Skip to content

Release v0.34.0-beta.1 - #1187

Merged
Andrei Kvapil (kvaps) merged 1 commit into
mainfrom
release-0.34.0-beta.1
Jul 10, 2025
Merged

Andrei Kvapil (kvaps) merged 1 commit into
mainfrom
release-0.34.0-beta.1

Conversation

@cozystack-bot

@cozystack-bot Cozystack Bot (cozystack-bot) commented Jul 10, 2025 •

Copy link
Copy Markdown
Contributor

This PR prepares the release v0.34.0-beta.1.

Summary by CodeRabbit

  • Chores
    • Updated multiple container image versions and tags across various components to newer releases, including several beta versions.
    • Refreshed image digests to ensure the latest builds are used.
    • Updated dashboard configuration to reflect the new app version.
    • No changes to functionality or user interface.

Signed-off-by: cozystack-bot <[email protected]>
@coderabbitai

coderabbitai Bot commented Jul 10, 2025 •

Copy link
Copy Markdown
Contributor

Walkthrough

This update revises multiple container image tags, SHA256 digests, and version references across several configuration and values files. Most changes advance components from version v0.33.2 to v0.34.0-beta.1 or update third-party images to newer patch versions. No structural or logic changes are introduced.

Changes

File(s) Change Summary
packages/apps/http-cache/images/nginx-cache.tag Updated nginx-cache image digest to a new SHA256 value for the same version.
packages/core/installer/values.yaml
packages/core/testing/values.yaml
Updated cozystack installer and e2e image tags and digests from v0.33.2 to v0.34.0-beta.1.
packages/extra/bootbox/images/matchbox.tag Updated matchbox image tag and digest from v0.33.2 to v0.34.0-beta.1.
packages/system/bucket/images/s3manager.tag Updated s3manager image digest to a new SHA256 value for the same version v0.5.0.
packages/system/cilium/values.yaml Updated Cilium image tag and digest from 1.17.4 to 1.17.5.
packages/system/cozystack-api/values.yaml Updated cozystackAPI image tag from v0.33.2 to v0.34.0-beta.1.
packages/system/cozystack-controller/values.yaml Updated controller image tag and cozystackVersion from v0.33.2 to v0.34.0-beta.1.
packages/system/dashboard/charts/kubeapps/templates/dashboard/configmap.yaml Updated dashboard ConfigMap appVersion from v0.33.2 to v0.34.0-beta.1.
packages/system/dashboard/values.yaml Updated dashboard and kubeapps-apis image tags and digests from v0.33.2 to v0.34.0-beta.1.
packages/system/kamaji/values.yaml Updated Kamaji image tag from v0.33.2 to v0.34.0-beta.1.
packages/system/kubeovn-webhook/values.yaml Updated kubeovn-webhook image tag from v0.33.2 to v0.34.0-beta.1.
packages/system/kubeovn/values.yaml Updated kubeovn image tag and digest from v1.13.13 to v1.13.14.

Possibly related PRs

  • cozystack/cozystack#450: Updates image tags and SHA256 digests for the nginx-cache component, affecting the same file.
  • cozystack/cozystack#562: Modifies the dashboard ConfigMap's appVersion field, similar to the update in this PR.
  • cozystack/cozystack#630: Updates image references to a different release version, involving similar files and fields.

Suggested reviewers

  • lllamnyp
  • kvaps
  • klinch0

Poem

A hop, a skip, a version bump,
New tags and digests—thump, thump, thump!
Beta bunnies race ahead,
With fresher images, bugs to shed.
From dashboard bright to s3 delight,
We leap to beta, code in flight!
🐇✨


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share
🪧 Tips

Chat

There are 3 ways to chat with CodeRabbit:

  • Review comments: Directly reply to a review comment made by CodeRabbit. Example:
    • I pushed a fix in commit <commit_id>, please review it.
    • Explain this complex logic.
    • Open a follow-up GitHub issue for this discussion.
  • Files and specific lines of code (under the "Files changed" tab): Tag @coderabbitai in a new review comment at the desired location with your query. Examples:
    • @coderabbitai explain this code block.
    • @coderabbitai modularize this function.
  • PR comments: Tag @coderabbitai in a new PR comment to ask questions about the PR branch. For the best results, please provide a very specific query, as very limited context is provided in this mode. Examples:
    • @coderabbitai gather interesting stats about this repository and render them as a table. Additionally, render a pie chart showing the language distribution in the codebase.
    • @coderabbitai read src/utils.ts and explain its main purpose.
    • @coderabbitai read the files in the src/scheduler package and generate a class diagram using mermaid and a README in the markdown format.
    • @coderabbitai help me debug CodeRabbit configuration file.

Support

Need help? Create a ticket on our support page for assistance with any issues or questions.

Note: Be mindful of the bot's finite context window. It's strongly recommended to break down tasks such as reading entire modules into smaller chunks. For a focused discussion, use review comments to chat about specific files and their changes, instead of using the PR comments.

CodeRabbit Commands (Invoked using PR comments)

  • @coderabbitai pause to pause the reviews on a PR.
  • @coderabbitai resume to resume the paused reviews.
  • @coderabbitai review to trigger an incremental review. This is useful when automatic reviews are disabled for the repository.
  • @coderabbitai full review to do a full review from scratch and review all the files again.
  • @coderabbitai summary to regenerate the summary of the PR.
  • @coderabbitai generate docstrings to generate docstrings for this PR.
  • @coderabbitai generate sequence diagram to generate a sequence diagram of the changes in this PR.
  • @coderabbitai resolve resolve all the CodeRabbit review comments.
  • @coderabbitai configuration to show the current CodeRabbit configuration for the repository.
  • @coderabbitai help to get help.

Other keywords and placeholders

  • Add @coderabbitai ignore anywhere in the PR description to prevent this PR from being reviewed.
  • Add @coderabbitai summary to generate the high-level summary at a specific location in the PR description.
  • Add @coderabbitai anywhere in the PR title to generate the title automatically.

CodeRabbit Configuration File (.coderabbit.yaml)

  • You can programmatically configure CodeRabbit by adding a .coderabbit.yaml file to the root of your repository.
  • Please see the configuration documentation for more information.
  • If your editor has YAML language server enabled, you can add the path at the top of this file to enable auto-completion and validation: # yaml-language-server: $schema=https://coderabbit.ai/integrations/schema.v2.json

Documentation and Community

  • Visit our Documentation for detailed information on how to use CodeRabbit.
  • Join our Discord Community to get help, request features, and share feedback.
  • Follow us on X/Twitter for updates and announcements.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (2)
packages/core/installer/values.yaml (1)

2-2: Consider omitting the tag when the digest is present

Including both is harmless but redundant; the digest guarantees immutability while the tag is ignored by registries/kubelet. Dropping the tag prevents future drift.

packages/core/testing/values.yaml (1)

2-2: Same optional cleanup as installer

A digest-only reference is clearer:

-  image: ghcr.io/cozystack/cozystack/e2e-sandbox:v0.34.0-beta.1@sha256:f0a7a45218122b57022e51d41c0e6b18d31621c8ec504651d2347f47e5e5f256
+  image: ghcr.io/cozystack/cozystack/e2e-sandbox@sha256:f0a7a45218122b57022e51d41c0e6b18d31621c8ec504651d2347f47e5e5f256
📜 Review details

Configuration used: CodeRabbit UI
Review profile: CHILL
Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between 32aea42 and 0ecb858.

📒 Files selected for processing (13)
  • packages/apps/http-cache/images/nginx-cache.tag (1 hunks)
  • packages/core/installer/values.yaml (1 hunks)
  • packages/core/testing/values.yaml (1 hunks)
  • packages/extra/bootbox/images/matchbox.tag (1 hunks)
  • packages/system/bucket/images/s3manager.tag (1 hunks)
  • packages/system/cilium/values.yaml (1 hunks)
  • packages/system/cozystack-api/values.yaml (1 hunks)
  • packages/system/cozystack-controller/values.yaml (1 hunks)
  • packages/system/dashboard/charts/kubeapps/templates/dashboard/configmap.yaml (1 hunks)
  • packages/system/dashboard/values.yaml (2 hunks)
  • packages/system/kamaji/values.yaml (1 hunks)
  • packages/system/kubeovn-webhook/values.yaml (1 hunks)
  • packages/system/kubeovn/values.yaml (1 hunks)
🧰 Additional context used
🧠 Learnings (7)
📓 Common learnings
Learnt from: NickVolynkin
PR: cozystack/cozystack#1117
File: packages/apps/mysql/Makefile:8-8
Timestamp: 2025-06-26T04:29:24.830Z
Learning: The cozystack project uses yq v4+ on their CI runner, so yq v4 syntax (-o json --indent 4) is compatible and version checks are not needed.
Learnt from: NickVolynkin
PR: cozystack/cozystack#1120
File: packages/apps/ferretdb/README.md:35-37
Timestamp: 2025-07-02T09:58:11.406Z
Learning: In the cozystack repository, the maintainer NickVolynkin prefers to keep realistic-looking example credentials in README documentation rather than using generic placeholders like <ACCESS_KEY>, even though they are just examples and not real secrets.
packages/core/installer/values.yaml (2)
Learnt from: NickVolynkin
PR: cozystack/cozystack#1117
File: packages/apps/mysql/Makefile:8-8
Timestamp: 2025-06-26T04:29:24.830Z
Learning: The cozystack project uses yq v4+ on their CI runner, so yq v4 syntax (-o json --indent 4) is compatible and version checks are not needed.
Learnt from: NickVolynkin
PR: cozystack/cozystack#1120
File: packages/apps/ferretdb/README.md:35-37
Timestamp: 2025-07-02T09:58:11.406Z
Learning: In the cozystack repository, the maintainer NickVolynkin prefers to keep realistic-looking example credentials in README documentation rather than using generic placeholders like <ACCESS_KEY>, even though they are just examples and not real secrets.
packages/core/testing/values.yaml (1)
Learnt from: NickVolynkin
PR: cozystack/cozystack#1117
File: packages/apps/mysql/Makefile:8-8
Timestamp: 2025-06-26T04:29:24.830Z
Learning: The cozystack project uses yq v4+ on their CI runner, so yq v4 syntax (-o json --indent 4) is compatible and version checks are not needed.
packages/system/cozystack-api/values.yaml (2)
Learnt from: NickVolynkin
PR: cozystack/cozystack#1117
File: packages/apps/mysql/Makefile:8-8
Timestamp: 2025-06-26T04:29:24.830Z
Learning: The cozystack project uses yq v4+ on their CI runner, so yq v4 syntax (-o json --indent 4) is compatible and version checks are not needed.
Learnt from: NickVolynkin
PR: cozystack/cozystack#1120
File: packages/apps/ferretdb/README.md:35-37
Timestamp: 2025-07-02T09:58:11.406Z
Learning: In the cozystack repository, the maintainer NickVolynkin prefers to keep realistic-looking example credentials in README documentation rather than using generic placeholders like <ACCESS_KEY>, even though they are just examples and not real secrets.
packages/extra/bootbox/images/matchbox.tag (1)
Learnt from: NickVolynkin
PR: cozystack/cozystack#1117
File: packages/apps/mysql/Makefile:8-8
Timestamp: 2025-06-26T04:29:24.830Z
Learning: The cozystack project uses yq v4+ on their CI runner, so yq v4 syntax (-o json --indent 4) is compatible and version checks are not needed.
packages/system/cozystack-controller/values.yaml (1)
Learnt from: NickVolynkin
PR: cozystack/cozystack#1117
File: packages/apps/mysql/Makefile:8-8
Timestamp: 2025-06-26T04:29:24.830Z
Learning: The cozystack project uses yq v4+ on their CI runner, so yq v4 syntax (-o json --indent 4) is compatible and version checks are not needed.
packages/system/bucket/images/s3manager.tag (2)
Learnt from: NickVolynkin
PR: cozystack/cozystack#1120
File: packages/apps/ferretdb/README.md:35-37
Timestamp: 2025-07-02T09:58:11.406Z
Learning: In the cozystack repository, the maintainer NickVolynkin prefers to keep realistic-looking example credentials in README documentation rather than using generic placeholders like <ACCESS_KEY>, even though they are just examples and not real secrets.
Learnt from: NickVolynkin
PR: cozystack/cozystack#1117
File: packages/apps/mysql/Makefile:8-8
Timestamp: 2025-06-26T04:29:24.830Z
Learning: The cozystack project uses yq v4+ on their CI runner, so yq v4 syntax (-o json --indent 4) is compatible and version checks are not needed.
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (1)
  • GitHub Check: Prepare environment
🔇 Additional comments (12)
packages/apps/http-cache/images/nginx-cache.tag (1)

1-1: Confirm the new digest matches the remote image
Digest typos easily slip through and break pulls. Automated HEAD requests didn’t return a manifest digest, so please verify manually that sha256:50ac1581e3100bd6c477a71161cb455a341ffaf9e5e2f6086802e4e25271e8af is indeed the digest for ghcr.io/cozystack/cozystack/nginx-cache:0.6.0. For example, you can run:

  • skopeo inspect --format '{{.Digest}}' docker://ghcr.io/cozystack/cozystack/nginx-cache:0.6.0
  • crane digest ghcr.io/cozystack/cozystack/nginx-cache:0.6.0
  • docker manifest inspect ghcr.io/cozystack/cozystack/nginx-cache:0.6.0 | jq -r '.config.digest'
packages/system/cilium/values.yaml (1)

17-18: Verify the pinned Cilium digest with authenticated registry access

We weren’t able to retrieve the manifest digest via unauthenticated HTTP HEAD—GHCR requires credentials for the distribution API. Please manually confirm that the digest in packages/system/cilium/values.yaml truly matches ghcr.io/cozystack/cozystack/cilium:1.17.5.

Suggested approaches (after logging in to GHCR):

  • Docker pull + inspect
    docker login ghcr.io
    docker pull ghcr.io/cozystack/cozystack/cilium:1.17.5
    docker inspect --format='{{index .RepoDigests 0}}' ghcr.io/cozystack/cozystack/cilium:1.17.5
    
  • Docker manifest inspect
    docker manifest inspect ghcr.io/cozystack/cozystack/cilium:1.17.5 \
      --verbose | jq -r '.config.digest'
    
  • Using crane from Google’s go-containerregistry
    crane digest ghcr.io/cozystack/cozystack/cilium:1.17.5
    

Ensure the retrieved digest equals
sha256:2def2dccfc17870be6e1d63584c25b32e812f21c9cdcfa06deadd2787606654d

packages/system/bucket/images/s3manager.tag (1)

1-1: Manual verification required: confirm GHCR image digest
GHCR requires authentication for manifest HEAD requests, so the automated check returned HTTP 401. Please double-check that the SHA256 digest in packages/system/bucket/images/s3manager.tag matches the published manifest for v0.5.0. You can verify it by either:

• Pulling and inspecting the image locally (if public or after gh auth login):

docker pull ghcr.io/cozystack/cozystack/s3manager:v0.5.0
docker inspect --format='{{index .RepoDigests 0}}' ghcr.io/cozystack/cozystack/s3manager:v0.5.0

• Using an authenticated curl call:

export CR_PAT=<YOUR_GHCR_TOKEN>
curl -sI \
  -H "Authorization: Bearer $CR_PAT" \
  -H "Accept: application/vnd.docker.distribution.manifest.v2+json" \
  "https://ghcr.io/v2/cozystack/cozystack/s3manager/manifests/v0.5.0" \
  | awk '/^Docker-Content-Digest:/ {print $2}'

Locations to verify:

  • packages/system/bucket/images/s3manager.tag (line 1)
packages/system/cozystack-api/values.yaml (1)

2-2: Verify GHCR image digest for v0.34.0-beta.1

The tag v0.34.0-beta.1 is being overridden by the existing digest, which likely still points at the prior image. Please confirm and update the digest to avoid running an unintended version.

Locations to check:

  • packages/system/cozystack-api/values.yaml (line 2)

Suggested update:

-  image: ghcr.io/cozystack/cozystack/cozystack-api:v0.34.0-beta.1@sha256:724a166d2daa9cae3caeb18bffdc7146d80de310a6f97360c2beaef340076e6d
+  # Replace with the verified digest for v0.34.0-beta.1
+  image: ghcr.io/cozystack/cozystack/cozystack-api:v0.34.0-beta.1@sha256:<new-digest>

Manual verification options:

  • Docker CLI:
    docker pull ghcr.io/cozystack/cozystack/cozystack-api:v0.34.0-beta.1
    docker inspect --format='{{index .RepoDigests 0}}' ghcr.io/cozystack/cozystack/cozystack-api:v0.34.0-beta.1
    
  • GitHub CLI:
    gh api \
      /orgs/cozystack/packages/container/cozystack-api/versions \
      --jq '.[] | select(.metadata.container.tags[]=="v0.34.0-beta.1") | .metadata.container.digest'
    
packages/system/kubeovn/values.yaml (1)

65-68: Thumbs-up – tag & digest move together

Tag v1.13.14 accompanies a new digest, eliminating the “tag-digest mismatch” pitfall seen elsewhere.

packages/extra/bootbox/images/matchbox.tag (1)

1-1: Pinned digest for new tag ensures reproducible builds
The reference is fully qualified (tag@digest), guaranteeing immutability across environments.

packages/system/kubeovn-webhook/values.yaml (1)

3-3: Confirm tag ↔ digest pairing
Please double-check that sha256:c7f42022280a… is indeed the manifest digest for v0.34.0-beta.1 to avoid accidental tag drift.

packages/system/cozystack-controller/values.yaml (2)

2-2: Image update looks correct
Fully-pinned image reference LGTM.


5-5: Verify downstream consumers of cozystackVersion
Ensure any CRDs or helm templates that read .Values.cozystackVersion were bumped as well, otherwise version skew warnings may appear at runtime.

packages/system/dashboard/charts/kubeapps/templates/dashboard/configmap.yaml (1)

79-79: Dashboard displays the new version
appVersion now matches the release tag; no further action required.

packages/system/dashboard/values.yaml (2)

22-24: Dashboard image pinned correctly
Tag and digest updated coherently—good job keeping them in sync.


40-41: Cross-check digest for kubeapps-apis
As with the webhook, please verify sha256:0270aea2e4b… matches v0.34.0-beta.1 to prevent pull-through of an unintended image.

image:
pullPolicy: IfNotPresent
tag: v0.33.2@sha256:09465ae8285b4ae43203581e443409cd4e1e119dde62a5c14d63ce064fb840b0
tag: v0.34.0-beta.1@sha256:09465ae8285b4ae43203581e443409cd4e1e119dde62a5c14d63ce064fb840b0

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Verification agent

🧩 Analysis chain

Same problem: tag bumped, digest unchanged

sha256:09465a… appears to be reused from the previous release.
Please publish the new image or adjust the manifest as suggested above.

[same reasoning as previous]


🏁 Script executed:

#!/usr/bin/env bash
# Compare image tag digests between the previous commit and the current commit
prev_digest=$(git show HEAD~1:packages/system/kamaji/values.yaml | grep "tag:" | sed -E 's/.*@([a-z0-9:]+)$/\1/')
curr_digest=$(grep "tag:" packages/system/kamaji/values.yaml | sed -E 's/.*@([a-z0-9:]+)$/\1/')
echo "Previous digest: $prev_digest"
echo "Current digest:  $curr_digest"

Length of output: 730


Critical: Image tag bumped without updating digest

The SHA256 digest for v0.34.0-beta.1 remains identical to the previous release, indicating no new image was published. Please publish the new image and update the sha256 value in packages/system/kamaji/values.yaml accordingly.

  • File: packages/system/kamaji/values.yaml
    Line 6: tag: v0.34.0-beta.1@sha256:09465ae8285b4ae43203581e443409cd4e1e119dde62a5c14d63ce064fb840b0
🤖 Prompt for AI Agents
In packages/system/kamaji/values.yaml at line 6, the image tag was updated to
v0.34.0-beta.1 but the SHA256 digest was not changed and still matches the
previous release. To fix this, ensure the new image for v0.34.0-beta.1 is
published, then update the sha256 value in the tag field to the correct digest
corresponding to the newly published image.

@kvaps
Andrei Kvapil (kvaps) merged commit 08cb7c0 into main Jul 10, 2025
@kvaps
Andrei Kvapil (kvaps) deleted the release-0.34.0-beta.1 branch July 10, 2025 09:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

release Releasing a new Cozystack version

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants