Repository navigation
fix(openhands): pin the postgres client image used by init containers and jobs - #1386
Draft
dylan-openhands wants to merge 2 commits into
Draft
dylan-openhands wants to merge 2 commits into
dylan-openhands wants to merge 2 commits into
Conversation
… and jobs Every wait-for-db, create-db and create-db-user container hardcoded either bitnamilegacy/postgresql:latest or postgres:14. All but Keycloak's bypassed the Replicated proxy and the airgap registry rewrite, and :latest was unpinned. Route all of them through global.postgresClientImage, pinned by digest to postgres:16.15-alpine, and mirror it in the online and local-registry Replicated values. Keycloak's wait-for-db keeps uid 1001, which the Bitnami image used to supply.
Optional on top of the previous commit: drop it to stay on the Docker Official postgres:16.15-alpine image. postgres:16.15-alpine still reports 1 CRITICAL and 24 HIGH fixable findings, all in the Go stdlib of its gosu binary, which none of these containers run. alpine/psql 18.6 ships only the client tools and scans clean (0 CRITICAL/HIGH). psql 18 supports servers back to 9.2, and the image runs every site's command with output identical to the old images against PostgreSQL 13, 16 and 18.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Every database init container and job that runs
psql/pg_isreadyhardcoded its image:bitnamilegacy/postgresql:latest(openhands, runtime-api and plugin-directorywait-for-db/create-db, automation and integrations-hubwait-for-postgres) orpostgres:14(automation and integrations-hubcreate-db-user, runtime-apicreate-postgres-userjob). Keycloak'swait-for-dbwas the only one with an override (keycloak.waitForDb.image).Why this matters:
:latestis unpinned, so what customers run changes underneath a release.images.r9.all-hands.dev/proxy/...) and the airgap local-registry rewrite. Online installs pull straight from Docker Hub and airgap installs can't pull them at all.bitnamilegacy/postgresql:latest, and 1 CRITICAL and 24 HIGH fixable forpostgres:14.What changes:
global.postgresClientImage: {repository, tag}, pinned by digest. Every site, including Keycloak'swait-for-db(rendered throughcommon.tplvalues.render), reads it. Each subchart carries the same default so it still renders standalone.keycloak.waitForDb.imageis removed in favour of the global.replicated/openhands.yamlsets the repository online (images.r9.all-hands.dev/proxy/<appSlug>/docker.io/...) and in theHasLocalRegistryblock (<LocalRegistryHost>/<LocalRegistryNamespace>/...). The tag comes from the chart, and thebuilderrender picks the image up for the airgap bundle.wait-for-dbhas no pod-levelrunAsUser, and the Bitnami image used to supply uid 1001. The new image defaults to root, so the container now setsrunAsUser: 1001/runAsNonRoot: trueto keep the same identity.scripts/test_postgres_client_image.pyrenders every site, including the non-default branches, and asserts that eachpsql/pg_isreadycontainer uses the mirrored, digest-pinned image in online and airgap modes.The image is chosen in two commits so reviewers can keep or drop the second:
docker.io/library/postgres:16.15-alpine@sha256:7218…080eais the Docker Official image, at the bundled server's major (Bitnami 16.4).docker.io/alpine/psql:18.6@sha256:08f3…64b8ships only the client tools. The official image's remaining 25 fixable findings all sit in the Go stdlib of itsgosubinary, which none of these containers execute. Drop this commit if policy requires Docker Official Images.Neither new image adds a fixable finding that the old images didn't have.
Testing
docker run: each site's exact rendered command and env (secrets substituted) ran against a throwawaybitnamilegacy/postgresql:16.4.0-debian-12-r14server, under the rendered pod's uid/gid: 42420 for openhands, automation and integrations-hub; 1000 for runtime-api; 1001 for plugin-directory and Keycloak. Every site ran twice to cover upgrade reruns. That's 12 distinct containers × 2 passes, with the old images,postgres:16.15-alpine,alpine/psql:18.6and the CNPG image. All 24 runs exited 0 for each image, and each new image's output was byte-identical to the old images' output. The final databases, roles and grants matched.wait-for-db,create-dband threecreate-db-usercommands also ran againstpostgres:13andpostgres:18withPGSSLMODE=require, twice each. All exited 0, and the connections negotiated TLSv1.3.bash, andalpine/psqlhas none. No site setsreadOnlyRootFilesystem. With an arbitrary uid,HOME=/, and psql runs non-interactively, so it writes no history. There were no locale warnings.helm templateagainstorigin/main(defaults, and with every site enabled) changes only the image lines and Keycloak's newsecurityContext.helm lintis clean. The CI helm-unittest suites all pass.pytest scripts -k 'not keycloak'reports 631 passed, against 626 onorigin/main; the 5 extra are the new tests.A 0.71.x backport of the same change exists on
dj/c3-0713-pgclient.Helm Chart Checklist
keycloak.waitForDb.imageis removed; useglobal.postgresClientImage)Additional Notes
keycloak.waitForDb.imagewas only set byreplicated/openhands.yamlin this repo. A direct Helm user who overrode it should setglobal.postgresClientImage.repositoryinstead.