Skip to content

feat(system): update ingress-nginx, cozy-proxy, cozystack-scheduler and keycloak-kms-proxy to multi-arch releases - #4549

Merged
IvanHunters merged 4 commits into
mainfrom
feat/bump-multiarch-components
Sep 28, 2026
Merged

IvanHunters merged 4 commits into
mainfrom
feat/bump-multiarch-components

Conversation

@lexfrei

@lexfrei Aleksei Sviridkin (lexfrei) commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

What this PR does

Four components move to their first releases built for both linux/amd64 and linux/arm64. The current pins are amd64 only, so these pods cannot start on an arm64 node.

  • ingress-nginx: the cozystack controller and protobuf-exporter rebuild goes to v1.11.6, and the vendored chart moves to the matching 4.11.6. Upstream 1.11.6 is a maintenance release (Go, dependencies, NGINX base). The template and Lua code the rebuild patches are unchanged since 1.11.5.
  • cozy-proxy v0.4.0
  • cozystack-scheduler v0.4.0
  • keycloak-kms-proxy 0.2.3

The charts were re-vendored with make update. Every digest resolves to an index that has both platforms.

Screenshots

Not a UI change.

Downstream repositories

Release note

feat(system): ingress-nginx v1.11.6, cozy-proxy v0.4.0, cozystack-scheduler v0.4.0 and keycloak-kms-proxy 0.2.3 now ship linux/arm64 images.

Summary by CodeRabbit

  • Updates
    • Updated Cozy Proxy and Cozystack Scheduler to version 0.4.0.
    • Updated Ingress-NGINX to 1.11.6, including its certificate-generation component.
    • Updated Keycloak’s KMS proxy to version 0.2.3.

@github-actions github-actions Bot added area/uncategorized PR auto-labeler could not map title scope to a known area/*; please review kind/feature Categorizes issue or PR as related to a new feature size/S This PR changes 10-29 lines, ignoring generated files labels Sep 28, 2026
@coderabbitai

coderabbitai Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Important

Review skipped

Review was skipped as selected files did not have any reviewable changes.

⚙️ Run configuration

Configuration used: Repository: cozystack/cozystack/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: e83f1773-9bf8-4f08-9676-fe6d662655c2

📥 Commits

Reviewing files that changed from the base of the PR and between b6d4e18 and 0040d6a.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: cozystack/cozystack/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: 8b989277-15ac-4a50-b2d7-a6c5674e74aa

📥 Commits

Reviewing files that changed from the base of the PR and between f301cb5 and b6d4e18.

📒 Files selected for processing (11)
  • packages/system/cozy-proxy/charts/cozy-proxy/Chart.yaml
  • packages/system/cozy-proxy/charts/cozy-proxy/values.yaml
  • packages/system/cozystack-scheduler/Chart.yaml
  • packages/system/cozystack-scheduler/charts/cozystack-scheduler/Chart.yaml
  • packages/system/cozystack-scheduler/charts/cozystack-scheduler/values.yaml
  • packages/system/ingress-nginx/Makefile
  • packages/system/ingress-nginx/charts/ingress-nginx/Chart.yaml
  • packages/system/ingress-nginx/charts/ingress-nginx/README.md
  • packages/system/ingress-nginx/charts/ingress-nginx/values.yaml
  • packages/system/ingress-nginx/values.yaml
  • packages/system/keycloak/values.yaml

Included review availability: This review used your included allowance. Your plan provides up to 8 included reviews per hour; 5 remain after this review.


📝 Walkthrough

Walkthrough

Chart versions and image references are updated for cozy-proxy, cozystack-scheduler, and ingress-nginx. The default Keycloak KMS proxy image reference is also updated.

Changes

Cozy-proxy update

Layer / File(s) Summary
Update cozy-proxy chart and image versions
packages/system/cozy-proxy/charts/cozy-proxy/Chart.yaml, packages/system/cozy-proxy/charts/cozy-proxy/values.yaml
The chart and app versions and the configured image tag change from 0.3.0 to 0.4.0.

Scheduler update

Layer / File(s) Summary
Update scheduler chart and image versions
packages/system/cozystack-scheduler/Chart.yaml, packages/system/cozystack-scheduler/charts/cozystack-scheduler/*
The parent and nested chart versions change to 0.4.0. The scheduler image tag and digest are updated.

Ingress-NGINX update

Layer / File(s) Summary
Update Ingress-NGINX chart and image versions
packages/system/ingress-nginx/Makefile, packages/system/ingress-nginx/charts/ingress-nginx/*, packages/system/ingress-nginx/values.yaml
The chart version changes to 4.11.6 and the app version to 1.11.6. Controller and protobuf exporter references change to v1.11.6. The webhook patch image changes to v1.5.3. Image digests and README version and image details are updated.

Keycloak KMS proxy update

Layer / File(s) Summary
Update Keycloak KMS proxy image
packages/system/keycloak/values.yaml
The default KMS proxy image changes from 0.2.2 to 0.2.3 with an updated digest.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~8 minutes

Change: Feature

Merge Risk: ⚪ Minimal · up to b6d4e

No actionable defect is established in these version updates. The scheduler image’s ARM64 manifest still needs confirmation as part of normal release validation.

Architecture Summary

Architecture risk: 🔵 Low · up to b6d4e

The change affects 1 system.

Changed systems: packages/system

Architecture concerns
No architecture-level concerns identified.

Review details

Systems and components

  • observed — packages/system (library) was modified; 11 changed files map to changed impact.

Before / after behavior

  • observed — Modified behavior in packages/system/cozy-proxy/charts/cozy-proxy/Chart.yaml: The chart version and app version change from 0.3.0 to 0.4.0.
  • observed — Modified behavior in packages/system/cozy-proxy/charts/cozy-proxy/values.yaml: Updated the configured cozy-proxy image tag from v0.3.0 to v0.4.0.
  • observed — Modified behavior in packages/system/cozystack-scheduler/Chart.yaml: The chart version changes from 0.3.0 to 0.4.0.
  • observed — Modified behavior in packages/system/cozystack-scheduler/charts/cozystack-scheduler/Chart.yaml: The chart version is updated from 0.3.0 to 0.4.0.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the main change: updating ingress-nginx, cozy-proxy, cozystack-scheduler, and keycloak-kms-proxy to multi-architecture releases.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches 💡 1
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@IvanHunters IvanHunters left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed as a multi-arch image bump. Verified each new digest resolves to a manifest list carrying both linux/amd64 and linux/arm64:

  • cozystack-scheduler, cozy-proxy, ingress-nginx controller and protobuf-exporter, keycloak-kms-proxy: all amd64 + arm64
  • kube-webhook-certgen digest matches upstream v1.5.3 and is multi-arch (amd64/arm/arm64)
  • upstream controller digest matches registry.k8s.io controller v1.11.6

Version bumps are consistent across Chart.yaml, values.yaml, README and the Makefile CHART_VERSION. The cozy-proxy outer Chart.yaml is the build-time 0.0.0 placeholder, so leaving it untouched is correct.

Optional non-blocking follow-up: cozy-proxy is pinned by tag only, while the other components are pinned by digest. Worth aligning on a digest pin for reproducibility.

LGTM.

The cozystack controller and protobuf-exporter rebuilds are now
published for linux/amd64 and linux/arm64, so the ingress controller
can start on arm64 nodes. The rebuild is tagged by its upstream
version, and v1.11.6 is the first multi-arch one, so the chart moves
to the matching 4.11.6.

Assisted-by: LLM
Signed-off-by: Aleksei Sviridkin <[email protected]>
v0.4.0 publishes cozy-proxy as a linux/amd64 and linux/arm64 index;
earlier releases were amd64 only.

Assisted-by: LLM
Signed-off-by: Aleksei Sviridkin <[email protected]>
v0.4.0 publishes the scheduler as a linux/amd64 and linux/arm64
index; earlier releases were amd64 only.

Assisted-by: LLM
Signed-off-by: Aleksei Sviridkin <[email protected]>
0.2.3 publishes the proxy as a linux/amd64 and linux/arm64 index;
earlier releases were amd64 only.

Assisted-by: LLM
Signed-off-by: Aleksei Sviridkin <[email protected]>
@IvanHunters
IvanHunters merged commit 689b7ee into main Sep 28, 2026
19 checks passed
@IvanHunters
IvanHunters deleted the feat/bump-multiarch-components branch September 28, 2026 21:32
Aleksei Sviridkin (lexfrei) added a commit that referenced this pull request Sep 29, 2026
…leases on it (#4505)

## What this PR does

Pre-release builds now publish every image as an amd64 and arm64 index,
and a release fails if anything it ships is single-arch. Main, release
lines and pull requests keep building amd64 only. It builds on #4498,
which made every image buildable for both architectures. Part of #1961.

**This PR is on hold until everything under "Merge after" has landed.**
Merged earlier, the new gate fails the next rc on the images those PRs
fix.

### How a pre-release is built

A pre-release tag gets a second job, for arm64, next to the existing
release job. That covers `-rc.N`, `-beta.N` and `-alpha.N` tags. It runs
on the CNCF arm64 pool (`oracle-vm-24cpu-96gb-arm64`), builds the same
images with `PLATFORM=linux/arm64`, and pushes them as `<tag>-arm64`.
`prepare-release` waits for it, and if the arm64 job fails the rc fails
with it. There is no amd64-only fallback. Stable tags do not run it:
promotion copies the rc digests with `skopeo copy --multi-arch all`, so
a stable release inherits the indexes.

After the amd64 build, the stitch joins each amd64 image with its arm64
twin into one index. It lives in `hack/stitch-multiarch.sh`. Every tag
of the amd64 image moves to the index, the component-versioned ones
included. The script then rewrites the digests in the tree and
republishes the packages artifact and the installer chart pinned on
them. It reads refs through `hack/lib/image-refs.sh`, and it fails if an
old digest survives anywhere outside `charts/`.

### The gate

A new check fails the rc when a pinned digest in the tree is not an
index with both linux/amd64 and linux/arm64. It lives in
`hack/verify-multiarch.sh`. It checks first-party and third-party refs
alike. Images that are amd64 by nature go into
`hack/multiarch-allowlist`, one repository per line, each with a
mandatory reason. Today that is only the e2e sandbox. An entry that
matches nothing is reported as stale.

The static gate only sees digest-pinned refs in the tree. A tag-only
ref, an image from a vendored chart default, or one an operator starts
at runtime is invisible to it. So the rc e2e also audits every image its
nodes pulled, with the same check and the same allowlist. Neither covers
a package the e2e never installs.

### Nightly

A new nightly workflow builds main for arm64. It keeps the arm64 build
cache warm, since the rc job only reads it. It also prints the
single-arch refs that would block the next rc. Nothing it builds is
published.

### Smaller changes

- `CACHE_TAG` in `hack/common-envs.mk` moves the default cache ref, so
the arm64 build keeps a cache of its own.
- `MATRIX_ARCH=arm64` makes `hack/build-matrix.sh` leave out the
amd64-only e2e sandbox.
- The kamaji provider image is pushed under the build's `IMAGE_TAG` like
every other image. Its Makefile set `IMAGE_TAG` itself, so concurrent
builds overwrote each other's component tag. Closes #4503.
- `hack/nightly-mirror.sh` verifies a copy against the raw manifest
digest. Plain `skopeo inspect` resolves an index to one platform's
child.
- matchbox is rebuilt for both platforms in the amd64 release job. The
arm64 leg skips the talos package, so there is no arm64 half to stitch,
and its Dockerfile only copies files, so no QEMU is needed. Releases
then network-boot arm64 machines too. Closes #4524.

The stitch also rewrites the kamaji ref inside `files/components.gz`,
recompressed with `gzip -n` so the bytes are reproducible, so the kamaji
control-plane provider ships multi-arch too. keda and kuberture now name
the repository next to their pinned digest, so the gate can resolve
them; their rendered manifests do not change.

### Merge after

- #4552 builds the Talos installer, matchbox, Harbor and the Velero
KubeVirt plugin for arm64, and adds flux-plunger, keycloak-operator,
kilo and migration-controller to the root `build:` list. It replaces
#4507, #4515, #4525 and #4528.
- #4549 moves ingress-nginx, cozy-proxy, cozystack-scheduler and
keycloak-kms-proxy to their multi-arch releases, which are already
published.

The rest of the stack is merged: #4485, #4498, #4512, #4517, #4521 and
#4522 here, and the multi-arch PRs in
ingress-nginx-with-protobuf-exporter, cozy-proxy, cozystack-scheduler
and keycloak-kms-proxy.

### Verification

The bats suites pass: stitch, verify-multiarch, build-matrix,
common-envs, nightly-mirror and the release contracts. The first three
also pass under `hack/cozytest.sh` with dash. Each new test was red
before its implementation, and the verify-multiarch and stitch tests
each have a mutation that turns them red. I ran `verify-multiarch
--report` against main. It lists the first-party refs the stitch will
fix, plus the third-party and special cases above. The workflows have
not run yet. The arm64 job's tools and duration, the stitch against real
registries, and the audit are checked for the first time on the nightly
and on the next rc.

### Screenshots

Not a UI change.

### Downstream repositories

- [x] No downstream repository is affected by this change
- [ ] [cozystack/website](https://github.com/cozystack/website) -
follow-up:
- [ ]
[cozystack/terraform-provider-cozystack](https://github.com/cozystack/terraform-provider-cozystack)
- follow-up:
- [ ]
[cozystack/ansible-cozystack](https://github.com/cozystack/ansible-cozystack)
- follow-up:
- [ ] [cozystack/ccp](https://github.com/cozystack/ccp) - follow-up:
- [ ] [cozystack/talm](https://github.com/cozystack/talm) - follow-up:
- [ ] [cozystack/cozyhr](https://github.com/cozystack/cozyhr) -
follow-up:
- [ ] [cozystack/cozy-proxy](https://github.com/cozystack/cozy-proxy) -
follow-up:
- [ ]
[cozystack/cozystack-telemetry-server](https://github.com/cozystack/cozystack-telemetry-server)
- follow-up:
- [ ]
[cozystack/external-apps-example](https://github.com/cozystack/external-apps-example)
- follow-up:
- [ ] [cozystack/examples](https://github.com/cozystack/examples) -
follow-up:
- [ ] [cozystack/community](https://github.com/cozystack/community) -
follow-up:

Nothing under `hack/` is moved or renamed, and no make target changes
its default behaviour: `CACHE_TAG` and `MATRIX_ARCH` are opt-in. The
satellite repositories listed under "Merge after" are prerequisites, not
follow-ups this change forces on them.

### Release note

```release-note
ci(release): pre-release builds publish every image as an amd64 and arm64 multi-arch index, and a release fails if any image it ships or pulls in e2e lacks either architecture. Stable releases inherit the indexes through promotion.
```


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Release candidates now build amd64 and arm64 images in parallel and
combine eligible images into verified multi-architecture indexes before
publication.
* A nightly arm64 image build is available for testing and supplies a
build cache for release-candidate builds.
* **Bug Fixes**
* End-to-end checks audit whether pulled images support both
architectures. Audit failures block prerelease checks, while stable
releases continue with a warning.
* End-to-end test artifacts now include collected image references and
multi-architecture audit results.
* **Documentation**
* Updated release and image guidance covers multi-architecture builds,
verification checks, and troubleshooting, including arm64 build and
stitching failures.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/uncategorized PR auto-labeler could not map title scope to a known area/*; please review kind/feature Categorizes issue or PR as related to a new feature size/S This PR changes 10-29 lines, ignoring generated files

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants