Commit Graph

14153 Commits

Author SHA1 Message Date
Jose Diaz-Gonzalez
87b240054f feat: add storage directory mode and removal flags
`storage:create` and `storage:set` accept a `--mode` flag that sets the octal permissions of a docker-local host directory, and `storage:destroy` accepts a `--destroy-host-dir` flag that removes the directory along with its contents. A docker-local entry also honors `--reclaim-policy Delete` at destroy time now, matching how that policy governs a k3s PersistentVolume. Both are limited to the default `/var/lib/dokku/data/storage/<name>` location, the same restriction `--chown` already carries. `storage:set` applies `--chown` and `--mode` to the directory rather than only recording them.
2026-08-10 01:23:10 -04:00
Jose Diaz-Gonzalez
39df6e3855 Merge pull request #8917 from dokku/8916-setting-app-label-alias-silently-disables-vector-log-collection
Apply app-label-alias to shipped events
2026-08-09 21:13:03 -04:00
Jose Diaz-Gonzalez
5b5d3d761b fix: apply app-label-alias to shipped events
The alias was only ever used to build the `include_labels` filter on the generated vector source, while dokku labels containers with `com.dokku.app-name` unconditionally. Setting the property therefore pointed the source at a label no container carries, and log collection stopped without any error. The source now always filters the label dokku applies, and a generated remap renames the field on its way to the sink, which is what the property was documented to do. An app whose own alias differs from the global one gets a branch in the global pipeline, so a per-app value is honored even when the app ships through the global sink.

Closes #8916.
2026-08-09 14:01:43 -04:00
Jose Diaz-Gonzalez
d767dd83f1 Merge pull request #8914 from dokku/feat/vector-cron-sink
Add vector-cron-sink for scheduled cron task output
2026-08-09 13:16:21 -04:00
Jose Diaz-Gonzalez
3edb5a3066 Merge pull request #8915 from dokku/chore/bump-herokuish-0.11.15
chore: bump herokuish to 0.11.15
2026-08-09 13:14:19 -04:00
Jose Diaz-Gonzalez
4a1bdc9bdf style: satisfy shfmt pipeline continuation formatting 2026-08-09 02:26:58 -04:00
Jose Diaz-Gonzalez
3d02d81562 fix: stop logs tests leaking a global app-label-alias
The `app-label-alias` test left the global property set, so every later test in the file generated a vector source filtering on a label that dokku never applies to a container, silently collecting nothing. Clearing it in teardown restores log collection for the rest of the file. The cron routing test now asserts against console sinks rather than files, since the sink an event reached is identifiable from vector's own output without depending on a writable host mount, and its task sleeps either side of its output because a cron container that exits immediately is removed before vector can attach to it.
2026-08-09 02:22:13 -04:00
Dokku Bot
8341c7cdcb chore: bump herokuish to 0.11.15 2026-08-09 06:15:51 +00:00
Dokku Bot
95f9d4f9b7 Release 0.38.26
# History

## 0.38.26

Install/update via the bootstrap script:

```shell
wget -NP . https://dokku.com/install/v0.38.26/bootstrap.sh
sudo DOKKU_TAG=v0.38.26 bash bootstrap.sh
```

### Bug Fixes

- #8906: @josegonzalez Match docker options by shell word when removing

### New Features

- #8911: @josegonzalez Route wildcard domains through traefik on k3s
- #8909: @josegonzalez Support manually managed cert issuers on k3s
- #8903: @josegonzalez Support kernel sysctls on the k3s scheduler
- #8856: @youdie006 Add pre-parsed port_mappings to ports:report json

### Refactors

- #8863: @josegonzalez Move host-crontab generation into cron plugin

### Documentation

- #8908: @josegonzalez Document --global on scheduler-k3s report and set
- #8858: @bakatz Added instructions for restoring backups on different CPU architectures.

### Tests

- #8893: @dependabot[bot] chore(deps): bump django from 5.2.16 to 5.2.17 in /tests/apps/dockerfile-release
- #8891: @dependabot[bot] chore(deps-dev): bump heroku/heroku-buildpack-php from 293 to 294 in /tests/apps/php
- #8877: @dependabot[bot] chore(deps): bump google.golang.org/grpc from 1.82.1 to 1.83.0 in /tests/apps/gogrpc
- #8874: @dependabot[bot] chore(deps): bump sass from 1.101.7 to 1.102.0 in /tests/apps/multi
- #8870: @dependabot[bot] chore(deps): bump sass from 1.101.6 to 1.101.7 in /tests/apps/multi
- #8866: @dependabot[bot] chore(deps): bump sass from 1.101.3 to 1.101.6 in /tests/apps/multi
- #8860: @dependabot[bot] chore(deps): bump setuptools from 78.1.1 to 83.0.0 in /tests/apps/dockerfile-release
- #8859: @dependabot[bot] chore(deps): bump immutable from 5.1.5 to 5.1.9 in /tests/apps/multi
- #8855: @dependabot[bot] chore(deps): bump sass from 1.101.0 to 1.101.3 in /tests/apps/multi
- #8857: @dependabot[bot] chore(deps): bump body-parser from 2.2.1 to 2.3.0 in /tests/apps/checks-root
- #8853: @dependabot[bot] chore(deps): bump python from 3.15.0b3-bookworm to 3.15.0b4-bookworm in /tests/apps/dockerfile-release

### Dependencies

- #8905: @dependabot[bot] chore(deps): bump oras.land/oras-go/v2 from 2.6.1 to 2.6.2 in /plugins/scheduler-k3s
- #8869: @dependabot[bot] chore(deps): bump github.com/mattn/go-isatty from 0.0.23 to 0.0.24 in /plugins/app-json
- #8887: @dependabot[bot] chore(deps): bump github.com/kedacore/keda/v2 from 2.20.1 to 2.20.2 in /plugins/scheduler-k3s
- #8883: @dokku-bot chore: bump docker-container-healthchecker to 0.16.0
- #8886: @dependabot[bot] chore(deps): update markdown requirement from <3.11,>=3.10.2 to >=3.10.3,<3.11 in /docs/_build
- #8892: @dependabot[bot] chore(deps): bump traefik from v3.7.9 to v3.7.10 in /plugins/traefik-vhosts
- #8885: @dokku-bot chore: bump dokku-update to 0.10.0
- #8884: @dokku-bot chore: bump procfile-util to 0.20.8
- #8882: @dokku-bot chore: bump docker-image-labeler to 0.10.0
- #8888: @dependabot[bot] chore(deps): bump github.com/traefik/traefik/v2 from 2.11.53 to 2.11.54 in /plugins/scheduler-k3s
- #8900: @dokku-bot chore: bump gliderlabs-sigil to 0.12.1
- #8899: @dokku-bot chore: bump herokuish to 0.11.14
- #8898: @dokku-bot chore: bump netrc to 0.11.1
- #8897: @dokku-bot chore: bump dokku-event-listener to 0.20.1
- #8896: @dokku-bot chore: bump sshcommand to 0.20.2
- #8895: @dokku-bot chore: bump lambda-builder to 0.9.4
- #8894: @dokku-bot chore: bump plugn to 0.17.1
- #8876: @dependabot[bot] chore(deps): bump github.com/cert-manager/cert-manager from 1.21.0 to 1.21.1 in /plugins/scheduler-k3s
- #8873: @dependabot[bot] chore(deps): bump traefik from v3.7.8 to v3.7.9 in /plugins/traefik-vhosts
- #8872: @dependabot[bot] chore(deps): bump github.com/traefik/traefik/v2 from 2.11.52 to 2.11.53 in /plugins/scheduler-k3s
- #8871: @dependabot[bot] chore(deps): bump k8s.io/kubernetes from 1.36.2 to 1.36.3 in /plugins/scheduler-k3s
- #8868: @dependabot[bot] chore(deps): bump k8s.io/kubectl from 0.36.2 to 0.36.3 in /plugins/scheduler-k3s
- #8867: @dependabot[bot] chore(deps): bump k8s.io/client-go from 0.36.2 to 0.36.3 in /plugins/scheduler-k3s
- #8865: @dependabot[bot] chore(deps): bump github.com/fluxcd/pkg/kustomize from 1.38.0 to 1.39.0 in /plugins/scheduler-k3s
- #8864: @dependabot[bot] chore(deps): bump soupsieve from 2.9 to 2.9.1 in /docs/_build
- #8854: @dependabot[bot] chore(deps): bump python from 3.15.0b3-alpine to 3.15.0b4-alpine in /docs/_build
- #8852: @dependabot[bot] chore(deps): bump soupsieve from 2.8.4 to 2.9 in /docs/_build
- #8851: @dependabot[bot] chore(deps): bump mkdocs-material from 9.7.6 to 9.7.7 in /docs/_build
- #8850: @dependabot[bot] chore(deps): bump actions/setup-python from 6 to 7

### Other

- #8907: @josegonzalez fix: migrate env files before reading deprecated vars
- #8881: @josegonzalez Ignore minor and patch updates for github actions
v0.38.26
2026-08-09 05:57:36 +00:00
Jose Diaz-Gonzalez
52b26a3760 feat: add vector-cron-sink for scheduled cron task output
Scheduled cron task output previously reached only the `dokku` user's cron mail, and could not be redirected because `app.json` rejects bare shell operators in a cron `command`. Setting `vector-cron-sink` on an app or globally routes that output to a dedicated sink instead, on both the `docker-local` and `k3s` schedulers, which keeps log destinations under operator control rather than in a deployed repository. Cron events carry `dokku_app` and `dokku_cron_id` fields so a sink can give each task its own destination. This also fixes a `k3s` bug where configuring a global `vector-sink` silently removed the vector prometheus exporter sink.
2026-08-09 01:10:21 -04:00
Jose Diaz-Gonzalez
047be485a2 Merge pull request #8911 from dokku/8910-k3s-scheduler-traefik-ingress-cannot-route-wildcard-domains
Route wildcard domains through traefik on k3s
2026-08-08 22:44:38 -04:00
Jose Diaz-Gonzalez
bb7335f88e feat: route wildcard domains through traefik on k3s
Traefik matches hosts exactly, so an app serving a wildcard domain under the `traefik` ingress class had a valid certificate but silently 404d on every request. Wildcard domains now render as a `HostRegexp` rule that matches a single label, the same semantics as a Kubernetes wildcard host, so both ingress classes behave the same. Those routes carry an explicit low priority so an exact domain on any app still wins over another app's wildcard, mirroring ingress-nginx.
2026-08-08 19:15:10 -04:00
Jose Diaz-Gonzalez
6c823e3b8a Merge pull request #8909 from dokku/8901-k3s-scheduler-custom-cert-issuer-name
Support manually managed cert issuers on k3s
2026-08-08 18:36:34 -04:00
Jose Diaz-Gonzalez
d134e75371 feat: support manually managed cert issuers on k3s
The `cert-issuer-name` and `cert-issuer-kind` properties point an app's generated `Certificate` at a cert-manager issuer created outside of Dokku, allowing certificates to be issued through solvers the built-in letsencrypt integration cannot use, such as `dns01` for wildcard certificates. Setting an issuer enables https on its own, as a manually managed issuer has no email for Dokku to configure. An imported certificate still takes precedence, and `letsencrypt-server false` remains the single off switch. Dokku warns before a build starts when the referenced issuer is absent from the cluster, without blocking the deploy. Wildcard domains no longer collide with their apex domain when generating ingress names, and `letsencrypt-server` values are now validated when set rather than at deploy time.
2026-08-08 15:16:12 -04:00
Jose Diaz-Gonzalez
2da48f4f86 Merge pull request #8908 from dokku/8861-scheduler-k3s-report-and-scheduler-k3s-set-help-omits-the-global-option
Document --global on scheduler-k3s report and set
2026-08-08 01:47:48 -04:00
Jose Diaz-Gonzalez
66bcfbd1ed fix: document --global on scheduler-k3s report and set
The usage strings for `scheduler-k3s:report` and `scheduler-k3s:set` omitted the `--global` option, which is the only way to reach the scheduler-wide report since a bare `scheduler-k3s:report` iterates every app, and `:report` also omitted `--format stdout|json`. The command listing in the k3s documentation is resynced with the help output, which additionally restores flags that had been dropped from `scheduler-k3s:cluster:add`, `scheduler-k3s:cluster:list`, and `scheduler-k3s:initialize`.
2026-08-08 01:43:40 -04:00
Jose Diaz-Gonzalez
e82a21a43a Merge pull request #8907 from dokku/8875-0-38-migration-plugins-ordered-before-config-silently-fail-to-migrate-their-dokku-config-vars
fix: migrate env files before reading deprecated vars
2026-08-08 01:17:34 -04:00
Jose Diaz-Gonzalez
e24859bfe6 test: stage the migration marker through the trigger
The hand-written marker file was created as root, which the config-migrate-env
trigger could not overwrite when it ran under a different user. Draining once up
front records the migration through the same code path the assertion exercises.
2026-08-07 17:56:15 -04:00
Jose Diaz-Gonzalez
70dc921967 fix: migrate env files before reading deprecated vars
Install steps run in alphabetical order of the enabled plugin directory, so `apps`, `builder`, and `checks` read an app's environment before the `config` plugin had moved the `ENV` file to its new location. The read came back empty, so their deprecated `DOKKU_*` variables were never migrated to the matching plugin property and were never unset, with nothing reported either way: `dokku config:show` kept listing the variable while the plugin behaved as though it were unset. The relocation now runs before any deprecated variable is read, whatever the install order, and each old file is removed as soon as it has been drained rather than on a later install, which also covers the global file that was never removed at all. A file that reappears at the old path can only have been written by hand, so it is merged in with a warning naming its keys instead of being discarded.
2026-08-07 16:43:56 -04:00
Jose Diaz-Gonzalez
2527d57dfc Merge pull request #8905 from dokku/dependabot/go_modules/plugins/scheduler-k3s/oras.land/oras-go/v2-2.6.2
chore(deps): bump oras.land/oras-go/v2 from 2.6.1 to 2.6.2 in /plugins/scheduler-k3s
2026-08-07 16:14:55 -04:00
Jose Diaz-Gonzalez
eedcb90e29 Merge pull request #8906 from dokku/8904-docker-options-remove-silently-no-ops-for-options-migrated-from-pre-0-38-25-docker-options-files
Match docker options by shell word when removing
2026-08-07 15:38:41 -04:00
Jose Diaz-Gonzalez
8d4e7d9793 fix: match docker options by shell word when removing
Options drained out of the pre-0.38.0 `DOCKER_OPTIONS_<PHASE>` files were copied verbatim rather than re-serialized the way `docker-options:add` stores them, so `docker-options:remove` compared the canonical string it builds against a stored value that could never match it and exited successfully without removing anything. Removal now matches stored options by shell word, and stored options are rewritten into the canonical form once on upgrade, which additionally splits an entry that carried several flags on a single line into one entry per flag so a single flag can be removed and so the readers that match on a flag prefix see one value per entry. The leftover `.migrated` sentinel drain is restored to running ahead of the global short-circuit that had made it unreachable, and the plugin's Go tests are added to the test target that had never run them.
2026-08-07 13:35:37 -04:00
Jose Diaz-Gonzalez
30a72f8d95 Merge pull request #8863 from dokku/8862-move-host-crontab-generation-into-the-cron-plugin
Move host-crontab generation into cron plugin
2026-08-07 12:36:40 -04:00
Jose Diaz-Gonzalez
da085c5ebb Merge branch 'master' into 8862-move-host-crontab-generation-into-the-cron-plugin 2026-08-07 12:36:32 -04:00
Jose Diaz-Gonzalez
e9b03e3dd2 Merge pull request #8869 from dokku/dependabot/go_modules/plugins/app-json/github.com/mattn/go-isatty-0.0.24
chore(deps): bump github.com/mattn/go-isatty from 0.0.23 to 0.0.24 in /plugins/app-json
2026-08-07 12:34:25 -04:00
Jose Diaz-Gonzalez
5895c51a4e Merge pull request #8887 from dokku/dependabot/go_modules/plugins/scheduler-k3s/github.com/kedacore/keda/v2-2.20.2
chore(deps): bump github.com/kedacore/keda/v2 from 2.20.1 to 2.20.2 in /plugins/scheduler-k3s
2026-08-07 12:33:51 -04:00
Jose Diaz-Gonzalez
aaa00a4934 Merge pull request #8883 from dokku/chore/bump-docker-container-healthchecker-0.16.0
chore: bump docker-container-healthchecker to 0.16.0
2026-08-07 12:33:44 -04:00
Jose Diaz-Gonzalez
20d6b57355 Merge pull request #8886 from dokku/dependabot/pip/docs/_build/markdown-gte-3.10.3-and-lt-3.11
chore(deps): update markdown requirement from <3.11,>=3.10.2 to >=3.10.3,<3.11 in /docs/_build
2026-08-07 12:28:08 -04:00
Jose Diaz-Gonzalez
5e12f638f4 Merge pull request #8892 from dokku/dependabot/docker/plugins/traefik-vhosts/traefik-v3.7.10
chore(deps): bump traefik from v3.7.9 to v3.7.10 in /plugins/traefik-vhosts
2026-08-07 12:27:06 -04:00
Jose Diaz-Gonzalez
6f867485f1 Merge pull request #8893 from dokku/dependabot/pip/tests/apps/dockerfile-release/django-5.2.17
chore(deps): bump django from 5.2.16 to 5.2.17 in /tests/apps/dockerfile-release
2026-08-07 12:26:39 -04:00
Jose Diaz-Gonzalez
e990d8dbfc Merge pull request #8885 from dokku/chore/bump-dokku-update-0.10.0
chore: bump dokku-update to 0.10.0
2026-08-07 12:25:33 -04:00
Jose Diaz-Gonzalez
9529ca8a3f Merge pull request #8884 from dokku/chore/bump-procfile-util-0.20.8
chore: bump procfile-util to 0.20.8
2026-08-07 12:25:25 -04:00
dependabot[bot]
daee1e6c68 chore(deps): bump github.com/kedacore/keda/v2 in /plugins/scheduler-k3s
Bumps [github.com/kedacore/keda/v2](https://github.com/kedacore/keda) from 2.20.1 to 2.20.2.
- [Release notes](https://github.com/kedacore/keda/releases)
- [Changelog](https://github.com/kedacore/keda/blob/main/CHANGELOG.md)
- [Commits](https://github.com/kedacore/keda/compare/v2.20.1...v2.20.2)

---
updated-dependencies:
- dependency-name: github.com/kedacore/keda/v2
  dependency-version: 2.20.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-08-07 16:25:18 +00:00
dependabot[bot]
6da020a65c chore(deps): bump oras.land/oras-go/v2 in /plugins/scheduler-k3s
Bumps [oras.land/oras-go/v2](https://github.com/oras-project/oras-go) from 2.6.1 to 2.6.2.
- [Release notes](https://github.com/oras-project/oras-go/releases)
- [Changelog](https://github.com/oras-project/oras-go/blob/main/RELEASES.md)
- [Commits](https://github.com/oras-project/oras-go/compare/v2.6.1...v2.6.2)

---
updated-dependencies:
- dependency-name: oras.land/oras-go/v2
  dependency-version: 2.6.2
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-08-07 16:25:07 +00:00
Jose Diaz-Gonzalez
973595e0f2 Merge pull request #8882 from dokku/chore/bump-docker-image-labeler-0.10.0
chore: bump docker-image-labeler to 0.10.0
2026-08-07 12:25:04 -04:00
Jose Diaz-Gonzalez
409d364e81 Merge pull request #8891 from dokku/dependabot/composer/tests/apps/php/heroku/heroku-buildpack-php-294
chore(deps-dev): bump heroku/heroku-buildpack-php from 293 to 294 in /tests/apps/php
2026-08-07 12:24:43 -04:00
Jose Diaz-Gonzalez
b37192a847 Merge pull request #8903 from dokku/scheduler-k3s-sysctls
feat: support kernel sysctls on the k3s scheduler
2026-08-07 12:24:22 -04:00
Jose Diaz-Gonzalez
2ed9294b6b Merge pull request #8888 from dokku/dependabot/go_modules/plugins/scheduler-k3s/github.com/traefik/traefik/v2-2.11.54
chore(deps): bump github.com/traefik/traefik/v2 from 2.11.53 to 2.11.54 in /plugins/scheduler-k3s
2026-08-07 12:22:44 -04:00
Jose Diaz-Gonzalez
2adb01f8c6 Merge pull request #8900 from dokku/chore/bump-gliderlabs-sigil-0.12.1
chore: bump gliderlabs-sigil to 0.12.1
2026-08-07 12:21:49 -04:00
Jose Diaz-Gonzalez
6f4117529a Merge pull request #8899 from dokku/chore/bump-herokuish-0.11.14
chore: bump herokuish to 0.11.14
2026-08-07 12:21:41 -04:00
Jose Diaz-Gonzalez
5741667d16 Merge pull request #8898 from dokku/chore/bump-netrc-0.11.1
chore: bump netrc to 0.11.1
2026-08-07 12:21:33 -04:00
Jose Diaz-Gonzalez
d0d1fc019c Merge pull request #8897 from dokku/chore/bump-dokku-event-listener-0.20.1
chore: bump dokku-event-listener to 0.20.1
2026-08-07 12:21:25 -04:00
Jose Diaz-Gonzalez
9c894401c8 Merge pull request #8896 from dokku/chore/bump-sshcommand-0.20.2
chore: bump sshcommand to 0.20.2
2026-08-07 12:21:16 -04:00
Jose Diaz-Gonzalez
69cff6a6b1 Merge pull request #8895 from dokku/chore/bump-lambda-builder-0.9.4
chore: bump lambda-builder to 0.9.4
2026-08-07 12:21:04 -04:00
Jose Diaz-Gonzalez
ea5e08754d Merge pull request #8894 from dokku/chore/bump-plugn-0.17.1
chore: bump plugn to 0.17.1
2026-08-07 12:20:56 -04:00
Jose Diaz-Gonzalez
44cd566178 feat: manage node-level kernel sysctls on the k3s scheduler
Sysctls the kernel does not namespace, such as `vm.max_map_count`, cannot be set from a pod spec and previously had no answer beyond editing `/etc/sysctl.d` on each host by hand. `scheduler-k3s:node-sysctls:set` now applies them through a privileged daemonset, which reaches nodes joined later and reapplies after a reboot. Sysctls may be scoped to a node profile, with a profile scope inheriting the global values and overriding them on conflict so that every node is covered by exactly one daemonset. Clearing a sysctl stops dokku managing it but does not restore the previous value, which persists until the node reboots.
2026-08-07 09:10:00 -04:00
Jose Diaz-Gonzalez
cd1089500b feat: translate docker-options --sysctl on the k3s scheduler
The `docker-local` scheduler supports `--sysctl` for free because docker options are passed verbatim to `docker run`, but the k3s scheduler silently dropped it. Namespaced sysctls now render into the pod's `securityContext.sysctls` for deployments, cron jobs, and one-off runs. A sysctl the kernel does not namespace fails the deploy instead of being dropped, since it cannot take effect within a pod regardless of what was requested.
2026-08-07 05:43:00 -04:00
Jose Diaz-Gonzalez
f050726f1a feat: label nodes with the node profile they joined with
Node profiles controlled how a node joined the cluster but left no trace on the node afterwards, so a profile could not be selected against with `kubectl`, a `nodeSelector`, or a node affinity rule. Nodes joined without a profile are left unlabeled, and the server node created by `scheduler-k3s:initialize` never carries the label since it does not pass through `scheduler-k3s:cluster:add`.
2026-08-07 02:32:34 -04:00
Jose Diaz-Gonzalez
8e17eee653 feat: add --kubelet-args to scheduler-k3s:initialize
The server node created by `scheduler-k3s:initialize` had no way to receive kubelet arguments, unlike nodes joined through `scheduler-k3s:cluster:add` or configured via `scheduler-k3s:profiles:add`. This meant settings such as `allowed-unsafe-sysctls` were unreachable on a single-node install.
2026-08-07 02:31:12 -04:00
Dokku Bot
bfbfdd3d9e chore: bump gliderlabs-sigil to 0.12.1 2026-08-06 06:55:18 +00:00