Skip to content

fix: wait 7 days for github releases, drop dive - #115

Merged
catinspace-au merged 3 commits into
mainfrom
fix/fetch-cooldown-and-drops
Oct 7, 2026
Merged

catinspace-au merged 3 commits into
mainfrom
fix/fetch-cooldown-and-drops

Conversation

@catinspace-au

Copy link
Copy Markdown
Contributor

Every "latest from GitHub" install now waits until a release is 7 days old. That gives a pulled or hijacked release a week to be noticed before it lands on our boxes.

  • One shared role, github_release, picks the highest-versioned release at least hyperi_release_min_age_days (default 7) old. It skips drafts, prereleases and suffixed tags.
    • If nothing qualifies, or the API errors, it installs nothing, keeps any installed copy, and reports it at the end of the run.
    • hyperi-io's own releases skip the wait (hyperi_release_cooldown_exempt), matching the supply-chain policy.
    • It covers 21 role fetches and sccache in hyperi-rust-setup. The old per-tool cooldown for aws-vault and kubectx is folded into it.
  • hyperi-update applies the same cooldown. The role writes /etc/default/hyperi-update with the age and exempt list, so manual and timer runs agree. A release too young to take is a warning. Finding no release at any age is a failure.
  • hadolint on Fedora uses the upstream binary, like Ubuntu. Fedora 44's package is 2.14.0 against 2.15.1. The package is removed once the binary is in place.
  • dive (no release since 2025-05) and gron (dormant since 2022) are no longer installed. --tags removals clears the old copies on Linux. A normal run leaves them alone.
  • The kubectl minor follows Kubernetes' stable.txt by default. Set infrastructure_kubectl_minor to pin it for cluster skew. A held or versionlocked kubectl is left alone, with a warning naming the unhold command.
  • Every binary the roles unpack into /usr/local/bin is owned by root. Several kept the tarball's uid, 1001, which on a shared box let that user replace a tool everyone runs.
  • Also fixed:
    • one failing Kubernetes tool no longer skips the rest;
    • act is idempotent on Ubuntu;
    • a version sort no longer crashes on mixed v1.2.3 and 1.2.3 tags.

Tested on ubuntu:24.04, ubuntu:26.04 and fedora:44:

  • the second converge changed=0;
  • a forced impossible age kept every installed copy and warned;
  • kubectl followed the var both ways and respected holds;
  • removals cleared dive and gron while a default run did not;
  • remediation verify passes on the merged fixtures;
  • the updater test passed.

Not run: macOS, fedora:43 and arm64.

Done when no box installs a GitHub release younger than the configured age, and a pin or hold the user set is never overridden.

Every tool taken from a GitHub release now installs the newest release at least 7 days old, through one shared role (roles/github_release) instead of a per-tool copy. hyperi_release_min_age_days sets the age, hyperi-io repos skip it, and with no release old enough the installed copy stays and the run warns. Newest means highest version, so a backport published last on an older line is not picked. hyperi-update applies the same rule, with --min-age or HYPERI_RELEASE_MIN_AGE_DAYS to change it, and lists a kept binary in its summary without failing. hyperi-rust-setup does the same for sccache.

The Kubernetes binaries in k8s.yml each get their own rescue, so one dead or too-young upstream no longer skips the rest.

hadolint on Fedora now takes the upstream binary as Ubuntu does, and the dnf package goes through the orphan-safe purge once the binary is in.

dive and gron are no longer installed. Each role removes its own copies on any run: the /usr/local/bin binary where it resolves under /usr/local, gron's apt package on Ubuntu, and the brew formulae on macOS. Both leave the duplicate sweeps and the updater too.

kubectl's minor is now infrastructure_kubectl_minor (v1.37). The pkgs.k8s.io repository and the package follow it, up or down, on the next converge, so it is the knob for cluster version skew.

The Ubuntu act install unpacks straight into /usr/local/bin, so a second converge no longer reports it changed.
A kubectl held with apt-mark hold or dnf versionlock is now left where it is, with a warning that names infrastructure_kubectl_minor and the held version, instead of the pinned install aborting the converge. The kubectl tasks sit in a block whose rescue records a warning. infrastructure_kubectl_minor now defaults to empty, which follows the stable minor at dl.k8s.io, and setting it pins the minor.

dive and gron leave only on a removals or soe run again: the /usr/local/bin binaries go with the other retired binaries, and gron joins the retired Ubuntu utilities. A Mac keeps its brew formulae, as with every other retired CLI utility. The per-role retired task files are gone.

Every Linux binary the roles drop in /usr/local/bin is now owned by root, where some kept the uid from the release tarball and changed owner on every converge.

hyperi-update reads the release age and the exempt orgs from /etc/default/hyperi-update, which the update_command tasks write from the role variables, so a manual run and the timer follow the same rule as a converge. The environment overrides the file and --min-age overrides both. A bad configured age warns and falls back to 7 rather than stopping the run. A release lookup that matches nothing at any age is now a failure rather than a too-young warning, and a kustomize API error is reported as one.

The role cooldown rejects a release age that is not a whole number of days, since 7d read as 0 and switched it off.
The release lookup needs curl and python3, which every provisioned host has and the base images lack. Without python3 the lookup found nothing at any age, which the updater now reports as a failure rather than a too-young warning. The installs read /dev/null, because the case script arrives on stdin and apt consumed the rest of it.
@catinspace-au
catinspace-au merged commit 64f913a into main Oct 7, 2026
18 checks passed
@catinspace-au
catinspace-au deleted the fix/fetch-cooldown-and-drops branch October 7, 2026 00:24
@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant