Extends this evolving upgrade PR (previously 2.39.2 then 2.40.2, !testme GREEN 2026-09-18, drone run 1374) to 2.40.5 — the flagged 2.40.3 catch-up plus the two newer patch releases — on the current upstream main tip (0b436ec, 3.5.0+2.38.4). Diff vs main is a single-line compose.yml image bump — the recipe version label is intentionally untouched (the release/publish is the operator's final step, command at the end).
intermediates 2.38.5–2.38.7, 2.39.1–2.39.7, 2.40.1–2.40.2: patch bugfixes (2.39.6 adds a warn-only N8N_DB_PING_TIMEOUT deprecation — this recipe does not set it)
Operator notes
No recipe deploy action required — rolling upgrade within 2.x; TypeORM migrations run automatically on startup (sqlite default; postgres variant unchanged). 2.40.2→2.40.5 adds no new migrations beyond the 15 verified at 2.40.2 (bugfix-only window).
API callers only (no recipe impact): 2.33.0 activate/deactivate endpoints deprecated (use publish/unpublish); 2.36.0 Array.merge→Array.mergeIntoObject + workflow-tags API migration; 2.37.0 "Any workflow" caller-policy deprecation + Content-Type: application/json required on decorator body routes + binary-data endpoint adapt; 2.39.0 workflow version endpoint (old two-variable path deprecated); 2.40.0 workflow publication service enabled by default; 2.40.x POST /rest/login now takes emailOrLdapLoginId instead of email (login-API request shape — scripts posting email need the new field name).
Informational: 2.39.0/2.39.1/2.40.3 encryption-key module rework + legacy/raw-key repair (recipe's N8N_ENCRYPTION_KEY secret path — exercised live below, clean). The legacy WEBHOOK_URL env still emits its pre-existing deprecation notice (honored; unchanged since the 2.38.4 boot).
The stable badge sits on the 2.39.x line (2.39.9/2.39.10 released 2026-09-21); the 2.40.x line is pre-release, consistent with this pipeline's tracking-the-newest-tag precedent (2.34.2/2.35.2/2.36.3/2.37.3/2.37.6/2.38.4/2.39.2/2.40.2 were all pre-release when taken). Docker Hub 2.40.5 manifest verified active multi-arch (amd64+arm64).
Live verification on cc-ci (direct deploy, before CI)
Real in-place upgrade over existing data (--chaos, baseline deploy of upstream main 0b436ec7 @ 2.38.4 first, seeded owner + workflow + CI marker, then WIP bf946679, image 2.38.4 → 2.40.5): all 2.39.x/2.40.x TypeORM migrations Finished cleanly (incl. CreatePromotionsTables, CreateAiPreferenceTable, DropGitConnectionTables); Recorded version change: 2.38.4 -> 2.40.5; Version: 2.40.5; n8n Task Broker ready; no encryption-key errors (raw-key repair path exercised with existing data, clean).
Data survival (the cc-ci tier flows, pre-flighted live): fresh login as the pre-upgrade owner → 200 (n8n-auth cookie; credentials + user survived); pre-upgrade workflow read-back → 200 with id/name/nodes preserved; /home/node/.n8n/ci-marker.txt still reads upgrade-survives.
Dev deploy torn down after verification (0 stacks / 0 services / 0 volumes / 0 secrets / 0 app env files leaked).
Recommended release (operator, after merge)
abra recipe release n8n -y
Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review.
Extends this evolving upgrade PR (previously **2.39.2** then **2.40.2**, `!testme` GREEN 2026-09-18, drone run 1374) to **2.40.5** — the flagged 2.40.3 catch-up plus the two newer patch releases — on the current upstream main tip (`0b436ec`, `3.5.0+2.38.4`). Diff vs main is a single-line `compose.yml` image bump — the recipe version label is intentionally untouched (the release/publish is the operator's final step, command at the end).
## Image tag table
| service | image | current (upstream main) | new |
|---------|-------|-------------------------|-----|
| app | n8nio/n8n | 2.38.4 | **2.40.5** |
| db | pgautoupgrade/pgautoupgrade (optional `compose.postgres.yml` only) | 18-alpine | unchanged — abra: "no new versions available … assuming 18-alpine is the latest" |
## Upstream release notes
**Upstream release notes:** app 2.38.4→2.40.5: https://github.com/n8n-io/n8n/releases (tags `n8n@2.39.x` / `n8n@2.40.x`)
- 2.39.0 (feature minor): https://github.com/n8n-io/n8n/releases/tag/n8n%402.39.0 — public-API source-control endpoints; workflow version endpoint (two-variable path deprecated); instance reporting; encryption-key module rework; no breaking compose/env changes
- 2.40.0 (feature minor): https://github.com/n8n-io/n8n/releases/tag/n8n%402.40.0 — Microsoft Dataverse node; Git-based promotion model; workflow publication service enabled by default; v3 migration-report warnings; ~150 bugfixes; no breaking compose/env changes, no `N8N_*` renames
- 2.40.3 (this run's flagged catch-up): https://github.com/n8n-io/n8n/releases/tag/n8n%402.40.3 — core "repair data-encryption keys stored as the raw instance key" + editor blank-workflow-preview fix
- 2.40.4: https://github.com/n8n-io/n8n/releases/tag/n8n%402.40.4 — core trigger teardown when publication meets an unloadable node type; perf (skip project members when listing credentials)
- 2.40.5 (target): https://github.com/n8n-io/n8n/releases/tag/n8n%402.40.5 — core "limit declarative routing during base URL ownership checks"
- intermediates 2.38.5–2.38.7, 2.39.1–2.39.7, 2.40.1–2.40.2: patch bugfixes (2.39.6 adds a warn-only `N8N_DB_PING_TIMEOUT` deprecation — this recipe does not set it)
## Operator notes
- **No recipe deploy action required** — rolling upgrade within 2.x; TypeORM migrations run automatically on startup (sqlite default; postgres variant unchanged). 2.40.2→2.40.5 adds **no new migrations** beyond the 15 verified at 2.40.2 (bugfix-only window).
- **API callers only** (no recipe impact): 2.33.0 activate/deactivate endpoints deprecated (use publish/unpublish); 2.36.0 `Array.merge`→`Array.mergeIntoObject` + workflow-tags API migration; 2.37.0 "Any workflow" caller-policy deprecation + `Content-Type: application/json` required on decorator body routes + binary-data endpoint adapt; 2.39.0 workflow version endpoint (old two-variable path deprecated); 2.40.0 workflow publication service enabled by default; 2.40.x `POST /rest/login` now takes `emailOrLdapLoginId` instead of `email` (login-API request shape — scripts posting `email` need the new field name).
- **Informational:** 2.39.0/2.39.1/2.40.3 encryption-key module rework + legacy/raw-key repair (recipe's `N8N_ENCRYPTION_KEY` secret path — exercised live below, clean). The legacy `WEBHOOK_URL` env still emits its pre-existing deprecation notice (honored; unchanged since the 2.38.4 boot).
- The `stable` badge sits on the **2.39.x** line (2.39.9/2.39.10 released 2026-09-21); the 2.40.x line is pre-release, consistent with this pipeline's tracking-the-newest-tag precedent (2.34.2/2.35.2/2.36.3/2.37.3/2.37.6/2.38.4/2.39.2/2.40.2 were all pre-release when taken). Docker Hub `2.40.5` manifest verified active multi-arch (amd64+arm64).
## Live verification on cc-ci (direct deploy, before CI)
- Real in-place upgrade over existing data (`--chaos`, baseline deploy of upstream main `0b436ec7` @ 2.38.4 first, seeded owner + workflow + CI marker, then WIP `bf946679`, image `2.38.4 → 2.40.5`): all 2.39.x/2.40.x TypeORM migrations `Finished` cleanly (incl. `CreatePromotionsTables`, `CreateAiPreferenceTable`, `DropGitConnectionTables`); `Recorded version change: 2.38.4 -> 2.40.5`; `Version: 2.40.5`; `n8n Task Broker ready`; no encryption-key errors (raw-key repair path exercised with existing data, clean).
- Serving: `/healthz` → 200 `{"status":"ok"}`; editor `/` → 200; `GET /rest/login` → 401 JSON (expected no-session shape).
- Data survival (the cc-ci tier flows, pre-flighted live): fresh **login as the pre-upgrade owner → 200** (`n8n-auth` cookie; credentials + user survived); **pre-upgrade workflow read-back → 200 with id/name/nodes preserved**; `/home/node/.n8n/ci-marker.txt` still reads `upgrade-survives`.
- Dev deploy torn down after verification (0 stacks / 0 services / 0 volumes / 0 secrets / 0 app env files leaked).
## Recommended release (operator, after merge)
`abra recipe release n8n -y`
Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review.
cc @trav @notplants
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Extends this evolving upgrade PR (previously 2.39.2 then 2.40.2,
!testmeGREEN 2026-09-18, drone run 1374) to 2.40.5 — the flagged 2.40.3 catch-up plus the two newer patch releases — on the current upstream main tip (0b436ec,3.5.0+2.38.4). Diff vs main is a single-linecompose.ymlimage bump — the recipe version label is intentionally untouched (the release/publish is the operator's final step, command at the end).Image tag table
compose.postgres.ymlonly)Upstream release notes
Upstream release notes: app 2.38.4→2.40.5: https://github.com/n8n-io/n8n/releases (tags
n8n@2.39.x/n8n@2.40.x)N8N_*renamesN8N_DB_PING_TIMEOUTdeprecation — this recipe does not set it)Operator notes
Array.merge→Array.mergeIntoObject+ workflow-tags API migration; 2.37.0 "Any workflow" caller-policy deprecation +Content-Type: application/jsonrequired on decorator body routes + binary-data endpoint adapt; 2.39.0 workflow version endpoint (old two-variable path deprecated); 2.40.0 workflow publication service enabled by default; 2.40.xPOST /rest/loginnow takesemailOrLdapLoginIdinstead ofemail(login-API request shape — scripts postingemailneed the new field name).N8N_ENCRYPTION_KEYsecret path — exercised live below, clean). The legacyWEBHOOK_URLenv still emits its pre-existing deprecation notice (honored; unchanged since the 2.38.4 boot).stablebadge sits on the 2.39.x line (2.39.9/2.39.10 released 2026-09-21); the 2.40.x line is pre-release, consistent with this pipeline's tracking-the-newest-tag precedent (2.34.2/2.35.2/2.36.3/2.37.3/2.37.6/2.38.4/2.39.2/2.40.2 were all pre-release when taken). Docker Hub2.40.5manifest verified active multi-arch (amd64+arm64).Live verification on cc-ci (direct deploy, before CI)
--chaos, baseline deploy of upstream main0b436ec7@ 2.38.4 first, seeded owner + workflow + CI marker, then WIPbf946679, image2.38.4 → 2.40.5): all 2.39.x/2.40.x TypeORM migrationsFinishedcleanly (incl.CreatePromotionsTables,CreateAiPreferenceTable,DropGitConnectionTables);Recorded version change: 2.38.4 -> 2.40.5;Version: 2.40.5;n8n Task Broker ready; no encryption-key errors (raw-key repair path exercised with existing data, clean)./healthz→ 200{"status":"ok"}; editor/→ 200;GET /rest/login→ 401 JSON (expected no-session shape).n8n-authcookie; credentials + user survived); pre-upgrade workflow read-back → 200 with id/name/nodes preserved;/home/node/.n8n/ci-marker.txtstill readsupgrade-survives.Recommended release (operator, after merge)
abra recipe release n8n -yTested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review.
cc @trav @notplants
!testme
🌻 cc-ci —
n8n@ef0dd56a✅ passedfull logs · dashboard
chore: upgrade n8nio/n8n to 2.39.2to chore: upgrade n8nio/n8n to 2.40.2!testme
🌻 cc-ci —
n8n@b64c1daa✅ passedfull logs · dashboard
chore: upgrade n8nio/n8n to 2.40.2to chore: upgrade n8nio/n8n to 2.40.5!testme
🌻 cc-ci —
n8n@6103b6ef✅ passedfull logs · dashboard
Auto-closed by /recipe-upgrade: its changes are already in upstream main (merged upstream); mirror main re-synced
autonomic-bot referenced this pull request2026-09-28 21:47:20 +00:00
Pull request closed