Release v0.34.0 - #1228
Release v0.34.0#1228
Conversation
WalkthroughThis update replaces multiple Docker image tags and digests across several configuration files, moving from beta versions (primarily Changes
Estimated code review effort1 (~5 minutes) Possibly related PRs
Suggested reviewers
Poem
📜 Recent review detailsConfiguration used: CodeRabbit UI 📒 Files selected for processing (11)
✅ Files skipped from review due to trivial changes (3)
🚧 Files skipped from review as they are similar to previous changes (8)
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (1)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. 🪧 TipsChatThere are 3 ways to chat with CodeRabbit:
SupportNeed help? Create a ticket on our support page for assistance with any issues or questions. Note: Be mindful of the bot's finite context window. It's strongly recommended to break down tasks such as reading entire modules into smaller chunks. For a focused discussion, use review comments to chat about specific files and their changes, instead of using the PR comments. CodeRabbit Commands (Invoked using PR comments)
Other keywords and placeholders
CodeRabbit Configuration File (
|
There was a problem hiding this comment.
Summary of Changes
Hello Cozystack Bot (@cozystack-bot), I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!
This pull request is a standard release preparation, bumping the project version to v0.34.0. It primarily involves updating image tags and their corresponding SHA256 digests across various internal components and applications to reflect the new stable release, ensuring all dependencies point to the correct, finalized versions.
Highlights
- Version Update: This pull request updates the project version from
v0.34.0-beta.3tov0.34.0across various configuration files and image tags, preparing for the official release. - Container Image Digest Updates: Numerous container image SHA256 digests have been updated for core components and applications, including
nginx-cache,kubevirt-cloud-provider,kubevirt-csi-driver,installer,e2e-sandbox,matchbox,cozystack-api,cozystack-controller,dashboard,kubeapps-apis,kamaji,kubeovn-webhook, andkubeovn. This ensures that the release points to the correct, immutable image versions.
Using Gemini Code Assist
The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.
Invoking Gemini
You can request assistance from Gemini at any point in your pull request via creating an issue comment (i.e. comment on the pull request page) using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands.
| Feature | Command | Description |
|---|---|---|
| Code Review | /gemini review |
Performs a code review for the current pull request in its current state. |
| Pull Request Summary | /gemini summary |
Provides a summary of the current pull request in its current state. |
| Comment | Gemini (@gemini-code-assist) | Responds in comments when explicitly tagged, both in issue comments and review comments. |
| Help | /gemini help |
Displays a list of available commands. |
Customization
To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.
Limitations & Feedback
Gemini Code Assist is currently in preview and may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on Gemini (@gemini-code-assist) comments to provide feedback.
You can also get AI-powered code generation, chat, as well as code reviews directly in the IDE at no cost with the Gemini Code Assist IDE Extension.
Footnotes
-
Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution. ↩
There was a problem hiding this comment.
Code Review
This pull request prepares for the v0.34.0 release by updating version strings and image digests across various configuration files. The changes are largely consistent and what one would expect for a release.
I've found one potential issue in packages/system/kamaji/values.yaml where the image tag was updated to the release version, but the image digest remained the same as the beta version. Please review this to ensure it's correct.
Otherwise, the changes look good. Thank you for your work!
| image: | ||
| pullPolicy: IfNotPresent | ||
| tag: v0.34.0-beta.3@sha256:09465ae8285b4ae43203581e443409cd4e1e119dde62a5c14d63ce064fb840b0 | ||
| tag: v0.34.0@sha256:09465ae8285b4ae43203581e443409cd4e1e119dde62a5c14d63ce064fb840b0 |
There was a problem hiding this comment.
The image tag has been updated from v0.34.0-beta.3 to v0.34.0, but the SHA256 digest 09465ae8285b4ae43203581e443409cd4e1e119dde62a5c14d63ce064fb840b0 remains unchanged.
This suggests that the release image is identical to the beta image. Could you please confirm if this is the intended behavior? If the v0.34.0 image should include new changes, its digest should be updated accordingly.
There was a problem hiding this comment.
Actionable comments posted: 0
🧹 Nitpick comments (2)
packages/core/installer/values.yaml (1)
2-2: Consider centralising the release version to avoid future drift.
v0.34.0now appears here as a hard-coded literal. The same string is duplicated across several charts / values files in this PR. A single HelmValues.global.version(or a Kustomizevars) would let future releases bump one knob instead of dozens.packages/system/dashboard/charts/kubeapps/templates/dashboard/configmap.yaml (1)
79-79: Ensure thisappVersionis the single source of truth for the dashboard UI.There are at least three different files containing
"v0.34.0"for the dashboard (values, deployment, and this ConfigMap). Consider templating it from a common variable to avoid version skew on the next bump.
📜 Review details
Configuration used: CodeRabbit UI
Review profile: CHILL
Plan: Pro
📒 Files selected for processing (14)
packages/apps/http-cache/images/nginx-cache.tag(1 hunks)packages/apps/kubernetes/images/kubevirt-cloud-provider.tag(1 hunks)packages/apps/kubernetes/images/kubevirt-csi-driver.tag(1 hunks)packages/core/installer/values.yaml(1 hunks)packages/core/testing/values.yaml(1 hunks)packages/extra/bootbox/images/matchbox.tag(1 hunks)packages/system/cozystack-api/values.yaml(1 hunks)packages/system/cozystack-controller/values.yaml(1 hunks)packages/system/dashboard/charts/kubeapps/templates/dashboard/configmap.yaml(1 hunks)packages/system/dashboard/values.yaml(2 hunks)packages/system/kamaji/values.yaml(1 hunks)packages/system/kubeovn-webhook/values.yaml(1 hunks)packages/system/kubeovn/values.yaml(1 hunks)packages/system/kubevirt-csi-node/values.yaml(1 hunks)
🧰 Additional context used
🧠 Learnings (7)
📓 Common learnings
Learnt from: NickVolynkin
PR: cozystack/cozystack#1117
File: packages/apps/mysql/Makefile:8-8
Timestamp: 2025-06-26T04:29:24.830Z
Learning: The cozystack project uses yq v4+ on their CI runner, so yq v4 syntax (-o json --indent 4) is compatible and version checks are not needed.
Learnt from: NickVolynkin
PR: cozystack/cozystack#1120
File: packages/apps/ferretdb/README.md:35-37
Timestamp: 2025-07-02T09:58:11.406Z
Learning: In the cozystack repository, the maintainer NickVolynkin prefers to keep realistic-looking example credentials in README documentation rather than using generic placeholders like <ACCESS_KEY>, even though they are just examples and not real secrets.
packages/extra/bootbox/images/matchbox.tag (1)
Learnt from: NickVolynkin
PR: #1117
File: packages/apps/mysql/Makefile:8-8
Timestamp: 2025-06-26T04:29:24.830Z
Learning: The cozystack project uses yq v4+ on their CI runner, so yq v4 syntax (-o json --indent 4) is compatible and version checks are not needed.
packages/core/installer/values.yaml (2)
Learnt from: NickVolynkin
PR: #1117
File: packages/apps/mysql/Makefile:8-8
Timestamp: 2025-06-26T04:29:24.830Z
Learning: The cozystack project uses yq v4+ on their CI runner, so yq v4 syntax (-o json --indent 4) is compatible and version checks are not needed.
Learnt from: NickVolynkin
PR: #1120
File: packages/apps/ferretdb/README.md:35-37
Timestamp: 2025-07-02T09:58:11.406Z
Learning: In the cozystack repository, the maintainer NickVolynkin prefers to keep realistic-looking example credentials in README documentation rather than using generic placeholders like <ACCESS_KEY>, even though they are just examples and not real secrets.
packages/core/testing/values.yaml (1)
Learnt from: NickVolynkin
PR: #1117
File: packages/apps/mysql/Makefile:8-8
Timestamp: 2025-06-26T04:29:24.830Z
Learning: The cozystack project uses yq v4+ on their CI runner, so yq v4 syntax (-o json --indent 4) is compatible and version checks are not needed.
packages/system/cozystack-api/values.yaml (3)
Learnt from: NickVolynkin
PR: #1117
File: packages/apps/mysql/Makefile:8-8
Timestamp: 2025-06-26T04:29:24.830Z
Learning: The cozystack project uses yq v4+ on their CI runner, so yq v4 syntax (-o json --indent 4) is compatible and version checks are not needed.
Learnt from: NickVolynkin
PR: #1120
File: packages/apps/ferretdb/README.md:35-37
Timestamp: 2025-07-02T09:58:11.406Z
Learning: In the cozystack repository, the maintainer NickVolynkin prefers to keep realistic-looking example credentials in README documentation rather than using generic placeholders like <ACCESS_KEY>, even though they are just examples and not real secrets.
Learnt from: lllamnyp
PR: #1130
File: hack/e2e-apps/kubernetes.bats:101-101
Timestamp: 2025-07-11T06:11:25.438Z
Learning: In cozystack, the plural form for the Kubernetes custom resource is kuberneteses.apps.cozystack.io, not kubernetes.apps.cozystack.io. This is defined in the API schema even though it's not grammatically perfect.
packages/system/cozystack-controller/values.yaml (1)
Learnt from: NickVolynkin
PR: #1117
File: packages/apps/mysql/Makefile:8-8
Timestamp: 2025-06-26T04:29:24.830Z
Learning: The cozystack project uses yq v4+ on their CI runner, so yq v4 syntax (-o json --indent 4) is compatible and version checks are not needed.
packages/system/dashboard/values.yaml (2)
Learnt from: NickVolynkin
PR: #1117
File: packages/apps/mysql/Makefile:8-8
Timestamp: 2025-06-26T04:29:24.830Z
Learning: The cozystack project uses yq v4+ on their CI runner, so yq v4 syntax (-o json --indent 4) is compatible and version checks are not needed.
Learnt from: lllamnyp
PR: #1130
File: hack/e2e-apps/kubernetes.bats:101-101
Timestamp: 2025-07-11T06:11:25.438Z
Learning: In cozystack, the plural form for the Kubernetes custom resource is kuberneteses.apps.cozystack.io, not kubernetes.apps.cozystack.io. This is defined in the API schema even though it's not grammatically perfect.
🔇 Additional comments (15)
packages/apps/http-cache/images/nginx-cache.tag (1)
1-1: Manually verify nginx-cache image digest matches tag 0.6.1Automated manifest checks against GHCR failed due to authentication restrictions. Before merging, please pull and inspect the image locally to confirm the SHA-256 matches
0.6.1:• File:
packages/apps/http-cache/images/nginx-cache.tag(line 1)
• Diff snippet:- ghcr.io/cozystack/cozystack/nginx-cache:0.6.1@sha256:<old> + ghcr.io/cozystack/cozystack/nginx-cache:0.6.1@sha256:b7633717cd7449c0042ae92d8ca9b36e4d69566561f5c7d44e21058e7d05c6d5Example verification commands:
docker pull ghcr.io/cozystack/cozystack/nginx-cache:0.6.1 docker inspect --format='{{index .RepoDigests 0}}' ghcr.io/cozystack/cozystack/nginx-cache:0.6.1 # → should output: # ghcr.io/cozystack/cozystack/nginx-cache@sha256:b7633717cd7449c0042ae92d8ca9b36e4d69566561f5c7d44e21058e7d05c6d5If you cannot authenticate in CI, you can also log in with
docker login ghcr.ioor use the GH CLI to fetch the manifest.packages/system/kubeovn-webhook/values.yaml (1)
3-3: Stable tag pinning looks goodUpgrading from the beta tag to the final
v0.34.0while still pinning the SHA256 digest keeps the deployment reproducible. No further action needed.packages/core/testing/values.yaml (1)
2-2: Version bump approvedThe e2e image now targets the release tag; digest pinning remains intact. ✅
packages/extra/bootbox/images/matchbox.tag (1)
1-1: Matchbox image updatedImage tag aligns with the rest of the release. Looks correct.
packages/system/kamaji/values.yaml (1)
6-6: Digest unchanged – double-check registryOnly the tag changed from
v0.34.0-beta.3tov0.34.0but the digest stayed identical. Verify that the digest actually corresponds to the final build and not the beta artifact that was retagged.packages/system/cozystack-api/values.yaml (1)
2-2: Verify image digest for cozystack-api:v0.34.0Please confirm that the SHA256 in packages/system/cozystack-api/values.yaml (line 2) matches the actual manifest digest for the v0.34.0 release. You can run this locally:
# Using skopeo (if available) skopeo inspect docker://ghcr.io/cozystack/cozystack/cozystack-api:v0.34.0 | jq .Digest # Or with curl curl -sI \ -H "Accept: application/vnd.docker.distribution.manifest.v2+json" \ https://ghcr.io/v2/cozystack/cozystack/cozystack-api/manifests/v0.34.0 \ | grep -i Docker-Content-DigestCompare the returned digest to
sha256:ce79f0452c0ad457885575e1cfe9be9e8480e685d1c9c3daffc6669a5dd6d1f3packages/apps/kubernetes/images/kubevirt-csi-driver.tag (1)
1-1: Please verify the image digest for v0.26.0CI couldn’t run
craneorskopeoto confirm the manifest digest. Please ensure that the committed value
sha256:761e7235ff9cb7f6f223f00954943e6a5af32ed6624ee592a8610122f96febb0
actually corresponds to the v0.26.0 tag:You can verify locally by either:
- Installing crane or skopeo and running:
crane digest ghcr.io/cozystack/cozystack/kubevirt-csi-driver:0.26.0 # or skopeo inspect --raw docker://ghcr.io/cozystack/cozystack/kubevirt-csi-driver:0.26.0 \ | sha256sum | cut -d' ' -f1 | xargs printf 'sha256:%s'- Using curl against the registry API:
curl -sI \ -H "Accept: application/vnd.docker.distribution.manifest.v2+json" \ "https://ghcr.io/v2/cozystack/cozystack/kubevirt-csi-driver/manifests/0.26.0" \ | grep Docker-Content-Digest \ | awk '{print $2}' | tr -d '\r'The output must exactly match the expected digest. If it doesn’t, update the SHA in
packages/apps/kubernetes/images/kubevirt-csi-driver.tag.packages/core/installer/values.yaml (1)
2-2: Digest check recommended for the installer image.Same rationale as for the CSI driver: pinning is great, but we should assert that the pinned digest indeed corresponds to
v0.34.0.Locations to verify:
- packages/core/installer/values.yaml (line 2)
Sandbox lacked the
cranetool, so please verify manually using one of the following approaches:# Option A: Using crane (locally) crane digest ghcr.io/cozystack/cozystack/installer:v0.34.0 # Should output: # sha256:0b321cc76d20158486ab58493f9ed33979e24ba8ad8c75e3a13542a111659bdd# Option B: Using curl against the Docker Registry API curl -sSL -H "Accept: application/vnd.docker.distribution.manifest.v2+json" -I \ https://ghcr.io/v2/cozystack/cozystack/installer/manifests/v0.34.0 \ | grep Docker-Content-Digest # Expected: # Docker-Content-Digest: sha256:0b321cc76d20158486ab58493f9ed33979e24ba8ad8c75e3a13542a111659bddpackages/system/cozystack-controller/values.yaml (2)
2-5: KeepcozystackVersionin sync with the controller’s HelmappVersion.If the chart’s
Chart.yamlstill declaresappVersion: v0.34.0-beta.3, the UI will display mixed versions. Please double-check thatChart.yamlwas updated together with this file.
2-2: Verify controller image digestPlease manually verify that the SHA256 digest for the controller image tag
v0.34.0matches the one recorded in
packages/system/cozystack-controller/values.yaml(line 2):image: ghcr.io/cozystack/cozystack/cozystack-controller:v0.34.0@sha256:6ee879b73560c71451892443598d87939fe917ee7c05bb75ade5d5ed7a26cf6cUse your preferred OCI registry tool (for example,
crane digest,skopeo inspect, or the GitHub Container Registry API) to confirm:# Example with crane crane digest ghcr.io/cozystack/cozystack/cozystack-controller:v0.34.0 # Expect: sha256:6ee879b73560c71451892443598d87939fe917ee7c05bb75ade5d5ed7a26cf6cpackages/system/kubeovn/values.yaml (1)
67-67: Manual verification required: kube-ovn v1.13.14 digest bumpThe automated manifest fetch from GHCR returned HTTP 401 (authentication required), so we couldn’t diff layers programmatically. Please confirm that this digest update only includes rebuilds (security patches, SBOM, etc.) and no behavior-breaking changes:
• File packages/system/kubeovn/values.yaml, line 67
tag changed to
v1.13.14@sha256:3e5955030e81e51ce73333c59c63e9530bec832bda982d963323fc76c1550f9dRecommended manual checks:
- Locally pull both digests (old vs. new) with proper GHCR credentials and compare layers via
crane manifestordocker inspect.- Review the official kube-ovn v1.13.14 release notes/CHANGELOG for any minor or behavioral changes.
packages/apps/kubernetes/images/kubevirt-cloud-provider.tag (1)
1-1: Please manually verify the kubevirt-cloud-provider:0.26.0 digest on GHCRI wasn’t able to fetch the manifest digest via the public API (no
Docker-Content-Digestheader returned without authentication), so to avoid pull-through failures after release promotion, please confirm that the published image’s digest matches the one inpackages/apps/kubernetes/images/kubevirt-cloud-provider.tag:# 1. Log in to GHCR if you haven’t already docker login ghcr.io # 2. Pull the 0.26.0 image and inspect its digest docker pull ghcr.io/cozystack/cozystack/kubevirt-cloud-provider:0.26.0 docker inspect --format='{{index .RepoDigests 0}}' ghcr.io/cozystack/cozystack/kubevirt-cloud-provider:0.26.0 # Expected digest: # sha256:49843a0b670eab061627e48df338b2b8bc9f577dc2cfd4c2ed4071e02e64b424packages/system/kubevirt-csi-node/values.yaml (1)
3-3: Digest updated – ensure all references stay in sync.The CSI node chart now points to digest
761e7235…ebb0.
Confirm that:
packages/apps/kubernetes/images/kubevirt-csi-driver.tagwas updated to the same digest in this PR.- No other Helm charts (installer, cluster-templates, etc.) still reference the previous digest, otherwise mixed versions may roll out.
packages/system/dashboard/values.yaml (2)
22-24: Tag bump tov0.34.0– checkappVersion/Chart.yaml matches.The dashboard image moved from beta to GA. Ensure the chart’s
Chart.yamlappVersion(and any ConfigMaps that surface it) were bumped tov0.34.0; otherwise UI will still display the beta string.
40-41: Verify new digest before publishing Helm repo.Digest
450ec9d0…ea5e5must exist in GHCR before chart packaging; otherwisehelm installwill fail after the repo is indexed.
Signed-off-by: cozystack-bot <[email protected]>
f0afaba to
2e1a7a0
Compare
This PR prepares the release
v0.34.0.Summary by CodeRabbit