Repository navigation
chore(main): release 0.81.0 - #844
Conversation
Reviewer's guide (collapsed on small PRs)Reviewer's GuideThis release PR updates the Release Please version manifest and prepends the generated 0.81.0 changelog entry, documenting the control-plane feature that makes the heading identify the stack instead of using a badge below it. File-Level Changes
Possibly linked issues
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
|
Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (2)
Included review availability: Your plan provides up to 10 included reviews per hour; 8 remain after this review. 📝 WalkthroughWalkthroughThe release manifest now uses version ChangesRelease metadata
Priority: ➖ Normal Estimated code review effort: 1 (Trivial) | ~3 minutes Change: Other Merge Risk: ⚪ Minimal · up to This PR contains release metadata and documentation changes with no unresolved merge-blocking risk. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
There was a problem hiding this comment.
Hey - I've reviewed your changes and they look great!
Sourcery assessment
Needs a human reviewer. This changes the repository's release metadata and changelog, and release automation could create a wrongly versioned tag or published release that a revert would not retract. The resulting metadata and release can be corrected, but doing so requires a bounded follow-up rather than a simple revert.
c8d96c3 to
f102788
Compare
241cd44 to
ad52348
Compare
Sourcery withdrew this approval because the latest commits introduced blocking findings.
e73d55f to
93000c2
Compare
add0324 to
31e59ea
Compare
…ofu (#874) Closes #872. ## What broke A Conductor tenant fork could not deploy. Its first run on a Forgejo runner stopped after 22 seconds, at `uses: opentofu/setup-opentofu@v2`: ``` unable to clone 'https://data.forgejo.org/opentofu/setup-opentofu' … remote: Not found. ``` Forgejo resolves a bare `uses:` against `DEFAULT_ACTIONS_URL`. The forgejo stack pins that to data.forgejo.org, and data.forgejo.org does not mirror this action. ## Change The six places that used the action (five workflows and `nexus-bootstrap`) now run `.github/scripts/install-opentofu.sh`, a plain script that behaves the same on GitHub Actions and on Forgejo. - **One version, in one place.** The script installs the pinned `1.10.0` and refuses any argument. Every workflow therefore gets the same OpenTofu, which `tofu-checks.yaml` relies on. `nexus-bootstrap` loses its `tofu_version` input; no caller passed it. - **Pinned checksums, not fetched ones.** #872 proposed downloading `SHA256SUMS` at run time. That file comes from the same place as the archive, so it would catch a broken download but not a replaced one. The pinned values were taken from `tofu_1.10.0_SHA256SUMS` after checking that file the way OpenTofu documents: - `cosign verify-blob` with the identity `…/release.yml@refs/heads/v1.10` → `Verified OK`; - the same command with a wrong identity → refused; - both pinned values compared with freshly downloaded archives → equal. The script's header says how to pin the next version. - **`.tar.gz` rather than `.zip`**, so `tar` is enough and `unzip` is not needed. - **Reads the version back.** The script checks what the installed binary reports before it appends the directory to `GITHUB_PATH`, which both runners honour. - **Refuses what it cannot install:** non-Linux runners, and architectures with no pinned checksum. - **`tofu-checks.yaml` now also triggers on changes to the script**, so the real install runs in CI whenever the script changes. Before switching, I checked every affected job: each one checks the repository out at its root before the install step, which the script needs. ## Verified Run on the deployed server: | Environment | Result | |---|---| | Ubuntu 26.04, amd64 | `OpenTofu v1.10.0` installed; `GITHUB_PATH` written; a following step with that `PATH` runs it | | `node:22-bookworm` (the Forgejo runner's job image) | the same. The image has `curl`, `tar`, `gzip` and `sha256sum` | | arm64 | not run, for lack of a machine. Its pinned checksum matches the real release archive | | called with a version argument | exit 1 | This PR does not verify a full lifecycle run on Forgejo. That is the last acceptance item of #872, and it needs a real Conductor deploy after a release that contains this change. ## What data.forgejo.org mirrors `docs/stacks/forgejo-runner.md` gets a new section. Every `uses:` in the repository was checked against data.forgejo.org on 2026-09-16. Tags were checked with `git ls-remote`; commit-SHA pins were checked by fetching the commit, because `ls-remote` cannot see a commit. - **Mirrored:** `actions/checkout`, `actions/cache`, `actions/setup-node`, `actions/upload-artifact`, `astral-sh/setup-uv`, including the three SHA pins. - **Not mirrored, CI-only:** `raven-actions/actionlint`, `googleapis/release-please-action`, `codecov/codecov-action`, `MishaKav/pytest-coverage-comment`. **After this change, every `uses:` in the lifecycle workflows resolves on Forgejo.** The docs say this covers action resolution only, not a full run. ## Tests The new file `tests/unit/test_install_opentofu.py` checks: - **No `uses:` of setup-opentofu.** It parses the YAML, so the explanatory comments do not count. - **No call of the script with a version.** - **No job runs `tofu` before installing it.** A local composite action that runs `tofu`, such as `nexus-config-tfvars`, counts as a `tofu` call. A second test makes sure this rule still finds the lifecycle jobs, so it cannot pass by matching nothing. - **Both checksums are pinned and well-formed.** - **The script's refusals**, run under bash with `curl` and `uname` replaced: a version argument, a non-Linux runner, an unpinned architecture, and an archive that does not match the pin (for both architectures). In each case nothing is installed and nothing is added to `PATH`. The requested URL is asserted, so the test is known to have reached the comparison. The success path cannot be faked against a pinned checksum; `tofu-checks.yaml` runs it for real. Seven mutations, each caught: | Mutation | Caught by | |---|---| | checksum comparison removed | mismatch test, both architectures, which also asserts the message, since the script still fails later on the bad archive | | argument check removed | argument test | | OS check removed | non-Linux test | | arm64 checksum removed | checksum-format test and the arm64 mismatch test | | a workflow back on setup-opentofu | `uses:` test and ordering test | | a workflow passing a version | version test | | a workflow with no install | ordering test | ## Local CodeRabbit round Reviewed **`592c9bf2`**: 1 finding. **`install-opentofu.sh` (major): move to OpenTofu 1.11.10 or later. Right on substance, not done here; filed as #873.** 1.10.0 is affected by [GHSA-q7j3-v8qv-22vq](GHSA-q7j3-v8qv-22vq) (high), and the 1.10 series will not be patched for it. The deploy configuration declares no modules, so it does not reach the advisory. `tofu-checks.yaml` does reach it, because it runs `tofu init` on configuration from pull requests. It is not part of this PR because a version change also changes which OpenTofu writes the real state in R2, and that needs a spin-up to verify. This PR changes only how OpenTofu is installed, and the 1.10.0 pin predates it. With this change in place, the move is three lines in one file. #873 has the advisories, the exposure and the decisions to make. ## Release order **This PR merges before the v0.81.0 release (#844).** Conductor forks are created from a release, so the fix reaches them only through a release that contains it. ## Checks - `pytest tests/unit`: 3400 passed - pre-commit, including actionlint and shellcheck: all hooks pass ## Summary by Sourcery Install a pinned, checksum-verified OpenTofu release with a repository script so lifecycle workflows resolve reliably on both GitHub Actions and Forgejo. New Features: - Replace the Forgejo-incompatible OpenTofu setup action with a cross-platform installation script that pins OpenTofu 1.10.0 and verified architecture-specific checksums. Bug Fixes: - Ensure lifecycle workflows can install OpenTofu on Forgejo runners where the setup-opentofu action is unavailable. Enhancements: - Centralize OpenTofu installation and version management across workflows and the bootstrap composite action. - Validate runner compatibility, downloaded archive integrity, installed version, and PATH propagation before completing installation. CI: - Run the OpenTofu checks when the installation script changes. - Add tests covering workflow usage, installation ordering, pinned checksums, and script refusal cases. Documentation: - Document Forgejo action mirroring limitations and identify which repository actions are available or unavailable through the mirror. Tests: - Add unit coverage for the pinned OpenTofu installer and workflow safeguards, including mutation-tested failure conditions. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added a pinned OpenTofu installer supporting Linux `amd64` and `arm64` runners. - OpenTofu downloads are verified with SHA-256 checksums before installation. - **Bug Fixes** - Updated infrastructure workflows to install OpenTofu reliably on Forgejo runners. - Prevented unsupported platforms, architectures, versions, and invalid downloads from proceeding. - **Documentation** - Documented Forgejo action availability, workflow limitations, and the OpenTofu installation workaround. - **Tests** - Added coverage for installer validation, workflow usage, installation ordering, and checksum integrity. <!-- end of auto-generated comment: release notes by coderabbit.ai -->
31e59ea to
7cbcda6
Compare
|
🤖 Created releases: 🌻 |
🤖 I have created a release beep boop
0.81.0 (2026-09-16)
🚀 Features
🐛 Bug Fixes
📚 Documentation
This PR was generated with Release Please. See documentation.