feat(container)!: Update image quay.io/ceph/ceph (v20.2.4 ➔ v21.1.0) - #4039
renovate[bot] wants to merge 1 commit into
Conversation
@@ spec.template.spec.containers.rook-ceph-tools.image @@
# apps/v1/Deployment/rook-ceph/rook-ceph-tools
! ± value change
- quay.io/ceph/ceph:v20.2.4@sha256:6bb1c8a42fbc0bf87938946990b65174466997bc11c31eb5a323225a779fd8f9
+ quay.io/ceph/ceph:v21.1.0@sha256:5ff3692d2f3f4bf47ca7717de6f8f8556440ce3e15efaa680b62cb924eec0541
@@ spec.cephVersion.image @@
# ceph.rook.io/v1/CephCluster/rook-ceph/rook-ceph
! ± value change
- quay.io/ceph/ceph:v20.2.4@sha256:6bb1c8a42fbc0bf87938946990b65174466997bc11c31eb5a323225a779fd8f9
+ quay.io/ceph/ceph:v21.1.0@sha256:5ff3692d2f3f4bf47ca7717de6f8f8556440ce3e15efaa680b62cb924eec0541
|
@@ spec.values.cephImage.tag @@
# helm.toolkit.fluxcd.io/v2/HelmRelease/rook-ceph/rook-ceph-cluster
! ± value change
- v20.2.4@sha256:6bb1c8a42fbc0bf87938946990b65174466997bc11c31eb5a323225a779fd8f9
+ v21.1.0@sha256:5ff3692d2f3f4bf47ca7717de6f8f8556440ce3e15efaa680b62cb924eec0541
|
AI Automated ReviewAnalysis engine: omniroute@http://litellm.ai.svc.cluster.local/v1 (openai) Recommendation: Hold this major Ceph image bump (v20.2.4 → v21.1.0) until compatibility with the pinned Rook chart and the custom Talos kernel is confirmed — the one-line diff is clean, but the surrounding evidence is not. Change-by-change: The only change is the Must-check items:
Release notes: Upstream Ceph v21.1.0 release notes were not fetched this run, so user-visible, breaking, and security changes are unverified. Note the repo's own history: the custom kernel was built specifically to unlock Tool Harness Findings: File reads confirmed the tag line and the chart pins ( Unknowns or Needs Verification:
Sources: repository files read this run ( |
fc8d017 to
5244c62
Compare
5244c62 to
6effea7
Compare
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
📝 WalkthroughWalkthroughThe Rook Ceph HelmRelease updates its pinned Ceph container image from v20.2.2 to v21.1.0, including the image digest. ChangesRook Ceph image update
Estimated code review effort: 1 (Trivial) | ~2 minutes Possibly related PRs
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
6effea7 to
f0052cb
Compare
f0052cb to
0b80f9d
Compare
|
|
Overall Grade |
Security Reliability Complexity Hygiene |
Code Review Summary
| Analyzer | Status | Updated (UTC) | Details |
|---|---|---|---|
| JavaScript | Sep 10, 2026 4:27p.m. | Review ↗ | |
| Shell | Sep 10, 2026 4:27p.m. | Review ↗ |
Important
AI Review is run only on demand for your team. We're only showing results of static analysis review right now. To trigger AI Review, comment @deepsourcebot review on this thread.
0b80f9d to
582eaf8
Compare
582eaf8 to
8727c18
Compare
cfc7704 to
ac036d9
Compare
ac036d9 to
67a287f
Compare
67a287f to
e1f69f3
Compare
|
Warning Your free Security trial is over. An organization admin can activate billing to continue. |
|
Holding. Two reasons, both independent of the reviewer findings:
Current state for the record: Rook chart The reviewer blockers asking for the Rook support matrix are directionally right, but the version naming in them is garbled (v21 is called Reef in one and Squid in another; v20 is Tentacle, v19 is Squid, Reef is v18). Revisit when |
e1f69f3 to
21699dc
Compare
The pin existed because the aes256k csi keyType needs librados 20.2.4, and chart v1.20.6 defaulted to cephcsi v3.17.0. v1.20.7 defaults to v3.17.1, the exact tag that was pinned, so the override now only restates the chart. Verified: `flate build hr` output is byte-identical with and without the override, and still resolves quay.io/cephcsi/cephcsi:v3.17.1. cephImage.repository also equals its chart default but stays: Renovate's helm-values manager needs it next to cephImage.tag to resolve the Ceph image, which is what #4039 tracks.
* fix(container): update rook-ceph (v1.20.6 ➔ v1.20.7) * refactor(rook-ceph): drop the cephcsi tag pin, v1.20.7 ships it The pin existed because the aes256k csi keyType needs librados 20.2.4, and chart v1.20.6 defaulted to cephcsi v3.17.0. v1.20.7 defaults to v3.17.1, the exact tag that was pinned, so the override now only restates the chart. Verified: `flate build hr` output is byte-identical with and without the override, and still resolves quay.io/cephcsi/cephcsi:v3.17.1. cephImage.repository also equals its chart default but stays: Renovate's helm-values manager needs it next to cephImage.tag to resolve the Ceph image, which is what #4039 tracks. --------- Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> Co-authored-by: Tanguille <91473554+Tanguille@users.noreply.github.com>
21699dc to
f0d267e
Compare
f0d267e to
2b83e1b
Compare
2b83e1b to
401cac7
Compare
605e32f to
f73f184
Compare
f73f184 to
c1488b1
Compare
| repository: quay.io/ceph/ceph | ||
| tag: v20.2.4@sha256:6bb1c8a42fbc0bf87938946990b65174466997bc11c31eb5a323225a779fd8f9 | ||
| tag: v21.1.0@sha256:5ff3692d2f3f4bf47ca7717de6f8f8556440ce3e15efaa680b62cb924eec0541 | ||
| cephClusterSpec: |
There was a problem hiding this comment.
Automated finding from AI PR review.
| repository: quay.io/ceph/ceph | ||
| tag: v20.2.4@sha256:6bb1c8a42fbc0bf87938946990b65174466997bc11c31eb5a323225a779fd8f9 | ||
| tag: v21.1.0@sha256:5ff3692d2f3f4bf47ca7717de6f8f8556440ce3e15efaa680b62cb924eec0541 | ||
| cephClusterSpec: |
There was a problem hiding this comment.
Info (question): v21.1.0 follows Ceph's RC-series numbering (x.1.z); confirm this is a stable release rather than a development build before pinning it with a digest.
Automated finding from AI PR review.
This PR contains the following updates:
v20.2.4→v21.1.0Configuration
📅 Schedule: (in timezone Europe/Brussels)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about these updates again.
This PR was generated by Mend Renovate. View the repository job log.