Release Version Bump (Vault Artifactory Secrets Plugin)
Complete workflow for this repo only. Follow phases in order. Track progress with the checklist.
Progress:
- [ ] 1. Detect current versions + target versions
- [ ] 2. Update Go / dependencies / CHANGELOG / CI
- [ ] 3. Build + unit tests
- [ ] 4. ASK → then local integration smoke tests vs Artifactory
- [ ] 5. Report go/no-go
- [ ] 6. ASK → then commit / branch / PR (only if approved)
User checkpoints (ask only these)
Ask the user only at these two points. Do not pause for confirmation on version targets, file edits, dependency upgrades, CHANGELOG text, unit tests, or intermediate choices.
Before Phase 4 — after unit tests/build succeed (or if there is nothing to change but user still wants smoke tests), ask:
Unit tests/build are done. OK to start Artifactory and run local integration smoke tests?
Proceed with Phase 4 only if the user says yes. If they say no, skip to Phase 5 with integration checks marked SKIPPED and still report a verdict.
Before Phase 6 — after the go/no-go verdict, ask:
Tests are complete (GO/NO-GO). Do you want me to create a branch, commit, push, and open a PR to
master?Proceed with commit/push/PR only if the user says yes.
Between checkpoints: run autonomously, choose sensible defaults, briefly report progress, and keep going.
Hard rules
- Do not open a PR, push, or create a remote branch until the user explicitly approves at checkpoint 2.
- Do not start Artifactory or run integration smoke tests until the user explicitly approves at checkpoint 1.
- Never commit temporary helpers (e.g.
scripts/get-token-inside.sh), credentials, tokens, or.envfiles. - Prefer one focused commit on a new branch from latest
origin/master. - Commit subject must match org style:
INST-XXXXX - Short-description(derive ticket from branch/user input). - Do not force-push unless the user explicitly asks.
- Do not update the Artifactory image version (
scripts/Dockerfilestays unchanged unless the user explicitly asks outside this skill).
Phase 1 — Detect versions
Do not ask the user to confirm targets. Pick latest Go + available dep upgrades automatically; note Artifactory tag for smoke tests only.
- Read current state:
go.mod→godirectivescripts/Dockerfile→ note current Artifactory image tag for smoke tests only (do not change it).github/workflows/acceptance-tests.ymlandrelease.yml→go-versionCHANGELOG.mdtop entry
- Resolve targets:
- Go: latest stable (
go versionlocally, or https://go.dev/dl/). Prefer full patch ingo.mod(e.g.1.26.6); CI may use minor (1.26). - Artifactory: leave as-is in
scripts/Dockerfile. Use that existing tag for local smoke tests. - Deps: update after Go bump (skill
go getlist).
- Go: latest stable (
- If already on latest Go and no dep updates exist, skip Phase 2 edits, still run Phase 3, then hit checkpoint 1 for optional smoke tests.
Phase 2 — Make version / dependency changes
Do not ask before editing. Apply changes immediately when targets differ from current.
Update these files as needed:
| File | Change |
|---|---|
go.mod |
go X.Y.Z |
.github/workflows/acceptance-tests.yml |
go-version: X.Y |
.github/workflows/release.yml |
go-version: X.Y |
CHANGELOG.md |
New/top NOTES for this release |
Do not edit scripts/Dockerfile (Artifactory image tag).
Dependency update (after Go bump):
# Direct deps
go get github.com/golang-jwt/jwt/v4@latest \
github.com/hashicorp/go-hclog@latest \
github.com/hashicorp/go-version@latest \
github.com/hashicorp/vault/api@latest \
github.com/hashicorp/vault/sdk@latest \
github.com/jarcoal/httpmock@latest \
github.com/samber/lo@latest \
github.com/stretchr/testify@latest
# Safe common upgrades (avoid `go get -u all` — breaks on armón/go-metrics rename)
go get golang.org/x/crypto@latest golang.org/x/net@latest golang.org/x/sys@latest \
golang.org/x/text@latest golang.org/x/sync@latest golang.org/x/oauth2@latest \
google.golang.org/grpc@latest google.golang.org/protobuf@latest \
github.com/hashicorp/go-plugin@latest github.com/hashicorp/go-metrics@latest \
github.com/hashicorp/go-kms-wrapping/v2@latest \
go.opentelemetry.io/otel@latest \
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp@latest
go mod tidy
CHANGELOG NOTES example:
## X.Y.Z (Month Day, Year)
NOTES:
* Update Go minimum version to A.B.C.
* Update Go module dependencies to latest available versions.
Phase 3 — Build and unit tests
Do not ask. Run immediately after Phase 2 (or Phase 1 if no edits).
export PATH="$HOME/bin:$PATH" # if vault CLI lives in ~/bin
rm -rf dist
go test -count=1 -timeout 5m ./...
make build
go version -m dist/*/artifactory-secrets-plugin | head -3
Stop and fix failures before asking checkpoint 1. After success → checkpoint 1 (Artifactory / smoke tests).
Phase 4 — Local integration smoke tests
Requires checkpoint 1 approval. Do not start Docker Artifactory or Vault integration flows before that.
Prereqs: Docker, Vault CLI, GoReleaser.
Use the existing Artifactory image from scripts/Dockerfile (do not bump it).
Tear down leftovers first:
pkill -f 'vault server -dev' 2>/dev/null || true
make stop_artifactory 2>/dev/null || true
docker ps --format '{{.ID}} {{.Image}} {{.Ports}}' | awk '/artifactory|:8082->/ {print $1}' | xargs -r docker stop
rm -f vault/artifactory.env
Then:
- Start Artifactory:
make artifactory(waits until ping OK; Apple Silicon uses OSS viarun-artifactory-container.sh). - Start Vault in background with plugin dir from
make build(dist/vault-plugin-secrets-artifactory_<os>_<arch>_*/). - Register + enable plugin (
make setupor explicitvault plugin register/secrets enablewith binary-reported version). - Configure admin token and run:
make adminor equivalent write/readconfig/admin+ rotatemake usertoken/user_token/<existing-user>make testrole/roles/test+token/test
Known gotchas (do not mis-report as product bugs)
- Host UI login to Artifactory may hang on localhost; if
scripts/getArtifactoryAdminToken.shtimes out, obtain an Access token via UI login inside the Artifactory container (temporary script OK locally — never commit it). user_token/<username>requires a real Artifactory user.user_token/testfails if usertestdoes not exist; useadminor create the user. Role pathtoken/testcreates a transientv-test-*user and does not need a pre-existing user.- Do not treat empty/wrong-audience legacy tokens as plugin failures; plugin Access APIs need Access-audience JWTs.
Detailed commands: testing.md.
Phase 5 — Verdict
Do not ask. Report immediately after Phase 4 (or after skip).
| Check | Result |
|---|---|
| Unit tests | PASS/FAIL |
| Build / Go toolchain in binary | PASS/FAIL + version |
| Plugin register/enable | PASS/FAIL / SKIPPED |
| config/admin + rotate | PASS/FAIL / SKIPPED |
| roles/test + token/test | PASS/FAIL / SKIPPED |
| user_token (existing user) | PASS/FAIL / SKIPPED |
End with GO or NO-GO and short rationale. Then → checkpoint 2 (PR).
Phase 6 — PR (permission required)
Requires checkpoint 2 approval.
Only if the user says yes:
git fetch origin master- Create branch:
INST-XXXXX-<short-slug>fromorigin/master(or user-provided name) - Stage only intended files (
go.mod,go.sum, workflows,CHANGELOG.md) — notscripts/Dockerfile - Commit:
INST-XXXXX - Update go version and dependencies(adjust to match changes) git push -u origin HEADgh pr create --base masterwith Summary + Test plan- Return the PR URL
If user declines, leave changes local and summarize next commands.
Do not
- Ask for confirmation except at the two user checkpoints above
- Update
scripts/Dockerfile/ Artifactory image version as part of this skill - Commit
scripts/get-token-inside.shor similar ad-hoc scripts - Run
go get -u allas the primary upgrade path - Call OSS-only UI failures or missing-user
user_token/testa dependency regression without rechecking with an existing user - Start Artifactory/integration tests or push/PR without the matching checkpoint approval