3.8.0-stackable0.0.0-dev") .expect("should be a valid label value"), - image: "oci.stackable.tech/sdp/opensearch:3.6.0-stackable0.0.0-dev".to_string(), + image: "oci.stackable.tech/sdp/opensearch:3.8.0-stackable0.0.0-dev".to_string(), image_pull_policy: "Always".to_owned(), pull_secrets: None, }, - ProductVersion::from_str_unsafe("3.6.0"), + ProductVersion::from_str_unsafe("3.8.0"), ClusterName::from_str_unsafe("my-opensearch"), NamespaceName::from_str_unsafe("default"), uuid!("e6ac237d-a6d4-43a1-8135-f36506110912"), diff --git a/rust/operator-binary/src/controller/build/node_config.rs b/rust/operator-binary/src/controller/build/node_config.rs index c1ad7e66..83bf4303 100644 --- a/rust/operator-binary/src/controller/build/node_config.rs +++ b/rust/operator-binary/src/controller/build/node_config.rs @@ -74,7 +74,7 @@ const CONFIG_OPTION_NODE_ROLES: &str = "node.roles"; /// Defines the path for the logs /// OpenSearch grants the required access rights, see -/// +/// /// The permissions "write" and "delete" are required for the log file rollover. /// Type: string const CONFIG_OPTION_PATH_LOGS: &str = "path.logs"; @@ -427,7 +427,7 @@ impl NodeConfig { /// Please read the following sections for an explanation of these restrictions. /// /// This configuration setting replaces the setting `cluster.initial_master_nodes`, see - /// . + /// . /// /// This setting is required on nodes with the cluster-manager node role on a multi-node /// cluster. Otherwise the bootstrapping of the cluster fails and all pods report: @@ -437,7 +437,7 @@ impl NodeConfig { /// error is thrown: /// > setting [cluster.initial_cluster_manager_nodes] is not allowed when [discovery.type] is set to [single-node] /// - /// see + /// see /// /// This setting does not seem to have an effect on nodes without the cluster-manager node /// role. However, as it is recommended (see the Elasticsearch documentation below) to not set @@ -590,7 +590,7 @@ mod tests { } fn node_config(test_config: TestConfig) -> NodeConfig { - let image: ProductImage = serde_json::from_str(r#"{"productVersion": "3.6.0"}"#) + let image: ProductImage = serde_json::from_str(r#"{"productVersion": "3.8.0"}"#) .expect("should be a valid ProductImage"); let role_group_name = RoleGroupName::from_str_unsafe("data"); @@ -659,10 +659,10 @@ mod tests { let cluster = ValidatedCluster::new( ResolvedProductImage { - product_version: "3.6.0".to_owned(), - app_version_label_value: LabelValue::from_str("3.6.0-stackable0.0.0-dev") + product_version: "3.8.0".to_owned(), + app_version_label_value: LabelValue::from_str("3.8.0-stackable0.0.0-dev") .expect("should be a valid label value"), - image: "oci.stackable.tech/sdp/opensearch:3.6.0-stackable0.0.0-dev".to_string(), + image: "oci.stackable.tech/sdp/opensearch:3.8.0-stackable0.0.0-dev".to_string(), image_pull_policy: "Always".to_owned(), pull_secrets: None, }, diff --git a/rust/operator-binary/src/controller/build/product_logging/config.rs b/rust/operator-binary/src/controller/build/product_logging/config.rs index d37dbf85..a6515c3e 100644 --- a/rust/operator-binary/src/controller/build/product_logging/config.rs +++ b/rust/operator-binary/src/controller/build/product_logging/config.rs @@ -92,7 +92,7 @@ fn log4j2_console_appender_config( "PatternLayout".to_owned(), ), // Same as the default layout pattern of the console appender - // see https://github.com/opensearch-project/OpenSearch/blob/3.6.0/distribution/src/config/log4j2.properties#L17 + // see https://github.com/opensearch-project/OpenSearch/blob/3.8.0/distribution/src/config/log4j2.properties#L17 ( "appender.CONSOLE.layout.pattern".to_owned(), "[%d{ISO8601}][%-5p][%-25c{1.}] [%node_name]%marker %m%n".to_owned(), diff --git a/rust/operator-binary/src/controller/build/product_logging/test-vector.sh b/rust/operator-binary/src/controller/build/product_logging/test-vector.sh index 56abe990..f548ddbe 100755 --- a/rust/operator-binary/src/controller/build/product_logging/test-vector.sh +++ b/rust/operator-binary/src/controller/build/product_logging/test-vector.sh @@ -1,5 +1,8 @@ #!/usr/bin/env sh +SUBSTITUTED_VECTOR_YAML="vector-subst.yaml" +trap 'rm "$SUBSTITUTED_VECTOR_YAML"' EXIT + DATA_DIR=/stackable/log/_vector-state \ LOG_DIR=/stackable/log \ OPENSEARCH_SERVER_LOG_FILE=opensearch_server.json \ @@ -9,4 +12,6 @@ ROLE_NAME=nodes \ ROLE_GROUP_NAME=cluster-manager \ VECTOR_AGGREGATOR_ADDRESS=vector-aggregator \ VECTOR_FILE_LOG_LEVEL=info \ -vector test vector.yaml vector-test.yaml +envsubst < vector.yaml > "$SUBSTITUTED_VECTOR_YAML" + +vector test "$SUBSTITUTED_VECTOR_YAML" vector-test.yaml diff --git a/rust/operator-binary/src/controller/build/product_logging/vector-test.yaml b/rust/operator-binary/src/controller/build/product_logging/vector-test.yaml index 122cc242..0813bca1 100644 --- a/rust/operator-binary/src/controller/build/product_logging/vector-test.yaml +++ b/rust/operator-binary/src/controller/build/product_logging/vector-test.yaml @@ -1,7 +1,7 @@ # Run tests with `./test-vector.sh` # # A downside of these test cases is that they compare the whole event and that the message can -# contain source code positions in vector.yaml, e.g. "function call error for \"parse_timestamp\" at (990:1070)". Please adapt the tests if you change VRL code in vector.yaml. +# contain source code positions in vector.yaml, e.g. "function call error for \"parse_timestamp\" at (999:1079)". Please adapt the tests if you change VRL code in vector.yaml. --- tests: - name: Test opensearch_server log entry without stacktrace @@ -45,14 +45,14 @@ tests: {"type": "server", "timestamp": "2025-10-01T12:47:28,363+0000", "level": "INFO", "component": "o.o.c.c.JoinHelper", "cluster.name": "opensearch", "node.name": "opensearch-nodes-cluster-manager-0", "message": "failed to join {opensearch-nodes-cluster-manager-0}{sk-r0P_TTYuPqaamTFbjKg}{fIRSMbQYSe2nKQZ_sPn4kg}{10.244.0.20}{10.244.0.20:9300}{m}{shard_indexing_pressure_enabled=true} with JoinRequest{sourceNode={opensearch-nodes-cluster-manager-0}{sk-r0P_TTYuPqaamTFbjKg}{fIRSMbQYSe2nKQZ_sPn4kg}{10.244.0.20}{10.244.0.20:9300}{m}{shard_indexing_pressure_enabled=true}, minimumTerm=0, optionalJoin=Optional[Join{term=1, lastAcceptedTerm=0, lastAcceptedVersion=0, sourceNode={opensearch-nodes-cluster-manager-0}{sk-r0P_TTYuPqaamTFbjKg}{fIRSMbQYSe2nKQZ_sPn4kg}{10.244.0.20}{10.244.0.20:9300}{m}{shard_indexing_pressure_enabled=true}, targetNode={opensearch-nodes-cluster-manager-0}{sk-r0P_TTYuPqaamTFbjKg}{fIRSMbQYSe2nKQZ_sPn4kg}{10.244.0.20}{10.244.0.20:9300}{m}{shard_indexing_pressure_enabled=true}}]}", "stacktrace": ["org.opensearch.transport.RemoteTransportException: [opensearch-nodes-cluster-manager-0][10.244.0.20:9300][internal:cluster/coordination/join]", "Caused by: org.opensearch.cluster.coordination.CoordinationStateRejectedException: became follower", - "at org.opensearch.cluster.coordination.JoinHelper$$CandidateJoinAccumulator.lambda$$close$$3(JoinHelper.java:648) ~[opensearch-3.6.0.jar:3.6.0]", + "at org.opensearch.cluster.coordination.JoinHelper$$CandidateJoinAccumulator.lambda$$close$$3(JoinHelper.java:648) ~[opensearch-3.8.0.jar:3.8.0]", "at java.base/java.util.HashMap$$Values.forEach(HashMap.java:1073) ~[?:?]", - "at org.opensearch.cluster.coordination.JoinHelper$$CandidateJoinAccumulator.close(JoinHelper.java:648) ~[opensearch-3.6.0.jar:3.6.0]", - "at org.opensearch.cluster.coordination.Coordinator.becomeFollower(Coordinator.java:829) ~[opensearch-3.6.0.jar:3.6.0]", - "at org.opensearch.cluster.coordination.Coordinator.onFollowerCheckRequest(Coordinator.java:405) ~[opensearch-3.6.0.jar:3.6.0]", - "at org.opensearch.cluster.coordination.FollowersChecker$$2.doRun(FollowersChecker.java:250) ~[opensearch-3.6.0.jar:3.6.0]", - "at org.opensearch.common.util.concurrent.ThreadContext$$ContextPreservingAbstractRunnable.doRun(ThreadContext.java:975) ~[opensearch-3.6.0.jar:3.6.0]", - "at org.opensearch.common.util.concurrent.AbstractRunnable.run(AbstractRunnable.java:52) ~[opensearch-3.6.0.jar:3.6.0]", + "at org.opensearch.cluster.coordination.JoinHelper$$CandidateJoinAccumulator.close(JoinHelper.java:648) ~[opensearch-3.8.0.jar:3.8.0]", + "at org.opensearch.cluster.coordination.Coordinator.becomeFollower(Coordinator.java:829) ~[opensearch-3.8.0.jar:3.8.0]", + "at org.opensearch.cluster.coordination.Coordinator.onFollowerCheckRequest(Coordinator.java:405) ~[opensearch-3.8.0.jar:3.8.0]", + "at org.opensearch.cluster.coordination.FollowersChecker$$2.doRun(FollowersChecker.java:250) ~[opensearch-3.8.0.jar:3.8.0]", + "at org.opensearch.common.util.concurrent.ThreadContext$$ContextPreservingAbstractRunnable.doRun(ThreadContext.java:975) ~[opensearch-3.8.0.jar:3.8.0]", + "at org.opensearch.common.util.concurrent.AbstractRunnable.run(AbstractRunnable.java:52) ~[opensearch-3.8.0.jar:3.8.0]", "at java.base/java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1144) ~[?:?]", "at java.base/java.util.concurrent.ThreadPoolExecutor$$Worker.run(ThreadPoolExecutor.java:642) ~[?:?]", "at java.base/java.lang.Thread.run(Thread.java:1583) [?:?]"] } @@ -75,14 +75,14 @@ tests: \n\ org.opensearch.transport.RemoteTransportException: [opensearch-nodes-cluster-manager-0][10.244.0.20:9300][internal:cluster/coordination/join]\n\ Caused by: org.opensearch.cluster.coordination.CoordinationStateRejectedException: became follower\n\ - at org.opensearch.cluster.coordination.JoinHelper$$CandidateJoinAccumulator.lambda$$close$$3(JoinHelper.java:648) ~[opensearch-3.6.0.jar:3.6.0]\n\ + at org.opensearch.cluster.coordination.JoinHelper$$CandidateJoinAccumulator.lambda$$close$$3(JoinHelper.java:648) ~[opensearch-3.8.0.jar:3.8.0]\n\ at java.base/java.util.HashMap$$Values.forEach(HashMap.java:1073) ~[?:?]\n\ - at org.opensearch.cluster.coordination.JoinHelper$$CandidateJoinAccumulator.close(JoinHelper.java:648) ~[opensearch-3.6.0.jar:3.6.0]\n\ - at org.opensearch.cluster.coordination.Coordinator.becomeFollower(Coordinator.java:829) ~[opensearch-3.6.0.jar:3.6.0]\n\ - at org.opensearch.cluster.coordination.Coordinator.onFollowerCheckRequest(Coordinator.java:405) ~[opensearch-3.6.0.jar:3.6.0]\n\ - at org.opensearch.cluster.coordination.FollowersChecker$$2.doRun(FollowersChecker.java:250) ~[opensearch-3.6.0.jar:3.6.0]\n\ - at org.opensearch.common.util.concurrent.ThreadContext$$ContextPreservingAbstractRunnable.doRun(ThreadContext.java:975) ~[opensearch-3.6.0.jar:3.6.0]\n\ - at org.opensearch.common.util.concurrent.AbstractRunnable.run(AbstractRunnable.java:52) ~[opensearch-3.6.0.jar:3.6.0]\n\ + at org.opensearch.cluster.coordination.JoinHelper$$CandidateJoinAccumulator.close(JoinHelper.java:648) ~[opensearch-3.8.0.jar:3.8.0]\n\ + at org.opensearch.cluster.coordination.Coordinator.becomeFollower(Coordinator.java:829) ~[opensearch-3.8.0.jar:3.8.0]\n\ + at org.opensearch.cluster.coordination.Coordinator.onFollowerCheckRequest(Coordinator.java:405) ~[opensearch-3.8.0.jar:3.8.0]\n\ + at org.opensearch.cluster.coordination.FollowersChecker$$2.doRun(FollowersChecker.java:250) ~[opensearch-3.8.0.jar:3.8.0]\n\ + at org.opensearch.common.util.concurrent.ThreadContext$$ContextPreservingAbstractRunnable.doRun(ThreadContext.java:975) ~[opensearch-3.8.0.jar:3.8.0]\n\ + at org.opensearch.common.util.concurrent.AbstractRunnable.run(AbstractRunnable.java:52) ~[opensearch-3.8.0.jar:3.8.0]\n\ at java.base/java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1144) ~[?:?]\n\ at java.base/java.util.concurrent.ThreadPoolExecutor$$Worker.run(ThreadPoolExecutor.java:642) ~[?:?]\n\ at java.base/java.lang.Thread.run(Thread.java:1583) [?:?]", @@ -213,7 +213,7 @@ tests: "cluster": "opensearch", "container": "opensearch", "errors": [ - "Timestamp not parsable, using current time instead: function call error for \"parse_timestamp\" at (990:1070): Invalid timestamp \"unparsable\": input contains invalid characters" + "Timestamp not parsable, using current time instead: function call error for \"parse_timestamp\" at (999:1079): Invalid timestamp \"unparsable\": input contains invalid characters" ], "file": "opensearch_server.json", "level": "INFO", diff --git a/rust/operator-binary/src/controller/build/product_logging/vector.yaml b/rust/operator-binary/src/controller/build/product_logging/vector.yaml index eae71203..3cc4ab15 100644 --- a/rust/operator-binary/src/controller/build/product_logging/vector.yaml +++ b/rust/operator-binary/src/controller/build/product_logging/vector.yaml @@ -50,8 +50,8 @@ transforms: timestamp_string, err = string(event.timestamp) if err == null { - # OpenSearch 3.4.0 uses log4j2 2.21.0 which renders the timezone using "Z" (Zulu). - # OpenSearch 3.6.0 uses log4j2 2.25.0 which renders the timezone as a numeric offset (e.g. "...,122+0000"). + # OpenSearch 3.1.0 uses log4j2 2.21.0 which renders the timezone using "Z" (Zulu). + # OpenSearch 3.6.0 and 3.8.0 use log4j2 2.25.x which renders the timezone as a numeric offset (e.g. "...,122+0000"). # Try the offset format first and fall back to the literal "Z" so both layouts are parsed. parsed_timestamp, err = parse_timestamp(timestamp_string, "%Y-%m-%dT%H:%M:%S,%3f%z") if err != null { diff --git a/rust/operator-binary/src/controller/build/role_builder.rs b/rust/operator-binary/src/controller/build/role_builder.rs index c9f7587d..cd7c3066 100644 --- a/rust/operator-binary/src/controller/build/role_builder.rs +++ b/rust/operator-binary/src/controller/build/role_builder.rs @@ -404,7 +404,7 @@ mod tests { } fn role_builder<'a>(context_names: &'a ContextNames) -> RoleBuilder<'a> { - let image: ProductImage = serde_json::from_str(r#"{"productVersion": "3.6.0"}"#) + let image: ProductImage = serde_json::from_str(r#"{"productVersion": "3.8.0"}"#) .expect("should be a valid ProductImage"); let role_group_config = OpenSearchRoleGroupConfig { @@ -440,10 +440,10 @@ mod tests { let cluster = ValidatedCluster::new( ResolvedProductImage { - product_version: "3.6.0".to_owned(), - app_version_label_value: LabelValue::from_str("3.6.0-stackable0.0.0-dev") + product_version: "3.8.0".to_owned(), + app_version_label_value: LabelValue::from_str("3.8.0-stackable0.0.0-dev") .expect("should be a valid label value"), - image: "oci.stackable.tech/sdp/opensearch:3.6.0-stackable0.0.0-dev".to_string(), + image: "oci.stackable.tech/sdp/opensearch:3.8.0-stackable0.0.0-dev".to_string(), image_pull_policy: "Always".to_owned(), pull_secrets: None, }, @@ -495,7 +495,7 @@ mod tests { "app.kubernetes.io/instance": "my-opensearch-cluster", "app.kubernetes.io/managed-by": "opensearch.stackable.tech_opensearchcluster", "app.kubernetes.io/name": "opensearch", - "app.kubernetes.io/version": "3.6.0", + "app.kubernetes.io/version": "3.8.0", "stackable.tech/vendor": "Stackable" }, "name": "my-opensearch-cluster-serviceaccount", @@ -533,7 +533,7 @@ mod tests { "app.kubernetes.io/instance": "my-opensearch-cluster", "app.kubernetes.io/managed-by": "opensearch.stackable.tech_opensearchcluster", "app.kubernetes.io/name": "opensearch", - "app.kubernetes.io/version": "3.6.0", + "app.kubernetes.io/version": "3.8.0", "stackable.tech/vendor": "Stackable" }, "name": "my-opensearch-cluster-rolebinding", @@ -584,7 +584,7 @@ mod tests { "app.kubernetes.io/instance": "my-opensearch-cluster", "app.kubernetes.io/managed-by": "opensearch.stackable.tech_opensearchcluster", "app.kubernetes.io/name": "opensearch", - "app.kubernetes.io/version": "3.6.0", + "app.kubernetes.io/version": "3.8.0", "stackable.tech/vendor": "Stackable" }, "name": "my-opensearch-cluster-seed-nodes", @@ -640,7 +640,7 @@ mod tests { "app.kubernetes.io/instance": "my-opensearch-cluster", "app.kubernetes.io/managed-by": "opensearch.stackable.tech_opensearchcluster", "app.kubernetes.io/name": "opensearch", - "app.kubernetes.io/version": "3.6.0", + "app.kubernetes.io/version": "3.8.0", "stackable.tech/vendor": "Stackable", }, "name": "my-opensearch-cluster", @@ -692,7 +692,7 @@ mod tests { "app.kubernetes.io/instance": "my-opensearch-cluster", "app.kubernetes.io/managed-by": "opensearch.stackable.tech_opensearchcluster", "app.kubernetes.io/name": "opensearch", - "app.kubernetes.io/version": "3.6.0", + "app.kubernetes.io/version": "3.8.0", "stackable.tech/vendor": "Stackable", }, "name": "my-opensearch-cluster", @@ -737,7 +737,7 @@ mod tests { "app.kubernetes.io/instance": "my-opensearch-cluster", "app.kubernetes.io/managed-by": "opensearch.stackable.tech_opensearchcluster", "app.kubernetes.io/name": "opensearch", - "app.kubernetes.io/version": "3.6.0", + "app.kubernetes.io/version": "3.8.0", "stackable.tech/vendor": "Stackable", }, "name": "my-opensearch-cluster-security-config", diff --git a/rust/operator-binary/src/controller/build/role_group_builder.rs b/rust/operator-binary/src/controller/build/role_group_builder.rs index b1f6b80d..1de198a2 100644 --- a/rust/operator-binary/src/controller/build/role_group_builder.rs +++ b/rust/operator-binary/src/controller/build/role_group_builder.rs @@ -1543,10 +1543,10 @@ mod tests { fn validated_cluster(security_mode: TestSecurityMode) -> ValidatedCluster { let image = ResolvedProductImage { - product_version: "3.6.0".to_owned(), - app_version_label_value: LabelValue::from_str("3.6.0-stackable0.0.0-dev") + product_version: "3.8.0".to_owned(), + app_version_label_value: LabelValue::from_str("3.8.0-stackable0.0.0-dev") .expect("should be a valid label value"), - image: "oci.stackable.tech/sdp/opensearch:3.6.0-stackable0.0.0-dev".to_string(), + image: "oci.stackable.tech/sdp/opensearch:3.8.0-stackable0.0.0-dev".to_string(), image_pull_policy: "Always".to_owned(), pull_secrets: None, }; @@ -1732,7 +1732,7 @@ mod tests { "app.kubernetes.io/managed-by": "opensearch.stackable.tech_opensearchcluster", "app.kubernetes.io/name": "opensearch", "app.kubernetes.io/role-group": "default", - "app.kubernetes.io/version": "3.6.0", + "app.kubernetes.io/version": "3.8.0", "stackable.tech/vendor": "Stackable" }, "name": "my-opensearch-cluster-nodes-default", @@ -2130,7 +2130,7 @@ mod tests { "value": "$(_POD_NAME).my-opensearch-cluster-nodes-default-headless.default.svc.cluster.local" }, ], - "image": "oci.stackable.tech/sdp/opensearch:3.6.0-stackable0.0.0-dev", + "image": "oci.stackable.tech/sdp/opensearch:3.8.0-stackable0.0.0-dev", "imagePullPolicy": "Always", "name": "opensearch", "ports": [ @@ -2240,7 +2240,7 @@ mod tests { "value": "info", }, ], - "image": "oci.stackable.tech/sdp/opensearch:3.6.0-stackable0.0.0-dev", + "image": "oci.stackable.tech/sdp/opensearch:3.8.0-stackable0.0.0-dev", "imagePullPolicy": "Always", "name": "vector", "resources": { @@ -2325,7 +2325,7 @@ mod tests { }, }, ], - "image": "oci.stackable.tech/sdp/opensearch:3.6.0-stackable0.0.0-dev", + "image": "oci.stackable.tech/sdp/opensearch:3.8.0-stackable0.0.0-dev", "imagePullPolicy": "Always", "name": "update-security-config", "resources": { @@ -2436,7 +2436,7 @@ mod tests { "/bin/bash", "-c" ], - "image": "oci.stackable.tech/sdp/opensearch:3.6.0-stackable0.0.0-dev", + "image": "oci.stackable.tech/sdp/opensearch:3.8.0-stackable0.0.0-dev", "imagePullPolicy": "Always", "name": "init-keystore", "resources": {}, @@ -2476,7 +2476,7 @@ mod tests { }, }, ], - "image": "oci.stackable.tech/sdp/opensearch:3.6.0-stackable0.0.0-dev", + "image": "oci.stackable.tech/sdp/opensearch:3.8.0-stackable0.0.0-dev", "imagePullPolicy": "Always", "name": "create-admin-certificate", "resources": { @@ -3112,7 +3112,7 @@ mod tests { "app.kubernetes.io/managed-by": "opensearch.stackable.tech_opensearchcluster", "app.kubernetes.io/name": "opensearch", "app.kubernetes.io/role-group": "default", - "app.kubernetes.io/version": "3.6.0", + "app.kubernetes.io/version": "3.8.0", "stackable.tech/vendor": "Stackable", "restarter.stackable.tech/enabled": "true" }, @@ -3151,7 +3151,7 @@ mod tests { "app.kubernetes.io/managed-by": "opensearch.stackable.tech_opensearchcluster", "app.kubernetes.io/name": "opensearch", "app.kubernetes.io/role-group": "default", - "app.kubernetes.io/version": "3.6.0", + "app.kubernetes.io/version": "3.8.0", "stackable.tech/opensearch-role.cluster_manager": "true", "stackable.tech/opensearch-role.data": "true", "stackable.tech/opensearch-role.ingest": "true", @@ -3314,7 +3314,7 @@ mod tests { "app.kubernetes.io/managed-by": "opensearch.stackable.tech_opensearchcluster", "app.kubernetes.io/name": "opensearch", "app.kubernetes.io/role-group": "default", - "app.kubernetes.io/version": "3.6.0", + "app.kubernetes.io/version": "3.8.0", "prometheus.io/scrape": "true", "stackable.tech/vendor": "Stackable" }, @@ -3380,7 +3380,7 @@ mod tests { "app.kubernetes.io/managed-by": "opensearch.stackable.tech_opensearchcluster", "app.kubernetes.io/name": "opensearch", "app.kubernetes.io/role-group": "default", - "app.kubernetes.io/version": "3.6.0", + "app.kubernetes.io/version": "3.8.0", "stackable.tech/vendor": "Stackable" }, "name": "my-opensearch-cluster-nodes-default", diff --git a/rust/operator-binary/src/controller/preprocess.rs b/rust/operator-binary/src/controller/preprocess.rs index 3614eb15..21b2e8fa 100644 --- a/rust/operator-binary/src/controller/preprocess.rs +++ b/rust/operator-binary/src/controller/preprocess.rs @@ -88,7 +88,7 @@ mod tests { }, "spec": { "image": { - "productVersion": "3.6.0" + "productVersion": "3.8.0" }, "clusterConfig": { "security": { diff --git a/rust/operator-binary/src/controller/validate.rs b/rust/operator-binary/src/controller/validate.rs index 8e77abf4..16e13f56 100644 --- a/rust/operator-binary/src/controller/validate.rs +++ b/rust/operator-binary/src/controller/validate.rs @@ -501,20 +501,20 @@ mod tests { assert_eq!( Some(ValidatedCluster::new( ResolvedProductImage { - product_version: "3.6.0".to_owned(), + product_version: "3.8.0".to_owned(), app_version_label_value: LabelValue::from_str(&format!( - "3.6.0-stackable{pkg_version}", + "3.8.0-stackable{pkg_version}", pkg_version = built_info::PKG_VERSION )) .expect("should be a valid label value"), image: format!( - "oci.example.org/opensearch:3.6.0-stackable{pkg_version}", + "oci.example.org/opensearch:3.8.0-stackable{pkg_version}", pkg_version = built_info::PKG_VERSION ), image_pull_policy: "Always".to_owned(), pull_secrets: None, }, - ProductVersion::from_str_unsafe("3.6.0"), + ProductVersion::from_str_unsafe("3.8.0"), ClusterName::from_str_unsafe("my-opensearch"), NamespaceName::from_str_unsafe("default"), uuid!("e6ac237d-a6d4-43a1-8135-f36506110912"), @@ -1000,7 +1000,7 @@ mod tests { ..ObjectMeta::default() }, spec: v1alpha1::OpenSearchClusterSpec { - image: serde_json::from_str(r#"{"productVersion": "3.6.0"}"#) + image: serde_json::from_str(r#"{"productVersion": "3.8.0"}"#) .expect("should be a valid ProductImage structure"), cluster_config: v1alpha1::OpenSearchClusterConfig { tls: v1alpha1::OpenSearchTls::default(), diff --git a/rust/operator-binary/src/crd/roundtrip_test_data.yaml b/rust/operator-binary/src/crd/roundtrip_test_data.yaml index a75a6bea..d7738b26 100644 --- a/rust/operator-binary/src/crd/roundtrip_test_data.yaml +++ b/rust/operator-binary/src/crd/roundtrip_test_data.yaml @@ -1,6 +1,6 @@ --- image: - productVersion: 3.6.0 + productVersion: 3.8.0 pullPolicy: IfNotPresent clusterOperation: reconciliationPaused: false @@ -117,8 +117,8 @@ nodes: replicas: 2 --- image: - custom: oci.example.com/namespace/opensearch:3.6.0-custom - productVersion: 3.6.0 + custom: oci.example.com/namespace/opensearch:3.8.0-custom + productVersion: 3.8.0 pullPolicy: Always pullSecrets: - name: registry-credentials diff --git a/tests/templates/kuttl/backup-restore/22-create-testuser.yaml b/tests/templates/kuttl/backup-restore/22-create-testuser.yaml index 8284902f..730d13c9 100644 --- a/tests/templates/kuttl/backup-restore/22-create-testuser.yaml +++ b/tests/templates/kuttl/backup-restore/22-create-testuser.yaml @@ -16,7 +16,7 @@ spec: - -c args: - | - pip install opensearch-py==3.1.0 + pip install opensearch-py==3.2.0 python scripts/create-testuser.py env: # required for pip install diff --git a/tests/templates/kuttl/backup-restore/23-create-data.yaml b/tests/templates/kuttl/backup-restore/23-create-data.yaml index 33f4500c..3b312202 100644 --- a/tests/templates/kuttl/backup-restore/23-create-data.yaml +++ b/tests/templates/kuttl/backup-restore/23-create-data.yaml @@ -16,7 +16,7 @@ spec: - -c args: - | - pip install opensearch-py==3.1.0 + pip install opensearch-py==3.2.0 python scripts/create-data.py env: # required for pip install diff --git a/tests/templates/kuttl/backup-restore/30-create-snapshot.yaml b/tests/templates/kuttl/backup-restore/30-create-snapshot.yaml index b38c8517..791f5a7c 100644 --- a/tests/templates/kuttl/backup-restore/30-create-snapshot.yaml +++ b/tests/templates/kuttl/backup-restore/30-create-snapshot.yaml @@ -16,7 +16,7 @@ spec: - -c args: - | - pip install opensearch-py==3.1.0 + pip install opensearch-py==3.2.0 python scripts/create-snapshot.py env: # required for pip install @@ -90,7 +90,11 @@ data: "bucket": "opensearch-data", # The S3CrtClient that was introduced in OpenSearch 3.3.0, does not # work with a TLS-secured MinIO. Use the old Netty client instead. - "s3_async_client_type": "netty" + "s3_async_client_type": "netty", + # The default "server_side_encryption_type" changed from + # "bucket_default" to "AES256" in OpenSearch 3.8.0. MinIO requires + # "bucket_default". + "server_side_encryption_type": "bucket_default" } } ) diff --git a/tests/templates/kuttl/backup-restore/31-backup-security-indices.yaml.j2 b/tests/templates/kuttl/backup-restore/31-backup-security-indices.yaml.j2 index a4f38173..09723b63 100644 --- a/tests/templates/kuttl/backup-restore/31-backup-security-indices.yaml.j2 +++ b/tests/templates/kuttl/backup-restore/31-backup-security-indices.yaml.j2 @@ -47,7 +47,7 @@ spec: cpu: 400m containers: - name: upload-security-indices-backup - image: minio/mc:RELEASE.2025-08-13T08-35-41Z + image: pgsty/mc:RELEASE.2026-09-16T00-00-00Z command: - /root/scripts/upload-security-indices-backup.sh env: @@ -78,7 +78,7 @@ spec: capabilities: drop: - ALL - # The image minio/mc runs as root. + # The image pgsty/mc runs as root. runAsNonRoot: false resources: requests: diff --git a/tests/templates/kuttl/backup-restore/60-restore-security-indices.yaml.j2 b/tests/templates/kuttl/backup-restore/60-restore-security-indices.yaml.j2 index be6d7669..e419cd41 100644 --- a/tests/templates/kuttl/backup-restore/60-restore-security-indices.yaml.j2 +++ b/tests/templates/kuttl/backup-restore/60-restore-security-indices.yaml.j2 @@ -8,7 +8,7 @@ spec: spec: initContainers: - name: download-security-indices-backup - image: minio/mc:RELEASE.2025-08-13T08-35-41Z + image: pgsty/mc:RELEASE.2026-09-16T00-00-00Z command: - /root/scripts/download-security-indices-backup.sh env: @@ -39,7 +39,7 @@ spec: capabilities: drop: - ALL - # The image minio/mc runs as root. + # The image pgsty/mc runs as root. runAsNonRoot: false resources: requests: diff --git a/tests/templates/kuttl/backup-restore/61-restore-snapshot.yaml b/tests/templates/kuttl/backup-restore/61-restore-snapshot.yaml index d436b669..ee92cb53 100644 --- a/tests/templates/kuttl/backup-restore/61-restore-snapshot.yaml +++ b/tests/templates/kuttl/backup-restore/61-restore-snapshot.yaml @@ -16,7 +16,7 @@ spec: - -c args: - | - pip install opensearch-py==3.1.0 + pip install opensearch-py==3.2.0 python scripts/restore-snapshot.py env: # required for pip install @@ -90,7 +90,11 @@ data: "bucket": "opensearch-data", # The S3CrtClient that was introduced in OpenSearch 3.3.0, does not # work with a TLS-secured MinIO. Use the old Netty client instead. - "s3_async_client_type": "netty" + "s3_async_client_type": "netty", + # The default "server_side_encryption_type" changed from + # "bucket_default" to "AES256" in OpenSearch 3.8.0. MinIO requires + # "bucket_default". + "server_side_encryption_type": "bucket_default" } } ) diff --git a/tests/templates/kuttl/backup-restore/70-test-opensearch-2.yaml b/tests/templates/kuttl/backup-restore/70-test-opensearch-2.yaml index 37a3f02d..d5053be8 100644 --- a/tests/templates/kuttl/backup-restore/70-test-opensearch-2.yaml +++ b/tests/templates/kuttl/backup-restore/70-test-opensearch-2.yaml @@ -16,7 +16,7 @@ spec: - -c args: - | - pip install opensearch-py==3.1.0 + pip install opensearch-py==3.2.0 python scripts/test-opensearch-2.py env: # required for pip install diff --git a/tests/templates/kuttl/opensearch-dashboards/20_opensearch-dashboards-values.yaml.j2 b/tests/templates/kuttl/opensearch-dashboards/20_opensearch-dashboards-values.yaml.j2 index a92a838e..84e3e074 100644 --- a/tests/templates/kuttl/opensearch-dashboards/20_opensearch-dashboards-values.yaml.j2 +++ b/tests/templates/kuttl/opensearch-dashboards/20_opensearch-dashboards-values.yaml.j2 @@ -11,6 +11,11 @@ serviceAccount: # OPENSEARCH_HOSTS cannot be supplied if opensearchHosts is set (so unset explicitly). # See https://github.com/opensearch-project/helm-charts/blob/main/charts/opensearch-dashboards/templates/deployment.yaml#L122 opensearchHosts: "" +resources: + requests: + cpu: 500m + limits: + cpu: "1" extraEnvs: - name: OPENSEARCH_HOSTS valueFrom: diff --git a/tests/test-definition.yaml b/tests/test-definition.yaml index a7395e79..f178a936 100644 --- a/tests/test-definition.yaml +++ b/tests/test-definition.yaml @@ -3,11 +3,11 @@ dimensions: - name: opensearch values: - 3.1.0 - - 3.4.0 - 3.6.0 + - 3.8.0 # To use a custom image, add a comma and the full name after the product version, e.g.: - # - 3.6.0,oci.stackable.tech/sandbox/opensearch:3.6.0-stackable0.0.0-dev - # - 3.6.0,localhost:5000/sdp/opensearch:3.6.0-stackable0.0.0-dev + # - 3.8.0,oci.stackable.tech/sandbox/opensearch:3.8.0-stackable0.0.0-dev + # - 3.8.0,localhost:5000/sdp/opensearch:3.8.0-stackable0.0.0-dev - name: opensearch_home values: - /stackable/opensearch @@ -97,6 +97,6 @@ suites: patch: - dimensions: - name: opensearch - expr: 3.6.0,opensearchproject/opensearch:3.6.0 + expr: 3.8.0,opensearchproject/opensearch:3.8.0 - name: opensearch_home expr: /usr/share/opensearch