Skip to content

chore(main): release 0.81.0 - #844

Merged
stefanko-ch merged 1 commit into
mainfrom
release-please--branches--main
Sep 16, 2026
Merged

stefanko-ch merged 1 commit into
mainfrom
release-please--branches--main

Conversation

@github-actions

@github-actions github-actions Bot commented Sep 12, 2026 •

Copy link
Copy Markdown
Contributor

🤖 I have created a release beep boop

0.81.0 (2026-09-16)

🚀 Features

  • ci: Check the OpenTofu configuration, in pre-commit and in CI (#862) (fa0bcfd)
  • control-plane: Let the heading name the stack, not a badge below it (#842) (2a1f311)
  • control-plane: Paint the logo through a mask so it takes the accent (#843) (3bf728f)
  • control-plane: Separate the brand accent from the status colours (#845) (01eed37)
  • stacks: Add Apache Airflow workflow orchestration (#855) (7487fc1)
  • stacks: Add Keycloak identity provider (#854) (debd45d)
  • stacks: Add Langfuse LLM observability (#856) (dca3440)
  • stacks: Add MLflow, and wire the notebook stacks to it (#850) (d117d24)
  • stacks: Add MongoDB with mongo-express as its web UI (#857) (1907e98)
  • stacks: Add Neo4j Community Edition with a Bolt-routing proxy (#858) (e1c76dc)
  • stacks: Add Qdrant vector database (#859) (7c12051)
  • stacks: Add Temporal durable workflow engine with Web UI (#860) (d5e73a9)
  • stacks: Add TimescaleDB time-series database (#861) (389b6a1)
  • stacks: Replace Keycloak's temporary admin with a permanent one (#871) (d27a9c9)

🐛 Bug Fixes

  • ci: Install OpenTofu with a pinned script instead of setup-opentofu (#874) (ae1a14a)
  • deploy: Refuse an empty DOMAIN once, in the env-file dispatcher (#868) (095874b)
  • examples: Escape inlined secrets and render the S3 DataFrame (#846) (23a7bdb)
  • stacks: Name the executable in MLflow's command (#853) (2b0b2fb)
  • stacks: Point Neo4j Browser at the port the tunnel serves (#870) (0bc0975)
  • stacks: Run MongoDB 7.0, which starts on the kernel we deploy (#869) (bea2f64)

📚 Documentation

  • stacks: Record the rare Lakekeeper write failure where users meet it (#849) (8df5f1f)

This PR was generated with Release Please. See documentation.

@sourcery-ai

sourcery-ai Bot commented Sep 12, 2026 •

Copy link
Copy Markdown
Reviewer's guide (collapsed on small PRs)

Reviewer's Guide

This release PR updates the Release Please version manifest and prepends the generated 0.81.0 changelog entry, documenting the control-plane feature that makes the heading identify the stack instead of using a badge below it.

File-Level Changes

Change Details Files
Record the 0.81.0 release metadata and changelog entry for the control-plane heading update. .release-please-manifest.json
CHANGELOG.md

Possibly linked issues


Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@coderabbitai

coderabbitai Bot commented Sep 12, 2026 •

Copy link
Copy Markdown

Review Change StackReview Change Stack

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: beb83932-c3bd-4b7a-affc-8c97e9ed4a20

📥 Commits

Reviewing files that changed from the base of the PR and between a568a6e and 77a8aa2.

📒 Files selected for processing (2)
  • .release-please-manifest.json
  • CHANGELOG.md

Included review availability: Your plan provides up to 10 included reviews per hour; 8 remain after this review.


📝 Walkthrough

Walkthrough

The release manifest now uses version 0.81.0. CHANGELOG.md includes the dated 0.81.0 release entry with eight features, two bug fixes, and one documentation update.

Changes

Release metadata

Layer / File(s) Summary
Release version and changelog
.release-please-manifest.json, CHANGELOG.md
The manifest version changed from 0.80.0 to 0.81.0. The changelog adds the dated 0.81.0 release entry with eight feature entries, two bug-fix entries, and one documentation entry.

Priority: ➖ Normal

Estimated code review effort: 1 (Trivial) | ~3 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to 77a8a

This PR contains release metadata and documentation changes with no unresolved merge-blocking risk.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly identifies the release version and matches the manifest and changelog updates for version 0.81.0.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch release-please--branches--main

Comment @coderabbitai help to get the list of available commands.

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've reviewed your changes and they look great!

Sourcery assessment

Needs a human reviewer. This changes the repository's release metadata and changelog, and release automation could create a wrongly versioned tag or published release that a revert would not retract. The resulting metadata and release can be corrected, but doing so requires a bounded follow-up rather than a simple revert.


Sourcery is free for open source - if you like our reviews please consider sharing them ✨

@github-actions
github-actions Bot force-pushed the release-please--branches--main branch from c8d96c3 to f102788 Compare September 12, 2026 09:42
sourcery-ai[bot]
sourcery-ai Bot previously approved these changes Sep 12, 2026

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sourcery assessment

Approved.

@github-actions
github-actions Bot force-pushed the release-please--branches--main branch 4 times, most recently from 241cd44 to ad52348 Compare September 14, 2026 14:57
@sourcery-ai
sourcery-ai Bot dismissed their stale review September 14, 2026 14:58

Sourcery withdrew this approval because the latest commits introduced blocking findings.

@github-actions
github-actions Bot force-pushed the release-please--branches--main branch 11 times, most recently from e73d55f to 93000c2 Compare September 16, 2026 08:22
@github-actions
github-actions Bot force-pushed the release-please--branches--main branch 3 times, most recently from add0324 to 31e59ea Compare September 16, 2026 12:42
stefanko-ch added a commit that referenced this pull request Sep 16, 2026
…ofu (#874)

Closes #872.

## What broke

A Conductor tenant fork could not deploy. Its first run on a Forgejo
runner stopped after 22 seconds, at `uses: opentofu/setup-opentofu@v2`:

```
unable to clone 'https://data.forgejo.org/opentofu/setup-opentofu' … remote: Not found.
```

Forgejo resolves a bare `uses:` against `DEFAULT_ACTIONS_URL`. The
forgejo stack pins that to data.forgejo.org, and data.forgejo.org does
not mirror this action.

## Change

The six places that used the action (five workflows and
`nexus-bootstrap`) now run `.github/scripts/install-opentofu.sh`, a
plain script that behaves the same on GitHub Actions and on Forgejo.

- **One version, in one place.** The script installs the pinned `1.10.0`
and refuses any argument. Every workflow therefore gets the same
OpenTofu, which `tofu-checks.yaml` relies on. `nexus-bootstrap` loses
its `tofu_version` input; no caller passed it.
- **Pinned checksums, not fetched ones.** #872 proposed downloading
`SHA256SUMS` at run time. That file comes from the same place as the
archive, so it would catch a broken download but not a replaced one. The
pinned values were taken from `tofu_1.10.0_SHA256SUMS` after checking
that file the way OpenTofu documents:
- `cosign verify-blob` with the identity
`…/release.yml@refs/heads/v1.10` → `Verified OK`;
  - the same command with a wrong identity → refused;
- both pinned values compared with freshly downloaded archives → equal.

  The script's header says how to pin the next version.
- **`.tar.gz` rather than `.zip`**, so `tar` is enough and `unzip` is
not needed.
- **Reads the version back.** The script checks what the installed
binary reports before it appends the directory to `GITHUB_PATH`, which
both runners honour.
- **Refuses what it cannot install:** non-Linux runners, and
architectures with no pinned checksum.
- **`tofu-checks.yaml` now also triggers on changes to the script**, so
the real install runs in CI whenever the script changes.

Before switching, I checked every affected job: each one checks the
repository out at its root before the install step, which the script
needs.

## Verified

Run on the deployed server:

| Environment | Result |
|---|---|
| Ubuntu 26.04, amd64 | `OpenTofu v1.10.0` installed; `GITHUB_PATH`
written; a following step with that `PATH` runs it |
| `node:22-bookworm` (the Forgejo runner's job image) | the same. The
image has `curl`, `tar`, `gzip` and `sha256sum` |
| arm64 | not run, for lack of a machine. Its pinned checksum matches
the real release archive |
| called with a version argument | exit 1 |

This PR does not verify a full lifecycle run on Forgejo. That is the
last acceptance item of #872, and it needs a real Conductor deploy after
a release that contains this change.

## What data.forgejo.org mirrors

`docs/stacks/forgejo-runner.md` gets a new section. Every `uses:` in the
repository was checked against data.forgejo.org on 2026-09-16. Tags were
checked with `git ls-remote`; commit-SHA pins were checked by fetching
the commit, because `ls-remote` cannot see a commit.

- **Mirrored:** `actions/checkout`, `actions/cache`,
`actions/setup-node`, `actions/upload-artifact`, `astral-sh/setup-uv`,
including the three SHA pins.
- **Not mirrored, CI-only:** `raven-actions/actionlint`,
`googleapis/release-please-action`, `codecov/codecov-action`,
`MishaKav/pytest-coverage-comment`.

**After this change, every `uses:` in the lifecycle workflows resolves
on Forgejo.** The docs say this covers action resolution only, not a
full run.

## Tests

The new file `tests/unit/test_install_opentofu.py` checks:

- **No `uses:` of setup-opentofu.** It parses the YAML, so the
explanatory comments do not count.
- **No call of the script with a version.**
- **No job runs `tofu` before installing it.** A local composite action
that runs `tofu`, such as `nexus-config-tfvars`, counts as a `tofu`
call. A second test makes sure this rule still finds the lifecycle jobs,
so it cannot pass by matching nothing.
- **Both checksums are pinned and well-formed.**
- **The script's refusals**, run under bash with `curl` and `uname`
replaced: a version argument, a non-Linux runner, an unpinned
architecture, and an archive that does not match the pin (for both
architectures). In each case nothing is installed and nothing is added
to `PATH`. The requested URL is asserted, so the test is known to have
reached the comparison.

The success path cannot be faked against a pinned checksum;
`tofu-checks.yaml` runs it for real.

Seven mutations, each caught:

| Mutation | Caught by |
|---|---|
| checksum comparison removed | mismatch test, both architectures, which
also asserts the message, since the script still fails later on the bad
archive |
| argument check removed | argument test |
| OS check removed | non-Linux test |
| arm64 checksum removed | checksum-format test and the arm64 mismatch
test |
| a workflow back on setup-opentofu | `uses:` test and ordering test |
| a workflow passing a version | version test |
| a workflow with no install | ordering test |

## Local CodeRabbit round

Reviewed **`592c9bf2`**: 1 finding.

**`install-opentofu.sh` (major): move to OpenTofu 1.11.10 or later.
Right on substance, not done here; filed as #873.**

1.10.0 is affected by
[GHSA-q7j3-v8qv-22vq](GHSA-q7j3-v8qv-22vq)
(high), and the 1.10 series will not be patched for it. The deploy
configuration declares no modules, so it does not reach the advisory.
`tofu-checks.yaml` does reach it, because it runs `tofu init` on
configuration from pull requests.

It is not part of this PR because a version change also changes which
OpenTofu writes the real state in R2, and that needs a spin-up to
verify. This PR changes only how OpenTofu is installed, and the 1.10.0
pin predates it. With this change in place, the move is three lines in
one file. #873 has the advisories, the exposure and the decisions to
make.

## Release order

**This PR merges before the v0.81.0 release (#844).** Conductor forks
are created from a release, so the fix reaches them only through a
release that contains it.

## Checks

- `pytest tests/unit`: 3400 passed
- pre-commit, including actionlint and shellcheck: all hooks pass

## Summary by Sourcery

Install a pinned, checksum-verified OpenTofu release with a repository
script so lifecycle workflows resolve reliably on both GitHub Actions
and Forgejo.

New Features:
- Replace the Forgejo-incompatible OpenTofu setup action with a
cross-platform installation script that pins OpenTofu 1.10.0 and
verified architecture-specific checksums.

Bug Fixes:
- Ensure lifecycle workflows can install OpenTofu on Forgejo runners
where the setup-opentofu action is unavailable.

Enhancements:
- Centralize OpenTofu installation and version management across
workflows and the bootstrap composite action.
- Validate runner compatibility, downloaded archive integrity, installed
version, and PATH propagation before completing installation.

CI:
- Run the OpenTofu checks when the installation script changes.
- Add tests covering workflow usage, installation ordering, pinned
checksums, and script refusal cases.

Documentation:
- Document Forgejo action mirroring limitations and identify which
repository actions are available or unavailable through the mirror.

Tests:
- Add unit coverage for the pinned OpenTofu installer and workflow
safeguards, including mutation-tested failure conditions.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **New Features**
- Added a pinned OpenTofu installer supporting Linux `amd64` and `arm64`
runners.
- OpenTofu downloads are verified with SHA-256 checksums before
installation.

- **Bug Fixes**
- Updated infrastructure workflows to install OpenTofu reliably on
Forgejo runners.
- Prevented unsupported platforms, architectures, versions, and invalid
downloads from proceeding.

- **Documentation**
- Documented Forgejo action availability, workflow limitations, and the
OpenTofu installation workaround.

- **Tests**
- Added coverage for installer validation, workflow usage, installation
ordering, and checksum integrity.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
@github-actions
github-actions Bot force-pushed the release-please--branches--main branch from 31e59ea to 7cbcda6 Compare September 16, 2026 12:54
@stefanko-ch
stefanko-ch merged commit 9a6fccd into main Sep 16, 2026
7 checks passed
@stefanko-ch
stefanko-ch deleted the release-please--branches--main branch September 16, 2026 14:19
@github-actions

Copy link
Copy Markdown
Contributor Author

🤖 Created releases:

🌻

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant