Skip to content

[ML] Bump anomalies index template version - #138097

Merged
davidkyle merged 5 commits into
elastic:mainfrom
davidkyle:template-version
Nov 17, 2025
Merged

davidkyle merged 5 commits into
elastic:mainfrom
davidkyle:template-version

Conversation

@davidkyle

@davidkyle davidkyle commented Nov 14, 2025 •

Copy link
Copy Markdown
Member

#135270 changed the template but without a corresponding version bump the template is not updated.

The version test is here

if (templateConfig != null && templateConfig.version().equals(installedTemplate.version()) == false) {

@davidkyle davidkyle added the :ml Machine learning label Nov 14, 2025

@valeriy42 valeriy42 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@elasticsearchmachine

Copy link
Copy Markdown
Collaborator

Hi @davidkyle, I've created a changelog YAML for you.

Comment thread docs/changelog/138097.yaml Outdated
*/
@SuppressWarnings("unchecked")
public static void assertLegacyTemplateMatchesIndexMappings(

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This function was not use

@davidkyle
davidkyle marked this pull request as ready for review November 14, 2025 16:01
@davidkyle
davidkyle enabled auto-merge (squash) November 14, 2025 16:01
@elasticsearchmachine elasticsearchmachine added the Team:ML Meta label for the ML team label Nov 14, 2025
@elasticsearchmachine

Copy link
Copy Markdown
Collaborator

Pinging @elastic/ml-core (Team:ML)

@davidkyle
davidkyle merged commit b2d3b9b into elastic:main Nov 17, 2025
34 checks passed
davidkyle added a commit to davidkyle/elasticsearch that referenced this pull request Nov 17, 2025
@elasticsearchmachine

Copy link
Copy Markdown
Collaborator

💚 Backport successful

Status Branch Result
✅ 9.2
✅ 8.19
✅ 9.1

davidkyle added a commit to davidkyle/elasticsearch that referenced this pull request Nov 17, 2025
elasticsearchmachine pushed a commit that referenced this pull request Nov 18, 2025
* [ML] Bump anomalies index template version (#138097)

* fix compile
valeriy42 added a commit that referenced this pull request Jul 15, 2026
…job_id (#153755)

## Summary

Fixes a class of ML anomaly-detection failures on clusters upgraded through 8.18/8.19 where `.reindexed-*-ml-anomalies-*` results indices were created without the managed AD template mappings. Jobs can enter `failed` with `failed to update results mapping` when opening, or silently write to indices whose mappings conflict with the current template.

This PR combines two complementary fixes:
1. **Preventive** — widen the AD results composable template pattern from `.reindexed-v7-ml-anomalies-*` to `.reindexed-*-ml-anomalies-*` (matching the heal wildcard already in `MlAnomaliesIndexUpdate`), and bump `ML_INDEX_TEMPLATE_VERSION` to `10000003` so existing clusters reinstall the template (#138097 lesson from #135270).
2. **Corrective** — extend the runtime heal from #147688 so it no longer gates only on `job_id: keyword`; indices with correct `job_id` but wrong `anomaly_score_explanation.*` types (e.g. `by_field_relative_rarity: float` instead of `double`) are also healed by moving aliases to a template-backed target index.

## Changes

Template (prevent future corruption)

- `results_index_template.json`: `.reindexed-v7-ml-anomalies-*` → `.reindexed-*-ml-anomalies-*`
- `MlIndexTemplateRegistry`: version bump to `10000003` with javadoc entry
- Cross-reference javadoc on `REINDEXED_ANOMALIES_PATTERN` ↔ template resource
- `MlIndexTemplateRegistryTests.testResultsTemplate()` — new regression pinning the pattern list
- `MlMappingsUpgradeIT` — updated version constant and asserted patterns
- `machine-learning-settings.md` — heal setting description aligned to the wildcard

Heal (repair already-broken clusters)

- `MlIndexAndAlias.hasFieldTypedAs(IndexMetadata, List<String> fieldPath, …)` — nested-path lookup for `anomaly_score_explanation.*`
- `MlAnomaliesIndexUpdate.isIndexMappingHealthy()` — requires `job_id: keyword` **and** all four template `double` fields under `anomaly_score_explanation` (`lower_confidence_bound`, `typical_value`, `upper_confidence_bound`, `by_field_relative_rarity`)
- Gate applied in both heal detection (`healOneBadIndex`) and target reuse (`resolveOrCreateTargetIndex`)
- Advisory notification text generalized beyond `job_id`; affected-version list updated
- `MlAnomaliesIndexUpdateTests.testHealReindexedV7_HealWhenJobIdKeywordButAnomalyScoreExplanationFloat` — regression for the platform-logging failure mode

## Notes

- The heal step is gated by `xpack.ml.anomalies.heal_reindexed_v7.enabled` (default `true`, dynamically updatable).
- Heal moves aliases only; it does not reindex historical results. Stranded data recovery still requires the `_reindex` procedure documented in #147686 notifications.
- Template version bump is required for the preventive fix to reach already-provisioned clusters (same deploy mechanism as #138097).
- Backport targets: `8.19`, `9.3`, `9.4` (branches already carry job_id-only heal from #153399/#153397/#153396).

Complements and extends the runtime heal in #147688.
elasticsearchmachine pushed a commit that referenced this pull request Jul 15, 2026
…job_id (#153755) (#153931)

## Summary

Fixes a class of ML anomaly-detection failures on clusters upgraded through 8.18/8.19 where `.reindexed-*-ml-anomalies-*` results indices were created without the managed AD template mappings. Jobs can enter `failed` with `failed to update results mapping` when opening, or silently write to indices whose mappings conflict with the current template.

This PR combines two complementary fixes:
1. **Preventive** — widen the AD results composable template pattern from `.reindexed-v7-ml-anomalies-*` to `.reindexed-*-ml-anomalies-*` (matching the heal wildcard already in `MlAnomaliesIndexUpdate`), and bump `ML_INDEX_TEMPLATE_VERSION` to `10000003` so existing clusters reinstall the template (#138097 lesson from #135270).
2. **Corrective** — extend the runtime heal from #147688 so it no longer gates only on `job_id: keyword`; indices with correct `job_id` but wrong `anomaly_score_explanation.*` types (e.g. `by_field_relative_rarity: float` instead of `double`) are also healed by moving aliases to a template-backed target index.

## Changes

Template (prevent future corruption)

- `results_index_template.json`: `.reindexed-v7-ml-anomalies-*` → `.reindexed-*-ml-anomalies-*`
- `MlIndexTemplateRegistry`: version bump to `10000003` with javadoc entry
- Cross-reference javadoc on `REINDEXED_ANOMALIES_PATTERN` ↔ template resource
- `MlIndexTemplateRegistryTests.testResultsTemplate()` — new regression pinning the pattern list
- `MlMappingsUpgradeIT` — updated version constant and asserted patterns
- `machine-learning-settings.md` — heal setting description aligned to the wildcard

Heal (repair already-broken clusters)

- `MlIndexAndAlias.hasFieldTypedAs(IndexMetadata, List<String> fieldPath, …)` — nested-path lookup for `anomaly_score_explanation.*`
- `MlAnomaliesIndexUpdate.isIndexMappingHealthy()` — requires `job_id: keyword` **and** all four template `double` fields under `anomaly_score_explanation` (`lower_confidence_bound`, `typical_value`, `upper_confidence_bound`, `by_field_relative_rarity`)
- Gate applied in both heal detection (`healOneBadIndex`) and target reuse (`resolveOrCreateTargetIndex`)
- Advisory notification text generalized beyond `job_id`; affected-version list updated
- `MlAnomaliesIndexUpdateTests.testHealReindexedV7_HealWhenJobIdKeywordButAnomalyScoreExplanationFloat` — regression for the platform-logging failure mode

## Notes

- The heal step is gated by `xpack.ml.anomalies.heal_reindexed_v7.enabled` (default `true`, dynamically updatable).
- Heal moves aliases only; it does not reindex historical results. Stranded data recovery still requires the `_reindex` procedure documented in #147686 notifications.
- Template version bump is required for the preventive fix to reach already-provisioned clusters (same deploy mechanism as #138097).
- Backport targets: `8.19`, `9.3`, `9.4` (branches already carry job_id-only heal from #153399/#153397/#153396).

Complements and extends the runtime heal in #147688.
elasticsearchmachine pushed a commit that referenced this pull request Jul 15, 2026
…job_id (#153755) (#153932)

## Summary

Fixes a class of ML anomaly-detection failures on clusters upgraded through 8.18/8.19 where `.reindexed-*-ml-anomalies-*` results indices were created without the managed AD template mappings. Jobs can enter `failed` with `failed to update results mapping` when opening, or silently write to indices whose mappings conflict with the current template.

This PR combines two complementary fixes:
1. **Preventive** — widen the AD results composable template pattern from `.reindexed-v7-ml-anomalies-*` to `.reindexed-*-ml-anomalies-*` (matching the heal wildcard already in `MlAnomaliesIndexUpdate`), and bump `ML_INDEX_TEMPLATE_VERSION` to `10000003` so existing clusters reinstall the template (#138097 lesson from #135270).
2. **Corrective** — extend the runtime heal from #147688 so it no longer gates only on `job_id: keyword`; indices with correct `job_id` but wrong `anomaly_score_explanation.*` types (e.g. `by_field_relative_rarity: float` instead of `double`) are also healed by moving aliases to a template-backed target index.

## Changes

Template (prevent future corruption)

- `results_index_template.json`: `.reindexed-v7-ml-anomalies-*` → `.reindexed-*-ml-anomalies-*`
- `MlIndexTemplateRegistry`: version bump to `10000003` with javadoc entry
- Cross-reference javadoc on `REINDEXED_ANOMALIES_PATTERN` ↔ template resource
- `MlIndexTemplateRegistryTests.testResultsTemplate()` — new regression pinning the pattern list
- `MlMappingsUpgradeIT` — updated version constant and asserted patterns
- `machine-learning-settings.md` — heal setting description aligned to the wildcard

Heal (repair already-broken clusters)

- `MlIndexAndAlias.hasFieldTypedAs(IndexMetadata, List<String> fieldPath, …)` — nested-path lookup for `anomaly_score_explanation.*`
- `MlAnomaliesIndexUpdate.isIndexMappingHealthy()` — requires `job_id: keyword` **and** all four template `double` fields under `anomaly_score_explanation` (`lower_confidence_bound`, `typical_value`, `upper_confidence_bound`, `by_field_relative_rarity`)
- Gate applied in both heal detection (`healOneBadIndex`) and target reuse (`resolveOrCreateTargetIndex`)
- Advisory notification text generalized beyond `job_id`; affected-version list updated
- `MlAnomaliesIndexUpdateTests.testHealReindexedV7_HealWhenJobIdKeywordButAnomalyScoreExplanationFloat` — regression for the platform-logging failure mode

## Notes

- The heal step is gated by `xpack.ml.anomalies.heal_reindexed_v7.enabled` (default `true`, dynamically updatable).
- Heal moves aliases only; it does not reindex historical results. Stranded data recovery still requires the `_reindex` procedure documented in #147686 notifications.
- Template version bump is required for the preventive fix to reach already-provisioned clusters (same deploy mechanism as #138097).
- Backport targets: `8.19`, `9.3`, `9.4` (branches already carry job_id-only heal from #153399/#153397/#153396).

Complements and extends the runtime heal in #147688.
valeriy42 added a commit that referenced this pull request Jul 15, 2026
…job_id (#153755) (#153930)

## Summary

Fixes a class of ML anomaly-detection failures on clusters upgraded through 8.18/8.19 where `.reindexed-*-ml-anomalies-*` results indices were created without the managed AD template mappings. Jobs can enter `failed` with `failed to update results mapping` when opening, or silently write to indices whose mappings conflict with the current template.

This PR combines two complementary fixes:
1. **Preventive** — widen the AD results composable template pattern from `.reindexed-v7-ml-anomalies-*` to `.reindexed-*-ml-anomalies-*` (matching the heal wildcard already in `MlAnomaliesIndexUpdate`), and bump `ML_INDEX_TEMPLATE_VERSION` to `10000003` so existing clusters reinstall the template (#138097 lesson from #135270).
2. **Corrective** — extend the runtime heal from #147688 so it no longer gates only on `job_id: keyword`; indices with correct `job_id` but wrong `anomaly_score_explanation.*` types (e.g. `by_field_relative_rarity: float` instead of `double`) are also healed by moving aliases to a template-backed target index.

## Changes

Template (prevent future corruption)

- `results_index_template.json`: `.reindexed-v7-ml-anomalies-*` → `.reindexed-*-ml-anomalies-*`
- `MlIndexTemplateRegistry`: version bump to `10000003` with javadoc entry
- Cross-reference javadoc on `REINDEXED_ANOMALIES_PATTERN` ↔ template resource
- `MlIndexTemplateRegistryTests.testResultsTemplate()` — new regression pinning the pattern list
- `MlMappingsUpgradeIT` — updated version constant and asserted patterns
- `machine-learning-settings.md` — heal setting description aligned to the wildcard

Heal (repair already-broken clusters)

- `MlIndexAndAlias.hasFieldTypedAs(IndexMetadata, List<String> fieldPath, …)` — nested-path lookup for `anomaly_score_explanation.*`
- `MlAnomaliesIndexUpdate.isIndexMappingHealthy()` — requires `job_id: keyword` **and** all four template `double` fields under `anomaly_score_explanation` (`lower_confidence_bound`, `typical_value`, `upper_confidence_bound`, `by_field_relative_rarity`)
- Gate applied in both heal detection (`healOneBadIndex`) and target reuse (`resolveOrCreateTargetIndex`)
- Advisory notification text generalized beyond `job_id`; affected-version list updated
- `MlAnomaliesIndexUpdateTests.testHealReindexedV7_HealWhenJobIdKeywordButAnomalyScoreExplanationFloat` — regression for the platform-logging failure mode

## Notes

- The heal step is gated by `xpack.ml.anomalies.heal_reindexed_v7.enabled` (default `true`, dynamically updatable).
- Heal moves aliases only; it does not reindex historical results. Stranded data recovery still requires the `_reindex` procedure documented in #147686 notifications.
- Template version bump is required for the preventive fix to reach already-provisioned clusters (same deploy mechanism as #138097).
- Backport targets: `8.19`, `9.3`, `9.4` (branches already carry job_id-only heal from #153399/#153397/#153396).

Complements and extends the runtime heal in #147688.
valeriy42 added a commit that referenced this pull request Sep 16, 2026
…beyond job_id (#153755) (#159079)

* [ML] Extend reindexed AD results template and generalize heal beyond job_id (#153755)

## Summary

Fixes a class of ML anomaly-detection failures on clusters upgraded through 8.18/8.19 where `.reindexed-*-ml-anomalies-*` results indices were created without the managed AD template mappings. Jobs can enter `failed` with `failed to update results mapping` when opening, or silently write to indices whose mappings conflict with the current template.

This PR combines two complementary fixes:
1. **Preventive** — widen the AD results composable template pattern from `.reindexed-v7-ml-anomalies-*` to `.reindexed-*-ml-anomalies-*` (matching the heal wildcard already in `MlAnomaliesIndexUpdate`), and bump `ML_INDEX_TEMPLATE_VERSION` to `10000003` so existing clusters reinstall the template (#138097 lesson from #135270).
2. **Corrective** — extend the runtime heal from #147688 so it no longer gates only on `job_id: keyword`; indices with correct `job_id` but wrong `anomaly_score_explanation.*` types (e.g. `by_field_relative_rarity: float` instead of `double`) are also healed by moving aliases to a template-backed target index.

## Changes

Template (prevent future corruption)

- `results_index_template.json`: `.reindexed-v7-ml-anomalies-*` → `.reindexed-*-ml-anomalies-*`
- `MlIndexTemplateRegistry`: version bump to `10000003` with javadoc entry
- Cross-reference javadoc on `REINDEXED_ANOMALIES_PATTERN` ↔ template resource
- `MlIndexTemplateRegistryTests.testResultsTemplate()` — new regression pinning the pattern list
- `MlMappingsUpgradeIT` — updated version constant and asserted patterns
- `machine-learning-settings.md` — heal setting description aligned to the wildcard

Heal (repair already-broken clusters)

- `MlIndexAndAlias.hasFieldTypedAs(IndexMetadata, List<String> fieldPath, …)` — nested-path lookup for `anomaly_score_explanation.*`
- `MlAnomaliesIndexUpdate.isIndexMappingHealthy()` — requires `job_id: keyword` **and** all four template `double` fields under `anomaly_score_explanation` (`lower_confidence_bound`, `typical_value`, `upper_confidence_bound`, `by_field_relative_rarity`)
- Gate applied in both heal detection (`healOneBadIndex`) and target reuse (`resolveOrCreateTargetIndex`)
- Advisory notification text generalized beyond `job_id`; affected-version list updated
- `MlAnomaliesIndexUpdateTests.testHealReindexedV7_HealWhenJobIdKeywordButAnomalyScoreExplanationFloat` — regression for the platform-logging failure mode

## Notes

- The heal step is gated by `xpack.ml.anomalies.heal_reindexed_v7.enabled` (default `true`, dynamically updatable).
- Heal moves aliases only; it does not reindex historical results. Stranded data recovery still requires the `_reindex` procedure documented in #147686 notifications.
- Template version bump is required for the preventive fix to reach already-provisioned clusters (same deploy mechanism as #138097).
- Backport targets: `8.19`, `9.3`, `9.4` (branches already carry job_id-only heal from #153399/#153397/#153396).

Complements and extends the runtime heal in #147688.

(cherry picked from commit 6161f77)

# Conflicts:
#	docs/reference/elasticsearch/configuration-reference/machine-learning-settings.md
#	x-pack/plugin/ml/src/main/java/org/elasticsearch/xpack/ml/MlIndexTemplateRegistry.java
#	x-pack/qa/rolling-upgrade/src/javaRestTest/java/org/elasticsearch/upgrades/MlMappingsUpgradeIT.java

* [ML] Adapt 8.19 backport of #153755 off projects metadata API
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

auto-backport Automatically create backport pull requests when merged >bug :ml Machine learning Team:ML Meta label for the ML team v8.19.8 v9.1.8 v9.2.2 v9.3.0

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants