chore: upgrade app to 26.7.0 #5

Open
autonomic-bot wants to merge 1 commits from upgrade-526f6b5 into main

Recipe upgrade: keycloak app image 26.6.4 → 26.7.0 (minor; Keycloak stable within a major). mariadb unchanged (12.3, up-to-date).

Image-tag table

service image current → new
app keycloak/keycloak 26.6.4 → 26.7.0
db mariadb 12.3 (unchanged)

The coop-cloud.${STACK_NAME}.version label is intentionally left untouched (10.8.1+26.6.4); the operator bumps + tags + publishes it with the release command below.

Upstream release notes

Operator Action Required

  • DB migration is automatic. The recipe sets KC_SPI_CONNECTIONS_JPA_LEGACY_MIGRATION_STRATEGY=update, so Keycloak's Liquibase JPA updater runs on startup and migrates the schema (verified on a --chaos dev deploy: logs show Migrating older model to 26.7.0 / migrated realm master to 26.7.0). Back up the MariaDB volume before upgrading as a precaution.
  • No compose/config changes required; all 26.7.0 features are opt-in experimental/preview flags disabled by default.
  • Deprecation warnings observed on boot (non-fatal, no recipe change needed, but operators should plan):
    • KEYCLOAK_ADMIN / KEYCLOAK_ADMIN_PASSWORD env vars are deprecated → KC_BOOTSTRAP_ADMIN_USERNAME / KC_BOOTSTRAP_ADMIN_PASSWORD (still work in 26.7.0).
    • Hostname v1 KC_PROXY=edge is deprecated (Hostname v2 available); non-breaking.
    • Deprecated features identity-brokering-api:v1 and twitter-broker:v1 are enabled by default; the Twitter IDP implementation was removed in 26.7.0 (the twitter-broker:v1 legacy shim remains for now) — operators relying on Twitter/X login should migrate before a future removal.
  • Removed in 26.7.0: token-exchange-external-internal:v2, the batching option for persistent sessions. Not configured by this recipe.
abra recipe release keycloak -y

(minor Keycloak upgrade → recipe minor bump; the published version will become 10.9.0+26.7.0.)


Verified on a --chaos dev deploy on the cc-ci swarm (Keycloak 26.7.0 booted, DB migrated, https://dev-keycloak.ci.commoninternet.net/realms/master returned HTTP 200, then torn down). !testme run on this PR for the real cc-ci recipe-CI verdict.

NOT merged — for operator review.

Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review.

cc @trav @notplants

Recipe upgrade: keycloak app image 26.6.4 → 26.7.0 (minor; Keycloak stable within a major). mariadb unchanged (12.3, up-to-date). ## Image-tag table | service | image | current → new | |---------|-------|---------------| | app | keycloak/keycloak | 26.6.4 → 26.7.0 | | db | mariadb | 12.3 (unchanged) | The `coop-cloud.${STACK_NAME}.version` label is intentionally left untouched (10.8.1+26.6.4); the operator bumps + tags + publishes it with the release command below. ## Upstream release notes - **app** keycloak/keycloak 26.6.4 → 26.7.0: https://github.com/keycloak/keycloak/releases/tag/26.7.0 - Keycloak upgrading guide (migration changes): https://www.keycloak.org/docs/latest/upgrading/#migration-changes - **db** mariadb 12.3 (unchanged): https://mariadb.com/docs/release-notes/community-server/ ## Operator Action Required - **DB migration is automatic.** The recipe sets `KC_SPI_CONNECTIONS_JPA_LEGACY_MIGRATION_STRATEGY=update`, so Keycloak's Liquibase JPA updater runs on startup and migrates the schema (verified on a `--chaos` dev deploy: logs show `Migrating older model to 26.7.0` / `migrated realm master to 26.7.0`). **Back up the MariaDB volume before upgrading** as a precaution. - No compose/config changes required; all 26.7.0 features are opt-in experimental/preview flags disabled by default. - Deprecation warnings observed on boot (non-fatal, no recipe change needed, but operators should plan): - `KEYCLOAK_ADMIN` / `KEYCLOAK_ADMIN_PASSWORD` env vars are deprecated → `KC_BOOTSTRAP_ADMIN_USERNAME` / `KC_BOOTSTRAP_ADMIN_PASSWORD` (still work in 26.7.0). - Hostname v1 `KC_PROXY=edge` is deprecated (Hostname v2 available); non-breaking. - Deprecated features `identity-brokering-api:v1` and `twitter-broker:v1` are enabled by default; the **Twitter IDP implementation was removed** in 26.7.0 (the `twitter-broker:v1` legacy shim remains for now) — operators relying on Twitter/X login should migrate before a future removal. - Removed in 26.7.0: `token-exchange-external-internal:v2`, the batching option for persistent sessions. Not configured by this recipe. ## Recommended release ``` abra recipe release keycloak -y ``` (minor Keycloak upgrade → recipe minor bump; the published version will become `10.9.0+26.7.0`.) --- Verified on a `--chaos` dev deploy on the cc-ci swarm (Keycloak 26.7.0 booted, DB migrated, `https://dev-keycloak.ci.commoninternet.net/realms/master` returned HTTP 200, then torn down). `!testme` run on this PR for the real cc-ci recipe-CI verdict. NOT merged — for operator review. Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review. cc @trav @notplants
autonomic-bot added 1 commit 2026-07-13 20:31:19 +00:00
chore: upgrade app to 26.7.0
All checks were successful
cc-ci/testme cc-ci: success
526f6b57c1
autonomic-bot requested review from trav 2026-07-13 20:31:20 +00:00
autonomic-bot requested review from notplants 2026-07-13 20:31:20 +00:00
Author
Owner

!testme

!testme
Author
Owner

🌻 cc-cikeycloak @ 526f6b57 passed

cc-ci result card

level

full logs · dashboard

<!-- cc-ci:testme --> 🌻 **cc-ci** — `keycloak` @ `526f6b57` ✅ **passed** [![cc-ci result card](https://ci.commoninternet.net/runs/1120/summary.png)](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1120) [![level](https://ci.commoninternet.net/runs/1120/badge.svg)](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1120) [full logs](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1120) · [dashboard](https://ci.commoninternet.net/)
Author
Owner

!testme

!testme
Author
Owner

🌻 cc-cikeycloak @ 526f6b57 passed

cc-ci result card

level

full logs · dashboard

<!-- cc-ci:testme --> 🌻 **cc-ci** — `keycloak` @ `526f6b57` ✅ **passed** [![cc-ci result card](https://ci.commoninternet.net/runs/1135/summary.png)](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1135) [![level](https://ci.commoninternet.net/runs/1135/badge.svg)](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1135) [full logs](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1135) · [dashboard](https://ci.commoninternet.net/)
All checks were successful
cc-ci/testme cc-ci: success
This pull request can be merged automatically.
You are not authorized to merge this pull request.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin upgrade-526f6b5:upgrade-526f6b5
git checkout upgrade-526f6b5
Sign in to join this conversation.
No Reviewers
No Label
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: recipe-maintainers/keycloak#5
No description provided.