diff --git a/calico-cloud/_includes/components/FelixConfig/config-params.json b/calico-cloud/_includes/components/FelixConfig/config-params.json index 8f6cd44252..876a8d4667 100644 --- a/calico-cloud/_includes/components/FelixConfig/config-params.json +++ b/calico-cloud/_includes/components/FelixConfig/config-params.json @@ -6440,8 +6440,8 @@ "Required": false, "OnParseFailure": "ReplaceWithDefault", "AllowedConfigSources": "All", - "Description": "Used to enable/disable dynamically changing aggregation levels. Default is true.", - "DescriptionHTML": "

Used to enable/disable dynamically changing aggregation levels. Default is true.

", + "Description": "Used to enable/disable dynamically changing aggregation levels. Default is false.", + "DescriptionHTML": "

Used to enable/disable dynamically changing aggregation levels. Default is false.

", "UserEditable": true, "GoType": "*bool", "OpenSourceOnly": false diff --git a/calico-cloud_versioned_docs/version-23-2/_includes/components/FelixConfig/config-params.json b/calico-cloud_versioned_docs/version-23-2/_includes/components/FelixConfig/config-params.json index 8f6cd44252..876a8d4667 100644 --- a/calico-cloud_versioned_docs/version-23-2/_includes/components/FelixConfig/config-params.json +++ b/calico-cloud_versioned_docs/version-23-2/_includes/components/FelixConfig/config-params.json @@ -6440,8 +6440,8 @@ "Required": false, "OnParseFailure": "ReplaceWithDefault", "AllowedConfigSources": "All", - "Description": "Used to enable/disable dynamically changing aggregation levels. Default is true.", - "DescriptionHTML": "

Used to enable/disable dynamically changing aggregation levels. Default is true.

", + "Description": "Used to enable/disable dynamically changing aggregation levels. Default is false.", + "DescriptionHTML": "

Used to enable/disable dynamically changing aggregation levels. Default is false.

", "UserEditable": true, "GoType": "*bool", "OpenSourceOnly": false diff --git a/calico-enterprise_versioned_docs/version-3.21-2/_includes/components/FelixConfig/config-params.json b/calico-enterprise_versioned_docs/version-3.21-2/_includes/components/FelixConfig/config-params.json index 0b129efe0f..bc5116230a 100644 --- a/calico-enterprise_versioned_docs/version-3.21-2/_includes/components/FelixConfig/config-params.json +++ b/calico-enterprise_versioned_docs/version-3.21-2/_includes/components/FelixConfig/config-params.json @@ -5799,8 +5799,8 @@ "Required": false, "OnParseFailure": "ReplaceWithDefault", "AllowedConfigSources": "All", - "Description": "Used to enable/disable dynamically changing aggregation levels. Default is true.", - "DescriptionHTML": "

Used to enable/disable dynamically changing aggregation levels. Default is true.

", + "Description": "Used to enable/disable dynamically changing aggregation levels. Default is false.", + "DescriptionHTML": "

Used to enable/disable dynamically changing aggregation levels. Default is false.

", "UserEditable": true, "GoType": "*bool", "OpenSourceOnly": false diff --git a/calico-enterprise_versioned_docs/version-3.22-2/_includes/components/FelixConfig/config-params.json b/calico-enterprise_versioned_docs/version-3.22-2/_includes/components/FelixConfig/config-params.json index 3c28de306c..b73f467f29 100644 --- a/calico-enterprise_versioned_docs/version-3.22-2/_includes/components/FelixConfig/config-params.json +++ b/calico-enterprise_versioned_docs/version-3.22-2/_includes/components/FelixConfig/config-params.json @@ -5976,8 +5976,8 @@ "Required": false, "OnParseFailure": "ReplaceWithDefault", "AllowedConfigSources": "All", - "Description": "Used to enable/disable dynamically changing aggregation levels. Default is true.", - "DescriptionHTML": "

Used to enable/disable dynamically changing aggregation levels. Default is true.

", + "Description": "Used to enable/disable dynamically changing aggregation levels. Default is false.", + "DescriptionHTML": "

Used to enable/disable dynamically changing aggregation levels. Default is false.

", "UserEditable": true, "GoType": "*bool", "OpenSourceOnly": false diff --git a/calico-enterprise_versioned_docs/version-3.23-2/_includes/components/FelixConfig/config-params.json b/calico-enterprise_versioned_docs/version-3.23-2/_includes/components/FelixConfig/config-params.json index 8f6cd44252..876a8d4667 100644 --- a/calico-enterprise_versioned_docs/version-3.23-2/_includes/components/FelixConfig/config-params.json +++ b/calico-enterprise_versioned_docs/version-3.23-2/_includes/components/FelixConfig/config-params.json @@ -6440,8 +6440,8 @@ "Required": false, "OnParseFailure": "ReplaceWithDefault", "AllowedConfigSources": "All", - "Description": "Used to enable/disable dynamically changing aggregation levels. Default is true.", - "DescriptionHTML": "

Used to enable/disable dynamically changing aggregation levels. Default is true.

", + "Description": "Used to enable/disable dynamically changing aggregation levels. Default is false.", + "DescriptionHTML": "

Used to enable/disable dynamically changing aggregation levels. Default is false.

", "UserEditable": true, "GoType": "*bool", "OpenSourceOnly": false diff --git a/calico-enterprise_versioned_docs/version-3.24-1/_includes/components/FelixConfig/config-params.json b/calico-enterprise_versioned_docs/version-3.24-1/_includes/components/FelixConfig/config-params.json index 8f6cd44252..876a8d4667 100644 --- a/calico-enterprise_versioned_docs/version-3.24-1/_includes/components/FelixConfig/config-params.json +++ b/calico-enterprise_versioned_docs/version-3.24-1/_includes/components/FelixConfig/config-params.json @@ -6440,8 +6440,8 @@ "Required": false, "OnParseFailure": "ReplaceWithDefault", "AllowedConfigSources": "All", - "Description": "Used to enable/disable dynamically changing aggregation levels. Default is true.", - "DescriptionHTML": "

Used to enable/disable dynamically changing aggregation levels. Default is true.

", + "Description": "Used to enable/disable dynamically changing aggregation levels. Default is false.", + "DescriptionHTML": "

Used to enable/disable dynamically changing aggregation levels. Default is false.

", "UserEditable": true, "GoType": "*bool", "OpenSourceOnly": false diff --git a/calico-enterprise_versioned_docs/version-3.24-2/_includes/components/FelixConfig/config-params.json b/calico-enterprise_versioned_docs/version-3.24-2/_includes/components/FelixConfig/config-params.json index 8f6cd44252..876a8d4667 100644 --- a/calico-enterprise_versioned_docs/version-3.24-2/_includes/components/FelixConfig/config-params.json +++ b/calico-enterprise_versioned_docs/version-3.24-2/_includes/components/FelixConfig/config-params.json @@ -6440,8 +6440,8 @@ "Required": false, "OnParseFailure": "ReplaceWithDefault", "AllowedConfigSources": "All", - "Description": "Used to enable/disable dynamically changing aggregation levels. Default is true.", - "DescriptionHTML": "

Used to enable/disable dynamically changing aggregation levels. Default is true.

", + "Description": "Used to enable/disable dynamically changing aggregation levels. Default is false.", + "DescriptionHTML": "

Used to enable/disable dynamically changing aggregation levels. Default is false.

", "UserEditable": true, "GoType": "*bool", "OpenSourceOnly": false diff --git a/scripts/felix-config-overrides.json b/scripts/felix-config-overrides.json new file mode 100644 index 0000000000..d0325aa8c0 --- /dev/null +++ b/scripts/felix-config-overrides.json @@ -0,0 +1,18 @@ +[ + { + "field": "FlowLogsDynamicAggregationEnabled", + "reason": "felix/config/config_params.go tags this field `bool;false` (unchanged across all versions), but the doc comment in api/pkg/apis/projectcalico/v3/felixconfig.go has always said 'Default is true.' -- a long-standing stale comment, not a behavior change. Corrected on tigera/calico-private master via PR #12538 (merged 2026-07-16, incidental to an unrelated fluentd-removal change) but not yet backported to any release branch. Remove this entry once a synced file no longer needs it -- a WARNING below will announce that automatically.", + "patches": [ + { + "key": "Description", + "expected": "Used to enable/disable dynamically changing aggregation levels. Default is true.", + "value": "Used to enable/disable dynamically changing aggregation levels. Default is false." + }, + { + "key": "DescriptionHTML", + "expected": "

Used to enable/disable dynamically changing aggregation levels. Default is true.

", + "value": "

Used to enable/disable dynamically changing aggregation levels. Default is false.

" + } + ] + } +] diff --git a/scripts/patch-felix-config-overrides.sh b/scripts/patch-felix-config-overrides.sh new file mode 100755 index 0000000000..03f44dbe40 --- /dev/null +++ b/scripts/patch-felix-config-overrides.sh @@ -0,0 +1,92 @@ +#!/usr/bin/env bash + +# Patches known-stale upstream Felix config doc text into a freshly-synced +# config-params.json, in place. Overrides are declared in felix-config-overrides.json, +# scoped by NameConfigFile so a patch can never touch an unrelated field that happens +# to share the same description text. +# +# Called from update_felix_config() in update-felix-config.sh, after the fetched file +# has been validated as JSON and before it replaces the checked-in copy. + +set -euo pipefail + +readonly SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)" +readonly OVERRIDES_FILE="${SCRIPT_DIR}/felix-config-overrides.json" + +if [[ $# -ne 1 ]]; then + echo "Usage: $(basename "${BASH_SOURCE[0]}") " >&2 + exit 1 +fi + +target=$1 +patched="" + +cleanup() { + [[ -n "$patched" && -f "$patched" ]] && rm -f "$patched" +} +trap cleanup EXIT + +if [[ ! -f "$target" ]]; then + echo "Error: target file not found: $target" >&2 + exit 1 +fi + +if ! jq -e . "$target" >/dev/null 2>&1; then + echo "Error: $target is not valid JSON." >&2 + exit 1 +fi + +if [[ ! -f "$OVERRIDES_FILE" ]]; then + echo "Error: overrides file not found: $OVERRIDES_FILE" >&2 + exit 1 +fi + +if ! jq -e . "$OVERRIDES_FILE" >/dev/null 2>&1; then + echo "Error: $OVERRIDES_FILE is not valid JSON." >&2 + exit 1 +fi + +# --- Decide every patch's status against the ORIGINAL document, once, then apply exactly +# those decisions. The notices and the applied document come from the same "ops" list +# inside a single jq invocation, so they cannot disagree with each other, and the +# (multi-thousand-line) target file is only parsed once. --- +result=$(jq --slurpfile overrides "$OVERRIDES_FILE" ' + ($overrides[0]) as $ovs + | . as $orig + | [ .Groups | to_entries[] as {key: $gi, value: $g} + | $g.Fields | to_entries[] as {key: $fi, value: $f} + | $ovs[] as $ov + | select($ov.field == $f.NameConfigFile) + | $ov.patches[] as $p + | ($f[$p.key]) as $cur + | { path: ["Groups", $gi, "Fields", $fi, $p.key], + status: (if $cur == $p.expected then "patched" + elif $cur == $p.value then "already-correct" + else "stale" end), + field: $ov.field, key: $p.key, reason: $ov.reason, value: $p.value } + ] as $ops + | { doc: (reduce $ops[] as $o ($orig; if $o.status == "patched" then setpath($o.path; $o.value) else . end)), + notices: ($ops | map({status, field, key, reason})) } +' "$target") + +# --- Report what each override did: applied, already unnecessary, or no longer matches --- +notices=$(jq -r '.notices[] | [.status, .field, .key, .reason] | @tsv' <<< "$result") +while IFS=$'\t' read -r status field key reason; do + case "$status" in + patched) + echo "NOTICE: patched ${field}.${key} (${reason})" + ;; + already-correct) + echo "WARNING: override for ${field}.${key} is a no-op -- upstream text already matches. Safe to remove from ${OVERRIDES_FILE}. (${reason})" >&2 + ;; + stale) + echo "WARNING: override for ${field}.${key} did not apply -- upstream text matches neither the known-buggy nor the corrected value. Needs review in ${OVERRIDES_FILE}. (${reason})" >&2 + ;; + esac +done <<< "$notices" + +# --- Write the patched document --- +patched=$(mktemp -t felix-config-patched.XXXXXX) +jq '.doc' <<< "$result" > "$patched" + +mv "$patched" "$target" diff --git a/scripts/update-felix-config.sh b/scripts/update-felix-config.sh index 49ceecb471..23bbcb4b07 100755 --- a/scripts/update-felix-config.sh +++ b/scripts/update-felix-config.sh @@ -69,6 +69,8 @@ update_felix_config() { exit "$E_INVALID_JSON" fi + "$(dirname "${BASH_SOURCE[0]}")/patch-felix-config-overrides.sh" "$tmpfile" + mv "$tmpfile" "$LOCAL_PATH" echo -e "Finished processing ${VERSION}.\n\n" }