chore: upgrade lasuite-drive to v0.23.0, collabora to 26.04.4.2.1; bump minio_initialize config to v2 #8

Open
autonomic-bot wants to merge 2 commits from upgrade-ce5308c into main
Owner

Recipe upgrade — extends this PR with this week's work (drive v0.23.0, collabora 26.04.4.2.1, minio_initialize config v2). Rebased onto current upstream main (which now carries the minio bitnami switch, coopcloud PR #13).

Image bumps

service image current new
app lasuite/drive-frontend v0.22.0 v0.23.0
backend lasuite/drive-backend v0.22.0 v0.23.0
celery lasuite/drive-backend v0.22.0 v0.23.0
celery-beat lasuite/drive-backend v0.22.0 v0.23.0
redis redis 8.10.1 8.10.2 (SECURITY, released 2026-09-17)
collabora collabora/code 25.04.10.3.1 26.04.4.2.1 (26.04 CODE line; newest tag, pushed 2026-09-24)

Held (verified current): pgautoupgrade 18-debian (no 19 line), mailcatcher v0.11.0,
onlyoffice 9.4.1.2 (newest hub tag — no 9.5), nginx 1.31.6, minio
bitnamilegacy/minio:2025.7.23-debian-12-r5 (upstream main's current pin; newest bitnami-legacy tag).

Other changes on this PR from the earlier commit: redis 8.10.1→8.10.2 already carried here.

Upstream release notes

Notes / breaking changes

  • drive v0.23.0 — no breaking changes and no migration step. Added: optional psycopg
    connection-pool config (opt-in; not wired by this recipe), helm-only backend env vars.
    Fixed: Recent view refresh after item mutations; root-item creation gated on the upload
    entitlement. drive's own reference compose pins the 26.04 collabora line (26.04.2.2.1),
    so 26.04.4.2.1 is the same line at a newer patch.
  • collabora 26.04 image contract (from the earlier commit on this PR, unchanged): the 26.04
    image execs coolwsd --use-env-vars directly — no shell, /start-collabora-online.sh gone —
    so the entrypoint override is dropped, SSL options move to command:, the healthcheck uses
    coolwsd --probe, and the panel password moves off the retired collabora_p Docker secret
    onto the COLLABORA_ADMIN_PASSWORD env var. See Operator Action Required.
  • minio_initialize config version bumped v1 → v2 (abra.sh) — this is required, not cosmetic.
    Upstream's minio switch (coopcloud PR #13, "Use other minio as the quay.io is not available")
    changed minio-initialize.sh content but left the vendored config version at v1. Swarm configs
    are immutable, so any upgrade of an existing deployment aborts with
    FATA failed to update config …_minio_initialize_v1: only updates to Labels are allowed —
    before any image even starts. Confirmed empirically: the cc-ci run on the superseded minio PR
    (run 17) failed exactly here. Bumping to v2 makes Swarm create a new config object instead.
  • minio image source — upstream repinned quay.io/minio/minio:RELEASE.2025-09-07T16-13-09Z
    → bitnamilegacy/minio:2025.7.23-debian-12-r5 because the Quay tag no longer exists
    (docker manifest inspect → no such manifest) and Docker Hub minio/minio was removed. No
    operator action; this PR takes upstream main's pin verbatim.

Security content (GitHub advisories via the cc-ci advisory scan, unioned with release-note reading)

5 CVEs fixed by this upgrade (all collabora; none named in the 26.04 release-notes prose, which
is exactly why the scan exists):

  • CVE-2026-77276 (HIGH) — GHSA-cf9v-hrj7-8p4v (fixed 25.04.12.3 / 26.04.2.2)
  • CVE-2026-55243 (MEDIUM) — GHSA-2g97-qwj5-fj7f (fixed 25.04.11 / 24.04.19 / 26.04.2)
  • CVE-2026-46499 (MEDIUM) — GHSA-27j2-3cqv-cc5q (fixed 25.04.11 / 24.04.18)
  • CVE-2026-48164 (MEDIUM) — GHSA-wgmm-q3ch-64jj (fixed 25.04.11 / 24.04.18)
  • CVE-2025-66208 (MEDIUM) — GHSA-j3q6-q5pc-v5wf

redis 8.10.2's security fixes (transaction ACL-revocation bypass #15673, unauthenticated
cluster-bus join #15722 — new cluster-bus-port-protected-mode defaults to no, preserving
behavior; TimeSeries/RedisSearch/VectorSets crash fixes in module-bearing builds) carry no CVE
ids in the release notes and were not GHSA-mapped in this window; counted from the notes. No
failed advisory sources; no open/undecided cases for the named windows.

Operator Action Required

  1. On upgrade, the Collabora admin panel
    (https://<COLLABORA_DOMAIN>/browser/dist/admin/admin.html) is locked until
    COLLABORA_ADMIN_PASSWORD is set in the app .env (was: Docker secret collabora_p, which
    the 26.04 image can no longer consume — no shell in the image). Empty/unset = panel stays
    locked (401, verified). Serving and WOPI editing are unaffected, so nothing is required to
    keep running after the upgrade.
  2. Recommended release after merge:
    abra recipe release lasuite-drive -y
    (drive minor + collabora feature-line bump with a config migration + redis security patch;
    non-breaking for existing deploys — no .env change is required to keep serving. Version
    label intentionally untouched.)

Live verification on cc-ci before CI (dev deploy, 2026-09-28, torn down after)

Deployed this head (86213d2) with --chaos on the cc-ci swarm as
dev-lasuite-drive.ci.commoninternet.net, from the published v0.22.0 deployment already running:
11/11 services converged and healthy; drive root HTTP 200; collabora /hosting/discovery → 200
and minio /minio/health/live → 200 (probed from inside the stack network); backend applied
pending migrations cleanly (incl. malware_detection.0003…) and gunicorn came up; minio
minio-initialize: bucket 'drive-media-storage' … present. The minio_initialize: v1 → v2
config hop was exercised live (both config objects observed) with no only updates to Labels
failure — the exact path that broke run 17.

Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review.

cc @trav @notplants

Recipe upgrade — extends this PR with this week's work (drive v0.23.0, collabora 26.04.4.2.1, minio_initialize config v2). Rebased onto current upstream main (which now carries the minio bitnami switch, coopcloud PR #13). ## Image bumps | service | image | current | new | |---------|-------|---------|-----| | app | `lasuite/drive-frontend` | v0.22.0 | **v0.23.0** | | backend | `lasuite/drive-backend` | v0.22.0 | **v0.23.0** | | celery | `lasuite/drive-backend` | v0.22.0 | **v0.23.0** | | celery-beat | `lasuite/drive-backend` | v0.22.0 | **v0.23.0** | | redis | `redis` | 8.10.1 | **8.10.2** (SECURITY, released 2026-09-17) | | collabora | `collabora/code` | 25.04.10.3.1 | **26.04.4.2.1** (26.04 CODE line; newest tag, pushed 2026-09-24) | Held (verified current): pgautoupgrade `18-debian` (no 19 line), mailcatcher `v0.11.0`, onlyoffice `9.4.1.2` (newest hub tag — no 9.5), nginx `1.31.6`, minio `bitnamilegacy/minio:2025.7.23-debian-12-r5` (upstream main's current pin; newest bitnami-legacy tag). Other changes on this PR from the earlier commit: redis 8.10.1→8.10.2 already carried here. ## Upstream release notes - **drive v0.22.0 → v0.23.0**: https://github.com/suitenumerique/drive/releases/tag/v0.23.0 - **redis 8.10.1 → 8.10.2**: https://github.com/redis/redis/releases/tag/8.10.2 - **collabora 25.04.10.3.1 → 26.04.4.2.1**: https://www.collaboraonline.com/collabora-online-26-04-release-notes/ ## Notes / breaking changes - **drive v0.23.0** — no breaking changes and no migration step. Added: optional psycopg connection-pool config (opt-in; not wired by this recipe), helm-only backend env vars. Fixed: Recent view refresh after item mutations; root-item creation gated on the upload entitlement. drive's own reference compose pins the **26.04** collabora line (26.04.2.2.1), so 26.04.4.2.1 is the same line at a newer patch. - **collabora 26.04 image contract** (from the earlier commit on this PR, unchanged): the 26.04 image execs `coolwsd --use-env-vars` directly — no shell, `/start-collabora-online.sh` gone — so the entrypoint override is dropped, SSL options move to `command:`, the healthcheck uses `coolwsd --probe`, and the panel password moves off the retired `collabora_p` Docker secret onto the `COLLABORA_ADMIN_PASSWORD` env var. See Operator Action Required. - **minio_initialize config version bumped v1 → v2** (`abra.sh`) — this is required, not cosmetic. Upstream's minio switch (coopcloud PR #13, "Use other minio as the quay.io is not available") changed `minio-initialize.sh` content but left the vendored config version at v1. Swarm configs are immutable, so **any upgrade of an existing deployment aborts** with `FATA failed to update config …_minio_initialize_v1: only updates to Labels are allowed` — before any image even starts. Confirmed empirically: the cc-ci run on the superseded minio PR (run 17) failed exactly here. Bumping to v2 makes Swarm create a new config object instead. - **minio image source** — upstream repinned `quay.io/minio/minio:RELEASE.2025-09-07T16-13-09Z` → `bitnamilegacy/minio:2025.7.23-debian-12-r5` because the Quay tag no longer exists (`docker manifest inspect` → no such manifest) and Docker Hub `minio/minio` was removed. No operator action; this PR takes upstream main's pin verbatim. ## Security content (GitHub advisories via the cc-ci advisory scan, unioned with release-note reading) 5 CVEs fixed by this upgrade (all collabora; none named in the 26.04 release-notes prose, which is exactly why the scan exists): - **CVE-2026-77276 (HIGH)** — GHSA-cf9v-hrj7-8p4v (fixed 25.04.12.3 / 26.04.2.2) - CVE-2026-55243 (MEDIUM) — GHSA-2g97-qwj5-fj7f (fixed 25.04.11 / 24.04.19 / 26.04.2) - CVE-2026-46499 (MEDIUM) — GHSA-27j2-3cqv-cc5q (fixed 25.04.11 / 24.04.18) - CVE-2026-48164 (MEDIUM) — GHSA-wgmm-q3ch-64jj (fixed 25.04.11 / 24.04.18) - CVE-2025-66208 (MEDIUM) — GHSA-j3q6-q5pc-v5wf redis 8.10.2's security fixes (transaction ACL-revocation bypass #15673, unauthenticated cluster-bus join #15722 — new `cluster-bus-port-protected-mode` defaults to `no`, preserving behavior; TimeSeries/RedisSearch/VectorSets crash fixes in module-bearing builds) carry no CVE ids in the release notes and were not GHSA-mapped in this window; counted from the notes. No failed advisory sources; no open/undecided cases for the named windows. ## Operator Action Required 1. On upgrade, the Collabora admin panel (`https://<COLLABORA_DOMAIN>/browser/dist/admin/admin.html`) is **locked** until `COLLABORA_ADMIN_PASSWORD` is set in the app `.env` (was: Docker secret `collabora_p`, which the 26.04 image can no longer consume — no shell in the image). Empty/unset = panel stays locked (401, verified). Serving and WOPI editing are unaffected, so nothing is *required* to keep running after the upgrade. 2. Recommended release after merge: `abra recipe release lasuite-drive -y` (drive minor + collabora feature-line bump with a config migration + redis security patch; non-breaking for existing deploys — no `.env` change is required to keep serving. Version label intentionally untouched.) ## Live verification on cc-ci before CI (dev deploy, 2026-09-28, torn down after) Deployed this head (`86213d2`) with `--chaos` on the cc-ci swarm as `dev-lasuite-drive.ci.commoninternet.net`, from the published v0.22.0 deployment already running: 11/11 services converged and healthy; drive root HTTP 200; collabora `/hosting/discovery` → 200 and minio `/minio/health/live` → 200 (probed from inside the stack network); backend applied pending migrations cleanly (incl. `malware_detection.0003…`) and gunicorn came up; minio `minio-initialize: bucket 'drive-media-storage' …` present. The `minio_initialize: v1 → v2` config hop was exercised live (both config objects observed) with no `only updates to Labels` failure — the exact path that broke run 17. Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review. cc @trav @notplants
autonomic-bot added 1 commit 2026-09-21 21:28:34 +00:00
collabora 26.04 images exec coolwsd directly (--use-env-vars; no shell in the
image), so the sh/start-collabora-online.sh entrypoint and extra_params env are
gone: ssl options move to command args, the healthcheck switches to
coolwsd --probe, and the admin panel password moves from the collabora_p
docker secret to the COLLABORA_ADMIN_PASSWORD env var (empty = locked).

redis 8.10.2 is a security release (transaction ACL-revocation bypass,
unauthenticated cluster-bus join; cache sidecar, no cluster mode here).
autonomic-bot requested review from trav 2026-09-21 21:28:34 +00:00
autonomic-bot requested review from notplants 2026-09-21 21:28:34 +00:00
Author
Owner

!testme

!testme
Author
Owner

🌻 cc-ci — lasuite-drive @ ce5308c7 ❌ failure

cc-ci result card

level

full logs · dashboard

<!-- cc-ci:testme --> 🌻 **cc-ci** — `lasuite-drive` @ `ce5308c7` ❌ **failure** [![cc-ci result card](https://ci.autonomic.zone/runs/9/summary.png)](https://drone.ci.autonomic.zone/recipe-maintainers/cc-ci/9) [![level](https://ci.autonomic.zone/runs/9/badge.svg)](https://drone.ci.autonomic.zone/recipe-maintainers/cc-ci/9) [full logs](https://drone.ci.autonomic.zone/recipe-maintainers/cc-ci/9) · [dashboard](https://ci.autonomic.zone/)
autonomic-bot changed title from chore: upgrade lasuite-drive redis to 8.10.2, collabora to 26.04.4.1.1 to chore: upgrade lasuite-drive to v0.23.0, collabora to 26.04.4.2.1; bump minio_initialize config to v2 2026-09-28 21:07:18 +00:00
autonomic-bot added 1 commit 2026-09-28 21:07:18 +00:00
Author
Owner

!testme

!testme
Author
Owner

🌻 cc-ci — lasuite-drive @ 1ed910df ✅ passed

cc-ci result card

level

full logs · dashboard

<!-- cc-ci:testme --> 🌻 **cc-ci** — `lasuite-drive` @ `1ed910df` ✅ **passed** [![cc-ci result card](https://ci.autonomic.zone/runs/18/summary.png)](https://drone.ci.autonomic.zone/recipe-maintainers/cc-ci/18) [![level](https://ci.autonomic.zone/runs/18/badge.svg)](https://drone.ci.autonomic.zone/recipe-maintainers/cc-ci/18) [full logs](https://drone.ci.autonomic.zone/recipe-maintainers/cc-ci/18) · [dashboard](https://ci.autonomic.zone/)
All checks were successful
cc-ci/testme cc-ci: success
You are not authorized to merge this pull request.
This pull request can be merged automatically.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin upgrade-ce5308c:upgrade-ce5308c
git checkout upgrade-ce5308c
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: recipe-maintainers/lasuite-drive#8