Contributing¶
muster is developed in the open at github.com/giantswarm/muster. Bug reports, documentation fixes and features are welcome as issues and pull requests.
Before you start¶
- Look for an existing issue or open one. For anything larger than a fix, agree on the approach in the issue first.
- Read Development setup for the toolchain, the make targets and the checks that run before every commit.
- Read Architecture, in particular the service locator rule: packages talk to each other only through
internal/api.
What a change includes¶
- Behaviour is specified by scenarios.
muster testruns YAML scenarios against isolated muster instances; a change in behaviour comes with a scenario that shows it, and a failing scenario is fixed in the code, not in the scenario. Testing explains the framework. - Unit tests for new code, without
time.Sleepand without timers that paper over races. - Documentation in
docs/when a user-visible surface changes: a tool argument, a configuration key, a CRD field, a CLI flag. The CLI reference is generated from the command tree (make generate-cli-docs); everything else is written by hand.make docs-buildmust pass. - A changelog entry under
UnreleasedinCHANGELOG.md, written for the person who operates or uses muster: what changed for them and why.
Conventions¶
- Commit messages follow Conventional Commits (
feat(aggregator): ...,fix(oauth): ...); the pre-commit hook enforces it. - Every commit is signed off under the Developer Certificate of Origin (
git commit -s). - Formatting and linting are
gofmt,goimports -local github.com/giantswarm/muster/v5andgolangci-lintwithgosecandgoconst;make lintruns them. - Generated files are regenerated, never edited: CRDs (
make generate-crds), the CLI reference (make generate-cli-docs), the Helm values schema and chart README (pre-commit hooks),schema.json(muster test --generate-schema).
Releases¶
Every pull request merged to main produces a release: the version is bumped, the tag is
pushed, and CircleCI builds the multi-architecture image, the signed binaries and the Helm
chart from that tag. There is no manual release step.
Security¶
Vulnerabilities are reported through Giant Swarm's responsible disclosure process, not as public issues.