Commit Graph

13449 Commits

Author SHA1 Message Date
Jose Diaz-Gonzalez
99855ae9f8 fix: correct issue with cancel 2026-04-29 13:48:50 -04:00
Jose Diaz-Gonzalez
0c08aefc54 feat: implement build tracking
The DOKKU_PID now never gets overwritten except in the case that DOKKU is executed by the sudo user. If the command ends up executing a deploy, then the pid of the `dokku` owned process - which may have been executed via sudo - will be written to the file lock, allowing future commands to interact with the original process.

Additionally, the new builds plugin can be used to handle killing a build.
2026-04-29 13:48:50 -04:00
Jose Diaz-Gonzalez
4257c17eab Merge pull request #8533 from dokku/8531-split-out-imagepullsecrets-and-config-env-into-separate-helm-charts
Split env config and image pull secret into separate helm releases
2026-04-29 13:48:08 -04:00
Jose Diaz-Gonzalez
3a6ae559c4 Merge pull request #8530 from dokku/8010-docker-options-cleaning-up-arguments
Split multi-flag input in docker-options
2026-04-29 13:16:37 -04:00
Jose Diaz-Gonzalez
507df612e8 fix: tidy go.sum for plugins importing docker-options 2026-04-29 13:16:18 -04:00
Jose Diaz-Gonzalez
55d7487d66 fix: split multi-flag input in docker-options
Multi-flag inputs (e.g. `--build-arg X=Y --link a --link b`) used to be stored as a single line, which bypassed the per-line filter that drops `--link` and similar flags for dockerfile-based builders. Each `--flag [value]` group is now stored as its own entry, and a `--process` typed after the app name is lifted into the subcommand flag instead of being stored as a docker option.
2026-04-29 13:15:51 -04:00
Jose Diaz-Gonzalez
7ba453e588 fix: thread secret annotations and labels through new helm charts
The new config and pull secret helm releases need to honor user-set annotations and labels for `--resource-type secret` so existing scheduler-k3s annotation tests keep passing. The dedicated charts now render `.Values.global.annotations` and `.Values.global.labels` onto their Secret manifest, and the deploy trigger plumbs `SecretAnnotations` and `SecretLabels` from the global annotation/label config. The rollback regression bats test now uses `dokku ps:rebuild` for its second deploy because git push of an unchanged ref is rejected by the dokku remote.
2026-04-29 12:18:06 -04:00
Jose Diaz-Gonzalez
ef9bdc0379 fix: split env config and image pull secret into separate helm releases
Bundling these Secrets in the app helm chart caused two bugs in the scheduler-k3s plugin: a chart rollback could delete Secrets that older ReplicaSets still referenced by exact timestamped name (`env-{app}.{ts}` and `ims-{app}.{ts}`), hard-crashing pods until manual intervention; and the strategic-merge `patchMergeKey` on `imagePullSecrets` let stale entries leak into the live Deployment until the list pointed at many nonexistent Secrets. Each Secret now lives in its own helm release with a stable name (`config-{app}` and `pull-secret-{app}`), installed before the app chart on every deploy. The deployment trigger also prunes any leaked `imagePullSecrets` entries from the live Deployment so the next deploy lands on a clean list, and the rename and destroy paths uninstall the new releases (and the previously-leaked TLS release on rename) under the old app name.
2026-04-29 12:18:03 -04:00
Jose Diaz-Gonzalez
f06048a266 Merge pull request #8535 from dokku/dependabot/go_modules/plugins/common/github.com/onsi/gomega-1.40.0
chore(deps): bump github.com/onsi/gomega from 1.39.1 to 1.40.0 in /plugins/common
2026-04-29 12:17:08 -04:00
Jose Diaz-Gonzalez
579481e76b chore: bump go modules 2026-04-29 12:16:58 -04:00
dependabot[bot]
2f1268172b chore(deps): bump github.com/onsi/gomega in /plugins/common
Bumps [github.com/onsi/gomega](https://github.com/onsi/gomega) from 1.39.1 to 1.40.0.
- [Release notes](https://github.com/onsi/gomega/releases)
- [Changelog](https://github.com/onsi/gomega/blob/master/CHANGELOG.md)
- [Commits](https://github.com/onsi/gomega/compare/v1.39.1...v1.40.0)

---
updated-dependencies:
- dependency-name: github.com/onsi/gomega
  dependency-version: 1.40.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-04-29 12:16:18 -04:00
Jose Diaz-Gonzalez
abb7faa503 Merge pull request #8527 from dokku/8500-allow-format-json-with-global-on-report-subcommands
Accept --global on :report subcommands
2026-04-29 12:14:54 -04:00
Jose Diaz-Gonzalez
1a45fef839 Merge pull request #8523 from dokku/3826-extending-resource-management-to-include-build-containers
Support resource limits on the build container
2026-04-29 10:45:16 -04:00
Jose Diaz-Gonzalez
0f78f81d71 test: drop cron:set in cron:report --global test
The set step relied on scheduler-cron-write accepting `--global` as the appName, which the scheduler-k3s plugin trigger does not.
2026-04-29 10:31:02 -04:00
Jose Diaz-Gonzalez
b28e4e552b test: align git:report --global assertion with rendered key 2026-04-29 10:31:01 -04:00
Jose Diaz-Gonzalez
8282981361 feat: accept --global on :report subcommands
Every `:report` subcommand now recognizes `--global` as a scope selector that limits the report to globally-configured properties, including in JSON form via `--global --format json`. Previously this combination was rejected because `--global` was treated as an info flag, conflicting with `--format`. The shared `common.ParseReportArgs` helper now returns a `ReportArgs` struct exposing the parsed scope; each Go and bash report selects a global-only flag map when scope is global, and skips per-app verification.
2026-04-29 10:30:59 -04:00
Jose Diaz-Gonzalez
ec70e10c5d Merge pull request #8528 from dokku/6998-dokku-ps-retire-or-cron-job-trying-to-retire-running-app
Skip retiring images still in use by app containers
2026-04-29 10:28:18 -04:00
Jose Diaz-Gonzalez
63958b99ef Merge pull request #8537 from dokku/dependabot/go_modules/plugins/scheduler-k3s/github.com/traefik/traefik/v2-2.11.44
chore(deps): bump github.com/traefik/traefik/v2 from 2.11.43 to 2.11.44 in /plugins/scheduler-k3s
2026-04-29 10:26:16 -04:00
dependabot[bot]
3267cb2ac8 chore(deps): bump github.com/traefik/traefik/v2
Bumps [github.com/traefik/traefik/v2](https://github.com/traefik/traefik) from 2.11.43 to 2.11.44.
- [Release notes](https://github.com/traefik/traefik/releases)
- [Changelog](https://github.com/traefik/traefik/blob/v2.11.44/CHANGELOG.md)
- [Commits](https://github.com/traefik/traefik/compare/v2.11.43...v2.11.44)

---
updated-dependencies:
- dependency-name: github.com/traefik/traefik/v2
  dependency-version: 2.11.44
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-04-29 14:24:21 +00:00
Jose Diaz-Gonzalez
cf5807c157 Merge pull request #8529 from dokku/fix-netrc-bug
chore: bump dokku/netrc to v0.11.0
2026-04-29 09:02:22 -04:00
Jose Diaz-Gonzalez
73238b7c97 Merge pull request #8524 from dokku/7827-pre-validate-the-nginx-conf-prior-to-starting-a-deploy
Pre-validate custom nginx.conf.sigil during core-post-extract
2026-04-29 08:47:56 -04:00
Jose Diaz-Gonzalez
ab804c678a test: assert dead-images grep result instead of count
The previous assertion piped grep -c through `|| echo 0`, which printed an extra `0` when the file existed without matches because grep -c emits the count of `0` and exits 1, triggering the fallback.
2026-04-29 08:19:54 -04:00
Jose Diaz-Gonzalez
40b8b25ad4 Merge pull request #8525 from dokku/8242-cron-run-and-dokku-run-fail-on-cnb-pack-images-since-0-37-fix
Add launcher entrypoint for CNB images on dokku run and cron:run
2026-04-29 08:15:24 -04:00
Jose Diaz-Gonzalez
7791a26e98 test: pass plugin and dokku root paths to plugn invocations 2026-04-29 08:11:47 -04:00
Jose Diaz-Gonzalez
f4a1559edc chore: bump dokku/netrc to v0.11.0
The `git:auth` test in `tests/unit/git_3.bats` verifies the written entry with `netrc get --netrc-file ${DOKKU_ROOT}/.netrc github.com`, but the `--netrc-file` flag was added in netrc v0.11.0 and CI was still pinned to v0.10.3, so the assertion ran against root's `~/.netrc` and exited 1.
2026-04-29 06:09:07 -04:00
Jose Diaz-Gonzalez
3a7d74cdaa fix: ensure leading space when injecting --entrypoint launcher
The trigger output started with `--entrypoint` and relied on the caller
to provide a trailing space. `scheduler-deploy-process-container` does
that, but `scheduler-run` does not when `DOKKU_TRACE` is unset, so the
flag concatenated onto the previous arg as `--env=KEY--entrypoint`,
leaving `launcher` as the image positional argument and causing
`docker container create` to fail with `Unable to find image 'launcher:latest'`.
Match the leading-space convention used by the other docker-args triggers
(`config/docker-args-run`, `builder-herokuish/docker-args-run`).
2026-04-29 05:48:43 -04:00
Jose Diaz-Gonzalez
effa9d37cf fix: add launcher entrypoint for CNB images on dokku run and cron:run
The scheduler-run script classified CNB-based images as `herokuish` because
`is_image_herokuish_based` returns true for them, which caused the
`docker-args-process-run` trigger for builder-pack to skip injecting
`--entrypoint launcher`. Without that flag the container fell back to the
image entrypoint (`/cnb/process/web`) and dropped the user-supplied
arguments. Mirror the deploy-side detection so CNB images set
`IMAGE_SOURCE_TYPE=pack`, allowing the launcher entrypoint to be added.
2026-04-29 05:39:56 -04:00
Jose Diaz-Gonzalez
d88e8f137f fix: skip retiring images still in use by app containers
When ps:rebuild runs against an image-based deploy via git:from-image, the resulting image often shares the same SHA as the previous deployment, so retiring the old container's image would target the live image of the new container. The retirement is now skipped when another running container of the same app still references the image, and the cron retire loop self-heals previously stuck entries the next time it encounters them.
2026-04-29 05:36:04 -04:00
Jose Diaz-Gonzalez
ec7841a07b fix: inject placeholder listener for pre-validation upstream blocks
When pre-validating a custom nginx.conf.sigil before the build phase, no app listeners exist yet on first deploys. Templates that emit `proxy_pass http://app-port` while gating the matching upstream block on `DOKKU_APP_WEB_LISTENERS` render an undefined upstream, causing `nginx -t` to fail with "host not found in upstream". Pre-validation now passes a `127.0.0.1:5000` placeholder for `DOKKU_APP_WEB_LISTENERS` so the upstream block emits a static server entry and the template can be validated for syntax without depending on live listeners.
2026-04-29 05:12:05 -04:00
Jose Diaz-Gonzalez
63b809f64c feat: pre-validate custom nginx.conf.sigil during core-post-extract
Renders the user-supplied nginx.conf.sigil via sigil into a tmp file and runs `nginx -t` against a wrapped copy as soon as the template is extracted from the source tree, so syntactically invalid templates abort the deploy before the build phase runs. Skipped when `proxy-type` is not `nginx`, when `disable-custom-config=true`, or when no custom template was extracted. Closes #7827.
2026-04-29 05:01:25 -04:00
Jose Diaz-Gonzalez
1812cfbdeb test: export PLUGIN_PATH when invoking plugn trigger in subshells 2026-04-29 05:00:53 -04:00
Jose Diaz-Gonzalez
9b6c32f39c Merge pull request #8516 from dokku/2441-process-scoped-docker-options
Scope docker-options to specific procfile processes
2026-04-29 04:45:23 -04:00
Jose Diaz-Gonzalez
132f724841 feat: support resource limits on the build container
Adds a `docker-args-process-build` trigger to the resource plugin so
limits set via `dokku resource:limit --process-type build APP` are
applied during the build phase. Only `build.limit.*` properties are
read - defaults do not inherit, since builds typically need more memory
than runtime and a leaked tiny default would cause confusing OOM
failures. Reservations are never applied at build time. Allowed flags
are filtered per builder: herokuish gets cpu, memory, memory-swap, and
nvidia-gpu; dockerfile gets memory and memory-swap; pack, nixpacks,
railpack, lambda, and null emit nothing because their underlying CLIs
do not accept docker run resource flags. The dockerfile builder
whitelists the new memory flags and corrects pre-existing typos where
`--ssh` mapped to `--platform` and `--ulimit` mapped to `--tag`.
2026-04-29 03:42:10 -04:00
Jose Diaz-Gonzalez
9a795fcf91 test: cover migration via go unit test
The bats test for migration idempotency invoked the install binary directly via sudo, which kept hitting fresh missing env vars on each iteration (DOKKU_LIB_ROOT, then PLUGIN_PATH, etc). The dokku launcher script exports a chain of vars that the install path reads via common.MustGetEnv, and mirroring that chain in a bats test is fragile. Migration is pure file IO plus a property marker - perfect for a Go unit test that isolates itself with t.TempDir and t.Setenv. The new test covers parsing comments and blank lines, the marker-based no-op on re-run, and the rule that a manually re-created legacy file is left untouched after the marker is set.
2026-04-29 03:14:17 -04:00
Jose Diaz-Gonzalez
d1213c14a8 test: relax default-scope assertions and pass env to install
The ps plugin auto-adds --restart=on-failure:10 to the default deploy scope on app create, so docker-options:list --phase deploy is never empty for a freshly-created app. Switch the default-scope assertions from exact-match to contains/not-contains so the auto-injected restart line stops causing false failures. The migration test invoked the install binary directly via sudo, but DOKKU_LIB_ROOT is normally exported by the dokku launcher script and isn't set in that subprocess; pass it (and DOKKU_ROOT) explicitly.
2026-04-29 02:34:30 -04:00
Jose Diaz-Gonzalez
d51726b7cb Merge pull request #8522 from dokku/fix-keda-scaling
Only emit keda fallback when a non-cpu/memory trigger exists
2026-04-29 02:27:03 -04:00
Jose Diaz-Gonzalez
177eac4ef1 Merge pull request #8517 from dokku/6833-send-sigterm-immediately-to-old-containers-when-deploying-via-docker-local
Send SIGTERM to old containers immediately on deploy
2026-04-29 01:50:35 -04:00
Jose Diaz-Gonzalez
f728fc8cd7 fix: only emit keda fallback when a non-cpu/memory trigger exists
Keda 2.17+ rejects ScaledObjects whose spec.fallback is set unless at least one trigger is not a cpu or memory scaler, so unconditionally emitting fallback broke deploys for apps autoscaled on cpu or memory alone. The chart now skips the fallback block when every configured trigger is cpu or memory and keeps the existing behavior otherwise.
2026-04-29 01:10:34 -04:00
Jose Diaz-Gonzalez
8a6c853ccd Merge pull request #8515 from dokku/fix-vector-data-dir
Fix vector mount directory config
2026-04-29 00:36:40 -04:00
Jose Diaz-Gonzalez
97b86707e7 fix: docker-options:list flag parsing and ci test fixes
The :list subcommand had `SetInterspersed(false)` which forced flags to come before positional arguments; in practice users invoke it as `docker-options:list <app> --process X --phase Y`. Drop the non-interspersed setting so flags can appear after the app name. Two existing buildpacks/dockerfile tests appended directly to the legacy `DOCKER_OPTIONS_DEPLOY` file - that path is no longer the source of truth, so switch them to `docker-options:add`. The new migration test invoked `dokku plugin:trigger install` which fans out to every plugin and trips on unrelated permission errors; call the docker-options install binary directly instead. Tighten the report and JSON assertions to match the actual output format (`.` becomes a space in the display key, and JSON values may concatenate options).
2026-04-29 00:35:26 -04:00
Jose Diaz-Gonzalez
c424cb06c2 Merge pull request #8520 from dokku/dependabot/pip/docs/_build/packaging-26.2
chore(deps): bump packaging from 26.1 to 26.2 in /docs/_build
2026-04-29 00:28:22 -04:00
dependabot[bot]
32c997e4a7 chore(deps): bump packaging from 26.1 to 26.2 in /docs/_build
Bumps [packaging](https://github.com/pypa/packaging) from 26.1 to 26.2.
- [Release notes](https://github.com/pypa/packaging/releases)
- [Changelog](https://github.com/pypa/packaging/blob/main/CHANGELOG.rst)
- [Commits](https://github.com/pypa/packaging/compare/26.1...26.2)

---
updated-dependencies:
- dependency-name: packaging
  dependency-version: '26.2'
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-04-28 13:54:14 +00:00
Jose Diaz-Gonzalez
1161dda05e feat: send SIGTERM to old containers immediately on deploy
The docker-local scheduler now sends `SIGTERM` to old containers immediately after a successful deploy via `docker container kill --signal=SIGTERM`, rather than waiting `wait-to-retire` seconds before signaling. This matches Heroku's graceful-shutdown contract and lets applications begin draining in-flight work as soon as proxy traffic switches. The existing `wait-to-retire` grace period and `stop-timeout-seconds` hard-stop continue to apply unchanged as the authoritative cleanup path.
2026-04-27 18:18:39 -04:00
Jose Diaz-Gonzalez
9c8d5f54fb feat: scope docker-options to specific procfile processes
Adds a `--process` flag (repeatable) to docker-options:add/remove/clear/list and the new docker-options:list subcommand for querying a single process+phase pair. Process scoping is supported only for the deploy phase since build runs once per app and run covers ad-hoc commands and cron tasks where no Procfile process type is available. Storage moves from `$DOKKU_ROOT/$APP/DOCKER_OPTIONS_*` files to property lists under `/var/lib/dokku/config/docker-options/$APP/{processType}.{phase}`, with `_default_` as the sentinel for app-wide options. The install trigger migrates pre-existing DOCKER_OPTIONS_* files into property lists once and renames them to `.migrated`; a global marker makes re-runs strictly no-op. The legacy docker-args-{build,deploy,run} bash triggers are reimplemented in Go alongside a new docker-args-process-deploy trigger that surfaces per-process options to the scheduler. The :report command exposes one dynamic flag per configured `process.deploy` pair (e.g. `--docker-options-deploy.web`) and supports `--format json`. There is no `--global` flag; omitting `--process` keeps the historical default behaviour, since `--global` elsewhere in dokku means "across all apps". Closes #2441.
2026-04-27 18:12:52 -04:00
Jose Diaz-Gonzalez
c0f23528af fix: just use an emptyDir
Let vector decide how to handle the directory.
2026-04-27 17:53:23 -04:00
Jose Diaz-Gonzalez
f19227dcd9 Merge pull request #8514 from dokku/migrate-docker-options-to-go
Migrate docker-options subcommands to go
2026-04-27 17:29:22 -04:00
Jose Diaz-Gonzalez
9767f996c6 Merge pull request #8509 from dokku/7309-nginx-default-site-038
Ship default catch-all site on fresh apt install
2026-04-27 17:11:57 -04:00
Jose Diaz-Gonzalez
acf841606c Merge pull request #8510 from dokku/dependabot/pip/docs/_build/packaging-26.2
chore(deps): bump packaging from 26.1 to 26.2 in /docs/_build
2026-04-27 16:09:24 -04:00
Jose Diaz-Gonzalez
8e7d158ac2 chore: revert transforms changes 2026-04-27 16:06:45 -04:00
Jose Diaz-Gonzalez
5dcefe7ffa fix: use extraVolumeMount just for the vector state 2026-04-27 16:06:07 -04:00