Skip to content

deps: bump Go toolchain to 1.27 - #2828

Open
Quang Nguyen (nddq) wants to merge 1 commit into
nddq/bump-golangci-lint-v2.14.0from
nddq/bump-go-toolchain-1.27
Open

Quang Nguyen (nddq) wants to merge 1 commit into
nddq/bump-golangci-lint-v2.14.0from
nddq/bump-go-toolchain-1.27

Conversation

@nddq

@nddq Quang Nguyen (nddq) commented Oct 3, 2026 •

Copy link
Copy Markdown
Member

Description

Go 1.27.1 is out, and the Microsoft Go 1.27 images ship it. This PR moves every build to Go 1.27.1 and keeps the go.mod compatibility floor at go 1.26.0:

  • go.mod: add toolchain go1.27.1. setup-go and the default GOTOOLCHAIN=auto use it. The Microsoft Go images set GOTOOLCHAIN=local, so they build with their own Go.
  • ADO: .azure-pipelines/steps/setup-go.yml reads the toolchain line first, then the go line. setup-go applies the same rule.
  • Dockerfiles: the golang builder images move from 1.26 → 1.27 (12 FROM lines in 10 Dockerfiles). The stale 1.26 comments in the Windows Dockerfiles are fixed too.
  • systemcrypto: Microsoft Go 1.27 removed GOEXPERIMENT=ms_nocgo_opensslcrypto, and a build that sets it fails:
    go: GOEXPERIMENT=ms_nocgo_opensslcrypto has been removed; system crypto supports CGO_ENABLED=0 automatically on platforms with a cgo-less OpenSSL implementation since Go 1.27
    
    The cli, operator, and controller builds drop it. With CGO_ENABLED=0, systemcrypto now selects the cgo-less OpenSSL backend by itself.
  • pwru: shell/Dockerfile built pwru with GOEXPERIMENT=none to turn off systemcrypto. On Go 1.27 that setting no longer turns it off, and it turns off the upstream default experiments instead. The opt-out is removed, so pwru uses OpenSSL like the other binaries and can run in FIPS mode.
  • Dependabot: ignore minor updates of oss/go/microsoft/golang. A Go minor version moves together with the toolchain line, so maintainers bump it by hand.

The go line stays at 1.26.0. The runtime GODEBUG defaults therefore stay at Go 1.26, and the stdversion check in go test reports any Go 1.27-only API.

Related Issue

Stacked on #2827. golangci-lint v2.11.4 panics on Go 1.27, so this PR needs v2.14.0 from #2827 first.

Checklist

  • I have read the contributing documentation.
  • I signed and signed-off the commits (git commit -S -s ...). See this documentation on signing commits.
  • I have correctly attributed the author(s) of the code.
  • I have tested the changes locally.
  • I have followed the project's style guidelines.
  • I have updated the documentation, if necessary. (N/A — build change)
  • I have added tests, if applicable. (N/A — build change)

Screenshots (if applicable) or Testing Completed

Local, on Go 1.27.1

Built every Linux image for linux/amd64. All binaries report go1.27.1 and microsoft_systemcrypto=1, with no GOEXPERIMENT:

Image Binaries
retina-agent controller, captureworkload, hubble
retina-init initretina
retina-operator retina-operator
kubectl-retina kubectl-retina
retina-shell pwru

Each binary starts normally and with GOFIPS=1 OPENSSL_FORCE_FIPS_MODE=1. As a control, GOFIPS=1 with OPENSSL_CONF=/nonexistent panics, as expected:

panic: opensslcrypto: FIPS mode requested (environment variable GOFIPS=1) but not available: OpenSSL 3.3.7 7 Apr 2026
  • golangci-lint v2.14.0, run as CI runs it, reports 0 issues for linux and windows on amd64 and arm64.
  • go build ./... (linux, windows) and the generate-check flow (amd64) pass, with no change to generated code.
  • make build-windows-binaries in the Microsoft Go 1.27 image produces go1.27.1 binaries with microsoft_systemcrypto=1 (CNG).
  • The unit tests in the test/image container pass (57 packages, 0 failures).
  • The kapinger and toolbox images build.

CI

A manual run of the CI pipeline with e2e validation enabled built all images, arm64 included, and passed the full e2e suite with 0 issues. PR builds post a placeholder e2e status, so this run is the real one.

Canary on an existing cluster

AKS cluster with four Azure Linux 3.0 node pools: amd64, arm64, FIPS amd64, FIPS arm64. The kernel flag /proc/sys/crypto/fips_enabled reads 1 on the FIPS pools. A curl loop on every node kept 400–1,400 flows/s per node. Baseline: v1.2.9 from MCR with the v1.2.9 charts.

Standard chart. helm upgrade --reuse-values to this build took 219 s. Over a 30-minute watch: 0 restarts in 47 observations, 0 error lines, go_info go1.27.1 on every agent, CPU and memory equal to the baseline (45–50 Mi vs 41–50 Mi), and forward_count +1.2 M to +2.8 M per node per 20 minutes. helm rollback to v1.2.9 took 124 s and was clean.

Hubble chart with its TLS defaults (certgen; CI runs this chart with TLS off). The same upgrade took 124 s. The relay reconnected to all four agents with tls=true within 5 s. hubble list nodes showed all four peers Connected at 411–1,404 flows/s, FIPS nodes included. 0 agent restarts in 20 observations. Rollback was clean.

Crypto backend. On all four nodes, the agent process maps libcrypto.so.3.3.7, libsymcrypt, and ossl-modules/symcryptprovider.so (read from /proc/<pid>/maps). The OpenSSL/SymCrypt backend is in use on amd64 and arm64, FIPS and non-FIPS.

Two observations apply to both versions and are not caused by this change. The relay restarts once per agent rollout, from a probe failure while all agents restart. The agent working set varies by up to about 170 Mi between nodes, from page-cache attribution of the image files.

@github-actions

github-actions Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

Retina Code Coverage Report

Total coverage increased from 36.8% to 38.5% ✅

Increased diff

Impacted Files Coverage
cli/cmd/capture/download.go 42.99% ... 44.55% (1.56%) ⬆️
pkg/plugin/packetparser/packetparser_linux.go 56.22% ... 57.92% (1.7%) ⬆️
pkg/watchers/apiserver/apiserver.go 88.35% ... 90.48% (2.13%) ⬆️
cli/cmd/capture/create.go 84.66% ... 86.26% (1.6%) ⬆️
pkg/loader/vmlinux.go 26.06% ... 27.53% (1.47%) ⬆️
test/e2e/framework/types/job.go 80.23% ... 80.76% (0.53%) ⬆️
pkg/plugin/dropreason/dropreason_linux.go 61.48% ... 62.34% (0.86%) ⬆️
shell/tracescript.go 88.82% ... 89.82% (1.0%) ⬆️
test/e2e/framework/types/jobvalues.go 44.45% ... 47.05% (2.6%) ⬆️
pkg/hubble/resources/ciliumidentity_linux.go 97.72% ... 98.53% (0.81%) ⬆️
pkg/capture/test_helper.go 80.0% ... 87.5% (7.5%) ⬆️
pkg/module/metrics/dns.go 72.46% ... 73.44% (0.98%) ⬆️
pkg/capture/crd_to_job.go 90.04% ... 91.67% (1.63%) ⬆️
pkg/module/metrics/drops.go 99.22% ... 99.3% (0.08%) ⬆️
pkg/common/types.go 44.45% ... 45.42% (0.97%) ⬆️
deploy/standard/registercrd.go 65.38% ... 67.42% (2.04%) ⬆️
cli/cmd/shell.go 65.2% ... 71.8% (6.6%) ⬆️
deploy/testutils/grafana/dashboards/simplify-grafana.go 67.18% ... 69.52% (2.34%) ⬆️
pkg/plugin/linuxutil/ethtool_stats_linux.go 69.76% ... 70.4% (0.64%) ⬆️
operator/config/config.go 91.7% ... 93.5% (1.8%) ⬆️
pkg/plugin/filter/filter_map_linux.go 78.21% ... 78.43% (0.22%) ⬆️
pkg/controllers/operator/retinaendpoint/retinaendpoint_controller.go 82.62% ... 83.52% (0.9%) ⬆️
pkg/plugin/linuxutil/linuxutil_linux.go 32.75% ... 33.53% (0.78%) ⬆️
cli/cmd/capture/delete.go 82.8% ... 88.9% (6.1%) ⬆️
pkg/telemetry/telemetry.go 50.77% ... 51.42% (0.65%) ⬆️
pkg/module/metrics/tcpflags.go 86.87% ... 87.42% (0.55%) ⬆️
pkg/controllers/operator/cilium-crds/endpoint/identitymanager_linux.go 68.4% ... 71.36% (2.96%) ⬆️
pkg/module/metrics/latency.go 59.67% ... 60.48% (0.81%) ⬆️
cli/cmd/bpftrace.go 74.08% ... 77.8% (3.72%) ⬆️
pkg/plugin/linuxutil/netstat_stats_linux.go 74.51% ... 75.34% (0.83%) ⬆️
pkg/config/config.go 57.78% ... 58.65% (0.87%) ⬆️
pkg/controllers/daemon/namespace/namespace_controller.go 76.24% ... 78.76% (2.52%) ⬆️
pkg/metrics/metrics.go 48.55% ... 49.9% (1.35%) ⬆️
pkg/plugin/infiniband/infiniband_linux.go 34.93% ... 35.9% (0.97%) ⬆️
pkg/controllers/operator/cilium-crds/endpoint/endpoint_controller_linux.go 40.65% ... 42.67% (2.02%) ⬆️
pkg/plugin/ciliumeventobserver/ciliumeventobserver_linux.go 49.63% ... 50.29% (0.66%) ⬆️
shell/manifests.go 94.45% ... 95.45% (1.0%) ⬆️
pkg/controllers/cache/cache.go 85.4% ... 86.85% (1.45%) ⬆️
pkg/server/server.go 97.03% ... 97.3% (0.27%) ⬆️
pkg/module/metrics/types.go 62.46% ... 62.89% (0.43%) ⬆️
pkg/pubsub/pubsub.go 95.3% ... 96.6% (1.3%) ⬆️
pkg/managers/pluginmanager/pluginmanager.go 42.8% ... 44.33% (1.53%) ⬆️
pkg/telemetry/perf_unix.go 28.57% ... 29.63% (1.06%) ⬆️
pkg/capture/capture_manager.go 67.24% ... 68.31% (1.07%) ⬆️
pkg/plugin/dns/dns_linux.go 49.04% ... 49.26% (0.22%) ⬆️
pkg/plugin/packetforward/packetforward_linux.go 57.79% ... 58.58% (0.79%) ⬆️
pkg/controllers/daemon/retinaendpoint/controller.go 88.0% ... 90.0% (2.0%) ⬆️
test/e2e/framework/azure/delete-rg.go 28.83% ... 29.02% (0.19%) ⬆️
pkg/controllers/operator/capture/controller.go 13.38% ... 14.35% (0.97%) ⬆️
pkg/module/metrics/metrics_module.go 76.68% ... 77.99% (1.31%) ⬆️
pkg/utils/flow_utils.go 45.32% ... 45.76% (0.44%) ⬆️
pkg/module/metrics/forward.go 98.33% ... 98.36% (0.03%) ⬆️
cli/cmd/capture/table_util.go 22.23% ... 22.98% (0.75%) ⬆️
pkg/module/metrics/basemetricsobject.go 96.03% ... 96.58% (0.55%) ⬆️
pkg/plugin/ciliumeventobserver/parser_linux.go 62.9% ... 67.3% (4.4%) ⬆️
pkg/hubble/resources/service_linux.go 97.98% ... 98.69% (0.71%) ⬆️
pkg/controllers/daemon/nodereconciler/node_controller_linux.go 12.5% ... 12.82% (0.32%) ⬆️
pkg/capture/provider/network_capture_unix.go 42.18% ... 43.9% (1.72%) ⬆️
pkg/plugin/tcpretrans/tcpretrans_linux.go 46.21% ... 46.32% (0.11%) ⬆️
test/e2e/framework/types/runner.go 88.9% ... 90.9% (2.0%) ⬆️
pkg/controllers/operator/pod/pod_controller.go 62.26% ... 62.93% (0.67%) ⬆️
cmd/hubble/daemon_main_linux.go 3.7% ... 4.98% (1.28%) ⬆️

Decreased diff

Impacted Files Coverage
pkg/capture/outputlocation/s3.go 31.43% ... 30.96% (-0.47%) ⬇️
pkg/enricher/enricher.go 65.47% ... 65.32% (-0.15%) ⬇️
pkg/controllers/operator/metricsconfiguration/metricsconfiguration_controller.go 55.57% ... 53.17% (-2.4%) ⬇️
pkg/capture/outputlocation/pvc.go 83.92% ... 80.67% (-3.25%) ⬇️
pkg/capture/outputlocation/hostpath.go 83.92% ... 83.65% (-0.27%) ⬇️
cli/cmd/capture/list.go 20.0% ... 15.8% (-4.2%) ⬇️
pkg/managers/controllermanager/controllermanager.go 54.88% ... 54.58% (-0.3%) ⬇️
pkg/controllers/daemon/metricsconfiguration/metricsconfiguration_controller.go 50.57% ... 48.97% (-1.6%) ⬇️
pkg/log/zap.go 58.44% ... 58.04% (-0.4%) ⬇️

@nddq
Quang Nguyen (nddq) changed the base branch from main to nddq/bump-golangci-lint-v2.14.0 October 3, 2026 05:02
@nddq
Quang Nguyen (nddq) added this pull request to stack #2829 October 3, 2026 05:02
@nddq
Quang Nguyen (nddq) removed this pull request from stack #2829 October 3, 2026 05:08
@nddq
Quang Nguyen (nddq) changed the base branch from nddq/bump-golangci-lint-v2.14.0 to main October 3, 2026 05:09
@nddq
Quang Nguyen (nddq) changed the base branch from main to nddq/bump-golangci-lint-v2.14.0 October 3, 2026 06:19
@nddq
Quang Nguyen (nddq) added this pull request to stack #2830 October 3, 2026 06:19
Build with Go 1.27.1, and keep the go.mod compatibility floor at
go 1.26.0.

- go.mod: add toolchain go1.27.1. setup-go and the default
  GOTOOLCHAIN=auto use it. The Microsoft Go images set
  GOTOOLCHAIN=local, so they build with their own Go.
- .azure-pipelines/steps/setup-go.yml: read the toolchain line first,
  then the go line. setup-go applies the same rule.
- Dockerfiles: move the golang builder images from 1.26 to 1.27, and
  fix the stale 1.26 comments in the Windows Dockerfiles.
- Remove GOEXPERIMENT=ms_nocgo_opensslcrypto from the cli, operator
  and controller (bpf-gen, intermediate, hubble-bin) builds. Microsoft
  Go 1.27 removed the experiment, and a build that sets it fails. With
  CGO_ENABLED=0, systemcrypto now selects the cgo-less OpenSSL backend
  by itself.
- shell/Dockerfile: remove GOEXPERIMENT=none from the pwru build. On
  Go 1.27 it no longer turns off systemcrypto, and it turns off the
  upstream default experiments instead. pwru now uses the OpenSSL
  backend, the same as the other binaries, so it can run in FIPS mode.
- dependabot: ignore minor updates of the golang images. A Go minor
  version moves together with the toolchain line, so maintainers bump
  it by hand.

The go line stays at 1.26.0. The runtime GODEBUG defaults therefore
stay at Go 1.26, and the go test stdversion check reports any Go
1.27-only API.

Signed-off-by: Quang Nguyen <28567936+nddq@users.noreply.github.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant