Skip to content

feat(mongodb): support MongoDB 9.0 and make 9.0.2 default - #414

Merged
KeiaiLab-PHIL merged 1 commit into
mainfrom
feat/mongodb-9.0-default
Oct 6, 2026
Merged

KeiaiLab-PHIL merged 1 commit into
mainfrom
feat/mongodb-9.0-default

Conversation

@KeiaiLab-PHIL

Copy link
Copy Markdown
Contributor

What / why

User instruction 2026-10-06 "mongodb 최신 메이저버전 적용": MongoDB 9.0 becomes supported and the default; the exporter default moves to 0.53.0; upstream images are whitelisted in the Artifact Hub scan.

  • supportedMongoDBList = 8.0 / 8.2 / 8.3 / 9.0 (v1alpha1 + v1beta1).
  • Upgrade path: IsValidUpgradePath used to reject every major change, so 8.3 → 9.0 was blocked. New checkMajorStep admits exactly one cross-major step: last supported minor of N → first supported minor of N+1 (8.3 → 9.0). 8.0/8.2 → 9.0 and 9.0 → 8.x stay rejected.
    • Why 8.3 specifically: 9.0 binaries start only with FCV = lastContinuous (8.3) or lastLTS (8.0). The operator commits FCV to the target minor after each validated upgrade (commitFCV / commitShardedFCV → fcvMajorMinor), so a cluster that walked 8.0 → 8.2 → 8.3 sits at FCV 8.3, which 9.0 accepts. The binary rollout stays rollback-safe until validation passes, then FCV "9.0" is committed (same flow as the minor steps).
    • 8.0 → 9.0 is valid for MongoDB, but it is kept blocked to stay consistent with the existing adjacent-step rule (8.0 → 8.3 is blocked too).
  • Defaults: mongo:9.0.2 (defaultImage, also used by the backup Job and the backup-verification StatefulSet), percona/mongodb_exporter:0.53.0 (kubebuilder default + exporterImage), chart values, crdsExamples, config/samples (+bundle samples, CSV alm-examples base), examples, docs (install / getting-started / i18n / chart README / README supported-version list).
  • Chart artifacthub.io/images: mongo:9.0.2 and percona/mongodb_exporter:0.53.0 are whitelisted: true; the operator image stays scanned. SECURITY.md gets an "Upstream images" section.
  • CRDs regenerated with make manifests generate + make sync-crds (note: manifests runs sync-crds before controller-gen, so a second sync-crds is needed to get the chart CRDs in step — pre-existing Makefile ordering).

Verification

  • New table cases (written first, observed red: major version change "8.3" → "9.0" is not allowed), then green: 8.3→9.0 ok, 8.3.1→9.0.2 ok, 8.0→9.0 / 8.2→9.0 / 9.0→8.3 / 8.3→10.0 rejected, 9.0.0→9.0.2 patch ok.
  • make test green · golangci-lint --new-from-rev=origin/main 0 issues · helm lint ok · make kube-lint pass · crane digest mongo:9.0.2 / percona/mongodb_exporter:0.53.0 exist.

Not verifiable without a cluster

  • A real 8.3 → 9.0 rolling upgrade (RS and sharded) with FCV 8.3 → 9.0 commit.
  • mongot search sidecar and backup tooling (mongodump/mongorestore in mongo:9.0.2) against 8.x servers.
  • Existing CRs that omit monitoring.exporter.image pick up the new CRD default 0.53.0 → exporter sidecar rolls once.
  • Existing clusters are not changed by the chart bump: spec.version.version is required in the CR; chart mongodb.version only feeds an unused DEFAULT_MONGODB_VERSION env and NOTES.

🤖 Generated with Claude Code

MongoDB 9.0 is the current major; the operator rejected it. The
exporter default also lagged (0.51.0).

- Supported list 8.0/8.2/8.3/9.0. The upgrade webhook admits one
  major step, 8.3 -> 9.0: 9.0 binaries start only with FCV 8.3
  (lastContinuous) or 8.0 (lastLTS), and the operator commits FCV
  to the target minor after each upgrade, so a cluster reaches 9.0
  from 8.3 with FCV 8.3. 8.0/8.2 -> 9.0 stay rejected, matching
  the adjacent-minor rule. FCV 9.0 is committed after validation.
- Defaults: mongo:9.0.2, percona/mongodb_exporter:0.53.0 (code,
  CRD default, chart values, samples, examples, docs).
- Artifact Hub: mongo and exporter images are whitelisted (upstream,
  not built here); the operator image stays scanned. SECURITY.md
  documents it.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Signed-off-by: phil <phil@keiailab.com>
@KeiaiLab-PHIL
KeiaiLab-PHIL enabled auto-merge (squash) October 6, 2026 01:53
@KeiaiLab-PHIL
KeiaiLab-PHIL merged commit d5d84fd into main Oct 6, 2026
15 checks passed
@KeiaiLab-PHIL
KeiaiLab-PHIL deleted the feat/mongodb-9.0-default branch October 6, 2026 02:07
KeiaiLab-PHIL added a commit that referenced this pull request Oct 6, 2026
Security release, also a code release: tag, chart version and
appVersion are aligned so release.yml builds and publishes the image.

Includes: Go toolchain 1.26.8 and vulnerable module bumps (#411),
workflow hardening (#412), Dependabot (#413), MongoDB 9.0 support with
9.0.2 and exporter 0.53.0 as defaults (#414), fuzz test (#422).

Bundle regenerated with `make bundle VERSION=1.16.10` (ADR-0038
parity). artifacthub.io/images moves the operator to v1.16.10 and
keeps the upstream mongo/exporter images whitelisted;
containsSecurityUpdates is true.

Signed-off-by: phil <phil@keiailab.com>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant