Recipe upgrade — extends this PR with this week's work (drive v0.23.0, collabora 26.04.4.2.1, minio_initialize config v2). Rebased onto current upstream main (which now carries the minio bitnami switch, coopcloud PR #13).
drive v0.23.0 — no breaking changes and no migration step. Added: optional psycopg
connection-pool config (opt-in; not wired by this recipe), helm-only backend env vars.
Fixed: Recent view refresh after item mutations; root-item creation gated on the upload
entitlement. drive's own reference compose pins the 26.04 collabora line (26.04.2.2.1),
so 26.04.4.2.1 is the same line at a newer patch.
collabora 26.04 image contract (from the earlier commit on this PR, unchanged): the 26.04
image execs coolwsd --use-env-vars directly — no shell, /start-collabora-online.sh gone —
so the entrypoint override is dropped, SSL options move to command:, the healthcheck uses coolwsd --probe, and the panel password moves off the retired collabora_p Docker secret
onto the COLLABORA_ADMIN_PASSWORD env var. See Operator Action Required.
minio_initialize config version bumped v1 → v2 (abra.sh) — this is required, not cosmetic.
Upstream's minio switch (coopcloud PR #13, "Use other minio as the quay.io is not available")
changed minio-initialize.sh content but left the vendored config version at v1. Swarm configs
are immutable, so any upgrade of an existing deployment aborts with FATA failed to update config …_minio_initialize_v1: only updates to Labels are allowed —
before any image even starts. Confirmed empirically: the cc-ci run on the superseded minio PR
(run 17) failed exactly here. Bumping to v2 makes Swarm create a new config object instead.
minio image source — upstream repinned quay.io/minio/minio:RELEASE.2025-09-07T16-13-09Z
→ bitnamilegacy/minio:2025.7.23-debian-12-r5 because the Quay tag no longer exists
(docker manifest inspect → no such manifest) and Docker Hub minio/minio was removed. No
operator action; this PR takes upstream main's pin verbatim.
Security content (GitHub advisories via the cc-ci advisory scan, unioned with release-note reading)
5 CVEs fixed by this upgrade (all collabora; none named in the 26.04 release-notes prose, which
is exactly why the scan exists):
redis 8.10.2's security fixes (transaction ACL-revocation bypass #15673, unauthenticated
cluster-bus join #15722 — new cluster-bus-port-protected-mode defaults to no, preserving
behavior; TimeSeries/RedisSearch/VectorSets crash fixes in module-bearing builds) carry no CVE
ids in the release notes and were not GHSA-mapped in this window; counted from the notes. No
failed advisory sources; no open/undecided cases for the named windows.
Operator Action Required
On upgrade, the Collabora admin panel
(https://<COLLABORA_DOMAIN>/browser/dist/admin/admin.html) is locked until COLLABORA_ADMIN_PASSWORD is set in the app .env (was: Docker secret collabora_p, which
the 26.04 image can no longer consume — no shell in the image). Empty/unset = panel stays
locked (401, verified). Serving and WOPI editing are unaffected, so nothing is required to
keep running after the upgrade.
Recommended release after merge: abra recipe release lasuite-drive -y
(drive minor + collabora feature-line bump with a config migration + redis security patch;
non-breaking for existing deploys — no .env change is required to keep serving. Version
label intentionally untouched.)
Live verification on cc-ci before CI (dev deploy, 2026-09-28, torn down after)
Deployed this head (86213d2) with --chaos on the cc-ci swarm as dev-lasuite-drive.ci.commoninternet.net, from the published v0.22.0 deployment already running:
11/11 services converged and healthy; drive root HTTP 200; collabora /hosting/discovery → 200
and minio /minio/health/live → 200 (probed from inside the stack network); backend applied
pending migrations cleanly (incl. malware_detection.0003…) and gunicorn came up; minio minio-initialize: bucket 'drive-media-storage' … present. The minio_initialize: v1 → v2
config hop was exercised live (both config objects observed) with no only updates to Labels
failure — the exact path that broke run 17.
Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review.
Recipe upgrade — extends this PR with this week's work (drive v0.23.0, collabora 26.04.4.2.1, minio_initialize config v2). Rebased onto current upstream main (which now carries the minio bitnami switch, coopcloud PR #13).
## Image bumps
| service | image | current | new |
|---------|-------|---------|-----|
| app | `lasuite/drive-frontend` | v0.22.0 | **v0.23.0** |
| backend | `lasuite/drive-backend` | v0.22.0 | **v0.23.0** |
| celery | `lasuite/drive-backend` | v0.22.0 | **v0.23.0** |
| celery-beat | `lasuite/drive-backend` | v0.22.0 | **v0.23.0** |
| redis | `redis` | 8.10.1 | **8.10.2** (SECURITY, released 2026-09-17) |
| collabora | `collabora/code` | 25.04.10.3.1 | **26.04.4.2.1** (26.04 CODE line; newest tag, pushed 2026-09-24) |
Held (verified current): pgautoupgrade `18-debian` (no 19 line), mailcatcher `v0.11.0`,
onlyoffice `9.4.1.2` (newest hub tag — no 9.5), nginx `1.31.6`, minio
`bitnamilegacy/minio:2025.7.23-debian-12-r5` (upstream main's current pin; newest bitnami-legacy tag).
Other changes on this PR from the earlier commit: redis 8.10.1→8.10.2 already carried here.
## Upstream release notes
- **drive v0.22.0 → v0.23.0**: https://github.com/suitenumerique/drive/releases/tag/v0.23.0
- **redis 8.10.1 → 8.10.2**: https://github.com/redis/redis/releases/tag/8.10.2
- **collabora 25.04.10.3.1 → 26.04.4.2.1**: https://www.collaboraonline.com/collabora-online-26-04-release-notes/
## Notes / breaking changes
- **drive v0.23.0** — no breaking changes and no migration step. Added: optional psycopg
connection-pool config (opt-in; not wired by this recipe), helm-only backend env vars.
Fixed: Recent view refresh after item mutations; root-item creation gated on the upload
entitlement. drive's own reference compose pins the **26.04** collabora line (26.04.2.2.1),
so 26.04.4.2.1 is the same line at a newer patch.
- **collabora 26.04 image contract** (from the earlier commit on this PR, unchanged): the 26.04
image execs `coolwsd --use-env-vars` directly — no shell, `/start-collabora-online.sh` gone —
so the entrypoint override is dropped, SSL options move to `command:`, the healthcheck uses
`coolwsd --probe`, and the panel password moves off the retired `collabora_p` Docker secret
onto the `COLLABORA_ADMIN_PASSWORD` env var. See Operator Action Required.
- **minio_initialize config version bumped v1 → v2** (`abra.sh`) — this is required, not cosmetic.
Upstream's minio switch (coopcloud PR #13, "Use other minio as the quay.io is not available")
changed `minio-initialize.sh` content but left the vendored config version at v1. Swarm configs
are immutable, so **any upgrade of an existing deployment aborts** with
`FATA failed to update config …_minio_initialize_v1: only updates to Labels are allowed` —
before any image even starts. Confirmed empirically: the cc-ci run on the superseded minio PR
(run 17) failed exactly here. Bumping to v2 makes Swarm create a new config object instead.
- **minio image source** — upstream repinned `quay.io/minio/minio:RELEASE.2025-09-07T16-13-09Z`
→ `bitnamilegacy/minio:2025.7.23-debian-12-r5` because the Quay tag no longer exists
(`docker manifest inspect` → no such manifest) and Docker Hub `minio/minio` was removed. No
operator action; this PR takes upstream main's pin verbatim.
## Security content (GitHub advisories via the cc-ci advisory scan, unioned with release-note reading)
5 CVEs fixed by this upgrade (all collabora; none named in the 26.04 release-notes prose, which
is exactly why the scan exists):
- **CVE-2026-77276 (HIGH)** — GHSA-cf9v-hrj7-8p4v (fixed 25.04.12.3 / 26.04.2.2)
- CVE-2026-55243 (MEDIUM) — GHSA-2g97-qwj5-fj7f (fixed 25.04.11 / 24.04.19 / 26.04.2)
- CVE-2026-46499 (MEDIUM) — GHSA-27j2-3cqv-cc5q (fixed 25.04.11 / 24.04.18)
- CVE-2026-48164 (MEDIUM) — GHSA-wgmm-q3ch-64jj (fixed 25.04.11 / 24.04.18)
- CVE-2025-66208 (MEDIUM) — GHSA-j3q6-q5pc-v5wf
redis 8.10.2's security fixes (transaction ACL-revocation bypass #15673, unauthenticated
cluster-bus join #15722 — new `cluster-bus-port-protected-mode` defaults to `no`, preserving
behavior; TimeSeries/RedisSearch/VectorSets crash fixes in module-bearing builds) carry no CVE
ids in the release notes and were not GHSA-mapped in this window; counted from the notes. No
failed advisory sources; no open/undecided cases for the named windows.
## Operator Action Required
1. On upgrade, the Collabora admin panel
(`https://<COLLABORA_DOMAIN>/browser/dist/admin/admin.html`) is **locked** until
`COLLABORA_ADMIN_PASSWORD` is set in the app `.env` (was: Docker secret `collabora_p`, which
the 26.04 image can no longer consume — no shell in the image). Empty/unset = panel stays
locked (401, verified). Serving and WOPI editing are unaffected, so nothing is *required* to
keep running after the upgrade.
2. Recommended release after merge:
`abra recipe release lasuite-drive -y`
(drive minor + collabora feature-line bump with a config migration + redis security patch;
non-breaking for existing deploys — no `.env` change is required to keep serving. Version
label intentionally untouched.)
## Live verification on cc-ci before CI (dev deploy, 2026-09-28, torn down after)
Deployed this head (`86213d2`) with `--chaos` on the cc-ci swarm as
`dev-lasuite-drive.ci.commoninternet.net`, from the published v0.22.0 deployment already running:
11/11 services converged and healthy; drive root HTTP 200; collabora `/hosting/discovery` → 200
and minio `/minio/health/live` → 200 (probed from inside the stack network); backend applied
pending migrations cleanly (incl. `malware_detection.0003…`) and gunicorn came up; minio
`minio-initialize: bucket 'drive-media-storage' …` present. The `minio_initialize: v1 → v2`
config hop was exercised live (both config objects observed) with no `only updates to Labels`
failure — the exact path that broke run 17.
Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review.
cc @trav @notplants
collabora 26.04 images exec coolwsd directly (--use-env-vars; no shell in the
image), so the sh/start-collabora-online.sh entrypoint and extra_params env are
gone: ssl options move to command args, the healthcheck switches to
coolwsd --probe, and the admin panel password moves from the collabora_p
docker secret to the COLLABORA_ADMIN_PASSWORD env var (empty = locked).
redis 8.10.2 is a security release (transaction ACL-revocation bypass,
unauthenticated cluster-bus join; cache sidecar, no cluster mode here).
autonomic-bot
requested review from trav 2026-09-21 21:28:34 +00:00
autonomic-bot
requested review from notplants 2026-09-21 21:28:34 +00:00
autonomic-bot
changed title from chore: upgrade lasuite-drive redis to 8.10.2, collabora to 26.04.4.1.1 to chore: upgrade lasuite-drive to v0.23.0, collabora to 26.04.4.2.1; bump minio_initialize config to v22026-09-28 21:07:18 +00:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Recipe upgrade — extends this PR with this week's work (drive v0.23.0, collabora 26.04.4.2.1, minio_initialize config v2). Rebased onto current upstream main (which now carries the minio bitnami switch, coopcloud PR #13).
Image bumps
lasuite/drive-frontendlasuite/drive-backendlasuite/drive-backendlasuite/drive-backendrediscollabora/codeHeld (verified current): pgautoupgrade
18-debian(no 19 line), mailcatcherv0.11.0,onlyoffice
9.4.1.2(newest hub tag — no 9.5), nginx1.31.6, miniobitnamilegacy/minio:2025.7.23-debian-12-r5(upstream main's current pin; newest bitnami-legacy tag).Other changes on this PR from the earlier commit: redis 8.10.1→8.10.2 already carried here.
Upstream release notes
Notes / breaking changes
connection-pool config (opt-in; not wired by this recipe), helm-only backend env vars.
Fixed: Recent view refresh after item mutations; root-item creation gated on the upload
entitlement. drive's own reference compose pins the 26.04 collabora line (26.04.2.2.1),
so 26.04.4.2.1 is the same line at a newer patch.
image execs
coolwsd --use-env-varsdirectly — no shell,/start-collabora-online.shgone —so the entrypoint override is dropped, SSL options move to
command:, the healthcheck usescoolwsd --probe, and the panel password moves off the retiredcollabora_pDocker secretonto the
COLLABORA_ADMIN_PASSWORDenv var. See Operator Action Required.abra.sh) — this is required, not cosmetic.Upstream's minio switch (coopcloud PR #13, "Use other minio as the quay.io is not available")
changed
minio-initialize.shcontent but left the vendored config version at v1. Swarm configsare immutable, so any upgrade of an existing deployment aborts with
FATA failed to update config …_minio_initialize_v1: only updates to Labels are allowed—before any image even starts. Confirmed empirically: the cc-ci run on the superseded minio PR
(run 17) failed exactly here. Bumping to v2 makes Swarm create a new config object instead.
quay.io/minio/minio:RELEASE.2025-09-07T16-13-09Z→
bitnamilegacy/minio:2025.7.23-debian-12-r5because the Quay tag no longer exists(
docker manifest inspect→ no such manifest) and Docker Hubminio/miniowas removed. Nooperator action; this PR takes upstream main's pin verbatim.
Security content (GitHub advisories via the cc-ci advisory scan, unioned with release-note reading)
5 CVEs fixed by this upgrade (all collabora; none named in the 26.04 release-notes prose, which
is exactly why the scan exists):
redis 8.10.2's security fixes (transaction ACL-revocation bypass #15673, unauthenticated
cluster-bus join #15722 — new
cluster-bus-port-protected-modedefaults tono, preservingbehavior; TimeSeries/RedisSearch/VectorSets crash fixes in module-bearing builds) carry no CVE
ids in the release notes and were not GHSA-mapped in this window; counted from the notes. No
failed advisory sources; no open/undecided cases for the named windows.
Operator Action Required
(
https://<COLLABORA_DOMAIN>/browser/dist/admin/admin.html) is locked untilCOLLABORA_ADMIN_PASSWORDis set in the app.env(was: Docker secretcollabora_p, whichthe 26.04 image can no longer consume — no shell in the image). Empty/unset = panel stays
locked (401, verified). Serving and WOPI editing are unaffected, so nothing is required to
keep running after the upgrade.
abra recipe release lasuite-drive -y(drive minor + collabora feature-line bump with a config migration + redis security patch;
non-breaking for existing deploys — no
.envchange is required to keep serving. Versionlabel intentionally untouched.)
Live verification on cc-ci before CI (dev deploy, 2026-09-28, torn down after)
Deployed this head (
86213d2) with--chaoson the cc-ci swarm asdev-lasuite-drive.ci.commoninternet.net, from the published v0.22.0 deployment already running:11/11 services converged and healthy; drive root HTTP 200; collabora
/hosting/discovery→ 200and minio
/minio/health/live→ 200 (probed from inside the stack network); backend appliedpending migrations cleanly (incl.
malware_detection.0003…) and gunicorn came up; miniominio-initialize: bucket 'drive-media-storage' …present. Theminio_initialize: v1 → v2config hop was exercised live (both config objects observed) with no
only updates to Labelsfailure — the exact path that broke run 17.
Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review.
cc @trav @notplants
!testme
🌻 cc-ci —
lasuite-drive@ce5308c7❌ failurefull logs · dashboard
chore: upgrade lasuite-drive redis to 8.10.2, collabora to 26.04.4.1.1to chore: upgrade lasuite-drive to v0.23.0, collabora to 26.04.4.2.1; bump minio_initialize config to v2!testme
🌻 cc-ci —
lasuite-drive@1ed910df✅ passedfull logs · dashboard
View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.