Skip to content

fix(valkey): pin the opt-in Valkey cache to 9.1.2-alpine - #1370

Merged
aivong-openhands merged 1 commit into
mainfrom
fix/valkey-alpine-pin
Oct 9, 2026
Merged

aivong-openhands merged 1 commit into
mainfrom
fix/valkey-alpine-pin

Conversation

@aivong-openhands

Copy link
Copy Markdown
Contributor

Why

The opt-in Valkey cache backend (the valkey subchart, chart 0.11.0) runs valkey/valkey at the subchart's appVersion, 9.1.1 on Debian, because values.yaml sets no tag. Trivy reports 3 critical / 15 high findings with fixes available on that image. This sets valkey.image.tag to 9.1.2-alpine, the current 9.1 patch on the Alpine base, which has 0 critical / 0 high. The Debian 9.1.2 build is not enough on its own: it still has 5 fixable high OpenSSL/PCRE2 findings, which is also why bumping the subchart to 0.12.0 (appVersion 9.1.2) would not clear them. Valkey stays enabled: false, so default installs render nothing different.

Validation

  • Trivy — valkey/valkey:9.1.1 reports 3 critical / 58 high (3 / 15 fixable); 9.1.2-alpine reports 0 critical / 0 high.
  • Cluster run — the valkey subchart 0.11.0, installed into a kind cluster with this repo's valkey: values and a redis Secret, came up ready with no restarts on 9.1.2-alpine (main and init containers). The init container built the ACL file from the existing Secret; unauthenticated and wrong-password commands got NOAUTH; authenticated PING, SET and GET worked; and another pod reached it through the oh-valkey Service.
  • Render — helm lint passes with valkey.enabled=true. With redis.enabled=false and valkey.enabled=true, all three Valkey image references render 9.1.2-alpine and the app's REDIS_HOST/REDIS_PORT resolve to oh-valkey:6379. A default render contains no Valkey image.

Helm Chart Checklist

  • I have tested the chart upgrade path from the previous version — Valkey has no persistent data here (dataStorage.enabled: false), so the upgrade is a pod restart on the new image.
  • I have verified backwards compatibility with existing values.yaml configurations — a user-set valkey.image.tag still wins.
  • I have updated the chart's README.md if there are any breaking changes or new required values — no new required values.

This PR was drafted by an AI agent on behalf of the user.

@github-actions github-actions Bot added the type: fix A bug fix label Oct 8, 2026
@aivong-openhands
aivong-openhands marked this pull request as ready for review October 9, 2026 11:08
@aivong-openhands
aivong-openhands merged commit d05cda4 into main Oct 9, 2026
25 checks passed
@aivong-openhands
aivong-openhands deleted the fix/valkey-alpine-pin branch October 9, 2026 11:09
@openhands-release-bot openhands-release-bot Bot added the released: openhands/0.80.0 Shipped in openhands/0.80.0 label Oct 9, 2026
@openhands-release-bot

Copy link
Copy Markdown
Contributor

🚀 Released in openhands/0.80.0.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

released: openhands/0.80.0 Shipped in openhands/0.80.0 type: fix A bug fix

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants