[ci] Drop Bazel 6 and ensure we run on Bazel 7 and 8 (#1525)

[ci] Drop Bazel 6 and ensure we run on Bazel 7 and 8

Minimal rules_kotlin bump to get tests passing with Bazel 8.5.1 on Windows. Also requires additional flag.
diff --git a/.bazelci/presubmit.yml b/.bazelci/presubmit.yml
index c693620..bdbf980 100644
--- a/.bazelci/presubmit.yml
+++ b/.bazelci/presubmit.yml
@@ -18,41 +18,25 @@
     test_targets:
       - "--"
       - "//..."
-  ubuntu2204_6_4_0:
+  ubuntu2204_7_x:
     platform: ubuntu2204
-    bazel: 6.4.0
-    environment:
-      REPIN: 1
-    shell_commands:
-      - bazel run @regression_testing_coursier//:pin
-      - bazel run @regression_testing_gradle//:pin
-      - bazel run @regression_testing_maven//:pin
-      - bazel run @maven_install_in_custom_location//:pin
-      - bazel run @same_override_target//:pin
-      - tests/bazel_run_tests.sh
-    test_targets:
-      - "--"
-      - "//..."
-  ubuntu2204_7_4_1:
-    platform: ubuntu2204
-    bazel: 7.4.1
-    environment:
-      REPIN: 1
-    shell_commands:
-      - bazel run @regression_testing_coursier//:pin
-      - bazel run @regression_testing_gradle//:pin
-      - bazel run @regression_testing_maven//:pin
-      - bazel run @maven_install_in_custom_location//:pin
-      - bazel run @same_override_target//:pin
-      - tests/bazel_run_tests.sh
-    test_targets:
-      - "--"
-      - "//..."
-  ubuntu2204_latest:
-    platform: ubuntu2204
-    # TODO: Revert to latest after fixing incompatibilities with Bazel 8.0.0
     bazel: 7.x
     environment:
+      REPIN: 1
+    shell_commands:
+      - bazel run @regression_testing_coursier//:pin
+      - bazel run @regression_testing_gradle//:pin
+      - bazel run @regression_testing_maven//:pin
+      - bazel run @maven_install_in_custom_location//:pin
+      - bazel run @same_override_target//:pin
+      - tests/bazel_run_tests.sh
+    test_targets:
+      - "--"
+      - "//..."
+  ubuntu2204_8_x:
+    platform: ubuntu2204
+    bazel: 8.x
+    environment:
       # This tests custom cache locations.
       # https://github.com/bazelbuild/rules_jvm_external/pull/316
       COURSIER_CACHE: /tmp/custom_coursier_cache
diff --git a/.bazelrc b/.bazelrc
index 29a6ef7..6db16c3 100644
--- a/.bazelrc
+++ b/.bazelrc
@@ -27,6 +27,11 @@
 # Enable protobuf MSVC support on Windows
 build:windows --define=protobuf_allow_msvc=true
 
+# rules_kotlin 2.x has a bug where the Kotlin compiler worker fails to
+# resolve runfiles on Windows without this flag.
+# https://github.com/bazelbuild/rules_kotlin/issues/1309
+build:windows --legacy_external_runfiles
+
 # Every JVM creates a temporary performance instrumentation file in
 # /tmp/hsperfdata_$USERNAME/$PID. When we use sandboxing, we use PID
 # namespaces, which means that the PIDs are virtualized and all
diff --git a/MODULE.bazel b/MODULE.bazel
index ca9ae99..106c84e 100644
--- a/MODULE.bazel
+++ b/MODULE.bazel
@@ -11,7 +11,7 @@
 bazel_dep(name = "platforms", version = "0.0.11")
 bazel_dep(name = "rules_license", version = "1.0.0")
 bazel_dep(name = "rules_java", version = "8.13.0")
-bazel_dep(name = "rules_kotlin", version = "1.9.6")
+bazel_dep(name = "rules_kotlin", version = "2.1.3")
 bazel_dep(name = "rules_shell", version = "0.4.1")
 
 bazel_dep(name = "aspect_bazel_lib", version = "2.20.0", dev_dependency = True)