Repository navigation
fix: wait 7 days for github releases, drop dive - #115
Merged
Merged
Conversation
Every tool taken from a GitHub release now installs the newest release at least 7 days old, through one shared role (roles/github_release) instead of a per-tool copy. hyperi_release_min_age_days sets the age, hyperi-io repos skip it, and with no release old enough the installed copy stays and the run warns. Newest means highest version, so a backport published last on an older line is not picked. hyperi-update applies the same rule, with --min-age or HYPERI_RELEASE_MIN_AGE_DAYS to change it, and lists a kept binary in its summary without failing. hyperi-rust-setup does the same for sccache. The Kubernetes binaries in k8s.yml each get their own rescue, so one dead or too-young upstream no longer skips the rest. hadolint on Fedora now takes the upstream binary as Ubuntu does, and the dnf package goes through the orphan-safe purge once the binary is in. dive and gron are no longer installed. Each role removes its own copies on any run: the /usr/local/bin binary where it resolves under /usr/local, gron's apt package on Ubuntu, and the brew formulae on macOS. Both leave the duplicate sweeps and the updater too. kubectl's minor is now infrastructure_kubectl_minor (v1.37). The pkgs.k8s.io repository and the package follow it, up or down, on the next converge, so it is the knob for cluster version skew. The Ubuntu act install unpacks straight into /usr/local/bin, so a second converge no longer reports it changed.
A kubectl held with apt-mark hold or dnf versionlock is now left where it is, with a warning that names infrastructure_kubectl_minor and the held version, instead of the pinned install aborting the converge. The kubectl tasks sit in a block whose rescue records a warning. infrastructure_kubectl_minor now defaults to empty, which follows the stable minor at dl.k8s.io, and setting it pins the minor. dive and gron leave only on a removals or soe run again: the /usr/local/bin binaries go with the other retired binaries, and gron joins the retired Ubuntu utilities. A Mac keeps its brew formulae, as with every other retired CLI utility. The per-role retired task files are gone. Every Linux binary the roles drop in /usr/local/bin is now owned by root, where some kept the uid from the release tarball and changed owner on every converge. hyperi-update reads the release age and the exempt orgs from /etc/default/hyperi-update, which the update_command tasks write from the role variables, so a manual run and the timer follow the same rule as a converge. The environment overrides the file and --min-age overrides both. A bad configured age warns and falls back to 7 rather than stopping the run. A release lookup that matches nothing at any age is now a failure rather than a too-young warning, and a kustomize API error is reported as one. The role cooldown rejects a release age that is not a whole number of days, since 7d read as 0 and switched it off.
The release lookup needs curl and python3, which every provisioned host has and the base images lack. Without python3 the lookup found nothing at any age, which the updater now reports as a failure rather than a too-young warning. The installs read /dev/null, because the case script arrives on stdin and apt consumed the rest of it.
Contributor
|
Released in v2.24.13 -- https://github.com/hyperi-io/hyperi-developer/releases/tag/v2.24.13 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Every "latest from GitHub" install now waits until a release is 7 days old. That gives a pulled or hijacked release a week to be noticed before it lands on our boxes.
github_release, picks the highest-versioned release at leasthyperi_release_min_age_days(default 7) old. It skips drafts, prereleases and suffixed tags.hyperi_release_cooldown_exempt), matching the supply-chain policy./etc/default/hyperi-updatewith the age and exempt list, so manual and timer runs agree. A release too young to take is a warning. Finding no release at any age is a failure.--tags removalsclears the old copies on Linux. A normal run leaves them alone.infrastructure_kubectl_minorto pin it for cluster skew. A held or versionlocked kubectl is left alone, with a warning naming the unhold command.v1.2.3and1.2.3tags.Tested on ubuntu:24.04, ubuntu:26.04 and fedora:44:
Not run: macOS, fedora:43 and arm64.
Done when no box installs a GitHub release younger than the configured age, and a pin or hold the user set is never overridden.