Repository navigation
fix(openhands): rebuild 0.71.3 images without Copa - #1387
Draft
dylan-openhands wants to merge 13 commits into
Draft
dylan-openhands wants to merge 13 commits into
dylan-openhands wants to merge 13 commits into
Conversation
Base for 0.71.3: 0.71.2's Copa image pins don't carry forward. charts/ and replicated/ are restored from openhands/0.71.1; .github/ and the chart version (0.71.2) are kept so release-please cuts 0.71.3.
Follows the restore: 0.71.2 pointed this test at the Copa-patched paths.
Rebuilt hotfix releases (1.64.0-r1, 1.49.5-r1-python) name the release they rebuild; release_tag() now strips -rN as it already strips -patched and digest pins.
Pins the PR-build candidate digests of the 7 in-house images, default ghcr.io/openhands/* repositories. The -r1 tags do not exist yet; the tag text is ignored because a digest is present. Replace each digest with the rescanned -r1 release digest once the hotfix PRs are tagged. agent-canvas carries the STAGING PostHog key (OpenHands#18258 candidate build) and must never ship: it needs the manual cancel-and-dispatch release before this pin is final. agent-server tag keeps 1.49.5 as its first segment so enterprise's get_agent_server_image() rewrite (default repository only) leaves it unchanged.
… and jobs Every wait-for-db, create-db and create-db-user container hardcoded either bitnamilegacy/postgresql:latest or postgres:14. All but Keycloak's bypassed the Replicated proxy and the airgap registry rewrite, and :latest was unpinned. Route all of them through global.postgresClientImage, pinned by digest to postgres:16.15-alpine, and mirror it in the online and local-registry Replicated values. Keycloak's wait-for-db keeps uid 1001, which the Bitnami image used to supply.
Optional on top of the previous commit: drop it to stay on the Docker Official postgres:16.15-alpine image. postgres:16.15-alpine still reports 1 CRITICAL and 24 HIGH fixable findings, all in the Go stdlib of its gosu binary, which none of these containers run. alpine/psql 18.6 ships only the client tools and scans clean (0 CRITICAL/HIGH). psql 18 supports servers back to 9.2, and the image runs every site's command with output identical to the old images against PostgreSQL 13, 16 and 18.
Contributor
|
| Location | Value |
|---|---|
charts/openhands/Chart.yaml → appVersion |
1.64.0 |
charts/openhands/values.yaml → image.tag |
1.64.0-r1@sha256:6c137216f1c6afe1d560300e92990a52050064a1358472c314285ae8e0bf8307 |
Fix: set appVersion to 1.64.0-r1@sha256:6c137216f1c6afe1d560300e92990a52050064a1358472c314285ae8e0bf8307 in charts/openhands/Chart.yaml.
This is a notice, not a blocking check.
Changing either chart makes release-please propose a release of it on release/0.71. The sync check now reads 1.49.5-r1-python as 1.49.5-python, so image-loader can stay on the release tag, as it did for 0.71.2. The crd-check edit was a doc comment (the chart is consumed as OCI 0.1.0).
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Warning
Draft. Do not merge as-is. The in-house images are pinned to hotfix PR candidate digests in the
TEST-ONLYcommit, and agent-canvas's candidate carries the staging PostHog key. Replace them with the rescanned-r1release digests before merging.What
0.71.3 for the 0.71.x hotfix line. It starts from 0.71.1's
charts/andreplicated/, so none of 0.71.2's Copa-patched images carry forward, then re-pins each image to a properly rebuilt or newer same-line build..github/(including the Beta deploy guard) and the chart version (0.71.2 → release-please proposes 0.71.3) are kept fromrelease/0.71.Commits
fix(openhands): restore charts and replicated to 0.71.1 images+test: expect 0.71.1's MinIO image refs againgit restore --source=openhands/0.71.1 charts replicated(chart version kept at 0.71.2); the MinIO test goes back to 0.71.1's refsci: accept -rN hotfix suffix in the agent-server sync checkcheck_agent_server_sync.pymaps<ver>-rN[@sha256:…]to release<ver>(one regex, 3 tests)ci: keep image-loader and crd-check on their release tags1.49.5-r1-pythonas1.49.5-python, socharts/image-loaderandcharts/crd-checkstay untouched (changing them would make release-please propose releases of those charts onrelease/0.71)TEST-ONLY: hotfix candidate pins (replace with -r1 release digests)<ver>-r1@sha256:<hotfix PR candidate>on the defaultghcr.io/openhands/*reposfix(infra): bump cert-manager chart to 1.20.4cert-manager-editaggregate role, GHSA-8rvj-mm4h-c258)fix(infra): rebuild trust-pkg default package image at 20230311-deb12u1.7fix(openhands): bump TLS preflight probe image to alpine/openssl 3.5.9fix(openhands): bump rancher/kubectl to v1.33.13main)fix(openhands): bump litellm-database to 1.100.5scripts/test_litellm_budget_cache.pyasserts the pinned reffix(openhands): bump Bitnami postgresql and redis image tagsfix(openhands): pin the postgres client image used by init containers and jobsbitnamilegacy/postgresql:latest/postgres:14sites → oneglobal.postgresClientImage, digest-pinned, through the Replicated proxy and in the airgap block; Keycloakwait-for-dbgetsrunAsUser: 1001to keep its old uid; newscripts/test_postgres_client_image.py(also #1386 onmain)fix(openhands): [optional] use alpine/psql for the postgres client imagepostgres:16.15-alpine(1/24 fixable, all in unusedgosu) →alpine/psql:18.6(0/0). Drop this commit to stay on the Docker Official imageVulnerability result
The set is every image a default KOTS install runs: the openhands chart, the infra-cert-manager / sysbox / trust-manager charts, and the sandbox image. Scanned with Trivy 0.75 on one frozen DB (2026-10-09T19:06Z), linux/amd64, counting unique (CVE, package).
This PR is below 0.71.1 everywhere and below 0.71.2 on high and on C+H, but not on critical. The criticals left are concentrated in Bitnami (Keycloak 23, PostgreSQL 17, Redis 17), MinIO (6 + 3) and sysbox (9). None has a same-line upgrade that scans better; see "Needs a decision".
Third-party images: dispositions
bitnamilegacy/postgresql:latest,postgres:14(client sites)rancher/kubectllitellm-database1.30.xtags scanned; none better)v0.7.0-1;v0.7.1-0is a sysbox version change (clears 1 critical)Needs a decision
alpine/psqlcommit.CI status
The three
Scan (openhands/…:<ver>-r1@sha256:…)jobs fail withmanifest unknown.scripts/wait_for_image_manifest.pylooks up the tag inname:tag@digest, and the-r1tags don't exist yet. The same digest without the tag resolves. Pods pull by digest, so this doesn't affect a running install, but it stays red until the-r1releases are published and pinned. Every other check passes.Check agent-server synconly runs on the release-please PR; it passes locally against the real enterprise repo.Before merging (handoff)
-r1releases (see each component PR). Confirm each tag resolves to a digest, rescan it on the same DB, pin<ver>-r1@sha256:<release digest>, and rerun CI.1.64.0-r1.ghcr.io/openhands/patched/agent-server@sha256:c143…published. Sandboxes created on 0.71.2 keep that image when resumed after the upgrade.Testing
helm lintpasses on every chart, and all 8helm unittestsuites pass.pytest scripts -k 'not keycloak': 540 passed (531 on the restore commit, plus 9 new tests).wait-for-db'ssecurityContext.docker runas its pod's uid, against a Bitnami 16.4 server and against externalpostgres:13andpostgres:18over TLS. Install and rerun-on-upgrade passes produced output identical to the old images.