Release v0.34.0-beta.1 - #1187
Conversation
Signed-off-by: cozystack-bot <[email protected]>
WalkthroughThis update revises multiple container image tags, SHA256 digests, and version references across several configuration and values files. Most changes advance components from version Changes
Possibly related PRs
Suggested reviewers
Poem
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. 🪧 TipsChatThere are 3 ways to chat with CodeRabbit:
SupportNeed help? Create a ticket on our support page for assistance with any issues or questions. Note: Be mindful of the bot's finite context window. It's strongly recommended to break down tasks such as reading entire modules into smaller chunks. For a focused discussion, use review comments to chat about specific files and their changes, instead of using the PR comments. CodeRabbit Commands (Invoked using PR comments)
Other keywords and placeholders
CodeRabbit Configuration File (
|
There was a problem hiding this comment.
Actionable comments posted: 1
🧹 Nitpick comments (2)
packages/core/installer/values.yaml (1)
2-2: Consider omitting the tag when the digest is presentIncluding both is harmless but redundant; the digest guarantees immutability while the tag is ignored by registries/kubelet. Dropping the tag prevents future drift.
packages/core/testing/values.yaml (1)
2-2: Same optional cleanup as installerA digest-only reference is clearer:
- image: ghcr.io/cozystack/cozystack/e2e-sandbox:v0.34.0-beta.1@sha256:f0a7a45218122b57022e51d41c0e6b18d31621c8ec504651d2347f47e5e5f256 + image: ghcr.io/cozystack/cozystack/e2e-sandbox@sha256:f0a7a45218122b57022e51d41c0e6b18d31621c8ec504651d2347f47e5e5f256
📜 Review details
Configuration used: CodeRabbit UI
Review profile: CHILL
Plan: Pro
📒 Files selected for processing (13)
packages/apps/http-cache/images/nginx-cache.tag(1 hunks)packages/core/installer/values.yaml(1 hunks)packages/core/testing/values.yaml(1 hunks)packages/extra/bootbox/images/matchbox.tag(1 hunks)packages/system/bucket/images/s3manager.tag(1 hunks)packages/system/cilium/values.yaml(1 hunks)packages/system/cozystack-api/values.yaml(1 hunks)packages/system/cozystack-controller/values.yaml(1 hunks)packages/system/dashboard/charts/kubeapps/templates/dashboard/configmap.yaml(1 hunks)packages/system/dashboard/values.yaml(2 hunks)packages/system/kamaji/values.yaml(1 hunks)packages/system/kubeovn-webhook/values.yaml(1 hunks)packages/system/kubeovn/values.yaml(1 hunks)
🧰 Additional context used
🧠 Learnings (7)
📓 Common learnings
Learnt from: NickVolynkin
PR: cozystack/cozystack#1117
File: packages/apps/mysql/Makefile:8-8
Timestamp: 2025-06-26T04:29:24.830Z
Learning: The cozystack project uses yq v4+ on their CI runner, so yq v4 syntax (-o json --indent 4) is compatible and version checks are not needed.
Learnt from: NickVolynkin
PR: cozystack/cozystack#1120
File: packages/apps/ferretdb/README.md:35-37
Timestamp: 2025-07-02T09:58:11.406Z
Learning: In the cozystack repository, the maintainer NickVolynkin prefers to keep realistic-looking example credentials in README documentation rather than using generic placeholders like <ACCESS_KEY>, even though they are just examples and not real secrets.
packages/core/installer/values.yaml (2)
Learnt from: NickVolynkin
PR: cozystack/cozystack#1117
File: packages/apps/mysql/Makefile:8-8
Timestamp: 2025-06-26T04:29:24.830Z
Learning: The cozystack project uses yq v4+ on their CI runner, so yq v4 syntax (-o json --indent 4) is compatible and version checks are not needed.
Learnt from: NickVolynkin
PR: cozystack/cozystack#1120
File: packages/apps/ferretdb/README.md:35-37
Timestamp: 2025-07-02T09:58:11.406Z
Learning: In the cozystack repository, the maintainer NickVolynkin prefers to keep realistic-looking example credentials in README documentation rather than using generic placeholders like <ACCESS_KEY>, even though they are just examples and not real secrets.
packages/core/testing/values.yaml (1)
Learnt from: NickVolynkin
PR: cozystack/cozystack#1117
File: packages/apps/mysql/Makefile:8-8
Timestamp: 2025-06-26T04:29:24.830Z
Learning: The cozystack project uses yq v4+ on their CI runner, so yq v4 syntax (-o json --indent 4) is compatible and version checks are not needed.
packages/system/cozystack-api/values.yaml (2)
Learnt from: NickVolynkin
PR: cozystack/cozystack#1117
File: packages/apps/mysql/Makefile:8-8
Timestamp: 2025-06-26T04:29:24.830Z
Learning: The cozystack project uses yq v4+ on their CI runner, so yq v4 syntax (-o json --indent 4) is compatible and version checks are not needed.
Learnt from: NickVolynkin
PR: cozystack/cozystack#1120
File: packages/apps/ferretdb/README.md:35-37
Timestamp: 2025-07-02T09:58:11.406Z
Learning: In the cozystack repository, the maintainer NickVolynkin prefers to keep realistic-looking example credentials in README documentation rather than using generic placeholders like <ACCESS_KEY>, even though they are just examples and not real secrets.
packages/extra/bootbox/images/matchbox.tag (1)
Learnt from: NickVolynkin
PR: cozystack/cozystack#1117
File: packages/apps/mysql/Makefile:8-8
Timestamp: 2025-06-26T04:29:24.830Z
Learning: The cozystack project uses yq v4+ on their CI runner, so yq v4 syntax (-o json --indent 4) is compatible and version checks are not needed.
packages/system/cozystack-controller/values.yaml (1)
Learnt from: NickVolynkin
PR: cozystack/cozystack#1117
File: packages/apps/mysql/Makefile:8-8
Timestamp: 2025-06-26T04:29:24.830Z
Learning: The cozystack project uses yq v4+ on their CI runner, so yq v4 syntax (-o json --indent 4) is compatible and version checks are not needed.
packages/system/bucket/images/s3manager.tag (2)
Learnt from: NickVolynkin
PR: cozystack/cozystack#1120
File: packages/apps/ferretdb/README.md:35-37
Timestamp: 2025-07-02T09:58:11.406Z
Learning: In the cozystack repository, the maintainer NickVolynkin prefers to keep realistic-looking example credentials in README documentation rather than using generic placeholders like <ACCESS_KEY>, even though they are just examples and not real secrets.
Learnt from: NickVolynkin
PR: cozystack/cozystack#1117
File: packages/apps/mysql/Makefile:8-8
Timestamp: 2025-06-26T04:29:24.830Z
Learning: The cozystack project uses yq v4+ on their CI runner, so yq v4 syntax (-o json --indent 4) is compatible and version checks are not needed.
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (1)
- GitHub Check: Prepare environment
🔇 Additional comments (12)
packages/apps/http-cache/images/nginx-cache.tag (1)
1-1: Confirm the new digest matches the remote image
Digest typos easily slip through and break pulls. Automated HEAD requests didn’t return a manifest digest, so please verify manually thatsha256:50ac1581e3100bd6c477a71161cb455a341ffaf9e5e2f6086802e4e25271e8afis indeed the digest forghcr.io/cozystack/cozystack/nginx-cache:0.6.0. For example, you can run:
skopeo inspect --format '{{.Digest}}' docker://ghcr.io/cozystack/cozystack/nginx-cache:0.6.0crane digest ghcr.io/cozystack/cozystack/nginx-cache:0.6.0docker manifest inspect ghcr.io/cozystack/cozystack/nginx-cache:0.6.0 | jq -r '.config.digest'packages/system/cilium/values.yaml (1)
17-18: Verify the pinned Cilium digest with authenticated registry accessWe weren’t able to retrieve the manifest digest via unauthenticated HTTP HEAD—GHCR requires credentials for the distribution API. Please manually confirm that the digest in
packages/system/cilium/values.yamltruly matchesghcr.io/cozystack/cozystack/cilium:1.17.5.Suggested approaches (after logging in to GHCR):
- Docker pull + inspect
docker login ghcr.io docker pull ghcr.io/cozystack/cozystack/cilium:1.17.5 docker inspect --format='{{index .RepoDigests 0}}' ghcr.io/cozystack/cozystack/cilium:1.17.5- Docker manifest inspect
docker manifest inspect ghcr.io/cozystack/cozystack/cilium:1.17.5 \ --verbose | jq -r '.config.digest'- Using
cranefrom Google’sgo-containerregistrycrane digest ghcr.io/cozystack/cozystack/cilium:1.17.5Ensure the retrieved digest equals
sha256:2def2dccfc17870be6e1d63584c25b32e812f21c9cdcfa06deadd2787606654dpackages/system/bucket/images/s3manager.tag (1)
1-1: Manual verification required: confirm GHCR image digest
GHCR requires authentication for manifest HEAD requests, so the automated check returned HTTP 401. Please double-check that the SHA256 digest inpackages/system/bucket/images/s3manager.tagmatches the published manifest forv0.5.0. You can verify it by either:• Pulling and inspecting the image locally (if public or after
gh auth login):docker pull ghcr.io/cozystack/cozystack/s3manager:v0.5.0 docker inspect --format='{{index .RepoDigests 0}}' ghcr.io/cozystack/cozystack/s3manager:v0.5.0• Using an authenticated curl call:
export CR_PAT=<YOUR_GHCR_TOKEN> curl -sI \ -H "Authorization: Bearer $CR_PAT" \ -H "Accept: application/vnd.docker.distribution.manifest.v2+json" \ "https://ghcr.io/v2/cozystack/cozystack/s3manager/manifests/v0.5.0" \ | awk '/^Docker-Content-Digest:/ {print $2}'Locations to verify:
- packages/system/bucket/images/s3manager.tag (line 1)
packages/system/cozystack-api/values.yaml (1)
2-2: Verify GHCR image digest for v0.34.0-beta.1The tag v0.34.0-beta.1 is being overridden by the existing digest, which likely still points at the prior image. Please confirm and update the digest to avoid running an unintended version.
Locations to check:
- packages/system/cozystack-api/values.yaml (line 2)
Suggested update:
- image: ghcr.io/cozystack/cozystack/cozystack-api:v0.34.0-beta.1@sha256:724a166d2daa9cae3caeb18bffdc7146d80de310a6f97360c2beaef340076e6d + # Replace with the verified digest for v0.34.0-beta.1 + image: ghcr.io/cozystack/cozystack/cozystack-api:v0.34.0-beta.1@sha256:<new-digest>Manual verification options:
- Docker CLI:
docker pull ghcr.io/cozystack/cozystack/cozystack-api:v0.34.0-beta.1 docker inspect --format='{{index .RepoDigests 0}}' ghcr.io/cozystack/cozystack/cozystack-api:v0.34.0-beta.1- GitHub CLI:
gh api \ /orgs/cozystack/packages/container/cozystack-api/versions \ --jq '.[] | select(.metadata.container.tags[]=="v0.34.0-beta.1") | .metadata.container.digest'packages/system/kubeovn/values.yaml (1)
65-68: Thumbs-up – tag & digest move togetherTag
v1.13.14accompanies a new digest, eliminating the “tag-digest mismatch” pitfall seen elsewhere.packages/extra/bootbox/images/matchbox.tag (1)
1-1: Pinned digest for new tag ensures reproducible builds
The reference is fully qualified (tag@digest), guaranteeing immutability across environments.packages/system/kubeovn-webhook/values.yaml (1)
3-3: Confirm tag ↔ digest pairing
Please double-check thatsha256:c7f42022280a…is indeed the manifest digest forv0.34.0-beta.1to avoid accidental tag drift.packages/system/cozystack-controller/values.yaml (2)
2-2: Image update looks correct
Fully-pinned image reference LGTM.
5-5: Verify downstream consumers ofcozystackVersion
Ensure any CRDs or helm templates that read.Values.cozystackVersionwere bumped as well, otherwise version skew warnings may appear at runtime.packages/system/dashboard/charts/kubeapps/templates/dashboard/configmap.yaml (1)
79-79: Dashboard displays the new version
appVersionnow matches the release tag; no further action required.packages/system/dashboard/values.yaml (2)
22-24: Dashboard image pinned correctly
Tag and digest updated coherently—good job keeping them in sync.
40-41: Cross-check digest forkubeapps-apis
As with the webhook, please verifysha256:0270aea2e4b…matchesv0.34.0-beta.1to prevent pull-through of an unintended image.
| image: | ||
| pullPolicy: IfNotPresent | ||
| tag: v0.33.2@sha256:09465ae8285b4ae43203581e443409cd4e1e119dde62a5c14d63ce064fb840b0 | ||
| tag: v0.34.0-beta.1@sha256:09465ae8285b4ae43203581e443409cd4e1e119dde62a5c14d63ce064fb840b0 |
There was a problem hiding this comment.
💡 Verification agent
🧩 Analysis chain
Same problem: tag bumped, digest unchanged
sha256:09465a… appears to be reused from the previous release.
Please publish the new image or adjust the manifest as suggested above.
[same reasoning as previous]
🏁 Script executed:
#!/usr/bin/env bash
# Compare image tag digests between the previous commit and the current commit
prev_digest=$(git show HEAD~1:packages/system/kamaji/values.yaml | grep "tag:" | sed -E 's/.*@([a-z0-9:]+)$/\1/')
curr_digest=$(grep "tag:" packages/system/kamaji/values.yaml | sed -E 's/.*@([a-z0-9:]+)$/\1/')
echo "Previous digest: $prev_digest"
echo "Current digest: $curr_digest"Length of output: 730
Critical: Image tag bumped without updating digest
The SHA256 digest for v0.34.0-beta.1 remains identical to the previous release, indicating no new image was published. Please publish the new image and update the sha256 value in packages/system/kamaji/values.yaml accordingly.
- File: packages/system/kamaji/values.yaml
Line 6:tag: v0.34.0-beta.1@sha256:09465ae8285b4ae43203581e443409cd4e1e119dde62a5c14d63ce064fb840b0
🤖 Prompt for AI Agents
In packages/system/kamaji/values.yaml at line 6, the image tag was updated to
v0.34.0-beta.1 but the SHA256 digest was not changed and still matches the
previous release. To fix this, ensure the new image for v0.34.0-beta.1 is
published, then update the sha256 value in the tag field to the correct digest
corresponding to the newly published image.
This PR prepares the release
v0.34.0-beta.1.Summary by CodeRabbit