This is an automated email from the ASF dual-hosted git repository.
potiuk pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/airflow.git
The following commit(s) were added to refs/heads/main by this push:
new 4329cd68465 Pause v3-4-test automation while it is fast-forwarded for
3.4.0 betas (#74327)
4329cd68465 is described below
commit 4329cd68465e0c15dbc8f59d9d783657e9332651
Author: Jarek Potiuk <[email protected]>
AuthorDate: Tue Oct 6 11:01:43 2026 +0200
Pause v3-4-test automation while it is fast-forwarded for 3.4.0 betas
(#74327)
* Pause v3-4-test automation while it is fast-forwarded for 3.4.0 betas
During the 3.4.0 beta phase v3-4-test is moved forward to main rather than
receiving cherry-picks. Any commit added directly to the branch - an
automated
CI upgrade PR such as #74324, a Dependabot bump or an automatic backport -
makes it diverge from main and breaks the next fast-forward, while the same
change reaches the branch from main anyway.
The release instructions did not describe this phase, so they now explain
when it starts and ends and what has to be paused and re-enabled around it.
Generated-by: Claude Opus 5
* Call out re-enabling v3-4-test automation when RCs start
Generated-by: Claude Opus 5
---
.github/boring-cyborg.yml | 29 +++++++------
.github/dependabot.yml | 21 +++++++++
.github/workflows/automatic-backport.yml | 14 +++++-
.../scheduled-upgrade-check-v3-4-test.yml | 9 ++--
dev/README_RELEASE_AIRFLOW.md | 50 ++++++++++++++++++++++
5 files changed, 106 insertions(+), 17 deletions(-)
diff --git a/.github/boring-cyborg.yml b/.github/boring-cyborg.yml
index 7ab7202c442..13938591de4 100644
--- a/.github/boring-cyborg.yml
+++ b/.github/boring-cyborg.yml
@@ -373,23 +373,26 @@ labelPRBasedOnFilePath:
- .rat-excludes
- .readthedocs.yml
+ # Paused while v3-4-test is fast-forwarded to main for the 3.4.0 betas -
nothing is
+ # cherry-picked yet. Uncomment when the 3.4.0 RCs start (see "Beta releases"
in
+ # dev/README_RELEASE_AIRFLOW.md).
# This should be copy of the "area:dev-tools" above minus contributing docs
and some files that should
# only make sense in main - it should be updated when we switch maintenance
branch.
# Scoped to PRs targeting `main` only — a PR opened directly against
v3-4-test
# does not need a backport-to-v3-4-test label.
- backport-to-v3-4-test:
- paths:
- - scripts/**/*
- - dev/**/*
- - .github/**/*
- - Dockerfile.ci
- - yamllint-config.yml
- - .dockerignore
- - .hadolint.yaml
- - .pre-commit-config.yaml
- - .rat-excludes
- targetBranchFilter:
- - ^main$
+ # backport-to-v3-4-test:
+ # paths:
+ # - scripts/**/*
+ # - dev/**/*
+ # - .github/**/*
+ # - Dockerfile.ci
+ # - yamllint-config.yml
+ # - .dockerignore
+ # - .hadolint.yaml
+ # - .pre-commit-config.yaml
+ # - .rat-excludes
+ # targetBranchFilter:
+ # - ^main$
# Apply to PRs touching airflow-ctl code so the release manager notices when
a
# fix should land on the airflow-ctl/v0-1-test maintenance branch.
diff --git a/.github/dependabot.yml b/.github/dependabot.yml
index c310b473518..64fdc6f08b0 100644
--- a/.github/dependabot.yml
+++ b/.github/dependabot.yml
@@ -46,6 +46,9 @@ updates:
# Check for updates to GitHub Actions every week
interval: "weekly"
target-branch: v3-4-test
+ # Paused while v3-4-test is fast-forwarded to main for the 3.4.0 betas -
remove when the
+ # 3.4.0 RCs start (see "Beta releases" in dev/README_RELEASE_AIRFLOW.md).
+ open-pull-requests-limit: 0
groups:
github-actions-updates:
patterns:
@@ -265,6 +268,9 @@ updates:
schedule:
interval: daily
target-branch: v3-4-test
+ # Paused while v3-4-test is fast-forwarded to main for the 3.4.0 betas -
remove when the
+ # 3.4.0 RCs start (see "Beta releases" in dev/README_RELEASE_AIRFLOW.md).
+ open-pull-requests-limit: 0
groups:
pip-dependency-updates:
patterns:
@@ -278,6 +284,9 @@ updates:
schedule:
interval: "weekly"
target-branch: v3-4-test
+ # Paused while v3-4-test is fast-forwarded to main for the 3.4.0 betas -
remove when the
+ # 3.4.0 RCs start (see "Beta releases" in dev/README_RELEASE_AIRFLOW.md).
+ open-pull-requests-limit: 0
groups:
3-4-core-ui-package-updates:
patterns:
@@ -297,6 +306,9 @@ updates:
schedule:
interval: "weekly"
target-branch: v3-4-test
+ # Paused while v3-4-test is fast-forwarded to main for the 3.4.0 betas -
remove when the
+ # 3.4.0 RCs start (see "Beta releases" in dev/README_RELEASE_AIRFLOW.md).
+ open-pull-requests-limit: 0
groups:
3-4-auth-ui-package-updates:
patterns:
@@ -325,6 +337,9 @@ updates:
schedule:
interval: "weekly"
target-branch: v3-4-test
+ # Paused while v3-4-test is fast-forwarded to main for the 3.4.0 betas -
remove when the
+ # 3.4.0 RCs start (see "Beta releases" in dev/README_RELEASE_AIRFLOW.md).
+ open-pull-requests-limit: 0
groups:
3-4-registry-package-updates:
patterns:
@@ -344,6 +359,9 @@ updates:
schedule:
interval: "weekly"
target-branch: v3-4-test
+ # Paused while v3-4-test is fast-forwarded to main for the 3.4.0 betas -
remove when the
+ # 3.4.0 RCs start (see "Beta releases" in dev/README_RELEASE_AIRFLOW.md).
+ open-pull-requests-limit: 0
groups:
3-4-ui-plugin-template-package-updates:
patterns:
@@ -362,6 +380,9 @@ updates:
schedule:
interval: "weekly"
target-branch: v3-4-test
+ # Paused while v3-4-test is fast-forwarded to main for the 3.4.0 betas -
remove when the
+ # 3.4.0 RCs start (see "Beta releases" in dev/README_RELEASE_AIRFLOW.md).
+ open-pull-requests-limit: 0
groups:
3-4-uv-dependency-updates:
patterns:
diff --git a/.github/workflows/automatic-backport.yml
b/.github/workflows/automatic-backport.yml
index daa142e9dfc..a80d350e707 100644
--- a/.github/workflows/automatic-backport.yml
+++ b/.github/workflows/automatic-backport.yml
@@ -48,8 +48,13 @@ jobs:
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3
# v9.0.0
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ # Branches fast-forwarded to main during a beta phase - a backport
PR there would make
+ # them diverge from main. Empty this list when the RCs start (see
"Beta releases"
+ # in dev/README_RELEASE_AIRFLOW.md).
+ BACKPORT_PAUSED_BRANCHES: '["v3-4-test"]'
with:
script: |
+ const pausedBranches =
JSON.parse(process.env.BACKPORT_PAUSED_BRANCHES);
const { data: pullRequest } = await
github.rest.repos.listPullRequestsAssociatedWithCommit({
owner: context.repo.owner,
repo: context.repo.repo,
@@ -59,7 +64,14 @@ jobs:
const pr = pullRequest[0];
const backportBranches = pr.labels
.filter(label => label.name.startsWith('backport-to-'))
- .map(label => label.name.replace('backport-to-', ''));
+ .map(label => label.name.replace('backport-to-', ''))
+ .filter(branch => {
+ if (pausedBranches.includes(branch)) {
+ console.log(`⚠️ Skipping backport to ${branch}:
backports to it are paused.`);
+ return false;
+ }
+ return true;
+ });
console.log(`Commit ${process.env.GITHUB_SHA} is associated
with PR ${pr.number}`);
console.log(`Backport branches: ${backportBranches}`);
diff --git a/.github/workflows/scheduled-upgrade-check-v3-4-test.yml
b/.github/workflows/scheduled-upgrade-check-v3-4-test.yml
index 604fcb2ed8f..723ec6e41e8 100644
--- a/.github/workflows/scheduled-upgrade-check-v3-4-test.yml
+++ b/.github/workflows/scheduled-upgrade-check-v3-4-test.yml
@@ -18,9 +18,12 @@
---
name: "[v3-4-test] Scheduled CI upgrade check"
on: # yamllint disable-line rule:truthy
- schedule:
- # Tue, Thu at 06:00 UTC — the days main does not run, so the two never
overlap.
- - cron: '0 6 * * 2,4'
+ # Schedule paused while v3-4-test is fast-forwarded to main for the 3.4.0
betas - upgrades
+ # land on main and reach v3-4-test with the next fast-forward. Re-enable
when the 3.4.0
+ # RCs start (see "Beta releases" in dev/README_RELEASE_AIRFLOW.md).
+ # schedule:
+ # # Tue, Thu at 06:00 UTC — the days main does not run, so the two never
overlap.
+ # - cron: '0 6 * * 2,4'
workflow_dispatch:
permissions:
contents: write
diff --git a/dev/README_RELEASE_AIRFLOW.md b/dev/README_RELEASE_AIRFLOW.md
index 8516657ab9d..059e3f2f26e 100644
--- a/dev/README_RELEASE_AIRFLOW.md
+++ b/dev/README_RELEASE_AIRFLOW.md
@@ -23,6 +23,7 @@
- [Collect ambiguities during the release (for a follow-up doc
PR)](#collect-ambiguities-during-the-release-for-a-follow-up-doc-pr)
- [Perform review of security issues that are marked for the
release](#perform-review-of-security-issues-that-are-marked-for-the-release)
- [Selecting what to put into the
release](#selecting-what-to-put-into-the-release)
+ - [Beta releases: fast-forwarding `vX-Y-test` to
`main`](#beta-releases-fast-forwarding-vx-y-test-to-main)
- [i18n workflow](#i18n-workflow)
- [Selecting what to cherry-pick](#selecting-what-to-cherry-pick)
- [Making the cherry picking](#making-the-cherry-picking)
@@ -104,6 +105,40 @@ The first step of a release is to work out what is being
included. This differs
- For a *patch* release, you will be selecting specific commits to cherry-pick
and backport into the existing release branch.
+## Beta releases: fast-forwarding `vX-Y-test` to `main`
+
+For a *major* or *minor* release, the `vX-Y-test` branch is created early (see
+[Build RC artifacts](#build-rc-artifacts)), but while the beta releases
(`X.Y.0b1`, `X.Y.0b2`, ...)
+are being prepared nothing is cherry-picked to it yet. Instead, the release
manager periodically
+moves `vX-Y-test` forward to the current `main` - only the branch-specific
commits (such as
+`Update default branches for X.Y`) are kept on top of `main`. Each beta is cut
from the branch
+in that state, so everything merged to `main` lands in the next beta.
+
+During this phase, all automation that would add commits directly to
`vX-Y-test` must be paused -
+any such commit makes `vX-Y-test` diverge from `main` and breaks the next
fast-forward. Upgrades and
+fixes land on `main` only and reach `vX-Y-test` with the next fast-forward.
When you add the new
+branch to the `.github/` configuration on `main` (see below), pause the
following on `main` for
+`vX-Y-test` at the same time (every paused place is marked with a comment
pointing to this section):
+
+- `.github/workflows/scheduled-upgrade-check-vX-Y-test.yml` - comment out the
`schedule` trigger
+ (keep `workflow_dispatch`), so no `[vX-Y-test] Upgrade important CI
environment` PRs are opened.
+- `.github/dependabot.yml` - add `open-pull-requests-limit: 0` to every
`target-branch: vX-Y-test`
+ entry, so Dependabot does not open version-update PRs against the branch.
+- `.github/boring-cyborg.yml` - comment out the `backport-to-vX-Y-test`
auto-labelling rule.
+- `.github/workflows/automatic-backport.yml` - add `vX-Y-test` to
`BACKPORT_PAUSED_BRANCHES`, so a
+ `backport-to-vX-Y-test` label added by hand does not open a backport PR
either.
+
+Close any PR that was opened against `vX-Y-test` by this automation before it
was paused - the
+change reaches the branch from `main` anyway.
+
+The fast-forward phase ends when the release manager stops taking everything
from `main` - usually
+just before the first release candidate (`X.Y.0rc1`), when `main` starts
accepting changes meant for
+the next minor release. From that point on `vX-Y-test` diverges from `main`
and changes reach it
+only by cherry-picking, as for a patch release. Announce the switch on the
[email protected]
+list (so contributors know they need to start adding `backport-to-vX-Y-test`
labels and milestones
+to the PRs they want in `X.Y.0`) and revert all the pauses listed above in a
PR to `main`
+(this step is also called out at the start of [Build RC
artifacts](#build-rc-artifacts)).
+
## i18n workflow
@@ -359,6 +394,17 @@ Before cutting an RC, we should look at the milestone and
merge anything ready,
The Release Candidate artifacts we vote upon should be the exact ones we vote
against, without any modification other than renaming – i.e. the contents of
the files must be the same between voted release candidate and final release.
Because of this the version in the built artifacts that will become the
official Apache releases must not include the rcN suffix.
+> [!IMPORTANT]
+> When you start the release candidates of a major/minor release that went
through beta releases
+> (`X.Y.0rc1`), `vX-Y-test` stops being fast-forwarded to `main` and changes
reach it only by
+> cherry-picking from now on. Before cutting `X.Y.0rc1`, re-enable the
`vX-Y-test` automation that
+> was paused for the betas in a PR to `main`: uncomment the `schedule` in
+> `.github/workflows/scheduled-upgrade-check-vX-Y-test.yml` and the
`backport-to-vX-Y-test` rule in
+> `.github/boring-cyborg.yml`, remove `open-pull-requests-limit: 0` from the
`vX-Y-test` entries in
+> `.github/dependabot.yml`, and remove `vX-Y-test` from
`BACKPORT_PAUSED_BRANCHES` in
+> `.github/workflows/automatic-backport.yml`. See
+> [Beta releases: fast-forwarding `vX-Y-test` to
`main`](#beta-releases-fast-forwarding-vx-y-test-to-main).
+
- Set environment variables
```shell script
@@ -486,6 +532,10 @@ still works but is no longer recommended.
- `.github/workflows/milestone-tag-assistant.yml` — add `vX-Y-test` to the
push branches list.
- `.github/workflows/basic-tests.yml` — update the release-management
dry-run commands to test the new version.
- `.github/workflows/ci-notification.yml` — switch the `workflow-status`
matrix branch to the new branch.
+
+ If the new branch is going through beta releases first, pause the automation
that adds commits to
+ `vX-Y-test` in the same PR, as described in
+ [Beta releases: fast-forwarding `vX-Y-test` to
`main`](#beta-releases-fast-forwarding-vx-y-test-to-main).
- Commit the above changes with the message `Update version to ${VERSION}`.
- Build the release notes: