Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
50 commits
Select commit Hold shift + click to select a range
2a83759
SK-3037 report the real cause when tokenize or delete never reach the…
saileshwar-skyflow Aug 3, 2026
5a4a8f5
[AUTOMATED] Private Release 3.0.0-beta.13-dev-2a83759e
saileshwar-skyflow Aug 3, 2026
58dda85
SK-3026 add tests
skyflow-bharti Aug 3, 2026
a898994
[AUTOMATED] Private Release 3.0.0-beta.13-dev-58dda850
skyflow-bharti Aug 3, 2026
1ff9144
SK-3026 add tests
skyflow-bharti Aug 3, 2026
ff4c29c
[AUTOMATED] Private Release 3.0.0-beta.13-dev-1ff91444
skyflow-bharti Aug 3, 2026
ef9fa59
SK-2967 Backport pr-flowvault.yml CI workflow (#391)
Devesh-Skyflow Aug 3, 2026
408c1dd
[AUTOMATED] Private Release 3.0.0-beta.13-dev-ef9fa592
Devesh-Skyflow Aug 3, 2026
50bd81f
Merge branch 'main' into flowvault-release/26.8.1
skyflow-bharti Aug 3, 2026
ae3d89d
SK-3037 add bulk tokenize and delete-tokens samples (#395)
saileshwar-skyflow Aug 3, 2026
1bdb24b
SK-3026 update custom header naming convention
skyflow-bharti Aug 3, 2026
b05ef4f
SK-3026 fix workfow
skyflow-bharti Aug 3, 2026
6085956
[AUTOMATED] Private Release 3.0.0-beta.13-dev-b05ef4fb
skyflow-bharti Aug 3, 2026
e8e0e2d
[AUTOMATED] Private Release 3.0.0-beta.13-dev-60859567
skyflow-bharti Aug 3, 2026
eb82be1
[AUTOMATED] Private Release 3.0.0-beta.13-dev-e8e0e2d0
skyflow-bharti Aug 3, 2026
496c83a
[AUTOMATED] Private Release 3.0.0-beta.13-dev-eb82be1b
skyflow-bharti Aug 3, 2026
5ddc562
[AUTOMATED] Private Release 3.0.0-beta.13-dev-496c83a0
skyflow-bharti Aug 3, 2026
e6552a0
[AUTOMATED] Private Release 3.0.0-beta.13-dev-5ddc5628
skyflow-bharti Aug 3, 2026
c804c74
[AUTOMATED] Private Release 3.0.0-beta.13-dev-e6552a0a
skyflow-bharti Aug 3, 2026
6ff46f0
[AUTOMATED] Private Release 3.0.0-beta.13-dev-c804c748
skyflow-bharti Aug 3, 2026
291b820
[AUTOMATED] Private Release 3.0.0-beta.13-dev-6ff46f02
skyflow-bharti Aug 3, 2026
99612f5
[AUTOMATED] Private Release 3.0.0-beta.13-dev-291b8206
skyflow-bharti Aug 3, 2026
674f7b0
[AUTOMATED] Private Release 3.0.0-beta.13-dev-99612f55
skyflow-bharti Aug 3, 2026
068e293
[AUTOMATED] Private Release 3.0.0-beta.13-dev-674f7b00
skyflow-bharti Aug 3, 2026
1af848a
[AUTOMATED] Private Release 3.0.0-beta.13-dev-068e293a
skyflow-bharti Aug 3, 2026
821cc99
[AUTOMATED] Private Release 3.0.0-beta.13-dev-1af848a0
skyflow-bharti Aug 3, 2026
610b8f2
[AUTOMATED] Private Release 3.0.0-beta.13-dev-821cc992
skyflow-bharti Aug 3, 2026
43f0ba6
[AUTOMATED] Private Release 3.0.0-beta.13-dev-610b8f21
skyflow-bharti Aug 3, 2026
f973782
[AUTOMATED] Private Release 3.0.0-beta.13-dev-43f0ba69
skyflow-bharti Aug 3, 2026
6ea42d7
[AUTOMATED] Private Release 3.0.0-beta.13-dev-f9737826
skyflow-bharti Aug 3, 2026
dbbdb73
[AUTOMATED] Private Release 3.0.0-beta.13-dev-6ea42d7c
skyflow-bharti Aug 3, 2026
c22ffe1
SK-2967 restore the [AUTOMATED] loop guard to stop the release recursion
Devesh-Skyflow Aug 3, 2026
2e606ce
Split READMEs per package and resolve flowvault README review (#396)
Devesh-Skyflow Aug 3, 2026
2d54cf9
[AUTOMATED] Private Release 3.0.0-beta.13-dev-2e606ceb
Devesh-Skyflow Aug 3, 2026
18f8f1b
SK-2967 trim verbose comments in the release workflows
Devesh-Skyflow Aug 3, 2026
7e049c6
[AUTOMATED] Private Release 3.0.0-beta.13-dev-18f8f1ba
Devesh-Skyflow Aug 3, 2026
ecf6b4b
SK-3026 update samples
skyflow-bharti Aug 3, 2026
9cfa2c9
[AUTOMATED] Private Release 3.0.0-beta.13-dev-ecf6b4be
skyflow-bharti Aug 3, 2026
962614b
SK-3037 run contract tests for flowvault, and gate on the public API …
saileshwar-skyflow Aug 3, 2026
53bcb86
[AUTOMATED] Private Release 3.0.0-beta.13-dev-962614b1
saileshwar-skyflow Aug 3, 2026
dda2bac
SK-3026 remove unused tokens key in insert
skyflow-bharti Aug 3, 2026
60f44cc
[AUTOMATED] Private Release 3.0.0-beta.13-dev-dda2bace
skyflow-bharti Aug 3, 2026
46cbffa
SK-3026 fix tests
skyflow-bharti Aug 3, 2026
0abbbb4
[AUTOMATED] Private Release 3.0.0-beta.13-dev-46cbffad
skyflow-bharti Aug 3, 2026
7e97883
Merge branch 'flowvault-release/26.8.1' into flowvault-release/26.8.1.1
skyflow-bharti Aug 3, 2026
78fb577
[AUTOMATED] Private Release 3.0.0-beta.13-dev-7e97883a
skyflow-bharti Aug 3, 2026
7c0fb7b
SK-3026 added tokens support
skyflow-bharti Aug 3, 2026
c784ff3
[AUTOMATED] Private Release 3.0.0-beta.13-dev-7c0fb7be
skyflow-bharti Aug 3, 2026
c731182
Merge pull request #399 from skyflowapi/flowvault-release/26.8.1.1
skyflow-bharti Aug 3, 2026
a496119
[AUTOMATED] Private Release 3.0.0-beta.13-dev-c7311820
skyflow-bharti Aug 3, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 3 additions & 1 deletion .cspell.json
Original file line number Diff line number Diff line change
Expand Up @@ -108,7 +108,9 @@
"deserialised",
"unmodelled",
"recordss",
"rarr"
"rarr",
"servname",
"nodename"
],
"languageSettings": [
{
Expand Down
20 changes: 0 additions & 20 deletions .github/workflows/beta-release.yml

This file was deleted.

90 changes: 69 additions & 21 deletions .github/workflows/contract-tests.yml
Original file line number Diff line number Diff line change
Expand Up @@ -5,12 +5,24 @@ on:
branches:
- main
- release/*
- flowvault-release/*

jobs:
contract-tests:
name: Contract Tests
# One job per module so a break in one is reported against that module by name,
# and both still run even when the other fails.
name: Contract Tests (${{ matrix.module }})
runs-on: ubuntu-latest

strategy:
fail-fast: false
matrix:
include:
- module: skyvault
artifact: skyflow-java
- module: flowvault
artifact: skyflow-flowvault-java

permissions:
contents: read
pull-requests: write
Expand All @@ -29,29 +41,31 @@ jobs:
cache: 'maven'

- name: Verify API surface snapshot
run: mvn -B install -pl common,skyvault -am -DskipTests -Dmaven.javadoc.skip=true -Dgpg.skip=true
run: mvn -B install -pl common,${{ matrix.module }} -am -DskipTests -Dmaven.javadoc.skip=true -Dgpg.skip=true

- name: Show API surface diff
if: failure()
run: |
echo "### API surface changes detected ###"
echo "See skyvault/target/japicmp/default-cli.diff for the full comparison against skyvault/api-report/skyflow-java.baseline.jar."
echo "If this change is intentional, run scripts/contract-snapshot-update.sh and commit the updated baseline jar."
echo "### API surface changes detected in ${{ matrix.module }} ###"
echo "Compared against ${{ matrix.module }}/api-report/${{ matrix.artifact }}.baseline.jar."
echo "If this change is intentional, run:"
echo " scripts/contract-snapshot-update.sh ${{ matrix.module }}"
echo "and commit the updated baseline jar."
echo ""
cat skyvault/target/japicmp/default-cli.diff || true
cat ${{ matrix.module }}/target/japicmp/default-cli.diff || true

- name: Upload API surface diff on failure
if: failure()
uses: actions/upload-artifact@v4
with:
name: api-surface-diff
path: skyvault/target/japicmp/**
name: api-surface-diff-${{ matrix.module }}
path: ${{ matrix.module }}/target/japicmp/**
retention-days: 7

# The step above only shows a diff when the CURRENT build differs from the
# committed baseline - once someone runs contract-snapshot-update.sh and
# commits the refreshed baseline jar, that check goes green and shows nothing.
# A reviewer looking at a green PR that touches api-report/skyflow-java.baseline.jar
# A reviewer looking at a green PR that touches api-report/*.baseline.jar
# (a binary file) would otherwise have no way to see WHAT was just approved as
# the new contract. These steps explicitly diff the OLD committed baseline
# (from the PR's base branch) against the NEW committed baseline (from this PR)
Expand All @@ -61,40 +75,74 @@ jobs:
if: always() && github.event.pull_request
run: |
git fetch origin "${{ github.event.pull_request.base.ref }}" --depth=1
if git diff --name-only "origin/${{ github.event.pull_request.base.ref }}" HEAD -- skyvault/api-report/skyflow-java.baseline.jar | grep -q .; then
BASELINE="${{ matrix.module }}/api-report/${{ matrix.artifact }}.baseline.jar"
if ! git diff --name-only "origin/${{ github.event.pull_request.base.ref }}" HEAD -- "$BASELINE" | grep -q .; then
echo "changed=false" >> "$GITHUB_OUTPUT"
elif git cat-file -e "origin/${{ github.event.pull_request.base.ref }}:$BASELINE" 2>/dev/null; then
echo "changed=true" >> "$GITHUB_OUTPUT"
else
echo "changed=false" >> "$GITHUB_OUTPUT"
# Added by this PR rather than modified: the module is getting its
# first baseline. git diff reports an addition as a change, but there
# is no old snapshot to `git show`, so a plain "true" here would send
# the next step into `git show <base>:<path>` and exit 128.
echo "changed=new" >> "$GITHUB_OUTPUT"
fi

- name: Diff old vs new contract baseline
if: always() && steps.baseline-diff-check.outputs.changed == 'true'
if: always() && (steps.baseline-diff-check.outputs.changed == 'true' || steps.baseline-diff-check.outputs.changed == 'new')
run: |
BASELINE="${{ matrix.module }}/api-report/${{ matrix.artifact }}.baseline.jar"

if [ "${{ steps.baseline-diff-check.outputs.changed }}" = "new" ]; then
{
echo "\`$BASELINE\` is **new in this PR** - \`${{ matrix.module }}\` had no committed baseline before, so there is nothing to diff against."
echo ""
echo "This snapshot becomes the approved contract: every later PR is compared against it, and any incompatible change fails the \`Contract Tests (${{ matrix.module }})\` job until someone regenerates it deliberately. Review it as the starting point, not as a change."
} > /tmp/contract-baseline-diff.md
cat /tmp/contract-baseline-diff.md
exit 0
fi

curl -sL -o /tmp/japicmp-cli.jar "https://repo.maven.apache.org/maven2/com/github/siom79/japicmp/japicmp/0.26.0/japicmp-0.26.0-jar-with-dependencies.jar"
mvn -q -B dependency:build-classpath -pl skyvault -Dmdep.outputFile=/tmp/skyvault-classpath.txt -Dmaven.javadoc.skip=true -Dgpg.skip=true
git show "origin/${{ github.event.pull_request.base.ref }}:skyvault/api-report/skyflow-java.baseline.jar" > /tmp/old-baseline.jar
mvn -q -B dependency:build-classpath -pl ${{ matrix.module }} -Dmdep.outputFile=/tmp/module-classpath.txt -Dmaven.javadoc.skip=true -Dgpg.skip=true
git show "origin/${{ github.event.pull_request.base.ref }}:$BASELINE" > /tmp/old-baseline.jar

# Same allowlist the poms gate on, so the comment shows the contract and
# nothing else. Keep these in sync with the <includes> in the module poms.
java -jar /tmp/japicmp-cli.jar \
-o /tmp/old-baseline.jar \
-n skyvault/api-report/skyflow-java.baseline.jar \
-n "$BASELINE" \
-a protected \
-e "com.skyflow.generated.*;com.skyflow.utils.*" \
--old-classpath "$(cat /tmp/skyvault-classpath.txt)" \
--new-classpath "$(cat /tmp/skyvault-classpath.txt)" \
-i "com.skyflow.Skyflow;com.skyflow.config;com.skyflow.enums;com.skyflow.errors;com.skyflow.serviceaccount.util;com.skyflow.vault.audit;com.skyflow.vault.bin;com.skyflow.vault.connection;com.skyflow.vault.controller;com.skyflow.vault.data;com.skyflow.vault.detect;com.skyflow.vault.tokens" \
--old-classpath "$(cat /tmp/module-classpath.txt)" \
--new-classpath "$(cat /tmp/module-classpath.txt)" \
-m \
--ignore-missing-classes \
--markdown > /tmp/contract-baseline-diff.md || true

cat /tmp/contract-baseline-diff.md

- name: Comment contract baseline change on PR
if: always() && steps.baseline-diff-check.outputs.changed == 'true'
if: always() && (steps.baseline-diff-check.outputs.changed == 'true' || steps.baseline-diff-check.outputs.changed == 'new')
uses: actions/github-script@v7
env:
BASELINE_STATE: ${{ steps.baseline-diff-check.outputs.changed }}
with:
script: |
const fs = require('fs');
const module = '${{ matrix.module }}';
const artifact = '${{ matrix.artifact }}';
const summary = fs.readFileSync('/tmp/contract-baseline-diff.md', 'utf8');
const marker = '<!-- contract-baseline-diff -->';
const body = `${marker}\n## Contract baseline change detected\n\nThis PR updates \`skyvault/api-report/skyflow-java.baseline.jar\` (the approved public API contract). Here is exactly what it changes, comparing the baseline on \`${{ github.event.pull_request.base.ref }}\` against the baseline committed in this PR:\n\n${summary}`;
// per-module marker so the two matrix jobs update their own comment
const marker = `<!-- contract-baseline-diff:${module} -->`;
const isNew = process.env.BASELINE_STATE === 'new';
const heading = isNew
? `## Contract baseline added (\`${module}\`)`
: `## Contract baseline change detected (\`${module}\`)`;
const preamble = isNew
? `This PR adds \`${module}/api-report/${artifact}.baseline.jar\`, the approved public API contract for this module.`
: `This PR updates \`${module}/api-report/${artifact}.baseline.jar\` (the approved public API contract). Here is exactly what it changes, comparing the baseline on \`${{ github.event.pull_request.base.ref }}\` against the baseline committed in this PR:`;
const body = `${marker}\n${heading}\n\n${preamble}\n\n${summary}`;
const { data: comments } = await github.rest.issues.listComments({
owner: context.repo.owner,
repo: context.repo.repo,
Expand Down
33 changes: 26 additions & 7 deletions .github/workflows/internal-release.yml
Original file line number Diff line number Diff line change
@@ -1,28 +1,45 @@
name: Publish module to the JFROG Artifactory
on:
push:
# '**' not '*.*': Actions glob '*' does not match '/', so '*.*' let slash
# tags (flowvault/v1.0.0) through and fired this branch-only workflow.
tags-ignore:
- '*.*'
- '**'
paths-ignore:
- "*.md"
branches:
- release/*
- flowvault-release/*
- skyvault-release/*
# Legacy: predates the per-module naming, still maps to skyvault.
- release/*

jobs:
resolve-module:
runs-on: ubuntu-latest
# Skip our own bump commit, or this loops: bump -> push -> release -> bump.
# PAT-authenticated pushes DO trigger workflows; GITHUB_TOKEN pushes do not.
# build-and-deploy needs this job, so skipping here skips the run.
if: ${{ !contains(github.event.head_commit.message, '[AUTOMATED]') }}
outputs:
module: ${{ steps.set-module.outputs.module }}
steps:
# Explicit match, no catch-all: defaulting once published the wrong module.
- name: Resolve module from branch name
id: set-module
env:
BRANCH: ${{ github.ref_name }}
run: |
if [[ "${{ github.ref_name }}" == flowvault-release/* ]]; then
echo "module=flowvault" >> "$GITHUB_OUTPUT"
else
echo "module=skyvault" >> "$GITHUB_OUTPUT"
fi
case "$BRANCH" in
flowvault-release/*) MODULE="flowvault" ;;
skyvault-release/*) MODULE="skyvault" ;;
release/*) MODULE="skyvault" ;;
*)
echo "::error::Branch '$BRANCH' does not map to a module."
exit 1
;;
esac
echo "Branch '$BRANCH' -> module '$MODULE'"
echo "module=$MODULE" >> "$GITHUB_OUTPUT"

build-and-deploy:
needs: resolve-module
Expand All @@ -41,3 +58,5 @@ jobs:
skyflow-credentials: ${{ secrets.SKYFLOW_CREDENTIALS }}
test-expired-token: ${{ secrets.TEST_EXPIRED_TOKEN }}
test-reusable-token: ${{ secrets.TEST_REUSABLE_TOKEN }}
pat-actions: ${{ secrets.PAT_ACTIONS }}
test-credentials-file-string: ${{ secrets.TEST_CREDENTIALS_FILE_STRING }}
86 changes: 86 additions & 0 deletions .github/workflows/pr-flowvault.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,86 @@
name: PR CI Checks (flowvault)

# flowvault is a folder under main, alongside skyvault - not a branch.
# This workflow fires for PRs targeting main or a flowvault-release/* branch
# that actually touch flowvault or its common dependency, and only builds/tests
# those two modules. skyvault is covered by pr.yml, not here.

on:
pull_request:
branches: [ "main", "flowvault-release/**" ]
paths:
- "flowvault/**"
- "common/**"
- "pom.xml"

jobs:
build:
name: Build
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4

- uses: actions/setup-java@v4
with:
distribution: "temurin"
java-version: "11"
cache: "maven"

# package (not verify/install) deliberately stops short of any japicmp
# contract gate bound to a module's `verify` phase - that's a separate
# check. This job only proves flowvault (and common) compile and package.
- name: Build flowvault
run: |
mvn -B -Dorg.slf4j.simpleLogger.log.org.apache.maven.cli.transfer.Slf4jMavenTransferListener=warn \
clean package -pl flowvault -am -DskipTests -Dmaven.javadoc.skip=true -Dgpg.skip=true

test:
name: Unit Tests
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4

- uses: actions/setup-java@v4
with:
distribution: "temurin"
java-version: "11"
cache: "maven"

- name: create-json
id: create-json
uses: jsdaniell/create-json@1.1.2
with:
name: "credentials.json"
json: ${{ secrets.TEST_CREDENTIALS_FILE_STRING }}

- name: create env
id: create-env
run: |
for dir in common flowvault; do
if [ -f "$dir/pom.xml" ]; then
cp credentials.json "$dir/credentials.json"
{
echo "SKYFLOW_CREDENTIALS=${{ secrets.SKYFLOW_CREDENTIALS }}"
echo "TEST_EXPIRED_TOKEN=${{ secrets.TEST_EXPIRED_TOKEN }}"
echo "TEST_REUSABLE_TOKEN=${{ secrets.TEST_REUSABLE_TOKEN }}"
} >> "$dir/.env"
fi
done

# jacoco:report is already bound to the `test` phase in the root pom
# (prepare-agent + report executions), so `mvn test` alone regenerates
# coverage - no need to invoke jacoco:report again on the command line.
- name: Run flowvault unit tests
run: |
mvn -B -Dorg.slf4j.simpleLogger.log.org.apache.maven.cli.transfer.Slf4jMavenTransferListener=warn \
clean test -pl flowvault -am -Dmaven.javadoc.skip=true -Dgpg.skip=true

- name: Codecov
uses: codecov/codecov-action@v5
with:
token: ${{ secrets.CODECOV_REPO_UPLOAD_TOKEN }}
files: flowvault/target/site/jacoco/jacoco.xml
flags: unittests-flowvault
name: codecov-skyflow-java-flowvault
fail_ci_if_error: true
verbose: true
Loading
Loading