Compare commits

..

462 Commits
v0.38.8 ... cn

Author SHA1 Message Date
apple
47538330f8 Merge branch 'master' into cn
Some checks failed
dependency-updates / prepare (push) Has been cancelled
dependency-updates / update / ${{ matrix.name }} (push) Has been cancelled
CodeQL / Analyze (go) (push) Has been cancelled
* master: (546 commits)
  chore(deps): bump gunicorn in /tests/apps/dockerfile-release
  chore(deps): bump github.com/traefik/traefik/v2
  chore(deps): bump gunicorn from 26.0.0 to 26.1.0 in /tests/apps/multi
  chore(deps): bump gunicorn in /tests/apps/python-flask
  chore(deps): bump pygments from 2.20.0 to 2.21.0 in /docs/_build
  chore: bump herokuish to 0.11.16
  chore: bump go modules
  chore(deps): bump golang.org/x/crypto in /plugins/common
  chore(deps): bump sqlparse in /tests/apps/dockerfile-release
  chore(deps): bump helm.sh/helm/v3 in /plugins/scheduler-k3s
  chore(deps): bump golang in /tests/apps/zombies-dockerfile-no-tini
  chore(deps): bump golang in /tests/apps/go-fail-postdeploy
  chore(deps): bump golang in /tests/apps/go-fail-predeploy
  chore(deps): bump golang from 1.26.5 to 1.26.6 in /tests/apps/gogrpc
  chore(deps): bump golang in /tests/apps/zombies-dockerfile-tini
  chore(deps): bump google.golang.org/protobuf in /tests/apps/gogrpc
  fix: retire cron containers past their active deadline
  Release 0.38.27
  fix: report traefik dns-provider env vars as global keys
  fix: do not require a local image for k3s deploys
  ...

# Conflicts:
#	common.mk
#	contrib/dependencies.json
2026-08-22 17:40:33 +08:00
Jose Diaz-Gonzalez
33896f5d7e Merge pull request #8954 from dokku/dependabot/pip/tests/apps/dockerfile-release/gunicorn-26.1.0
Some checks failed
CI / check-commit (push) Has been cancelled
CodeQL / Analyze (go) (push) Has been cancelled
docs / deploy (push) Has been cancelled
lint / hadolint (push) Has been cancelled
lint / markdown-lint (push) Has been cancelled
lint / packer (push) Has been cancelled
lint / shellcheck (push) Has been cancelled
lint / shfmt (push) Has been cancelled
lint / yamllint (push) Has been cancelled
CI / build (push) Has been cancelled
CI / build-image.linux/amd64 (push) Has been cancelled
CI / build-image.linux/arm64 (push) Has been cancelled
CI / unit.${{ matrix.index }} (push) Has been cancelled
CI / docker (push) Has been cancelled
CI / go.0 (push) Has been cancelled
CI / go.1 (push) Has been cancelled
CI / go.2 (push) Has been cancelled
CI / go.3 (push) Has been cancelled
CI / publish-test-results (push) Has been cancelled
chore(deps): bump gunicorn from 26.0.0 to 26.1.0 in /tests/apps/dockerfile-release
2026-08-21 16:18:10 -04:00
Jose Diaz-Gonzalez
066c1228ef Merge pull request #8953 from dokku/dependabot/go_modules/plugins/scheduler-k3s/github.com/traefik/traefik/v2-2.11.55
chore(deps): bump github.com/traefik/traefik/v2 from 2.11.54 to 2.11.55 in /plugins/scheduler-k3s
2026-08-21 16:18:02 -04:00
Jose Diaz-Gonzalez
8194d27cf9 Merge pull request #8952 from dokku/dependabot/pip/tests/apps/multi/gunicorn-26.1.0
chore(deps): bump gunicorn from 26.0.0 to 26.1.0 in /tests/apps/multi
2026-08-21 16:17:49 -04:00
Jose Diaz-Gonzalez
527805dbcc Merge pull request #8951 from dokku/dependabot/pip/tests/apps/python-flask/gunicorn-26.1.0
chore(deps): bump gunicorn from 26.0.0 to 26.1.0 in /tests/apps/python-flask
2026-08-21 16:17:42 -04:00
dependabot[bot]
bb0086798d chore(deps): bump gunicorn in /tests/apps/dockerfile-release
Bumps [gunicorn](https://github.com/benoitc/gunicorn) from 26.0.0 to 26.1.0.
- [Release notes](https://github.com/benoitc/gunicorn/releases)
- [Commits](https://github.com/benoitc/gunicorn/compare/26.0.0...26.1.0)

---
updated-dependencies:
- dependency-name: gunicorn
  dependency-version: 26.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-08-21 13:55:25 +00:00
dependabot[bot]
15c00bd159 chore(deps): bump github.com/traefik/traefik/v2
Bumps [github.com/traefik/traefik/v2](https://github.com/traefik/traefik) from 2.11.54 to 2.11.55.
- [Release notes](https://github.com/traefik/traefik/releases)
- [Changelog](https://github.com/traefik/traefik/blob/v2.11.55/CHANGELOG.md)
- [Commits](https://github.com/traefik/traefik/compare/v2.11.54...v2.11.55)

---
updated-dependencies:
- dependency-name: github.com/traefik/traefik/v2
  dependency-version: 2.11.55
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-08-21 13:55:14 +00:00
dependabot[bot]
5129582c85 chore(deps): bump gunicorn from 26.0.0 to 26.1.0 in /tests/apps/multi
Bumps [gunicorn](https://github.com/benoitc/gunicorn) from 26.0.0 to 26.1.0.
- [Release notes](https://github.com/benoitc/gunicorn/releases)
- [Commits](https://github.com/benoitc/gunicorn/compare/26.0.0...26.1.0)

---
updated-dependencies:
- dependency-name: gunicorn
  dependency-version: 26.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-08-21 13:52:58 +00:00
dependabot[bot]
2e27889d50 chore(deps): bump gunicorn in /tests/apps/python-flask
Bumps [gunicorn](https://github.com/benoitc/gunicorn) from 26.0.0 to 26.1.0.
- [Release notes](https://github.com/benoitc/gunicorn/releases)
- [Commits](https://github.com/benoitc/gunicorn/compare/26.0.0...26.1.0)

---
updated-dependencies:
- dependency-name: gunicorn
  dependency-version: 26.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-08-21 13:52:53 +00:00
Jose Diaz-Gonzalez
ea7249fed4 Merge pull request #8950 from dokku/dependabot/pip/docs/_build/pygments-2.21.0
chore(deps): bump pygments from 2.20.0 to 2.21.0 in /docs/_build
2026-08-20 12:17:21 -04:00
dependabot[bot]
284bb810f6 chore(deps): bump pygments from 2.20.0 to 2.21.0 in /docs/_build
Bumps [pygments](https://github.com/pygments/pygments) from 2.20.0 to 2.21.0.
- [Release notes](https://github.com/pygments/pygments/releases)
- [Changelog](https://github.com/pygments/pygments/blob/master/CHANGES)
- [Commits](https://github.com/pygments/pygments/compare/2.20.0...2.21.0)

---
updated-dependencies:
- dependency-name: pygments
  dependency-version: 2.21.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-08-20 13:53:24 +00:00
Jose Diaz-Gonzalez
579e4a3288 Merge pull request #8945 from dokku/dependabot/go_modules/plugins/common/golang.org/x/crypto-0.55.0
chore(deps): bump golang.org/x/crypto from 0.54.0 to 0.55.0 in /plugins/common
2026-08-19 11:05:42 -04:00
Jose Diaz-Gonzalez
cf842bcd53 Merge pull request #8949 from dokku/chore/bump-herokuish-0.11.16
chore: bump herokuish to 0.11.16
2026-08-19 10:45:55 -04:00
Dokku Bot
e3c76869fa chore: bump herokuish to 0.11.16 2026-08-19 10:03:50 +00:00
Jose Diaz-Gonzalez
a29bf12553 chore: bump go modules 2026-08-19 00:24:44 -04:00
dependabot[bot]
934b1a0370 chore(deps): bump golang.org/x/crypto in /plugins/common
Bumps [golang.org/x/crypto](https://github.com/golang/crypto) from 0.54.0 to 0.55.0.
- [Commits](https://github.com/golang/crypto/compare/v0.54.0...v0.55.0)

---
updated-dependencies:
- dependency-name: golang.org/x/crypto
  dependency-version: 0.55.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-08-19 03:23:24 +00:00
Jose Diaz-Gonzalez
d03c9df862 Merge pull request #8943 from dokku/dependabot/docker/tests/apps/zombies-dockerfile-no-tini/golang-1.26.6
chore(deps): bump golang from 1.26.5 to 1.26.6 in /tests/apps/zombies-dockerfile-no-tini
2026-08-18 23:22:23 -04:00
Jose Diaz-Gonzalez
9afb439d52 Merge pull request #8944 from dokku/dependabot/docker/tests/apps/go-fail-postdeploy/golang-1.26.6
chore(deps): bump golang from 1.26.5 to 1.26.6 in /tests/apps/go-fail-postdeploy
2026-08-18 23:22:16 -04:00
Jose Diaz-Gonzalez
d11543bbf9 Merge pull request #8942 from dokku/dependabot/docker/tests/apps/go-fail-predeploy/golang-1.26.6
chore(deps): bump golang from 1.26.5 to 1.26.6 in /tests/apps/go-fail-predeploy
2026-08-18 23:22:09 -04:00
Jose Diaz-Gonzalez
3cb090294a Merge pull request #8941 from dokku/dependabot/docker/tests/apps/gogrpc/golang-1.26.6
chore(deps): bump golang from 1.26.5 to 1.26.6 in /tests/apps/gogrpc
2026-08-18 23:22:01 -04:00
Jose Diaz-Gonzalez
b18273378e Merge pull request #8940 from dokku/dependabot/docker/tests/apps/zombies-dockerfile-tini/golang-1.26.6
chore(deps): bump golang from 1.26.5 to 1.26.6 in /tests/apps/zombies-dockerfile-tini
2026-08-18 23:21:54 -04:00
Jose Diaz-Gonzalez
013113936e Merge pull request #8947 from dokku/dependabot/pip/tests/apps/dockerfile-release/sqlparse-0.6.0
chore(deps): bump sqlparse from 0.5.5 to 0.6.0 in /tests/apps/dockerfile-release
2026-08-18 23:21:43 -04:00
Jose Diaz-Gonzalez
2122befc56 Merge pull request #8946 from dokku/dependabot/go_modules/plugins/scheduler-k3s/helm.sh/helm/v3-3.21.4
chore(deps): bump helm.sh/helm/v3 from 3.21.3 to 3.21.4 in /plugins/scheduler-k3s
2026-08-18 23:21:35 -04:00
dependabot[bot]
f494537817 chore(deps): bump sqlparse in /tests/apps/dockerfile-release
Bumps [sqlparse](https://github.com/andialbrecht/sqlparse) from 0.5.5 to 0.6.0.
- [Changelog](https://github.com/andialbrecht/sqlparse/blob/master/CHANGELOG)
- [Commits](https://github.com/andialbrecht/sqlparse/compare/0.5.5...0.6.0)

---
updated-dependencies:
- dependency-name: sqlparse
  dependency-version: 0.6.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-08-17 21:29:38 +00:00
dependabot[bot]
6464096917 chore(deps): bump helm.sh/helm/v3 in /plugins/scheduler-k3s
Bumps [helm.sh/helm/v3](https://github.com/helm/helm) from 3.21.3 to 3.21.4.
- [Commits](https://github.com/helm/helm/compare/v3.21.3...v3.21.4)

---
updated-dependencies:
- dependency-name: helm.sh/helm/v3
  dependency-version: 3.21.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-08-17 13:55:34 +00:00
dependabot[bot]
b1273cc4fe chore(deps): bump golang in /tests/apps/zombies-dockerfile-no-tini
Bumps golang from 1.26.5 to 1.26.6.

---
updated-dependencies:
- dependency-name: golang
  dependency-version: 1.26.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-08-17 13:53:00 +00:00
dependabot[bot]
4a6471ba16 chore(deps): bump golang in /tests/apps/go-fail-postdeploy
Bumps golang from 1.26.5 to 1.26.6.

---
updated-dependencies:
- dependency-name: golang
  dependency-version: 1.26.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-08-17 13:53:00 +00:00
dependabot[bot]
16936697a5 chore(deps): bump golang in /tests/apps/go-fail-predeploy
Bumps golang from 1.26.5 to 1.26.6.

---
updated-dependencies:
- dependency-name: golang
  dependency-version: 1.26.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-08-17 13:52:55 +00:00
dependabot[bot]
50ad9cfb09 chore(deps): bump golang from 1.26.5 to 1.26.6 in /tests/apps/gogrpc
Bumps golang from 1.26.5 to 1.26.6.

---
updated-dependencies:
- dependency-name: golang
  dependency-version: 1.26.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-08-17 13:52:55 +00:00
dependabot[bot]
140895f4cc chore(deps): bump golang in /tests/apps/zombies-dockerfile-tini
Bumps golang from 1.26.5 to 1.26.6.

---
updated-dependencies:
- dependency-name: golang
  dependency-version: 1.26.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-08-17 13:52:48 +00:00
Jose Diaz-Gonzalez
a0bf26543e Merge pull request #8939 from dokku/dependabot/go_modules/tests/apps/gogrpc/google.golang.org/protobuf-1.36.12
chore(deps): bump google.golang.org/protobuf from 1.36.11 to 1.36.12 in /tests/apps/gogrpc
2026-08-13 15:09:33 -04:00
dependabot[bot]
fd95223052 chore(deps): bump google.golang.org/protobuf in /tests/apps/gogrpc
Bumps google.golang.org/protobuf from 1.36.11 to 1.36.12.

---
updated-dependencies:
- dependency-name: google.golang.org/protobuf
  dependency-version: 1.36.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-08-13 13:52:25 +00:00
Jose Diaz-Gonzalez
4c3d43a3ac Merge pull request #8937 from dokku/8912-cron-containers-are-never-retired-past-their-active-deadline
Retire cron containers past their active deadline
2026-08-12 16:26:44 -04:00
Jose Diaz-Gonzalez
96d726c43c fix: retire cron containers past their active deadline
Cron containers were never reaped once they exceeded their active deadline, so a hung cron task ran indefinitely instead of being retired after 24 hours as documented. `cron:run` now also accepts a `--ttl-seconds` argument, matching the one `dokku run` already takes.
2026-08-12 13:11:34 -04:00
Dokku Bot
80bfde6dc9 Release 0.38.27
# History

## 0.38.27

Install/update via the bootstrap script:

```shell
wget -NP . https://dokku.com/install/v0.38.27/bootstrap.sh
sudo DOKKU_TAG=v0.38.27 bash bootstrap.sh
```

### Bug Fixes

- #8933: @josegonzalez Do not require a local image for k3s deploys
- #8930: @josegonzalez Do not import an already-migrated ENV file
- #8919: @josegonzalez Regenerate vector config on app lifecycle changes
- #8917: @josegonzalez Apply app-label-alias to shipped events

### New Features

- #8934: @josegonzalez Report traefik dns-provider env vars as global keys
- #8920: @josegonzalez Add storage directory mode and removal flags
- #8914: @josegonzalez Add vector-cron-sink for scheduled cron task output

### Tests

- #8931: @dependabot[bot] chore(deps): bump djangorestframework from 3.17.2 to 3.18.0 in /tests/apps/dockerfile-release
- #8927: @dependabot[bot] chore(deps): bump djangorestframework from 3.17.1 to 3.17.2 in /tests/apps/dockerfile-release
- #8923: @dependabot[bot] chore(deps): bump python from 3.15.0b4-bookworm to 3.15.0rc1-bookworm in /tests/apps/dockerfile-release

### Dependencies

- #8926: @dependabot[bot] chore(deps): bump github.com/gliderlabs/sigil from 0.12.0 to 0.12.1 in /plugins/nginx-vhosts
- #8925: @dependabot[bot] chore(deps): bump packaging from 26.2 to 26.3 in /docs/_build
- #8921: @dokku-bot chore: bump pack to 0.40.9
- #8924: @dependabot[bot] chore(deps): bump soupsieve from 2.9.1 to 2.9.2 in /docs/_build
- #8922: @dependabot[bot] chore(deps): bump python from 3.15.0b4-alpine to 3.15.0rc1-alpine in /docs/_build
- #8915: @dokku-bot chore: bump herokuish to 0.11.15
2026-08-12 08:54:47 +00:00
Jose Diaz-Gonzalez
0bfd35dada Merge pull request #8934 from dokku/8928-traefik-report-does-not-surface-the-dns-provider-properties
Report traefik dns-provider env vars as global keys
2026-08-12 04:52:58 -04:00
Jose Diaz-Gonzalez
69b74cbe7d Merge pull request #8933 from dokku/k3s-do-not-require-image-for-ps-restart
Do not require a local image for k3s deploys
2026-08-12 04:52:52 -04:00
Jose Diaz-Gonzalez
81a929d768 fix: report traefik dns-provider env vars as global keys
The dynamic `dns-provider-*` properties were reported as `--traefik-dns-provider-<env_var>`, outside the `global`/`computed` namespace every other traefik property uses, so a consumer reading the json report could not tell which of the two a key represented. They are now reported as `--traefik-global-dns-provider-<env_var>`. The `basic-auth-password` property is a credential as well and is now masked in the default report output on the same terms as the dns provider values, meaning the raw value is returned only for `--format json` or when the flag is queried by name.
2026-08-12 03:22:04 -04:00
Jose Diaz-Gonzalez
1d2c7424aa fix: do not require a local image for k3s deploys
Kubernetes pulls the app image itself, so a k3s host is free to reap its local copy while the workload keeps running, which the `registry` plugin already does on its own. Deploys, restarts, `dokku run`, and in-cluster cron no longer assert that the image is present locally, falling back to the metadata recorded in the app's current Helm release. A `ps:restart` naming a single process type now rolls only that process type's pods rather than silently redeploying every one. Apps with an `app.json` postdeploy task still require the image locally, as that task runs on the Dokku host.
2026-08-12 02:14:56 -04:00
Jose Diaz-Gonzalez
adf2bd14fb Merge pull request #8930 from dokku/8929-0-38-26-regression-drainlegacyenvfile-silently-overwrites-current-config-with-the-stale-legacy-env-file
fix: do not import an already-migrated ENV file
2026-08-12 02:13:59 -04:00
Jose Diaz-Gonzalez
54fe86ecd8 Merge pull request #8931 from dokku/dependabot/pip/tests/apps/dockerfile-release/djangorestframework-3.18.0
chore(deps): bump djangorestframework from 3.17.2 to 3.18.0 in /tests/apps/dockerfile-release
2026-08-11 19:38:51 -04:00
Jose Diaz-Gonzalez
25a5bacde9 docs: note the preserved ENV file can be deleted
The preserved copy holds everything the legacy file was not allowed to import, which includes keys that had been `config:unset` on purpose, so a revoked secret can outlive its revocation in a file `dokku config:*` no longer reads. Nothing said the copy was the operator's to remove once reviewed.
2026-08-11 19:11:06 -04:00
dependabot[bot]
71df7da367 chore(deps): bump djangorestframework in /tests/apps/dockerfile-release
Bumps [djangorestframework](https://github.com/encode/django-rest-framework) from 3.17.2 to 3.18.0.
- [Release notes](https://github.com/encode/django-rest-framework/releases)
- [Commits](https://github.com/encode/django-rest-framework/compare/3.17.2...3.18.0)

---
updated-dependencies:
- dependency-name: djangorestframework
  dependency-version: 3.18.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-08-11 13:55:03 +00:00
Jose Diaz-Gonzalez
685f16e6b1 fix: do not import an already-migrated ENV file
Releases 0.38.0 through 0.38.25 recorded the ENV file migration and deliberately left the file at the old path, so 0.38.26 treating a leftover file as a hand-edit replayed the environment as it stood at that upgrade over every `config:set` and `config:unset` made since, reinstating variables and secrets that had been deliberately unset. A file found at the old path once its migration is on record is no longer imported: it is removed when it agrees with the current config, and is otherwise moved aside to `ENV.migrated` with the keys it disagrees on named in a warning. That warning now reaches the operator during an upgrade rather than being swallowed, which is why the overwrite went unreported.
2026-08-10 17:58:10 -04:00
Jose Diaz-Gonzalez
2d34caec00 Merge pull request #8920 from dokku/8913-storage-host-directories-have-no-mode-flag-and-no-removal-path
Add storage directory mode and removal flags
2026-08-10 17:22:31 -04:00
Jose Diaz-Gonzalez
4e169e8842 Merge pull request #8927 from dokku/dependabot/pip/tests/apps/dockerfile-release/djangorestframework-3.17.2
chore(deps): bump djangorestframework from 3.17.1 to 3.17.2 in /tests/apps/dockerfile-release
2026-08-10 15:03:49 -04:00
Jose Diaz-Gonzalez
9c31ff8792 Merge pull request #8919 from dokku/8918-renaming-or-cloning-an-app-silently-stops-vector-log-shipping
Regenerate vector config on app lifecycle changes
2026-08-10 15:03:22 -04:00
Jose Diaz-Gonzalez
43163f2719 Merge pull request #8926 from dokku/dependabot/go_modules/plugins/nginx-vhosts/github.com/gliderlabs/sigil-0.12.1
chore(deps): bump github.com/gliderlabs/sigil from 0.12.0 to 0.12.1 in /plugins/nginx-vhosts
2026-08-10 15:03:10 -04:00
Jose Diaz-Gonzalez
6c4809e850 Merge pull request #8923 from dokku/dependabot/docker/tests/apps/dockerfile-release/python-3.15.0rc1-bookworm
chore(deps): bump python from 3.15.0b4-bookworm to 3.15.0rc1-bookworm in /tests/apps/dockerfile-release
2026-08-10 15:03:02 -04:00
Jose Diaz-Gonzalez
6eba85e0b2 Merge pull request #8925 from dokku/dependabot/pip/docs/_build/packaging-26.3
chore(deps): bump packaging from 26.2 to 26.3 in /docs/_build
2026-08-10 15:02:52 -04:00
Jose Diaz-Gonzalez
44b0414a4d Merge pull request #8921 from dokku/chore/bump-pack-0.40.9
chore: bump pack to 0.40.9
2026-08-10 15:02:41 -04:00
Jose Diaz-Gonzalez
836843d5cd Merge pull request #8924 from dokku/dependabot/pip/docs/_build/soupsieve-2.9.2
chore(deps): bump soupsieve from 2.9.1 to 2.9.2 in /docs/_build
2026-08-10 15:02:34 -04:00
Jose Diaz-Gonzalez
c110a3eb23 Merge pull request #8922 from dokku/dependabot/docker/docs/_build/python-3.15.0rc1-alpine
chore(deps): bump python from 3.15.0b4-alpine to 3.15.0rc1-alpine in /docs/_build
2026-08-10 15:02:25 -04:00
Jose Diaz-Gonzalez
74f9acf7ba refactor: align storage:set with dokku conventions
`storage:set` now takes `<name> <property> [<value>]` like every other `:set` command, where omitting the value unsets the property. Previously it took flags and could not distinguish an empty value from an omitted one, so nothing it set could ever be cleared. The flag form keeps working and emits a deprecation warning.

Annotations and labels move to `storage:annotations:set`, `storage:annotations:report`, `storage:labels:set`, and `storage:labels:report`, matching the `scheduler-k3s` equivalents. These operate on a single key, so clearing one leaves the rest in place rather than replacing the whole map as the `--annotation` and `--label` flags do.
2026-08-10 15:00:45 -04:00
dependabot[bot]
3e412ccae0 chore(deps): bump djangorestframework in /tests/apps/dockerfile-release
Bumps [djangorestframework](https://github.com/encode/django-rest-framework) from 3.17.1 to 3.17.2.
- [Release notes](https://github.com/encode/django-rest-framework/releases)
- [Commits](https://github.com/encode/django-rest-framework/compare/3.17.1...3.17.2)

---
updated-dependencies:
- dependency-name: djangorestframework
  dependency-version: 3.17.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-08-10 13:55:27 +00:00
dependabot[bot]
6150c69f9f chore(deps): bump github.com/gliderlabs/sigil in /plugins/nginx-vhosts
Bumps [github.com/gliderlabs/sigil](https://github.com/gliderlabs/sigil) from 0.12.0 to 0.12.1.
- [Release notes](https://github.com/gliderlabs/sigil/releases)
- [Commits](https://github.com/gliderlabs/sigil/compare/v0.12.0...v0.12.1)

---
updated-dependencies:
- dependency-name: github.com/gliderlabs/sigil
  dependency-version: 0.12.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-08-10 13:54:22 +00:00
dependabot[bot]
210c428c3d chore(deps): bump packaging from 26.2 to 26.3 in /docs/_build
Bumps [packaging](https://github.com/pypa/packaging) from 26.2 to 26.3.
- [Release notes](https://github.com/pypa/packaging/releases)
- [Changelog](https://github.com/pypa/packaging/blob/main/CHANGELOG.rst)
- [Commits](https://github.com/pypa/packaging/compare/26.2...26.3)

---
updated-dependencies:
- dependency-name: packaging
  dependency-version: '26.3'
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-08-10 13:53:36 +00:00
dependabot[bot]
464eb88152 chore(deps): bump soupsieve from 2.9.1 to 2.9.2 in /docs/_build
Bumps [soupsieve](https://github.com/facelessuser/soupsieve) from 2.9.1 to 2.9.2.
- [Release notes](https://github.com/facelessuser/soupsieve/releases)
- [Commits](https://github.com/facelessuser/soupsieve/compare/2.9.1...2.9.2)

---
updated-dependencies:
- dependency-name: soupsieve
  dependency-version: 2.9.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-08-10 13:53:29 +00:00
dependabot[bot]
35f54a5e45 chore(deps): bump python in /tests/apps/dockerfile-release
Bumps python from 3.15.0b4-bookworm to 3.15.0rc1-bookworm.

---
updated-dependencies:
- dependency-name: python
  dependency-version: 3.15.0rc1-bookworm
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-08-10 13:53:09 +00:00
dependabot[bot]
e7ab73d173 chore(deps): bump python in /docs/_build
Bumps python from 3.15.0b4-alpine to 3.15.0rc1-alpine.

---
updated-dependencies:
- dependency-name: python
  dependency-version: 3.15.0rc1-alpine
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-08-10 13:52:51 +00:00
Dokku Bot
df053f6039 chore: bump pack to 0.40.9 2026-08-10 06:29:01 +00:00
Jose Diaz-Gonzalez
87b240054f feat: add storage directory mode and removal flags
`storage:create` and `storage:set` accept a `--mode` flag that sets the octal permissions of a docker-local host directory, and `storage:destroy` accepts a `--destroy-host-dir` flag that removes the directory along with its contents. A docker-local entry also honors `--reclaim-policy Delete` at destroy time now, matching how that policy governs a k3s PersistentVolume. Both are limited to the default `/var/lib/dokku/data/storage/<name>` location, the same restriction `--chown` already carries. `storage:set` applies `--chown` and `--mode` to the directory rather than only recording them.
2026-08-10 01:23:10 -04:00
Jose Diaz-Gonzalez
b43929df27 fix: regenerate vector config on app lifecycle changes
The generated vector config is a snapshot of the app list and their sink properties, but it was only ever written by `logs:set` and `logs:vector-start`. Renaming an app left a source filtering on a label no container carries and gave the new name no source at all, so the app kept a sink with nothing feeding it. Cloning produced the same result for the clone, and destroying an app left its source and sink behind, the latter still pointing at an endpoint decommissioned along with the app. The global relabel transform embeds app names directly in generated VRL, so a rename also left behind a branch naming an app that no longer existed. Every case was silent, and the only repair was an operator running `logs:vector-start`. The `post-app-clone-setup`, `post-app-rename-setup` and `post-delete` triggers now rewrite the config, warning rather than failing so that a config write cannot abort the app operation whose state it is derived from.

Closes #8918.
2026-08-09 23:53:12 -04:00
Jose Diaz-Gonzalez
39df6e3855 Merge pull request #8917 from dokku/8916-setting-app-label-alias-silently-disables-vector-log-collection
Apply app-label-alias to shipped events
2026-08-09 21:13:03 -04:00
Jose Diaz-Gonzalez
5b5d3d761b fix: apply app-label-alias to shipped events
The alias was only ever used to build the `include_labels` filter on the generated vector source, while dokku labels containers with `com.dokku.app-name` unconditionally. Setting the property therefore pointed the source at a label no container carries, and log collection stopped without any error. The source now always filters the label dokku applies, and a generated remap renames the field on its way to the sink, which is what the property was documented to do. An app whose own alias differs from the global one gets a branch in the global pipeline, so a per-app value is honored even when the app ships through the global sink.

Closes #8916.
2026-08-09 14:01:43 -04:00
Jose Diaz-Gonzalez
d767dd83f1 Merge pull request #8914 from dokku/feat/vector-cron-sink
Add vector-cron-sink for scheduled cron task output
2026-08-09 13:16:21 -04:00
Jose Diaz-Gonzalez
3edb5a3066 Merge pull request #8915 from dokku/chore/bump-herokuish-0.11.15
chore: bump herokuish to 0.11.15
2026-08-09 13:14:19 -04:00
Jose Diaz-Gonzalez
4a1bdc9bdf style: satisfy shfmt pipeline continuation formatting 2026-08-09 02:26:58 -04:00
Jose Diaz-Gonzalez
3d02d81562 fix: stop logs tests leaking a global app-label-alias
The `app-label-alias` test left the global property set, so every later test in the file generated a vector source filtering on a label that dokku never applies to a container, silently collecting nothing. Clearing it in teardown restores log collection for the rest of the file. The cron routing test now asserts against console sinks rather than files, since the sink an event reached is identifiable from vector's own output without depending on a writable host mount, and its task sleeps either side of its output because a cron container that exits immediately is removed before vector can attach to it.
2026-08-09 02:22:13 -04:00
Dokku Bot
8341c7cdcb chore: bump herokuish to 0.11.15 2026-08-09 06:15:51 +00:00
Dokku Bot
95f9d4f9b7 Release 0.38.26
# History

## 0.38.26

Install/update via the bootstrap script:

```shell
wget -NP . https://dokku.com/install/v0.38.26/bootstrap.sh
sudo DOKKU_TAG=v0.38.26 bash bootstrap.sh
```

### Bug Fixes

- #8906: @josegonzalez Match docker options by shell word when removing

### New Features

- #8911: @josegonzalez Route wildcard domains through traefik on k3s
- #8909: @josegonzalez Support manually managed cert issuers on k3s
- #8903: @josegonzalez Support kernel sysctls on the k3s scheduler
- #8856: @youdie006 Add pre-parsed port_mappings to ports:report json

### Refactors

- #8863: @josegonzalez Move host-crontab generation into cron plugin

### Documentation

- #8908: @josegonzalez Document --global on scheduler-k3s report and set
- #8858: @bakatz Added instructions for restoring backups on different CPU architectures.

### Tests

- #8893: @dependabot[bot] chore(deps): bump django from 5.2.16 to 5.2.17 in /tests/apps/dockerfile-release
- #8891: @dependabot[bot] chore(deps-dev): bump heroku/heroku-buildpack-php from 293 to 294 in /tests/apps/php
- #8877: @dependabot[bot] chore(deps): bump google.golang.org/grpc from 1.82.1 to 1.83.0 in /tests/apps/gogrpc
- #8874: @dependabot[bot] chore(deps): bump sass from 1.101.7 to 1.102.0 in /tests/apps/multi
- #8870: @dependabot[bot] chore(deps): bump sass from 1.101.6 to 1.101.7 in /tests/apps/multi
- #8866: @dependabot[bot] chore(deps): bump sass from 1.101.3 to 1.101.6 in /tests/apps/multi
- #8860: @dependabot[bot] chore(deps): bump setuptools from 78.1.1 to 83.0.0 in /tests/apps/dockerfile-release
- #8859: @dependabot[bot] chore(deps): bump immutable from 5.1.5 to 5.1.9 in /tests/apps/multi
- #8855: @dependabot[bot] chore(deps): bump sass from 1.101.0 to 1.101.3 in /tests/apps/multi
- #8857: @dependabot[bot] chore(deps): bump body-parser from 2.2.1 to 2.3.0 in /tests/apps/checks-root
- #8853: @dependabot[bot] chore(deps): bump python from 3.15.0b3-bookworm to 3.15.0b4-bookworm in /tests/apps/dockerfile-release

### Dependencies

- #8905: @dependabot[bot] chore(deps): bump oras.land/oras-go/v2 from 2.6.1 to 2.6.2 in /plugins/scheduler-k3s
- #8869: @dependabot[bot] chore(deps): bump github.com/mattn/go-isatty from 0.0.23 to 0.0.24 in /plugins/app-json
- #8887: @dependabot[bot] chore(deps): bump github.com/kedacore/keda/v2 from 2.20.1 to 2.20.2 in /plugins/scheduler-k3s
- #8883: @dokku-bot chore: bump docker-container-healthchecker to 0.16.0
- #8886: @dependabot[bot] chore(deps): update markdown requirement from <3.11,>=3.10.2 to >=3.10.3,<3.11 in /docs/_build
- #8892: @dependabot[bot] chore(deps): bump traefik from v3.7.9 to v3.7.10 in /plugins/traefik-vhosts
- #8885: @dokku-bot chore: bump dokku-update to 0.10.0
- #8884: @dokku-bot chore: bump procfile-util to 0.20.8
- #8882: @dokku-bot chore: bump docker-image-labeler to 0.10.0
- #8888: @dependabot[bot] chore(deps): bump github.com/traefik/traefik/v2 from 2.11.53 to 2.11.54 in /plugins/scheduler-k3s
- #8900: @dokku-bot chore: bump gliderlabs-sigil to 0.12.1
- #8899: @dokku-bot chore: bump herokuish to 0.11.14
- #8898: @dokku-bot chore: bump netrc to 0.11.1
- #8897: @dokku-bot chore: bump dokku-event-listener to 0.20.1
- #8896: @dokku-bot chore: bump sshcommand to 0.20.2
- #8895: @dokku-bot chore: bump lambda-builder to 0.9.4
- #8894: @dokku-bot chore: bump plugn to 0.17.1
- #8876: @dependabot[bot] chore(deps): bump github.com/cert-manager/cert-manager from 1.21.0 to 1.21.1 in /plugins/scheduler-k3s
- #8873: @dependabot[bot] chore(deps): bump traefik from v3.7.8 to v3.7.9 in /plugins/traefik-vhosts
- #8872: @dependabot[bot] chore(deps): bump github.com/traefik/traefik/v2 from 2.11.52 to 2.11.53 in /plugins/scheduler-k3s
- #8871: @dependabot[bot] chore(deps): bump k8s.io/kubernetes from 1.36.2 to 1.36.3 in /plugins/scheduler-k3s
- #8868: @dependabot[bot] chore(deps): bump k8s.io/kubectl from 0.36.2 to 0.36.3 in /plugins/scheduler-k3s
- #8867: @dependabot[bot] chore(deps): bump k8s.io/client-go from 0.36.2 to 0.36.3 in /plugins/scheduler-k3s
- #8865: @dependabot[bot] chore(deps): bump github.com/fluxcd/pkg/kustomize from 1.38.0 to 1.39.0 in /plugins/scheduler-k3s
- #8864: @dependabot[bot] chore(deps): bump soupsieve from 2.9 to 2.9.1 in /docs/_build
- #8854: @dependabot[bot] chore(deps): bump python from 3.15.0b3-alpine to 3.15.0b4-alpine in /docs/_build
- #8852: @dependabot[bot] chore(deps): bump soupsieve from 2.8.4 to 2.9 in /docs/_build
- #8851: @dependabot[bot] chore(deps): bump mkdocs-material from 9.7.6 to 9.7.7 in /docs/_build
- #8850: @dependabot[bot] chore(deps): bump actions/setup-python from 6 to 7

### Other

- #8907: @josegonzalez fix: migrate env files before reading deprecated vars
- #8881: @josegonzalez Ignore minor and patch updates for github actions
2026-08-09 05:57:36 +00:00
Jose Diaz-Gonzalez
52b26a3760 feat: add vector-cron-sink for scheduled cron task output
Scheduled cron task output previously reached only the `dokku` user's cron mail, and could not be redirected because `app.json` rejects bare shell operators in a cron `command`. Setting `vector-cron-sink` on an app or globally routes that output to a dedicated sink instead, on both the `docker-local` and `k3s` schedulers, which keeps log destinations under operator control rather than in a deployed repository. Cron events carry `dokku_app` and `dokku_cron_id` fields so a sink can give each task its own destination. This also fixes a `k3s` bug where configuring a global `vector-sink` silently removed the vector prometheus exporter sink.
2026-08-09 01:10:21 -04:00
Jose Diaz-Gonzalez
047be485a2 Merge pull request #8911 from dokku/8910-k3s-scheduler-traefik-ingress-cannot-route-wildcard-domains
Route wildcard domains through traefik on k3s
2026-08-08 22:44:38 -04:00
Jose Diaz-Gonzalez
bb7335f88e feat: route wildcard domains through traefik on k3s
Traefik matches hosts exactly, so an app serving a wildcard domain under the `traefik` ingress class had a valid certificate but silently 404d on every request. Wildcard domains now render as a `HostRegexp` rule that matches a single label, the same semantics as a Kubernetes wildcard host, so both ingress classes behave the same. Those routes carry an explicit low priority so an exact domain on any app still wins over another app's wildcard, mirroring ingress-nginx.
2026-08-08 19:15:10 -04:00
Jose Diaz-Gonzalez
6c823e3b8a Merge pull request #8909 from dokku/8901-k3s-scheduler-custom-cert-issuer-name
Support manually managed cert issuers on k3s
2026-08-08 18:36:34 -04:00
Jose Diaz-Gonzalez
d134e75371 feat: support manually managed cert issuers on k3s
The `cert-issuer-name` and `cert-issuer-kind` properties point an app's generated `Certificate` at a cert-manager issuer created outside of Dokku, allowing certificates to be issued through solvers the built-in letsencrypt integration cannot use, such as `dns01` for wildcard certificates. Setting an issuer enables https on its own, as a manually managed issuer has no email for Dokku to configure. An imported certificate still takes precedence, and `letsencrypt-server false` remains the single off switch. Dokku warns before a build starts when the referenced issuer is absent from the cluster, without blocking the deploy. Wildcard domains no longer collide with their apex domain when generating ingress names, and `letsencrypt-server` values are now validated when set rather than at deploy time.
2026-08-08 15:16:12 -04:00
Jose Diaz-Gonzalez
2da48f4f86 Merge pull request #8908 from dokku/8861-scheduler-k3s-report-and-scheduler-k3s-set-help-omits-the-global-option
Document --global on scheduler-k3s report and set
2026-08-08 01:47:48 -04:00
Jose Diaz-Gonzalez
66bcfbd1ed fix: document --global on scheduler-k3s report and set
The usage strings for `scheduler-k3s:report` and `scheduler-k3s:set` omitted the `--global` option, which is the only way to reach the scheduler-wide report since a bare `scheduler-k3s:report` iterates every app, and `:report` also omitted `--format stdout|json`. The command listing in the k3s documentation is resynced with the help output, which additionally restores flags that had been dropped from `scheduler-k3s:cluster:add`, `scheduler-k3s:cluster:list`, and `scheduler-k3s:initialize`.
2026-08-08 01:43:40 -04:00
Jose Diaz-Gonzalez
e82a21a43a Merge pull request #8907 from dokku/8875-0-38-migration-plugins-ordered-before-config-silently-fail-to-migrate-their-dokku-config-vars
fix: migrate env files before reading deprecated vars
2026-08-08 01:17:34 -04:00
Jose Diaz-Gonzalez
e24859bfe6 test: stage the migration marker through the trigger
The hand-written marker file was created as root, which the config-migrate-env
trigger could not overwrite when it ran under a different user. Draining once up
front records the migration through the same code path the assertion exercises.
2026-08-07 17:56:15 -04:00
Jose Diaz-Gonzalez
70dc921967 fix: migrate env files before reading deprecated vars
Install steps run in alphabetical order of the enabled plugin directory, so `apps`, `builder`, and `checks` read an app's environment before the `config` plugin had moved the `ENV` file to its new location. The read came back empty, so their deprecated `DOKKU_*` variables were never migrated to the matching plugin property and were never unset, with nothing reported either way: `dokku config:show` kept listing the variable while the plugin behaved as though it were unset. The relocation now runs before any deprecated variable is read, whatever the install order, and each old file is removed as soon as it has been drained rather than on a later install, which also covers the global file that was never removed at all. A file that reappears at the old path can only have been written by hand, so it is merged in with a warning naming its keys instead of being discarded.
2026-08-07 16:43:56 -04:00
Jose Diaz-Gonzalez
2527d57dfc Merge pull request #8905 from dokku/dependabot/go_modules/plugins/scheduler-k3s/oras.land/oras-go/v2-2.6.2
chore(deps): bump oras.land/oras-go/v2 from 2.6.1 to 2.6.2 in /plugins/scheduler-k3s
2026-08-07 16:14:55 -04:00
Jose Diaz-Gonzalez
eedcb90e29 Merge pull request #8906 from dokku/8904-docker-options-remove-silently-no-ops-for-options-migrated-from-pre-0-38-25-docker-options-files
Match docker options by shell word when removing
2026-08-07 15:38:41 -04:00
Jose Diaz-Gonzalez
8d4e7d9793 fix: match docker options by shell word when removing
Options drained out of the pre-0.38.0 `DOCKER_OPTIONS_<PHASE>` files were copied verbatim rather than re-serialized the way `docker-options:add` stores them, so `docker-options:remove` compared the canonical string it builds against a stored value that could never match it and exited successfully without removing anything. Removal now matches stored options by shell word, and stored options are rewritten into the canonical form once on upgrade, which additionally splits an entry that carried several flags on a single line into one entry per flag so a single flag can be removed and so the readers that match on a flag prefix see one value per entry. The leftover `.migrated` sentinel drain is restored to running ahead of the global short-circuit that had made it unreachable, and the plugin's Go tests are added to the test target that had never run them.
2026-08-07 13:35:37 -04:00
Jose Diaz-Gonzalez
30a72f8d95 Merge pull request #8863 from dokku/8862-move-host-crontab-generation-into-the-cron-plugin
Move host-crontab generation into cron plugin
2026-08-07 12:36:40 -04:00
Jose Diaz-Gonzalez
da085c5ebb Merge branch 'master' into 8862-move-host-crontab-generation-into-the-cron-plugin 2026-08-07 12:36:32 -04:00
Jose Diaz-Gonzalez
e9b03e3dd2 Merge pull request #8869 from dokku/dependabot/go_modules/plugins/app-json/github.com/mattn/go-isatty-0.0.24
chore(deps): bump github.com/mattn/go-isatty from 0.0.23 to 0.0.24 in /plugins/app-json
2026-08-07 12:34:25 -04:00
Jose Diaz-Gonzalez
5895c51a4e Merge pull request #8887 from dokku/dependabot/go_modules/plugins/scheduler-k3s/github.com/kedacore/keda/v2-2.20.2
chore(deps): bump github.com/kedacore/keda/v2 from 2.20.1 to 2.20.2 in /plugins/scheduler-k3s
2026-08-07 12:33:51 -04:00
Jose Diaz-Gonzalez
aaa00a4934 Merge pull request #8883 from dokku/chore/bump-docker-container-healthchecker-0.16.0
chore: bump docker-container-healthchecker to 0.16.0
2026-08-07 12:33:44 -04:00
Jose Diaz-Gonzalez
20d6b57355 Merge pull request #8886 from dokku/dependabot/pip/docs/_build/markdown-gte-3.10.3-and-lt-3.11
chore(deps): update markdown requirement from <3.11,>=3.10.2 to >=3.10.3,<3.11 in /docs/_build
2026-08-07 12:28:08 -04:00
Jose Diaz-Gonzalez
5e12f638f4 Merge pull request #8892 from dokku/dependabot/docker/plugins/traefik-vhosts/traefik-v3.7.10
chore(deps): bump traefik from v3.7.9 to v3.7.10 in /plugins/traefik-vhosts
2026-08-07 12:27:06 -04:00
Jose Diaz-Gonzalez
6f867485f1 Merge pull request #8893 from dokku/dependabot/pip/tests/apps/dockerfile-release/django-5.2.17
chore(deps): bump django from 5.2.16 to 5.2.17 in /tests/apps/dockerfile-release
2026-08-07 12:26:39 -04:00
Jose Diaz-Gonzalez
e990d8dbfc Merge pull request #8885 from dokku/chore/bump-dokku-update-0.10.0
chore: bump dokku-update to 0.10.0
2026-08-07 12:25:33 -04:00
Jose Diaz-Gonzalez
9529ca8a3f Merge pull request #8884 from dokku/chore/bump-procfile-util-0.20.8
chore: bump procfile-util to 0.20.8
2026-08-07 12:25:25 -04:00
dependabot[bot]
daee1e6c68 chore(deps): bump github.com/kedacore/keda/v2 in /plugins/scheduler-k3s
Bumps [github.com/kedacore/keda/v2](https://github.com/kedacore/keda) from 2.20.1 to 2.20.2.
- [Release notes](https://github.com/kedacore/keda/releases)
- [Changelog](https://github.com/kedacore/keda/blob/main/CHANGELOG.md)
- [Commits](https://github.com/kedacore/keda/compare/v2.20.1...v2.20.2)

---
updated-dependencies:
- dependency-name: github.com/kedacore/keda/v2
  dependency-version: 2.20.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-08-07 16:25:18 +00:00
dependabot[bot]
6da020a65c chore(deps): bump oras.land/oras-go/v2 in /plugins/scheduler-k3s
Bumps [oras.land/oras-go/v2](https://github.com/oras-project/oras-go) from 2.6.1 to 2.6.2.
- [Release notes](https://github.com/oras-project/oras-go/releases)
- [Changelog](https://github.com/oras-project/oras-go/blob/main/RELEASES.md)
- [Commits](https://github.com/oras-project/oras-go/compare/v2.6.1...v2.6.2)

---
updated-dependencies:
- dependency-name: oras.land/oras-go/v2
  dependency-version: 2.6.2
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-08-07 16:25:07 +00:00
Jose Diaz-Gonzalez
973595e0f2 Merge pull request #8882 from dokku/chore/bump-docker-image-labeler-0.10.0
chore: bump docker-image-labeler to 0.10.0
2026-08-07 12:25:04 -04:00
Jose Diaz-Gonzalez
409d364e81 Merge pull request #8891 from dokku/dependabot/composer/tests/apps/php/heroku/heroku-buildpack-php-294
chore(deps-dev): bump heroku/heroku-buildpack-php from 293 to 294 in /tests/apps/php
2026-08-07 12:24:43 -04:00
Jose Diaz-Gonzalez
b37192a847 Merge pull request #8903 from dokku/scheduler-k3s-sysctls
feat: support kernel sysctls on the k3s scheduler
2026-08-07 12:24:22 -04:00
Jose Diaz-Gonzalez
2ed9294b6b Merge pull request #8888 from dokku/dependabot/go_modules/plugins/scheduler-k3s/github.com/traefik/traefik/v2-2.11.54
chore(deps): bump github.com/traefik/traefik/v2 from 2.11.53 to 2.11.54 in /plugins/scheduler-k3s
2026-08-07 12:22:44 -04:00
Jose Diaz-Gonzalez
2adb01f8c6 Merge pull request #8900 from dokku/chore/bump-gliderlabs-sigil-0.12.1
chore: bump gliderlabs-sigil to 0.12.1
2026-08-07 12:21:49 -04:00
Jose Diaz-Gonzalez
6f4117529a Merge pull request #8899 from dokku/chore/bump-herokuish-0.11.14
chore: bump herokuish to 0.11.14
2026-08-07 12:21:41 -04:00
Jose Diaz-Gonzalez
5741667d16 Merge pull request #8898 from dokku/chore/bump-netrc-0.11.1
chore: bump netrc to 0.11.1
2026-08-07 12:21:33 -04:00
Jose Diaz-Gonzalez
d0d1fc019c Merge pull request #8897 from dokku/chore/bump-dokku-event-listener-0.20.1
chore: bump dokku-event-listener to 0.20.1
2026-08-07 12:21:25 -04:00
Jose Diaz-Gonzalez
9c894401c8 Merge pull request #8896 from dokku/chore/bump-sshcommand-0.20.2
chore: bump sshcommand to 0.20.2
2026-08-07 12:21:16 -04:00
Jose Diaz-Gonzalez
69cff6a6b1 Merge pull request #8895 from dokku/chore/bump-lambda-builder-0.9.4
chore: bump lambda-builder to 0.9.4
2026-08-07 12:21:04 -04:00
Jose Diaz-Gonzalez
ea5e08754d Merge pull request #8894 from dokku/chore/bump-plugn-0.17.1
chore: bump plugn to 0.17.1
2026-08-07 12:20:56 -04:00
Jose Diaz-Gonzalez
44cd566178 feat: manage node-level kernel sysctls on the k3s scheduler
Sysctls the kernel does not namespace, such as `vm.max_map_count`, cannot be set from a pod spec and previously had no answer beyond editing `/etc/sysctl.d` on each host by hand. `scheduler-k3s:node-sysctls:set` now applies them through a privileged daemonset, which reaches nodes joined later and reapplies after a reboot. Sysctls may be scoped to a node profile, with a profile scope inheriting the global values and overriding them on conflict so that every node is covered by exactly one daemonset. Clearing a sysctl stops dokku managing it but does not restore the previous value, which persists until the node reboots.
2026-08-07 09:10:00 -04:00
Jose Diaz-Gonzalez
cd1089500b feat: translate docker-options --sysctl on the k3s scheduler
The `docker-local` scheduler supports `--sysctl` for free because docker options are passed verbatim to `docker run`, but the k3s scheduler silently dropped it. Namespaced sysctls now render into the pod's `securityContext.sysctls` for deployments, cron jobs, and one-off runs. A sysctl the kernel does not namespace fails the deploy instead of being dropped, since it cannot take effect within a pod regardless of what was requested.
2026-08-07 05:43:00 -04:00
Jose Diaz-Gonzalez
f050726f1a feat: label nodes with the node profile they joined with
Node profiles controlled how a node joined the cluster but left no trace on the node afterwards, so a profile could not be selected against with `kubectl`, a `nodeSelector`, or a node affinity rule. Nodes joined without a profile are left unlabeled, and the server node created by `scheduler-k3s:initialize` never carries the label since it does not pass through `scheduler-k3s:cluster:add`.
2026-08-07 02:32:34 -04:00
Jose Diaz-Gonzalez
8e17eee653 feat: add --kubelet-args to scheduler-k3s:initialize
The server node created by `scheduler-k3s:initialize` had no way to receive kubelet arguments, unlike nodes joined through `scheduler-k3s:cluster:add` or configured via `scheduler-k3s:profiles:add`. This meant settings such as `allowed-unsafe-sysctls` were unreachable on a single-node install.
2026-08-07 02:31:12 -04:00
Dokku Bot
bfbfdd3d9e chore: bump gliderlabs-sigil to 0.12.1 2026-08-06 06:55:18 +00:00
Dokku Bot
ac6d2723d9 chore: bump herokuish to 0.11.14 2026-08-06 06:55:16 +00:00
Dokku Bot
ea77396a24 chore: bump netrc to 0.11.1 2026-08-06 06:55:14 +00:00
Dokku Bot
f182ed4ccb chore: bump dokku-event-listener to 0.20.1 2026-08-06 06:55:11 +00:00
Dokku Bot
4de89c28e9 chore: bump sshcommand to 0.20.2 2026-08-06 06:55:09 +00:00
Dokku Bot
43b69c57bc chore: bump lambda-builder to 0.9.4 2026-08-06 06:55:08 +00:00
Dokku Bot
819f32ff86 chore: bump plugn to 0.17.1 2026-08-06 06:55:07 +00:00
dependabot[bot]
c4c61db92b chore(deps): bump django in /tests/apps/dockerfile-release
Bumps [django](https://github.com/django/django) from 5.2.16 to 5.2.17.
- [Commits](https://github.com/django/django/compare/5.2.16...5.2.17)

---
updated-dependencies:
- dependency-name: django
  dependency-version: 5.2.17
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-08-05 13:54:45 +00:00
dependabot[bot]
be619eb999 chore(deps): bump traefik in /plugins/traefik-vhosts
Bumps traefik from v3.7.9 to v3.7.10.

---
updated-dependencies:
- dependency-name: traefik
  dependency-version: v3.7.10
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-08-04 13:54:02 +00:00
dependabot[bot]
85eace7c75 chore(deps-dev): bump heroku/heroku-buildpack-php in /tests/apps/php
Bumps [heroku/heroku-buildpack-php](https://github.com/heroku/heroku-buildpack-php) from 293 to 294.
- [Release notes](https://github.com/heroku/heroku-buildpack-php/releases)
- [Changelog](https://github.com/heroku/heroku-buildpack-php/blob/main/CHANGELOG.md)
- [Commits](https://github.com/heroku/heroku-buildpack-php/compare/v293...v294)

---
updated-dependencies:
- dependency-name: heroku/heroku-buildpack-php
  dependency-version: '294'
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-08-04 13:52:27 +00:00
dependabot[bot]
05c389b586 chore(deps): bump github.com/traefik/traefik/v2
Bumps [github.com/traefik/traefik/v2](https://github.com/traefik/traefik) from 2.11.53 to 2.11.54.
- [Release notes](https://github.com/traefik/traefik/releases)
- [Changelog](https://github.com/traefik/traefik/blob/v2.11.54/CHANGELOG.md)
- [Commits](https://github.com/traefik/traefik/compare/v2.11.53...v2.11.54)

---
updated-dependencies:
- dependency-name: github.com/traefik/traefik/v2
  dependency-version: 2.11.54
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-08-03 13:54:51 +00:00
dependabot[bot]
a29532bd0d chore(deps): update markdown requirement in /docs/_build
Updates the requirements on [markdown](https://github.com/Python-Markdown/markdown) to permit the latest version.
- [Release notes](https://github.com/Python-Markdown/markdown/releases)
- [Changelog](https://github.com/Python-Markdown/markdown/blob/master/docs/changelog.md)
- [Commits](https://github.com/Python-Markdown/markdown/compare/3.10.2...3.10.3)

---
updated-dependencies:
- dependency-name: markdown
  dependency-version: 3.10.3
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-08-03 13:53:48 +00:00
Dokku Bot
e186f7be14 chore: bump dokku-update to 0.10.0 2026-08-03 07:08:32 +00:00
Dokku Bot
d1aa41e4f1 chore: bump procfile-util to 0.20.8 2026-08-02 06:53:58 +00:00
Dokku Bot
49f9d63760 chore: bump docker-container-healthchecker to 0.16.0 2026-08-02 06:53:54 +00:00
Dokku Bot
d17a538a2c chore: bump docker-image-labeler to 0.10.0 2026-08-02 06:53:52 +00:00
Jose Diaz-Gonzalez
52f869d7b1 chore: bump go modules 2026-08-01 16:29:09 -04:00
dependabot[bot]
9f1f19a58d chore(deps): bump github.com/mattn/go-isatty in /plugins/app-json
Bumps [github.com/mattn/go-isatty](https://github.com/mattn/go-isatty) from 0.0.23 to 0.0.24.
- [Commits](https://github.com/mattn/go-isatty/compare/v0.0.23...v0.0.24)

---
updated-dependencies:
- dependency-name: github.com/mattn/go-isatty
  dependency-version: 0.0.24
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-08-01 16:29:09 -04:00
Jose Diaz-Gonzalez
28b4126091 Merge pull request #8876 from dokku/dependabot/go_modules/plugins/scheduler-k3s/github.com/cert-manager/cert-manager-1.21.1
chore(deps): bump github.com/cert-manager/cert-manager from 1.21.0 to 1.21.1 in /plugins/scheduler-k3s
2026-07-31 13:25:22 -04:00
Jose Diaz-Gonzalez
ef50c72a28 Merge pull request #8877 from dokku/dependabot/go_modules/tests/apps/gogrpc/google.golang.org/grpc-1.83.0
chore(deps): bump google.golang.org/grpc from 1.82.1 to 1.83.0 in /tests/apps/gogrpc
2026-07-31 13:25:13 -04:00
Jose Diaz-Gonzalez
3b5b2e32be Merge pull request #8881 from dokku/josegonzalez-patch-1
Ignore minor and patch updates for github actions
2026-07-31 13:24:49 -04:00
Jose Diaz-Gonzalez
87fe6e6925 chore: ignore minor and patch updates for github actions
Add ignore rules for minor and patch updates in Dependabot configuration.
2026-07-31 13:24:06 -04:00
dependabot[bot]
0e4347cb3e chore(deps): bump google.golang.org/grpc in /tests/apps/gogrpc
Bumps [google.golang.org/grpc](https://github.com/grpc/grpc-go) from 1.82.1 to 1.83.0.
- [Release notes](https://github.com/grpc/grpc-go/releases)
- [Commits](https://github.com/grpc/grpc-go/compare/v1.82.1...v1.83.0)

---
updated-dependencies:
- dependency-name: google.golang.org/grpc
  dependency-version: 1.83.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-30 13:52:21 +00:00
dependabot[bot]
fbcfbce944 chore(deps): bump github.com/cert-manager/cert-manager
Bumps [github.com/cert-manager/cert-manager](https://github.com/cert-manager/cert-manager) from 1.21.0 to 1.21.1.
- [Release notes](https://github.com/cert-manager/cert-manager/releases)
- [Changelog](https://github.com/cert-manager/cert-manager/blob/master/RELEASE.md)
- [Commits](https://github.com/cert-manager/cert-manager/compare/v1.21.0...v1.21.1)

---
updated-dependencies:
- dependency-name: github.com/cert-manager/cert-manager
  dependency-version: 1.21.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-29 13:54:14 +00:00
Jose Diaz-Gonzalez
50583b3376 Merge pull request #8874 from dokku/dependabot/npm_and_yarn/tests/apps/multi/sass-1.102.0
chore(deps): bump sass from 1.101.7 to 1.102.0 in /tests/apps/multi
2026-07-27 19:14:59 -04:00
Jose Diaz-Gonzalez
0672a89757 Merge pull request #8873 from dokku/dependabot/docker/plugins/traefik-vhosts/traefik-v3.7.9
chore(deps): bump traefik from v3.7.8 to v3.7.9 in /plugins/traefik-vhosts
2026-07-27 19:14:52 -04:00
dependabot[bot]
276f613be1 chore(deps): bump sass from 1.101.7 to 1.102.0 in /tests/apps/multi
Bumps [sass](https://github.com/sass/dart-sass) from 1.101.7 to 1.102.0.
- [Release notes](https://github.com/sass/dart-sass/releases)
- [Changelog](https://github.com/sass/dart-sass/blob/main/CHANGELOG.md)
- [Commits](https://github.com/sass/dart-sass/compare/1.101.7...1.102.0)

---
updated-dependencies:
- dependency-name: sass
  dependency-version: 1.102.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-27 13:54:13 +00:00
dependabot[bot]
5ed560eb36 chore(deps): bump traefik in /plugins/traefik-vhosts
Bumps traefik from v3.7.8 to v3.7.9.

---
updated-dependencies:
- dependency-name: traefik
  dependency-version: v3.7.9
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-27 13:53:31 +00:00
Jose Diaz-Gonzalez
ad5107d09d Merge pull request #8872 from dokku/dependabot/go_modules/plugins/scheduler-k3s/github.com/traefik/traefik/v2-2.11.53
chore(deps): bump github.com/traefik/traefik/v2 from 2.11.52 to 2.11.53 in /plugins/scheduler-k3s
2026-07-24 13:57:37 -04:00
Jose Diaz-Gonzalez
3590d5a19e Merge pull request #8870 from dokku/dependabot/npm_and_yarn/tests/apps/multi/sass-1.101.7
chore(deps): bump sass from 1.101.6 to 1.101.7 in /tests/apps/multi
2026-07-24 11:49:57 -04:00
Jose Diaz-Gonzalez
5acac54752 Merge pull request #8871 from dokku/dependabot/go_modules/plugins/scheduler-k3s/k8s.io/kubernetes-1.36.3
chore(deps): bump k8s.io/kubernetes from 1.36.2 to 1.36.3 in /plugins/scheduler-k3s
2026-07-24 11:49:48 -04:00
dependabot[bot]
e2214e281a chore(deps): bump github.com/traefik/traefik/v2
Bumps [github.com/traefik/traefik/v2](https://github.com/traefik/traefik) from 2.11.52 to 2.11.53.
- [Release notes](https://github.com/traefik/traefik/releases)
- [Changelog](https://github.com/traefik/traefik/blob/v2.11.53/CHANGELOG.md)
- [Commits](https://github.com/traefik/traefik/compare/v2.11.52...v2.11.53)

---
updated-dependencies:
- dependency-name: github.com/traefik/traefik/v2
  dependency-version: 2.11.53
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-24 13:55:05 +00:00
dependabot[bot]
867924b080 chore(deps): bump k8s.io/kubernetes in /plugins/scheduler-k3s
Bumps [k8s.io/kubernetes](https://github.com/kubernetes/kubernetes) from 1.36.2 to 1.36.3.
- [Release notes](https://github.com/kubernetes/kubernetes/releases)
- [Commits](https://github.com/kubernetes/kubernetes/compare/v1.36.2...v1.36.3)

---
updated-dependencies:
- dependency-name: k8s.io/kubernetes
  dependency-version: 1.36.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-24 13:54:46 +00:00
dependabot[bot]
52a44467f9 chore(deps): bump sass from 1.101.6 to 1.101.7 in /tests/apps/multi
Bumps [sass](https://github.com/sass/dart-sass) from 1.101.6 to 1.101.7.
- [Release notes](https://github.com/sass/dart-sass/releases)
- [Changelog](https://github.com/sass/dart-sass/blob/main/CHANGELOG.md)
- [Commits](https://github.com/sass/dart-sass/compare/1.101.6...1.101.7)

---
updated-dependencies:
- dependency-name: sass
  dependency-version: 1.101.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-24 13:54:09 +00:00
Jose Diaz-Gonzalez
d9ef6ced6e Merge pull request #8868 from dokku/dependabot/go_modules/plugins/scheduler-k3s/k8s.io/kubectl-0.36.3
chore(deps): bump k8s.io/kubectl from 0.36.2 to 0.36.3 in /plugins/scheduler-k3s
2026-07-24 00:18:49 -04:00
dependabot[bot]
230a63e3c0 chore(deps): bump k8s.io/kubectl in /plugins/scheduler-k3s
Bumps [k8s.io/kubectl](https://github.com/kubernetes/kubectl) from 0.36.2 to 0.36.3.
- [Commits](https://github.com/kubernetes/kubectl/compare/v0.36.2...v0.36.3)

---
updated-dependencies:
- dependency-name: k8s.io/kubectl
  dependency-version: 0.36.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-24 02:23:01 +00:00
Jose Diaz-Gonzalez
f921e1e1eb Merge pull request #8867 from dokku/dependabot/go_modules/plugins/scheduler-k3s/k8s.io/client-go-0.36.3
chore(deps): bump k8s.io/client-go from 0.36.2 to 0.36.3 in /plugins/scheduler-k3s
2026-07-23 22:21:40 -04:00
Jose Diaz-Gonzalez
9f4317707e Merge pull request #8866 from dokku/dependabot/npm_and_yarn/tests/apps/multi/sass-1.101.6
chore(deps): bump sass from 1.101.3 to 1.101.6 in /tests/apps/multi
2026-07-23 22:20:19 -04:00
dependabot[bot]
ce88f439dd chore(deps): bump k8s.io/client-go in /plugins/scheduler-k3s
Bumps [k8s.io/client-go](https://github.com/kubernetes/client-go) from 0.36.2 to 0.36.3.
- [Changelog](https://github.com/kubernetes/client-go/blob/master/CHANGELOG.md)
- [Commits](https://github.com/kubernetes/client-go/compare/v0.36.2...v0.36.3)

---
updated-dependencies:
- dependency-name: k8s.io/client-go
  dependency-version: 0.36.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-23 13:54:23 +00:00
dependabot[bot]
64785ca0ee chore(deps): bump sass from 1.101.3 to 1.101.6 in /tests/apps/multi
Bumps [sass](https://github.com/sass/dart-sass) from 1.101.3 to 1.101.6.
- [Release notes](https://github.com/sass/dart-sass/releases)
- [Changelog](https://github.com/sass/dart-sass/blob/main/CHANGELOG.md)
- [Commits](https://github.com/sass/dart-sass/compare/1.101.3...1.101.6)

---
updated-dependencies:
- dependency-name: sass
  dependency-version: 1.101.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-23 13:54:09 +00:00
Jose Diaz-Gonzalez
a78da9abdf Merge pull request #8865 from dokku/dependabot/go_modules/plugins/scheduler-k3s/github.com/fluxcd/pkg/kustomize-1.39.0
chore(deps): bump github.com/fluxcd/pkg/kustomize from 1.38.0 to 1.39.0 in /plugins/scheduler-k3s
2026-07-23 08:52:10 -04:00
Jose Diaz-Gonzalez
022c6be3eb Merge pull request #8864 from dokku/dependabot/pip/docs/_build/soupsieve-2.9.1
chore(deps): bump soupsieve from 2.9 to 2.9.1 in /docs/_build
2026-07-23 08:51:43 -04:00
dependabot[bot]
b925ad0be9 chore(deps): bump github.com/fluxcd/pkg/kustomize
Bumps [github.com/fluxcd/pkg/kustomize](https://github.com/fluxcd/pkg) from 1.38.0 to 1.39.0.
- [Commits](https://github.com/fluxcd/pkg/compare/kustomize/v1.38.0...kustomize/v1.39.0)

---
updated-dependencies:
- dependency-name: github.com/fluxcd/pkg/kustomize
  dependency-version: 1.39.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-22 13:54:29 +00:00
dependabot[bot]
716ad744b8 chore(deps): bump soupsieve from 2.9 to 2.9.1 in /docs/_build
Bumps [soupsieve](https://github.com/facelessuser/soupsieve) from 2.9 to 2.9.1.
- [Release notes](https://github.com/facelessuser/soupsieve/releases)
- [Commits](https://github.com/facelessuser/soupsieve/compare/2.9...2.9.1)

---
updated-dependencies:
- dependency-name: soupsieve
  dependency-version: 2.9.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-22 13:53:32 +00:00
Jose Diaz-Gonzalez
c6b4ea75c1 refactor: move host-crontab generation into cron plugin
Host-crontab generation for `app.json` cron tasks now lives in the `cron` plugin, gated by a new `scheduler-uses-host-cron` trigger that the `docker-local` scheduler answers true while self-managed schedulers such as `k3s` answer false. This lets any host-cron scheduler participate in normal `app.json` cron without coupling to `scheduler-docker-local` or duplicating the crontab writer, while the `k3s` scheduler continues to manage its own in-cluster cron jobs.

Closes #8862.
2026-07-22 08:35:11 -04:00
Jose Diaz-Gonzalez
e3687a62ed Merge pull request #8856 from youdie006/feat/ports-parsed-mappings
Add pre-parsed port_mappings to ports:report json
2026-07-22 04:57:13 -04:00
Jose Diaz-Gonzalez
9c61031f3e docs: add docs and tests for this feature 2026-07-22 03:45:32 -04:00
youdie006
3f13949337 feat: add pre-parsed json string version of port mappings 2026-07-22 03:24:45 -04:00
Jose Diaz-Gonzalez
e7df3a5fd6 Merge pull request #8860 from dokku/dependabot/pip/tests/apps/dockerfile-release/setuptools-83.0.0
chore(deps): bump setuptools from 78.1.1 to 83.0.0 in /tests/apps/dockerfile-release
2026-07-22 03:17:18 -04:00
Jose Diaz-Gonzalez
9e246e2114 Merge pull request #8859 from dokku/dependabot/npm_and_yarn/tests/apps/multi/immutable-5.1.9
chore(deps): bump immutable from 5.1.5 to 5.1.9 in /tests/apps/multi
2026-07-22 03:16:52 -04:00
Jose Diaz-Gonzalez
f440c7794e Merge pull request #8855 from dokku/dependabot/npm_and_yarn/tests/apps/multi/sass-1.101.3
chore(deps): bump sass from 1.101.0 to 1.101.3 in /tests/apps/multi
2026-07-22 03:16:38 -04:00
Jose Diaz-Gonzalez
6116edf16a Merge pull request #8858 from bakatz/patch-3
Added instructions for restoring backups on different CPU architectures.
2026-07-22 03:16:27 -04:00
Jose Diaz-Gonzalez
d2f84a8a1f docs: just remove the directory
We don't use basher, `plugn` actually extracts it from `progrium/go-basher` live.
2026-07-22 03:13:59 -04:00
dependabot[bot]
3bf1079926 chore(deps): bump setuptools in /tests/apps/dockerfile-release
Bumps [setuptools](https://github.com/pypa/setuptools) from 78.1.1 to 83.0.0.
- [Release notes](https://github.com/pypa/setuptools/releases)
- [Changelog](https://github.com/pypa/setuptools/blob/main/NEWS.rst)
- [Commits](https://github.com/pypa/setuptools/compare/v78.1.1...v83.0.0)

---
updated-dependencies:
- dependency-name: setuptools
  dependency-version: 83.0.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-22 07:13:34 +00:00
dependabot[bot]
878ca3c2f7 chore(deps): bump immutable from 5.1.5 to 5.1.9 in /tests/apps/multi
Bumps [immutable](https://github.com/immutable-js/immutable-js) from 5.1.5 to 5.1.9.
- [Release notes](https://github.com/immutable-js/immutable-js/releases)
- [Changelog](https://github.com/immutable-js/immutable-js/blob/main/CHANGELOG.md)
- [Commits](https://github.com/immutable-js/immutable-js/compare/v5.1.5...v5.1.9)

---
updated-dependencies:
- dependency-name: immutable
  dependency-version: 5.1.9
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-22 07:13:25 +00:00
Jose Diaz-Gonzalez
d39064058b Merge pull request #8857 from dokku/dependabot/npm_and_yarn/tests/apps/checks-root/body-parser-2.3.0
chore(deps): bump body-parser from 2.2.1 to 2.3.0 in /tests/apps/checks-root
2026-07-22 03:12:12 -04:00
Jose Diaz-Gonzalez
3c5b03f4ec Merge pull request #8854 from dokku/dependabot/docker/docs/_build/python-3.15.0b4-alpine
chore(deps): bump python from 3.15.0b3-alpine to 3.15.0b4-alpine in /docs/_build
2026-07-22 03:12:04 -04:00
Jose Diaz-Gonzalez
46b6057e97 Merge pull request #8853 from dokku/dependabot/docker/tests/apps/dockerfile-release/python-3.15.0b4-bookworm
chore(deps): bump python from 3.15.0b3-bookworm to 3.15.0b4-bookworm in /tests/apps/dockerfile-release
2026-07-22 03:11:53 -04:00
Ben Katz
bc0104137d Added instructions for restoring backups on different CPU architectures. 2026-07-21 21:56:22 -04:00
dependabot[bot]
3542acc271 chore(deps): bump body-parser in /tests/apps/checks-root
Bumps [body-parser](https://github.com/expressjs/body-parser) from 2.2.1 to 2.3.0.
- [Release notes](https://github.com/expressjs/body-parser/releases)
- [Changelog](https://github.com/expressjs/body-parser/blob/master/HISTORY.md)
- [Commits](https://github.com/expressjs/body-parser/compare/v2.2.1...v2.3.0)

---
updated-dependencies:
- dependency-name: body-parser
  dependency-version: 2.3.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-21 19:58:27 +00:00
dependabot[bot]
64e7654453 chore(deps): bump sass from 1.101.0 to 1.101.3 in /tests/apps/multi
Bumps [sass](https://github.com/sass/dart-sass) from 1.101.0 to 1.101.3.
- [Release notes](https://github.com/sass/dart-sass/releases)
- [Changelog](https://github.com/sass/dart-sass/blob/main/CHANGELOG.md)
- [Commits](https://github.com/sass/dart-sass/compare/1.101.0...1.101.3)

---
updated-dependencies:
- dependency-name: sass
  dependency-version: 1.101.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-21 13:54:12 +00:00
dependabot[bot]
c4af39ff8f chore(deps): bump python in /docs/_build
Bumps python from 3.15.0b3-alpine to 3.15.0b4-alpine.

---
updated-dependencies:
- dependency-name: python
  dependency-version: 3.15.0b4-alpine
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-21 13:53:18 +00:00
dependabot[bot]
e746ea98f8 chore(deps): bump python in /tests/apps/dockerfile-release
Bumps python from 3.15.0b3-bookworm to 3.15.0b4-bookworm.

---
updated-dependencies:
- dependency-name: python
  dependency-version: 3.15.0b4-bookworm
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-21 13:53:08 +00:00
Jose Diaz-Gonzalez
491fae6c00 Merge pull request #8852 from dokku/dependabot/pip/docs/_build/soupsieve-2.9
chore(deps): bump soupsieve from 2.8.4 to 2.9 in /docs/_build
2026-07-20 12:12:39 -04:00
Jose Diaz-Gonzalez
2fc0a0ee9c Merge pull request #8851 from dokku/dependabot/pip/docs/_build/mkdocs-material-9.7.7
chore(deps): bump mkdocs-material from 9.7.6 to 9.7.7 in /docs/_build
2026-07-20 12:12:33 -04:00
Jose Diaz-Gonzalez
636558bb28 Merge pull request #8850 from dokku/dependabot/github_actions/actions/setup-python-7
chore(deps): bump actions/setup-python from 6 to 7
2026-07-20 12:12:24 -04:00
dependabot[bot]
43f097e62f chore(deps): bump soupsieve from 2.8.4 to 2.9 in /docs/_build
Bumps [soupsieve](https://github.com/facelessuser/soupsieve) from 2.8.4 to 2.9.
- [Release notes](https://github.com/facelessuser/soupsieve/releases)
- [Commits](https://github.com/facelessuser/soupsieve/compare/2.8.4...2.9)

---
updated-dependencies:
- dependency-name: soupsieve
  dependency-version: '2.9'
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-20 13:53:37 +00:00
dependabot[bot]
e3c329c96b chore(deps): bump mkdocs-material from 9.7.6 to 9.7.7 in /docs/_build
Bumps [mkdocs-material](https://github.com/squidfunk/mkdocs-material) from 9.7.6 to 9.7.7.
- [Release notes](https://github.com/squidfunk/mkdocs-material/releases)
- [Changelog](https://github.com/squidfunk/mkdocs-material/blob/master/CHANGELOG)
- [Commits](https://github.com/squidfunk/mkdocs-material/compare/9.7.6...9.7.7)

---
updated-dependencies:
- dependency-name: mkdocs-material
  dependency-version: 9.7.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-20 13:53:32 +00:00
dependabot[bot]
c9e35498be chore(deps): bump actions/setup-python from 6 to 7
Bumps [actions/setup-python](https://github.com/actions/setup-python) from 6 to 7.
- [Release notes](https://github.com/actions/setup-python/releases)
- [Commits](https://github.com/actions/setup-python/compare/v6...v7)

---
updated-dependencies:
- dependency-name: actions/setup-python
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-20 13:52:34 +00:00
Dokku Bot
0537c8d153 Release 0.38.25
# History

## 0.38.25

Install/update via the bootstrap script:

```shell
wget -NP . https://dokku.com/install/v0.38.25/bootstrap.sh
sudo DOKKU_TAG=v0.38.25 bash bootstrap.sh
```

### Security

- #8848: @josegonzalez Prevent command injection via docker options eval

### New Features

- #8849: @josegonzalez Support per-app letsencrypt emails on k3s
2026-07-19 09:36:27 +00:00
Jose Diaz-Gonzalez
7b8c8169e7 Merge pull request #8849 from dokku/k3s-per-app-letsencrypt 2026-07-19 05:34:57 -04:00
Jose Diaz-Gonzalez
90831a5504 fix: guard k3s issuer template against absent values
The `issuer.yaml` chart template dereferenced `.Values.global.issuer.enabled` without guarding against the value being absent, which yaml serialization omitted for apps without a per-app email, causing a nil-pointer render error that broke every k3s web deploy.
2026-07-19 04:34:40 -04:00
Jose Diaz-Gonzalez
dc802ddd19 feat: support per-app letsencrypt emails on k3s
The `letsencrypt-email-prod` and `letsencrypt-email-stag` properties can now be set per app in addition to globally, resolving app-level before the global value for the app's selected `letsencrypt-server`. An app that sets its own email renders a namespaced cert-manager `Issuer` using that email, while apps without an override continue to use the shared `ClusterIssuer` with the global email.
2026-07-19 03:31:55 -04:00
Jose Diaz-Gonzalez
05ce8fb68e Merge pull request #8848 from dokku/host-command-execution-via-eval-of-unsanitized-docker-options-in-dockerargs
Prevent command injection via docker options eval
2026-07-19 02:42:39 -04:00
Jose Diaz-Gonzalez
1a376c3622 fix: prevent command injection via docker options eval
Values supplied through docker options, `--ttl-seconds`, and `-e` flowed into a Bash `eval` during build, deploy, and run, letting a low-privileged user execute arbitrary commands on the host as the dokku user. These arguments are now tokenized and passed through to the container verbatim, without shell expansion. A one-time migration repairs stored labels whose backticks were saved with a stray backslash so Traefik-style rules stay valid on the next deploy.
2026-07-19 01:42:12 -04:00
Dokku Bot
730fa85d03 Release 0.38.24
# History

## 0.38.24

Install/update via the bootstrap script:

```shell
wget -NP . https://dokku.com/install/v0.38.24/bootstrap.sh
sudo DOKKU_TAG=v0.38.24 bash bootstrap.sh
```

### Documentation

- #8836: @josegonzalez Link herokuish buildpack references to buildpack management page

### Tests

- #8841: @dependabot[bot] chore(deps): bump ruby from 4.0.5 to 4.0.6 in /tests/apps/dockerfile-entrypoint
- #8843: @dependabot[bot] chore(deps): bump google.golang.org/grpc from 1.82.0 to 1.82.1 in /tests/apps/gogrpc

### Dependencies

- #8845: @dependabot[bot] chore(deps): bump github.com/mattn/go-isatty from 0.0.22 to 0.0.23 in /plugins/app-json
- #8844: @dependabot[bot] chore(deps): bump github.com/melbahja/goph from 1.5.1 to 1.5.2 in /plugins/common
- #8842: @dependabot[bot] chore(deps): bump timberio/vector from 0.56.0-debian to 0.57.0-debian in /plugins/logs
- #8838: @dokku-bot chore: bump pack to 0.40.8
- #8846: @dependabot[bot] chore(deps): bump traefik from v3.7.7 to v3.7.8 in /plugins/traefik-vhosts
- #8839: @dependabot[bot] chore(deps): bump actions/setup-node from 6 to 7
- #8834: @dokku-bot chore: bump dokku-event-listener to 0.20.0
2026-07-18 01:39:15 +00:00
Jose Diaz-Gonzalez
2950292309 Merge pull request #8845 from dokku/dependabot/go_modules/plugins/app-json/github.com/mattn/go-isatty-0.0.23
chore(deps): bump github.com/mattn/go-isatty from 0.0.22 to 0.0.23 in /plugins/app-json
2026-07-17 21:34:41 -04:00
dependabot[bot]
fb5a1e12e6 chore(deps): bump github.com/mattn/go-isatty in /plugins/app-json
Bumps [github.com/mattn/go-isatty](https://github.com/mattn/go-isatty) from 0.0.22 to 0.0.23.
- [Commits](https://github.com/mattn/go-isatty/compare/v0.0.22...v0.0.23)

---
updated-dependencies:
- dependency-name: github.com/mattn/go-isatty
  dependency-version: 0.0.23
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-17 21:33:26 -04:00
Jose Diaz-Gonzalez
e3ad4b3bcc Merge pull request #8844 from dokku/dependabot/go_modules/plugins/common/github.com/melbahja/goph-1.5.2
chore(deps): bump github.com/melbahja/goph from 1.5.1 to 1.5.2 in /plugins/common
2026-07-17 21:32:08 -04:00
Jose Diaz-Gonzalez
debb1b8f27 chore: bump go modules 2026-07-17 21:21:55 -04:00
Jose Diaz-Gonzalez
7c7af5767a Merge pull request #8842 from dokku/dependabot/docker/plugins/logs/timberio/vector-0.57.0-debian
chore(deps): bump timberio/vector from 0.56.0-debian to 0.57.0-debian in /plugins/logs
2026-07-17 10:45:11 -04:00
Jose Diaz-Gonzalez
f1f90233f6 Merge pull request #8841 from dokku/dependabot/docker/tests/apps/dockerfile-entrypoint/ruby-4.0.6
chore(deps): bump ruby from 4.0.5 to 4.0.6 in /tests/apps/dockerfile-entrypoint
2026-07-17 10:45:05 -04:00
Jose Diaz-Gonzalez
3402185c6f Merge pull request #8838 from dokku/chore/bump-pack-0.40.8
chore: bump pack to 0.40.8
2026-07-17 10:44:59 -04:00
Jose Diaz-Gonzalez
63b9a93e4e Merge pull request #8843 from dokku/dependabot/go_modules/tests/apps/gogrpc/google.golang.org/grpc-1.82.1
chore(deps): bump google.golang.org/grpc from 1.82.0 to 1.82.1 in /tests/apps/gogrpc
2026-07-17 10:43:18 -04:00
Jose Diaz-Gonzalez
7f33ac8edf Merge pull request #8846 from dokku/dependabot/docker/plugins/traefik-vhosts/traefik-v3.7.8
chore(deps): bump traefik from v3.7.7 to v3.7.8 in /plugins/traefik-vhosts
2026-07-17 10:41:08 -04:00
dependabot[bot]
177cc81dae chore(deps): bump traefik in /plugins/traefik-vhosts
Bumps traefik from v3.7.7 to v3.7.8.

---
updated-dependencies:
- dependency-name: traefik
  dependency-version: v3.7.8
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-16 13:54:04 +00:00
dependabot[bot]
3124fdc2b0 chore(deps): bump github.com/melbahja/goph in /plugins/common
Bumps [github.com/melbahja/goph](https://github.com/melbahja/goph) from 1.5.1 to 1.5.2.
- [Release notes](https://github.com/melbahja/goph/releases)
- [Commits](https://github.com/melbahja/goph/compare/v1.5.1...v1.5.2)

---
updated-dependencies:
- dependency-name: github.com/melbahja/goph
  dependency-version: 1.5.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-16 13:53:44 +00:00
dependabot[bot]
22718c10d7 chore(deps): bump google.golang.org/grpc in /tests/apps/gogrpc
Bumps [google.golang.org/grpc](https://github.com/grpc/grpc-go) from 1.82.0 to 1.82.1.
- [Release notes](https://github.com/grpc/grpc-go/releases)
- [Commits](https://github.com/grpc/grpc-go/compare/v1.82.0...v1.82.1)

---
updated-dependencies:
- dependency-name: google.golang.org/grpc
  dependency-version: 1.82.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-16 13:52:23 +00:00
dependabot[bot]
0f54c6f26e chore(deps): bump timberio/vector in /plugins/logs
Bumps timberio/vector from 0.56.0-debian to 0.57.0-debian.

---
updated-dependencies:
- dependency-name: timberio/vector
  dependency-version: 0.57.0-debian
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-15 13:53:35 +00:00
dependabot[bot]
90d76060fe chore(deps): bump ruby in /tests/apps/dockerfile-entrypoint
Bumps ruby from 4.0.5 to 4.0.6.

---
updated-dependencies:
- dependency-name: ruby
  dependency-version: 4.0.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-15 13:52:31 +00:00
Dokku Bot
ce76bcd772 chore: bump pack to 0.40.8 2026-07-15 06:46:10 +00:00
Jose Diaz-Gonzalez
0bf2df49c2 Merge pull request #8839 from dokku/dependabot/github_actions/actions/setup-node-7
chore(deps): bump actions/setup-node from 6 to 7
2026-07-14 14:01:01 -04:00
dependabot[bot]
2352c09d2a chore(deps): bump actions/setup-node from 6 to 7
Bumps [actions/setup-node](https://github.com/actions/setup-node) from 6 to 7.
- [Release notes](https://github.com/actions/setup-node/releases)
- [Commits](https://github.com/actions/setup-node/compare/v6...v7)

---
updated-dependencies:
- dependency-name: actions/setup-node
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-14 13:52:30 +00:00
Jose Diaz-Gonzalez
9847412990 Merge pull request #8836 from dokku/8835-herokuish-documentation-references-the-wrong-page-for-buildpack-management
Link herokuish buildpack references to buildpack management page
2026-07-12 21:26:28 -04:00
Jose Diaz-Gonzalez
9f8ef83a02 docs: link herokuish buildpack references to buildpack management page
The Herokuish Buildpacks doc linked buildpack topics to anchors on the process management page that do not exist, so those links resolved to the wrong page. Point them at the corresponding sections of the buildpack management page and add that page to the sidebar so it is reachable.
2026-07-12 21:24:38 -04:00
Jose Diaz-Gonzalez
9021ddcdca Merge pull request #8834 from dokku/chore/bump-dokku-event-listener-0.20.0
chore: bump dokku-event-listener to 0.20.0
2026-07-11 05:07:23 -04:00
Dokku Bot
5880ebc298 chore: bump dokku-event-listener to 0.20.0 2026-07-11 06:46:30 +00:00
Dokku Bot
0764529d23 Release 0.38.23
# History

## 0.38.23

Install/update via the bootstrap script:

```shell
wget -NP . https://dokku.com/install/v0.38.23/bootstrap.sh
sudo DOKKU_TAG=v0.38.23 bash bootstrap.sh
```

### Bug Fixes

- #8833: @josegonzalez Parse cert CN and subject on OpenSSL 3.x

### Tests

- #8825: @dependabot[bot] chore(deps): bump golang from 1.26.4 to 1.26.5 in /tests/apps/zombies-dockerfile-no-tini
- #8823: @dependabot[bot] chore(deps): bump golang from 1.26.4 to 1.26.5 in /tests/apps/zombies-dockerfile-tini
- #8820: @dependabot[bot] chore(deps-dev): bump heroku/heroku-buildpack-php from 292 to 293 in /tests/apps/php
- #8821: @dependabot[bot] chore(deps): bump golang from 1.26.4 to 1.26.5 in /tests/apps/go-fail-predeploy
- #8822: @dependabot[bot] chore(deps): bump golang from 1.26.4 to 1.26.5 in /tests/apps/gogrpc
- #8824: @dependabot[bot] chore(deps): bump golang from 1.26.4 to 1.26.5 in /tests/apps/go-fail-postdeploy

### Dependencies

- #8831: @dependabot[bot] chore(deps): bump helm.sh/helm/v3 from 3.21.2 to 3.21.3 in /plugins/scheduler-k3s
- #8830: @dependabot[bot] chore(deps): bump github.com/fluxcd/pkg/kustomize from 1.37.0 to 1.38.0 in /plugins/scheduler-k3s
- #8826: @dependabot[bot] chore(deps): bump golang.org/x/crypto from 0.53.0 to 0.54.0 in /plugins/common
- #8827: @dependabot[bot] chore(deps): bump github.com/cert-manager/cert-manager from 1.20.3 to 1.21.0 in /plugins/scheduler-k3s
- #8828: @dependabot[bot] chore(deps): bump traefik from v3.7.6 to v3.7.7 in /plugins/traefik-vhosts
- #8829: @dependabot[bot] chore(deps): bump github.com/go-openapi/jsonpointer from 0.24.0 to 1.0.0 in /plugins/scheduler-k3s
2026-07-10 22:48:15 +00:00
Jose Diaz-Gonzalez
e40d325996 Merge pull request #8833 from dokku/8832-cn-and-subject-parsing-broken-on-openssl-3-x-get-ssl-hostnames-reportsslhostnames-reportsslsubject
Parse cert CN and subject on OpenSSL 3.x
2026-07-10 17:45:02 -04:00
Jose Diaz-Gonzalez
5496029e07 fix: parse cert CN and subject on OpenSSL 3.x
The `certs` plugin extracted a certificate's Common Name and formatted its subject using string assumptions that only held for pre-3.x OpenSSL output, so a certificate with only a Common Name and no Subject Alternative Name reported no hostnames from `certs:report` and was not recognized during nginx config generation, while the subject report retained the `subject=` prefix and used the wrong separators. Normalizing the subject with `-nameopt` before parsing makes the extraction version independent across OpenSSL and LibreSSL.
2026-07-10 15:05:27 -04:00
Jose Diaz-Gonzalez
e47bae8f55 Merge pull request #8831 from dokku/dependabot/go_modules/plugins/scheduler-k3s/helm.sh/helm/v3-3.21.3
chore(deps): bump helm.sh/helm/v3 from 3.21.2 to 3.21.3 in /plugins/scheduler-k3s
2026-07-10 12:22:36 -04:00
Jose Diaz-Gonzalez
b01ec9be48 Merge pull request #8830 from dokku/dependabot/go_modules/plugins/scheduler-k3s/github.com/fluxcd/pkg/kustomize-1.38.0
chore(deps): bump github.com/fluxcd/pkg/kustomize from 1.37.0 to 1.38.0 in /plugins/scheduler-k3s
2026-07-10 12:22:27 -04:00
dependabot[bot]
3ca52407ed chore(deps): bump helm.sh/helm/v3 in /plugins/scheduler-k3s
Bumps [helm.sh/helm/v3](https://github.com/helm/helm) from 3.21.2 to 3.21.3.
- [Release notes](https://github.com/helm/helm/releases)
- [Commits](https://github.com/helm/helm/compare/v3.21.2...v3.21.3)

---
updated-dependencies:
- dependency-name: helm.sh/helm/v3
  dependency-version: 3.21.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-10 13:53:59 +00:00
dependabot[bot]
2191bafd77 chore(deps): bump github.com/fluxcd/pkg/kustomize
Bumps [github.com/fluxcd/pkg/kustomize](https://github.com/fluxcd/pkg) from 1.37.0 to 1.38.0.
- [Commits](https://github.com/fluxcd/pkg/compare/kustomize/v1.37.0...kustomize/v1.38.0)

---
updated-dependencies:
- dependency-name: github.com/fluxcd/pkg/kustomize
  dependency-version: 1.38.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-10 13:53:51 +00:00
Jose Diaz-Gonzalez
e79dd1b493 Merge pull request #8826 from dokku/dependabot/go_modules/plugins/common/golang.org/x/crypto-0.54.0
chore(deps): bump golang.org/x/crypto from 0.53.0 to 0.54.0 in /plugins/common
2026-07-09 21:34:30 -04:00
Jose Diaz-Gonzalez
5da5f1dfe6 chore: bump go modules 2026-07-09 21:16:42 -04:00
dependabot[bot]
26914b2fc0 chore(deps): bump golang.org/x/crypto in /plugins/common
Bumps [golang.org/x/crypto](https://github.com/golang/crypto) from 0.53.0 to 0.54.0.
- [Commits](https://github.com/golang/crypto/compare/v0.53.0...v0.54.0)

---
updated-dependencies:
- dependency-name: golang.org/x/crypto
  dependency-version: 0.54.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-09 21:16:29 -04:00
Jose Diaz-Gonzalez
7bd866efee Merge pull request #8825 from dokku/dependabot/docker/tests/apps/zombies-dockerfile-no-tini/golang-1.26.5
chore(deps): bump golang from 1.26.4 to 1.26.5 in /tests/apps/zombies-dockerfile-no-tini
2026-07-09 21:14:44 -04:00
Jose Diaz-Gonzalez
4205871cec Merge pull request #8823 from dokku/dependabot/docker/tests/apps/zombies-dockerfile-tini/golang-1.26.5
chore(deps): bump golang from 1.26.4 to 1.26.5 in /tests/apps/zombies-dockerfile-tini
2026-07-09 21:14:36 -04:00
Jose Diaz-Gonzalez
16ba93f9e2 Merge pull request #8820 from dokku/dependabot/composer/tests/apps/php/heroku/heroku-buildpack-php-293
chore(deps-dev): bump heroku/heroku-buildpack-php from 292 to 293 in /tests/apps/php
2026-07-09 21:14:26 -04:00
Jose Diaz-Gonzalez
e2781c0553 Merge pull request #8821 from dokku/dependabot/docker/tests/apps/go-fail-predeploy/golang-1.26.5
chore(deps): bump golang from 1.26.4 to 1.26.5 in /tests/apps/go-fail-predeploy
2026-07-09 21:14:17 -04:00
Jose Diaz-Gonzalez
91025ee23e Merge pull request #8822 from dokku/dependabot/docker/tests/apps/gogrpc/golang-1.26.5
chore(deps): bump golang from 1.26.4 to 1.26.5 in /tests/apps/gogrpc
2026-07-09 21:14:04 -04:00
Jose Diaz-Gonzalez
06a79b3f5c Merge pull request #8824 from dokku/dependabot/docker/tests/apps/go-fail-postdeploy/golang-1.26.5
chore(deps): bump golang from 1.26.4 to 1.26.5 in /tests/apps/go-fail-postdeploy
2026-07-09 21:13:53 -04:00
Jose Diaz-Gonzalez
71ce14feca Merge pull request #8827 from dokku/dependabot/go_modules/plugins/scheduler-k3s/github.com/cert-manager/cert-manager-1.21.0
chore(deps): bump github.com/cert-manager/cert-manager from 1.20.3 to 1.21.0 in /plugins/scheduler-k3s
2026-07-09 21:13:34 -04:00
Jose Diaz-Gonzalez
8986a27318 Merge pull request #8828 from dokku/dependabot/docker/plugins/traefik-vhosts/traefik-v3.7.7
chore(deps): bump traefik from v3.7.6 to v3.7.7 in /plugins/traefik-vhosts
2026-07-09 21:13:23 -04:00
Jose Diaz-Gonzalez
78977e3402 Merge pull request #8829 from dokku/dependabot/go_modules/plugins/scheduler-k3s/github.com/go-openapi/jsonpointer-1.0.0
chore(deps): bump github.com/go-openapi/jsonpointer from 0.24.0 to 1.0.0 in /plugins/scheduler-k3s
2026-07-09 21:13:16 -04:00
dependabot[bot]
7eaaaa7ac2 chore(deps): bump github.com/go-openapi/jsonpointer
Bumps [github.com/go-openapi/jsonpointer](https://github.com/go-openapi/jsonpointer) from 0.24.0 to 1.0.0.
- [Release notes](https://github.com/go-openapi/jsonpointer/releases)
- [Commits](https://github.com/go-openapi/jsonpointer/compare/v0.24.0...v1.0.0)

---
updated-dependencies:
- dependency-name: github.com/go-openapi/jsonpointer
  dependency-version: 1.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-09 13:55:04 +00:00
dependabot[bot]
04486f18ca chore(deps): bump traefik in /plugins/traefik-vhosts
Bumps traefik from v3.7.6 to v3.7.7.

---
updated-dependencies:
- dependency-name: traefik
  dependency-version: v3.7.7
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-09 13:55:00 +00:00
dependabot[bot]
19c167ca1f chore(deps): bump github.com/cert-manager/cert-manager
Bumps [github.com/cert-manager/cert-manager](https://github.com/cert-manager/cert-manager) from 1.20.3 to 1.21.0.
- [Release notes](https://github.com/cert-manager/cert-manager/releases)
- [Changelog](https://github.com/cert-manager/cert-manager/blob/master/RELEASE.md)
- [Commits](https://github.com/cert-manager/cert-manager/compare/v1.20.3...v1.21.0)

---
updated-dependencies:
- dependency-name: github.com/cert-manager/cert-manager
  dependency-version: 1.21.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-09 13:54:58 +00:00
dependabot[bot]
5ff86ec977 chore(deps): bump golang in /tests/apps/zombies-dockerfile-no-tini
Bumps golang from 1.26.4 to 1.26.5.

---
updated-dependencies:
- dependency-name: golang
  dependency-version: 1.26.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-09 13:53:12 +00:00
dependabot[bot]
7e05d6cca4 chore(deps): bump golang in /tests/apps/go-fail-postdeploy
Bumps golang from 1.26.4 to 1.26.5.

---
updated-dependencies:
- dependency-name: golang
  dependency-version: 1.26.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-09 13:53:05 +00:00
dependabot[bot]
58f509ed0c chore(deps): bump golang in /tests/apps/zombies-dockerfile-tini
Bumps golang from 1.26.4 to 1.26.5.

---
updated-dependencies:
- dependency-name: golang
  dependency-version: 1.26.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-09 13:52:57 +00:00
dependabot[bot]
5462744cf0 chore(deps): bump golang from 1.26.4 to 1.26.5 in /tests/apps/gogrpc
Bumps golang from 1.26.4 to 1.26.5.

---
updated-dependencies:
- dependency-name: golang
  dependency-version: 1.26.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-09 13:52:57 +00:00
dependabot[bot]
ab14872c77 chore(deps): bump golang in /tests/apps/go-fail-predeploy
Bumps golang from 1.26.4 to 1.26.5.

---
updated-dependencies:
- dependency-name: golang
  dependency-version: 1.26.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-09 13:52:38 +00:00
dependabot[bot]
01f3280746 chore(deps-dev): bump heroku/heroku-buildpack-php in /tests/apps/php
Bumps [heroku/heroku-buildpack-php](https://github.com/heroku/heroku-buildpack-php) from 292 to 293.
- [Release notes](https://github.com/heroku/heroku-buildpack-php/releases)
- [Changelog](https://github.com/heroku/heroku-buildpack-php/blob/main/CHANGELOG.md)
- [Commits](https://github.com/heroku/heroku-buildpack-php/compare/v292...v293)

---
updated-dependencies:
- dependency-name: heroku/heroku-buildpack-php
  dependency-version: '293'
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-09 13:52:36 +00:00
Dokku Bot
0dd183e6cc Release 0.38.22
# History

## 0.38.22

Install/update via the bootstrap script:

```shell
wget -NP . https://dokku.com/install/v0.38.22/bootstrap.sh
sudo DOKKU_TAG=v0.38.22 bash bootstrap.sh
```

### New Features

- #8805: @RichardDorian Allow custom values for chown
- #8810: @josegonzalez Expose whether a network was created by dokku
- #8807: @josegonzalez Allow replacing buildpack list atomically
- #8808: @josegonzalez Expose docker-options as structured lists in JSON report
- #8806: @josegonzalez Expose scheduler-k3s autoscaling-auth state for read-back
- #8801: @josegonzalez Add --format json support to plugin:list

### Refactors

- #8804: @josegonzalez Port bash :report subcommands to golang

### Documentation

- #8809: @josegonzalez Document nginx validate-config load_module override

### Tests

- #8803: @dependabot[bot] chore(deps): bump django from 5.2.15 to 5.2.16 in /tests/apps/dockerfile-release

### Dependencies

- #8816: @dependabot[bot] chore(deps): bump golang.org/x/sync from 0.21.0 to 0.22.0 in /plugins/common
- #8818: @dependabot[bot] chore(deps): bump github.com/traefik/traefik/v2 from 2.11.51 to 2.11.52 in /plugins/scheduler-k3s
- #8817: @dependabot[bot] chore(deps): bump golang.org/x/sync from 0.21.0 to 0.22.0 in /plugins/scheduler-docker-local
- #8819: @dependabot[bot] chore(deps): bump golang.org/x/sync from 0.21.0 to 0.22.0 in /plugins/scheduler-k3s
2026-07-08 22:12:05 +00:00
Jose Diaz-Gonzalez
611cb89711 Merge pull request #8805 from RichardDorian/master
Allow custom values for chown
2026-07-08 18:09:31 -04:00
Jose Diaz-Gonzalez
e38c1754e4 Merge pull request #8816 from dokku/dependabot/go_modules/plugins/common/golang.org/x/sync-0.22.0
chore(deps): bump golang.org/x/sync from 0.21.0 to 0.22.0 in /plugins/common
2026-07-08 17:04:07 -04:00
Jose Diaz-Gonzalez
807e50edbf chore: bump go modules 2026-07-08 15:43:21 -04:00
dependabot[bot]
f931a84191 chore(deps): bump golang.org/x/sync in /plugins/common
Bumps [golang.org/x/sync](https://github.com/golang/sync) from 0.21.0 to 0.22.0.
- [Commits](https://github.com/golang/sync/compare/v0.21.0...v0.22.0)

---
updated-dependencies:
- dependency-name: golang.org/x/sync
  dependency-version: 0.22.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-08 15:40:54 -04:00
Jose Diaz-Gonzalez
4a4ae6256f Merge pull request #8818 from dokku/dependabot/go_modules/plugins/scheduler-k3s/github.com/traefik/traefik/v2-2.11.52
chore(deps): bump github.com/traefik/traefik/v2 from 2.11.51 to 2.11.52 in /plugins/scheduler-k3s
2026-07-08 14:54:14 -04:00
dependabot[bot]
515d030689 chore(deps): bump github.com/traefik/traefik/v2
Bumps [github.com/traefik/traefik/v2](https://github.com/traefik/traefik) from 2.11.51 to 2.11.52.
- [Release notes](https://github.com/traefik/traefik/releases)
- [Changelog](https://github.com/traefik/traefik/blob/v2.11.52/CHANGELOG.md)
- [Commits](https://github.com/traefik/traefik/compare/v2.11.51...v2.11.52)

---
updated-dependencies:
- dependency-name: github.com/traefik/traefik/v2
  dependency-version: 2.11.52
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-08 18:54:06 +00:00
Jose Diaz-Gonzalez
f5e81cdcbe Merge pull request #8817 from dokku/dependabot/go_modules/plugins/scheduler-docker-local/golang.org/x/sync-0.22.0
chore(deps): bump golang.org/x/sync from 0.21.0 to 0.22.0 in /plugins/scheduler-docker-local
2026-07-08 14:52:53 -04:00
Jose Diaz-Gonzalez
57d23db98a Merge pull request #8819 from dokku/dependabot/go_modules/plugins/scheduler-k3s/golang.org/x/sync-0.22.0
chore(deps): bump golang.org/x/sync from 0.21.0 to 0.22.0 in /plugins/scheduler-k3s
2026-07-08 14:52:41 -04:00
Jose Diaz-Gonzalez
c37ba0f255 Merge pull request #8810 from dokku/8797-network-list-expose-whether-a-network-was-created-by-dokku
Expose whether a network was created by dokku
2026-07-08 14:52:32 -04:00
RichardDorian
513b200f5c test(storage): add out-of-bounds chown coverage for go code and script 2026-07-08 19:38:08 +02:00
dependabot[bot]
b0ba167df8 chore(deps): bump golang.org/x/sync in /plugins/scheduler-k3s
Bumps [golang.org/x/sync](https://github.com/golang/sync) from 0.21.0 to 0.22.0.
- [Commits](https://github.com/golang/sync/compare/v0.21.0...v0.22.0)

---
updated-dependencies:
- dependency-name: golang.org/x/sync
  dependency-version: 0.22.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-08 13:55:26 +00:00
dependabot[bot]
e71893621b chore(deps): bump golang.org/x/sync in /plugins/scheduler-docker-local
Bumps [golang.org/x/sync](https://github.com/golang/sync) from 0.21.0 to 0.22.0.
- [Commits](https://github.com/golang/sync/compare/v0.21.0...v0.22.0)

---
updated-dependencies:
- dependency-name: golang.org/x/sync
  dependency-version: 0.22.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-08 13:54:20 +00:00
RichardDorian
06bedebce3 fix(storage): allow custom chown values in chown-storage-dir script 2026-07-08 08:29:13 +02:00
Jose Diaz-Gonzalez
fc3a526bf9 Merge pull request #8809 from dokku/8784-new-nginx-pre-validation-breaks-configs-that-need-plugins
Document nginx validate-config load_module override
2026-07-08 00:32:09 -04:00
Jose Diaz-Gonzalez
ac4b86fd8e feat: expose whether a network was created by dokku
`network:list` and `network:info` now expose a `DokkuManaged` boolean derived from the `com.dokku.network-name` label that `network:create` applies, and `network:list` gains a `--dokku-managed` flag to restrict output to dokku-created networks. This lets tooling distinguish networks dokku created from Docker built-ins and networks created by other tooling such as compose.
2026-07-08 00:03:29 -04:00
Jose Diaz-Gonzalez
1ee462dc3c docs: document nginx validate-config load_module override
The nginx deploy-time pre-validation runs `nginx -t` against a minimal wrapper that omits the global `load_module` directives, so a custom `nginx.conf.sigil` using a directive from a dynamically loaded module fails validation even though it is valid against the running server. Document overriding the `validate-config` template through the `nginx-app-template-source` trigger as the supported workaround.
2026-07-07 23:33:59 -04:00
Jose Diaz-Gonzalez
24e3809a34 Merge pull request #8807 from dokku/8802-buildpacks-allow-setting-the-entire-ordered-buildpack-list-in-one-command
Allow replacing buildpack list atomically
2026-07-07 22:13:59 -04:00
Jose Diaz-Gonzalez
62164181e0 Merge pull request #8808 from dokku/8799-docker-options-report-expose-options-as-a-structured-list
Expose docker-options as structured lists in JSON report
2026-07-07 21:29:56 -04:00
Jose Diaz-Gonzalez
f73e888d98 Merge pull request #8806 from dokku/8800-scheduler-k3s-expose-annotations-labels-trigger-auth-for-read-back
Expose scheduler-k3s autoscaling-auth state for read-back
2026-07-07 20:47:28 -04:00
Jose Diaz-Gonzalez
c8bcba0145 fix: set dokku system user in buildpacks unit tests
Pin DOKKU_SYSTEM_USER and DOKKU_SYSTEM_GROUP to the current process user in test setup so PropertyListWrite succeeds in CI Docker where the dokku group does not exist.
2026-07-07 19:57:03 -04:00
Jose Diaz-Gonzalez
4652749b5b feat: expose docker-options as structured lists in JSON report
Add parallel -list keys to docker-options:report --format json so export
tools can round-trip options without splitting space-joined strings.

Closes #8799
2026-07-07 19:49:17 -04:00
Jose Diaz-Gonzalez
16f8b25bda feat: allow replacing buildpack list atomically
Add buildpacks:set --replace so callers can replace an app's complete ordered buildpack list in one command while preserving existing single-buildpack and --index behavior.

Closes #8802
2026-07-07 18:37:38 -04:00
Jose Diaz-Gonzalez
b2c4f61387 feat: expose scheduler-k3s autoscaling-auth state for read-back
Align autoscaling-auth:report with annotations and labels reporting so export tools can recover configured trigger auth via flat JSON keys and info flags, while stdout stays secret-safe unless --include-metadata is used.

Closes #8800
2026-07-07 18:07:39 -04:00
RichardDorian
a0361d59c1 test(storage): add unit test for custom chown values 2026-07-07 20:48:34 +02:00
RichardDorian
962c54bb2a docs(storage): add documentation regarding custom chown values 2026-07-07 19:28:27 +02:00
RichardDorian
fc9ae03eb7 feat(storage): allow custom chown value 2026-07-07 19:25:22 +02:00
Jose Diaz-Gonzalez
25b1356435 Merge pull request #8803 from dokku/dependabot/pip/tests/apps/dockerfile-release/django-5.2.16
chore(deps): bump django from 5.2.15 to 5.2.16 in /tests/apps/dockerfile-release
2026-07-07 12:18:52 -04:00
Jose Diaz-Gonzalez
48bee7fed0 Merge pull request #8804 from dokku/parallel-bash-reports
Port bash :report subcommands to golang
2026-07-07 12:18:37 -04:00
Jose Diaz-Gonzalez
cdcc10e91c fix: satisfy shfmt lint on certs internal-functions 2026-07-07 10:45:06 -04:00
Jose Diaz-Gonzalez
cf15fb139e Merge remote-tracking branch 'origin/master' into parallel-bash-reports
# Conflicts:
#	go.work
2026-07-07 10:38:57 -04:00
dependabot[bot]
8a35ed337e chore(deps): bump django in /tests/apps/dockerfile-release
Bumps [django](https://github.com/django/django) from 5.2.15 to 5.2.16.
- [Commits](https://github.com/django/django/commits)

---
updated-dependencies:
- dependency-name: django
  dependency-version: 5.2.16
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-07 13:54:29 +00:00
Jose Diaz-Gonzalez
5d07484cc2 refactor: remove unused bash report helper functions
With every bash :report subcommand now ported to golang, the shared fn-report-parse-args, fn-report-emit-json, fn-report-filter-global and fn-report-validate-format helpers are no longer referenced and are removed.
2026-07-07 07:15:19 -04:00
Jose Diaz-Gonzalez
7ee882c4e7 feat: port nginx :report subcommand to golang
The bash :report implementation for the nginx-vhosts plugin is replaced with a compiled golang binary that reuses the plugin's existing golang property getters, so every raw, global and computed key is unchanged while collection runs in parallel and json is marshalled directly. The global report keeps its existing behaviour of surfacing only the global keys.
2026-07-07 07:12:59 -04:00
Jose Diaz-Gonzalez
fe11d508d3 feat: port scheduler-docker-local :report subcommand to golang
The bash :report implementation for the scheduler-docker-local plugin is replaced with a compiled golang binary. The plugin already shipped golang code, so the report subcommand is added alongside its existing triggers binary, and the init-process and parallel-schedule-count helpers remain in bash for the deploy pipeline.
2026-07-07 07:06:24 -04:00
Jose Diaz-Gonzalez
3fee5b881a feat: port git :report subcommand to golang
The bash :report implementation for the git plugin is replaced with a compiled golang binary. Property, computed and global keys are collected in parallel, while the sha and last-updated-at keys still shell out to git and stat the deploy branch ref so their values are unchanged. The non-report git helpers such as fn-git-cmd and the computed deploy-branch and keep-git-dir getters remain in place for the build pipeline.
2026-07-07 07:02:38 -04:00
Jose Diaz-Gonzalez
6e5afb84a9 feat: port certs :report subcommand to golang
The bash :report implementation for the certs plugin is replaced with a compiled golang binary. The certificate inspection getters run openssl and reproduce the existing field extraction, so the ssl report keys are unchanged, while collection now happens in parallel and json is marshalled directly. The now-unused fn-ssl-* display helpers are dropped, and fn-certs-set and fn-certs-remove remain for certs:add and certs:remove.
2026-07-07 06:56:51 -04:00
Jose Diaz-Gonzalez
857c215ccc Merge pull request #8801 from dokku/8798-plugin-list-expose-the-install-source-url-json-output
feat: add --format json support to plugin:list
2026-07-07 06:44:48 -04:00
Jose Diaz-Gonzalez
8d0c36bad6 feat: port checks and domains :report subcommands to golang
The bash :report implementations for the checks and domains plugins are replaced with a compiled golang binary that collects report keys in parallel and marshals json directly. The domains global report header now matches the shared renderer used by every other golang report, and its bats assertion is updated accordingly.
2026-07-07 06:43:31 -04:00
Jose Diaz-Gonzalez
5faabea3d4 feat: port vhost proxy :report subcommands to golang
The bash :report implementations for the caddy, haproxy, openresty, and traefik proxy plugins are replaced with a compiled golang binary that collects report keys in parallel and marshals json directly. The traefik dns-provider values keep their masking behaviour, remaining hidden in the default stdout report while surfacing for --format json or an explicit flag query. These four plugins previously had no unit tests, so a bats suite covering the report matrix is added for each.
2026-07-07 06:29:01 -04:00
Jose Diaz-Gonzalez
f9db9583a1 feat: port builder :report subcommands to golang
The bash :report implementations for the dockerfile, herokuish, lambda, nixpacks, pack, and railpack builders are replaced with a compiled golang binary that collects report keys in parallel and marshals json directly, avoiding the per-key subshell and jq forks that made the bash reports slow. The subcommands/report and root report trigger become symlinks to the compiled binary, while the non-report bash helpers each plugin still relies on are left in place.
2026-07-07 06:11:13 -04:00
Jose Diaz-Gonzalez
9c819cfebc feat: add --format json support to plugin:list
Adds a `--format json` flag to `plugin:list` whose output includes each plugin's install source - for git-based third-party plugins, the git remote URL, the checked-out commit, and the followed branch - so the set of installed plugins can be reconstructed elsewhere.

Closes #8798.
2026-07-07 05:17:40 -04:00
Dokku Bot
4eabf54fd4 Release 0.38.21
# History

## 0.38.21

Install/update via the bootstrap script:

```shell
wget -NP . https://dokku.com/install/v0.38.21/bootstrap.sh
sudo DOKKU_TAG=v0.38.21 bash bootstrap.sh
```

### New Features

- #8795: @josegonzalez Add --format json support to apps:list

### Tests

- #8788: @dependabot[bot] chore(deps): bump google.golang.org/grpc from 1.81.1 to 1.82.0 in /tests/apps/gogrpc
- #8787: @dependabot[bot] chore(deps): bump golang.org/x/net from 0.51.0 to 0.55.0 in /tests/apps/gogrpc

### Dependencies

- #8781: @dependabot[bot] chore(deps): bump lucaslorentz/caddy-docker-proxy from 2.12 to 2.13 in /plugins/caddy-vhosts
- #8794: @dependabot[bot] chore(deps): bump github.com/fluxcd/pkg/kustomize from 1.36.0 to 1.37.0 in /plugins/scheduler-k3s
- #8789: @dependabot[bot] chore(deps): bump pymdown-extensions from 11.0 to 11.0.1 in /docs/_build
- #8782: @dependabot[bot] chore(deps): bump github.com/go-openapi/jsonpointer from 0.23.2 to 0.24.0 in /plugins/scheduler-k3s
- #8785: @dependabot[bot] chore(deps): bump traefik from v3.7.5 to v3.7.6 in /plugins/traefik-vhosts
- #8786: @dependabot[bot] chore(deps): bump github.com/fluxcd/pkg/kustomize from 1.31.0 to 1.36.0 in /plugins/scheduler-k3s
- #8783: @dependabot[bot] chore(deps): bump github.com/traefik/traefik/v2 from 2.11.50 to 2.11.51 in /plugins/scheduler-k3s
- #8780: @dependabot[bot] chore(deps): bump github.com/cert-manager/cert-manager from 1.20.2 to 1.20.3 in /plugins/scheduler-k3s
- #8779: @dependabot[bot] chore(deps): bump github.com/go-openapi/jsonpointer from 0.23.1 to 0.23.2 in /plugins/scheduler-k3s

### Other

- #8796: @josegonzalez Add --format json support to ps:scale
2026-07-06 22:42:58 +00:00
Jose Diaz-Gonzalez
f945a9879b Merge pull request #8781 from dokku/dependabot/docker/plugins/caddy-vhosts/lucaslorentz/caddy-docker-proxy-2.13
chore(deps): bump lucaslorentz/caddy-docker-proxy from 2.12 to 2.13 in /plugins/caddy-vhosts
2026-07-06 18:41:01 -04:00
Jose Diaz-Gonzalez
ebb63ed40b Merge pull request #8796 from dokku/8793-add-format-json-support-to-ps-scale
Add --format json support to ps:scale
2026-07-06 18:40:48 -04:00
Jose Diaz-Gonzalez
857d115fdd feat: add --format json support to ps:scale
The `ps:scale` command now accepts a `--format` flag that defaults to `stdout` and can be set to `json` to emit the current formation as a JSON array of process type and quantity objects, matching the JSON output the `:report` subcommands already provide. The flag only applies when displaying the current formation; it is ignored when process types are supplied for scaling. When no scale has been set for the app, the JSON output is an empty array.
2026-07-06 13:57:19 -04:00
Jose Diaz-Gonzalez
4a88f3aba4 Merge pull request #8795 from dokku/8792-add-format-json-support-to-apps-list
Add --format json support to apps:list
2026-07-06 13:32:38 -04:00
Jose Diaz-Gonzalez
21c27e99cc feat: add --format json support to apps:list
The `apps:list` command now accepts a `--format` flag that defaults to `stdout` and can be set to `json` to emit the app names as a JSON array, matching the JSON output the `:report` subcommands already provide. When no apps exist, the JSON output is an empty array.
2026-07-06 11:50:56 -04:00
Jose Diaz-Gonzalez
631b0a4dc3 Merge pull request #8794 from dokku/dependabot/go_modules/plugins/scheduler-k3s/github.com/fluxcd/pkg/kustomize-1.37.0
chore(deps): bump github.com/fluxcd/pkg/kustomize from 1.36.0 to 1.37.0 in /plugins/scheduler-k3s
2026-07-06 11:05:33 -04:00
Jose Diaz-Gonzalez
4e15f137df Merge pull request #8789 from dokku/dependabot/pip/docs/_build/pymdown-extensions-11.0.1
chore(deps): bump pymdown-extensions from 11.0 to 11.0.1 in /docs/_build
2026-07-06 11:05:25 -04:00
dependabot[bot]
e558b4c203 chore(deps): bump github.com/fluxcd/pkg/kustomize
Bumps [github.com/fluxcd/pkg/kustomize](https://github.com/fluxcd/pkg) from 1.36.0 to 1.37.0.
- [Commits](https://github.com/fluxcd/pkg/compare/kustomize/v1.36.0...kustomize/v1.37.0)

---
updated-dependencies:
- dependency-name: github.com/fluxcd/pkg/kustomize
  dependency-version: 1.37.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-06 13:54:35 +00:00
dependabot[bot]
e0e62c75da chore(deps): bump pymdown-extensions from 11.0 to 11.0.1 in /docs/_build
Bumps [pymdown-extensions](https://github.com/facelessuser/pymdown-extensions) from 11.0 to 11.0.1.
- [Release notes](https://github.com/facelessuser/pymdown-extensions/releases)
- [Commits](https://github.com/facelessuser/pymdown-extensions/compare/11.0...11.0.1)

---
updated-dependencies:
- dependency-name: pymdown-extensions
  dependency-version: 11.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-03 13:53:22 +00:00
Jose Diaz-Gonzalez
ce69ca76ad Merge pull request #8782 from dokku/dependabot/go_modules/plugins/scheduler-k3s/github.com/go-openapi/jsonpointer-0.24.0
chore(deps): bump github.com/go-openapi/jsonpointer from 0.23.2 to 0.24.0 in /plugins/scheduler-k3s
2026-07-02 13:31:24 -04:00
Jose Diaz-Gonzalez
8130f41043 Merge pull request #8788 from dokku/dependabot/go_modules/tests/apps/gogrpc/google.golang.org/grpc-1.82.0
chore(deps): bump google.golang.org/grpc from 1.81.1 to 1.82.0 in /tests/apps/gogrpc
2026-07-02 13:01:43 -04:00
dependabot[bot]
e3bb5099b8 chore(deps): bump github.com/go-openapi/jsonpointer
Bumps [github.com/go-openapi/jsonpointer](https://github.com/go-openapi/jsonpointer) from 0.23.2 to 0.24.0.
- [Release notes](https://github.com/go-openapi/jsonpointer/releases)
- [Commits](https://github.com/go-openapi/jsonpointer/compare/v0.23.2...v0.24.0)

---
updated-dependencies:
- dependency-name: github.com/go-openapi/jsonpointer
  dependency-version: 0.24.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-02 15:24:35 +00:00
dependabot[bot]
f7e41ab633 chore(deps): bump google.golang.org/grpc in /tests/apps/gogrpc
Bumps [google.golang.org/grpc](https://github.com/grpc/grpc-go) from 1.81.1 to 1.82.0.
- [Release notes](https://github.com/grpc/grpc-go/releases)
- [Commits](https://github.com/grpc/grpc-go/compare/v1.81.1...v1.82.0)

---
updated-dependencies:
- dependency-name: google.golang.org/grpc
  dependency-version: 1.82.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-02 15:23:25 +00:00
Jose Diaz-Gonzalez
c4355af7c4 Merge pull request #8785 from dokku/dependabot/docker/plugins/traefik-vhosts/traefik-v3.7.6
chore(deps): bump traefik from v3.7.5 to v3.7.6 in /plugins/traefik-vhosts
2026-07-02 11:22:46 -04:00
Jose Diaz-Gonzalez
6d7c175c5e Merge pull request #8786 from dokku/dependabot/go_modules/plugins/scheduler-k3s/github.com/fluxcd/pkg/kustomize-1.36.0
chore(deps): bump github.com/fluxcd/pkg/kustomize from 1.31.0 to 1.36.0 in /plugins/scheduler-k3s
2026-07-02 11:22:20 -04:00
Jose Diaz-Gonzalez
fee5456c94 Merge pull request #8787 from dokku/dependabot/go_modules/tests/apps/gogrpc/golang.org/x/net-0.55.0
chore(deps): bump golang.org/x/net from 0.51.0 to 0.55.0 in /tests/apps/gogrpc
2026-07-02 11:22:03 -04:00
dependabot[bot]
2639c0cdf6 chore(deps): bump golang.org/x/net in /tests/apps/gogrpc
Bumps [golang.org/x/net](https://github.com/golang/net) from 0.51.0 to 0.55.0.
- [Commits](https://github.com/golang/net/compare/v0.51.0...v0.55.0)

---
updated-dependencies:
- dependency-name: golang.org/x/net
  dependency-version: 0.55.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-02 02:57:36 +00:00
dependabot[bot]
d311111537 chore(deps): bump github.com/fluxcd/pkg/kustomize
Bumps [github.com/fluxcd/pkg/kustomize](https://github.com/fluxcd/pkg) from 1.31.0 to 1.36.0.
- [Commits](https://github.com/fluxcd/pkg/compare/apis/meta/v1.31.0...kustomize/v1.36.0)

---
updated-dependencies:
- dependency-name: github.com/fluxcd/pkg/kustomize
  dependency-version: 1.36.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-01 13:53:59 +00:00
dependabot[bot]
356e9704fd chore(deps): bump traefik in /plugins/traefik-vhosts
Bumps traefik from v3.7.5 to v3.7.6.

---
updated-dependencies:
- dependency-name: traefik
  dependency-version: v3.7.6
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-01 13:53:36 +00:00
Jose Diaz-Gonzalez
384b45f8f9 Merge pull request #8783 from dokku/dependabot/go_modules/plugins/scheduler-k3s/github.com/traefik/traefik/v2-2.11.51
chore(deps): bump github.com/traefik/traefik/v2 from 2.11.50 to 2.11.51 in /plugins/scheduler-k3s
2026-06-30 17:23:15 -04:00
dependabot[bot]
be7f9fc3dd chore(deps): bump github.com/traefik/traefik/v2
Bumps [github.com/traefik/traefik/v2](https://github.com/traefik/traefik) from 2.11.50 to 2.11.51.
- [Release notes](https://github.com/traefik/traefik/releases)
- [Changelog](https://github.com/traefik/traefik/blob/v2.11.51/CHANGELOG.md)
- [Commits](https://github.com/traefik/traefik/compare/v2.11.50...v2.11.51)

---
updated-dependencies:
- dependency-name: github.com/traefik/traefik/v2
  dependency-version: 2.11.51
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-30 13:54:17 +00:00
dependabot[bot]
8c47c10748 chore(deps): bump lucaslorentz/caddy-docker-proxy
Bumps lucaslorentz/caddy-docker-proxy from 2.12 to 2.13.

---
updated-dependencies:
- dependency-name: lucaslorentz/caddy-docker-proxy
  dependency-version: '2.13'
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-30 13:53:32 +00:00
Jose Diaz-Gonzalez
7d4d3d78f0 Merge pull request #8780 from dokku/dependabot/go_modules/plugins/scheduler-k3s/github.com/cert-manager/cert-manager-1.20.3
chore(deps): bump github.com/cert-manager/cert-manager from 1.20.2 to 1.20.3 in /plugins/scheduler-k3s
2026-06-29 14:14:26 -04:00
Jose Diaz-Gonzalez
5962986985 Merge pull request #8779 from dokku/dependabot/go_modules/plugins/scheduler-k3s/github.com/go-openapi/jsonpointer-0.23.2
chore(deps): bump github.com/go-openapi/jsonpointer from 0.23.1 to 0.23.2 in /plugins/scheduler-k3s
2026-06-29 14:14:19 -04:00
dependabot[bot]
cc5023959a chore(deps): bump github.com/cert-manager/cert-manager
Bumps [github.com/cert-manager/cert-manager](https://github.com/cert-manager/cert-manager) from 1.20.2 to 1.20.3.
- [Release notes](https://github.com/cert-manager/cert-manager/releases)
- [Changelog](https://github.com/cert-manager/cert-manager/blob/master/RELEASE.md)
- [Commits](https://github.com/cert-manager/cert-manager/compare/v1.20.2...v1.20.3)

---
updated-dependencies:
- dependency-name: github.com/cert-manager/cert-manager
  dependency-version: 1.20.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-29 13:54:43 +00:00
dependabot[bot]
e31240112d chore(deps): bump github.com/go-openapi/jsonpointer
Bumps [github.com/go-openapi/jsonpointer](https://github.com/go-openapi/jsonpointer) from 0.23.1 to 0.23.2.
- [Release notes](https://github.com/go-openapi/jsonpointer/releases)
- [Commits](https://github.com/go-openapi/jsonpointer/compare/v0.23.1...v0.23.2)

---
updated-dependencies:
- dependency-name: github.com/go-openapi/jsonpointer
  dependency-version: 0.23.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-29 13:54:35 +00:00
Dokku Bot
31177a5730 Release 0.38.20
# History

## 0.38.20

Install/update via the bootstrap script:

```shell
wget -NP . https://dokku.com/install/v0.38.20/bootstrap.sh
sudo DOKKU_TAG=v0.38.20 bash bootstrap.sh
```

### Tests

- #8773: @dependabot[bot] chore(deps): bump python from 3.15.0b2-bookworm to 3.15.0b3-bookworm in /tests/apps/dockerfile-release
- #8756: @dependabot[bot] chore(deps): bump sass from 1.100.0 to 1.101.0 in /tests/apps/multi
- #8753: @dependabot[bot] chore(deps-dev): bump heroku/heroku-buildpack-php from 291 to 292 in /tests/apps/php

### Dependencies

- #8766: @dependabot[bot] chore(deps): bump helm.sh/helm/v3 from 3.21.1 to 3.21.2 in /plugins/scheduler-k3s
- #8777: @dependabot[bot] chore(deps): bump github.com/onsi/gomega from 1.41.0 to 1.42.1 in /plugins/common
- #8778: @dependabot[bot] chore(deps): bump byjg/easy-haproxy from 6.1.0 to 6.1.1 in /plugins/haproxy-vhosts
- #8748: @dependabot[bot] chore(deps): bump golang.org/x/crypto from 0.52.0 to 0.53.0 in /plugins/common
- #8745: @dependabot[bot] chore(deps): bump golang.org/x/sync from 0.20.0 to 0.21.0 in /plugins/common
- #8774: @dependabot[bot] chore(deps): bump python from 3.15.0b2-alpine to 3.15.0b3-alpine in /docs/_build
- #8769: @dependabot[bot] chore(deps): bump pymdown-extensions from 10.21.3 to 11.0 in /docs/_build
- #8775: @dependabot[bot] chore(deps): bump click from 8.4.1 to 8.4.2 in /docs/_build
- #8776: @dependabot[bot] chore(deps): bump byjg/easy-haproxy from 6.0.1 to 6.1.0 in /plugins/haproxy-vhosts
- #8772: @dependabot[bot] chore(deps): bump github.com/onsi/gomega from 1.42.0 to 1.42.1 in /plugins/buildpacks
- #8770: @dokku-bot chore: bump pack to 0.40.7
- #8767: @dependabot[bot] chore(deps): bump github.com/containerd/containerd from 1.7.32 to 1.7.33 in /plugins/scheduler-k3s
- #8765: @dependabot[bot] chore(deps): bump github.com/onsi/gomega from 1.41.0 to 1.42.0 in /plugins/scheduler-k3s
- #8764: @dependabot[bot] chore(deps): bump actions/checkout from 6 to 7
- #8762: @dependabot[bot] chore(deps): bump k8s.io/kubernetes from 1.36.1 to 1.36.2 in /plugins/scheduler-k3s
- #8758: @dependabot[bot] chore(deps): bump github.com/onsi/gomega from 1.41.0 to 1.42.0 in /plugins/buildpacks
- #8760: @dependabot[bot] chore(deps): bump k8s.io/apimachinery from 0.36.1 to 0.36.2 in /plugins/scheduler-k3s
- #8757: @dependabot[bot] chore(deps): bump helm.sh/helm/v3 from 3.21.0 to 3.21.1 in /plugins/scheduler-k3s
- #8755: @dependabot[bot] chore(deps): bump traefik from v3.7.4 to v3.7.5 in /plugins/traefik-vhosts
- #8754: @dependabot[bot] chore(deps): bump github.com/traefik/traefik/v2 from 2.11.49 to 2.11.50 in /plugins/scheduler-k3s
- #8749: @dependabot[bot] chore(deps): bump github.com/traefik/traefik/v2 from 2.11.47 to 2.11.49 in /plugins/scheduler-k3s
- #8743: @dependabot[bot] chore(deps): bump beautifulsoup4 from 4.14.3 to 4.15.0 in /docs/_build
- #8744: @dependabot[bot] chore(deps): bump traefik from v3.7.3 to v3.7.4 in /plugins/traefik-vhosts
- #8747: @dependabot[bot] chore(deps): bump golang.org/x/sync from 0.20.0 to 0.21.0 in /plugins/scheduler-k3s
- #8746: @dependabot[bot] chore(deps): bump golang.org/x/sync from 0.20.0 to 0.21.0 in /plugins/scheduler-docker-local
2026-06-28 05:32:10 +00:00
Jose Diaz-Gonzalez
6fc99896d4 Merge pull request #8766 from dokku/dependabot/go_modules/plugins/scheduler-k3s/helm.sh/helm/v3-3.21.2
chore(deps): bump helm.sh/helm/v3 from 3.21.1 to 3.21.2 in /plugins/scheduler-k3s
2026-06-28 01:17:11 -04:00
Jose Diaz-Gonzalez
89b2952c28 chore: gitignore 2 files 2026-06-27 23:18:49 -04:00
Jose Diaz-Gonzalez
6cd22ed7b9 fix: bump keda and controller-runtime for client-go v0.36
The `helm.sh/helm/v3` v3.21.2 bump pulled `client-go` up to `v0.36.2`, which is incompatible with the pinned `controller-runtime v0.22.4`. Moving `controller-runtime` to `v0.24.1` (the first release targeting `client-go v0.36`) requires KEDA `v2.20.1`, allowing the old version pin to be removed.
2026-06-27 23:17:50 -04:00
dependabot[bot]
8f7785dc89 chore(deps): bump helm.sh/helm/v3 in /plugins/scheduler-k3s
Bumps [helm.sh/helm/v3](https://github.com/helm/helm) from 3.21.1 to 3.21.2.
- [Release notes](https://github.com/helm/helm/releases)
- [Commits](https://github.com/helm/helm/compare/v3.21.1...v3.21.2)

---
updated-dependencies:
- dependency-name: helm.sh/helm/v3
  dependency-version: 3.21.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-27 22:57:44 -04:00
Jose Diaz-Gonzalez
97dd599afb Merge pull request #8777 from dokku/dependabot/go_modules/plugins/common/github.com/onsi/gomega-1.42.1
chore(deps): bump github.com/onsi/gomega from 1.41.0 to 1.42.1 in /plugins/common
2026-06-27 22:56:54 -04:00
Jose Diaz-Gonzalez
bf812ac2ad chore: bump go modules 2026-06-27 21:20:52 -04:00
Jose Diaz-Gonzalez
e533d68e86 Merge pull request #8778 from dokku/dependabot/docker/plugins/haproxy-vhosts/byjg/easy-haproxy-6.1.1
chore(deps): bump byjg/easy-haproxy from 6.1.0 to 6.1.1 in /plugins/haproxy-vhosts
2026-06-27 20:21:03 -04:00
dependabot[bot]
12dec0e71d chore(deps): bump byjg/easy-haproxy in /plugins/haproxy-vhosts
Bumps byjg/easy-haproxy from 6.1.0 to 6.1.1.

---
updated-dependencies:
- dependency-name: byjg/easy-haproxy
  dependency-version: 6.1.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-26 13:53:37 +00:00
dependabot[bot]
13b97b3243 chore(deps): bump github.com/onsi/gomega in /plugins/common
Bumps [github.com/onsi/gomega](https://github.com/onsi/gomega) from 1.41.0 to 1.42.1.
- [Release notes](https://github.com/onsi/gomega/releases)
- [Changelog](https://github.com/onsi/gomega/blob/master/CHANGELOG.md)
- [Commits](https://github.com/onsi/gomega/compare/v1.41.0...v1.42.1)

---
updated-dependencies:
- dependency-name: github.com/onsi/gomega
  dependency-version: 1.42.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-26 13:53:13 +00:00
Jose Diaz-Gonzalez
a1ddca00ba Merge pull request #8748 from dokku/dependabot/go_modules/plugins/common/golang.org/x/crypto-0.53.0 2026-06-26 06:52:59 -04:00
Jose Diaz-Gonzalez
113e47c3ab chore: bump go modules 2026-06-26 00:19:30 -04:00
dependabot[bot]
ccdad284ee chore(deps): bump golang.org/x/crypto in /plugins/common
Bumps [golang.org/x/crypto](https://github.com/golang/crypto) from 0.52.0 to 0.53.0.
- [Commits](https://github.com/golang/crypto/compare/v0.52.0...v0.53.0)

---
updated-dependencies:
- dependency-name: golang.org/x/crypto
  dependency-version: 0.53.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-26 00:19:10 -04:00
Jose Diaz-Gonzalez
b36716b1c7 Merge pull request #8745 from dokku/dependabot/go_modules/plugins/common/golang.org/x/sync-0.21.0
chore(deps): bump golang.org/x/sync from 0.20.0 to 0.21.0 in /plugins/common
2026-06-26 00:17:38 -04:00
Jose Diaz-Gonzalez
b5a08e3326 chore: bump go modules 2026-06-25 22:33:53 -04:00
dependabot[bot]
1e0be40561 chore(deps): bump golang.org/x/sync in /plugins/common
Bumps [golang.org/x/sync](https://github.com/golang/sync) from 0.20.0 to 0.21.0.
- [Commits](https://github.com/golang/sync/compare/v0.20.0...v0.21.0)

---
updated-dependencies:
- dependency-name: golang.org/x/sync
  dependency-version: 0.21.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-25 22:22:01 -04:00
Jose Diaz-Gonzalez
61ac061332 Merge pull request #8774 from dokku/dependabot/docker/docs/_build/python-3.15.0b3-alpine
chore(deps): bump python from 3.15.0b2-alpine to 3.15.0b3-alpine in /docs/_build
2026-06-25 21:00:41 -04:00
Jose Diaz-Gonzalez
9a52161aec Merge pull request #8769 from dokku/dependabot/pip/docs/_build/pymdown-extensions-11.0
chore(deps): bump pymdown-extensions from 10.21.3 to 11.0 in /docs/_build
2026-06-25 21:00:27 -04:00
Jose Diaz-Gonzalez
9ed5415e9b Merge pull request #8773 from dokku/dependabot/docker/tests/apps/dockerfile-release/python-3.15.0b3-bookworm
chore(deps): bump python from 3.15.0b2-bookworm to 3.15.0b3-bookworm in /tests/apps/dockerfile-release
2026-06-25 21:00:16 -04:00
Jose Diaz-Gonzalez
be2bc126c2 Merge pull request #8775 from dokku/dependabot/pip/docs/_build/click-8.4.2
chore(deps): bump click from 8.4.1 to 8.4.2 in /docs/_build
2026-06-25 21:00:07 -04:00
Jose Diaz-Gonzalez
2944b16114 Merge pull request #8776 from dokku/dependabot/docker/plugins/haproxy-vhosts/byjg/easy-haproxy-6.1.0
chore(deps): bump byjg/easy-haproxy from 6.0.1 to 6.1.0 in /plugins/haproxy-vhosts
2026-06-25 20:59:59 -04:00
dependabot[bot]
aba40f40ad chore(deps): bump byjg/easy-haproxy in /plugins/haproxy-vhosts
Bumps byjg/easy-haproxy from 6.0.1 to 6.1.0.

---
updated-dependencies:
- dependency-name: byjg/easy-haproxy
  dependency-version: 6.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-25 13:54:09 +00:00
dependabot[bot]
a538f0e6fe chore(deps): bump click from 8.4.1 to 8.4.2 in /docs/_build
Bumps [click](https://github.com/pallets/click) from 8.4.1 to 8.4.2.
- [Release notes](https://github.com/pallets/click/releases)
- [Changelog](https://github.com/pallets/click/blob/main/CHANGES.md)
- [Commits](https://github.com/pallets/click/compare/8.4.1...8.4.2)

---
updated-dependencies:
- dependency-name: click
  dependency-version: 8.4.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-25 13:53:20 +00:00
dependabot[bot]
0153187a2c chore(deps): bump python in /docs/_build
Bumps python from 3.15.0b2-alpine to 3.15.0b3-alpine.

---
updated-dependencies:
- dependency-name: python
  dependency-version: 3.15.0b3-alpine
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-25 13:52:58 +00:00
dependabot[bot]
9215f56d61 chore(deps): bump python in /tests/apps/dockerfile-release
Bumps python from 3.15.0b2-bookworm to 3.15.0b3-bookworm.

---
updated-dependencies:
- dependency-name: python
  dependency-version: 3.15.0b3-bookworm
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-25 13:52:36 +00:00
Jose Diaz-Gonzalez
442b8b1b81 Merge pull request #8772 from dokku/dependabot/go_modules/plugins/buildpacks/github.com/onsi/gomega-1.42.1
chore(deps): bump github.com/onsi/gomega from 1.42.0 to 1.42.1 in /plugins/buildpacks
2026-06-24 16:28:37 -04:00
Jose Diaz-Gonzalez
1e178d8636 Merge pull request #8770 from dokku/chore/bump-pack-0.40.7
chore: bump pack to 0.40.7
2026-06-24 15:41:45 -04:00
dependabot[bot]
36a62d1c7c chore(deps): bump github.com/onsi/gomega in /plugins/buildpacks
Bumps [github.com/onsi/gomega](https://github.com/onsi/gomega) from 1.42.0 to 1.42.1.
- [Release notes](https://github.com/onsi/gomega/releases)
- [Changelog](https://github.com/onsi/gomega/blob/master/CHANGELOG.md)
- [Commits](https://github.com/onsi/gomega/compare/v1.42.0...v1.42.1)

---
updated-dependencies:
- dependency-name: github.com/onsi/gomega
  dependency-version: 1.42.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-24 13:53:44 +00:00
Dokku Bot
da147538dc chore: bump pack to 0.40.7 2026-06-24 07:12:39 +00:00
Jose Diaz-Gonzalez
a87ed18893 Merge pull request #8767 from dokku/dependabot/go_modules/plugins/scheduler-k3s/github.com/containerd/containerd-1.7.33
chore(deps): bump github.com/containerd/containerd from 1.7.32 to 1.7.33 in /plugins/scheduler-k3s
2026-06-23 10:04:37 -04:00
dependabot[bot]
0d2ca470ad chore(deps): bump pymdown-extensions in /docs/_build
Bumps [pymdown-extensions](https://github.com/facelessuser/pymdown-extensions) from 10.21.3 to 11.0.
- [Release notes](https://github.com/facelessuser/pymdown-extensions/releases)
- [Commits](https://github.com/facelessuser/pymdown-extensions/compare/10.21.3...11.0)

---
updated-dependencies:
- dependency-name: pymdown-extensions
  dependency-version: '11.0'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-23 13:53:06 +00:00
dependabot[bot]
985f222ab2 chore(deps): bump github.com/containerd/containerd
Bumps [github.com/containerd/containerd](https://github.com/containerd/containerd) from 1.7.32 to 1.7.33.
- [Release notes](https://github.com/containerd/containerd/releases)
- [Changelog](https://github.com/containerd/containerd/blob/main/RELEASES.md)
- [Commits](https://github.com/containerd/containerd/compare/v1.7.32...v1.7.33)

---
updated-dependencies:
- dependency-name: github.com/containerd/containerd
  dependency-version: 1.7.33
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-23 06:21:45 +00:00
Jose Diaz-Gonzalez
cbb816bba4 Merge pull request #8765 from dokku/dependabot/go_modules/plugins/scheduler-k3s/github.com/onsi/gomega-1.42.0
chore(deps): bump github.com/onsi/gomega from 1.41.0 to 1.42.0 in /plugins/scheduler-k3s
2026-06-19 13:18:33 -04:00
Jose Diaz-Gonzalez
69684a43f1 Merge pull request #8764 from dokku/dependabot/github_actions/actions/checkout-7
chore(deps): bump actions/checkout from 6 to 7
2026-06-19 13:13:47 -04:00
dependabot[bot]
40e6178802 chore(deps): bump github.com/onsi/gomega in /plugins/scheduler-k3s
Bumps [github.com/onsi/gomega](https://github.com/onsi/gomega) from 1.41.0 to 1.42.0.
- [Release notes](https://github.com/onsi/gomega/releases)
- [Changelog](https://github.com/onsi/gomega/blob/master/CHANGELOG.md)
- [Commits](https://github.com/onsi/gomega/compare/v1.41.0...v1.42.0)

---
updated-dependencies:
- dependency-name: github.com/onsi/gomega
  dependency-version: 1.42.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-19 13:53:56 +00:00
dependabot[bot]
381e8fb8c1 chore(deps): bump actions/checkout from 6 to 7
Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/v6...v7)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-19 13:52:33 +00:00
Jose Diaz-Gonzalez
ef5f2f7086 Merge pull request #8762 from dokku/dependabot/go_modules/plugins/scheduler-k3s/k8s.io/kubernetes-1.36.2
chore(deps): bump k8s.io/kubernetes from 1.36.1 to 1.36.2 in /plugins/scheduler-k3s
2026-06-18 14:05:54 -04:00
dependabot[bot]
3f81539a2a chore(deps): bump k8s.io/kubernetes in /plugins/scheduler-k3s
Bumps [k8s.io/kubernetes](https://github.com/kubernetes/kubernetes) from 1.36.1 to 1.36.2.
- [Release notes](https://github.com/kubernetes/kubernetes/releases)
- [Commits](https://github.com/kubernetes/kubernetes/compare/v1.36.1...v1.36.2)

---
updated-dependencies:
- dependency-name: k8s.io/kubernetes
  dependency-version: 1.36.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-17 13:54:22 +00:00
Jose Diaz-Gonzalez
97c11b668b Merge pull request #8758 from dokku/dependabot/go_modules/plugins/buildpacks/github.com/onsi/gomega-1.42.0
chore(deps): bump github.com/onsi/gomega from 1.41.0 to 1.42.0 in /plugins/buildpacks
2026-06-16 11:28:18 -04:00
Jose Diaz-Gonzalez
fcaf24f92e Merge pull request #8760 from dokku/dependabot/go_modules/plugins/scheduler-k3s/k8s.io/apimachinery-0.36.2
chore(deps): bump k8s.io/apimachinery from 0.36.1 to 0.36.2 in /plugins/scheduler-k3s
2026-06-16 11:27:57 -04:00
dependabot[bot]
a02d83c3fb chore(deps): bump k8s.io/apimachinery in /plugins/scheduler-k3s
Bumps [k8s.io/apimachinery](https://github.com/kubernetes/apimachinery) from 0.36.1 to 0.36.2.
- [Commits](https://github.com/kubernetes/apimachinery/compare/v0.36.1...v0.36.2)

---
updated-dependencies:
- dependency-name: k8s.io/apimachinery
  dependency-version: 0.36.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-15 13:54:32 +00:00
dependabot[bot]
c1207db63f chore(deps): bump github.com/onsi/gomega in /plugins/buildpacks
Bumps [github.com/onsi/gomega](https://github.com/onsi/gomega) from 1.41.0 to 1.42.0.
- [Release notes](https://github.com/onsi/gomega/releases)
- [Changelog](https://github.com/onsi/gomega/blob/master/CHANGELOG.md)
- [Commits](https://github.com/onsi/gomega/compare/v1.41.0...v1.42.0)

---
updated-dependencies:
- dependency-name: github.com/onsi/gomega
  dependency-version: 1.42.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-15 13:53:25 +00:00
Jose Diaz-Gonzalez
13535a18f5 Merge pull request #8757 from dokku/dependabot/go_modules/plugins/scheduler-k3s/helm.sh/helm/v3-3.21.1
chore(deps): bump helm.sh/helm/v3 from 3.21.0 to 3.21.1 in /plugins/scheduler-k3s
2026-06-12 12:57:52 -04:00
Jose Diaz-Gonzalez
7bb1cc3d58 Merge pull request #8756 from dokku/dependabot/npm_and_yarn/tests/apps/multi/sass-1.101.0
chore(deps): bump sass from 1.100.0 to 1.101.0 in /tests/apps/multi
2026-06-12 12:57:45 -04:00
dependabot[bot]
887ae6c640 chore(deps): bump helm.sh/helm/v3 in /plugins/scheduler-k3s
Bumps [helm.sh/helm/v3](https://github.com/helm/helm) from 3.21.0 to 3.21.1.
- [Release notes](https://github.com/helm/helm/releases)
- [Commits](https://github.com/helm/helm/compare/v3.21.0...v3.21.1)

---
updated-dependencies:
- dependency-name: helm.sh/helm/v3
  dependency-version: 3.21.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-12 13:54:19 +00:00
dependabot[bot]
fda24ff9f2 chore(deps): bump sass from 1.100.0 to 1.101.0 in /tests/apps/multi
Bumps [sass](https://github.com/sass/dart-sass) from 1.100.0 to 1.101.0.
- [Release notes](https://github.com/sass/dart-sass/releases)
- [Changelog](https://github.com/sass/dart-sass/blob/main/CHANGELOG.md)
- [Commits](https://github.com/sass/dart-sass/compare/1.100.0...1.101.0)

---
updated-dependencies:
- dependency-name: sass
  dependency-version: 1.101.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-12 13:53:53 +00:00
Jose Diaz-Gonzalez
23d0080374 Merge pull request #8755 from dokku/dependabot/docker/plugins/traefik-vhosts/traefik-v3.7.5
chore(deps): bump traefik from v3.7.4 to v3.7.5 in /plugins/traefik-vhosts
2026-06-11 22:38:46 -04:00
dependabot[bot]
97ad5a8417 chore(deps): bump traefik in /plugins/traefik-vhosts
Bumps traefik from v3.7.4 to v3.7.5.

---
updated-dependencies:
- dependency-name: traefik
  dependency-version: v3.7.5
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-11 13:54:15 +00:00
Jose Diaz-Gonzalez
13afe84fdd Merge pull request #8754 from dokku/dependabot/go_modules/plugins/scheduler-k3s/github.com/traefik/traefik/v2-2.11.50
chore(deps): bump github.com/traefik/traefik/v2 from 2.11.49 to 2.11.50 in /plugins/scheduler-k3s
2026-06-10 14:47:22 -04:00
Jose Diaz-Gonzalez
e99f01498f Merge pull request #8753 from dokku/dependabot/composer/tests/apps/php/heroku/heroku-buildpack-php-292
chore(deps-dev): bump heroku/heroku-buildpack-php from 291 to 292 in /tests/apps/php
2026-06-10 14:47:12 -04:00
dependabot[bot]
343d7ffffa chore(deps): bump github.com/traefik/traefik/v2
Bumps [github.com/traefik/traefik/v2](https://github.com/traefik/traefik) from 2.11.49 to 2.11.50.
- [Release notes](https://github.com/traefik/traefik/releases)
- [Changelog](https://github.com/traefik/traefik/blob/v2.11.50/CHANGELOG.md)
- [Commits](https://github.com/traefik/traefik/compare/v2.11.49...v2.11.50)

---
updated-dependencies:
- dependency-name: github.com/traefik/traefik/v2
  dependency-version: 2.11.50
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-10 13:54:56 +00:00
dependabot[bot]
75c164f8bd chore(deps-dev): bump heroku/heroku-buildpack-php in /tests/apps/php
Bumps [heroku/heroku-buildpack-php](https://github.com/heroku/heroku-buildpack-php) from 291 to 292.
- [Release notes](https://github.com/heroku/heroku-buildpack-php/releases)
- [Changelog](https://github.com/heroku/heroku-buildpack-php/blob/main/CHANGELOG.md)
- [Commits](https://github.com/heroku/heroku-buildpack-php/compare/v291...v292)

---
updated-dependencies:
- dependency-name: heroku/heroku-buildpack-php
  dependency-version: '292'
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-10 13:52:23 +00:00
Jose Diaz-Gonzalez
823e1a5dfe Merge pull request #8749 from dokku/dependabot/go_modules/plugins/scheduler-k3s/github.com/traefik/traefik/v2-2.11.49
chore(deps): bump github.com/traefik/traefik/v2 from 2.11.47 to 2.11.49 in /plugins/scheduler-k3s
2026-06-09 11:28:13 -04:00
dependabot[bot]
1d991de4b0 chore(deps): bump github.com/traefik/traefik/v2
Bumps [github.com/traefik/traefik/v2](https://github.com/traefik/traefik) from 2.11.47 to 2.11.49.
- [Release notes](https://github.com/traefik/traefik/releases)
- [Changelog](https://github.com/traefik/traefik/blob/v2.11.49/CHANGELOG.md)
- [Commits](https://github.com/traefik/traefik/compare/v2.11.47...v2.11.49)

---
updated-dependencies:
- dependency-name: github.com/traefik/traefik/v2
  dependency-version: 2.11.49
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-09 13:54:47 +00:00
Jose Diaz-Gonzalez
0e652b9e71 Merge pull request #8743 from dokku/dependabot/pip/docs/_build/beautifulsoup4-4.15.0
chore(deps): bump beautifulsoup4 from 4.14.3 to 4.15.0 in /docs/_build
2026-06-08 13:28:57 -04:00
Jose Diaz-Gonzalez
0e8a882951 Merge pull request #8744 from dokku/dependabot/docker/plugins/traefik-vhosts/traefik-v3.7.4
chore(deps): bump traefik from v3.7.3 to v3.7.4 in /plugins/traefik-vhosts
2026-06-08 13:28:43 -04:00
Jose Diaz-Gonzalez
2c54ee70ee Merge pull request #8747 from dokku/dependabot/go_modules/plugins/scheduler-k3s/golang.org/x/sync-0.21.0
chore(deps): bump golang.org/x/sync from 0.20.0 to 0.21.0 in /plugins/scheduler-k3s
2026-06-08 13:28:26 -04:00
Jose Diaz-Gonzalez
0b807b36b9 Merge pull request #8746 from dokku/dependabot/go_modules/plugins/scheduler-docker-local/golang.org/x/sync-0.21.0
chore(deps): bump golang.org/x/sync from 0.20.0 to 0.21.0 in /plugins/scheduler-docker-local
2026-06-08 13:28:18 -04:00
dependabot[bot]
13217c602e chore(deps): bump golang.org/x/sync in /plugins/scheduler-k3s
Bumps [golang.org/x/sync](https://github.com/golang/sync) from 0.20.0 to 0.21.0.
- [Commits](https://github.com/golang/sync/compare/v0.20.0...v0.21.0)

---
updated-dependencies:
- dependency-name: golang.org/x/sync
  dependency-version: 0.21.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-08 13:54:21 +00:00
dependabot[bot]
430da379fc chore(deps): bump golang.org/x/sync in /plugins/scheduler-docker-local
Bumps [golang.org/x/sync](https://github.com/golang/sync) from 0.20.0 to 0.21.0.
- [Commits](https://github.com/golang/sync/compare/v0.20.0...v0.21.0)

---
updated-dependencies:
- dependency-name: golang.org/x/sync
  dependency-version: 0.21.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-08 13:53:55 +00:00
dependabot[bot]
271a1ddf2c chore(deps): bump traefik in /plugins/traefik-vhosts
Bumps traefik from v3.7.3 to v3.7.4.

---
updated-dependencies:
- dependency-name: traefik
  dependency-version: v3.7.4
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-08 13:53:46 +00:00
dependabot[bot]
63af7ec84a chore(deps): bump beautifulsoup4 from 4.14.3 to 4.15.0 in /docs/_build
Bumps [beautifulsoup4](https://www.crummy.com/software/BeautifulSoup/bs4/) from 4.14.3 to 4.15.0.

---
updated-dependencies:
- dependency-name: beautifulsoup4
  dependency-version: 4.15.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-08 13:53:24 +00:00
Dokku Bot
a9b68e8917 Release 0.38.19
# History

## 0.38.19

Install/update via the bootstrap script:

```shell
wget -NP . https://dokku.com/install/v0.38.19/bootstrap.sh
sudo DOKKU_TAG=v0.38.19 bash bootstrap.sh
```
2026-06-08 05:41:55 +00:00
Dokku Bot
05e11a873d Release 0.38.18
# History

## 0.38.18

Install/update via the bootstrap script:

```shell
wget -NP . https://dokku.com/install/v0.38.18/bootstrap.sh
sudo DOKKU_TAG=v0.38.18 bash bootstrap.sh
```

### Tests

- #8734: @dependabot[bot] chore(deps): bump golang from 1.26.3 to 1.26.4 in /tests/apps/gogrpc
- #8731: @dependabot[bot] chore(deps): bump golang from 1.26.3 to 1.26.4 in /tests/apps/go-fail-predeploy
- #8733: @dependabot[bot] chore(deps): bump golang from 1.26.3 to 1.26.4 in /tests/apps/zombies-dockerfile-tini
- #8735: @dependabot[bot] chore(deps): bump golang from 1.26.3 to 1.26.4 in /tests/apps/go-fail-postdeploy
- #8736: @dependabot[bot] chore(deps): bump golang from 1.26.3 to 1.26.4 in /tests/apps/zombies-dockerfile-no-tini
- #8738: @dependabot[bot] chore(deps): bump python from 3.15.0b1-bookworm to 3.15.0b2-bookworm in /tests/apps/dockerfile-release
- #8730: @dependabot[bot] chore(deps): bump django from 5.2.14 to 5.2.15 in /tests/apps/dockerfile-release

### Dependencies

- #8727: @dependabot[bot] chore(deps): bump github.com/melbahja/goph from 1.5.0 to 1.5.1 in /plugins/common
- #8739: @dependabot[bot] chore(deps): bump github.com/traefik/traefik/v2 from 2.11.46 to 2.11.47 in /plugins/scheduler-k3s
- #8737: @dependabot[bot] chore(deps): bump dokku/openresty-docker-proxy from 0.12.0 to 0.12.1 in /plugins/openresty-vhosts
- #8732: @dependabot[bot] chore(deps): bump python from 3.15.0b1-alpine to 3.15.0b2-alpine in /docs/_build
- #8740: @dependabot[bot] chore(deps): bump timberio/vector from 0.55.0-debian to 0.56.0-debian in /plugins/logs
- #8741: @dependabot[bot] chore(deps): bump traefik from v3.7.1 to v3.7.3 in /plugins/traefik-vhosts
2026-06-07 03:01:19 +00:00
Jose Diaz-Gonzalez
4f6acbf995 Merge pull request #8727 from dokku/dependabot/go_modules/plugins/common/github.com/melbahja/goph-1.5.1
chore(deps): bump github.com/melbahja/goph from 1.5.0 to 1.5.1 in /plugins/common
2026-06-06 22:59:14 -04:00
dependabot[bot]
54bf5b6433 chore(deps): bump github.com/melbahja/goph in /plugins/common
Bumps [github.com/melbahja/goph](https://github.com/melbahja/goph) from 1.5.0 to 1.5.1.
- [Commits](https://github.com/melbahja/goph/compare/v1.5.0...v1.5.1)

---
updated-dependencies:
- dependency-name: github.com/melbahja/goph
  dependency-version: 1.5.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-06 17:03:28 -04:00
Jose Diaz-Gonzalez
ee238c9716 Merge pull request #8739 from dokku/dependabot/go_modules/plugins/scheduler-k3s/github.com/traefik/traefik/v2-2.11.47
chore(deps): bump github.com/traefik/traefik/v2 from 2.11.46 to 2.11.47 in /plugins/scheduler-k3s
2026-06-06 17:00:51 -04:00
Jose Diaz-Gonzalez
35dcd41443 Merge pull request #8737 from dokku/dependabot/docker/plugins/openresty-vhosts/dokku/openresty-docker-proxy-0.12.1
chore(deps): bump dokku/openresty-docker-proxy from 0.12.0 to 0.12.1 in /plugins/openresty-vhosts
2026-06-06 17:00:42 -04:00
Jose Diaz-Gonzalez
17e99f3e11 Merge pull request #8734 from dokku/dependabot/docker/tests/apps/gogrpc/golang-1.26.4
chore(deps): bump golang from 1.26.3 to 1.26.4 in /tests/apps/gogrpc
2026-06-06 17:00:34 -04:00
Jose Diaz-Gonzalez
d414420303 Merge pull request #8732 from dokku/dependabot/docker/docs/_build/python-3.15.0b2-alpine
chore(deps): bump python from 3.15.0b1-alpine to 3.15.0b2-alpine in /docs/_build
2026-06-06 17:00:24 -04:00
Jose Diaz-Gonzalez
6aef528e49 Merge pull request #8731 from dokku/dependabot/docker/tests/apps/go-fail-predeploy/golang-1.26.4
chore(deps): bump golang from 1.26.3 to 1.26.4 in /tests/apps/go-fail-predeploy
2026-06-06 17:00:13 -04:00
Jose Diaz-Gonzalez
53f36bcb27 Merge pull request #8733 from dokku/dependabot/docker/tests/apps/zombies-dockerfile-tini/golang-1.26.4
chore(deps): bump golang from 1.26.3 to 1.26.4 in /tests/apps/zombies-dockerfile-tini
2026-06-06 17:00:04 -04:00
Jose Diaz-Gonzalez
578043f049 Merge pull request #8735 from dokku/dependabot/docker/tests/apps/go-fail-postdeploy/golang-1.26.4
chore(deps): bump golang from 1.26.3 to 1.26.4 in /tests/apps/go-fail-postdeploy
2026-06-06 16:59:44 -04:00
Jose Diaz-Gonzalez
c3d7ab8c04 Merge pull request #8736 from dokku/dependabot/docker/tests/apps/zombies-dockerfile-no-tini/golang-1.26.4
chore(deps): bump golang from 1.26.3 to 1.26.4 in /tests/apps/zombies-dockerfile-no-tini
2026-06-06 16:59:35 -04:00
Jose Diaz-Gonzalez
24798197de Merge pull request #8738 from dokku/dependabot/docker/tests/apps/dockerfile-release/python-3.15.0b2-bookworm
chore(deps): bump python from 3.15.0b1-bookworm to 3.15.0b2-bookworm in /tests/apps/dockerfile-release
2026-06-06 16:59:26 -04:00
Jose Diaz-Gonzalez
c4e5ad40db Merge pull request #8740 from dokku/dependabot/docker/plugins/logs/timberio/vector-0.56.0-debian
chore(deps): bump timberio/vector from 0.55.0-debian to 0.56.0-debian in /plugins/logs
2026-06-06 16:59:16 -04:00
Jose Diaz-Gonzalez
05869e3a21 Merge pull request #8741 from dokku/dependabot/docker/plugins/traefik-vhosts/traefik-v3.7.3
chore(deps): bump traefik from v3.7.1 to v3.7.3 in /plugins/traefik-vhosts
2026-06-06 16:59:06 -04:00
Jose Diaz-Gonzalez
974f2d28d5 Merge pull request #8730 from dokku/dependabot/pip/tests/apps/dockerfile-release/django-5.2.15
chore(deps): bump django from 5.2.14 to 5.2.15 in /tests/apps/dockerfile-release
2026-06-06 16:58:54 -04:00
dependabot[bot]
6ae66f3cfd chore(deps): bump traefik in /plugins/traefik-vhosts
Bumps traefik from v3.7.1 to v3.7.3.

---
updated-dependencies:
- dependency-name: traefik
  dependency-version: v3.7.3
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-05 13:53:42 +00:00
dependabot[bot]
1171b48f7b chore(deps): bump timberio/vector in /plugins/logs
Bumps timberio/vector from 0.55.0-debian to 0.56.0-debian.

---
updated-dependencies:
- dependency-name: timberio/vector
  dependency-version: 0.56.0-debian
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-04 01:57:24 +00:00
dependabot[bot]
7bd062f5de chore(deps): bump github.com/traefik/traefik/v2
Bumps [github.com/traefik/traefik/v2](https://github.com/traefik/traefik) from 2.11.46 to 2.11.47.
- [Release notes](https://github.com/traefik/traefik/releases)
- [Changelog](https://github.com/traefik/traefik/blob/v2.11.47/CHANGELOG.md)
- [Commits](https://github.com/traefik/traefik/compare/v2.11.46...v2.11.47)

---
updated-dependencies:
- dependency-name: github.com/traefik/traefik/v2
  dependency-version: 2.11.47
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-04 01:55:19 +00:00
dependabot[bot]
bdf7a0e18f chore(deps): bump python in /tests/apps/dockerfile-release
Bumps python from 3.15.0b1-bookworm to 3.15.0b2-bookworm.

---
updated-dependencies:
- dependency-name: python
  dependency-version: 3.15.0b2-bookworm
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-04 01:53:51 +00:00
dependabot[bot]
e241739610 chore(deps): bump dokku/openresty-docker-proxy
Bumps dokku/openresty-docker-proxy from 0.12.0 to 0.12.1.

---
updated-dependencies:
- dependency-name: dokku/openresty-docker-proxy
  dependency-version: 0.12.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-04 01:53:50 +00:00
dependabot[bot]
ccc09813e4 chore(deps): bump golang in /tests/apps/go-fail-postdeploy
Bumps golang from 1.26.3 to 1.26.4.

---
updated-dependencies:
- dependency-name: golang
  dependency-version: 1.26.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-04 01:53:46 +00:00
dependabot[bot]
ec7f744220 chore(deps): bump golang in /tests/apps/zombies-dockerfile-no-tini
Bumps golang from 1.26.3 to 1.26.4.

---
updated-dependencies:
- dependency-name: golang
  dependency-version: 1.26.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-04 01:53:46 +00:00
dependabot[bot]
05b2463668 chore(deps): bump golang from 1.26.3 to 1.26.4 in /tests/apps/gogrpc
Bumps golang from 1.26.3 to 1.26.4.

---
updated-dependencies:
- dependency-name: golang
  dependency-version: 1.26.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-04 01:53:41 +00:00
dependabot[bot]
673e298721 chore(deps): bump golang in /tests/apps/zombies-dockerfile-tini
Bumps golang from 1.26.3 to 1.26.4.

---
updated-dependencies:
- dependency-name: golang
  dependency-version: 1.26.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-04 01:53:10 +00:00
dependabot[bot]
ce291603e9 chore(deps): bump python in /docs/_build
Bumps python from 3.15.0b1-alpine to 3.15.0b2-alpine.

---
updated-dependencies:
- dependency-name: python
  dependency-version: 3.15.0b2-alpine
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-04 01:52:52 +00:00
dependabot[bot]
27ceca0870 chore(deps): bump golang in /tests/apps/go-fail-predeploy
Bumps golang from 1.26.3 to 1.26.4.

---
updated-dependencies:
- dependency-name: golang
  dependency-version: 1.26.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-04 01:51:50 +00:00
dependabot[bot]
d74f96d58c chore(deps): bump django in /tests/apps/dockerfile-release
Bumps [django](https://github.com/django/django) from 5.2.14 to 5.2.15.
- [Commits](https://github.com/django/django/compare/5.2.14...5.2.15)

---
updated-dependencies:
- dependency-name: django
  dependency-version: 5.2.15
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-04 01:50:42 +00:00
Dokku Bot
f5064066be Release 0.38.17
# History

## 0.38.17

Install/update via the bootstrap script:

```shell
wget -NP . https://dokku.com/install/v0.38.17/bootstrap.sh
sudo DOKKU_TAG=v0.38.17 bash bootstrap.sh
```

### New Features

- #8729: @josegonzalez Add scheduler-k3s:preview subcommand to allow previewing helm chart changes

### Dependencies

- #8728: @dependabot[bot] chore(deps): bump dokku/openresty-docker-proxy from 0.11.0 to 0.12.0 in /plugins/openresty-vhosts
2026-06-03 08:05:01 +00:00
Jose Diaz-Gonzalez
91ea6b51a9 Merge pull request #8729 from dokku/scheduler-k3s-diff-subcommand
Add scheduler-k3s:preview subcommand
2026-06-03 03:36:36 -04:00
Jose Diaz-Gonzalez
ac6e4f5793 test: allow multiple 'has been added' matches in preview test 3
For an undeployed app, the additive diff covers every chart resource, so
the literal 'has been added' header appears once per resource - six times
in the python test app's chart. `assert_output_contains` defaults to
exact-count 1, which fails. Pass -1 (at least 1) to match the actual
semantics of the test.
2026-06-03 01:53:30 -04:00
Jose Diaz-Gonzalez
4ce8afaa97 fix: let scheduler-k3s:preview tolerate a missing image
`common.GetDeployingAppImageName` runs `VerifyImage` and errors out when
no image has been built for the app. A freshly-created app has no image
yet, so the preview could never render for never-deployed apps. Add an
`AllowMissingImage` flag to `BuildOptions` that lets BuildAppChart
substitute a placeholder image string in that case; CommandPreview sets
it. The deploy path still passes `BuildOptions{}`, so missing-image
remains a hard error there.
2026-06-03 00:48:26 -04:00
Jose Diaz-Gonzalez
f1e31ded41 fix: pin scheduler-k3s:preview deployment id to the deployed release
Without this, the preview build invented a fresh timestamp for
`Values.global.deployment_id` and the resulting diff showed every
Deployment changing its `app.kubernetes.io/version` annotation - even when
nothing semantically changed. CommandPreview now reads the deployment id
out of `release.Chart.Metadata.Version` and passes it through a new
`BuildOptions.OverrideDeploymentID` parameter so the previewed manifests
carry the same version label as the live release. The deploy path still
generates a fresh timestamp.
2026-06-02 23:34:10 -04:00
Jose Diaz-Gonzalez
cd66361895 fix: sort the properties so that the snippets do not cause drift for each deploy 2026-06-02 23:18:19 -04:00
Jose Diaz-Gonzalez
9dfb2b1fc9 fix: register scheduler-k3s:preview in plugin Makefile
The previous commit added the dispatcher case but missed appending
`subcommands/preview` to the plugin's `SUBCOMMANDS` list, so no symlink
was created at install time and dokku reported the command as unknown.
2026-06-02 22:25:22 -04:00
Jose Diaz-Gonzalez
e8671790b5 feat: add --context flag to scheduler-k3s:preview
Users can override the default 3-line surrounding context per change. Pass
`--context -1` to render the full resource around every change, matching
upstream `helm diff upgrade` behavior.
2026-06-02 21:02:43 -04:00
Jose Diaz-Gonzalez
496ede44b7 feat: add scheduler-k3s:preview subcommand
Adds a `scheduler-k3s:preview <app>` command that renders a unified diff
between the manifests currently stored in the live Helm release for an app
and the manifests that the next deploy would roll out. The diff is produced
entirely via the Helm Go SDK that scheduler-k3s already uses, with no
external `helm` binary or `helm-diff` plugin install required. The
underlying diff and parse logic is vendored from `databus23/helm-diff`
(Apache 2.0) into a new internal package, trimmed of three-way-merge,
release-ownership tracking, and the non-default output formatters.

The chart-construction half of `TriggerSchedulerDeploy` has been extracted
into a reusable `BuildAppChart` helper so deploy and preview share the
same chart materialization without duplicating template logic. Secret
values are redacted by default in preview output; `--show-secrets` and
`--show-secrets-decoded` flags match the upstream `helm diff` UX. Only the
main app helm release is compared in this iteration; auxiliary releases
for config vars, image-pull secrets, and TLS certificates are out of scope
and documented as such.
2026-06-02 20:28:31 -04:00
Jose Diaz-Gonzalez
db798dfe16 Merge pull request #8728 from dokku/dependabot/docker/plugins/openresty-vhosts/dokku/openresty-docker-proxy-0.12.0
chore(deps): bump dokku/openresty-docker-proxy from 0.11.0 to 0.12.0 in /plugins/openresty-vhosts
2026-06-02 19:24:49 -04:00
dependabot[bot]
ec4d406460 chore(deps): bump dokku/openresty-docker-proxy
Bumps dokku/openresty-docker-proxy from 0.11.0 to 0.12.0.

---
updated-dependencies:
- dependency-name: dokku/openresty-docker-proxy
  dependency-version: 0.12.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-02 17:30:59 +00:00
Dokku Bot
fd8247018f Release 0.38.16
# History

## 0.38.16

Install/update via the bootstrap script:

```shell
wget -NP . https://dokku.com/install/v0.38.16/bootstrap.sh
sudo DOKKU_TAG=v0.38.16 bash bootstrap.sh
```

### Bug Fixes

- #8723: @josegonzalez Match control-plane nodes by their modern label
- #8724: @josegonzalez Stop truncating existing files in common.TouchFile
2026-05-31 22:50:58 +00:00
Jose Diaz-Gonzalez
af4ca1b8ba Merge pull request #8723 from dokku/8721-scheduler-k3s-cluster-add-fails-with-no-nodes-found-in-the-cluster 2026-05-31 18:49:37 -04:00
Jose Diaz-Gonzalez
e81afe5274 Merge pull request #8724 from dokku/8722-adding-a-new-host-to-a-k3s-cluster-without-insecure-allow-unknown-hosts-clears-the-dokku-user-s-known-hosts 2026-05-31 18:12:28 -04:00
Jose Diaz-Gonzalez
cf84679133 fix: stop truncating existing files in common.TouchFile
`common.TouchFile` opened files with `O_TRUNC`, so the call from `common.SshTask.Execute` against `~/.ssh/known_hosts` emptied the dokku user's previously trusted host keys before `goph.DefaultKnownHosts()` read them. Running `scheduler-k3s:cluster:add` without `--insecure-allow-unknown-hosts` then failed with `knownhosts: key is unknown` and left a zero-byte `known_hosts`. The function now matches `touch(1)` semantics: create the file if missing, otherwise leave its contents intact.
2026-05-31 16:37:15 -04:00
Jose Diaz-Gonzalez
099cf10e98 fix: match control-plane nodes by their modern label
Kubernetes 1.20 deprecated the node-role.kubernetes.io/master label and replaced it with node-role.kubernetes.io/control-plane, and 1.24 dropped the legacy label entirely. The scheduler-k3s:cluster:add join path still filtered control-plane nodes with master=true, so on any k3s release built from Kubernetes 1.24+ the lookup matched zero nodes and aborted with "no nodes found in the cluster" before the worker could join.
2026-05-31 16:24:23 -04:00
Dokku Bot
213d89b1e4 Release 0.38.15
# History

## 0.38.15

Install/update via the bootstrap script:

```shell
wget -NP . https://dokku.com/install/v0.38.15/bootstrap.sh
sudo DOKKU_TAG=v0.38.15 bash bootstrap.sh
```

### Bug Fixes

- #8718: @josegonzalez Persist scheduler-k3s chart overrides as JSON maps

### Other

- #8720: @josegonzalez Persist scheduler-k3s annotations and labels as JSON maps
2026-05-31 08:05:25 +00:00
Jose Diaz-Gonzalez
76b9f03818 Merge pull request #8720 from dokku/8719-scheduler-k3s-annotations-and-labels-migrate-to-propertymap-storage-to-support-multi-line-values 2026-05-31 04:04:08 -04:00
Jose Diaz-Gonzalez
a0bae9b0a9 Merge pull request #8718 from dokku/8717-scheduler-k3s-charts-set-cannot-persist-property-names-containing-and-silently-breaks-multi-line-values 2026-05-31 03:40:52 -04:00
Jose Diaz-Gonzalez
21ed5fb738 fix: persist scheduler-k3s annotations and labels as JSON maps
Annotation and label values containing a newline previously round-tripped
as two adjacent `key: value` lines, and the second line then failed the
`SplitN(line, ": ", 2)` parse on read. Move the per-`(processType,
resourceType)` files to `PropertyMap*` storage so `\n` in values and `/`
in keys are preserved verbatim. An idempotent `TriggerInstall` migration
walks `--global` and every app, converting any legacy line-formatted file
in place by probing `PropertyMapGet` first and rewriting via
`PropertyListGet` only when the probe fails. Property names are
unchanged, so the annotations/labels report scanner and the
`reservedAnnotationPrefixes` filter keep working without modification.

Closes #8719.
2026-05-31 02:38:35 -04:00
Jose Diaz-Gonzalez
4ae48c6ea0 test: pin test-env system identity and core-plugins path
PropertyMap tests went through SetPermissions, which looks up the `dokku` user/group; the fresh `golang:1.26.2` container used by `go-test-plugin-in-docker` has neither, so the chown failed with `unknown group dokku`. Override `DOKKU_SYSTEM_USER` and `DOKKU_SYSTEM_GROUP` to `root` in the property and chart-migration test setups so the chown targets an identity that exists everywhere. The config tests also called `plugn trigger post-config-update` without `PLUGIN_CORE_AVAILABLE_PATH` set, so the hook tried to source `/common/functions` and logged a noisy warning on every test; point the env var at the canonical `/var/lib/dokku/core-plugins/available` location.
2026-05-31 02:23:35 -04:00
Jose Diaz-Gonzalez
b8929712d4 fix: persist scheduler-k3s chart overrides as JSON maps
Chart property names containing `/` failed because per-key flat-file storage interpreted the slash as a filesystem path separator, and any move to line-based storage would silently truncate multi-line values. A new `PropertyMap*` helper family in `common` persists each map as a single JSON file so both `/` in keys and `\n` in values round-trip losslessly. Chart overrides move to `chart-overrides.<chart>` and an idempotent `TriggerInstall` migration rewrites any legacy `chart.<chart>.<key>` files into the new layout. The deprecated `scheduler-k3s:set --global chart.*` form is rerouted through the same map storage so it does not silently orphan writes. Closes #8717.
2026-05-31 01:54:28 -04:00
Dokku Bot
ff00bcb218 Release 0.38.14
# History

## 0.38.14

Install/update via the bootstrap script:

```shell
wget -NP . https://dokku.com/install/v0.38.14/bootstrap.sh
sudo DOKKU_TAG=v0.38.14 bash bootstrap.sh
```

### New Features

- #8716: @josegonzalez Add scheduler-k3s annotations:report and labels:report
- #8715: @josegonzalez Add scheduler-k3s:charts:set and :charts:report
2026-05-31 01:12:35 +00:00
Jose Diaz-Gonzalez
580aa892de Merge pull request #8716 from dokku/scheduler-k3s-report-subcommands 2026-05-30 21:11:10 -04:00
Jose Diaz-Gonzalez
f9183bbff2 Merge pull request #8715 from dokku/scheduler-k3s-charts-set 2026-05-30 20:49:27 -04:00
Jose Diaz-Gonzalez
5dbb2951bb feat: add scheduler-k3s annotations:report and labels:report
The scheduler-k3s plugin exposes `annotations:set` and `labels:set` but no matching report subcommands, so scripts could not inspect the configured state for idempotent management without reading the property files directly. The new `scheduler-k3s:annotations:report` and `scheduler-k3s:labels:report` surface the configured entries with stdout, JSON, single-flag query, and `--process-type` / `--resource-type` filtering, mirroring the recently added `scheduler-k3s:charts:report`. The literal `GlobalProcessType` value `--global` is rendered as `global` in report keys to avoid leading dashes. The `scheduler-k3s:autoscaling-auth:report` command is updated alongside to loop over every app when no app and no `--global` flag is provided, matching the convention used by `scheduler-k3s:report`.
2026-05-30 20:12:00 -04:00
Jose Diaz-Gonzalez
4346a18194 feat: add scheduler-k3s:charts:set and :charts:report
Helm chart overrides on the scheduler-k3s plugin were previously set
through the generic `scheduler-k3s:set --global chart.<chart>.<property>`
interface, which mixed chart-level configuration into the same command
that manages scheduler properties and offered no focused way to inspect
which overrides were configured. A dedicated `scheduler-k3s:charts:set`
sets and clears chart-specific helm values, and a complementary
`scheduler-k3s:charts:report` surfaces configured overrides per chart
with optional JSON output and single-field flag queries. The legacy form
on `scheduler-k3s:set` continues to work but now emits a deprecation
warning pointing users at the new subcommand.
2026-05-30 19:35:20 -04:00
Dokku Bot
0cea642dd9 Release 0.38.13
# History

## 0.38.13

Install/update via the bootstrap script:

```shell
wget -NP . https://dokku.com/install/v0.38.13/bootstrap.sh
sudo DOKKU_TAG=v0.38.13 bash bootstrap.sh
```

### Bug Fixes

- #8713: @josegonzalez Make storage:mount upsert the existing attachment

### New Features

- #8714: @josegonzalez Expose per-attachment fields in storage:report
- #8712: @josegonzalez Expose attachment readonly and volume_options in storage:list json
- #8711: @josegonzalez Add --volume-options flag to storage:mount
2026-05-30 10:21:55 +00:00
Jose Diaz-Gonzalez
f86b2cb1cb Merge pull request #8714 from dokku/8710-storage-report-include-volume-options-for-each-attachment 2026-05-30 06:20:40 -04:00
Jose Diaz-Gonzalez
641be4334d Merge pull request #8713 from dokku/8709-storage-mount-update-existing-attachment-in-place-instead-of-duplicating 2026-05-30 04:56:27 -04:00
Jose Diaz-Gonzalez
e13b9d33f9 Merge pull request #8712 from dokku/8708-storage-list-format-json-include-volume-options
Expose attachment readonly and volume_options in storage:list json
2026-05-30 04:19:02 -04:00
Jose Diaz-Gonzalez
bec6b9f14a feat: expose per-attachment fields in storage:report
storage:report gains a flat dotted key per attachment field (entry-name, host-path, container-path, phases, process-type, subpath, readonly, volume-options, volume-chown) under the --storage-attachment.<index>.<field> shape. Both stdout and JSON pick the keys up through the existing common.ReportSingleApp pipeline. Attachments that reference a missing storage entry emit a warning and are skipped, so the rest of the report still renders. Closes #8710.
2026-05-30 04:11:30 -04:00
Jose Diaz-Gonzalez
f896c731f2 Merge pull request #8711 from dokku/8707-storage-mount-volume-options-flag
Add --volume-options flag to storage:mount
2026-05-30 03:26:08 -04:00
Jose Diaz-Gonzalez
3bb21b6987 feat: make storage:mount upsert the existing attachment
Re-running `storage:mount <app> <entry> --container-dir <path>` against an existing `(entry, container_dir, process_type)` tuple now updates the attachment's mount-time fields in place instead of erroring with `already mounted`. Declarative tooling that wants to change `--volume-options`, `--volume-chown`, `--phase`, `--volume-subpath`, or `--volume-readonly` on an existing mount no longer has to unmount-then-remount, which briefly dropped the volume from `storage:report` and raced against any deploy that fired in the window. The legacy `host:container[:opts]` form keeps its strict `Mount path already exists.` failure.
2026-05-30 03:23:32 -04:00
Jose Diaz-Gonzalez
e9160db769 fix: expose attachment readonly and volume_options in storage:list json
The `storage:list <app> --format json` payload conflated the
attachment's `Readonly` flag and its `VolumeOptions` field into a
single derived `volume_options` string that rendered as `ro`,
`<options>`, or `ro,<options>` depending on which fields were set on
the underlying attachment. That shape is fine for the legacy
`host:container[:options]` text view but it leaves drift-detection
tooling unable to tell whether a `ro` token came from
`Attachment.Readonly == true` or from the operator setting
`Attachment.VolumeOptions = "ro"` directly. The JSON now exposes
`readonly` (boolean) and `volume_options` (string) as separate
omitempty keys populated straight from the attachment, and
`formatStorageListEntry` combines them at format time for the colon-
form text view. `ParseMountPath` was extended in lockstep so callers
of the legacy `host:container:opts` form no longer have to special-
case the `ro` token themselves.
2026-05-30 03:00:21 -04:00
Jose Diaz-Gonzalez
f4d27be7a6 feat: add --volume-options flag to storage:mount
The named-entry form of `storage:mount` had no way to set the attachment's `volume_options`, even though the legacy `host:container:opts` colon form parses options into the same field and every downstream consumer (the docker-args trigger and the storage:list/storage:report display path) already renders them. Tooling that declaratively re-applies attachments silently dropped options on every re-apply.
2026-05-30 02:28:14 -04:00
Dokku Bot
411cb88796 Release 0.38.12
# History

## 0.38.12

Install/update via the bootstrap script:

```shell
wget -NP . https://dokku.com/install/v0.38.12/bootstrap.sh
sudo DOKKU_TAG=v0.38.12 bash bootstrap.sh
```

### Bug Fixes

- #8706: @josegonzalez Align apps:set/apps:report with what dokku actually reads
2026-05-30 03:48:50 +00:00
Jose Diaz-Gonzalez
25d96f3f23 Merge pull request #8706 from dokku/8705-apps-drop-vestigial-global-deploy-source-deploy-source-metadata-and-surface-disable-autocreation-in-apps-report
Align apps:set/apps:report with what dokku actually reads
2026-05-29 23:47:19 -04:00
Jose Diaz-Gonzalez
da92b3721f fix: align apps:set/apps:report with what dokku actually reads
The apps plugin accepted `apps:set --global deploy-source` and
`apps:set --global deploy-source-metadata` even though nothing reads
those properties globally, accepted `apps:set <app> disable-autocreation`
even though only the global form is consulted by `maybeCreateApp`, and
never emitted `disable-autocreation` in `apps:report` for either scope.
Drop the global `deploy-source*` writes from `GlobalProperties`, reject
per-app `disable-autocreation` writes at the plugin level, and surface
`--app-global-disable-autocreation` in both the per-app and `--global`
reports so the property the runtime actually reads is round-trippable.
2026-05-29 22:55:24 -04:00
Dokku Bot
34b19f99b9 Release 0.38.11
# History

## 0.38.11

Install/update via the bootstrap script:

```shell
wget -NP . https://dokku.com/install/v0.38.11/bootstrap.sh
sudo DOKKU_TAG=v0.38.11 bash bootstrap.sh
```

### Bug Fixes

- #8704: @josegonzalez Pass storage entry basename to chown-storage-dir
2026-05-30 01:05:46 +00:00
Jose Diaz-Gonzalez
214c8cc2e1 Merge pull request #8704 from dokku/8703-storage-create-chown-passes-the-full-host-path-to-chown-storage-dir-instead-of-the-entry-name
Pass storage entry basename to chown-storage-dir
2026-05-29 21:04:36 -04:00
Jose Diaz-Gonzalez
94c43f6dd8 fix: pass storage entry basename to chown-storage-dir
storage:create --chown invoked chown-storage-dir with the full host path, but the helper validates a basename and prepends the storage root itself, so every call failed with `Directory can only contain the following set of characters`. Pass the entry name and reject the combination of --chown with a non-default host path, since the helper only manages the default storage location.
2026-05-29 20:49:12 -04:00
Dokku Bot
59d880e3f9 Release 0.38.10
# History

## 0.38.10

Install/update via the bootstrap script:

```shell
wget -NP . https://dokku.com/install/v0.38.10/bootstrap.sh
sudo DOKKU_TAG=v0.38.10 bash bootstrap.sh
```

### New Features

- #8702: @josegonzalez Prompt for confirmation on storage:destroy

### Tests

- #8698: @dependabot[bot] chore(deps-dev): bump org.apache.maven.plugins:maven-dependency-plugin from 3.10.0 to 3.11.0 in /tests/apps/java
2026-05-29 21:33:18 +00:00
Jose Diaz-Gonzalez
14013c8a7c Merge pull request #8702 from dokku/8701-storage-destroy-removes-a-storage-registry-entry-without-confirmation 2026-05-29 17:31:58 -04:00
Jose Diaz-Gonzalez
3493869fa4 feat: prompt for confirmation on storage:destroy
`storage:destroy` now prompts for confirmation before removing a named storage entry, matching the behavior of other destructive commands such as `apps:destroy` and `network:destroy`. The prompt can be skipped with the `--force` flag or the global `dokku --force` flag for non-interactive callers.
2026-05-29 14:31:20 -04:00
Jose Diaz-Gonzalez
d003bfaf0e Merge pull request #8698 from dokku/dependabot/maven/tests/apps/java/org.apache.maven.plugins-maven-dependency-plugin-3.11.0
chore(deps-dev): bump org.apache.maven.plugins:maven-dependency-plugin from 3.10.0 to 3.11.0 in /tests/apps/java
2026-05-28 12:43:01 -04:00
dependabot[bot]
b08f00a105 chore(deps-dev): bump org.apache.maven.plugins:maven-dependency-plugin
Bumps [org.apache.maven.plugins:maven-dependency-plugin](https://github.com/apache/maven-dependency-plugin) from 3.10.0 to 3.11.0.
- [Release notes](https://github.com/apache/maven-dependency-plugin/releases)
- [Commits](https://github.com/apache/maven-dependency-plugin/compare/maven-dependency-plugin-3.10.0...maven-dependency-plugin-3.11.0)

---
updated-dependencies:
- dependency-name: org.apache.maven.plugins:maven-dependency-plugin
  dependency-version: 3.11.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-05-28 15:54:58 +00:00
Dokku Bot
c8101aa2a7 Release 0.38.9
# History

## 0.38.9

Install/update via the bootstrap script:

```shell
wget -NP . https://dokku.com/install/v0.38.9/bootstrap.sh
sudo DOKKU_TAG=v0.38.9 bash bootstrap.sh
```

### New Features

- #8697: @josegonzalez Split openresty report into raw/computed/global

### Refactors

- #8696: @josegonzalez Treat empty ps restart-policy as an unset
2026-05-28 09:14:30 +00:00
Jose Diaz-Gonzalez
a561a5069e Merge pull request #8696 from dokku/8695-ps-set-app-restart-policy-should-unset-not-error-with-invalid-restart-policy-specified 2026-05-28 05:13:16 -04:00
Jose Diaz-Gonzalez
5d802e3cf4 fix: separate docker-args outputs to avoid arg collisions
Emitting the restart policy as a `--restart` argument from a `docker-args-process-deploy` trigger exposed a latent gluing bug: proxy and builder triggers concatenated `$STDIN$output` with no separator, and the scheduler and builders appended `docker-args-process-*` output directly onto the older `docker-args-*` output, so adjacent arguments could merge into values like `--restart=on-failure:10--label`. A space is now inserted at both the trigger echo and the concatenation so arguments always stay separated.
2026-05-28 04:16:55 -04:00
Jose Diaz-Gonzalez
fec872711a fix: treat empty ps restart-policy as an unset
`dokku ps:set <app> restart-policy` with no value erroneously returned `Invalid restart-policy specified` instead of unsetting the property like every other ps property. The restart policy is now managed as a normal app and global property surfaced through the `--ps-restart-policy`, `--ps-global-restart-policy`, and `--ps-computed-restart-policy` report flags, with the effective value applied at deploy time and existing values migrated on install. Because it is no longer stored as a Docker option it no longer appears in `docker-options:report`, and `--ps-restart-policy` now reports the raw value with the `on-failure:10` default available via `--ps-computed-restart-policy`.
2026-05-28 03:10:03 -04:00
Jose Diaz-Gonzalez
44dd5e9eea Merge pull request #8697 from dokku/8694-extend-report-raw-computed-split-8675-to-openresty-vhosts
Split openresty report into raw/computed/global
2026-05-28 03:08:23 -04:00
Jose Diaz-Gonzalez
64b104a2a3 feat: split openresty report into raw/computed/global
Exposes raw, global, and computed report flags for every openresty per-app property and allows those properties to be set with `--global`, so external tooling can distinguish a property that was never set from one left at its built-in default. The computed value resolves the per-app value first, then the global value, then the default. Also corrects `client-header-timeout` which read the `client-body-timeout` key and sets the computed `client-max-body-size` default to `1m`.
2026-05-28 00:03:47 -04:00
apple
89e359ae7d 更新 letsencrypt
Some checks failed
CodeQL / Analyze (go) (push) Has been cancelled
2026-04-25 14:14:39 +08:00
apple
96812e7ed4 Merge branch 'master' into cn
* master:
  chore(deps): bump github.com/fluxcd/pkg/kustomize
  chore(deps-dev): bump heroku/heroku-buildpack-php in /tests/apps/php
  chore(deps): bump github.com/traefik/traefik/v2
  chore(deps): bump timberio/vector in /plugins/logs
  chore(deps): bump traefik in /plugins/traefik-vhosts
  chore(deps): bump click from 8.3.2 to 8.3.3 in /docs/_build
  chore(deps): bump k8s.io/kubectl in /plugins/scheduler-k3s
  chore(deps): bump k8s.io/client-go in /plugins/scheduler-k3s
  chore(deps): update markdown requirement in /docs/_build
  chore(deps): bump ruby in /tests/apps/dockerfile-entrypoint
  chore(deps): bump psycopg2-binary in /tests/apps/dockerfile-release
  chore(deps): bump k8s.io/kubernetes in /plugins/scheduler-k3s
  chore(deps): bump github.com/go-openapi/jsonpointer
  chore: label test app dependency updates as type: tests
2026-04-25 14:13:20 +08:00
apple
72de4581be Merge branch 'master' into cn
Some checks failed
CodeQL / Analyze (go) (push) Failing after 1m9s
* master: (35 commits)
  Release 0.37.9
  chore(deps): bump github.com/go-acme/lego/v4 in /plugins/scheduler-k3s
  chore(deps): bump github.com/moby/spdystream in /plugins/scheduler-k3s
  chore(deps): bump github.com/go-openapi/jsonpointer
  chore(deps): bump k8s.io/api in /plugins/scheduler-k3s
  Release 0.37.8
  chore(deps): bump k8s.io/apimachinery in /plugins/scheduler-k3s
  chore(deps): bump k8s.io/kubernetes in /plugins/scheduler-k3s
  chore(deps): bump packaging from 26.0 to 26.1 in /docs/_build
  chore(deps): bump github.com/fluxcd/pkg/kustomize
  chore(deps): bump zipp from 3.23.0 to 3.23.1 in /docs/_build
  fix(deps): pin controller-runtime to v0.22.4 for keda compatibility
  chore(deps): bump github.com/cert-manager/cert-manager
  chore: bump dependencies in tests/apps/php
  chore: upgrade traefik from v2.11.41 to v2.11.42
  chore: bump go modules
  chore(deps): bump mvdan.cc/sh/v3 from 3.13.0 to 3.13.1 in /plugins/cron
  chore: bump dependencies in tests/apps/multi
  chore: bump go modules
  chore: bump go modules
  ...
2026-04-20 13:59:23 +08:00
apple
bf4bd0e3ea Merge branch 'master' into cn
* master: (68 commits)
  chore(deps): bump werkzeug in /tests/apps/python-flask
  chore(deps): bump github.com/go-jose/go-jose/v4
  chore(deps): bump rack from 3.2.5 to 3.2.6 in /tests/apps/ruby
  chore(deps): bump pymdown-extensions in /docs/_build
  Add application/graphql-response+json to nginx gzip_types
  chore(deps): bump google.golang.org/grpc in /tests/apps/gogrpc
  chore(deps): bump pygments from 2.19.2 to 2.20.0 in /docs/_build
  chore(deps): bump golang.org/x/crypto in /plugins/common
  chore: bump go modules
  chore(deps): bump github.com/fatih/color in /plugins/common
  chore(deps): bump brace-expansion in /tests/apps/multi
  chore(deps): bump gunicorn in /tests/apps/python-flask
  chore(deps): bump path-to-regexp in /tests/apps/checks-root
  chore(deps): bump gunicorn in /tests/apps/dockerfile-release
  chore(deps): bump traefik in /plugins/traefik-vhosts
  chore(deps): bump gunicorn from 25.2.0 to 25.3.0 in /tests/apps/multi
  chore(deps): bump werkzeug in /tests/apps/python-flask
  chore(deps): bump picomatch from 2.3.1 to 2.3.2 in /tests/apps/multi
  chore(deps): bump gunicorn in /tests/apps/dockerfile-release
  chore(deps): bump djangorestframework in /tests/apps/dockerfile-release
  ...
2026-04-08 10:14:03 +08:00
apple
28f76dd30c Merge branch 'master' into cn
* master: (427 commits)
  chore(deps): bump gunicorn from 25.0.2 to 25.1.0 in /tests/apps/multi
  chore(deps): bump flask from 3.1.2 to 3.1.3 in /tests/apps/multi
  chore(deps): bump python in /docs/_build
  chore(deps): bump google.golang.org/grpc in /tests/apps/gogrpc
  chore(deps): bump qs from 6.14.1 to 6.14.2 in /tests/apps/checks-root
  chore(deps): bump rack from 3.2.4 to 3.2.5 in /tests/apps/ruby
  fix: call correct function for limiting letsencrypt to certain domains
  chore(deps): bump gunicorn in /tests/apps/python-flask
  chore(deps): bump whitenoise in /tests/apps/dockerfile-release
  chore(deps): bump phusion/baseimage from noble-1.0.2 to noble-1.0.3
  chore(deps): bump actions/upload-artifact from 6 to 7
  chore(deps): bump actions/download-artifact from 7 to 8
  chore(deps): bump github.com/traefik/traefik/v2
  chore(deps): bump gunicorn in /tests/apps/dockerfile-release
  chore(deps): bump flask from 3.1.2 to 3.1.3 in /tests/apps/python-flask
  chore(deps): bump traefik from 3.6.7 to 3.6.9 in /plugins/traefik-vhosts
  chore(deps): bump mkdocs-material from 9.7.1 to 9.7.3 in /docs/_build
  chore(deps): bump byjg/easy-haproxy in /plugins/haproxy-vhosts
  chore(deps): bump dj-database-url in /tests/apps/dockerfile-release
  chore(deps): bump werkzeug in /tests/apps/python-flask
  ...

# Conflicts:
#	common.mk
#	contrib/dependencies.json
2026-03-02 16:41:58 +08:00
apple
807271359d 删除插件 2025-10-30 10:45:43 +08:00
apple
479287c3e6 删除mysql 2025-10-30 10:37:23 +08:00
apple
809a271859 添加 mysql redis postgres 插件 2025-10-27 13:17:17 +08:00
apple
a16eae23ce Merge commit 'c7cbebece5c0b03e9777cd8b6228659c340cc6dc' into cn 2025-10-16 16:56:54 +08:00
apple
46b20246db 添加 ssl 插件 2025-10-11 17:50:48 +08:00
apple
6f31504a29 修改docker 安装方式 2025-10-09 13:11:15 +08:00
apple
f0e2fd35bd 忽略 wget ssl 检查 2025-10-09 11:50:32 +08:00
apple
69eee39904 Merge branch 'master' into cn
# Conflicts:
#	common.mk
#	contrib/dependencies.json
2025-10-09 11:40:06 +08:00
root
ba8e522ff8 修改成国内可以部署 2025-01-23 14:39:15 +08:00
575 changed files with 28843 additions and 5487 deletions

View File

@@ -330,6 +330,11 @@ updates:
open-pull-requests-limit: 10
labels:
- "type: dependencies"
ignore:
- dependency-name: "*"
update-types:
- "version-update:semver-minor"
- "version-update:semver-patch"
- package-ecosystem: "docker"
directory: "/"
schedule:

View File

@@ -24,7 +24,7 @@ jobs:
skip: ${{ steps.check-commit.outputs.skip }}
steps:
- uses: actions/checkout@v6
- uses: actions/checkout@v7
with:
ref: ${{ github.event.pull_request.head.sha }}
@@ -53,7 +53,7 @@ jobs:
timeout-minutes: 45
steps:
- uses: actions/checkout@v6
- uses: actions/checkout@v7
- name: set up qemu
uses: docker/setup-qemu-action@v4
@@ -87,7 +87,7 @@ jobs:
timeout-minutes: 20
steps:
- uses: actions/checkout@v6
- uses: actions/checkout@v7
- name: build-image
uses: ./.github/actions/build-image
@@ -101,7 +101,7 @@ jobs:
timeout-minutes: 20
steps:
- uses: actions/checkout@v6
- uses: actions/checkout@v7
- name: build-image
uses: ./.github/actions/build-image
@@ -117,7 +117,7 @@ jobs:
matrix: ${{fromJson(needs.build.outputs.matrix)}}
steps:
- uses: actions/checkout@v6
- uses: actions/checkout@v7
- name: download packages
uses: actions/download-artifact@v8
@@ -156,7 +156,7 @@ jobs:
fail-fast: false
steps:
- uses: actions/checkout@v6
- uses: actions/checkout@v7
- name: download packages
uses: actions/download-artifact@v8
@@ -190,7 +190,7 @@ jobs:
GITHUB_NODE_INDEX: ${{ matrix.index }}
steps:
- uses: actions/checkout@v6
- uses: actions/checkout@v7
- name: download packages
uses: actions/download-artifact@v8

View File

@@ -42,7 +42,7 @@ jobs:
steps:
- name: Checkout repository
uses: actions/checkout@v6
uses: actions/checkout@v7
# workaround for https://github.com/github/codeql/issues/14235
- name: Remove go.work file

View File

@@ -19,7 +19,7 @@ jobs:
matrix: ${{ steps.matrix.outputs.matrix }}
steps:
- name: Clone
uses: actions/checkout@v6
uses: actions/checkout@v7
- name: Build dependency matrix
id: matrix
@@ -48,7 +48,7 @@ jobs:
cancel-in-progress: false
steps:
- name: Clone
uses: actions/checkout@v6
uses: actions/checkout@v7
- name: Resolve latest release
id: latest

View File

@@ -16,12 +16,12 @@ jobs:
runs-on: ubuntu-24.04
steps:
- name: Cloning repo
uses: actions/checkout@v6
uses: actions/checkout@v7
with:
fetch-depth: 0
- name: "Setup python 3.10"
uses: actions/setup-python@v6
uses: actions/setup-python@v7
with:
python-version: '3.10'

View File

@@ -20,7 +20,7 @@ jobs:
runs-on: ubuntu-24.04
steps:
- name: Clone
uses: actions/checkout@v6
uses: actions/checkout@v7
- name: Run hadolint
uses: hadolint/hadolint-action@2332a7b74a6de0dda2e2221d575162eba76ba5e5
# v3.0.0 => 4b5806eb9c6bee4954fc0e0cc3ad6175fc9782c1
@@ -30,9 +30,9 @@ jobs:
runs-on: ubuntu-24.04
steps:
- name: Clone
uses: actions/checkout@v6
uses: actions/checkout@v7
- name: Setup node
uses: actions/setup-node@v6
uses: actions/setup-node@v7
with:
node-version: '20'
cache: 'npm'
@@ -48,7 +48,7 @@ jobs:
if: github.event.pull_request.user.login != 'dependabot[bot]'
steps:
- name: Checkout code
uses: actions/checkout@v6
uses: actions/checkout@v7
- name: Setup packer
uses: hashicorp/setup-packer@main
with:
@@ -67,7 +67,7 @@ jobs:
runs-on: ubuntu-24.04
steps:
- name: Clone
uses: actions/checkout@v6
uses: actions/checkout@v7
- name: Run shellcheck
uses: ludeeus/action-shellcheck@00cae500b08a931fb5698e11e79bfbd38e612a38
# 1.1.0 => 94e0aab03ca135d11a35e5bfc14e6746dc56e7e9
@@ -77,7 +77,7 @@ jobs:
runs-on: ubuntu-24.04
steps:
- name: Clone
uses: actions/checkout@v6
uses: actions/checkout@v7
- name: Run shfmt
uses: luizm/action-sh-checker@883217215b11c1fabbf00eb1a9a041f62d74c744
# v0.5.0 => edd0e45ecff35b05f162052b50df50976c1b74fc
@@ -91,7 +91,7 @@ jobs:
runs-on: ubuntu-24.04
steps:
- name: Clone
uses: actions/checkout@v6
uses: actions/checkout@v7
- name: Run yamllint
uses: ibiqlik/action-yamllint@2576378a8e339169678f9939646ee3ee325e845c
# v3.1.1 => 2576378a8e339169678f9939646ee3ee325e845c

View File

@@ -25,7 +25,7 @@ jobs:
outputs:
version: ${{ steps.version.outputs.version }}
steps:
- uses: actions/checkout@v6
- uses: actions/checkout@v7
with:
fetch-depth: 0
@@ -84,7 +84,7 @@ jobs:
needs: release
steps:
- name: Checkout code
uses: actions/checkout@v6
uses: actions/checkout@v7
- name: Setup packer
uses: hashicorp/setup-packer@main
@@ -120,7 +120,7 @@ jobs:
needs: release
steps:
- name: Checkout code
uses: actions/checkout@v6
uses: actions/checkout@v7
- name: Bump Azure Template
env:
BOT_GITHUB_USERNAME: ${{ secrets.HOMEBREW_GITHUB_USERNAME }}

View File

@@ -1,5 +1,490 @@
# History
## 0.38.27
Install/update via the bootstrap script:
```shell
wget -NP . https://dokku.com/install/v0.38.27/bootstrap.sh
sudo DOKKU_TAG=v0.38.27 bash bootstrap.sh
```
### Bug Fixes
- #8933: @josegonzalez Do not require a local image for k3s deploys
- #8930: @josegonzalez Do not import an already-migrated ENV file
- #8919: @josegonzalez Regenerate vector config on app lifecycle changes
- #8917: @josegonzalez Apply app-label-alias to shipped events
### New Features
- #8934: @josegonzalez Report traefik dns-provider env vars as global keys
- #8920: @josegonzalez Add storage directory mode and removal flags
- #8914: @josegonzalez Add vector-cron-sink for scheduled cron task output
### Tests
- #8931: @dependabot[bot] chore(deps): bump djangorestframework from 3.17.2 to 3.18.0 in /tests/apps/dockerfile-release
- #8927: @dependabot[bot] chore(deps): bump djangorestframework from 3.17.1 to 3.17.2 in /tests/apps/dockerfile-release
- #8923: @dependabot[bot] chore(deps): bump python from 3.15.0b4-bookworm to 3.15.0rc1-bookworm in /tests/apps/dockerfile-release
### Dependencies
- #8926: @dependabot[bot] chore(deps): bump github.com/gliderlabs/sigil from 0.12.0 to 0.12.1 in /plugins/nginx-vhosts
- #8925: @dependabot[bot] chore(deps): bump packaging from 26.2 to 26.3 in /docs/_build
- #8921: @dokku-bot chore: bump pack to 0.40.9
- #8924: @dependabot[bot] chore(deps): bump soupsieve from 2.9.1 to 2.9.2 in /docs/_build
- #8922: @dependabot[bot] chore(deps): bump python from 3.15.0b4-alpine to 3.15.0rc1-alpine in /docs/_build
- #8915: @dokku-bot chore: bump herokuish to 0.11.15
## 0.38.26
Install/update via the bootstrap script:
```shell
wget -NP . https://dokku.com/install/v0.38.26/bootstrap.sh
sudo DOKKU_TAG=v0.38.26 bash bootstrap.sh
```
### Bug Fixes
- #8906: @josegonzalez Match docker options by shell word when removing
### New Features
- #8911: @josegonzalez Route wildcard domains through traefik on k3s
- #8909: @josegonzalez Support manually managed cert issuers on k3s
- #8903: @josegonzalez Support kernel sysctls on the k3s scheduler
- #8856: @youdie006 Add pre-parsed port_mappings to ports:report json
### Refactors
- #8863: @josegonzalez Move host-crontab generation into cron plugin
### Documentation
- #8908: @josegonzalez Document --global on scheduler-k3s report and set
- #8858: @bakatz Added instructions for restoring backups on different CPU architectures.
### Tests
- #8893: @dependabot[bot] chore(deps): bump django from 5.2.16 to 5.2.17 in /tests/apps/dockerfile-release
- #8891: @dependabot[bot] chore(deps-dev): bump heroku/heroku-buildpack-php from 293 to 294 in /tests/apps/php
- #8877: @dependabot[bot] chore(deps): bump google.golang.org/grpc from 1.82.1 to 1.83.0 in /tests/apps/gogrpc
- #8874: @dependabot[bot] chore(deps): bump sass from 1.101.7 to 1.102.0 in /tests/apps/multi
- #8870: @dependabot[bot] chore(deps): bump sass from 1.101.6 to 1.101.7 in /tests/apps/multi
- #8866: @dependabot[bot] chore(deps): bump sass from 1.101.3 to 1.101.6 in /tests/apps/multi
- #8860: @dependabot[bot] chore(deps): bump setuptools from 78.1.1 to 83.0.0 in /tests/apps/dockerfile-release
- #8859: @dependabot[bot] chore(deps): bump immutable from 5.1.5 to 5.1.9 in /tests/apps/multi
- #8855: @dependabot[bot] chore(deps): bump sass from 1.101.0 to 1.101.3 in /tests/apps/multi
- #8857: @dependabot[bot] chore(deps): bump body-parser from 2.2.1 to 2.3.0 in /tests/apps/checks-root
- #8853: @dependabot[bot] chore(deps): bump python from 3.15.0b3-bookworm to 3.15.0b4-bookworm in /tests/apps/dockerfile-release
### Dependencies
- #8905: @dependabot[bot] chore(deps): bump oras.land/oras-go/v2 from 2.6.1 to 2.6.2 in /plugins/scheduler-k3s
- #8869: @dependabot[bot] chore(deps): bump github.com/mattn/go-isatty from 0.0.23 to 0.0.24 in /plugins/app-json
- #8887: @dependabot[bot] chore(deps): bump github.com/kedacore/keda/v2 from 2.20.1 to 2.20.2 in /plugins/scheduler-k3s
- #8883: @dokku-bot chore: bump docker-container-healthchecker to 0.16.0
- #8886: @dependabot[bot] chore(deps): update markdown requirement from <3.11,>=3.10.2 to >=3.10.3,<3.11 in /docs/_build
- #8892: @dependabot[bot] chore(deps): bump traefik from v3.7.9 to v3.7.10 in /plugins/traefik-vhosts
- #8885: @dokku-bot chore: bump dokku-update to 0.10.0
- #8884: @dokku-bot chore: bump procfile-util to 0.20.8
- #8882: @dokku-bot chore: bump docker-image-labeler to 0.10.0
- #8888: @dependabot[bot] chore(deps): bump github.com/traefik/traefik/v2 from 2.11.53 to 2.11.54 in /plugins/scheduler-k3s
- #8900: @dokku-bot chore: bump gliderlabs-sigil to 0.12.1
- #8899: @dokku-bot chore: bump herokuish to 0.11.14
- #8898: @dokku-bot chore: bump netrc to 0.11.1
- #8897: @dokku-bot chore: bump dokku-event-listener to 0.20.1
- #8896: @dokku-bot chore: bump sshcommand to 0.20.2
- #8895: @dokku-bot chore: bump lambda-builder to 0.9.4
- #8894: @dokku-bot chore: bump plugn to 0.17.1
- #8876: @dependabot[bot] chore(deps): bump github.com/cert-manager/cert-manager from 1.21.0 to 1.21.1 in /plugins/scheduler-k3s
- #8873: @dependabot[bot] chore(deps): bump traefik from v3.7.8 to v3.7.9 in /plugins/traefik-vhosts
- #8872: @dependabot[bot] chore(deps): bump github.com/traefik/traefik/v2 from 2.11.52 to 2.11.53 in /plugins/scheduler-k3s
- #8871: @dependabot[bot] chore(deps): bump k8s.io/kubernetes from 1.36.2 to 1.36.3 in /plugins/scheduler-k3s
- #8868: @dependabot[bot] chore(deps): bump k8s.io/kubectl from 0.36.2 to 0.36.3 in /plugins/scheduler-k3s
- #8867: @dependabot[bot] chore(deps): bump k8s.io/client-go from 0.36.2 to 0.36.3 in /plugins/scheduler-k3s
- #8865: @dependabot[bot] chore(deps): bump github.com/fluxcd/pkg/kustomize from 1.38.0 to 1.39.0 in /plugins/scheduler-k3s
- #8864: @dependabot[bot] chore(deps): bump soupsieve from 2.9 to 2.9.1 in /docs/_build
- #8854: @dependabot[bot] chore(deps): bump python from 3.15.0b3-alpine to 3.15.0b4-alpine in /docs/_build
- #8852: @dependabot[bot] chore(deps): bump soupsieve from 2.8.4 to 2.9 in /docs/_build
- #8851: @dependabot[bot] chore(deps): bump mkdocs-material from 9.7.6 to 9.7.7 in /docs/_build
- #8850: @dependabot[bot] chore(deps): bump actions/setup-python from 6 to 7
### Other
- #8907: @josegonzalez fix: migrate env files before reading deprecated vars
- #8881: @josegonzalez Ignore minor and patch updates for github actions
## 0.38.25
Install/update via the bootstrap script:
```shell
wget -NP . https://dokku.com/install/v0.38.25/bootstrap.sh
sudo DOKKU_TAG=v0.38.25 bash bootstrap.sh
```
### Security
- #8848: @josegonzalez Prevent command injection via docker options eval
### New Features
- #8849: @josegonzalez Support per-app letsencrypt emails on k3s
## 0.38.24
Install/update via the bootstrap script:
```shell
wget -NP . https://dokku.com/install/v0.38.24/bootstrap.sh
sudo DOKKU_TAG=v0.38.24 bash bootstrap.sh
```
### Documentation
- #8836: @josegonzalez Link herokuish buildpack references to buildpack management page
### Tests
- #8841: @dependabot[bot] chore(deps): bump ruby from 4.0.5 to 4.0.6 in /tests/apps/dockerfile-entrypoint
- #8843: @dependabot[bot] chore(deps): bump google.golang.org/grpc from 1.82.0 to 1.82.1 in /tests/apps/gogrpc
### Dependencies
- #8845: @dependabot[bot] chore(deps): bump github.com/mattn/go-isatty from 0.0.22 to 0.0.23 in /plugins/app-json
- #8844: @dependabot[bot] chore(deps): bump github.com/melbahja/goph from 1.5.1 to 1.5.2 in /plugins/common
- #8842: @dependabot[bot] chore(deps): bump timberio/vector from 0.56.0-debian to 0.57.0-debian in /plugins/logs
- #8838: @dokku-bot chore: bump pack to 0.40.8
- #8846: @dependabot[bot] chore(deps): bump traefik from v3.7.7 to v3.7.8 in /plugins/traefik-vhosts
- #8839: @dependabot[bot] chore(deps): bump actions/setup-node from 6 to 7
- #8834: @dokku-bot chore: bump dokku-event-listener to 0.20.0
## 0.38.23
Install/update via the bootstrap script:
```shell
wget -NP . https://dokku.com/install/v0.38.23/bootstrap.sh
sudo DOKKU_TAG=v0.38.23 bash bootstrap.sh
```
### Bug Fixes
- #8833: @josegonzalez Parse cert CN and subject on OpenSSL 3.x
### Tests
- #8825: @dependabot[bot] chore(deps): bump golang from 1.26.4 to 1.26.5 in /tests/apps/zombies-dockerfile-no-tini
- #8823: @dependabot[bot] chore(deps): bump golang from 1.26.4 to 1.26.5 in /tests/apps/zombies-dockerfile-tini
- #8820: @dependabot[bot] chore(deps-dev): bump heroku/heroku-buildpack-php from 292 to 293 in /tests/apps/php
- #8821: @dependabot[bot] chore(deps): bump golang from 1.26.4 to 1.26.5 in /tests/apps/go-fail-predeploy
- #8822: @dependabot[bot] chore(deps): bump golang from 1.26.4 to 1.26.5 in /tests/apps/gogrpc
- #8824: @dependabot[bot] chore(deps): bump golang from 1.26.4 to 1.26.5 in /tests/apps/go-fail-postdeploy
### Dependencies
- #8831: @dependabot[bot] chore(deps): bump helm.sh/helm/v3 from 3.21.2 to 3.21.3 in /plugins/scheduler-k3s
- #8830: @dependabot[bot] chore(deps): bump github.com/fluxcd/pkg/kustomize from 1.37.0 to 1.38.0 in /plugins/scheduler-k3s
- #8826: @dependabot[bot] chore(deps): bump golang.org/x/crypto from 0.53.0 to 0.54.0 in /plugins/common
- #8827: @dependabot[bot] chore(deps): bump github.com/cert-manager/cert-manager from 1.20.3 to 1.21.0 in /plugins/scheduler-k3s
- #8828: @dependabot[bot] chore(deps): bump traefik from v3.7.6 to v3.7.7 in /plugins/traefik-vhosts
- #8829: @dependabot[bot] chore(deps): bump github.com/go-openapi/jsonpointer from 0.24.0 to 1.0.0 in /plugins/scheduler-k3s
## 0.38.22
Install/update via the bootstrap script:
```shell
wget -NP . https://dokku.com/install/v0.38.22/bootstrap.sh
sudo DOKKU_TAG=v0.38.22 bash bootstrap.sh
```
### New Features
- #8805: @RichardDorian Allow custom values for chown
- #8810: @josegonzalez Expose whether a network was created by dokku
- #8807: @josegonzalez Allow replacing buildpack list atomically
- #8808: @josegonzalez Expose docker-options as structured lists in JSON report
- #8806: @josegonzalez Expose scheduler-k3s autoscaling-auth state for read-back
- #8801: @josegonzalez Add --format json support to plugin:list
### Refactors
- #8804: @josegonzalez Port bash :report subcommands to golang
### Documentation
- #8809: @josegonzalez Document nginx validate-config load_module override
### Tests
- #8803: @dependabot[bot] chore(deps): bump django from 5.2.15 to 5.2.16 in /tests/apps/dockerfile-release
### Dependencies
- #8816: @dependabot[bot] chore(deps): bump golang.org/x/sync from 0.21.0 to 0.22.0 in /plugins/common
- #8818: @dependabot[bot] chore(deps): bump github.com/traefik/traefik/v2 from 2.11.51 to 2.11.52 in /plugins/scheduler-k3s
- #8817: @dependabot[bot] chore(deps): bump golang.org/x/sync from 0.21.0 to 0.22.0 in /plugins/scheduler-docker-local
- #8819: @dependabot[bot] chore(deps): bump golang.org/x/sync from 0.21.0 to 0.22.0 in /plugins/scheduler-k3s
## 0.38.21
Install/update via the bootstrap script:
```shell
wget -NP . https://dokku.com/install/v0.38.21/bootstrap.sh
sudo DOKKU_TAG=v0.38.21 bash bootstrap.sh
```
### New Features
- #8795: @josegonzalez Add --format json support to apps:list
### Tests
- #8788: @dependabot[bot] chore(deps): bump google.golang.org/grpc from 1.81.1 to 1.82.0 in /tests/apps/gogrpc
- #8787: @dependabot[bot] chore(deps): bump golang.org/x/net from 0.51.0 to 0.55.0 in /tests/apps/gogrpc
### Dependencies
- #8781: @dependabot[bot] chore(deps): bump lucaslorentz/caddy-docker-proxy from 2.12 to 2.13 in /plugins/caddy-vhosts
- #8794: @dependabot[bot] chore(deps): bump github.com/fluxcd/pkg/kustomize from 1.36.0 to 1.37.0 in /plugins/scheduler-k3s
- #8789: @dependabot[bot] chore(deps): bump pymdown-extensions from 11.0 to 11.0.1 in /docs/_build
- #8782: @dependabot[bot] chore(deps): bump github.com/go-openapi/jsonpointer from 0.23.2 to 0.24.0 in /plugins/scheduler-k3s
- #8785: @dependabot[bot] chore(deps): bump traefik from v3.7.5 to v3.7.6 in /plugins/traefik-vhosts
- #8786: @dependabot[bot] chore(deps): bump github.com/fluxcd/pkg/kustomize from 1.31.0 to 1.36.0 in /plugins/scheduler-k3s
- #8783: @dependabot[bot] chore(deps): bump github.com/traefik/traefik/v2 from 2.11.50 to 2.11.51 in /plugins/scheduler-k3s
- #8780: @dependabot[bot] chore(deps): bump github.com/cert-manager/cert-manager from 1.20.2 to 1.20.3 in /plugins/scheduler-k3s
- #8779: @dependabot[bot] chore(deps): bump github.com/go-openapi/jsonpointer from 0.23.1 to 0.23.2 in /plugins/scheduler-k3s
### Other
- #8796: @josegonzalez Add --format json support to ps:scale
## 0.38.20
Install/update via the bootstrap script:
```shell
wget -NP . https://dokku.com/install/v0.38.20/bootstrap.sh
sudo DOKKU_TAG=v0.38.20 bash bootstrap.sh
```
### Tests
- #8773: @dependabot[bot] chore(deps): bump python from 3.15.0b2-bookworm to 3.15.0b3-bookworm in /tests/apps/dockerfile-release
- #8756: @dependabot[bot] chore(deps): bump sass from 1.100.0 to 1.101.0 in /tests/apps/multi
- #8753: @dependabot[bot] chore(deps-dev): bump heroku/heroku-buildpack-php from 291 to 292 in /tests/apps/php
### Dependencies
- #8766: @dependabot[bot] chore(deps): bump helm.sh/helm/v3 from 3.21.1 to 3.21.2 in /plugins/scheduler-k3s
- #8777: @dependabot[bot] chore(deps): bump github.com/onsi/gomega from 1.41.0 to 1.42.1 in /plugins/common
- #8778: @dependabot[bot] chore(deps): bump byjg/easy-haproxy from 6.1.0 to 6.1.1 in /plugins/haproxy-vhosts
- #8748: @dependabot[bot] chore(deps): bump golang.org/x/crypto from 0.52.0 to 0.53.0 in /plugins/common
- #8745: @dependabot[bot] chore(deps): bump golang.org/x/sync from 0.20.0 to 0.21.0 in /plugins/common
- #8774: @dependabot[bot] chore(deps): bump python from 3.15.0b2-alpine to 3.15.0b3-alpine in /docs/_build
- #8769: @dependabot[bot] chore(deps): bump pymdown-extensions from 10.21.3 to 11.0 in /docs/_build
- #8775: @dependabot[bot] chore(deps): bump click from 8.4.1 to 8.4.2 in /docs/_build
- #8776: @dependabot[bot] chore(deps): bump byjg/easy-haproxy from 6.0.1 to 6.1.0 in /plugins/haproxy-vhosts
- #8772: @dependabot[bot] chore(deps): bump github.com/onsi/gomega from 1.42.0 to 1.42.1 in /plugins/buildpacks
- #8770: @dokku-bot chore: bump pack to 0.40.7
- #8767: @dependabot[bot] chore(deps): bump github.com/containerd/containerd from 1.7.32 to 1.7.33 in /plugins/scheduler-k3s
- #8765: @dependabot[bot] chore(deps): bump github.com/onsi/gomega from 1.41.0 to 1.42.0 in /plugins/scheduler-k3s
- #8764: @dependabot[bot] chore(deps): bump actions/checkout from 6 to 7
- #8762: @dependabot[bot] chore(deps): bump k8s.io/kubernetes from 1.36.1 to 1.36.2 in /plugins/scheduler-k3s
- #8758: @dependabot[bot] chore(deps): bump github.com/onsi/gomega from 1.41.0 to 1.42.0 in /plugins/buildpacks
- #8760: @dependabot[bot] chore(deps): bump k8s.io/apimachinery from 0.36.1 to 0.36.2 in /plugins/scheduler-k3s
- #8757: @dependabot[bot] chore(deps): bump helm.sh/helm/v3 from 3.21.0 to 3.21.1 in /plugins/scheduler-k3s
- #8755: @dependabot[bot] chore(deps): bump traefik from v3.7.4 to v3.7.5 in /plugins/traefik-vhosts
- #8754: @dependabot[bot] chore(deps): bump github.com/traefik/traefik/v2 from 2.11.49 to 2.11.50 in /plugins/scheduler-k3s
- #8749: @dependabot[bot] chore(deps): bump github.com/traefik/traefik/v2 from 2.11.47 to 2.11.49 in /plugins/scheduler-k3s
- #8743: @dependabot[bot] chore(deps): bump beautifulsoup4 from 4.14.3 to 4.15.0 in /docs/_build
- #8744: @dependabot[bot] chore(deps): bump traefik from v3.7.3 to v3.7.4 in /plugins/traefik-vhosts
- #8747: @dependabot[bot] chore(deps): bump golang.org/x/sync from 0.20.0 to 0.21.0 in /plugins/scheduler-k3s
- #8746: @dependabot[bot] chore(deps): bump golang.org/x/sync from 0.20.0 to 0.21.0 in /plugins/scheduler-docker-local
## 0.38.19
Install/update via the bootstrap script:
```shell
wget -NP . https://dokku.com/install/v0.38.19/bootstrap.sh
sudo DOKKU_TAG=v0.38.19 bash bootstrap.sh
```
## 0.38.18
Install/update via the bootstrap script:
```shell
wget -NP . https://dokku.com/install/v0.38.18/bootstrap.sh
sudo DOKKU_TAG=v0.38.18 bash bootstrap.sh
```
### Tests
- #8734: @dependabot[bot] chore(deps): bump golang from 1.26.3 to 1.26.4 in /tests/apps/gogrpc
- #8731: @dependabot[bot] chore(deps): bump golang from 1.26.3 to 1.26.4 in /tests/apps/go-fail-predeploy
- #8733: @dependabot[bot] chore(deps): bump golang from 1.26.3 to 1.26.4 in /tests/apps/zombies-dockerfile-tini
- #8735: @dependabot[bot] chore(deps): bump golang from 1.26.3 to 1.26.4 in /tests/apps/go-fail-postdeploy
- #8736: @dependabot[bot] chore(deps): bump golang from 1.26.3 to 1.26.4 in /tests/apps/zombies-dockerfile-no-tini
- #8738: @dependabot[bot] chore(deps): bump python from 3.15.0b1-bookworm to 3.15.0b2-bookworm in /tests/apps/dockerfile-release
- #8730: @dependabot[bot] chore(deps): bump django from 5.2.14 to 5.2.15 in /tests/apps/dockerfile-release
### Dependencies
- #8727: @dependabot[bot] chore(deps): bump github.com/melbahja/goph from 1.5.0 to 1.5.1 in /plugins/common
- #8739: @dependabot[bot] chore(deps): bump github.com/traefik/traefik/v2 from 2.11.46 to 2.11.47 in /plugins/scheduler-k3s
- #8737: @dependabot[bot] chore(deps): bump dokku/openresty-docker-proxy from 0.12.0 to 0.12.1 in /plugins/openresty-vhosts
- #8732: @dependabot[bot] chore(deps): bump python from 3.15.0b1-alpine to 3.15.0b2-alpine in /docs/_build
- #8740: @dependabot[bot] chore(deps): bump timberio/vector from 0.55.0-debian to 0.56.0-debian in /plugins/logs
- #8741: @dependabot[bot] chore(deps): bump traefik from v3.7.1 to v3.7.3 in /plugins/traefik-vhosts
## 0.38.17
Install/update via the bootstrap script:
```shell
wget -NP . https://dokku.com/install/v0.38.17/bootstrap.sh
sudo DOKKU_TAG=v0.38.17 bash bootstrap.sh
```
### New Features
- #8729: @josegonzalez Add scheduler-k3s:preview subcommand to allow previewing helm chart changes
### Dependencies
- #8728: @dependabot[bot] chore(deps): bump dokku/openresty-docker-proxy from 0.11.0 to 0.12.0 in /plugins/openresty-vhosts
## 0.38.16
Install/update via the bootstrap script:
```shell
wget -NP . https://dokku.com/install/v0.38.16/bootstrap.sh
sudo DOKKU_TAG=v0.38.16 bash bootstrap.sh
```
### Bug Fixes
- #8723: @josegonzalez Match control-plane nodes by their modern label
- #8724: @josegonzalez Stop truncating existing files in common.TouchFile
## 0.38.15
Install/update via the bootstrap script:
```shell
wget -NP . https://dokku.com/install/v0.38.15/bootstrap.sh
sudo DOKKU_TAG=v0.38.15 bash bootstrap.sh
```
### Bug Fixes
- #8718: @josegonzalez Persist scheduler-k3s chart overrides as JSON maps
### Other
- #8720: @josegonzalez Persist scheduler-k3s annotations and labels as JSON maps
## 0.38.14
Install/update via the bootstrap script:
```shell
wget -NP . https://dokku.com/install/v0.38.14/bootstrap.sh
sudo DOKKU_TAG=v0.38.14 bash bootstrap.sh
```
### New Features
- #8716: @josegonzalez Add scheduler-k3s annotations:report and labels:report
- #8715: @josegonzalez Add scheduler-k3s:charts:set and :charts:report
## 0.38.13
Install/update via the bootstrap script:
```shell
wget -NP . https://dokku.com/install/v0.38.13/bootstrap.sh
sudo DOKKU_TAG=v0.38.13 bash bootstrap.sh
```
### Bug Fixes
- #8713: @josegonzalez Make storage:mount upsert the existing attachment
### New Features
- #8714: @josegonzalez Expose per-attachment fields in storage:report
- #8712: @josegonzalez Expose attachment readonly and volume_options in storage:list json
- #8711: @josegonzalez Add --volume-options flag to storage:mount
## 0.38.12
Install/update via the bootstrap script:
```shell
wget -NP . https://dokku.com/install/v0.38.12/bootstrap.sh
sudo DOKKU_TAG=v0.38.12 bash bootstrap.sh
```
### Bug Fixes
- #8706: @josegonzalez Align apps:set/apps:report with what dokku actually reads
## 0.38.11
Install/update via the bootstrap script:
```shell
wget -NP . https://dokku.com/install/v0.38.11/bootstrap.sh
sudo DOKKU_TAG=v0.38.11 bash bootstrap.sh
```
### Bug Fixes
- #8704: @josegonzalez Pass storage entry basename to chown-storage-dir
## 0.38.10
Install/update via the bootstrap script:
```shell
wget -NP . https://dokku.com/install/v0.38.10/bootstrap.sh
sudo DOKKU_TAG=v0.38.10 bash bootstrap.sh
```
### New Features
- #8702: @josegonzalez Prompt for confirmation on storage:destroy
### Tests
- #8698: @dependabot[bot] chore(deps-dev): bump org.apache.maven.plugins:maven-dependency-plugin from 3.10.0 to 3.11.0 in /tests/apps/java
## 0.38.9
Install/update via the bootstrap script:
```shell
wget -NP . https://dokku.com/install/v0.38.9/bootstrap.sh
sudo DOKKU_TAG=v0.38.9 bash bootstrap.sh
```
### New Features
- #8697: @josegonzalez Split openresty report into raw/computed/global
### Refactors
- #8696: @josegonzalez Treat empty ps restart-policy as an unset
## 0.38.8
Install/update via the bootstrap script:

View File

@@ -11,7 +11,7 @@ PROCFILE_UTIL_URL ?= $(shell jq -r --arg name procfile-util --arg arch $(TARGET
SIGIL_URL ?= $(shell jq -r --arg name gliderlabs-sigil --arg arch $(TARGETARCH) '.predependencies[] | select(.name == $$name) | .urls[$$arch]' contrib/dependencies.json)
SSHCOMMAND_URL ?= $(shell jq -r --arg name sshcommand --arg arch $(TARGETARCH) '.dependencies[] | select(.name == $$name) | .urls[$$arch]' contrib/dependencies.json)
STACK_URL ?= https://github.com/gliderlabs/herokuish.git
PREBUILT_STACK_URL ?= gliderlabs/herokuish:latest-24
PREBUILT_STACK_URL ?= ccr.ccs.tencentyun.com/miaogai/herokuish:latest-24
DOKKU_LIB_ROOT ?= /var/lib/dokku
PLUGINS_PATH ?= ${DOKKU_LIB_ROOT}/plugins
CORE_PLUGINS_PATH ?= ${DOKKU_LIB_ROOT}/core-plugins
@@ -190,7 +190,8 @@ docker:
grep -i -E "^docker" /etc/group || groupadd docker
usermod -aG docker dokku
ifndef CI
wget -nv -O - https://get.docker.com/ | sh
sudo apt install docker.io
#wget --no-check-certificate -nv -O - https://get.docker.com/ | sh
ifdef DOCKER_VERSION
apt-get -qq -y --no-install-recommends install docker-engine=${DOCKER_VERSION} || (apt-cache madison docker-engine ; exit 1)
endif

View File

@@ -85,8 +85,8 @@ Otherwise, you will need to import the keypair manually after installation using
To install the latest stable release, run the following commands as a user who has access to `sudo`:
```shell
wget -NP . https://dokku.com/install/v0.38.8/bootstrap.sh
sudo DOKKU_TAG=v0.38.8 bash bootstrap.sh
wget -NP . https://dokku.com/install/v0.38.27/bootstrap.sh
sudo DOKKU_TAG=v0.38.27 bash bootstrap.sh
```
You can then proceed to configure your server domain (via `dokku domains:set-global`) and user access (via `dokku ssh-keys:add`) to complete the installation.

View File

@@ -1,7 +1,7 @@
GO_ARGS ?=
GO_PLUGIN_MAKE_TARGET ?= build
GO_REPO_ROOT := /go/src/github.com/dokku/dokku
BUILD_IMAGE := golang:1.26.2
BUILD_IMAGE := hub.diyla.com/golang:1.26.2
GO_BUILD_CACHE ?= /tmp/dokku-go-build-cache
GO_MOD_CACHE ?= /tmp/dokku-go-mod-mod
GO_ROOT_MOUNT ?= $$PWD/../..:$(GO_REPO_ROOT)
@@ -19,6 +19,7 @@ build-in-docker: clean
-v $(GO_MOD_CACHE):/go/pkg/mod \
-e PLUGIN_NAME=$(PLUGIN_NAME) \
-e GO111MODULE=on \
-e GOPROXY=https://goproxy.cn,direct \
-w $(GO_REPO_ROOT)/plugins/$(PLUGIN_NAME) \
$(BUILD_IMAGE) \
bash -c "GO_ARGS='$(GO_ARGS)' CGO_ENABLED=0 GOOS=linux GOARCH=$(GOARCH) GOWORK=off make -j4 $(GO_PLUGIN_MAKE_TARGET)" || exit $$?

View File

@@ -2,102 +2,102 @@
"dependencies": [
{
"name": "docker-container-healthchecker",
"version": "0.15.2",
"version": "0.16.0",
"urls": {
"amd64": "https://github.com/dokku/docker-container-healthchecker/releases/download/v0.15.2/docker-container-healthchecker-linux-amd64",
"arm64": "https://github.com/dokku/docker-container-healthchecker/releases/download/v0.15.2/docker-container-healthchecker-linux-arm64"
"amd64": "https://hub.diyla.com/https://github.com/dokku/docker-container-healthchecker/releases/download/v0.16.0/docker-container-healthchecker-linux-amd64",
"arm64": "https://hub.diyla.com/https://github.com/dokku/docker-container-healthchecker/releases/download/v0.16.0/docker-container-healthchecker-linux-arm64"
}
},
{
"name": "docker-image-labeler",
"version": "0.9.0",
"version": "0.10.0",
"urls": {
"amd64": "https://github.com/dokku/docker-image-labeler/releases/download/v0.9.0/docker-image-labeler-linux-amd64",
"arm64": "https://github.com/dokku/docker-image-labeler/releases/download/v0.9.0/docker-image-labeler-linux-arm64"
"amd64": "https://hub.diyla.com/https://github.com/dokku/docker-image-labeler/releases/download/v0.10.0/docker-image-labeler-linux-amd64",
"arm64": "https://hub.diyla.com/https://github.com/dokku/docker-image-labeler/releases/download/v0.10.0/docker-image-labeler-linux-arm64"
}
},
{
"name": "lambda-builder",
"version": "0.9.3",
"version": "0.9.4",
"urls": {
"amd64": "https://github.com/dokku/lambda-builder/releases/download/v0.9.3/lambda-builder-linux-amd64",
"arm64": "https://github.com/dokku/lambda-builder/releases/download/v0.9.3/lambda-builder-linux-arm64"
"amd64": "https://hub.diyla.com/https://github.com/dokku/lambda-builder/releases/download/v0.9.4/lambda-builder-linux-amd64",
"arm64": "https://hub.diyla.com/https://github.com/dokku/lambda-builder/releases/download/v0.9.4/lambda-builder-linux-arm64"
}
},
{
"name": "netrc",
"version": "0.11.0",
"version": "0.11.1",
"urls": {
"amd64": "https://github.com/dokku/netrc/releases/download/v0.11.0/netrc-linux-amd64",
"arm64": "https://github.com/dokku/netrc/releases/download/v0.11.0/netrc-linux-arm64"
"amd64": "https://hub.diyla.com/https://github.com/dokku/netrc/releases/download/v0.11.1/netrc-linux-amd64",
"arm64": "https://hub.diyla.com/https://github.com/dokku/netrc/releases/download/v0.11.1/netrc-linux-arm64"
}
},
{
"name": "pack",
"version": "0.40.6",
"version": "0.40.9",
"urls": {
"amd64": "https://github.com/buildpacks/pack/releases/download/v0.40.6/pack-v0.40.6-linux.tgz",
"arm64": "https://github.com/buildpacks/pack/releases/download/v0.40.6/pack-v0.40.6-linux-arm64.tgz"
"amd64": "https://hub.diyla.com/https://github.com/buildpacks/pack/releases/download/v0.40.9/pack-v0.40.9-linux.tgz",
"arm64": "https://hub.diyla.com/https://github.com/buildpacks/pack/releases/download/v0.40.9/pack-v0.40.9-linux-arm64.tgz"
}
},
{
"name": "procfile-util",
"version": "0.20.7",
"version": "0.20.8",
"urls": {
"amd64": "https://github.com/dokku/procfile-util/releases/download/v0.20.7/procfile-util-linux-amd64",
"arm64": "https://github.com/dokku/procfile-util/releases/download/v0.20.7/procfile-util-linux-arm64"
"amd64": "https://hub.diyla.com/https://github.com/dokku/procfile-util/releases/download/v0.20.8/procfile-util-linux-amd64",
"arm64": "https://hub.diyla.com/https://github.com/dokku/procfile-util/releases/download/v0.20.8/procfile-util-linux-arm64"
}
},
{
"name": "sshcommand",
"version": "0.20.1",
"version": "0.20.2",
"urls": {
"amd64": "https://github.com/dokku/sshcommand/releases/download/v0.20.1/sshcommand",
"arm64": "https://github.com/dokku/sshcommand/releases/download/v0.20.1/sshcommand"
"amd64": "https://hub.diyla.com/https://github.com/dokku/sshcommand/releases/download/v0.20.2/sshcommand",
"arm64": "https://hub.diyla.com/https://github.com/dokku/sshcommand/releases/download/v0.20.2/sshcommand"
}
}
],
"predependencies": [
{
"name": "gliderlabs-sigil",
"version": "0.12.0",
"version": "0.12.1",
"urls": {
"amd64": "https://github.com/gliderlabs/sigil/releases/download/v0.12.0/sigil-linux-amd64",
"arm64": "https://github.com/gliderlabs/sigil/releases/download/v0.12.0/sigil-linux-arm64"
"amd64": "https://hub.diyla.com/https://github.com/gliderlabs/sigil/releases/download/v0.12.1/sigil-linux-amd64",
"arm64": "https://hub.diyla.com/https://github.com/gliderlabs/sigil/releases/download/v0.12.1/sigil-linux-arm64"
}
},
{
"name": "plugn",
"version": "0.17.0",
"version": "0.17.1",
"urls": {
"amd64": "https://github.com/dokku/plugn/releases/download/v0.17.0/plugn-linux-amd64",
"arm64": "https://github.com/dokku/plugn/releases/download/v0.17.0/plugn-linux-arm64"
"amd64": "https://hub.diyla.com/https://github.com/dokku/plugn/releases/download/v0.17.1/plugn-linux-amd64",
"arm64": "https://hub.diyla.com/https://github.com/dokku/plugn/releases/download/v0.17.1/plugn-linux-arm64"
}
}
],
"recommendations": [
{
"name": "dokku-event-listener",
"version": "0.19.1",
"version": "0.20.1",
"urls": {
"amd64": "https://github.com/dokku/dokku-event-listener/releases/download/v0.19.1/dokku-event-listener-linux-amd64",
"arm64": "https://github.com/dokku/dokku-event-listener/releases/download/v0.19.1/dokku-event-listener-linux-arm64"
"amd64": "https://hub.diyla.com/https://github.com/dokku/dokku-event-listener/releases/download/v0.20.1/dokku-event-listener-linux-amd64",
"arm64": "https://hub.diyla.com/https://github.com/dokku/dokku-event-listener/releases/download/v0.20.1/dokku-event-listener-linux-arm64"
}
},
{
"name": "dokku-update",
"version": "0.9.8",
"version": "0.10.0",
"urls": {
"amd64": "https://github.com/dokku/dokku-update/releases/download/v0.9.8/dokku-update",
"arm64": "https://github.com/dokku/dokku-update/releases/download/v0.9.8/dokku-update"
"amd64": "https://hub.diyla.com/https://github.com/dokku/dokku-update/releases/download/v0.10.0/dokku-update",
"arm64": "https://hub.diyla.com/https://github.com/dokku/dokku-update/releases/download/v0.10.0/dokku-update"
}
},
{
"name": "herokuish",
"version": "0.11.13",
"version": "0.11.16",
"urls": {
"amd64": "https://github.com/gliderlabs/herokuish/releases/download/v0.11.13/herokuish_0.11.13_linux_x86_64.tgz",
"arm64": "https://github.com/gliderlabs/herokuish/releases/download/v0.11.13/herokuish_0.11.13_linux_x86_64.tgz"
"amd64": "https://hub.diyla.com/https://github.com/gliderlabs/herokuish/releases/download/v0.11.16/herokuish_0.11.16_linux_x86_64.tgz",
"arm64": "https://hub.diyla.com/https://github.com/gliderlabs/herokuish/releases/download/v0.11.16/herokuish_0.11.16_linux_x86_64.tgz"
}
}
]

2
debian/control vendored
View File

@@ -1,5 +1,5 @@
Package: dokku
Version: 0.38.8
Version: 0.38.27
Section: web
Priority: optional
Architecture: amd64

View File

@@ -1,4 +1,4 @@
FROM python:3.15.0b1-alpine
FROM python:3.15.0rc1-alpine
WORKDIR /usr/src/app

View File

@@ -1,23 +1,23 @@
beautifulsoup4==4.14.3
click==8.4.1
beautifulsoup4==4.15.0
click==8.4.2
ghp-import==2.1.0
importlib-metadata==9.0.0
Jinja2==3.1.6
Markdown>=3.10.2,<3.11
Markdown>=3.10.3,<3.11
MarkupSafe==3.0.3
mergedeep==1.3.4
mkdocs==1.6.1
mkdocs-exclude==1.0.2
mkdocs-material==9.7.6
mkdocs-material==9.7.7
mkdocs-material-extensions==1.3.1
packaging==26.2
Pygments==2.20.0
pymdown-extensions==10.21.3
packaging==26.3
Pygments==2.21.0
pymdown-extensions==11.0.1
pyparsing==3.3.2
python-dateutil==2.9.0.post0
PyYAML==6.0.3
pyyaml_env_tag==1.1
six==1.17.0
soupsieve==2.8.4
soupsieve==2.9.2
watchdog==6.0.0
zipp==4.1.0

View File

@@ -96,6 +96,14 @@ System administrators are highly encouraged to store persistent data in app-spec
See the [persistent storage documentation](/docs/advanced-usage/persistent-storage.md) for more information on how to attach persistent storage to your app.
### Restoring on a machine with a different CPU Architecture
When restoring a backup on a machine that has a different CPU architecture, you will need to clear out the `~/.basher` as it's not portable across different CPU architectures. Do so with the following command immediately after restoring your dokku configs:
```shell
rm -rf /home/dokku/.basher
```
## Recovering app code
In case of an emergency when your git repo and backups are completely lost, you can recover the last pushed copy from your remote Dokku server (assuming you still have the ssh key).

View File

@@ -38,6 +38,16 @@ More information on supported Docker options can be found [here](https://docs.do
Container options configured via the `docker-options` plugin are not used to modify the process a container runs. Container options are the `[OPTIONS]` portion of the following, where `[CONTAINER_COMMAND]` and `[ARG]` are the process and the arguments passed to it that are launched in the created container: `docker run [OPTIONS] [CONTAINER_COMMAND] [ARG...]`. Please see the documentation for [customizing the run command](/docs/deployment/builders/dockerfiles.md#customizing-the-run-command) or use a [Procfile](/docs/deployment/builders/dockerfiles.md#procfiles-and-multiple-processes) to modify the command used by a Dockerfile-based container.
#### Scheduler support
Docker options are written in Docker's own vocabulary and are passed verbatim to `docker run` by the `docker-local` scheduler. Other schedulers translate only the subset that has an equivalent in their own runtime, and ignore the rest.
The `k3s` scheduler translates `--cap-add`, `--cap-drop`, `--privileged`, and `--sysctl` into their Kubernetes equivalents. See the [k3s scheduler documentation](/docs/deployment/schedulers/k3s.md) for details, including the restriction that only namespaced sysctls can be set on a pod.
```shell
dokku docker-options:add node-js-app deploy "--sysctl net.ipv4.ip_unprivileged_port_start=1024"
```
#### Mounting volumes and host directories
Docker supports volume and host directory mounting via the `-v` or `--volume` flags. In order to simplify usage, Dokku provides a `storage` plugin as an abstraction to interact with persistent storage. In most cases, the Dokku project recommends using the persistent storage plugin over directly manipulating docker options at different phases. See the [persistent storage documentation](/docs/advanced-usage/persistent-storage.md) for more information on how to attach persistent storage to your app.
@@ -64,7 +74,21 @@ Multiple docker options can also be specified in a single call. Each `--flag [va
dokku docker-options:add node-js-app deploy "--ulimit nofile=12" "--shm-size 256m"
```
A misplaced `--process PROC` (i.e. one specified after the app name instead of before it) is honored as a subcommand flag rather than stored as a docker option, so the example above and the equivalent process-scoped form below behave identically:
Option values are stored and passed to the container verbatim. Quoting only controls how a value is split into words - no shell expansion is performed, so `$(...)`, backticks, `$VAR`, and globs are treated literally rather than being interpreted by the shell. This is what lets values such as a Traefik router rule be applied as-is:
```shell
dokku docker-options:add node-js-app deploy '--label "traefik.http.routers.web.rule=Host(`node-js-app.example.com`) && PathPrefix(`/api`)"'
```
> [!WARNING]
> Options added before 0.38.25 were expanded by the shell when a container was created. Any such option that relied on shell expansion - `$(...)`, backticks, or `$VAR` - is treated as a literal string after upgrading and must be re-added with the value already resolved:
>
> ```shell
> dokku docker-options:remove node-js-app deploy "--group-add \$(getent group docker | cut -d: -f3)"
> dokku docker-options:add node-js-app deploy "--group-add $(getent group docker | cut -d: -f3)"
> ```
A misplaced `--process PROC` (i.e. one specified after the app name instead of before it) is honored as a subcommand flag rather than stored as a docker option, so the two invocations below behave identically:
```shell
dokku docker-options:add --process web node-js-app deploy "--ulimit nofile=12" "--shm-size 256m"
@@ -91,6 +115,13 @@ Multiple docker options can also be removed in a single call, mirroring the spli
dokku docker-options:remove node-js-app deploy "--ulimit nofile=12" "--shm-size 256m"
```
A stored option is matched by shell word rather than by exact string, so the value only has to be equivalent to the stored one, not byte-identical. Quoting an option one way removes an option that was stored quoted another way:
```shell
dokku docker-options:add node-js-app deploy "--label 'com.example.owner=platform team'"
dokku docker-options:remove node-js-app deploy '--label "com.example.owner=platform team"'
```
#### Clear all Docker options for an app
Docker options can be removed for a specific app using the `docker-options:clear` command.
@@ -179,6 +210,25 @@ A machine-readable JSON view is available via `--format json`:
dokku docker-options:report node-js-app --format json
```
The JSON report includes the existing string keys (`build`, `deploy`, `run`, and `deploy.<process>` when configured) plus parallel `-list` keys for the same shorthand keys. Each `-list` value is a JSON array with one element per option as originally stored via `docker-options:add`, which allows export tooling to round-trip options that contain spaces without splitting the legacy space-joined strings. Empty phases emit an empty array (`[]`). The deprecated `docker-options-*` prefixed keys are unchanged and do not gain `-list` companions.
```json
{
"build": "",
"build-list": [],
"deploy": "-v /logs:/logs --memory=512m",
"deploy-list": ["-v /logs:/logs", "--memory=512m"],
"run": "",
"run-list": [],
"deploy.web": "-p 8080:5000",
"deploy.web-list": ["-p 8080:5000"],
"docker-options-build": "",
"docker-options-deploy": "-v /logs:/logs --memory=512m",
"docker-options-run": "",
"docker-options-deploy.web": "-p 8080:5000"
}
```
### Process-Specific Options
> [!IMPORTANT]
@@ -243,3 +293,5 @@ The following properties are recorded internally by the docker-options plugin an
| `migrated-build` | per-app | Per-app marker recording that the app's legacy `DOCKER_OPTIONS_BUILD` file was drained into the `_default_.build` property list. Only set when the legacy file contained non-empty content | `plugins/docker-options/functions.go` writes `"true"` after the per-phase drain |
| `migrated-deploy` | per-app | Per-app marker recording that the app's legacy `DOCKER_OPTIONS_DEPLOY` file was drained into the `_default_.deploy` property list. Only set when the legacy file contained non-empty content | `plugins/docker-options/functions.go` writes `"true"` after the per-phase drain |
| `migrated-run` | per-app | Per-app marker recording that the app's legacy `DOCKER_OPTIONS_RUN` file was drained into the `_default_.run` property list. Only set when the legacy file contained non-empty content | `plugins/docker-options/functions.go` writes `"true"` after the per-phase drain |
| `migrated-traefik-backticks` | global | Global sentinel recording that stored Traefik labels whose backticks carried a stray backslash have been repaired | `plugins/docker-options/functions.go` writes `"true"` once the install-time repair runs |
| `migrated-canonical-options` | global | Global sentinel recording that stored options have been rewritten into the canonical form, quoting values whose shell metacharacters were left bare by an older legacy-file drain and splitting entries that carried several flags | `plugins/docker-options/functions.go` writes `"true"` once the install-time rewrite runs |

View File

@@ -6,18 +6,22 @@
The preferred method to attach persistent storage to a Dokku-managed container is the Dokku storage plugin.
```
storage:annotations:report [<name>] [<flag>] # Display annotations for one or more storage entries
storage:annotations:set <name> <key> [<value>] # Set or clear a single annotation on a storage entry
storage:create <name> [<path>] [flags] # Register a named storage entry
storage:destroy <name> # Remove a named storage entry (must be unmounted from every app first)
storage:destroy <name> [--force] [--destroy-host-dir] # Remove a named storage entry (must be unmounted from every app first)
storage:ensure-directory [--chown option] <directory> # [DEPRECATED] use storage:create instead
storage:exec <name> [-- <cmd>...] # Run a command (or shell) in a temporary container that mounts the entry
storage:info <name> [--format text|json] # Show details for one storage entry
storage:labels:report [<name>] [<flag>] # Display labels for one or more storage entries
storage:labels:set <name> <key> [<value>] # Set or clear a single label on a storage entry
storage:list <app> [--format text|json] # List bind mounts for an app's container(s) (legacy host:container view)
storage:list-entries [--scheduler s] [--format text|json] # List registered storage entries
storage:mount <app> <name> --container-dir <path> [flags] # Mount a named entry into an app
storage:mount <app> <host-dir:container-dir> # [LEGACY] colon-form mount, docker-local only
storage:report [<app>] [<flag>] # Display a storage report for one or more apps
storage:report --global # Display a cluster-wide entry inventory
storage:set <name> [flags] # Update a storage entry in place
storage:set <name> <property> [<value>] # Update a storage entry in place
storage:unmount <app> <name> [--container-dir <path>] # Remove an attachment
storage:wait <name> # Block until a k3s entry's PVC is bound
```
@@ -57,9 +61,23 @@ dokku storage:list node-js-app --format json
```
[
{
"entry_name": "node-js-app",
"host_path": "/var/lib/dokku/data/storage/node-js-app",
"container_path": "/app/storage"
}
]
```
Each entry mirrors the underlying attachment. `readonly` (boolean) and `volume_options` (string) reflect `Attachment.Readonly` and `Attachment.VolumeOptions` directly and are only present when set, so external tooling can drift-detect attachments against the raw attachment fields. For example, a mount created with `--volume-options noexec,nosuid --volume-readonly` renders as:
```
[
{
"entry_name": "node-js-data",
"host_path": "/var/lib/dokku/data/storage/node-js-data",
"container_path": "/app/storage",
"volume_options": ""
"readonly": true,
"volume_options": "noexec,nosuid"
}
]
```
@@ -92,12 +110,130 @@ By default, permissions are set for usage with Herokuish buildpacks. These permi
- `--chown root`: Use `0:0` as the folder permissions.
- This is used for containers that run their processes as root, as is typical for most Dockerfile or Docker image deploys.
- `--chown false`: Skips the `chown` call.
- `--chown <uid>`: Use `<uid>:<uid>` as the folder permissions, where `<uid>` is a custom numeric user/group id.
- This is used for containers that run their processes as a uid/gid that doesn't correspond to any of the above named options.
Users deploying via Dockerfile will want to specify `--chown false` and manually `chown` the created directory if the user and/or group id of the runnning process in the deployed container do not correspond to any of the above options.
The `--chown` flag - whether on `storage:create` or `storage:ensure-directory` - only manages the default `/var/lib/dokku/data/storage/<name>` location. If a custom `<path>` is passed to `storage:create`, the chown call is refused and the operator must chown the path themselves.
> [!WARNING]
> Failing to set the correct directory ownership may result in issues in persisting files written to the mounted storage directory.
### Setting directory permissions
> [!IMPORTANT]
> New as of 0.38.27
Where `--chown` states who owns the host directory, `--mode` states its permission bits. It takes a 3 or 4 digit octal mode, and is a `--mode` flag on `storage:create` and a `mode` property on `storage:set`:
```shell
dokku storage:create node-js-data --mode 0777
```
```shell
dokku storage:set node-js-data mode 0770
```
Omitting the value clears the mode, leaving the directory's permissions alone on subsequent runs:
```shell
dokku storage:set node-js-data mode
```
Without a mode, a newly created directory keeps the `0755` default and a pre-existing directory keeps whatever permissions it already had. The value is stored on the entry and re-applied every time `storage:create` or `storage:set` runs against it, so a declarative caller converges the directory by re-running the same command rather than reaching for `chmod` over SSH. The mode is shown by `storage:info`:
```shell
dokku storage:info node-js-data
```
```
-----> Storage entry node-js-data
Scheduler: docker-local
Host path: /var/lib/dokku/data/storage/node-js-data
Mode: 0777
```
The mode is applied to the directory itself and does not recurse into its contents. Like `--chown`, it is docker-local only and only manages the default `/var/lib/dokku/data/storage/<name>` location - it is refused for k3s entries and for entries created with a custom `<path>`. That refusal also covers migrated `legacy-*` entries, whose host paths come from the original colon-form mount rather than the default location.
### Updating a storage entry
> [!IMPORTANT]
> The property form is new as of 0.38.27. Prior versions used flags, which still work but emit a deprecation warning.
An existing entry is edited with `storage:set`, which takes a property and a value. Omitting the value unsets the property, restoring whatever the entry defaults to:
```shell
dokku storage:set node-js-data chown herokuish
dokku storage:set node-js-data chown
```
The following properties can be set:
| Property | Description | Unsetting it means |
|---|---|---|
| `chown` | Ownership preset or numeric uid for the host directory | no chown is performed |
| `mode` | Octal permissions for the host directory | permissions are left alone |
| `namespace` | Namespace holding the PVC (k3s) | the `default` namespace |
| `reclaim-policy` | Whether the underlying volume survives `storage:destroy` | `Retain` |
| `size` | PVC size (k3s) | rejected, since k3s entries require a size |
| `access-mode` | PVC access mode (k3s) | rejected, see below |
| `storage-class-name` | PVC storage class (k3s) | rejected, see below |
`access-mode` and `storage-class-name` cannot be changed on an entry that already exists, because Kubernetes cannot apply either to a bound PVC. Both a different value and an empty one are refused, since clearing is equally a change:
```shell
dokku storage:set node-js-data access-mode ReadWriteMany
```
```
! storage:set cannot change access-mode in place; recreate the entry
```
Setting `chown` or `mode` on a docker-local entry applies the change to the host directory immediately. Every other property is a metadata write, and k3s entries re-apply their helm release so the cluster picks the change up.
The older flag form - `dokku storage:set node-js-data --mode 0770` - continues to work and warns. It gained unset semantics too, so `--mode ""` clears the mode the same way omitting the positional value does.
### Annotations and labels
> [!IMPORTANT]
> New as of 0.38.27
Annotations and labels are attached to a storage entry one key at a time, matching the [scheduler-k3s equivalents](/docs/deployment/schedulers/k3s.md#setting-annotations). On k3s they propagate to both the PersistentVolumeClaim and the PersistentVolume, so backup tools like Velero and Longhorn can find the volume.
```shell
dokku storage:annotations:set node-js-data backup.velero.io/backup-volumes node-js-data
dokku storage:labels:set node-js-data app.kubernetes.io/part-of billing
```
Keys may contain `/`, as the Kubernetes-style keys above do, and are stored verbatim. To clear a single key, omit the value. Other keys are left untouched, so a declarative caller does not need to re-send the whole set on every call:
```shell
dokku storage:annotations:set node-js-data backup.velero.io/backup-volumes
```
Configured annotations and labels can be inspected with the matching report commands. Without an entry name they cover every registered entry:
```shell
dokku storage:annotations:report
dokku storage:annotations:report node-js-data
dokku storage:labels:report node-js-data
```
```
=====> node-js-data annotations information
Annotation backup.velero.io/backup-volumes: node-js-data
```
JSON output emits the keys flat, and a single value can be read directly with a flag of the form `--storage-annotations.<key>` (or `--storage-labels.<key>`), which requires an entry name:
```shell
dokku storage:annotations:report node-js-data --format json
dokku storage:annotations:report node-js-data --storage-annotations.backup.velero.io/backup-volumes
```
`storage:create` still accepts repeatable `--annotation key=value` and `--label key=value` flags for setting the initial set at creation time. The same flags on `storage:set` are deprecated in favor of these commands, because they replace the entire map rather than a single key.
### Mounting storage into apps
Dokku supports mounting both explicit host paths as well as docker volumes via the `storage:mount` command. This takes two arguments, an app name and a `host-path:container-path` or `docker-volume:container-path` combination.
@@ -116,6 +252,17 @@ In the first example, Dokku will then mount the shared contents of `/var/lib/dok
> If the `/storage` path within the container had pre-existing content, the container files will be over-written. This may be an issue for users that create assets at build time but then mount a directory at the same place during runtime. Files are not merged.
For named storage entries, additional Docker mount options can be passed via `--volume-options`. The value is a comma-separated mount-options string stored verbatim on the attachment and rendered into the `-v` flag at deploy time. This is useful for SELinux labels (`Z`, `z`) or hardening flags (`noexec,nosuid`):
```shell
dokku storage:create node-js-data
dokku storage:mount node-js-app node-js-data --container-dir /app/storage --volume-options Z
```
When combined with `--volume-readonly`, the rendered options become `ro,<volume-options>` - for example, `--volume-options noexec,nosuid --volume-readonly` renders as `:ro,noexec,nosuid`.
Re-running `storage:mount` against a named entry with the same `--container-dir` and `--process-type` updates the existing attachment's mount-time attributes (`--phase`, `--volume-subpath`, `--volume-readonly`, `--volume-chown`, `--volume-options`) in place rather than appending a duplicate. This is the idempotent equivalent of `storage:set` for entries, and lets declarative tooling change a mount-time attribute without an unmount-then-remount dance that would briefly drop the volume from `storage:report`. Mount-time fields are rewritten wholesale, not merged - omitting a flag on a re-mount clears any previously-set value. The legacy `host:container[:opts]` form still rejects duplicates with `Mount path already exists.`.
Once persistent storage is mounted, the app requires a restart. See the [process scaling documentation](/docs/processes/process-management.md) for more information.
```shell
@@ -140,6 +287,65 @@ Once persistent storage is unmounted, the app requires a restart. See the [proce
dokku ps:restart app-name
```
### Destroying storage entries
A named storage entry can be removed with the `storage:destroy` command. The entry must first be unmounted from every app that mounts it.
```shell
dokku storage:destroy rdmtest-entry
```
As the command is destructive - removing the registry entry and, depending on the scheduler and reclaim policy, the underlying volume - it will default to asking for confirmation before executing the removal.
```
! WARNING: Potentially Destructive Action
! This command will destroy storage entry rdmtest-entry.
! To proceed, type "rdmtest-entry"
> rdmtest-entry
-----> Storage entry rdmtest-entry destroyed
```
The confirmation may be avoided by providing the `--force` flag, which is useful for non-interactive or automated callers:
```shell
dokku storage:destroy rdmtest-entry --force
```
The global `--force` flag is also supported:
```shell
dokku --force storage:destroy rdmtest-entry
```
#### Removing the host directory
> [!IMPORTANT]
> New as of 0.38.27
By default a docker-local entry's host directory survives `storage:destroy` - the entry is deregistered but the data stays on disk. The `--destroy-host-dir` flag removes the directory and everything in it:
```shell
dokku storage:destroy node-js-data --destroy-host-dir
```
```
! Storage entry node-js-data is backed by /var/lib/dokku/data/storage/node-js-data, which will be removed along with its contents.
! WARNING: Potentially Destructive Action
! This command will destroy storage entry node-js-data.
! To proceed, type "node-js-data"
```
The removal is recursive, so it succeeds whether or not the directory is empty. It is only permitted for entries at the default `/var/lib/dokku/data/storage/<name>` location; an entry created with a custom `<path>` is refused, and the operator removes the path themselves.
The same removal can be declared ahead of time with `--reclaim-policy`, which behaves for a docker-local host directory the way it behaves for a k3s PersistentVolume. An entry created with `Delete` has its host directory removed on `storage:destroy` without any extra flag, while `Retain` - the default when unset - keeps it:
```shell
dokku storage:create node-js-data --reclaim-policy Delete
dokku storage:destroy node-js-data --force
```
`--destroy-host-dir` is docker-local only. On a k3s entry the underlying volume is already governed by the reclaim policy recorded on the entry, so passing the flag is an error.
### Displaying storage reports for an app
> [!IMPORTANT]
@@ -185,6 +391,60 @@ You can pass flags which will output only the value of the specific information
dokku storage:report node-js-app --storage-deploy-mounts
```
In addition to the aggregated `Storage build/deploy/run mounts:` lines, the report emits one flat dotted key per attachment field, indexed from `1`. The key shape is `--storage-attachment.<index>.<field>` for each of `entry-name`, `host-path`, `container-path`, `phases`, `process-type`, `subpath`, `readonly`, `volume-options`, and `volume-chown`. Fields render as empty strings when unset, and attachments are ordered by lex-sort of the index (so `10` sorts before `2`):
```shell
dokku storage:create node-js-data
dokku storage:mount node-js-app node-js-data --container-dir /app/storage --volume-options Z --volume-chown herokuish --volume-subpath uploads
dokku storage:report node-js-app
```
```
=====> node-js-app storage information
Storage attachment 1 container path: /app/storage
Storage attachment 1 entry name: node-js-data
Storage attachment 1 host path: /var/lib/dokku/data/storage/node-js-data
Storage attachment 1 phases: deploy,run
Storage attachment 1 process type: _default_
Storage attachment 1 readonly: false
Storage attachment 1 subpath: uploads
Storage attachment 1 volume chown: herokuish
Storage attachment 1 volume options: Z
Storage build mounts:
Storage deploy mounts: -v /var/lib/dokku/data/storage/node-js-data:/app/storage:Z
Storage run mounts: -v /var/lib/dokku/data/storage/node-js-data:/app/storage:Z
```
The same keys are exposed in JSON output, both in the stripped (`attachment.1.volume-options`) and legacy (`storage-attachment.1.volume-options`) forms:
```shell
dokku storage:report node-js-app --format json | jq '. | with_entries(select(.key | startswith("attachment.")))'
```
```json
{
"attachment.1.container-path": "/app/storage",
"attachment.1.entry-name": "node-js-data",
"attachment.1.host-path": "/var/lib/dokku/data/storage/node-js-data",
"attachment.1.phases": "deploy,run",
"attachment.1.process-type": "_default_",
"attachment.1.readonly": "false",
"attachment.1.subpath": "uploads",
"attachment.1.volume-chown": "herokuish",
"attachment.1.volume-options": "Z"
}
```
A single attachment field can be fetched directly via the info-flag form:
```shell
dokku storage:report node-js-app --storage-attachment.1.volume-options
```
```
Z
```
## Use Cases
### Sharing storage across deploys

View File

@@ -9,7 +9,7 @@ plugin:enable <name> # Enable a previously disabled plugin
plugin:install [--core|git-url] [--committish branch|commit|tag] [--name custom-plugin-name] [--skip-install-trigger] # Optionally download git-url (and pin to the specified branch/commit/tag) & run install trigger for active plugins (or only core ones)
plugin:installed <name> # Checks if a plugin is installed
plugin:install-dependencies [--core] # Run install-dependencies trigger for active plugins (or only core ones)
plugin:list # Print active plugins
plugin:list [--format stdout|json] # Print active plugins
plugin:trigger <args...>. # Trigger an arbitrary plugin hook
plugin:uninstall <name> # Uninstall a plugin (third-party only)
plugin:update [name [branch|commit|tag]] # Optionally update named plugin from git (and pin to the specified branch/commit/tag) & run update trigger for active plugins
@@ -36,37 +36,70 @@ dokku plugin:list
```
plugn: dev
00_dokku-standard 0.38.8 enabled dokku core standard plugin
20_events 0.38.8 enabled dokku core events logging plugin
app-json 0.38.8 enabled dokku core app-json plugin
apps 0.38.8 enabled dokku core apps plugin
build-env 0.38.8 enabled dokku core build-env plugin
buildpacks 0.38.8 enabled dokku core buildpacks plugin
certs 0.38.8 enabled dokku core certificate management plugin
checks 0.38.8 enabled dokku core checks plugin
common 0.38.8 enabled dokku core common plugin
config 0.38.8 enabled dokku core config plugin
docker-options 0.38.8 enabled dokku core docker-options plugin
domains 0.38.8 enabled dokku core domains plugin
enter 0.38.8 enabled dokku core enter plugin
git 0.38.8 enabled dokku core git plugin
logs 0.38.8 enabled dokku core logs plugin
network 0.38.8 enabled dokku core network plugin
nginx-vhosts 0.38.8 enabled dokku core nginx-vhosts plugin
plugin 0.38.8 enabled dokku core plugin plugin
proxy 0.38.8 enabled dokku core proxy plugin
ps 0.38.8 enabled dokku core ps plugin
repo 0.38.8 enabled dokku core repo plugin
resource 0.38.8 enabled dokku core resource plugin
scheduler-docker-local 0.38.8 enabled dokku core scheduler-docker-local plugin
shell 0.38.8 enabled dokku core shell plugin
ssh-keys 0.38.8 enabled dokku core ssh-keys plugin
storage 0.38.8 enabled dokku core storage plugin
tags 0.38.8 enabled dokku core tags plugin
tar 0.38.8 enabled dokku core tar plugin
trace 0.38.8 enabled dokku core trace plugin
00_dokku-standard 0.38.27 enabled dokku core standard plugin
20_events 0.38.27 enabled dokku core events logging plugin
app-json 0.38.27 enabled dokku core app-json plugin
apps 0.38.27 enabled dokku core apps plugin
build-env 0.38.27 enabled dokku core build-env plugin
buildpacks 0.38.27 enabled dokku core buildpacks plugin
certs 0.38.27 enabled dokku core certificate management plugin
checks 0.38.27 enabled dokku core checks plugin
common 0.38.27 enabled dokku core common plugin
config 0.38.27 enabled dokku core config plugin
docker-options 0.38.27 enabled dokku core docker-options plugin
domains 0.38.27 enabled dokku core domains plugin
enter 0.38.27 enabled dokku core enter plugin
git 0.38.27 enabled dokku core git plugin
logs 0.38.27 enabled dokku core logs plugin
network 0.38.27 enabled dokku core network plugin
nginx-vhosts 0.38.27 enabled dokku core nginx-vhosts plugin
plugin 0.38.27 enabled dokku core plugin plugin
proxy 0.38.27 enabled dokku core proxy plugin
ps 0.38.27 enabled dokku core ps plugin
repo 0.38.27 enabled dokku core repo plugin
resource 0.38.27 enabled dokku core resource plugin
scheduler-docker-local 0.38.27 enabled dokku core scheduler-docker-local plugin
shell 0.38.27 enabled dokku core shell plugin
ssh-keys 0.38.27 enabled dokku core ssh-keys plugin
storage 0.38.27 enabled dokku core storage plugin
tags 0.38.27 enabled dokku core tags plugin
tar 0.38.27 enabled dokku core tar plugin
trace 0.38.27 enabled dokku core trace plugin
```
The list can also be emitted as JSON via the `--format json` flag. In addition to the name, version, enabled state, and description shown in the default output, the JSON output includes whether a plugin is a core plugin and - for git-based third-party plugins - the install source (the git remote URL, the currently checked-out commit, and the followed branch). This is useful for tooling that reconstructs a server's set of installed plugins:
```shell
dokku plugin:list --format json
```
```json
[
{
"name": "apps",
"version": "0.38.27",
"enabled": true,
"core": true,
"description": "dokku core apps plugin",
"source_url": "",
"committish": "",
"branch": ""
},
{
"name": "postgres",
"version": "1.42.0",
"enabled": true,
"core": false,
"description": "dokku postgres service plugin",
"source_url": "https://github.com/dokku/dokku-postgres.git",
"committish": "a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0",
"branch": "master"
}
]
```
The `source_url`, `committish`, and `branch` fields are only populated for plugins installed from a git repository. They are empty for core plugins as well as for plugins installed from a tarball or a local `file://` path. When a plugin is pinned to a specific commit or tag (a detached checkout), the `branch` field is empty while `committish` still reports the exact commit.
> [!WARNING]
> All plugin commands other than `plugin:list` and `plugin:help` require sudo access and must be run directly from the Dokku server.

View File

@@ -15,7 +15,7 @@
}
```
- The path on disk to both the global `ENV` file and app `ENV` files have been moved. Users should reference environment variables via the provided plugin triggers rather than directly sourcing the ENV files. Existing ENV files are left untouched and will be removed on the subsequent Dokku install.
- The path on disk to both the global `ENV` file and app `ENV` files have been moved. Users should reference environment variables via the provided plugin triggers rather than directly sourcing the ENV files. Existing ENV files are merged into the new location and removed once they have been drained. **Changed in 0.38.26:** removal previously happened on the subsequent Dokku install for app ENV files, and never happened at all for the global ENV file. **Changed in 0.38.27:** an ENV file found at the old path after its migration has been recorded is never merged into the new location, because the new location holds every change made since. Such a file is removed when its values agree with the current config, and otherwise moved aside to `ENV.migrated` with the keys it disagrees on named in a warning, so its values can still be applied by hand with `dokku config:set`. That copy is left for review and should be deleted afterwards: Dokku no longer reads it, and it holds everything it was not allowed to import - including keys that were unset on purpose, which for a revoked secret means a copy lingering on disk.
- During a fresh apt install, the upstream nginx default vhost files (`/etc/nginx/sites-enabled/default`, `/etc/nginx/sites-available/default`, and `/etc/nginx/conf.d/default.conf`) are renamed to `${path}.dokku-disabled` (not deleted) to avoid a `duplicate default server for 0.0.0.0:80` error. Operators with local customizations can recover them by inspecting the `.dokku-disabled` siblings. Upgrade-in-place installs do not touch any existing nginx files.
- Fresh apt installs now ship a catch-all default site at `/etc/nginx/conf.d/00-default-vhost.conf` that rejects requests with unknown Host headers using `ssl_reject_handshake on` (HTTPS) and `return 444` (HTTP). This replaces the manual workaround previously documented in the nginx docs. The behavior can be opted out at install time via the `dokku/install_default_site` debconf prompt. On nginx older than 1.19.4 (e.g., Debian Bullseye's nginx 1.18.0), the postinst installs an HTTP-only variant of the catch-all that omits the SSL listener and `ssl_reject_handshake`, since that directive is unsupported on those versions. See the [Default site documentation](/docs/networking/proxies/nginx.md#default-site).
- The `docker-local` scheduler now sends `SIGTERM` to old containers immediately after a successful deploy, rather than waiting `wait-to-retire` seconds before signaling. This matches Heroku's graceful-shutdown contract and lets applications begin draining in-flight work as soon as proxy traffic switches. The `wait-to-retire` grace period and `stop-timeout-seconds` hard-stop continue to apply as before. See the [zero downtime deploys documentation](/docs/deployment/zero-downtime-deploys.md#wait-to-retire) for more details.
@@ -23,9 +23,13 @@
- All `:report` subcommands now accept the `--global` flag, which scopes the report to globally-configured properties. The flag composes with `--format json`, so a JSON report of global properties can be obtained via, for example, `dokku scheduler:report --global --format json`. Previously, combining `--global` with `--format json` was rejected with an "info flag" error, and `--global` on its own was treated as an unknown flag.
- Every `:report` key of the form `<plugin>-global-<property>` now returns the raw stored global value (empty when the property has never been set) instead of the resolved value with the built-in default substituted in. A new `<plugin>-computed-<property>` key has been added wherever a default existed and returns the effective value (per-app value, falling back to the global value, then to the built-in default). This affects `app-json`, `builder-dockerfile`, `builder-herokuish`, `builder-lambda`, `builder-nixpacks`, `builder-pack`, `builder-railpack`, `caddy`, `checks`, `git`, `haproxy`, `logs`, `network`, `nginx`, `openresty`, `proxy`, `registry`, `scheduler`, `scheduler-k3s` and `traefik`. External tooling that read `<plugin>-global-<property>` and depended on the default value should switch to `<plugin>-computed-<property>`. The bare `<plugin>-<property>` keys for caddy/haproxy/traefik/openresty global-only properties (`caddy-image`, `haproxy-log-level`, `traefik-api-enabled`, `openresty-image`, `openresty-letsencrypt-email`, `openresty-letsencrypt-server`, `openresty-allowed-letsencrypt-domains-func-base64`, etc.) have also been replaced by the `global-` and `computed-` pair.
- The `ps` and `cron` plugins now follow the same `<plugin>-global-<property>` / `<plugin>-computed-<property>` convention. The `ps:report` keys `stop-timeout-seconds`, `global-stop-timeout-seconds`, and `computed-stop-timeout-seconds` have been renamed to `ps-stop-timeout-seconds`, `ps-global-stop-timeout-seconds`, and `ps-computed-stop-timeout-seconds`. The `cron:report` keys `cron-mailfrom` and `cron-mailto` have been renamed to `cron-global-mailfrom` and `cron-global-mailto`, and new `cron-computed-mailfrom` and `cron-computed-mailto` keys have been added. The corresponding user-facing `--<flag>` arguments to `ps:report` and `cron:report` were renamed alongside the JSON keys; no aliases are kept. Additionally, both `ps:report --global` and `cron:report --global` now emit the `<plugin>-computed-<property>` keys for every settable global property with a default (`ps-computed-procfile-path`, `ps-computed-stop-timeout-seconds`, `cron-computed-maintenance`, `cron-computed-mailfrom`, `cron-computed-mailto`), matching the shape used by the other plugins.
- A second round of `:report` additions surfaces every remaining settable-but-unreported property under the same raw/global/computed convention so external tooling can verify drift via `:report --format json` without falling back to a generic bash task. The `ps` plugin gains `--ps-dockerfile-start-cmd` and `--ps-computed-dockerfile-start-cmd`, `--ps-start-cmd` and `--ps-computed-start-cmd`, and the `--ps-skip-deploy` / `--ps-global-skip-deploy` / `--ps-computed-skip-deploy` triple (default `false`). The `builder` plugin gains the `--builder-skip-cleanup` triple (default `false`). The `scheduler` plugin gains the `--scheduler-shell` triple. The `proxy` plugin gains the `--proxy-proxy-port` and `--proxy-proxy-ssl-port` triples and exposes the raw `disabled` property as `--proxy-disabled` / `--proxy-computed-disabled`, alongside the existing inverted `--proxy-enabled`. The `openresty` plugin gains `--openresty-global-log-level` and `--openresty-computed-log-level` (default `ERROR`). The `nginx` plugin gains the `--nginx-nginx-service-command` triple. The `scheduler-k3s` plugin gains `--scheduler-k3s-global-token`, but the value is masked as `*******` in default stdout output; the raw value is returned only when the report is requested via `--format json` or when this flag is queried explicitly by name. The traefik `dns-provider-<env_var>` keys now follow the same explicit-query rule - previously they were unmasked only for `--format json`, but a query like `dokku traefik:report --traefik-dns-provider-cf_api_key` now returns the actual value instead of `*******`.
- A second round of `:report` additions surfaces every remaining settable-but-unreported property under the same raw/global/computed convention so external tooling can verify drift via `:report --format json` without falling back to a generic bash task. The `ps` plugin gains `--ps-dockerfile-start-cmd` and `--ps-computed-dockerfile-start-cmd`, `--ps-start-cmd` and `--ps-computed-start-cmd`, and the `--ps-skip-deploy` / `--ps-global-skip-deploy` / `--ps-computed-skip-deploy` triple (default `false`). The `builder` plugin gains the `--builder-skip-cleanup` triple (default `false`). The `scheduler` plugin gains the `--scheduler-shell` triple. The `proxy` plugin gains the `--proxy-proxy-port` and `--proxy-proxy-ssl-port` triples and exposes the raw `disabled` property as `--proxy-disabled` / `--proxy-computed-disabled`, alongside the existing inverted `--proxy-enabled`. The `openresty` plugin gains `--openresty-global-log-level` and `--openresty-computed-log-level` (default `ERROR`). The `nginx` plugin gains the `--nginx-nginx-service-command` triple. The `scheduler-k3s` plugin gains `--scheduler-k3s-global-token`, but the value is masked as `*******` in default stdout output; the raw value is returned only when the report is requested via `--format json` or when this flag is queried explicitly by name. The traefik `dns-provider-<env_var>` keys are reported as `--traefik-global-dns-provider-<env_var>` and follow the same masking and explicit-query rules, as does the traefik `basic-auth-password` property, whose `--traefik-global-basic-auth-password` and `--traefik-computed-basic-auth-password` keys are masked in default stdout output.
- All Go-implemented plugins (`app-json`, `apps`, `builder`, `buildpacks`, `builds`, `cron`, `docker-options`, `logs`, `network`, `ports`, `proxy`, `ps`, `registry`, `resource`, `scheduler`, `scheduler-k3s`, `storage`) now emit JSON keys from `:report --format json` without the `<plugin>-` head segment, matching the shape bash plugins have always emitted. For example, `dokku ps:report myapp --format json` now contains `stop-timeout-seconds`, `global-stop-timeout-seconds`, and `computed-stop-timeout-seconds` keys. The CLI flag names (`--ps-stop-timeout-seconds`, etc.) are unchanged, and `:set` semantics are unchanged. For backwards compatibility during the 0.38.x patch series, the old `<plugin>-<property>` JSON keys are emitted side-by-side with the new keys, so external scripts reading either shape continue to work. The legacy keys will be dropped in a future major release. External JSON consumers should migrate to the new key shape.
- The `scheduler-k3s` plugin now manages env config and the dokku-generated image pull Secret as their own helm releases with stable names (`config-{app}` and `pull-secret-{app}`) rather than bundling them into the app helm chart with a per-deploy timestamp suffix (`env-{app}.{ts}` / `ims-{app}.{ts}`). This fixes two bugs: a helm rollback of the app chart no longer deletes Secrets that older ReplicaSets still reference, and the Deployment's `imagePullSecrets` list no longer accumulates references to nonexistent Secrets across deploys. The next deploy of an app switches the Deployment's `envFrom` and `imagePullSecrets` references to the stable names and prunes any leaked entries; existing live Deployments do not need to be patched manually. App rename now also uninstalls the old `tls-{app}`, `config-{app}`, and `pull-secret-{app}` releases under the previous app name; the new name's releases are recreated on the next deploy or certs sync.
- **New in 0.38.25:** Values supplied through docker options, `dokku run`'s `-e`/`--env` flag, and `--ttl-seconds` are no longer evaluated by the shell when assembling a container's arguments; they are now tokenized and passed through verbatim. This closes a command-injection vector where a `$(...)` or backtick expression in one of these values executed on the host as the `dokku` user during build, deploy, or run. As a result, shell metacharacters such as `$(...)`, backticks, `$VAR`, and globs in these values are treated literally instead of being expanded, and `--ttl-seconds` must now be a plain integer. Existing Traefik docker-options labels (those whose label key begins with `traefik.`) whose backticks were stored with a stray backslash are repaired automatically the first time `dokku` runs after the upgrade, so they become valid on the next deploy.
- **New in 0.38.26:** Docker options drained out of the pre-0.38.0 `DOCKER_OPTIONS_<PHASE>` files were copied verbatim rather than being re-serialized the way `docker-options:add` stores them, so `docker-options:remove` compared the canonical string it builds against a value that could never match it and exited successfully without removing anything. Removal now matches stored options by shell word instead of by exact string, so those entries can be removed with the value as originally written. Stored options are also rewritten into the canonical form the first time `dokku` runs after the upgrade: values whose shell metacharacters were left unquoted are quoted, and an entry that carried several flags on one line becomes one entry per flag, which additionally fixes `ps:report` reading a restart policy off such a line and the `k3s` scheduler translating only the first of several `--cap-add`/`--sysctl` flags. Options added through `docker-options:add` are already canonical and are left untouched.
- **New in 0.38.26:** Deprecated `DOKKU_*` config variables belonging to plugins whose install step runs before the `config` plugin's were not migrated to their plugin property on the upgrade run. Install steps fire in alphabetical order, so `apps`, `builder`, and `checks` read an app's environment before the `config` plugin had relocated the `ENV` file, found nothing, and moved nothing - without reporting anything. `dokku config:show` kept listing the variable while the plugin behaved as though it were unset, which for `DOKKU_CHECKS_SKIPPED` meant a process type silently regained a health check it was meant to skip. The relocation is now performed before any deprecated variable is read, regardless of install order. Affected installs recover on their next `dokku plugin:install --core`, which the upgrade already runs; the variables listed below can also be re-applied by hand using their replacement command.
- **New in 0.38.27:** The 0.38.26 upgrade merged the leftover pre-0.38.0 `ENV` file back over the current config. Releases 0.38.0 through 0.38.25 recorded the migration and left that file on disk on purpose, and 0.38.26 read it as a hand-edit, so the environment as it stood at the 0.38.x upgrade won over every `dokku config:set` and `dokku config:unset` made since - including reinstating variables and secrets that had been deliberately unset. Nothing appeared broken, because running containers keep the environment they were created with; the rewound values would have reached containers on the next deploy. The 0.38.26 run consumed the leftover file, so this cannot happen a second time, but it also cannot be undone automatically. To check an app that was upgraded to 0.38.26 and has a container still running from before that upgrade, compare each key in `dokku config:show <app>` against `docker exec <container> printenv <key>` - `GIT_REV` is expected to differ after a deploy, anything else that differs was rewound. Repair with `dokku config:set --no-restart <app> KEY=VALUE` for values that regressed and `dokku config:unset --no-restart <app> KEY` for variables that came back.
- The storage plugin now treats persistent volumes as named, scheduler-aware first-class resources via `storage:create`, `storage:mount`, `storage:set`, and `storage:destroy`. The legacy `storage:mount <app> <host>:<container>` colon form continues to work on docker-local apps but is deprecated; on k3s apps it is rejected. Existing colon-form mounts are migrated automatically the first time the new storage plugin runs (during the install trigger) - they appear as `legacy-<hash>` entries in `storage:list-entries`. The migration is idempotent and tied to a per-app flag file at `$DOKKU_LIB_ROOT/config/storage/.migrated/<app>`; deleting that file forces a re-scan on the next install. The `storage:ensure-directory` command keeps working but now emits a deprecation warning - prefer `storage:create <name> [<path>]` (the path defaults to the same `$DOKKU_LIB_ROOT/data/storage/<name>` location). Storage entry names must now be DNS-1123 labels of 45 characters or less so they can be used verbatim as Helm release and Kubernetes resource names; underscores and uppercase characters that the older `ensure-directory` validator accepted are rejected for new names. The migration synthesizer always uses lowercase hex hashes so existing data is never locked out.
### TLS handshake behavior change

View File

@@ -8,6 +8,43 @@ A custom `nginx.conf.sigil` is pre-validated at the start of every deploy, immed
Pre-validation is skipped when the proxy type is not `nginx` or when `disable-custom-config` is set to `true` for the app.
### Custom nginx modules
Pre-validation runs `nginx -t` against a minimal wrapper config that does _not_ include the top-level `load_module` directives from the global `/etc/nginx/nginx.conf`. A `nginx.conf.sigil` that uses a directive provided by a dynamically loaded module - such as `image_filter`, provided by the [ngx_http_image_filter_module](https://nginx.org/en/docs/http/ngx_http_image_filter_module.html) - therefore fails pre-validation with an `unknown directive` error, even though `nginx -t` succeeds against the real server config where the module is loaded.
The `load_module` directive cannot be added to the app's `nginx.conf.sigil` to work around this, as that file is included inside the `http { }` block while `load_module` is only valid in nginx's top-level main context.
To make pre-validation aware of a module, override the wrapper template used for validation. The [`nginx-app-template-source`](/docs/development/plugin-triggers.md#nginx-app-template-source) trigger returns the path to the `sigil` template used to generate a given nginx configuration file, and its `validate-config` template type controls the pre-validation wrapper. Create a [custom plugin](/docs/development/plugin-creation.md) that implements the trigger and returns a `validate.conf.sigil` that adds the required `load_module` line at the top of the wrapper.
The trigger file (named `nginx-app-template-source` and marked executable):
```shell
#!/usr/bin/env bash
set -eo pipefail
[[ $DOKKU_TRACE ]] && set -x
APP="$1"
TEMPLATE_TYPE="$2"
if [[ "$TEMPLATE_TYPE" == "validate-config" ]]; then
echo "$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)/validate.conf.sigil"
fi
```
The custom `validate.conf.sigil`, which is the [default wrapper](https://github.com/dokku/dokku/blob/master/plugins/nginx-vhosts/templates/validate.conf.sigil) with the required `load_module` line added at the top. Use the same `load_module` line that the host's global `/etc/nginx/nginx.conf` uses:
```
load_module modules/ngx_http_image_filter_module.so;
events { worker_connections 768; }
http {
access_log off;
error_log /dev/null;
include {{ $.NGINX_CONF }};
}
```
The same override also governs the standalone `dokku nginx:validate-config` command, which renders the `validate-config` template as well.
## HTTP/2
nginx 1.25.1 deprecated the `http2` parameter on the `listen` directive in favor of a standalone `http2 on;` directive. Custom `nginx.conf.sigil` templates that hardcode `listen ... ssl http2;` will produce `nginx: [warn] the "listen ... http2" directive is deprecated` warnings when run against nginx 1.25.1 or newer.

View File

@@ -2,10 +2,10 @@
<browserconfig>
<msapplication>
<tile>
<square70x70logo src="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.8/docs/assets/favicons/mstile-70x70.png"/>
<square150x150logo src="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.8/docs/assets/favicons/mstile-150x150.png"/>
<square310x310logo src="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.8/docs/assets/favicons/mstile-310x310.png"/>
<wide310x150logo src="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.8/docs/assets/favicons/mstile-310x150.png"/>
<square70x70logo src="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.27/docs/assets/favicons/mstile-70x70.png"/>
<square150x150logo src="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.27/docs/assets/favicons/mstile-150x150.png"/>
<square310x310logo src="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.27/docs/assets/favicons/mstile-310x310.png"/>
<wide310x150logo src="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.27/docs/assets/favicons/mstile-310x150.png"/>
<TileColor>#da532c</TileColor>
</tile>
</msapplication>

View File

@@ -2,37 +2,37 @@
"name": "Dokku",
"icons": [
{
"src": "https:\/\/cdn.jsdelivr.net\/dokku\/dokku@v0.38.8\/docs\/assets\/favicons\/android-chrome-36x36.png",
"src": "https:\/\/cdn.jsdelivr.net\/dokku\/dokku@v0.38.27\/docs\/assets\/favicons\/android-chrome-36x36.png",
"sizes": "36x36",
"type": "image\/png",
"density": "0.75"
},
{
"src": "https:\/\/cdn.jsdelivr.net\/dokku\/dokku@v0.38.8\/docs\/assets\/favicons\/android-chrome-48x48.png",
"src": "https:\/\/cdn.jsdelivr.net\/dokku\/dokku@v0.38.27\/docs\/assets\/favicons\/android-chrome-48x48.png",
"sizes": "48x48",
"type": "image\/png",
"density": "1.0"
},
{
"src": "https:\/\/cdn.jsdelivr.net\/dokku\/dokku@v0.38.8\/docs\/assets\/favicons\/android-chrome-72x72.png",
"src": "https:\/\/cdn.jsdelivr.net\/dokku\/dokku@v0.38.27\/docs\/assets\/favicons\/android-chrome-72x72.png",
"sizes": "72x72",
"type": "image\/png",
"density": "1.5"
},
{
"src": "https:\/\/cdn.jsdelivr.net\/dokku\/dokku@v0.38.8\/docs\/assets\/favicons\/android-chrome-96x96.png",
"src": "https:\/\/cdn.jsdelivr.net\/dokku\/dokku@v0.38.27\/docs\/assets\/favicons\/android-chrome-96x96.png",
"sizes": "96x96",
"type": "image\/png",
"density": "2.0"
},
{
"src": "https:\/\/cdn.jsdelivr.net\/dokku\/dokku@v0.38.8\/docs\/assets\/favicons\/android-chrome-144x144.png",
"src": "https:\/\/cdn.jsdelivr.net\/dokku\/dokku@v0.38.27\/docs\/assets\/favicons\/android-chrome-144x144.png",
"sizes": "144x144",
"type": "image\/png",
"density": "3.0"
},
{
"src": "https:\/\/cdn.jsdelivr.net\/dokku\/dokku@v0.38.8\/docs\/assets\/favicons\/android-chrome-192x192.png",
"src": "https:\/\/cdn.jsdelivr.net\/dokku\/dokku@v0.38.27\/docs\/assets\/favicons\/android-chrome-192x192.png",
"sizes": "192x192",
"type": "image\/png",
"density": "4.0"

View File

@@ -25,9 +25,9 @@
/* Avatar section darkmode fade */
--avatar-before-gradient: rgba(0, 0, 0, 0) linear-gradient(90deg, white 2.52%, rgba(255, 255, 255, 0) 100%) repeat scroll 0% 0%;
--avatar-darkmode-before-gradient: rgba(0, 0, 0, 0) linear-gradient(90deg, #0.38.8 2.52%, rgba(255, 255, 255, 0) 100%) repeat scroll 0% 0%;
--avatar-darkmode-before-gradient: rgba(0, 0, 0, 0) linear-gradient(90deg, #0.38.27 2.52%, rgba(255, 255, 255, 0) 100%) repeat scroll 0% 0%;
--avatar-after-gradient: rgba(0, 0, 0, 0) linear-gradient(270deg, white 2.52%, rgba(255, 255, 255, 0) 100%) repeat scroll 0% 0%;
--avatar-darkmode-after-gradient: rgba(0, 0, 0, 0) linear-gradient(270deg, #0.38.8 2.52%, rgba(255, 255, 255, 0) 100%) repeat scroll 0% 0%;
--avatar-darkmode-after-gradient: rgba(0, 0, 0, 0) linear-gradient(270deg, #0.38.27 2.52%, rgba(255, 255, 255, 0) 100%) repeat scroll 0% 0%;
}
body {
@@ -1191,15 +1191,15 @@ ul.fas li .fa-large:before {
.getting-started::after {
background: linear-gradient(0deg, rgba(52, 52, 87, 0.2) -40.97%, rgba(0, 0, 0, 0) 103.19%),
#0.38.8;
#0.38.27;
}
.tab-content {
background: #0.38.8;
background: #0.38.27;
}
.nav-tabs {
background: #0.38.8;
background: #0.38.27;
}
.powered-by_brands {

View File

@@ -35,6 +35,6 @@
"0.35.20",
"0.36.11",
"0.37.10",
"0.38.8"
"0.38.27"
]
}

View File

@@ -151,4 +151,4 @@ The following property is recorded internally by the config plugin and is not ex
| Property | Description | Source |
|---|---|---|
| `env-migrated` | Migration sentinel that records the per-app or global `DOKKU_*` env-var → property migration completed for 0.38.0 | `plugins/config/triggers.go` writes `"true"` after the upgrade-time pass |
| `env-migrated` | Migration sentinel that records that the per-app or global `ENV` file has been drained out of its pre-0.38.0 location into the config path. The drain happens once: a file found at the old path once this is recorded is never imported, since the config path holds every change made since. Such a file is removed when it agrees with the current config, and otherwise moved aside to `ENV.migrated` with the keys it disagrees on named in a warning. The preserved copy is left for review and should be deleted afterwards, since it holds keys that were unset on purpose | `plugins/config/migrate.go` writes `"true"` once the file has been drained |

View File

@@ -8,7 +8,7 @@ apps:clone <old-app> <new-app> # Clones an app
apps:create <app> # Create a new app
apps:destroy <app> # Permanently destroy an app
apps:exists <app> # Checks if an app exists
apps:list # List your apps
apps:list [--format stdout|json] # List your apps
apps:lock <app> # Locks an app for deployment
apps:locked <app> # Checks if an app is locked for deployment
apps:rename <old-app> <new-app> # Rename an app
@@ -47,6 +47,18 @@ node-js-app
python-app
```
You can also retrieve the list of apps as a JSON array by using the `--format json` flag, which is useful for programmatic consumption:
```shell
dokku apps:list --format json
```
```json
["node-js-app","python-app"]
```
When no apps exist, the JSON output is an empty array (`[]`).
### Checking if an application exists
For CI/CD pipelines, it may be useful to see if an application exists before creating a "review" application for a specific branch. You can do so via the `apps:exists` command:
@@ -315,6 +327,15 @@ dokku apps:report node-js-app --app-dir
## Properties
### Settable properties
> [!NOTE]
> The `Report flags` column lists the CLI argument names accepted by `apps:report`. The JSON keys emitted by `apps:report --format json` are the same names with the leading `--app-` stripped (e.g. `global-disable-autocreation`). Legacy keys with the `app-` prefix (e.g. `app-global-disable-autocreation`) are also emitted during the 0.38.x deprecation window and will be removed in a future major release.
| Property | Scope | Default | Report flags | Description |
|---|---|---|---|---|
| `disable-autocreation` | global only | `false` | `--app-global-disable-autocreation` | When `true`, pushes to a remote for an app that does not yet exist are rejected instead of auto-creating the app |
### Read-only flags
The following flags surface in `apps:report` but are not managed by `apps:set`:

View File

@@ -10,6 +10,7 @@ buildpacks:list <app> # List all buildpacks fo
buildpacks:remove <app> <buildpack> # Remove a buildpack set on the app
buildpacks:report [<app>] [<flag>] # Displays a buildpack report for one or more apps
buildpacks:set [--index 1] <app> <buildpack> # Set new app buildpack at a given position defaulting to the first buildpack if no index is specified
buildpacks:set --replace <app> <buildpack> [<buildpack> ...] # Replace the entire ordered buildpack list with the specified buildpacks
```
## Usage
@@ -86,6 +87,25 @@ If the index specified is larger than the number of buildpacks currently configu
dokku buildpacks:set --index 99 node-js-app https://github.com/heroku/heroku-buildpack-ruby.git
```
### Replacing the entire buildpack list
To replace the complete ordered buildpack list in a single command, use the `--replace` flag. This is useful for tooling that needs to apply a full buildpack list atomically instead of running `buildpacks:clear` followed by multiple `buildpacks:add` calls.
```shell
dokku buildpacks:set --replace node-js-app https://github.com/heroku/heroku-buildpack-ruby.git https://github.com/heroku/heroku-buildpack-nodejs.git
```
The buildpacks are executed in the order they are specified, and the previous list is discarded. If any specified buildpack is invalid, the existing list is left unchanged.
A single buildpack may also be specified to replace the entire list with just that buildpack:
```shell
dokku buildpacks:set --replace node-js-app https://github.com/heroku/heroku-buildpack-ruby.git
```
> [!NOTE]
> The `--replace` flag cannot be combined with the `--index` flag. To remove all buildpacks, use the `buildpacks:clear` command instead of `--replace` with no buildpacks.
### Removing a buildpack
> At least one of a buildpack or index must be specified

View File

@@ -185,32 +185,32 @@ See the [Procfile documentation](/docs/processes/process-management.md#procfile)
### Listing Buildpacks in Use
See the [buildpack management documentation](/docs/processes/process-management.md#listing-buildpacks-in-use) for more information on how to list buildpacks in use.
See the [buildpack management documentation](/docs/deployment/builders/buildpack-management.md#listing-buildpacks-in-use) for more information on how to list buildpacks in use.
### Adding custom buildpacks
See the [buildpack management documentation](/docs/processes/process-management.md#adding-custom-buildpacks) for more information on how to add custom buildpacks.
See the [buildpack management documentation](/docs/deployment/builders/buildpack-management.md#adding-custom-buildpacks) for more information on how to add custom buildpacks.
### Overwriting a buildpack position
See the [buildpack management documentation](/docs/processes/process-management.md#overwriting-a-buildpack-position) for more information on how to overwrite a buildpack position.
See the [buildpack management documentation](/docs/deployment/builders/buildpack-management.md#overwriting-a-buildpack-position) for more information on how to overwrite a buildpack position.
### Removing a buildpack
See the [buildpack management documentation](/docs/processes/process-management.md#removing-a-buildpack) for more information on how to remove a buildpack.
See the [buildpack management documentation](/docs/deployment/builders/buildpack-management.md#removing-a-buildpack) for more information on how to remove a buildpack.
### Clearing all buildpacks
See the [buildpack management documentation](/docs/processes/process-management.md#clearing-all-buildpacks) for more information on how to clear all buildpacks.
See the [buildpack management documentation](/docs/deployment/builders/buildpack-management.md#clearing-all-buildpacks) for more information on how to clear all buildpacks.
### Using a specific buildpack version
See the [buildpack management documentation](/docs/processes/process-management.md#using-a-specific-buildpack-version) for more information on how to using a specific buildpack version
See the [buildpack management documentation](/docs/deployment/builders/buildpack-management.md#using-a-specific-buildpack-version) for more information on how to using a specific buildpack version
### Displaying buildpack reports for an app
See the [buildpack management documentation](/docs/processes/process-management.md#displaying-buildpack-reports-for-an-app) for more information on how to display buildpack reports for an app.
See the [buildpack management documentation](/docs/deployment/builders/buildpack-management.md#displaying-buildpack-reports-for-an-app) for more information on how to display buildpack reports for an app.
## Properties

View File

@@ -124,6 +124,21 @@ The `/etc/vector` mount includes the `vector.json` configuration file, but also
The final volume mount - `/var/log/dokku/apps` - may be used for users that wish to ship logs to a file on disk that may be later logrotated. This directory is owned by the `dokku` user and group, with permissions set to `0755`. At this time, log-rotation is not configured for this directory.
Operators using a `file` sink are encouraged to configure rotation themselves, as Dokku will not truncate these files. A minimal `/etc/logrotate.d/dokku-app-logs` might look like:
```
/var/log/dokku/apps/*/*.log {
daily
rotate 14
compress
missingok
notifempty
copytruncate
}
```
`copytruncate` is used because Vector holds the file open between writes.
#### Stopping the Vector container
Vector may be stopped via the `logs:vector-stop` command.
@@ -241,6 +256,8 @@ As with app-specific sink settings, the global value may also be cleared by sett
dokku logs:set --global vector-sink
```
The generated vector configuration is also rewritten whenever an app is renamed, cloned or destroyed. A renamed app keeps shipping to its sink under the new name, a cloned app gets a source of its own for the sink it inherited, and a destroyed app's source and sink are removed rather than left pointing at an endpoint that was decommissioned with the app.
##### Log Sink DSN Format
The DSN form of a sink is as follows:
@@ -282,28 +299,85 @@ This will transform the value to it's encoded form when configuring Vector sinks
Please read the [sink documentation](https://vector.dev/docs/reference/configuration/sinks/) for your sink of choice to configure the sink as desired.
##### Configuring the app label
#### Configuring a cron task log sink
Logs shipped by vector include the label `com.dokku.app-name`, which is an alias for the app name. This can be changed via the `app-label-alias` logs property with the `logs:set` command. Specifying a new alias will reload any running vector container.
Scheduled cron tasks run in one-off containers that carry the app's usual labels, so their output is already collected by the `vector-sink` configured for the app or globally. To send that output somewhere separate, set a `vector-cron-sink`.
```shell
# setting the sink value in quotes is encouraged to avoid
# issues with ampersand encoding in shell commands
dokku logs:set node-js-app app-label-alias "app-name"
dokku logs:set node-js-app vector-cron-sink "console://?encoding[codec]=text"
```
As with `vector-sink`, the value may be cleared by setting an empty value, and may also be set globally:
```shell
dokku logs:set --global vector-cron-sink "console://?encoding[codec]=text"
```
Setting a cron sink **moves** cron task output rather than copying it. Vector routes each log line to exactly one of the two sinks:
| Configuration | Where cron output goes | Where all other output goes |
|---|---|---|
| `vector-sink` only | `vector-sink` | `vector-sink` |
| `vector-cron-sink` only | `vector-cron-sink` | nowhere |
| both | `vector-cron-sink` | `vector-sink` |
If an app is already shipping to a metered service via `vector-sink`, adding a cron sink will stop cron output from arriving there.
Events on the cron branch have two extra fields added to them, so that they can be used in sink options that support templating:
- `dokku_app`: the name of the app the task belongs to
- `dokku_cron_id`: the cron task ID, as shown by `dokku cron:list`
> [!WARNING]
> Cron task containers are removed as soon as the task exits. Vector attaches to a container after it starts, so output from tasks that finish almost immediately - a bare `echo`, for instance - may be missed. Log shipping should not be relied on as the sole record that a task ran; use an external check for that.
##### Writing cron output to a file on disk
The `file` sink writes to a path within the vector container. The `/var/log/dokku/apps` directory is mounted into that container from the host at the same path, so it is the correct destination for output that should survive on the host.
```shell
dokku logs:set node-js-app vector-cron-sink "file://?path=/var/log/dokku/apps/node-js-app/cron.log&encoding[codec]=text"
```
Because `path` supports templating, `dokku_cron_id` can be used to give each task its own file:
```shell
dokku logs:set node-js-app vector-cron-sink "file://?path=/var/log/dokku/apps/node-js-app/cron-{{ dokku_cron_id }}.log&encoding[codec]=text"
```
Quoting the value is required, both for the `&` separators and for the spaces inside the template.
> [!WARNING]
> Vector drops any event whose templated `path` references a field it cannot resolve. Only `dokku_app` and `dokku_cron_id` are guaranteed to exist on cron events - referencing anything else risks silently discarding log lines.
Vector creates missing parent directories, and buffers writes before flushing. Set `idle_timeout_secs` to shorten that delay for infrequent tasks:
```shell
dokku logs:set node-js-app vector-cron-sink "file://?path=/var/log/dokku/apps/node-js-app/cron.log&encoding[codec]=text&idle_timeout_secs=5"
```
##### Configuring the app label
Dokku labels every app container with `com.dokku.app-name`, and events shipped by vector carry that label as the field `label."com.dokku.app-name"`. Some sinks cannot use a field named that way - Loki label names, for instance, may only contain letters, digits and underscores - so the field can be renamed on the way to the sink via the `app-label-alias` logs property. Specifying a new alias will reload any running vector container.
```shell
dokku logs:set node-js-app app-label-alias "app_name"
```
Events for `node-js-app` then carry `label.app_name` and no longer carry `label."com.dokku.app-name"`.
An alias may be removed by setting an empty value, which will also reload the running vector container.
```shell
dokku logs:set node-js-app app-label-alias
```
Only one alias may be specified on a per-app basis at a given time.
Only one alias may be specified on a per-app basis at a given time. Valid values start with a letter or number and may otherwise contain letters, numbers, underscores, periods and hyphens.
App label aliases can also be specified globally by specifying the `--global` flag to `logs:set` with no app name specified:
```shell
dokku logs:set --global app-label-alias "app-name"
dokku logs:set --global app-label-alias "app_name"
```
As with app-specific label alias settings, the global value may also be cleared by setting no value.
@@ -312,6 +386,10 @@ As with app-specific label alias settings, the global value may also be cleared
dokku logs:set --global app-label-alias
```
An app-specific value takes precedence over the global one, and is applied to that app's events whether they are shipped by the app's own `vector-sink` or by the global one.
The alias only changes the shipped event. Containers are always discovered by the `com.dokku.app-name` label, so changing this property never affects which logs are collected, and a change takes effect on the next vector reload without redeploying the app. Cron events are unaffected in another respect too: `dokku_app` is read from the container label before the rename, so it holds the app name regardless of the configured alias.
## Properties
### Settable properties
@@ -321,8 +399,9 @@ dokku logs:set --global app-label-alias
| Property | Scope | Default | Report flags | Description |
|---|---|---|---|---|
| `app-label-alias` | app + global | `com.dokku.app-name` | `--logs-app-label-alias`, `--logs-global-app-label-alias`, `--logs-computed-app-label-alias` | Docker label key whose value is used to identify the app when shipping logs |
| `app-label-alias` | app + global | `com.dokku.app-name` | `--logs-app-label-alias`, `--logs-global-app-label-alias`, `--logs-computed-app-label-alias` | Field name the app name is shipped under, renamed from `com.dokku.app-name` on the event |
| `max-size` | app + global | `10m` | `--logs-max-size`, `--logs-global-max-size`, `--logs-computed-max-size` | Maximum size of an individual log file before rotation |
| `vector-image` | global only | _parsed from `plugins/logs/Dockerfile`_ | `--logs-global-vector-image`, `--logs-computed-vector-image` | Docker image used to run the vector log-shipper container |
| `vector-networks` | global only | none | `--logs-global-vector-networks`, `--logs-computed-vector-networks` | Comma-separated list of docker networks the vector container is attached to |
| `vector-cron-sink` | app + global | none | `--logs-vector-cron-sink`, `--logs-global-vector-cron-sink`, `--logs-computed-vector-cron-sink` | DSN-style sink configuration for scheduled cron task output; when set, cron output is routed here instead of to `vector-sink` |
| `vector-sink` | app + global | none | `--logs-vector-sink`, `--logs-global-vector-sink`, `--logs-computed-vector-sink` | DSN-style sink configuration for vector (e.g. `console://` or `loki://...`) |

View File

@@ -4,22 +4,29 @@
> New as of 0.33.0
```
scheduler-k3s:annotations:set <app|--global> <property> (<value>) [--process-type PROCESS_TYPE] <--resource-type RESOURCE_TYPE>, Set or clear an annotation for a given app/process-type/resource-type combination
scheduler-k3s:autoscaling-auth:set <app|--global> <trigger> [<--metadata key=value>...], Set or clear a scheduler-k3s autoscaling keda trigger authentication resource for an app
scheduler-k3s:autoscaling-auth:report <app|--global> [--format stdout|json] [--include-metadata] # Displays a scheduler-k3s autoscaling auth report for an app
scheduler-k3s:cluster:add [ssh://user@host:port] # Adds a server node to a Dokku-managed cluster
scheduler-k3s:cluster:list # Lists all nodes in a Dokku-managed cluster
scheduler-k3s:cluster:remove [node-id] # Removes client node to a Dokku-managed cluster
scheduler-k3s:ensure-charts # Ensures the k3s charts are installed
scheduler-k3s:initialize # Initializes a cluster
scheduler-k3s:annotations:set <app|--global> <property> (<value>) [--process-type PROCESS_TYPE] <--resource-type RESOURCE_TYPE> # Set or clear an annotation for a given app/process-type/resource-type combination
scheduler-k3s:annotations:report [<app>|--global] [--format stdout|json] [--process-type PROCESS_TYPE] [--resource-type RESOURCE_TYPE] # Displays a scheduler-k3s annotations report for one or more apps
scheduler-k3s:autoscaling-auth:set <app|--global> <trigger> [<--metadata key=value>...] # Set or clear a scheduler-k3s autoscaling keda trigger authentication resource for an app
scheduler-k3s:autoscaling-auth:report [<app>|--global] [--format stdout|json] [--include-metadata] # Displays a scheduler-k3s autoscaling auth report for one or more apps
scheduler-k3s:charts:report [<chart>] [--format stdout|json] # Displays a scheduler-k3s chart override report
scheduler-k3s:charts:set <chart-name.property> (<value>) # Set or clear a chart-specific helm value
scheduler-k3s:cluster:add [--profile PROFILE] [--role ROLE] [--insecure-allow-unknown-hosts] [--server-ip SERVER_IP] [--taint-scheduling] [--kubelet-args KUBELET_ARGS] <ssh://user@host:port> # Adds a server node to a Dokku-managed cluster
scheduler-k3s:cluster:list [--format json|stdout] # Lists all nodes in a Dokku-managed cluster
scheduler-k3s:cluster:remove [node-id] # Removes client node to a Dokku-managed cluster
scheduler-k3s:ensure-charts # Ensures the k3s charts are installed
scheduler-k3s:initialize [--server-ip SERVER_IP] [--taint-scheduling] [--kubelet-args KUBELET_ARGS] # Initializes a cluster
scheduler-k3s:labels:set <app|--global> <property> (<value>) [--process-type PROCESS_TYPE] <--resource-type RESOURCE_TYPE> # Set or clear a label for a given app/process-type/resource-type combination
scheduler-k3s:profiles:add <profile> [--role ROLE] [--insecure-allow-unknown-hosts] [--taint-scheduling] [--kubelet-args KUBELET_ARGS] Adds a node profile to the k3s cluster
scheduler-k3s:profiles:list [--format json|stdout] # Lists all node profiles in the k3s cluster
scheduler-k3s:profiles:remove <profile> # Removes a node profile from the k3s cluster
scheduler-k3s:report [<app>] [<flag>] # Displays a scheduler-k3s report for one or more apps
scheduler-k3s:set [<app>|--global] <key> (<value>) # Set or clear a scheduler-k3s property for an app or the scheduler
scheduler-k3s:show-kubeconfig # Displays the kubeconfig for remote usage
scheduler-k3s:uninstall # Uninstalls k3s from the Dokku server
scheduler-k3s:labels:report [<app>|--global] [--format stdout|json] [--process-type PROCESS_TYPE] [--resource-type RESOURCE_TYPE] # Displays a scheduler-k3s labels report for one or more apps
scheduler-k3s:node-sysctls:set <sysctl> (<value>) [--global|--profile PROFILE] # Set or clear a node-level kernel sysctl for unprofiled nodes or a single node profile
scheduler-k3s:node-sysctls:report [--format stdout|json] # Displays the node-level kernel sysctls applied to each scope
scheduler-k3s:preview <app> [--context N] [--show-secrets] [--show-secrets-decoded] # Displays a diff between the current and next deployment for an app
scheduler-k3s:profiles:add <profile> [--role ROLE] [--insecure-allow-unknown-hosts] [--taint-scheduling] [--kubelet-args KUBELET_ARGS] # Adds a node profile to the k3s cluster
scheduler-k3s:profiles:list [--format json|stdout] # Lists all node profiles in the k3s cluster
scheduler-k3s:profiles:remove <profile> # Removes a node profile from the k3s cluster
scheduler-k3s:report [<app>|--global] [--format stdout|json] [<flag>] # Displays a scheduler-k3s report for one or more apps
scheduler-k3s:set <app|--global> <property> (<value>) # Set or clear a scheduler-k3s property for an app or globally
scheduler-k3s:show-kubeconfig # Displays the kubeconfig for remote usage
scheduler-k3s:uninstall # Uninstalls k3s from the Dokku server
```
> [!NOTE]
@@ -73,6 +80,20 @@ Dokku can also use Traefik on cluster initialization via the [Traefik's CRDs](ht
dokku scheduler-k3s:initialize --ingress-class traefik
```
Kubelet flags for the initial server node can be supplied by passing `--kubelet-args` with a comma-separated `key=value` list. This is the only way to configure the kubelet on the node created by `scheduler-k3s:initialize`, as that node never passes through `scheduler-k3s:cluster:add`.
```shell
dokku scheduler-k3s:initialize \
--kubelet-args allowed-unsafe-sysctls=net.ipv6.conf.all.disable_ipv6
```
Multiple kubelet arguments can be specified in the same call by separating them with commas.
```shell
dokku scheduler-k3s:initialize \
--kubelet-args allowed-unsafe-sysctls=net.ipv6.conf.all.disable_ipv6,max-pods=150
```
### Adding nodes to the cluster
> [!WARNING]
@@ -195,6 +216,21 @@ dokku scheduler-k3s:profiles:remove edge-workers
Removal only deletes the stored definition; nodes that already joined the cluster keep their existing configuration.
#### The node profile label
When a node joins via `scheduler-k3s:cluster:add --profile <name>`, Dokku labels it with `dokku.com/node-profile=<name>`. This makes a profile selectable after the fact, whether via `kubectl`, a `nodeSelector`, or a node affinity rule.
```shell
kubectl get nodes -L dokku.com/node-profile
```
Nodes added without `--profile` are not labeled, as an empty label value would be indistinguishable from a profile literally named the empty string.
Two limits are worth knowing before relying on this label:
- The server node never carries it. That node is created by `scheduler-k3s:initialize` and never passes through `scheduler-k3s:cluster:add`, so no profile is ever associated with it.
- Nodes that joined before this label existed are not backfilled. Use `kubectl label node <node> dokku.com/node-profile=<name>` to set it on an existing node.
### Changing deployment settings
The k3s plugin provides a number of settings that can be used to managed deployments on a per-app basis. The following table outlines ones not covered elsewhere:
@@ -232,6 +268,74 @@ The global default value may be set by passing an empty value for the option.
dokku scheduler-k3s:set --global deploy-timeout
```
### Restarting apps
A `ps:restart` re-renders the app's Helm chart from its current configuration and upgrades the release, which is how configuration changes are picked up. Pods cycle because each Deployment's pod template carries an `app.kubernetes.io/version` annotation that changes on restart.
A single process type may be targeted, in which case only that process type's pods are replaced. The rest of the release is still upgraded so configuration converges everywhere, but the untargeted Deployments keep their existing annotation and are left running:
```shell
dokku ps:restart node-js-app web
```
The app image does not need to be present on the Dokku host. Kubernetes pulls it from the registry, so a host that has reaped its local copy - as the `registry` plugin does on its own once an app has been deployed a number of times - can still restart, scale, and run one-off commands against the app. The builder type and working directory needed to render the chart are read back from the app's current Helm release when the image is unavailable locally.
There is one exception. An `app.json` with a `scripts.dokku.postdeploy` task runs that task in a container on the Dokku host rather than in the cluster, and so does require the image locally. Apps without a postdeploy task are unaffected.
### Displaying the scheduler report
Configured properties can be inspected with the `scheduler-k3s:report` command. Without arguments, it iterates every app. Passing an app name scopes the report to that app, while `--global` reports the scheduler-wide properties on their own:
```shell
dokku scheduler-k3s:report
dokku scheduler-k3s:report node-js-app
dokku scheduler-k3s:report --global
```
The output can be emitted as JSON for programmatic consumption:
```shell
dokku scheduler-k3s:report --global --format json
```
A single value can also be read directly by passing its report flag, as listed in the [settable properties](#settable-properties) table:
```shell
dokku scheduler-k3s:report node-js-app --scheduler-k3s-computed-deploy-timeout
```
### Previewing deployment changes
Before triggering a deploy, the `scheduler-k3s:preview` command can be used to display a unified diff between the manifests currently stored in the live Helm release for an app and the manifests that the next deploy would roll out:
```shell
dokku scheduler-k3s:preview node-js-app
```
A clean redeploy with no property changes produces no output. After modifying a property that affects the main app chart (for example `dokku resource:limit --memory 256m node-js-app`), the command shows the unified diff for each changed resource. For an app that has never been deployed, the entire proposed manifest is rendered as added lines.
By default each change is shown with 3 lines of surrounding context, git-diff style. The `--context` flag overrides this; pass `-1` to render the full resource around every change:
```shell
dokku scheduler-k3s:preview node-js-app --context 0
dokku scheduler-k3s:preview node-js-app --context -1
```
By default any `kind: Secret` resources have their `data` values redacted so secret bytes never appear in terminal scrollback or CI logs. Two flags adjust this behavior:
```shell
dokku scheduler-k3s:preview node-js-app --show-secrets
dokku scheduler-k3s:preview node-js-app --show-secrets-decoded
```
`--show-secrets` keeps the raw base64-encoded values, and `--show-secrets-decoded` renders them base64-decoded. In current dokku, the only Secret objects in the main app chart come from KEDA autoscaling auth resources configured via [`scheduler-k3s:autoscaling-auth:set`](#workload-autoscaling-authentication); for apps without autoscaling auth, these flags are no-ops.
> [!IMPORTANT]
> The preview only covers the main app helm release (the release named after the app). Dokku installs three auxiliary helm releases per app for config-var storage, image-pull credentials, and TLS certificates, and changes to those releases do **not** appear in this preview. In particular, a `dokku config:set` change followed by `scheduler-k3s:preview` will show no diff because the new config-var value lives in the separate `config-<app>` helm release.
> [!NOTE]
> Helm renders the proposed manifest using a client-side dry-run. The `lookup` template function returns empty values in this mode, so charts overridden via `scheduler-k3s:charts:set` that depend on `lookup` may render differently here than at actual deploy time. Dokku's bundled chart templates do not use `lookup`.
### Exposing services on the network
Dokku will automatically expose the `web` process as a Kubernetes Service, with all others being treated as background processes. In some cases, it may be useful to have other processes exposed as Kubernetes Service objects so as to segregate internal http endpoints from public http endpoints. This can be done by modifying the `app.json` Formation entry for your process type.
@@ -253,6 +357,20 @@ In the above example, the `internal-web` process is exposed as a service. The `P
> [!NOTE]
> It is not possible to modify the port mapping, nor is it possible to assign domains or SSL to a non-web process.
### Wildcard domains
Both the `nginx` and `traefik` ingress classes route wildcard domains. Add the wildcard as a domain on the app:
```shell
dokku domains:add node-js-app '*.node-js-app.com'
```
A wildcard matches exactly one label, matching DNS itself, so `*.node-js-app.com` covers `api.node-js-app.com` but not `node-js-app.com` or `api.staging.node-js-app.com`. Add the apex as a separate domain if it should also be served.
An exact domain always takes precedence over a wildcard, including across apps. If one app serves `*.node-js-app.com` and another serves `api.node-js-app.com`, requests for `api.node-js-app.com` are routed to the second app.
Only the leading label may be wildcarded. A domain such as `api.*.node-js-app.com` is treated as a literal hostname and will not match anything.
### SSL Certificates
#### Enabling letsencrypt integration
@@ -269,6 +387,30 @@ dokku scheduler-k3s:set --global letsencrypt-email-stag automated@dokku.sh
After enabling and rebuilding, all apps with an `http:80` port mapping will have a corresponding `https:443` added and ssl will be automatically enabled. All http requests will then be redirected to https.
#### Customizing the letsencrypt email per app
The `letsencrypt-email-prod` and `letsencrypt-email-stag` properties can also be set per app, overriding the global value for that app. This is useful when different apps should register their certificates under different contact emails.
```shell
dokku scheduler-k3s:set node-js-app letsencrypt-email-prod team@node-js-app.com
```
The value resolves in two steps: the app's `letsencrypt-server` selects which server (`prod` or `staging`) is used, and the matching `letsencrypt-email-<server>` property is then resolved as the app-level value, falling back to the global value. Because the two emails are per-server, an app-level `letsencrypt-email-stag` only takes effect once the app's `letsencrypt-server` is set to `staging`.
When an app sets its own email for the selected server, Dokku renders a namespaced cert-manager `Issuer` into the app's own release using that email instead of pointing the app at the shared global `ClusterIssuer`. Apps without an app-level email continue to use the shared `ClusterIssuer` with the global email.
The default value may be set by passing an empty value for the option, which falls the app back to the global value:
```shell
dokku scheduler-k3s:set node-js-app letsencrypt-email-prod
```
The computed value in effect for an app can be inspected via the report command:
```shell
dokku scheduler-k3s:report node-js-app --scheduler-k3s-computed-letsencrypt-email-prod
```
#### Customizing the letsencrypt server
The letsencrypt integration is set to the production letsencrypt server by default. This can be changed on an app-level by setting the `letsencrypt-server` property with the `scheduler-k3s:set` command
@@ -295,7 +437,7 @@ The default value may be set by passing an empty value for the option.
dokku scheduler-k3s:set --global letsencrypt-server staging
```
Letsencrypt can be completely disabled for a given app by setting the `letsencrypt-server` to `false`
Automatic certificate issuance can be completely disabled for a given app by setting the `letsencrypt-server` to `false`. This is the single off switch for the app, and also disables a [manually managed issuer](#using-a-manually-managed-cert-manager-issuer).
```shell
dokku scheduler-k3s:set node-js-app letsencrypt-server false
@@ -307,6 +449,72 @@ The server can also be disabled globally, and then conditionally enabled on a pe
dokku scheduler-k3s:set --global letsencrypt-server false
```
Values are validated when the property is set, so a typo fails immediately rather than breaking the next deploy. The valid values are `prod`, `production`, `stag`, `staging`, and `false`.
#### Using a manually managed cert-manager issuer
Dokku's built-in letsencrypt integration uses an `http01` solver, which cannot issue wildcard certificates and cannot satisfy providers that require `dns01`. For those cases, create a cert-manager `Issuer` or `ClusterIssuer` yourself and point an app at it with the `cert-issuer-name` property.
```shell
dokku scheduler-k3s:set node-js-app cert-issuer-name acme-dns
```
Dokku does not create, modify, or delete the issuer - it only references it from the app's generated `Certificate`. Any cert-manager issuer works, including non-ACME ones such as `selfSigned`, `ca`, or `vault`.
The issuer kind defaults to `ClusterIssuer`. To reference a namespaced `Issuer`, set the `cert-issuer-kind` property:
```shell
dokku scheduler-k3s:set node-js-app cert-issuer-kind Issuer
```
> [!WARNING]
> A namespaced `Issuer` must exist in the same namespace as the app, as configured by the `namespace` property. cert-manager cannot reference an `Issuer` across namespaces.
Unlike the letsencrypt integration, no email property is required - setting `cert-issuer-name` is itself what enables https for the app. Certificates are requested for every domain attached to the app.
Both properties can also be set globally, which enables https for every app that has domains, no imported certificate, and no `letsencrypt-server false`:
```shell
dokku scheduler-k3s:set --global cert-issuer-name acme-dns
```
Certificate sources are resolved in the following order:
1. A certificate imported via the `certs` plugin.
2. `letsencrypt-server` set to `false`, which disables issuance entirely.
3. `cert-issuer-name`, resolved app-first and then globally.
4. The built-in letsencrypt integration.
Because an empty app-level property falls back to the global value, an app cannot return to the built-in letsencrypt integration by unsetting `cert-issuer-name` while a global value is configured. Set the app's `cert-issuer-name` to the reserved value `false` instead:
```shell
dokku scheduler-k3s:set node-js-app cert-issuer-name false
```
As a consequence, an issuer literally named `false` cannot be referenced.
The default value may be set by passing an empty value for the option, which falls the app back to the global value:
```shell
dokku scheduler-k3s:set node-js-app cert-issuer-name
```
If the named issuer does not exist in the cluster, Dokku emits a warning before the build starts. The warning never blocks a deploy, since the issuer may be managed independently and applied later. When a certificate fails to issue, inspect it directly:
```shell
kubectl describe certificate node-js-app-web -n default
```
##### Wildcard certificates
A `dns01` issuer can issue wildcard certificates. Add the wildcard as a domain on the app, and it will be included in the generated `Certificate`:
```shell
dokku domains:add node-js-app '*.node-js-app.com'
```
See [wildcard domains](#wildcard-domains) for how a wildcard is matched against incoming requests.
#### Using imported SSL certificates
SSL certificates imported via the `certs` plugin can be used with the k3s scheduler. When a certificate is imported, it is automatically synced to Kubernetes as a TLS secret and will be used for the app's ingress configuration.
@@ -321,9 +529,9 @@ When a certificate is imported:
- A Kubernetes TLS secret named `tls-<app-name>` is created in the app's namespace
- The ingress configuration is updated to use the imported certificate
- Automatic Let's Encrypt certificate generation is disabled for the app
- Automatic certificate generation is disabled for the app
Imported certificates take precedence over Let's Encrypt certificates. If you have both an imported certificate and Let's Encrypt configured, the imported certificate will be used.
Imported certificates take precedence over both Let's Encrypt and a [manually managed issuer](#using-a-manually-managed-cert-manager-issuer). If you have an imported certificate alongside either of those, the imported certificate will be used.
To remove an imported certificate:
@@ -372,6 +580,8 @@ The following resource types are supported:
- `traefik_ingressroute`
- `traefik_middleware`
Annotation keys may contain `/` (e.g. Kubernetes-style keys such as `prometheus.io/scrape`) and values may span multiple lines; both are preserved verbatim.
A `ps:restart` is required after setting annotations in order to have them apply to running resources.
#### Removing an annotation
@@ -385,6 +595,35 @@ dokku scheduler-k3s:annotations:set node-js-app annotation.key --resource-type d
A `ps:restart` is required after removing annotations in order to remove them from running resources.
#### Displaying annotations
Configured annotations can be inspected with the `scheduler-k3s:annotations:report` command. Without arguments, it iterates every app and prints all annotations. Passing an app name (or `--global`) scopes the report:
```shell
dokku scheduler-k3s:annotations:report
dokku scheduler-k3s:annotations:report node-js-app
dokku scheduler-k3s:annotations:report --global
```
`--process-type` and `--resource-type` flags narrow the output to a specific scope, matching the flags accepted by `scheduler-k3s:annotations:set`:
```shell
dokku scheduler-k3s:annotations:report node-js-app --resource-type deployment
dokku scheduler-k3s:annotations:report node-js-app --process-type web --resource-type deployment
```
JSON output emits flat keys of the form `{process_type}.{resource_type}.{annotation_key}`. The literal `--global` process type is rendered as `global` to keep keys free of leading dashes:
```shell
dokku scheduler-k3s:annotations:report node-js-app --format json
```
A single value can also be read directly with a flag of the form `--scheduler-k3s-annotations.{process_type}.{resource_type}.{annotation_key}`:
```shell
dokku scheduler-k3s:annotations:report node-js-app --scheduler-k3s-annotations.global.deployment.annotation.key
```
#### Setting Labels
Dokku injects certain labels into each created resource by default, but it may be necessary to inject others for tighter integration with third-party tools. The `scheduler-k3s:labels:set` command can be used to perform this task. The command takes an app name and a required `--resource-type` flag.
@@ -413,6 +652,8 @@ The following resource types are supported:
- `traefik_ingressroute`
- `traefik_middleware`
Label keys may contain `/` (e.g. Kubernetes-style keys such as `app.kubernetes.io/part-of`) and values may span multiple lines; both are preserved verbatim.
A `ps:restart` is required after setting labels in order to have them apply to running resources.
#### Removing a label
@@ -426,6 +667,20 @@ dokku scheduler-k3s:labels:set node-js-app label.key --resource-type deployment
A `ps:restart` is required after removing labels in order to remove them from running resources.
#### Displaying labels
Configured labels can be inspected with the `scheduler-k3s:labels:report` command. The surface mirrors `scheduler-k3s:annotations:report`:
```shell
dokku scheduler-k3s:labels:report
dokku scheduler-k3s:labels:report node-js-app
dokku scheduler-k3s:labels:report --global
dokku scheduler-k3s:labels:report node-js-app --resource-type deployment
dokku scheduler-k3s:labels:report node-js-app --process-type web --resource-type deployment
dokku scheduler-k3s:labels:report node-js-app --format json
dokku scheduler-k3s:labels:report node-js-app --scheduler-k3s-labels.global.deployment.label.key
```
### Autoscaling
#### Workload Autoscaling
@@ -564,15 +819,17 @@ dokku scheduler-k3s:autoscaling-auth:set $APP $TRIGGER_TYPE
##### Displaying an Authentication Resource report
To see a list of authentication resources managed by Dokku, run the `scheduler-k3s:autoscaling-auth:report` command.
To see a list of authentication resources managed by Dokku, run the `scheduler-k3s:autoscaling-auth:report` command. Without arguments, the report iterates every app; passing an app name (or `--global`) scopes the report:
```shell
dokku scheduler-k3s:autoscaling-auth:report
dokku scheduler-k3s:autoscaling-auth:report node-js-app
dokku scheduler-k3s:autoscaling-auth:report --global
```
```
====> $APP autoscaling-auth report
datadog: configured
====> node-js-app autoscaling-auth information
Datadog: configured
```
By default, the report will not display configured metadata - making it safe to include in Dokku report output. To include metadata and their values, add the `--include-metadata` flag:
@@ -582,13 +839,93 @@ dokku scheduler-k3s:autoscaling-auth:report node-js-app --include-metadata
```
```
====> node-js-app autoscaling-auth report
====> node-js-app autoscaling-auth information
Datadog: configured
Datadog apiKey: 1234567890
Datadog appKey: asdfghjkl
Datadog datadogSite: us5.datadoghq.com
```
JSON output emits flat keys of the form `{trigger}.{metadata_key}` and includes the actual metadata values so export tools can reconstruct the configured state:
```shell
dokku scheduler-k3s:autoscaling-auth:report node-js-app --format json
```
A single configured metadata key can also be queried with a flag of the form `--scheduler-k3s-autoscaling-auth.{trigger}.{metadata_key}`. The returned value is masked in the same way as stdout output; use `--format json` to read the actual value:
```shell
dokku scheduler-k3s:autoscaling-auth:report node-js-app --scheduler-k3s-autoscaling-auth.datadog.apiKey
```
### Setting kernel sysctls
Kernel sysctls fall into two categories, and which one a sysctl belongs to determines how it must be set.
The kernel maintains a per-namespace copy of `net.*` (network namespace) as well as `kernel.shm*`, `kernel.msg*`, `kernel.sem`, and `fs.mqueue.*` (IPC namespace). These can be set on a single app's pods. Every other sysctl - including all of `vm.*`, and therefore `vm.max_map_count` - holds a single value shared by the entire machine, so it cannot be scoped to a pod and must be applied to the node itself.
#### Namespaced sysctls
Namespaced sysctls are set with the `docker-options` plugin, and are translated into the pod's `securityContext.sysctls`. A `ps:restart` is required to apply them.
```shell
dokku docker-options:add node-js-app deploy "--sysctl net.ipv4.ip_unprivileged_port_start=1024"
```
Passing a non-namespaced sysctl this way fails the deploy rather than silently dropping the value, since it provably cannot take effect within a pod. Note this differs from the `docker-local` scheduler, where such an option is passed straight through to `docker run`.
Kubernetes further splits namespaced sysctls into a *safe* list that any pod may set, and everything else. A sysctl outside the safe list - `net.core.somaxconn`, for example - is rejected at pod admission unless the node's kubelet was started with a matching `allowed-unsafe-sysctls` value, which can be supplied at cluster initialization or when joining a node.
```shell
dokku scheduler-k3s:initialize --kubelet-args allowed-unsafe-sysctls=net.core.somaxconn
```
Dokku does not enforce the safe list itself, as its membership changes between Kubernetes releases. Only the namespaced/non-namespaced distinction, which is a property of the kernel, is validated.
#### Non-namespaced sysctls
Non-namespaced sysctls are a property of the node, not of any app, and are managed with the `node-sysctls:set` command. Dokku applies them via a privileged DaemonSet, so they reach every node without being told which nodes exist, cover nodes joined later, and are reapplied after a node reboots.
```shell
dokku scheduler-k3s:node-sysctls:set --global vm.max_map_count 262144
```
Omitting the value clears it.
```shell
dokku scheduler-k3s:node-sysctls:set --global vm.max_map_count
```
Clearing a sysctl stops Dokku managing it, but does not restore whatever the node had before. The last value written stays in place until that node reboots, which is how `sysctl -w` behaves everywhere else.
Sysctls can also be scoped to a [node profile](#node-profiles) with `--profile`, which applies them only to nodes joined with that profile.
```shell
dokku scheduler-k3s:node-sysctls:set --profile edge-workers vm.max_map_count 524288
```
A profile scope inherits everything set globally and overrides it on conflict, so each node is covered by exactly one DaemonSet and no two ever write the same value. Note that the server node created by `scheduler-k3s:initialize` never carries a profile label, so only globally-scoped sysctls reach it.
Use `node-sysctls:report` to see the resolved set for every scope.
```shell
dokku scheduler-k3s:node-sysctls:report
```
```shell
dokku scheduler-k3s:node-sysctls:report --format json
```
The DaemonSet pulls `busybox` and `registry.k8s.io/pause` by default. On an air-gapped cluster or one behind a registry mirror, point them elsewhere:
```shell
dokku scheduler-k3s:set --global node-sysctls-image registry.internal/busybox:1.36
```
```shell
dokku scheduler-k3s:set --global node-sysctls-pause-image registry.internal/pause:3.9
```
### Integrating Kustomize
Dokku supports integration with [Kustomize](https://kustomize.io/) to further customize the generated helm charts for app deployments. For example, a `config/kustomize/kustomization.yaml` file with the following contents will override the scale for each process deployed to `3`:
@@ -658,21 +995,34 @@ The default value for the `kube-context` is an empty string, and will result in
### Customizing Helm Chart Properties
Dokku includes a number of helm charts by default with settings that are optimized for Dokku. That said, it may be useful to further customize the charts for a given environment. Users can customize which charts are installed by setting properties prefixed with `chart.$CHART_NAME.` with the `--global` flag.
Dokku includes a number of helm charts by default with settings that are optimized for Dokku. That said, it may be useful to further customize the charts for a given environment. Chart overrides are managed via the `scheduler-k3s:charts:set` command, which takes a `<chart-name>.<property>` argument and a value. Chart overrides are always global because helm charts are not managed on a per-app basis.
```shell
dokku scheduler-k3s:set --global chart.cert-manager.version 1.13.3
dokku scheduler-k3s:charts:set cert-manager.version 1.13.3
```
> [!NOTE]
> Properties follow dot-notation, and are expanded according to Helm's internal logic. See the [Helm documentation](https://helm.sh/docs/helm/helm_install/#helm-install) for `helm install` for further details.
To unset a chart property, omit the value from the `scheduler-k3s:set` call:
Property names may contain `/` (e.g. for Kubernetes-style annotation keys such as `service.annotations.prometheus.io/scrape`) and values may span multiple lines; both are preserved verbatim.
To unset a chart property, omit the value from the `scheduler-k3s:charts:set` call:
```shell
dokku scheduler-k3s:set --global chart.cert-manager.version
dokku scheduler-k3s:charts:set cert-manager.version
```
Configured chart overrides can be inspected with the `scheduler-k3s:charts:report` command. Without an argument, it lists every chart known to Dokku along with any configured overrides; passing a chart name scopes the report to that chart:
```shell
dokku scheduler-k3s:charts:report
dokku scheduler-k3s:charts:report cert-manager
dokku scheduler-k3s:charts:report --format json
```
> [!NOTE]
> The legacy form `dokku scheduler-k3s:set --global chart.<chart>.<property> <value>` continues to work but is deprecated and will be removed in a future major release. Migrate to `scheduler-k3s:charts:set` instead.
A `scheduler-k3s:ensure-charts` command with the `--force` flag is required after changing any chart properties in order to have them apply. This will install all charts, not just the ones that have changed.
```shell
@@ -702,7 +1052,7 @@ dokku storage:wait demo-data
git push dokku master
```
For a hostPath-backed PV (no StorageClass), pass `<path>` as the second positional argument and omit `--storage-class-name`. The plugin renders both the PV and the PVC into the entry's helm release. The `--reclaim-policy` flag (`Retain` or `Delete`) controls whether the underlying PV survives `storage:destroy`. Annotations and labels on `storage:create` / `storage:set` propagate to both the PVC and the PV so backup tools (Velero, Longhorn snapshots) can find them.
For a hostPath-backed PV (no StorageClass), pass `<path>` as the second positional argument and omit `--storage-class-name`. The plugin renders both the PV and the PVC into the entry's helm release. The `--reclaim-policy` flag (`Retain` or `Delete`) controls whether the underlying PV survives `storage:destroy`. Annotations and labels set via `storage:annotations:set` and `storage:labels:set` propagate to both the PVC and the PV so backup tools (Velero, Longhorn snapshots) can find them.
The legacy `storage:mount <app> <host>:<container>` colon form is rejected on k3s apps; create a named entry instead. See [Persistent Storage](/docs/advanced-usage/persistent-storage.md) for the full command reference.
@@ -730,6 +1080,7 @@ This plugin implements various functionality through `plugn` triggers to integra
- `--cap-add`
- `--cap-drop`
- `--privileged`
- `--sysctl` (namespaced sysctls only, see [Setting kernel sysctls](#setting-kernel-sysctls))
- `cron`
- `enter`
- `deploy`
@@ -742,6 +1093,8 @@ This plugin implements various functionality through `plugn` triggers to integra
- Properties set by the `nginx` plugin will be respected, either by turning them into annotations or creating a custom server/location snippet that the `ingress-nginx` project can use. A `ps:restart` after changing any nginx properties is required in order to have them apply.
- The `nginx:access-logs` and `nginx:error-logs` commands will fetch logs from one running `ingress-nginx` pod.
- The `nginx:show-config` command will retrieve any `server` blocks associated with a domain attached to the app from one running `ingress-nginx` pod.
- `ps:restart`
- Supports targeting a single process type, see [Restarting apps](#restarting-apps)
- `ps:stop`
- `run`
- The `scheduler-post-run` trigger is not always triggered
@@ -776,6 +1129,24 @@ dokku scheduler-k3s:ensure-charts --charts vector
Please see the [vector logs documentation](/docs/deployment/logs.md#configuring-a-log-sink) for more information on specifying vector sinks.
#### Shipping cron task logs
The global `vector-cron-sink` property is also respected. When set, logs from cron task pods are routed to that sink instead of the sink configured for everything else, matching the behavior described in the [cron task log sink documentation](/docs/deployment/logs.md#configuring-a-cron-task-log-sink).
```shell
dokku logs:set --global vector-cron-sink "console://?encoding[codec]=text"
dokku scheduler-k3s:ensure-charts --charts vector
```
As with `vector-sink`, only the global property is respected - a per-app `vector-cron-sink` has no effect on the `k3s` scheduler.
Cron events carry the same `dokku_app` and `dokku_cron_id` fields as they do on the `docker-local` scheduler, so sink configuration referencing them is portable between the two.
Two differences are worth noting:
- Templated values must be base64 encoded. Sink values containing `{{ }}` are interpreted by Helm at chart install time rather than by Vector, so the `base64enc:` form documented under [log sink DSN format](/docs/deployment/logs.md#log-sink-dsn-format) is required.
- The `file` sink is not useful here. Vector runs as a DaemonSet agent, so a file path resolves to whichever node the agent is running on rather than to durable shared storage. Use a network sink and reference `dokku_cron_id` as a field instead of as a path component.
### Supported Resource Management Properties
The `k3s` scheduler supports a minimal list of resource _limits_ and _reservations_:
@@ -797,18 +1168,22 @@ If unspecified for any task, the default reservation will be `.1` CPU and `128Mi
| Property | Scope | Default | Report flags | Description |
|---|---|---|---|---|
| `cert-issuer-kind` | app + global | `ClusterIssuer` | `--scheduler-k3s-cert-issuer-kind`, `--scheduler-k3s-global-cert-issuer-kind`, `--scheduler-k3s-computed-cert-issuer-kind` | Kind of the manually managed cert-manager issuer referenced by `cert-issuer-name`, either `Issuer` or `ClusterIssuer` |
| `cert-issuer-name` | app + global | none | `--scheduler-k3s-cert-issuer-name`, `--scheduler-k3s-global-cert-issuer-name`, `--scheduler-k3s-computed-cert-issuer-name` | Name of a manually managed cert-manager issuer to request certificates from, taking precedence over the letsencrypt integration. Set to `false` to opt an app out of a global value |
| `deploy-timeout` | app + global | `300s` | `--scheduler-k3s-deploy-timeout`, `--scheduler-k3s-global-deploy-timeout`, `--scheduler-k3s-computed-deploy-timeout` | Timeout for a single helm install/upgrade cycle |
| `image-pull-secrets` | app + global | none | `--scheduler-k3s-image-pull-secrets`, `--scheduler-k3s-global-image-pull-secrets`, `--scheduler-k3s-computed-image-pull-secrets` | Comma-separated list of Kubernetes secret names used to pull private images |
| `ingress-class` | global only | `nginx` | `--scheduler-k3s-global-ingress-class`, `--scheduler-k3s-computed-ingress-class` | IngressClass name used for app ingresses (e.g. `nginx`, `traefik`) |
| `kube-context` | global only | none | `--scheduler-k3s-global-kube-context`, `--scheduler-k3s-computed-kube-context` | Kube context name used by helm and kubectl invocations |
| `kubeconfig-path` | global only | `/etc/rancher/k3s/k3s.yaml` | `--scheduler-k3s-global-kubeconfig-path`, `--scheduler-k3s-computed-kubeconfig-path` | Filesystem path to the kubeconfig used to talk to the cluster |
| `kustomize-root-path` | app + global | `config/kustomize` | `--scheduler-k3s-kustomize-root-path`, `--scheduler-k3s-global-kustomize-root-path`, `--scheduler-k3s-computed-kustomize-root-path` | Path within the app to a kustomize root applied after the helm install |
| `letsencrypt-email-prod` | global only | none | `--scheduler-k3s-global-letsencrypt-email-prod`, `--scheduler-k3s-computed-letsencrypt-email-prod` | Contact email for the production cert-manager ClusterIssuer |
| `letsencrypt-email-stag` | global only | none | `--scheduler-k3s-global-letsencrypt-email-stag`, `--scheduler-k3s-computed-letsencrypt-email-stag` | Contact email for the staging cert-manager ClusterIssuer |
| `letsencrypt-server` | app + global | `prod` | `--scheduler-k3s-letsencrypt-server`, `--scheduler-k3s-global-letsencrypt-server`, `--scheduler-k3s-computed-letsencrypt-server` | ACME directory (`prod` or `staging`) used for app certificates |
| `letsencrypt-email-prod` | app + global | none | `--scheduler-k3s-letsencrypt-email-prod`, `--scheduler-k3s-global-letsencrypt-email-prod`, `--scheduler-k3s-computed-letsencrypt-email-prod` | Contact email for production certificates. App-level values render a per-app namespaced Issuer; otherwise the shared production ClusterIssuer is used |
| `letsencrypt-email-stag` | app + global | none | `--scheduler-k3s-letsencrypt-email-stag`, `--scheduler-k3s-global-letsencrypt-email-stag`, `--scheduler-k3s-computed-letsencrypt-email-stag` | Contact email for staging certificates. App-level values render a per-app namespaced Issuer; otherwise the shared staging ClusterIssuer is used |
| `letsencrypt-server` | app + global | `prod` | `--scheduler-k3s-letsencrypt-server`, `--scheduler-k3s-global-letsencrypt-server`, `--scheduler-k3s-computed-letsencrypt-server` | ACME directory (`prod` or `staging`) used for app certificates, or `false` to disable all automatic certificate issuance |
| `namespace` | app + global | `default` | `--scheduler-k3s-namespace`, `--scheduler-k3s-global-namespace`, `--scheduler-k3s-computed-namespace` | Kubernetes namespace into which the app's resources are installed |
| `network-interface` | global only | `eth0` | `--scheduler-k3s-global-network-interface`, `--scheduler-k3s-computed-network-interface` | Host network interface used by k3s |
| `node-sysctls-image` | global only | `busybox:1.36` | `--scheduler-k3s-global-node-sysctls-image` | Image used to apply node-level sysctls, override for air-gapped clusters |
| `node-sysctls-pause-image` | global only | `registry.k8s.io/pause:3.9` | `--scheduler-k3s-global-node-sysctls-pause-image` | Image keeping the node sysctls daemonset pods running |
| `rollback-on-failure` | app + global | `false` | `--scheduler-k3s-rollback-on-failure`, `--scheduler-k3s-global-rollback-on-failure`, `--scheduler-k3s-computed-rollback-on-failure` | When `true`, helm rolls back the release if a deploy fails |
| `shm-size` | app + global | none | `--scheduler-k3s-shm-size`, `--scheduler-k3s-global-shm-size`, `--scheduler-k3s-computed-shm-size` | `/dev/shm` size override applied to app containers |
| `token` | global only | none | `--scheduler-k3s-global-token` (masked as `*******` in default stdout output; the raw value is returned when queried via `--format json` or when this flag is requested explicitly) | Cluster join token used by `scheduler-k3s:cluster-add` |
| `chart.<chart-name>.<property>` | global only | none | `--scheduler-k3s-global-chart.<chart-name>.<property>` (dynamic per chart/property) | Override a value injected into the helm chart named `<chart-name>` (one row per chart/property pair) |
| `chart.<chart-name>.<property>` | global only | none | `--scheduler-k3s-global-chart.<chart-name>.<property>` (dynamic per chart/property) | Override a value injected into the helm chart named `<chart-name>` (one row per chart/property pair). Manage these via the dedicated `scheduler-k3s:charts:set` / `scheduler-k3s:charts:report` commands; the `scheduler-k3s:set`/`scheduler-k3s:report` form is deprecated. |

View File

@@ -122,7 +122,7 @@ At this time, the following dokku commands are used to implement a complete sche
- `apps:clone`: handles app cloning
- triggers: post-app-clone-setup
- `cron`: generates cron tasks for the app
- triggers: scheduler-cron-write
- triggers: scheduler-uses-host-cron, scheduler-cron-write
- `deploy`: deploys app proceses and checks the status of a deploy
- triggers: scheduler-app-status, scheduler-deploy, scheduler-is-deployed, scheduler-logs-failed
- `enter`: enters a running container

View File

@@ -581,6 +581,21 @@ set -eo pipefail; [[ $DOKKU_TRACE ]] && set -x
# TODO
```
### `config-migrate-env`
- Description: Drains the pre-0.38 `$DOKKU_ROOT/ENV` and `$DOKKU_ROOT/<app>/ENV` files into the config property path, removing each file once it has been drained. A file found at the old path after its migration has been recorded is never imported: the config path holds every change made since, so the file is removed when it agrees with the current config and otherwise moved aside to `ENV.migrated`. Idempotent, and safe to call from an install trigger that runs before the config plugin's own.
- Invoked by: `common` when migrating deprecated config vars to plugin properties, checks plugin
- Arguments: none
- Example:
```shell
#!/usr/bin/env bash
set -eo pipefail; [[ $DOKKU_TRACE ]] && set -x
plugn trigger config-migrate-env
```
### `config-set`
- Description: Sets one or more config values for an app without restarting (when --no-restart flag is specified)
@@ -1340,6 +1355,8 @@ esac
The default templates are viewable here: [plugins/nginx-vhosts/templates/](https://github.com/dokku/dokku/tree/master/plugins/nginx-vhosts/templates)
Overriding the `validate-config` template is the supported way to make deploy-time pre-validation aware of directives from nginx modules that the host loads via `load_module` in its global config. As implementing this trigger requires a [custom plugin](/docs/development/plugin-creation.md), see [Custom nginx modules](/docs/appendices/file-formats/nginx-conf-sigil.md#custom-nginx-modules) for a complete example.
### `nginx-dokku-template-source`
- Description: Return the path to a `sigil` template that should be used to generate the `dokku.conf` nginx configuration file.
@@ -2525,8 +2542,8 @@ DOKKU_SCHEDULER="$1"; APP="$2";
> The scheduler plugin trigger apis are under development and may change
> between minor releases until the 1.0 release.
- Description: Force triggers writing out cron tasks. Arguments are optional.
- Invoked by: `ps:start`, `ps:stop`, `cron:set`
- Description: Force triggers writing out cron tasks. Arguments are optional. The `cron` plugin implements this for host-crontab schedulers (regenerating the whole `dokku` user crontab when the scheduler uses host cron or when no scheduler is given); self-managed schedulers such as `k3s` implement it to update their own cron backend.
- Invoked by: `ps:start`, `ps:stop`, `cron:set`, `apps:destroy`
- Arguments: `$DOKKU_SCHEDULER $APP`
- Example:
@@ -2545,16 +2562,16 @@ source "$PLUGIN_CORE_AVAILABLE_PATH/common/functions"
> The scheduler plugin trigger apis are under development and may change
> between minor releases until the 1.0 release.
- Description: Allows you to run scheduler commands when an app is deployed
- Description: Allows you to run scheduler commands when an app is deployed. `$PROCESS_TYPE` is empty for a normal deploy and set when a single process type is targeted, as by `dokku ps:restart <app> <process-type>`, in which case only that process type should be redeployed.
- Invoked by: `dokku deploy`
- Arguments: `$DOKKU_SCHEDULER $APP $IMAGE_TAG`
- Arguments: `$DOKKU_SCHEDULER $APP $IMAGE_TAG $PROCESS_TYPE`
- Example:
```shell
#!/usr/bin/env bash
set -eo pipefail; [[ $DOKKU_TRACE ]] && set -x
DOKKU_SCHEDULER="$1"; APP="$2"; IMAGE_TAG="$3";
DOKKU_SCHEDULER="$1"; APP="$2"; IMAGE_TAG="$3"; PROCESS_TYPE="$4";
# TODO
```
@@ -2886,8 +2903,8 @@ DOKKU_SCHEDULER="$1"; APP="$2"; CONTAINER="$3"; TAIL="$4"; PRETTY_PRINT="$5"; NU
> The scheduler plugin trigger apis are under development and may change
> between minor releases until the 1.0 release.
- Description: Allows you to retire containers started by the `run` command
- Invoked by: `dokku run:retire`
- Description: Allows you to retire containers started by the `run` and `cron:run` commands that have exceeded their active deadline
- Invoked by: `dokku run:retire`, `dokku ps:retire`
- Arguments: `$DOKKU_SCHEDULER $APP`
- Example:
@@ -2987,6 +3004,30 @@ DOKKU_SCHEDULER="$1"; APP="$2"; REMOVE_CONTAINERS="$3";
- Arguments: `$SCHEDULER $ENTRY_NAME $IMAGE [-- $cmd...]`
- Flags: `--interactive` (stdin is open), `--tty` (stdin is a terminal), `--as-user <uid>` (override `entry.Chown`).
### `scheduler-uses-host-cron`
> [!WARNING]
> The scheduler plugin trigger apis are under development and may change
> between minor releases until the 1.0 release.
- Description: Reports whether the scheduler writes `app.json` cron tasks to the host `dokku` user crontab. Schedulers that use the host crontab (`docker-local`) echo `true`; schedulers that manage their own cron backend (`k3s`, which creates in-cluster CronJobs) echo `false`. The cron plugin reads this to decide which apps to include when regenerating the host crontab; a scheduler that does not implement the trigger is treated as `false`.
- Invoked by: `cron`
- Arguments: `$DOKKU_SCHEDULER`
- Example:
```shell
#!/usr/bin/env bash
set -eo pipefail; [[ $DOKKU_TRACE ]] && set -x
DOKKU_SCHEDULER="$1";
if [[ "$DOKKU_SCHEDULER" != "custom-scheduler" ]]; then
return
fi
echo "true"
```
### `traefik-template-source`
- Description: Retrieves an alternative template for the traefik compose config

View File

@@ -29,7 +29,7 @@ The workflow looks like this:
```shell
# having dokku-arch in ../dokku-arch
vagrant up build-arch
# wait for "==> build-arch: ==> Finished making: dokku 0.38.8-2 (Mon Feb 22 23:20:37 CET 2016)"
# wait for "==> build-arch: ==> Finished making: dokku 0.38.27-2 (Mon Feb 22 23:20:37 CET 2016)"
cd ../dokku-arch
git add PKGBUILD .SRCINFO
git commit -m 'Update to dokku 0.9.9'

View File

@@ -3,7 +3,7 @@
Pull the dokku/dokku image:
```shell
docker pull dokku/dokku:0.38.8
docker pull dokku/dokku:0.38.27
```
Next, run the image.
@@ -19,7 +19,7 @@ docker container run -d \
--publish 8443:443 \
--volume /var/lib/dokku:/mnt/dokku \
--volume /var/run/docker.sock:/var/run/docker.sock \
dokku/dokku:0.38.8
dokku/dokku:0.38.27
```
Alternatively, you can use `docker-compose.yml`:
@@ -27,7 +27,7 @@ Alternatively, you can use `docker-compose.yml`:
```yaml
services:
dokku:
image: dokku/dokku:0.38.8
image: dokku/dokku:0.38.27
container_name: dokku
network_mode: bridge
ports:
@@ -67,7 +67,7 @@ Compose dependents can gate on the healthcheck via `depends_on` with `condition:
```yaml
services:
dokku:
image: dokku/dokku:0.38.8
image: dokku/dokku:0.38.27
# ...
bootstrap:
image: alpine:3.20
@@ -114,7 +114,7 @@ redis: https://github.com/dokku/dokku-redis.git
The alternative is to build a custom docker image via a custom Dockerfile. This Dockerfile can run any `plugin:install` command, though the `install` trigger must be skipped via the `--skip-install-trigger`. The version installed at that time will be the one that persists. Below is an example Dockerfile showing this method.
```Dockerfile
FROM dokku/dokku:0.38.8
FROM dokku/dokku:0.38.27
RUN dokku plugin:install https://github.com/dokku/dokku-postgres.git --skip-install-trigger
RUN dokku plugin:install https://github.com/dokku/dokku-redis.git --skip-install-trigger
```

View File

@@ -31,8 +31,8 @@ To install the latest stable version of Dokku, you can run the following shell c
```shell
# for debian systems, installs Dokku via apt-get
wget -NP . https://dokku.com/install/v0.38.8/bootstrap.sh
sudo DOKKU_TAG=v0.38.8 bash bootstrap.sh
wget -NP . https://dokku.com/install/v0.38.27/bootstrap.sh
sudo DOKKU_TAG=v0.38.27 bash bootstrap.sh
```
The installation process takes about 5-10 minutes, depending upon internet connection speed.

View File

@@ -10,26 +10,26 @@
<meta name="author" content="">
<title>Dokku - The smallest PaaS implementation you've ever seen</title>
<link rel="apple-touch-icon" sizes="57x57" href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.8/docs/assets/favicons/apple-touch-icon-57x57.png">
<link rel="apple-touch-icon" sizes="60x60" href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.8/docs/assets/favicons/apple-touch-icon-60x60.png">
<link rel="apple-touch-icon" sizes="72x72" href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.8/docs/assets/favicons/apple-touch-icon-72x72.png">
<link rel="apple-touch-icon" sizes="76x76" href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.8/docs/assets/favicons/apple-touch-icon-76x76.png">
<link rel="apple-touch-icon" sizes="114x114" href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.8/docs/assets/favicons/apple-touch-icon-114x114.png">
<link rel="apple-touch-icon" sizes="120x120" href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.8/docs/assets/favicons/apple-touch-icon-120x120.png">
<link rel="apple-touch-icon" sizes="144x144" href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.8/docs/assets/favicons/apple-touch-icon-144x144.png">
<link rel="apple-touch-icon" sizes="152x152" href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.8/docs/assets/favicons/apple-touch-icon-152x152.png">
<link rel="apple-touch-icon" sizes="180x180" href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.8/docs/assets/favicons/apple-touch-icon-180x180.png">
<link rel="icon" type="image/png" href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.8/docs/assets/favicons/favicon-32x32.png" sizes="32x32">
<link rel="icon" type="image/png" href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.8/docs/assets/favicons/android-chrome-192x192.png" sizes="192x192">
<link rel="icon" type="image/png" href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.8/docs/assets/favicons/favicon-96x96.png" sizes="96x96">
<link rel="icon" type="image/png" href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.8/docs/assets/favicons/favicon-16x16.png" sizes="16x16">
<link rel="manifest" href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.8/docs/assets/favicons/manifest.json">
<link rel="shortcut icon" href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.8/docs/assets/favicons/favicon.ico">
<link rel="apple-touch-icon" sizes="57x57" href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.27/docs/assets/favicons/apple-touch-icon-57x57.png">
<link rel="apple-touch-icon" sizes="60x60" href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.27/docs/assets/favicons/apple-touch-icon-60x60.png">
<link rel="apple-touch-icon" sizes="72x72" href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.27/docs/assets/favicons/apple-touch-icon-72x72.png">
<link rel="apple-touch-icon" sizes="76x76" href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.27/docs/assets/favicons/apple-touch-icon-76x76.png">
<link rel="apple-touch-icon" sizes="114x114" href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.27/docs/assets/favicons/apple-touch-icon-114x114.png">
<link rel="apple-touch-icon" sizes="120x120" href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.27/docs/assets/favicons/apple-touch-icon-120x120.png">
<link rel="apple-touch-icon" sizes="144x144" href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.27/docs/assets/favicons/apple-touch-icon-144x144.png">
<link rel="apple-touch-icon" sizes="152x152" href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.27/docs/assets/favicons/apple-touch-icon-152x152.png">
<link rel="apple-touch-icon" sizes="180x180" href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.27/docs/assets/favicons/apple-touch-icon-180x180.png">
<link rel="icon" type="image/png" href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.27/docs/assets/favicons/favicon-32x32.png" sizes="32x32">
<link rel="icon" type="image/png" href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.27/docs/assets/favicons/android-chrome-192x192.png" sizes="192x192">
<link rel="icon" type="image/png" href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.27/docs/assets/favicons/favicon-96x96.png" sizes="96x96">
<link rel="icon" type="image/png" href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.27/docs/assets/favicons/favicon-16x16.png" sizes="16x16">
<link rel="manifest" href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.27/docs/assets/favicons/manifest.json">
<link rel="shortcut icon" href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.27/docs/assets/favicons/favicon.ico">
<meta name="apple-mobile-web-app-title" content="Dokku">
<meta name="application-name" content="Dokku">
<meta name="msapplication-TileColor" content="#da532c">
<meta name="msapplication-TileImage" content="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.8/docs/assets/favicons/mstile-144x144.png">
<meta name="msapplication-config" content="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.8/docs/assets/favicons/browserconfig.xml">
<meta name="msapplication-TileImage" content="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.27/docs/assets/favicons/mstile-144x144.png">
<meta name="msapplication-config" content="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.27/docs/assets/favicons/browserconfig.xml">
<meta name="theme-color" content="#ffffff">
<link href="https://cdn.jsdelivr.net/npm/bootstrap@5.2.0-beta1/dist/css/bootstrap.min.css" rel="stylesheet" integrity="sha384-0evHe/X+R7YkIZDRvuzKMRqM+OrBnVFBL6DOitfPri4tjfHxaWutUpFmBp4vmVor" crossorigin="anonymous">
@@ -38,7 +38,7 @@
<link rel="preconnect" href="https://fonts.googleapis.com">
<link rel="preconnect" href="https://fonts.gstatic.com" crossorigin>
<link href="https://fonts.googleapis.com/css2?family=Lato:wght@400;700;900&display=swap" rel="stylesheet">
<link href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.8/docs/assets/style.css" rel="stylesheet">
<link href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.27/docs/assets/style.css" rel="stylesheet">
<!-- <link href="./assets/style.css" rel="stylesheet"> -->
</head>
@@ -98,7 +98,7 @@
<main class="container px-4 px-lg-5">
<div class="row">
<div class="col-lg-7">
<a class="badge-link" href="https://github.com/dokku/dokku/releases"><span class="badge py-2 d-flex fit-content"><div class="circle align-self-center me-2"></div>Latest release <span id="releaseVersion" class="ms-1">v0.38.8</span></span></a>
<a class="badge-link" href="https://github.com/dokku/dokku/releases"><span class="badge py-2 d-flex fit-content"><div class="circle align-self-center me-2"></div>Latest release <span id="releaseVersion" class="ms-1">v0.38.27</span></span></a>
<h1 class="text-white hero-heading mt-5">An open source PAAS alternative to Heroku.</h1>
<h4 class="text-white mt-5">Dokku helps you build and manage the lifecycle of applications from building to scaling.</h4>
<div class="d-flex mt-5">
@@ -125,7 +125,7 @@
</p>
<p class="line">
<span class="prompt">$</span>
<span class="command">sudo DOKKU_TAG=v0.38.8 bash bootstrap.sh</span>
<span class="command">sudo DOKKU_TAG=v0.38.27 bash bootstrap.sh</span>
</p>
<br>

View File

@@ -8,7 +8,7 @@ network:create <network> # Creates an attachable docker netwo
network:destroy <network> # Destroys a docker network
network:exists <network> # Checks if a docker network exists
network:info <network> [--format text|json] # Outputs information about a docker network
network:list [--format text|json] # Lists all docker networks
network:list [--format text|json] [--dokku-managed] # Lists all docker networks
network:report [<app>] [<flag>] # Displays a network report for one or more apps
network:rebuild <app> # Rebuilds network settings for an app
network:rebuildall # Rebuild network settings for all apps
@@ -59,13 +59,26 @@ dokku network:list --format json
```
[
{"CreatedAt":"2024-02-25T01:55:24.275184461Z","Driver":"bridge","ID":"d18df2d21433","Internal":false,"IPv6":false,"Labels":{},"Name":"bridge","Scope":"local"},
{"CreatedAt":"2024-02-25T01:55:24.275184461Z","Driver":"bridge","ID":"f50fa882e7de","Internal":false,"IPv6":false,"Labels":{},"Name":"test-network","Scope":"local"},
{"CreatedAt":"2024-02-25T01:55:24.275184461Z","Driver":"host","ID":"ab6a59291443","Internal":false,"IPv6":false,"Labels":{},"Name":"host","Scope":"local"},
{"CreatedAt":"2024-02-25T01:55:24.275184461Z","Driver":"null","ID":"e2506bc8b7d7","Internal":false,"IPv6":false,"Labels":{},"Name":"none","Scope":"local"}
{"CreatedAt":"2024-02-25T01:55:24.275184461Z","DokkuManaged":false,"Driver":"bridge","ID":"d18df2d21433","Internal":false,"IPv6":false,"Labels":{},"Name":"bridge","Scope":"local"},
{"CreatedAt":"2024-02-25T01:55:24.275184461Z","DokkuManaged":true,"Driver":"bridge","ID":"f50fa882e7de","Internal":false,"IPv6":false,"Labels":{"com.dokku.network-name":"test-network"},"Name":"test-network","Scope":"local"},
{"CreatedAt":"2024-02-25T01:55:24.275184461Z","DokkuManaged":false,"Driver":"host","ID":"ab6a59291443","Internal":false,"IPv6":false,"Labels":{},"Name":"host","Scope":"local"},
{"CreatedAt":"2024-02-25T01:55:24.275184461Z","DokkuManaged":false,"Driver":"null","ID":"e2506bc8b7d7","Internal":false,"IPv6":false,"Labels":{},"Name":"none","Scope":"local"}
]
```
The `DokkuManaged` field is `true` for networks created by `network:create` and `false` for Docker built-in networks (such as `bridge`, `host`, and `none`) or networks created outside of Dokku (such as compose `*_default` networks). This can be used by automation to determine which networks Dokku is responsible for.
The `network:list` command also takes a `--dokku-managed` flag, which restricts the output to only those networks created by Dokku. It can be combined with the `--format` flag:
```shell
dokku network:list --dokku-managed
```
```
=====> Networks
test-network
```
### Creating a network
> [!IMPORTANT]
@@ -142,10 +155,11 @@ dokku network:info bridge
```
=====> bridge network information
ID: d18df2d21433
Name: bridge
Driver: bridge
Scope: local
ID: d18df2d21433
Name: bridge
Driver: bridge
Scope: local
Dokku managed: false
```
The `network:info` command also takes a `--format` flag, with the valid options including `text` (default) and `json`. The `json` output format can be used for automation purposes:
@@ -155,7 +169,7 @@ dokku network:info bridge --format json
```
```
{"CreatedAt":"2024-02-25T01:55:24.275184461Z","Driver":"bridge","ID":"d18df2d21433","Internal":false,"IPv6":false,"Labels":{},"Name":"bridge","Scope":"local"}
{"CreatedAt":"2024-02-25T01:55:24.275184461Z","DokkuManaged":false,"Driver":"bridge","ID":"d18df2d21433","Internal":false,"IPv6":false,"Labels":{},"Name":"bridge","Scope":"local"}
```
### Routing an app to a known ip:port combination

View File

@@ -221,8 +221,61 @@ You can pass flags which will output only the value of the specific information
dokku ports:report node-js-app --ports-map
```
Use `--ports-map-json` or `--ports-map-detected-json` to get the same data as a JSON array of objects. Each object has the following fields:
- `scheme`: the port scheme (e.g. `http`, `https`, `udp`)
- `host_port`: the host/listener port
- `container_port`: the container port
```shell
dokku ports:report node-js-app --ports-map-json
```
```json
[
{
"scheme": "http",
"host_port": 80,
"container_port": 5000
},
{
"scheme": "https",
"host_port": 443,
"container_port": 5000
}
]
```
The JSON output can be processed with tools such as `jq`:
```shell
dokku ports:report node-js-app --ports-map-json | jq '.[].host_port'
```
```
80
443
```
```shell
dokku ports:report node-js-app --ports-map-detected-json | jq '.[0].container_port'
```
```
5000
```
## Properties
### Configured flags
The following flags surface configured port mappings managed by `ports:set` / `ports:add` / `ports:remove` / `ports:clear`:
| Flag | Description |
|---|---|
| `--ports-map` | Configured port mappings as space-separated `scheme:host-port:container-port` values |
| `--ports-map-json` | Configured port mappings as a JSON array of `{scheme, host_port, container_port}` objects |
### Read-only flags
The following flags surface in `ports:report` but are not managed by `ports:set` - they are derived from the deploy:
@@ -230,3 +283,4 @@ The following flags surface in `ports:report` but are not managed by `ports:set`
| Flag | Description |
|---|---|
| `--ports-map-detected` | Port mapping inferred from `EXPOSE` directives or the running container |
| `--ports-map-detected-json` | Detected port mappings as a JSON array of `{scheme, host_port, container_port}` objects |

View File

@@ -121,6 +121,8 @@ dokku nginx:show-config node-js-app
App-supplied `nginx.conf.sigil` files are pre-validated automatically at the start of every deploy, immediately after the template is extracted from the source tree and before the build phase runs. The template is rendered with sigil and run through `nginx -t` against a minimal wrapper config; if validation fails, the deploy is aborted before any build work begins. To bypass this behavior, set `disable-custom-config` to `true` (see "Disabling custom nginx config" below).
The wrapper config used for validation does not include the top-level `load_module` directives from the global nginx config, so a `nginx.conf.sigil` that relies on a directive from a dynamically loaded module will fail this validation even when `nginx -t` passes against the real server config. See [Custom nginx modules](/docs/appendices/file-formats/nginx-conf-sigil.md#custom-nginx-modules) for how to supply a custom validation wrapper via the `nginx-app-template-source` trigger's `validate-config` template type.
It may also be desired to validate an nginx config outside of the deployment process. To do so, run the `nginx:validate-config` command. With no arguments, this will validate all app nginx configs, one at a time. A minimal wrapper nginx config is generated for each app's nginx config, upon which `nginx -t` will be run.
```shell

View File

@@ -284,41 +284,43 @@ dokku openresty:report node-js-app --openresty-computed-letsencrypt-email
### Settable properties
Five properties (`image`, `log-level`, `letsencrypt-email`, `letsencrypt-server`, `allowed-letsencrypt-domains-func-base64`) are global only. The rest are app only - they cannot be set with `--global`.
Five properties (`image`, `log-level`, `letsencrypt-email`, `letsencrypt-server`, `allowed-letsencrypt-domains-func-base64`) are global only. The rest may be set per-app or globally with `--global`; a global value applies to any app that has no per-app value, otherwise the built-in default is used.
Global-only properties expose two report flags: `--openresty-global-<property>` returns the raw stored value (empty when the property has never been set), while `--openresty-computed-<property>` returns the effective value (the global value if set, otherwise the built-in default). The per-app `hsts` property additionally has a bare `--openresty-hsts` flag for the raw per-app value.
Global-only properties expose two report flags: `--openresty-global-<property>` returns the raw stored value (empty when the property has never been set), while `--openresty-computed-<property>` returns the effective value (the global value if set, otherwise the built-in default).
App-or-global properties expose three report flags: `--openresty-<property>` returns the raw per-app value (empty when unset), `--openresty-global-<property>` returns the raw global value (empty when unset), and `--openresty-computed-<property>` returns the effective value, resolving the per-app value first, then the global value, then the built-in default.
| Property | Scope | Default | Report flags | Description |
|---|---|---|---|---|
| `access-log-format` | app only | none | `--openresty-access-log-format` | Custom nginx `log_format` directive used for the access log |
| `access-log-path` | app only | _`/var/log/nginx/{app}-access.log`_ | `--openresty-access-log-path` | Path inside the openresty container where access logs are written |
| `access-log-format` | app or global | none | `--openresty-access-log-format`, `--openresty-global-access-log-format`, `--openresty-computed-access-log-format` | Custom nginx `log_format` directive used for the access log |
| `access-log-path` | app or global | _`/var/log/nginx/{app}-access.log`_ | `--openresty-access-log-path`, `--openresty-global-access-log-path`, `--openresty-computed-access-log-path` | Path inside the openresty container where access logs are written |
| `allowed-letsencrypt-domains-func-base64` | global only | _allow-all stub_ | `--openresty-global-allowed-letsencrypt-domains-func-base64`, `--openresty-computed-allowed-letsencrypt-domains-func-base64` | Base64-encoded Lua function deciding which domains may request a letsencrypt certificate |
| `bind-address-ipv4` | app only | none | `--openresty-bind-address-ipv4` | IPv4 address the openresty server block binds to |
| `bind-address-ipv6` | app only | `::` | `--openresty-bind-address-ipv6` | IPv6 address the openresty server block binds to |
| `client-body-timeout` | app only | `60s` | `--openresty-client-body-timeout` | Time allowed to read the request body from the client |
| `client-header-timeout` | app only | `60s` | `--openresty-client-header-timeout` | Time allowed to read the request header from the client |
| `client-max-body-size` | app only | `1m` | `--openresty-client-max-body-size` | Maximum allowed request body size |
| `error-log-path` | app only | _`/var/log/nginx/{app}-error.log`_ | `--openresty-error-log-path` | Path inside the openresty container where error logs are written |
| `hsts` | app only | `true` | `--openresty-hsts`, `--openresty-global-hsts`, `--openresty-computed-hsts` | When `true`, emits a `Strict-Transport-Security` header on HTTPS responses |
| `hsts-include-subdomains` | app only | `true` | `--openresty-hsts-include-subdomains` | Adds the `includeSubDomains` directive to the HSTS header |
| `hsts-max-age` | app only | `15724800` | `--openresty-hsts-max-age` | `max-age` value (seconds) in the HSTS header |
| `hsts-preload` | app only | `false` | `--openresty-hsts-preload` | Adds the `preload` directive to the HSTS header |
| `bind-address-ipv4` | app or global | none | `--openresty-bind-address-ipv4`, `--openresty-global-bind-address-ipv4`, `--openresty-computed-bind-address-ipv4` | IPv4 address the openresty server block binds to |
| `bind-address-ipv6` | app or global | `::` | `--openresty-bind-address-ipv6`, `--openresty-global-bind-address-ipv6`, `--openresty-computed-bind-address-ipv6` | IPv6 address the openresty server block binds to |
| `client-body-timeout` | app or global | `60s` | `--openresty-client-body-timeout`, `--openresty-global-client-body-timeout`, `--openresty-computed-client-body-timeout` | Time allowed to read the request body from the client |
| `client-header-timeout` | app or global | `60s` | `--openresty-client-header-timeout`, `--openresty-global-client-header-timeout`, `--openresty-computed-client-header-timeout` | Time allowed to read the request header from the client |
| `client-max-body-size` | app or global | `1m` | `--openresty-client-max-body-size`, `--openresty-global-client-max-body-size`, `--openresty-computed-client-max-body-size` | Maximum allowed request body size |
| `error-log-path` | app or global | _`/var/log/nginx/{app}-error.log`_ | `--openresty-error-log-path`, `--openresty-global-error-log-path`, `--openresty-computed-error-log-path` | Path inside the openresty container where error logs are written |
| `hsts` | app or global | `true` | `--openresty-hsts`, `--openresty-global-hsts`, `--openresty-computed-hsts` | When `true`, emits a `Strict-Transport-Security` header on HTTPS responses |
| `hsts-include-subdomains` | app or global | `true` | `--openresty-hsts-include-subdomains`, `--openresty-global-hsts-include-subdomains`, `--openresty-computed-hsts-include-subdomains` | Adds the `includeSubDomains` directive to the HSTS header |
| `hsts-max-age` | app or global | `15724800` | `--openresty-hsts-max-age`, `--openresty-global-hsts-max-age`, `--openresty-computed-hsts-max-age` | `max-age` value (seconds) in the HSTS header |
| `hsts-preload` | app or global | `false` | `--openresty-hsts-preload`, `--openresty-global-hsts-preload`, `--openresty-computed-hsts-preload` | Adds the `preload` directive to the HSTS header |
| `image` | global only | _parsed from `plugins/openresty-vhosts/Dockerfile`_ | `--openresty-global-image`, `--openresty-computed-image` | Docker image used to run the openresty container |
| `keepalive-timeout` | app only | `75s` | `--openresty-keepalive-timeout` | Time an idle keep-alive connection stays open |
| `keepalive-timeout` | app or global | `75s` | `--openresty-keepalive-timeout`, `--openresty-global-keepalive-timeout`, `--openresty-computed-keepalive-timeout` | Time an idle keep-alive connection stays open |
| `letsencrypt-email` | global only | none | `--openresty-global-letsencrypt-email`, `--openresty-computed-letsencrypt-email` | Contact email enabling letsencrypt; empty disables https issuance |
| `letsencrypt-server` | global only | `https://acme-v02.api.letsencrypt.org/directory` | `--openresty-global-letsencrypt-server`, `--openresty-computed-letsencrypt-server` | ACME directory used when requesting certificates |
| `lingering-timeout` | app only | `5s` | `--openresty-lingering-timeout` | Time openresty waits for more client data when closing a connection |
| `lingering-timeout` | app or global | `5s` | `--openresty-lingering-timeout`, `--openresty-global-lingering-timeout`, `--openresty-computed-lingering-timeout` | Time openresty waits for more client data when closing a connection |
| `log-level` | global only | `ERROR` | `--openresty-global-log-level`, `--openresty-computed-log-level` | Openresty log level |
| `proxy-buffer-size` | app only | _system pagesize_ | `--openresty-proxy-buffer-size` | Buffer size for reading the first part of the upstream response |
| `proxy-buffering` | app only | `on` | `--openresty-proxy-buffering` | Whether openresty buffers upstream responses (`on` or `off`) |
| `proxy-buffers` | app only | _`8 {pagesize}`_ | `--openresty-proxy-buffers` | Number and size of buffers used for an upstream response |
| `proxy-busy-buffers-size` | app only | _`2 * pagesize`_ | `--openresty-proxy-busy-buffers-size` | Maximum buffer size that can be busy sending a response to the client |
| `proxy-connect-timeout` | app only | `60s` | `--openresty-proxy-connect-timeout` | Time to establish a connection to the upstream |
| `proxy-read-timeout` | app only | `60s` | `--openresty-proxy-read-timeout` | Time to read a response from the upstream |
| `proxy-send-timeout` | app only | `60s` | `--openresty-proxy-send-timeout` | Time to transmit a request to the upstream |
| `send-timeout` | app only | `60s` | `--openresty-send-timeout` | Time between two successive write operations to the client |
| `underscore-in-headers` | app only | `off` | `--openresty-underscore-in-headers` | Whether to allow underscores in client request header field names |
| `x-forwarded-for-value` | app only | `$remote_addr` | `--openresty-x-forwarded-for-value` | Value used for the `X-Forwarded-For` header |
| `x-forwarded-port-value` | app only | `$server_port` | `--openresty-x-forwarded-port-value` | Value used for the `X-Forwarded-Port` header |
| `x-forwarded-proto-value` | app only | `$scheme` | `--openresty-x-forwarded-proto-value` | Value used for the `X-Forwarded-Proto` header |
| `x-forwarded-ssl` | app only | none | `--openresty-x-forwarded-ssl` | Value used for the `X-Forwarded-Ssl` header (e.g. `on`/`off`) |
| `proxy-buffer-size` | app or global | _system pagesize_ | `--openresty-proxy-buffer-size`, `--openresty-global-proxy-buffer-size`, `--openresty-computed-proxy-buffer-size` | Buffer size for reading the first part of the upstream response |
| `proxy-buffering` | app or global | `on` | `--openresty-proxy-buffering`, `--openresty-global-proxy-buffering`, `--openresty-computed-proxy-buffering` | Whether openresty buffers upstream responses (`on` or `off`) |
| `proxy-buffers` | app or global | _`8 {pagesize}`_ | `--openresty-proxy-buffers`, `--openresty-global-proxy-buffers`, `--openresty-computed-proxy-buffers` | Number and size of buffers used for an upstream response |
| `proxy-busy-buffers-size` | app or global | _`2 * pagesize`_ | `--openresty-proxy-busy-buffers-size`, `--openresty-global-proxy-busy-buffers-size`, `--openresty-computed-proxy-busy-buffers-size` | Maximum buffer size that can be busy sending a response to the client |
| `proxy-connect-timeout` | app or global | `60s` | `--openresty-proxy-connect-timeout`, `--openresty-global-proxy-connect-timeout`, `--openresty-computed-proxy-connect-timeout` | Time to establish a connection to the upstream |
| `proxy-read-timeout` | app or global | `60s` | `--openresty-proxy-read-timeout`, `--openresty-global-proxy-read-timeout`, `--openresty-computed-proxy-read-timeout` | Time to read a response from the upstream |
| `proxy-send-timeout` | app or global | `60s` | `--openresty-proxy-send-timeout`, `--openresty-global-proxy-send-timeout`, `--openresty-computed-proxy-send-timeout` | Time to transmit a request to the upstream |
| `send-timeout` | app or global | `60s` | `--openresty-send-timeout`, `--openresty-global-send-timeout`, `--openresty-computed-send-timeout` | Time between two successive write operations to the client |
| `underscore-in-headers` | app or global | `off` | `--openresty-underscore-in-headers`, `--openresty-global-underscore-in-headers`, `--openresty-computed-underscore-in-headers` | Whether to allow underscores in client request header field names |
| `x-forwarded-for-value` | app or global | `$remote_addr` | `--openresty-x-forwarded-for-value`, `--openresty-global-x-forwarded-for-value`, `--openresty-computed-x-forwarded-for-value` | Value used for the `X-Forwarded-For` header |
| `x-forwarded-port-value` | app or global | `$server_port` | `--openresty-x-forwarded-port-value`, `--openresty-global-x-forwarded-port-value`, `--openresty-computed-x-forwarded-port-value` | Value used for the `X-Forwarded-Port` header |
| `x-forwarded-proto-value` | app or global | `$scheme` | `--openresty-x-forwarded-proto-value`, `--openresty-global-x-forwarded-proto-value`, `--openresty-computed-x-forwarded-proto-value` | Value used for the `X-Forwarded-Proto` header |
| `x-forwarded-ssl` | app or global | none | `--openresty-x-forwarded-ssl`, `--openresty-global-x-forwarded-ssl`, `--openresty-computed-x-forwarded-ssl` | Value used for the `X-Forwarded-Ssl` header (e.g. `on`/`off`) |

View File

@@ -260,6 +260,16 @@ dokku traefik:set --global dns-provider-cf_api_key your-api-key
The `dns-provider-` prefix will be stripped and the variable name will be uppercased when passed to the Traefik container. For example, `dns-provider-cf_api_email` becomes `CF_API_EMAIL`.
Each configured variable is surfaced by `traefik:report` as `--traefik-global-dns-provider-<env_var>`. As these values are provider credentials, they are masked as `*******` in the default report output, including the aggregate `dokku report`. The raw value is returned when the flag is requested explicitly or when the report is rendered as json:
```shell
dokku traefik:report --global --traefik-global-dns-provider-cf_api_email
```
```shell
dokku traefik:report --global --format json | jq -r '."global-dns-provider-cf_api_email"'
```
After configuring, the Traefik container will need to be restarted and apps will need to be rebuilt.
Refer to the [Traefik DNS Challenge documentation](https://doc.traefik.io/traefik/https/acme/#dnschallenge) for the list of supported DNS providers and their required environment variables.
@@ -403,12 +413,12 @@ All traefik properties are global only. Set with `traefik:set --global <property
| `api-entry-point` | global only | none | `--traefik-global-api-entry-point`, `--traefik-computed-api-entry-point` | Name of the entry point used by the Traefik API |
| `api-entry-point-address` | global only | none | `--traefik-global-api-entry-point-address`, `--traefik-computed-api-entry-point-address` | Address (`host:port`) the Traefik API listens on |
| `api-vhost` | global only | `traefik.dokku.me` | `--traefik-global-api-vhost`, `--traefik-computed-api-vhost` | Virtual host that routes to the Traefik API |
| `basic-auth-password` | global only | none | `--traefik-global-basic-auth-password`, `--traefik-computed-basic-auth-password` | Password for basic auth in front of the API/dashboard |
| `basic-auth-password` | global only | none | `--traefik-global-basic-auth-password`, `--traefik-computed-basic-auth-password` (masked as `*******` in the default stdout report; the raw value is returned when queried via `--format json` or when one of these flags is requested explicitly) | Password for basic auth in front of the API/dashboard |
| `basic-auth-username` | global only | none | `--traefik-global-basic-auth-username`, `--traefik-computed-basic-auth-username` | Username for basic auth in front of the API/dashboard |
| `challenge-mode` | global only | `tls` | `--traefik-global-challenge-mode`, `--traefik-computed-challenge-mode` | ACME challenge method used by Traefik (`tls`, `http`, or `dns`) |
| `dashboard-enabled` | global only | `false` | `--traefik-global-dashboard-enabled`, `--traefik-computed-dashboard-enabled` | When `true`, enables the Traefik dashboard |
| `dns-provider` | global only | none | `--traefik-global-dns-provider`, `--traefik-computed-dns-provider` | Lego DNS provider name used when `challenge-mode` is `dns` |
| `dns-provider-<ENV_VAR>` | global only | none | `--traefik-dns-provider-<env_var>` (masked as `*******` in the default stdout report; the raw value is returned when queried via `--format json` or when this flag is requested explicitly) | Per-provider environment variables passed to the Traefik container; `<ENV_VAR>` is the upstream variable name (e.g. `dns-provider-cloudflare-api-token`) |
| `dns-provider-<ENV_VAR>` | global only | none | `--traefik-global-dns-provider-<env_var>` (masked as `*******` in the default stdout report; the raw value is returned when queried via `--format json` or when this flag is requested explicitly) | Per-provider environment variables passed to the Traefik container; `<ENV_VAR>` is the upstream variable name (e.g. `dns-provider-cloudflare-api-token`) |
| `http-entry-point` | global only | `http` | `--traefik-global-http-entry-point`, `--traefik-computed-http-entry-point` | Entry point name handling plaintext HTTP traffic |
| `https-entry-point` | global only | `https` | `--traefik-global-https-entry-point`, `--traefik-computed-https-entry-point` | Entry point name handling TLS-terminated HTTPS traffic |
| `image` | global only | _parsed from `plugins/traefik-vhosts/Dockerfile`_ | `--traefik-global-image`, `--traefik-computed-image` | Docker image used to run the Traefik container |

View File

@@ -4,15 +4,15 @@
> New as of 0.3.14, Enhanced in 0.7.0
```
ps:inspect <app> # Displays a sanitized version of docker inspect for an app
ps:rebuild [--parallel count] [--all|<app>] # Rebuilds an app from source
ps:report [<app>] [<flag>] # Displays a process report for one or more apps
ps:restart [--parallel count] [--all|<app>] [<process-name>] # Restart an app
ps:restore [<app>] # Start previously running apps e.g. after reboot
ps:scale [--skip-deploy] <app> <proc>=<count> [<proc>=<count>...] # Get/Set how many instances of a given process to run
ps:set <app> <key> <value> # Set or clear a ps property for an app
ps:start [--parallel count] [--all|<app>] # Start an app
ps:stop [--parallel count] [--all|<app>] # Stop an app
ps:inspect <app> # Displays a sanitized version of docker inspect for an app
ps:rebuild [--parallel count] [--all|<app>] # Rebuilds an app from source
ps:report [<app>] [<flag>] # Displays a process report for one or more apps
ps:restart [--parallel count] [--all|<app>] [<process-name>] # Restart an app
ps:restore [<app>] # Start previously running apps e.g. after reboot
ps:scale [--skip-deploy] [--format stdout|json] <app> [<proc>=<count>...] # Get/Set how many instances of a given process to run
ps:set <app> <key> <value> # Set or clear a ps property for an app
ps:start [--parallel count] [--all|<app>] # Start an app
ps:stop [--parallel count] [--all|<app>] # Stop an app
```
## Usage
@@ -107,6 +107,18 @@ proctype: qty
web: 1
```
The formation can also be retrieved as JSON by using the `--format json` flag, which is useful for programmatic consumption. Each entry maps a process type to its desired quantity:
```shell
dokku ps:scale node-js-app --format json
```
```json
[{"process_type":"web","quantity":1},{"process_type":"worker","quantity":4}]
```
When no scale has been set for the app, the JSON output is an empty array (`[]`).
### Changing process management settings
The `ps` plugin provides a number of settings that can be used to managed deployments on a per-app basis. The following table outlines ones not covered elsewhere:
@@ -367,6 +379,20 @@ dokku ps:set node-js-app restart-policy on-failure
dokku ps:set node-js-app restart-policy on-failure:20
```
The default policy (`on-failure:10`) may be restored by passing an empty value:
```shell
dokku ps:set node-js-app restart-policy
```
A global default may also be set, and is used by any app that does not have an app-specific restart policy:
```shell
dokku ps:set --global restart-policy always
```
The effective policy applied to an app's containers is resolved as the app-specific value, then the global value, then the built-in `on-failure:10` default. This computed value can be inspected via the `--ps-computed-restart-policy` report flag.
Restart policies have no bearing on server reboot, and Dokku will always attempt to restart your apps at that point unless they were manually stopped.
Dokku also runs `dokku-event-listener` in the background via the system's init service. This monitors container state, performing the following actions:
@@ -391,8 +417,10 @@ dokku ps:report
Processes: 0
Ps can scale: true
Ps computed procfile path: Procfile2
Ps computed restart policy: on-failure:10
Ps global procfile path: Procfile
Ps restart policy: on-failure:10
Ps global restart policy:
Ps restart policy:
Ps procfile path: Procfile2
Restore: true
Running: false
@@ -401,8 +429,10 @@ dokku ps:report
Processes: 0
Ps can scale: true
Ps computed procfile path: Procfile
Ps computed restart policy: on-failure:10
Ps global procfile path: Procfile
Ps restart policy: on-failure:10
Ps global restart policy:
Ps restart policy:
Ps procfile path:
Restore: true
Running: false
@@ -411,8 +441,10 @@ dokku ps:report
Processes: 0
Ps can scale: true
Ps computed procfile path: Procfile
Ps computed restart policy: on-failure:10
Ps global procfile path: Procfile
Ps restart policy: on-failure:10
Ps global restart policy:
Ps restart policy:
Ps procfile path:
Restore: true
Running: false
@@ -429,7 +461,9 @@ dokku ps:report node-js-app
Deployed: false
Processes: 0
Ps can scale: true
Ps restart policy: on-failure:10
Ps computed restart policy: on-failure:10
Ps global restart policy:
Ps restart policy:
Restore: true
Running: false
```
@@ -475,7 +509,7 @@ dokku ps:set node-js-app restore
|---|---|---|---|---|
| `dockerfile-start-cmd` | app only | none | `--ps-dockerfile-start-cmd`, `--ps-computed-dockerfile-start-cmd` | Override `CMD` for Dockerfile-based apps |
| `procfile-path` | app + global | `Procfile` | `--ps-procfile-path`, `--ps-global-procfile-path`, `--ps-computed-procfile-path` | Path to the app's Procfile, relative to the build root |
| `restart-policy` | app only | `on-failure:10` | `--ps-restart-policy` | Docker restart policy applied to deployed containers (`no`, `always`, `unless-stopped`, `on-failure[:max-retries]`) |
| `restart-policy` | app + global | `on-failure:10` | `--ps-restart-policy`, `--ps-global-restart-policy`, `--ps-computed-restart-policy` | Docker restart policy applied to deployed containers (`no`, `always`, `unless-stopped`, `on-failure[:max-retries]`) |
| `restore` | app only | `true` | `--restore` | When `true`, the app is restarted automatically by `ps:retire` after a host reboot |
| `skip-deploy` | app + global | `false` | `--ps-skip-deploy`, `--ps-global-skip-deploy`, `--ps-computed-skip-deploy` | When `true`, skips the deploy phase after a successful build |
| `start-cmd` | app only | none | `--ps-start-cmd`, `--ps-computed-start-cmd` | Override start command for buildpack apps |

View File

@@ -4,12 +4,12 @@
> New as of 0.23.0
```
cron:list <app> [--format json|stdout] # List scheduled cron tasks for an app
cron:report [<app>] [<flag>] # Display report about an app
cron:resume <app> <cron_id> # Resume a cron task
cron:run <app> <cron_id> [--detach] # Run a cron task on the fly
cron:set [--global|<app>] <key> <value> # Set or clear a cron property for an app
cron:suspend <app> <cron_id> # Suspend a cron task
cron:list <app> [--format json|stdout] # List scheduled cron tasks for an app
cron:report [<app>] [<flag>] # Display report about an app
cron:resume <app> <cron_id> # Resume a cron task
cron:run <app> <cron_id> [--detach] [--ttl-seconds SECONDS] # Run a cron task on the fly
cron:set [--global|<app>] <key> <value> # Set or clear a cron property for an app
cron:suspend <app> <cron_id> # Suspend a cron task
```
## Usage
@@ -43,7 +43,7 @@ A cron task takes the following properties:
Zero or more cron tasks can be specified per app. Cron tasks are validated after the build artifact is created but before the app is deployed, and the cron schedule is updated during the post-deploy phase.
Cron tasks can run for a maximum of 24 hours via the docker-local scheduler, after which they are reaped from the system.
Cron tasks can run for a maximum of 24 hours, after which they are reaped from the system. The `docker-local` scheduler reaps expired tasks via the `dokku ps:retire` pass that runs every 5 minutes, so a task may overrun its deadline by up to 5 minutes. The `k3s` scheduler enforces the deadline directly through the job's `activeDeadlineSeconds`.
See the [app.json location documentation](/docs/advanced-usage/deployment-tasks.md#changing-the-appjson-location) for more information on where to place your `app.json` file.
@@ -57,10 +57,35 @@ When running scheduled cron tasks, there are a few items to be aware of:
- A `MAILTO` value can be set via the `cron:set` command.
- A `MAILFROM` value can be set via the `cron:set` command.
- Each scheduled task is executed within a one-off `run` container, and thus inherit any docker-options specified for `run` containers. Resources are never shared between scheduled tasks.
- Scheduled cron tasks are supported on a per-scheduler basis, and are currently only implemented by the `docker-local` scheduler.
- Tasks for _all_ apps managed by the `docker-local` scheduler are written to a single crontab file owned by the `dokku` user. The `dokku` user's crontab should be considered reserved for this purpose.
- Scheduled cron tasks are supported on a per-scheduler basis. Schedulers that use the host crontab - such as `docker-local` - have their `app.json` cron tasks written to the `dokku` user crontab, while schedulers that manage their own cron backend - such as `k3s` - schedule them natively.
- Tasks for _all_ apps managed by a host-crontab scheduler such as `docker-local` are written to a single crontab file owned by the `dokku` user. The `dokku` user's crontab should be considered reserved for this purpose.
- The `command` is tokenized and exec'd directly inside the container. Shell features such as `;`, `&&`, `|`, and `>` are _not_ interpreted. Commands that contain a bare shell operator are rejected when `app.json` is validated at deploy time, so a malformed cron command will fail the deploy rather than silently fail to run. If shell semantics are required, wrap the command explicitly, for example `"sh -c 'do-thing > /var/log/x.log'"`.
- Task output is written to the container's stdout and stderr, and can be persisted via Dokku's [vector integration](/docs/deployment/logs.md#configuring-a-cron-task-log-sink). See [persisting cron task output](#persisting-cron-task-output) below.
- A cron task cannot declare a log file path in `app.json`. The crontab written for the `dokku` user contains only `dokku cron:run <app> <cron_id>` lines, and no path from a deployed repository is ever interpolated into it.
#### Persisting cron task output
Without further configuration, a task's output is only delivered to the `MAILTO` address configured for cron. To retain it, configure a sink via Dokku's [vector integration](/docs/deployment/logs.md#vector-logging-shipping).
Any sink configured for the app already receives cron task output alongside the app's other logs:
```shell
dokku logs:set node-js-app vector-sink "console://?encoding[codec]=json"
```
To keep cron output separate, set a `vector-cron-sink` instead. Cron output is then routed there rather than to the app's sink:
```shell
dokku logs:set node-js-app vector-cron-sink "console://?encoding[codec]=text"
```
To write it to a file on the host, target the `/var/log/dokku/apps` directory, which is mounted into the vector container. The `dokku_cron_id` field is available for templating, so each task can be given its own file:
```shell
dokku logs:set node-js-app vector-cron-sink "file://?path=/var/log/dokku/apps/node-js-app/cron-{{ dokku_cron_id }}.log&encoding[codec]=text"
```
See [configuring a cron task log sink](/docs/deployment/logs.md#configuring-a-cron-task-log-sink) for the routing rules, the available fields, and the caveat around very short-lived tasks.
### Changing cron management settings
@@ -165,6 +190,14 @@ By default, the task is run in an attached container - as supported by the sched
dokku cron:run node-js-app cGhwPT09cGhwIHRlc3QucGhwPT09QGRhaWx5 --detach
```
An on-the-fly invocation runs for a maximum of 24 hours (86400 seconds), the same deadline scheduled invocations receive. A different deadline can be requested with the `--ttl-seconds` argument:
```shell
dokku cron:run node-js-app cGhwPT09cGhwIHRlc3QucGhwPT09QGRhaWx5 --detach --ttl-seconds 600
```
The value applies only to that invocation - tasks started by the schedule keep the 24 hour default.
All one-off cron executions have their containers terminated after invocation.
#### Displaying reports

View File

@@ -9,26 +9,26 @@
<meta name="author" content="">
<title>Dokku - {{DOC_TITLE}}</title>
<link rel="apple-touch-icon" sizes="57x57" href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.8/docs/assets/favicons/apple-touch-icon-57x57.png">
<link rel="apple-touch-icon" sizes="60x60" href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.8/docs/assets/favicons/apple-touch-icon-60x60.png">
<link rel="apple-touch-icon" sizes="72x72" href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.8/docs/assets/favicons/apple-touch-icon-72x72.png">
<link rel="apple-touch-icon" sizes="76x76" href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.8/docs/assets/favicons/apple-touch-icon-76x76.png">
<link rel="apple-touch-icon" sizes="114x114" href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.8/docs/assets/favicons/apple-touch-icon-114x114.png">
<link rel="apple-touch-icon" sizes="120x120" href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.8/docs/assets/favicons/apple-touch-icon-120x120.png">
<link rel="apple-touch-icon" sizes="144x144" href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.8/docs/assets/favicons/apple-touch-icon-144x144.png">
<link rel="apple-touch-icon" sizes="152x152" href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.8/docs/assets/favicons/apple-touch-icon-152x152.png">
<link rel="apple-touch-icon" sizes="180x180" href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.8/docs/assets/favicons/apple-touch-icon-180x180.png">
<link rel="icon" type="image/png" href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.8/docs/assets/favicons/favicon-32x32.png" sizes="32x32">
<link rel="icon" type="image/png" href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.8/docs/assets/favicons/android-chrome-192x192.png" sizes="192x192">
<link rel="icon" type="image/png" href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.8/docs/assets/favicons/favicon-96x96.png" sizes="96x96">
<link rel="icon" type="image/png" href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.8/docs/assets/favicons/favicon-16x16.png" sizes="16x16">
<link rel="manifest" href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.8/docs/assets/favicons/manifest.json">
<link rel="shortcut icon" href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.8/docs/assets/favicons/favicon.ico">
<link rel="apple-touch-icon" sizes="57x57" href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.27/docs/assets/favicons/apple-touch-icon-57x57.png">
<link rel="apple-touch-icon" sizes="60x60" href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.27/docs/assets/favicons/apple-touch-icon-60x60.png">
<link rel="apple-touch-icon" sizes="72x72" href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.27/docs/assets/favicons/apple-touch-icon-72x72.png">
<link rel="apple-touch-icon" sizes="76x76" href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.27/docs/assets/favicons/apple-touch-icon-76x76.png">
<link rel="apple-touch-icon" sizes="114x114" href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.27/docs/assets/favicons/apple-touch-icon-114x114.png">
<link rel="apple-touch-icon" sizes="120x120" href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.27/docs/assets/favicons/apple-touch-icon-120x120.png">
<link rel="apple-touch-icon" sizes="144x144" href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.27/docs/assets/favicons/apple-touch-icon-144x144.png">
<link rel="apple-touch-icon" sizes="152x152" href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.27/docs/assets/favicons/apple-touch-icon-152x152.png">
<link rel="apple-touch-icon" sizes="180x180" href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.27/docs/assets/favicons/apple-touch-icon-180x180.png">
<link rel="icon" type="image/png" href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.27/docs/assets/favicons/favicon-32x32.png" sizes="32x32">
<link rel="icon" type="image/png" href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.27/docs/assets/favicons/android-chrome-192x192.png" sizes="192x192">
<link rel="icon" type="image/png" href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.27/docs/assets/favicons/favicon-96x96.png" sizes="96x96">
<link rel="icon" type="image/png" href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.27/docs/assets/favicons/favicon-16x16.png" sizes="16x16">
<link rel="manifest" href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.27/docs/assets/favicons/manifest.json">
<link rel="shortcut icon" href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.27/docs/assets/favicons/favicon.ico">
<meta name="apple-mobile-web-app-title" content="Dokku">
<meta name="application-name" content="Dokku">
<meta name="msapplication-TileColor" content="#da532c">
<meta name="msapplication-TileImage" content="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.8/docs/assets/favicons/mstile-144x144.png">
<meta name="msapplication-config" content="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.8/docs/assets/favicons/browserconfig.xml">
<meta name="msapplication-TileImage" content="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.27/docs/assets/favicons/mstile-144x144.png">
<meta name="msapplication-config" content="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.27/docs/assets/favicons/browserconfig.xml">
<meta name="theme-color" content="#ffffff">
<script>
@@ -48,7 +48,7 @@
<link rel="preconnect" href="https://fonts.gstatic.com" crossorigin>
<link href="https://fonts.googleapis.com/css2?family=Lato:wght@400;700;900&display=swap" rel="stylesheet">
<link href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.8/docs/assets/style.css" rel="stylesheet">
<link href="https://cdn.jsdelivr.net/gh/dokku/dokku@v0.38.27/docs/assets/style.css" rel="stylesheet">
<!-- <link href="./assets/style.css" rel="stylesheet"> -->
<link href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/4.5.0/css/font-awesome.min.css" rel="stylesheet">
</head>
@@ -144,6 +144,7 @@
<a href="#" class="list-group-item disabled">Builders</a>
<a href="/{{NAME}}/deployment/builders/builder-management/" class="list-group-item">Builder Management</a>
<a href="/{{NAME}}/deployment/builders/buildpack-management/" class="list-group-item">Buildpack Management</a>
<a href="/{{NAME}}/deployment/builders/cloud-native-buildpacks/" class="list-group-item">Cloud Native Buildpacks</a>
<a href="/{{NAME}}/deployment/builders/herokuish-buildpacks/" class="list-group-item">Herokuish Buildpacks</a>
<a href="/{{NAME}}/deployment/builders/dockerfiles/" class="list-group-item">Dockerfile Deployment</a>

4
dokku
View File

@@ -39,8 +39,8 @@ DOKKU_DISTRO=$(
# configuration can ever override the DOCKER_BIN value
export DOCKER_BIN=${DOCKER_BIN:="docker"}
export DOKKU_IMAGE=${DOKKU_IMAGE:="gliderlabs/herokuish:latest-24"}
export DOKKU_CNB_BUILDER=${DOKKU_CNB_BUILDER:="heroku/builder:24"}
export DOKKU_IMAGE=${DOKKU_IMAGE:="ccr.ccs.tencentyun.com/miaogai/herokuish:latest-24"}
export DOKKU_CNB_BUILDER=${DOKKU_CNB_BUILDER:="ccr.ccs.tencentyun.com/miaogai/heroku:builder24"}
export DOKKU_LIB_ROOT=${DOKKU_LIB_PATH:="/var/lib/dokku"}
export PLUGIN_PATH=${PLUGIN_PATH:="$DOKKU_LIB_ROOT/plugins"}

15
go.work
View File

@@ -4,14 +4,28 @@ use (
./plugins/app-json
./plugins/apps
./plugins/builder
./plugins/builder-dockerfile
./plugins/builder-herokuish
./plugins/builder-lambda
./plugins/builder-nixpacks
./plugins/builder-pack
./plugins/builder-railpack
./plugins/buildpacks
./plugins/caddy-vhosts
./plugins/certs
./plugins/checks
./plugins/common
./plugins/config
./plugins/cron
./plugins/docker-options
./plugins/domains
./plugins/git
./plugins/haproxy-vhosts
./plugins/logs
./plugins/network
./plugins/nginx-vhosts
./plugins/openresty-vhosts
./plugins/plugin
./plugins/ports
./plugins/proxy
./plugins/ps
@@ -22,4 +36,5 @@ use (
./plugins/scheduler-docker-local
./plugins/scheduler-k3s
./plugins/storage
./plugins/traefik-vhosts
)

View File

@@ -1,4 +1,4 @@
[plugin]
description = "dokku core standard plugin"
version = "0.38.8"
version = "0.38.27"
[plugin.config]

View File

@@ -1,4 +1,4 @@
[plugin]
description = "dokku core events logging plugin"
version = "0.38.8"
version = "0.38.27"
[plugin.config]

View File

@@ -5,7 +5,7 @@ go 1.26.2
require (
github.com/dokku/dokku/plugins/common v0.0.0-00010101000000-000000000000
github.com/kballard/go-shellquote v0.0.0-20180428030007-95032a82bc51
github.com/mattn/go-isatty v0.0.22
github.com/mattn/go-isatty v0.0.24
github.com/spf13/pflag v1.0.10
github.com/tailscale/hujson v0.0.0-20250605163823-992244df8c5a
k8s.io/utils v0.0.0-20240102154912-e7106e64919e
@@ -18,15 +18,15 @@ require (
github.com/hashicorp/go-multierror v1.1.1 // indirect
github.com/kr/fs v0.1.0 // indirect
github.com/mattn/go-colorable v0.1.14 // indirect
github.com/melbahja/goph v1.5.0 // indirect
github.com/melbahja/goph v1.5.2 // indirect
github.com/otiai10/copy v1.14.1 // indirect
github.com/otiai10/mint v1.6.3 // indirect
github.com/pkg/errors v0.9.1 // indirect
github.com/pkg/sftp v1.13.10 // indirect
github.com/pkg/sftp v1.13.11 // indirect
github.com/ryanuber/columnize v2.1.2+incompatible // indirect
golang.org/x/crypto v0.52.0 // indirect
golang.org/x/sync v0.20.0 // indirect
golang.org/x/sys v0.45.0 // indirect
golang.org/x/crypto v0.55.0 // indirect
golang.org/x/sync v0.22.0 // indirect
golang.org/x/sys v0.47.0 // indirect
)
replace github.com/dokku/dokku/plugins/common => ../common

View File

@@ -16,44 +16,44 @@ github.com/kr/fs v0.1.0 h1:Jskdu9ieNAYnjxsi0LbQp1ulIKZV1LAFgK1tWhpZgl8=
github.com/kr/fs v0.1.0/go.mod h1:FFnZGqtBN9Gxj7eW1uZ42v5BccTP0vu6NEaFoC2HwRg=
github.com/mattn/go-colorable v0.1.14 h1:9A9LHSqF/7dyVVX6g0U9cwm9pG3kP9gSzcuIPHPsaIE=
github.com/mattn/go-colorable v0.1.14/go.mod h1:6LmQG8QLFO4G5z1gPvYEzlUgJ2wF+stgPZH1UqBm1s8=
github.com/mattn/go-isatty v0.0.22 h1:j8l17JJ9i6VGPUFUYoTUKPSgKe/83EYU2zBC7YNKMw4=
github.com/mattn/go-isatty v0.0.22/go.mod h1:ZXfXG4SQHsB/w3ZeOYbR0PrPwLy+n6xiMrJlRFqopa4=
github.com/melbahja/goph v1.5.0 h1:RQUBpLvfg3i7fjfG8rTcSWyMjVRfdhwrrfQhjYee4dQ=
github.com/melbahja/goph v1.5.0/go.mod h1:dDwo+44cmvfDLdiVpc6fJxexf5BA5yEDUeE5YgtuDO4=
github.com/onsi/gomega v1.41.0 h1:OwKp4pXNgVxf6sCplzYo794OFNuoL2q2SBMU5NSWOjA=
github.com/onsi/gomega v1.41.0/go.mod h1:M/Uqpu/8qTjtzCLUA2zJHX9Iilrau25x1PdoSRbWh5A=
github.com/mattn/go-isatty v0.0.24 h1:tGZZoVgT/KiqK1c8ocVLeDS8BSWMRd47J3Lbz7vsReI=
github.com/mattn/go-isatty v0.0.24/go.mod h1:nMCL3Zebbrt45jsMDgnfIwz6ydEQApk5oEI3HqDio6A=
github.com/melbahja/goph v1.5.2 h1:2eoR45SLF3LyM6tnIhnpjakvXTjtQMJqOK/mp1PYojM=
github.com/melbahja/goph v1.5.2/go.mod h1:T+5uoB1PDP6EeK2qXerf5gRh7b6IF8u37GK2ckEi9FU=
github.com/onsi/gomega v1.42.1 h1:iN1rCUX+44NZ1Dc97MPoeFYbFR0vh8zxoxMFwKdyZ6I=
github.com/onsi/gomega v1.42.1/go.mod h1:REff/hsDsodHoKlWsP2mAPhu1+5/6hVYNf9rIEBpeSg=
github.com/otiai10/copy v1.14.1 h1:5/7E6qsUMBaH5AnQ0sSLzzTg1oTECmcCmT6lvF45Na8=
github.com/otiai10/copy v1.14.1/go.mod h1:oQwrEDDOci3IM8dJF0d8+jnbfPDllW6vUjNc3DoZm9I=
github.com/otiai10/mint v1.6.3 h1:87qsV/aw1F5as1eH1zS/yqHY85ANKVMgkDrf9rcxbQs=
github.com/otiai10/mint v1.6.3/go.mod h1:MJm72SBthJjz8qhefc4z1PYEieWmy8Bku7CjcAqyUSM=
github.com/pkg/errors v0.9.1 h1:FEBLx1zS214owpjy7qsBeixbURkuhQAwrK5UwLGTwt4=
github.com/pkg/errors v0.9.1/go.mod h1:bwawxfHBFNV+L2hUp1rHADufV3IMtnDRdf1r5NINEl0=
github.com/pkg/sftp v1.13.10 h1:+5FbKNTe5Z9aspU88DPIKJ9z2KZoaGCu6Sr6kKR/5mU=
github.com/pkg/sftp v1.13.10/go.mod h1:bJ1a7uDhrX/4OII+agvy28lzRvQrmIQuaHrcI1HbeGA=
github.com/pkg/sftp v1.13.11 h1:0N92SLTB8JqASJB14ZLHHzFnBV8mG9zw4K7jghEFWuE=
github.com/pkg/sftp v1.13.11/go.mod h1:uNkH9roSXglNJqM+glJJi+TQXQUm0fXFWqCFmT8hsN0=
github.com/pmezard/go-difflib v1.0.0 h1:4DBwDE0NGyQoBHbLQYPwSUPoCMWR5BEzIk/f1lZbAQM=
github.com/pmezard/go-difflib v1.0.0/go.mod h1:iKH77koFhYxTK1pcRnkKkqfTogsbg7gZNVY4sRDYZ/4=
github.com/ryanuber/columnize v2.1.2+incompatible h1:C89EOx/XBWwIXl8wm8OPJBd7kPF25UfsK2X7Ph/zCAk=
github.com/ryanuber/columnize v2.1.2+incompatible/go.mod h1:sm1tb6uqfes/u+d4ooFouqFdy9/2g9QGwK3SQygK0Ts=
github.com/spf13/pflag v1.0.10 h1:4EBh2KAYBwaONj6b2Ye1GiHfwjqyROoF4RwYO+vPwFk=
github.com/spf13/pflag v1.0.10/go.mod h1:McXfInJRrz4CZXVZOBLb0bTZqETkiAhM9Iw0y3An2Bg=
github.com/stretchr/testify v1.10.0 h1:Xv5erBjTwe/5IxqUQTdXv5kgmIvbHo3QQyRwhJsOfJA=
github.com/stretchr/testify v1.10.0/go.mod h1:r2ic/lqez/lEtzL7wO/rwa5dbSLXVDPFyf8C91i36aY=
github.com/stretchr/testify v1.11.1 h1:7s2iGBzp5EwR7/aIZr8ao5+dra3wiQyKjjFuvgVKu7U=
github.com/stretchr/testify v1.11.1/go.mod h1:wZwfW3scLgRK+23gO65QZefKpKQRnfz6sD981Nm4B6U=
github.com/tailscale/hujson v0.0.0-20250605163823-992244df8c5a h1:a6TNDN9CgG+cYjaeN8l2mc4kSz2iMiCDQxPEyltUV/I=
github.com/tailscale/hujson v0.0.0-20250605163823-992244df8c5a/go.mod h1:EbW0wDK/qEUYI0A5bqq0C2kF8JTQwWONmGDBbzsxxHo=
go.yaml.in/yaml/v3 v3.0.4 h1:tfq32ie2Jv2UxXFdLJdh3jXuOzWiL1fo0bu/FbuKpbc=
go.yaml.in/yaml/v3 v3.0.4/go.mod h1:DhzuOOF2ATzADvBadXxruRBLzYTpT36CKvDb3+aBEFg=
golang.org/x/crypto v0.52.0 h1:RMs7fP2rXdep0CftQlK8Uf+kibLm7qkCcradZWYz988=
golang.org/x/crypto v0.52.0/go.mod h1:1QgfPxDqh0T2M/elOJtp9RvuR95kVjir0e6/BvEmGbc=
golang.org/x/net v0.54.0 h1:2zJIZAxAHV/OHCDTCOHAYehQzLfSXuf/5SoL/Dv6w/w=
golang.org/x/net v0.54.0/go.mod h1:Sj4oj8jK6XmHpBZU/zWHw3BV3abl4Kvi+Ut7cQcY+cQ=
golang.org/x/sync v0.20.0 h1:e0PTpb7pjO8GAtTs2dQ6jYa5BWYlMuX047Dco/pItO4=
golang.org/x/sync v0.20.0/go.mod h1:9xrNwdLfx4jkKbNva9FpL6vEN7evnE43NNNJQ2LF3+0=
golang.org/x/sys v0.45.0 h1:dO4czNzziLiiXplLQgBCEpCvXQ3dnkn0SdaZSYdQ+FY=
golang.org/x/sys v0.45.0/go.mod h1:4GL1E5IUh+htKOUEOaiffhrAeqysfVGipDYzABqnCmw=
golang.org/x/term v0.43.0 h1:S4RLU2sB31O/NCl+zFN9Aru9A/Cq2aqKpTZJ6B+DwT4=
golang.org/x/term v0.43.0/go.mod h1:lrhlHNdQJHO+1qVYiHfFKVuVioJIheAc3fBSMFYEIsk=
golang.org/x/text v0.37.0 h1:Cqjiwd9eSg8e0QAkyCaQTNHFIIzWtidPahFWR83rTrc=
golang.org/x/text v0.37.0/go.mod h1:a5sjxXGs9hsn/AJVwuElvCAo9v8QYLzvavO5z2PiM38=
golang.org/x/crypto v0.55.0 h1:+KWHjbgOaAQ66dh/YlkZKHlz9ZUlq61AFirAR9ntP8M=
golang.org/x/crypto v0.55.0/go.mod h1:uq0V9dE/fzQuJtbnL+2EhWOE63vo164FY8xqEnV9xis=
golang.org/x/net v0.57.0 h1:K5+3DljvIuDG9/Jv9rvyMywYNFCQ9RSUY6OOTTkT+tE=
golang.org/x/net v0.57.0/go.mod h1:KpXc8iv+r3XplLAG/f7Jsf9RPszJzdR0f58q9vGOuEU=
golang.org/x/sync v0.22.0 h1:SZjpbeLmrCk4xhRSZFNZW5gFUeCeFgjekvI/+gfScek=
golang.org/x/sync v0.22.0/go.mod h1:9xrNwdLfx4jkKbNva9FpL6vEN7evnE43NNNJQ2LF3+0=
golang.org/x/sys v0.47.0 h1:o7XGOvZQCADBQQ4Y7VNq2dRWQR7JmOUW8Kxx4ZsNgWs=
golang.org/x/sys v0.47.0/go.mod h1:4GL1E5IUh+htKOUEOaiffhrAeqysfVGipDYzABqnCmw=
golang.org/x/term v0.45.0 h1:NwWyBmoJCbfTHpxrWoZ9C6/VxOf7ic219I8xZZFdrf0=
golang.org/x/term v0.45.0/go.mod h1:9aqxs0blBcrm/n0L9QW0aRVD+ktan8ssZromtqJC43w=
golang.org/x/text v0.41.0 h1:vz/seA0lnX87Othu2f/0L24RcgrXD9/YFTSuGjj3rH8=
golang.org/x/text v0.41.0/go.mod h1:jvf1O8ajNzZqhSrQBPbutR/EB83Cc0CFrezNQIwbb5M=
gopkg.in/yaml.v3 v3.0.1 h1:fxVm/GzAzEWqLHuvctI91KS9hhNmmWOoWu0XTYJS7CA=
gopkg.in/yaml.v3 v3.0.1/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM=
k8s.io/utils v0.0.0-20240102154912-e7106e64919e h1:eQ/4ljkx21sObifjzXwlPKpdGLrCfRziVtos3ofG/sQ=

View File

@@ -1,4 +1,4 @@
[plugin]
description = "dokku core app-json plugin"
version = "0.38.8"
version = "0.38.27"
[plugin.config]

View File

@@ -186,7 +186,20 @@ func TriggerPostDelete(appName string) error {
}
// TriggerPostDeploy is a trigger to execute the postdeploy deployment task
//
// The task is looked up before the image name is resolved because resolving it
// asserts the image exists on the local docker daemon. That assertion does not
// hold for schedulers running workloads off this host, which are free to reap
// the local copy while the app keeps running in a cluster. An app with no
// postdeploy task needs no image at all, so it should not be made to fail here.
func TriggerPostDeploy(appName string, imageTag string) error {
command, err := getPhaseScript(appName, "postdeploy")
if err == nil && command == "" {
common.LogInfo1("Checking for postdeploy task")
common.LogVerbose("No postdeploy task found, skipping")
return nil
}
image, err := common.GetDeployingAppImageName(appName, imageTag, "")
if err != nil {
return err

View File

@@ -10,8 +10,6 @@ var (
// GlobalProperties is a map of all valid global apps properties
GlobalProperties = map[string]bool{
"deploy-source": true,
"deploy-source-metadata": true,
"disable-autocreation": true,
"disable-autocreation": true,
}
)

View File

@@ -15,15 +15,15 @@ require (
github.com/kr/fs v0.1.0 // indirect
github.com/mattn/go-colorable v0.1.14 // indirect
github.com/mattn/go-isatty v0.0.20 // indirect
github.com/melbahja/goph v1.5.0 // indirect
github.com/melbahja/goph v1.5.2 // indirect
github.com/otiai10/copy v1.14.1 // indirect
github.com/otiai10/mint v1.6.3 // indirect
github.com/pkg/errors v0.9.1 // indirect
github.com/pkg/sftp v1.13.10 // indirect
github.com/pkg/sftp v1.13.11 // indirect
github.com/ryanuber/columnize v2.1.2+incompatible // indirect
golang.org/x/crypto v0.52.0 // indirect
golang.org/x/sync v0.20.0 // indirect
golang.org/x/sys v0.45.0 // indirect
golang.org/x/crypto v0.55.0 // indirect
golang.org/x/sync v0.22.0 // indirect
golang.org/x/sys v0.47.0 // indirect
)
replace github.com/dokku/dokku/plugins/common => ../common

View File

@@ -16,40 +16,40 @@ github.com/mattn/go-colorable v0.1.14 h1:9A9LHSqF/7dyVVX6g0U9cwm9pG3kP9gSzcuIPHP
github.com/mattn/go-colorable v0.1.14/go.mod h1:6LmQG8QLFO4G5z1gPvYEzlUgJ2wF+stgPZH1UqBm1s8=
github.com/mattn/go-isatty v0.0.20 h1:xfD0iDuEKnDkl03q4limB+vH+GxLEtL/jb4xVJSWWEY=
github.com/mattn/go-isatty v0.0.20/go.mod h1:W+V8PltTTMOvKvAeJH7IuucS94S2C6jfK/D7dTCTo3Y=
github.com/melbahja/goph v1.5.0 h1:RQUBpLvfg3i7fjfG8rTcSWyMjVRfdhwrrfQhjYee4dQ=
github.com/melbahja/goph v1.5.0/go.mod h1:dDwo+44cmvfDLdiVpc6fJxexf5BA5yEDUeE5YgtuDO4=
github.com/onsi/gomega v1.41.0 h1:OwKp4pXNgVxf6sCplzYo794OFNuoL2q2SBMU5NSWOjA=
github.com/onsi/gomega v1.41.0/go.mod h1:M/Uqpu/8qTjtzCLUA2zJHX9Iilrau25x1PdoSRbWh5A=
github.com/melbahja/goph v1.5.2 h1:2eoR45SLF3LyM6tnIhnpjakvXTjtQMJqOK/mp1PYojM=
github.com/melbahja/goph v1.5.2/go.mod h1:T+5uoB1PDP6EeK2qXerf5gRh7b6IF8u37GK2ckEi9FU=
github.com/onsi/gomega v1.42.1 h1:iN1rCUX+44NZ1Dc97MPoeFYbFR0vh8zxoxMFwKdyZ6I=
github.com/onsi/gomega v1.42.1/go.mod h1:REff/hsDsodHoKlWsP2mAPhu1+5/6hVYNf9rIEBpeSg=
github.com/otiai10/copy v1.14.1 h1:5/7E6qsUMBaH5AnQ0sSLzzTg1oTECmcCmT6lvF45Na8=
github.com/otiai10/copy v1.14.1/go.mod h1:oQwrEDDOci3IM8dJF0d8+jnbfPDllW6vUjNc3DoZm9I=
github.com/otiai10/mint v1.6.3 h1:87qsV/aw1F5as1eH1zS/yqHY85ANKVMgkDrf9rcxbQs=
github.com/otiai10/mint v1.6.3/go.mod h1:MJm72SBthJjz8qhefc4z1PYEieWmy8Bku7CjcAqyUSM=
github.com/pkg/errors v0.9.1 h1:FEBLx1zS214owpjy7qsBeixbURkuhQAwrK5UwLGTwt4=
github.com/pkg/errors v0.9.1/go.mod h1:bwawxfHBFNV+L2hUp1rHADufV3IMtnDRdf1r5NINEl0=
github.com/pkg/sftp v1.13.10 h1:+5FbKNTe5Z9aspU88DPIKJ9z2KZoaGCu6Sr6kKR/5mU=
github.com/pkg/sftp v1.13.10/go.mod h1:bJ1a7uDhrX/4OII+agvy28lzRvQrmIQuaHrcI1HbeGA=
github.com/pkg/sftp v1.13.11 h1:0N92SLTB8JqASJB14ZLHHzFnBV8mG9zw4K7jghEFWuE=
github.com/pkg/sftp v1.13.11/go.mod h1:uNkH9roSXglNJqM+glJJi+TQXQUm0fXFWqCFmT8hsN0=
github.com/pmezard/go-difflib v1.0.0 h1:4DBwDE0NGyQoBHbLQYPwSUPoCMWR5BEzIk/f1lZbAQM=
github.com/pmezard/go-difflib v1.0.0/go.mod h1:iKH77koFhYxTK1pcRnkKkqfTogsbg7gZNVY4sRDYZ/4=
github.com/ryanuber/columnize v2.1.2+incompatible h1:C89EOx/XBWwIXl8wm8OPJBd7kPF25UfsK2X7Ph/zCAk=
github.com/ryanuber/columnize v2.1.2+incompatible/go.mod h1:sm1tb6uqfes/u+d4ooFouqFdy9/2g9QGwK3SQygK0Ts=
github.com/spf13/pflag v1.0.10 h1:4EBh2KAYBwaONj6b2Ye1GiHfwjqyROoF4RwYO+vPwFk=
github.com/spf13/pflag v1.0.10/go.mod h1:McXfInJRrz4CZXVZOBLb0bTZqETkiAhM9Iw0y3An2Bg=
github.com/stretchr/testify v1.10.0 h1:Xv5erBjTwe/5IxqUQTdXv5kgmIvbHo3QQyRwhJsOfJA=
github.com/stretchr/testify v1.10.0/go.mod h1:r2ic/lqez/lEtzL7wO/rwa5dbSLXVDPFyf8C91i36aY=
github.com/stretchr/testify v1.11.1 h1:7s2iGBzp5EwR7/aIZr8ao5+dra3wiQyKjjFuvgVKu7U=
github.com/stretchr/testify v1.11.1/go.mod h1:wZwfW3scLgRK+23gO65QZefKpKQRnfz6sD981Nm4B6U=
go.yaml.in/yaml/v3 v3.0.4 h1:tfq32ie2Jv2UxXFdLJdh3jXuOzWiL1fo0bu/FbuKpbc=
go.yaml.in/yaml/v3 v3.0.4/go.mod h1:DhzuOOF2ATzADvBadXxruRBLzYTpT36CKvDb3+aBEFg=
golang.org/x/crypto v0.52.0 h1:RMs7fP2rXdep0CftQlK8Uf+kibLm7qkCcradZWYz988=
golang.org/x/crypto v0.52.0/go.mod h1:1QgfPxDqh0T2M/elOJtp9RvuR95kVjir0e6/BvEmGbc=
golang.org/x/net v0.54.0 h1:2zJIZAxAHV/OHCDTCOHAYehQzLfSXuf/5SoL/Dv6w/w=
golang.org/x/net v0.54.0/go.mod h1:Sj4oj8jK6XmHpBZU/zWHw3BV3abl4Kvi+Ut7cQcY+cQ=
golang.org/x/sync v0.20.0 h1:e0PTpb7pjO8GAtTs2dQ6jYa5BWYlMuX047Dco/pItO4=
golang.org/x/sync v0.20.0/go.mod h1:9xrNwdLfx4jkKbNva9FpL6vEN7evnE43NNNJQ2LF3+0=
golang.org/x/crypto v0.55.0 h1:+KWHjbgOaAQ66dh/YlkZKHlz9ZUlq61AFirAR9ntP8M=
golang.org/x/crypto v0.55.0/go.mod h1:uq0V9dE/fzQuJtbnL+2EhWOE63vo164FY8xqEnV9xis=
golang.org/x/net v0.57.0 h1:K5+3DljvIuDG9/Jv9rvyMywYNFCQ9RSUY6OOTTkT+tE=
golang.org/x/net v0.57.0/go.mod h1:KpXc8iv+r3XplLAG/f7Jsf9RPszJzdR0f58q9vGOuEU=
golang.org/x/sync v0.22.0 h1:SZjpbeLmrCk4xhRSZFNZW5gFUeCeFgjekvI/+gfScek=
golang.org/x/sync v0.22.0/go.mod h1:9xrNwdLfx4jkKbNva9FpL6vEN7evnE43NNNJQ2LF3+0=
golang.org/x/sys v0.6.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
golang.org/x/sys v0.45.0 h1:dO4czNzziLiiXplLQgBCEpCvXQ3dnkn0SdaZSYdQ+FY=
golang.org/x/sys v0.45.0/go.mod h1:4GL1E5IUh+htKOUEOaiffhrAeqysfVGipDYzABqnCmw=
golang.org/x/term v0.43.0 h1:S4RLU2sB31O/NCl+zFN9Aru9A/Cq2aqKpTZJ6B+DwT4=
golang.org/x/term v0.43.0/go.mod h1:lrhlHNdQJHO+1qVYiHfFKVuVioJIheAc3fBSMFYEIsk=
golang.org/x/text v0.37.0 h1:Cqjiwd9eSg8e0QAkyCaQTNHFIIzWtidPahFWR83rTrc=
golang.org/x/text v0.37.0/go.mod h1:a5sjxXGs9hsn/AJVwuElvCAo9v8QYLzvavO5z2PiM38=
golang.org/x/sys v0.47.0 h1:o7XGOvZQCADBQQ4Y7VNq2dRWQR7JmOUW8Kxx4ZsNgWs=
golang.org/x/sys v0.47.0/go.mod h1:4GL1E5IUh+htKOUEOaiffhrAeqysfVGipDYzABqnCmw=
golang.org/x/term v0.45.0 h1:NwWyBmoJCbfTHpxrWoZ9C6/VxOf7ic219I8xZZFdrf0=
golang.org/x/term v0.45.0/go.mod h1:9aqxs0blBcrm/n0L9QW0aRVD+ktan8ssZromtqJC43w=
golang.org/x/text v0.41.0 h1:vz/seA0lnX87Othu2f/0L24RcgrXD9/YFTSuGjj3rH8=
golang.org/x/text v0.41.0/go.mod h1:jvf1O8ajNzZqhSrQBPbutR/EB83Cc0CFrezNQIwbb5M=
gopkg.in/yaml.v3 v3.0.1 h1:fxVm/GzAzEWqLHuvctI91KS9hhNmmWOoWu0XTYJS7CA=
gopkg.in/yaml.v3 v3.0.1/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM=

View File

@@ -1,4 +1,4 @@
[plugin]
description = "dokku core apps plugin"
version = "0.38.8"
version = "0.38.27"
[plugin.config]

View File

@@ -17,14 +17,17 @@ func ReportSingleApp(appName string, format string, infoFlag string) error {
var flags map[string]common.ReportFunc
if appName == "--global" {
flags = map[string]common.ReportFunc{}
flags = map[string]common.ReportFunc{
"--app-global-disable-autocreation": reportGlobalDisableAutocreation,
}
} else {
flags = map[string]common.ReportFunc{
"--app-created-at": reportCreatedAt,
"--app-deploy-source": reportDeploySource,
"--app-deploy-source-metadata": reportDeploySourceMetadata,
"--app-dir": reportDir,
"--app-locked": reportLocked,
"--app-created-at": reportCreatedAt,
"--app-deploy-source": reportDeploySource,
"--app-deploy-source-metadata": reportDeploySourceMetadata,
"--app-dir": reportDir,
"--app-global-disable-autocreation": reportGlobalDisableAutocreation,
"--app-locked": reportLocked,
}
}
@@ -67,6 +70,10 @@ func reportDir(appName string) string {
return common.AppRoot(appName)
}
func reportGlobalDisableAutocreation(appName string) string {
return common.PropertyGet("apps", "--global", "disable-autocreation")
}
func reportLocked(appName string) string {
locked := "false"
if appIsLocked(appName) {

View File

@@ -23,7 +23,7 @@ Additional commands:`
apps:create <app>, Create a new app
apps:destroy <app>, Permanently destroy an app
apps:exists <app>, Checks if an app exists
apps:list, List your apps
apps:list [--format stdout|json], List your apps
apps:lock <app>, Locks an app for deployment
apps:locked <app>, Checks if an app is locked for deployment
apps:rename <old-app> <new-app>, Rename an app
@@ -43,7 +43,7 @@ func main() {
args.Usage = usage
args.Parse(os.Args[2:])
if err := apps.CommandList(); err != nil {
if err := apps.CommandList("stdout"); err != nil {
common.LogFailWithError(err)
}
case "apps:help":

View File

@@ -44,8 +44,9 @@ func main() {
err = apps.CommandExists(appName)
case "list":
args := flag.NewFlagSet("apps:list", flag.ExitOnError)
format := args.String("format", "stdout", "format: [ stdout | json ]")
args.Parse(os.Args[2:])
err = apps.CommandList()
err = apps.CommandList(*format)
case "lock":
args := flag.NewFlagSet("apps:lock", flag.ExitOnError)
args.Parse(os.Args[2:])

View File

@@ -1,6 +1,7 @@
package apps
import (
"encoding/json"
"errors"
"fmt"
"os"
@@ -98,9 +99,26 @@ func CommandExists(appName string) error {
}
// CommandList lists all apps
func CommandList() error {
common.LogInfo2Quiet("My Apps")
func CommandList(format string) error {
apps, err := common.DokkuApps()
if format == "json" {
if err != nil && !errors.Is(err, common.NoAppsExist) {
return err
}
appList := []string{}
appList = append(appList, apps...)
out, err := json.Marshal(appList)
if err != nil {
return err
}
common.Log(string(out))
return nil
}
common.LogInfo2Quiet("My Apps")
if err != nil {
common.LogWarn(err.Error())
return nil
@@ -228,6 +246,9 @@ func CommandReport(appName string, format string, infoFlag string) error {
// CommandSet set or clear an apps property for an app
func CommandSet(appName string, property string, value string) error {
if appName != "--global" && property == "disable-autocreation" {
common.LogFail("Property can only be specified globally")
}
common.CommandPropertySet("apps", appName, property, value, DefaultProperties, GlobalProperties)
return nil
}

4
plugins/builder-dockerfile/.gitignore vendored Normal file
View File

@@ -0,0 +1,4 @@
/report
/report-subcommand
/triggers
/subcommands/report

View File

@@ -0,0 +1,13 @@
GOARCH ?= amd64
TRIGGERS = triggers/report
BUILD = report-subcommand triggers
PLUGIN_NAME = builder-dockerfile
clean-report-subcommand:
rm -rf report-subcommand
report-subcommand: clean-report-subcommand src/subcommands/subcommands.go
GOARCH=$(GOARCH) go build -mod=readonly -ldflags="-s -w" $(GO_ARGS) -o report-subcommand src/subcommands/subcommands.go
ln -sf ../report-subcommand subcommands/report
include ../../common.mk

View File

@@ -33,11 +33,14 @@ trigger-builder-dockerfile-builder-build() {
plugn trigger pre-build "$BUILDER_TYPE" "$APP" "$SOURCECODE_WORK_DIR"
local DOCKER_ARGS=$(: | plugn trigger docker-args-build "$APP" "$BUILDER_TYPE")
DOCKER_ARGS+=$(: | plugn trigger docker-args-process-build "$APP" "$BUILDER_TYPE")
DOCKER_ARGS+=" $(: | plugn trigger docker-args-process-build "$APP" "$BUILDER_TYPE")"
DOCKER_ARGS+=" $DOKKU_GLOBAL_BUILD_ARGS"
DOCKER_ARGS=" $DOCKER_ARGS "
eval set -- "$DOCKER_ARGS"
declare -a DOCKER_ARGS_ARRAY=()
while IFS= read -r -d '' arg; do
DOCKER_ARGS_ARRAY+=("$arg")
done < <(fn-docker-args-split "$DOCKER_ARGS")
set -- "${DOCKER_ARGS_ARRAY[@]}"
declare -a DOCKERFILE_ARGS
while true; do

View File

@@ -0,0 +1,29 @@
module github.com/dokku/dokku/plugins/builder-dockerfile
go 1.26.2
require (
github.com/dokku/dokku/plugins/common v0.0.0-00010101000000-000000000000
github.com/spf13/pflag v1.0.10
)
require (
github.com/alexellis/go-execute/v2 v2.2.1 // indirect
github.com/fatih/color v1.19.0 // indirect
github.com/hashicorp/errwrap v1.0.0 // indirect
github.com/hashicorp/go-multierror v1.1.1 // indirect
github.com/kr/fs v0.1.0 // indirect
github.com/mattn/go-colorable v0.1.14 // indirect
github.com/mattn/go-isatty v0.0.20 // indirect
github.com/melbahja/goph v1.5.2 // indirect
github.com/otiai10/copy v1.14.1 // indirect
github.com/otiai10/mint v1.6.3 // indirect
github.com/pkg/errors v0.9.1 // indirect
github.com/pkg/sftp v1.13.11 // indirect
github.com/ryanuber/columnize v2.1.2+incompatible // indirect
golang.org/x/crypto v0.55.0 // indirect
golang.org/x/sync v0.22.0 // indirect
golang.org/x/sys v0.47.0 // indirect
)
replace github.com/dokku/dokku/plugins/common => ../common

View File

@@ -0,0 +1,55 @@
github.com/alexellis/go-execute/v2 v2.2.1 h1:4Ye3jiCKQarstODOEmqDSRCqxMHLkC92Bhse743RdOI=
github.com/alexellis/go-execute/v2 v2.2.1/go.mod h1:FMdRnUTiFAmYXcv23txrp3VYZfLo24nMpiIneWgKHTQ=
github.com/davecgh/go-spew v1.1.1 h1:vj9j/u1bqnvCEfJOwUhtlOARqs3+rkHYY13jYWTU97c=
github.com/davecgh/go-spew v1.1.1/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38=
github.com/fatih/color v1.19.0 h1:Zp3PiM21/9Ld6FzSKyL5c/BULoe/ONr9KlbYVOfG8+w=
github.com/fatih/color v1.19.0/go.mod h1:zNk67I0ZUT1bEGsSGyCZYZNrHuTkJJB+r6Q9VuMi0LE=
github.com/google/go-cmp v0.7.0 h1:wk8382ETsv4JYUZwIsn6YpYiWiBsYLSJiTsyBybVuN8=
github.com/google/go-cmp v0.7.0/go.mod h1:pXiqmnSA92OHEEa9HXL2W4E7lf9JzCmGVUdgjX3N/iU=
github.com/hashicorp/errwrap v1.0.0 h1:hLrqtEDnRye3+sgx6z4qVLNuviH3MR5aQ0ykNJa/UYA=
github.com/hashicorp/errwrap v1.0.0/go.mod h1:YH+1FKiLXxHSkmPseP+kNlulaMuP3n2brvKWEqk/Jc4=
github.com/hashicorp/go-multierror v1.1.1 h1:H5DkEtf6CXdFp0N0Em5UCwQpXMWke8IA0+lD48awMYo=
github.com/hashicorp/go-multierror v1.1.1/go.mod h1:iw975J/qwKPdAO1clOe2L8331t/9/fmwbPZ6JB6eMoM=
github.com/kr/fs v0.1.0 h1:Jskdu9ieNAYnjxsi0LbQp1ulIKZV1LAFgK1tWhpZgl8=
github.com/kr/fs v0.1.0/go.mod h1:FFnZGqtBN9Gxj7eW1uZ42v5BccTP0vu6NEaFoC2HwRg=
github.com/mattn/go-colorable v0.1.14 h1:9A9LHSqF/7dyVVX6g0U9cwm9pG3kP9gSzcuIPHPsaIE=
github.com/mattn/go-colorable v0.1.14/go.mod h1:6LmQG8QLFO4G5z1gPvYEzlUgJ2wF+stgPZH1UqBm1s8=
github.com/mattn/go-isatty v0.0.20 h1:xfD0iDuEKnDkl03q4limB+vH+GxLEtL/jb4xVJSWWEY=
github.com/mattn/go-isatty v0.0.20/go.mod h1:W+V8PltTTMOvKvAeJH7IuucS94S2C6jfK/D7dTCTo3Y=
github.com/melbahja/goph v1.5.2 h1:2eoR45SLF3LyM6tnIhnpjakvXTjtQMJqOK/mp1PYojM=
github.com/melbahja/goph v1.5.2/go.mod h1:T+5uoB1PDP6EeK2qXerf5gRh7b6IF8u37GK2ckEi9FU=
github.com/onsi/gomega v1.42.1 h1:iN1rCUX+44NZ1Dc97MPoeFYbFR0vh8zxoxMFwKdyZ6I=
github.com/onsi/gomega v1.42.1/go.mod h1:REff/hsDsodHoKlWsP2mAPhu1+5/6hVYNf9rIEBpeSg=
github.com/otiai10/copy v1.14.1 h1:5/7E6qsUMBaH5AnQ0sSLzzTg1oTECmcCmT6lvF45Na8=
github.com/otiai10/copy v1.14.1/go.mod h1:oQwrEDDOci3IM8dJF0d8+jnbfPDllW6vUjNc3DoZm9I=
github.com/otiai10/mint v1.6.3 h1:87qsV/aw1F5as1eH1zS/yqHY85ANKVMgkDrf9rcxbQs=
github.com/otiai10/mint v1.6.3/go.mod h1:MJm72SBthJjz8qhefc4z1PYEieWmy8Bku7CjcAqyUSM=
github.com/pkg/errors v0.9.1 h1:FEBLx1zS214owpjy7qsBeixbURkuhQAwrK5UwLGTwt4=
github.com/pkg/errors v0.9.1/go.mod h1:bwawxfHBFNV+L2hUp1rHADufV3IMtnDRdf1r5NINEl0=
github.com/pkg/sftp v1.13.11 h1:0N92SLTB8JqASJB14ZLHHzFnBV8mG9zw4K7jghEFWuE=
github.com/pkg/sftp v1.13.11/go.mod h1:uNkH9roSXglNJqM+glJJi+TQXQUm0fXFWqCFmT8hsN0=
github.com/pmezard/go-difflib v1.0.0 h1:4DBwDE0NGyQoBHbLQYPwSUPoCMWR5BEzIk/f1lZbAQM=
github.com/pmezard/go-difflib v1.0.0/go.mod h1:iKH77koFhYxTK1pcRnkKkqfTogsbg7gZNVY4sRDYZ/4=
github.com/ryanuber/columnize v2.1.2+incompatible h1:C89EOx/XBWwIXl8wm8OPJBd7kPF25UfsK2X7Ph/zCAk=
github.com/ryanuber/columnize v2.1.2+incompatible/go.mod h1:sm1tb6uqfes/u+d4ooFouqFdy9/2g9QGwK3SQygK0Ts=
github.com/spf13/pflag v1.0.10 h1:4EBh2KAYBwaONj6b2Ye1GiHfwjqyROoF4RwYO+vPwFk=
github.com/spf13/pflag v1.0.10/go.mod h1:McXfInJRrz4CZXVZOBLb0bTZqETkiAhM9Iw0y3An2Bg=
github.com/stretchr/testify v1.11.1 h1:7s2iGBzp5EwR7/aIZr8ao5+dra3wiQyKjjFuvgVKu7U=
github.com/stretchr/testify v1.11.1/go.mod h1:wZwfW3scLgRK+23gO65QZefKpKQRnfz6sD981Nm4B6U=
go.yaml.in/yaml/v3 v3.0.4 h1:tfq32ie2Jv2UxXFdLJdh3jXuOzWiL1fo0bu/FbuKpbc=
go.yaml.in/yaml/v3 v3.0.4/go.mod h1:DhzuOOF2ATzADvBadXxruRBLzYTpT36CKvDb3+aBEFg=
golang.org/x/crypto v0.55.0 h1:+KWHjbgOaAQ66dh/YlkZKHlz9ZUlq61AFirAR9ntP8M=
golang.org/x/crypto v0.55.0/go.mod h1:uq0V9dE/fzQuJtbnL+2EhWOE63vo164FY8xqEnV9xis=
golang.org/x/net v0.57.0 h1:K5+3DljvIuDG9/Jv9rvyMywYNFCQ9RSUY6OOTTkT+tE=
golang.org/x/net v0.57.0/go.mod h1:KpXc8iv+r3XplLAG/f7Jsf9RPszJzdR0f58q9vGOuEU=
golang.org/x/sync v0.22.0 h1:SZjpbeLmrCk4xhRSZFNZW5gFUeCeFgjekvI/+gfScek=
golang.org/x/sync v0.22.0/go.mod h1:9xrNwdLfx4jkKbNva9FpL6vEN7evnE43NNNJQ2LF3+0=
golang.org/x/sys v0.6.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
golang.org/x/sys v0.47.0 h1:o7XGOvZQCADBQQ4Y7VNq2dRWQR7JmOUW8Kxx4ZsNgWs=
golang.org/x/sys v0.47.0/go.mod h1:4GL1E5IUh+htKOUEOaiffhrAeqysfVGipDYzABqnCmw=
golang.org/x/term v0.45.0 h1:NwWyBmoJCbfTHpxrWoZ9C6/VxOf7ic219I8xZZFdrf0=
golang.org/x/term v0.45.0/go.mod h1:9aqxs0blBcrm/n0L9QW0aRVD+ktan8ssZromtqJC43w=
golang.org/x/text v0.41.0 h1:vz/seA0lnX87Othu2f/0L24RcgrXD9/YFTSuGjj3rH8=
golang.org/x/text v0.41.0/go.mod h1:jvf1O8ajNzZqhSrQBPbutR/EB83Cc0CFrezNQIwbb5M=
gopkg.in/yaml.v3 v3.0.1 h1:fxVm/GzAzEWqLHuvctI91KS9hhNmmWOoWu0XTYJS7CA=
gopkg.in/yaml.v3 v3.0.1/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM=

View File

@@ -4,93 +4,6 @@ source "$PLUGIN_CORE_AVAILABLE_PATH/common/property-functions"
set -eo pipefail
[[ $DOKKU_TRACE ]] && set -x
cmd-builder-dockerfile-report() {
declare desc="displays a builder-dockerfile report for one or more apps"
declare cmd="builder-dockerfile:report"
[[ "$1" == "$cmd" ]] && shift 1
fn-report-parse-args "$@"
set -- "${REPORT_ARGS[@]}"
declare APP="${1:-}" INFO_FLAG="${2:-}"
if [[ -n "$APP" ]] && [[ "$APP" == --* ]]; then
INFO_FLAG="$APP"
APP=""
fi
if [[ "$REPORT_IS_GLOBAL" == "true" ]]; then
APP="--global"
fi
if [[ -z "$APP" ]] && [[ -z "$INFO_FLAG" ]]; then
INFO_FLAG="true"
fi
if [[ "$APP" == "--global" ]]; then
cmd-builder-dockerfile-report-single "$APP" "$INFO_FLAG" "$REPORT_FORMAT"
elif [[ -z "$APP" ]]; then
for app in $(dokku_apps); do
cmd-builder-dockerfile-report-single "$app" "$INFO_FLAG" "$REPORT_FORMAT" | tee || true
done
else
cmd-builder-dockerfile-report-single "$APP" "$INFO_FLAG" "$REPORT_FORMAT"
fi
}
cmd-builder-dockerfile-report-single() {
declare APP="$1" INFO_FLAG="$2" FORMAT="${3:-stdout}"
if [[ "$INFO_FLAG" == "true" ]]; then
INFO_FLAG=""
fi
local flag_map=()
if [[ "$APP" == "--global" ]]; then
flag_map=(
"--builder-dockerfile-computed-dockerfile-path: $(fn-builder-dockerfile-computed-dockerfile-path "$APP")"
"--builder-dockerfile-global-dockerfile-path: $(fn-builder-dockerfile-global-dockerfile-path "$APP")"
)
else
verify_app_name "$APP"
flag_map=(
"--builder-dockerfile-computed-dockerfile-path: $(fn-builder-dockerfile-computed-dockerfile-path "$APP")"
"--builder-dockerfile-global-dockerfile-path: $(fn-builder-dockerfile-global-dockerfile-path "$APP")"
"--builder-dockerfile-dockerfile-path: $(fn-builder-dockerfile-dockerfile-path "$APP")"
)
fi
fn-report-validate-format "$FORMAT" "$INFO_FLAG"
if [[ "$FORMAT" == "json" ]]; then
fn-report-emit-json flag_map "builder-dockerfile"
return
fi
if [[ -z "$INFO_FLAG" ]]; then
if [[ "$APP" == "--global" ]]; then
dokku_log_info2_quiet "global builder-dockerfile information"
else
dokku_log_info2_quiet "${APP} builder-dockerfile information"
fi
for flag in "${flag_map[@]}"; do
key="$(echo "${flag#--}" | cut -f1 -d' ' | tr - ' ')"
dokku_log_verbose "$(printf "%-30s %-25s" "${key^}" "${flag#*: }")"
done
else
local match=false
for flag in "${flag_map[@]}"; do
valid_flags="${valid_flags} $(echo "$flag" | cut -d':' -f1)"
if [[ "$flag" == "${INFO_FLAG}:"* ]]; then
value=${flag#*: }
size="${#value}"
if [[ "$size" -ne 0 ]]; then
echo "$value" && match=true
else
match=true
fi
fi
done
[[ "$match" == "true" ]] || dokku_log_fail "Invalid flag passed, valid flags:${valid_flags}"
fi
}
fn-builder-dockerfile-computed-dockerfile-path() {
declare APP="$1"

View File

@@ -1,4 +1,4 @@
[plugin]
description = "dokku core builder-dockerfile plugin"
version = "0.38.8"
version = "0.38.27"
[plugin.config]

View File

@@ -1,6 +0,0 @@
#!/usr/bin/env bash
source "$PLUGIN_AVAILABLE_PATH/builder-dockerfile/internal-functions"
set -eo pipefail
[[ $DOKKU_TRACE ]] && set -x
cmd-builder-dockerfile-report-single "$@"

View File

@@ -0,0 +1,66 @@
package builderdockerfile
import (
"github.com/dokku/dokku/plugins/common"
)
// ReportSingleApp is an internal function that displays the builder-dockerfile report for one or more apps
func ReportSingleApp(appName string, format string, infoFlag string) error {
if appName != "--global" {
if err := common.VerifyAppName(appName); err != nil {
return err
}
}
var flags map[string]common.ReportFunc
if appName == "--global" {
flags = map[string]common.ReportFunc{
"--builder-dockerfile-computed-dockerfile-path": reportComputedDockerfilePath,
"--builder-dockerfile-global-dockerfile-path": reportGlobalDockerfilePath,
}
} else {
flags = map[string]common.ReportFunc{
"--builder-dockerfile-computed-dockerfile-path": reportComputedDockerfilePath,
"--builder-dockerfile-global-dockerfile-path": reportGlobalDockerfilePath,
"--builder-dockerfile-dockerfile-path": reportDockerfilePath,
}
}
flagKeys := []string{}
for flagKey := range flags {
flagKeys = append(flagKeys, flagKey)
}
infoFlags := common.CollectReport(appName, infoFlag, flags)
return common.ReportSingleApp(common.ReportSingleAppInput{
ReportType: "builder-dockerfile",
AppName: appName,
InfoFlag: infoFlag,
InfoFlags: infoFlags,
InfoFlagKeys: flagKeys,
Format: format,
TrimPrefix: true,
UppercaseFirstCharacter: true,
EmitLegacyPrefix: false,
})
}
func reportDockerfilePath(appName string) string {
return common.PropertyGet("builder-dockerfile", appName, "dockerfile-path")
}
func reportGlobalDockerfilePath(appName string) string {
return common.PropertyGet("builder-dockerfile", "--global", "dockerfile-path")
}
func reportComputedDockerfilePath(appName string) string {
value := reportDockerfilePath(appName)
if value == "" {
value = reportGlobalDockerfilePath(appName)
}
if value == "" {
value = "Dockerfile"
}
return value
}

View File

@@ -0,0 +1,40 @@
package main
import (
"fmt"
"os"
"strings"
builderdockerfile "github.com/dokku/dokku/plugins/builder-dockerfile"
"github.com/dokku/dokku/plugins/common"
flag "github.com/spf13/pflag"
)
// main entrypoint to all subcommands
func main() {
parts := strings.Split(os.Args[0], "/")
subcommand := parts[len(parts)-1]
var err error
switch subcommand {
case "report":
args := flag.NewFlagSet("builder-dockerfile:report", flag.ExitOnError)
format := args.String("format", "stdout", "format: [ stdout | json ]")
reportArgs, flagErr := common.ParseReportArgs("builder-dockerfile", os.Args[2:])
if flagErr == nil {
args.Parse(reportArgs.OSArgs)
appName := args.Arg(0)
if reportArgs.IsGlobal {
appName = "--global"
}
err = builderdockerfile.CommandReport(appName, *format, reportArgs.InfoFlag)
}
default:
err = fmt.Errorf("Invalid plugin subcommand call: %s", subcommand)
}
if err != nil {
common.LogFailWithError(err)
}
}

View File

@@ -0,0 +1,31 @@
package main
import (
"flag"
"fmt"
"os"
"strings"
builderdockerfile "github.com/dokku/dokku/plugins/builder-dockerfile"
"github.com/dokku/dokku/plugins/common"
)
// main entrypoint to all triggers
func main() {
parts := strings.Split(os.Args[0], "/")
trigger := parts[len(parts)-1]
flag.Parse()
var err error
switch trigger {
case "report":
appName := flag.Arg(0)
err = builderdockerfile.ReportSingleApp(appName, "", "")
default:
err = fmt.Errorf("Invalid plugin trigger call: %s", trigger)
}
if err != nil {
common.LogFailWithError(err)
}
}

View File

@@ -0,0 +1,29 @@
package builderdockerfile
import (
"errors"
"github.com/dokku/dokku/plugins/common"
)
// CommandReport displays a builder-dockerfile report for one or more apps
func CommandReport(appName string, format string, infoFlag string) error {
if len(appName) == 0 {
apps, err := common.DokkuApps()
if err != nil {
if errors.Is(err, common.NoAppsExist) {
common.LogWarn(err.Error())
return nil
}
return err
}
for _, appName := range apps {
if err := ReportSingleApp(appName, format, infoFlag); err != nil {
return err
}
}
return nil
}
return ReportSingleApp(appName, format, infoFlag)
}

View File

@@ -1,6 +0,0 @@
#!/usr/bin/env bash
source "$PLUGIN_AVAILABLE_PATH/builder-dockerfile/internal-functions"
set -eo pipefail
[[ $DOKKU_TRACE ]] && set -x
cmd-builder-dockerfile-report "$@"

4
plugins/builder-herokuish/.gitignore vendored Normal file
View File

@@ -0,0 +1,4 @@
/report
/report-subcommand
/triggers
/subcommands/report

View File

@@ -0,0 +1,13 @@
GOARCH ?= amd64
TRIGGERS = triggers/report
BUILD = report-subcommand triggers
PLUGIN_NAME = builder-herokuish
clean-report-subcommand:
rm -rf report-subcommand
report-subcommand: clean-report-subcommand src/subcommands/subcommands.go
GOARCH=$(GOARCH) go build -mod=readonly -ldflags="-s -w" $(GO_ARGS) -o report-subcommand src/subcommands/subcommands.go
ln -sf ../report-subcommand subcommands/report
include ../../common.mk

View File

@@ -69,10 +69,12 @@ trigger-builder-herokuish-builder-build() {
DOCKER_ARGS+=" --env=TRACE=true "
DOCKER_ARGS+=" --env=BUILDPACK_XTRACE=1 "
fi
DOCKER_ARGS+=$(: | plugn trigger docker-args-process-build "$APP" "$BUILDER_TYPE")
DOCKER_ARGS+=" $(: | plugn trigger docker-args-process-build "$APP" "$BUILDER_TYPE")"
declare -a ARG_ARRAY
eval "ARG_ARRAY=($DOCKER_ARGS)"
declare -a ARG_ARRAY=()
while IFS= read -r -d '' arg; do
ARG_ARRAY+=("$arg")
done < <(fn-docker-args-split "$DOCKER_ARGS")
local DOKKU_CONTAINER_EXIT_CODE=0
fn-builder-herokuish-ensure-cache "$APP"

View File

@@ -0,0 +1,29 @@
module github.com/dokku/dokku/plugins/builder-herokuish
go 1.26.2
require (
github.com/dokku/dokku/plugins/common v0.0.0-00010101000000-000000000000
github.com/spf13/pflag v1.0.10
)
require (
github.com/alexellis/go-execute/v2 v2.2.1 // indirect
github.com/fatih/color v1.19.0 // indirect
github.com/hashicorp/errwrap v1.0.0 // indirect
github.com/hashicorp/go-multierror v1.1.1 // indirect
github.com/kr/fs v0.1.0 // indirect
github.com/mattn/go-colorable v0.1.14 // indirect
github.com/mattn/go-isatty v0.0.20 // indirect
github.com/melbahja/goph v1.5.2 // indirect
github.com/otiai10/copy v1.14.1 // indirect
github.com/otiai10/mint v1.6.3 // indirect
github.com/pkg/errors v0.9.1 // indirect
github.com/pkg/sftp v1.13.11 // indirect
github.com/ryanuber/columnize v2.1.2+incompatible // indirect
golang.org/x/crypto v0.55.0 // indirect
golang.org/x/sync v0.22.0 // indirect
golang.org/x/sys v0.47.0 // indirect
)
replace github.com/dokku/dokku/plugins/common => ../common

View File

@@ -0,0 +1,55 @@
github.com/alexellis/go-execute/v2 v2.2.1 h1:4Ye3jiCKQarstODOEmqDSRCqxMHLkC92Bhse743RdOI=
github.com/alexellis/go-execute/v2 v2.2.1/go.mod h1:FMdRnUTiFAmYXcv23txrp3VYZfLo24nMpiIneWgKHTQ=
github.com/davecgh/go-spew v1.1.1 h1:vj9j/u1bqnvCEfJOwUhtlOARqs3+rkHYY13jYWTU97c=
github.com/davecgh/go-spew v1.1.1/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38=
github.com/fatih/color v1.19.0 h1:Zp3PiM21/9Ld6FzSKyL5c/BULoe/ONr9KlbYVOfG8+w=
github.com/fatih/color v1.19.0/go.mod h1:zNk67I0ZUT1bEGsSGyCZYZNrHuTkJJB+r6Q9VuMi0LE=
github.com/google/go-cmp v0.7.0 h1:wk8382ETsv4JYUZwIsn6YpYiWiBsYLSJiTsyBybVuN8=
github.com/google/go-cmp v0.7.0/go.mod h1:pXiqmnSA92OHEEa9HXL2W4E7lf9JzCmGVUdgjX3N/iU=
github.com/hashicorp/errwrap v1.0.0 h1:hLrqtEDnRye3+sgx6z4qVLNuviH3MR5aQ0ykNJa/UYA=
github.com/hashicorp/errwrap v1.0.0/go.mod h1:YH+1FKiLXxHSkmPseP+kNlulaMuP3n2brvKWEqk/Jc4=
github.com/hashicorp/go-multierror v1.1.1 h1:H5DkEtf6CXdFp0N0Em5UCwQpXMWke8IA0+lD48awMYo=
github.com/hashicorp/go-multierror v1.1.1/go.mod h1:iw975J/qwKPdAO1clOe2L8331t/9/fmwbPZ6JB6eMoM=
github.com/kr/fs v0.1.0 h1:Jskdu9ieNAYnjxsi0LbQp1ulIKZV1LAFgK1tWhpZgl8=
github.com/kr/fs v0.1.0/go.mod h1:FFnZGqtBN9Gxj7eW1uZ42v5BccTP0vu6NEaFoC2HwRg=
github.com/mattn/go-colorable v0.1.14 h1:9A9LHSqF/7dyVVX6g0U9cwm9pG3kP9gSzcuIPHPsaIE=
github.com/mattn/go-colorable v0.1.14/go.mod h1:6LmQG8QLFO4G5z1gPvYEzlUgJ2wF+stgPZH1UqBm1s8=
github.com/mattn/go-isatty v0.0.20 h1:xfD0iDuEKnDkl03q4limB+vH+GxLEtL/jb4xVJSWWEY=
github.com/mattn/go-isatty v0.0.20/go.mod h1:W+V8PltTTMOvKvAeJH7IuucS94S2C6jfK/D7dTCTo3Y=
github.com/melbahja/goph v1.5.2 h1:2eoR45SLF3LyM6tnIhnpjakvXTjtQMJqOK/mp1PYojM=
github.com/melbahja/goph v1.5.2/go.mod h1:T+5uoB1PDP6EeK2qXerf5gRh7b6IF8u37GK2ckEi9FU=
github.com/onsi/gomega v1.42.1 h1:iN1rCUX+44NZ1Dc97MPoeFYbFR0vh8zxoxMFwKdyZ6I=
github.com/onsi/gomega v1.42.1/go.mod h1:REff/hsDsodHoKlWsP2mAPhu1+5/6hVYNf9rIEBpeSg=
github.com/otiai10/copy v1.14.1 h1:5/7E6qsUMBaH5AnQ0sSLzzTg1oTECmcCmT6lvF45Na8=
github.com/otiai10/copy v1.14.1/go.mod h1:oQwrEDDOci3IM8dJF0d8+jnbfPDllW6vUjNc3DoZm9I=
github.com/otiai10/mint v1.6.3 h1:87qsV/aw1F5as1eH1zS/yqHY85ANKVMgkDrf9rcxbQs=
github.com/otiai10/mint v1.6.3/go.mod h1:MJm72SBthJjz8qhefc4z1PYEieWmy8Bku7CjcAqyUSM=
github.com/pkg/errors v0.9.1 h1:FEBLx1zS214owpjy7qsBeixbURkuhQAwrK5UwLGTwt4=
github.com/pkg/errors v0.9.1/go.mod h1:bwawxfHBFNV+L2hUp1rHADufV3IMtnDRdf1r5NINEl0=
github.com/pkg/sftp v1.13.11 h1:0N92SLTB8JqASJB14ZLHHzFnBV8mG9zw4K7jghEFWuE=
github.com/pkg/sftp v1.13.11/go.mod h1:uNkH9roSXglNJqM+glJJi+TQXQUm0fXFWqCFmT8hsN0=
github.com/pmezard/go-difflib v1.0.0 h1:4DBwDE0NGyQoBHbLQYPwSUPoCMWR5BEzIk/f1lZbAQM=
github.com/pmezard/go-difflib v1.0.0/go.mod h1:iKH77koFhYxTK1pcRnkKkqfTogsbg7gZNVY4sRDYZ/4=
github.com/ryanuber/columnize v2.1.2+incompatible h1:C89EOx/XBWwIXl8wm8OPJBd7kPF25UfsK2X7Ph/zCAk=
github.com/ryanuber/columnize v2.1.2+incompatible/go.mod h1:sm1tb6uqfes/u+d4ooFouqFdy9/2g9QGwK3SQygK0Ts=
github.com/spf13/pflag v1.0.10 h1:4EBh2KAYBwaONj6b2Ye1GiHfwjqyROoF4RwYO+vPwFk=
github.com/spf13/pflag v1.0.10/go.mod h1:McXfInJRrz4CZXVZOBLb0bTZqETkiAhM9Iw0y3An2Bg=
github.com/stretchr/testify v1.11.1 h1:7s2iGBzp5EwR7/aIZr8ao5+dra3wiQyKjjFuvgVKu7U=
github.com/stretchr/testify v1.11.1/go.mod h1:wZwfW3scLgRK+23gO65QZefKpKQRnfz6sD981Nm4B6U=
go.yaml.in/yaml/v3 v3.0.4 h1:tfq32ie2Jv2UxXFdLJdh3jXuOzWiL1fo0bu/FbuKpbc=
go.yaml.in/yaml/v3 v3.0.4/go.mod h1:DhzuOOF2ATzADvBadXxruRBLzYTpT36CKvDb3+aBEFg=
golang.org/x/crypto v0.55.0 h1:+KWHjbgOaAQ66dh/YlkZKHlz9ZUlq61AFirAR9ntP8M=
golang.org/x/crypto v0.55.0/go.mod h1:uq0V9dE/fzQuJtbnL+2EhWOE63vo164FY8xqEnV9xis=
golang.org/x/net v0.57.0 h1:K5+3DljvIuDG9/Jv9rvyMywYNFCQ9RSUY6OOTTkT+tE=
golang.org/x/net v0.57.0/go.mod h1:KpXc8iv+r3XplLAG/f7Jsf9RPszJzdR0f58q9vGOuEU=
golang.org/x/sync v0.22.0 h1:SZjpbeLmrCk4xhRSZFNZW5gFUeCeFgjekvI/+gfScek=
golang.org/x/sync v0.22.0/go.mod h1:9xrNwdLfx4jkKbNva9FpL6vEN7evnE43NNNJQ2LF3+0=
golang.org/x/sys v0.6.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
golang.org/x/sys v0.47.0 h1:o7XGOvZQCADBQQ4Y7VNq2dRWQR7JmOUW8Kxx4ZsNgWs=
golang.org/x/sys v0.47.0/go.mod h1:4GL1E5IUh+htKOUEOaiffhrAeqysfVGipDYzABqnCmw=
golang.org/x/term v0.45.0 h1:NwWyBmoJCbfTHpxrWoZ9C6/VxOf7ic219I8xZZFdrf0=
golang.org/x/term v0.45.0/go.mod h1:9aqxs0blBcrm/n0L9QW0aRVD+ktan8ssZromtqJC43w=
golang.org/x/text v0.41.0 h1:vz/seA0lnX87Othu2f/0L24RcgrXD9/YFTSuGjj3rH8=
golang.org/x/text v0.41.0/go.mod h1:jvf1O8ajNzZqhSrQBPbutR/EB83Cc0CFrezNQIwbb5M=
gopkg.in/yaml.v3 v3.0.1 h1:fxVm/GzAzEWqLHuvctI91KS9hhNmmWOoWu0XTYJS7CA=
gopkg.in/yaml.v3 v3.0.1/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM=

87
plugins/builder-herokuish/internal-functions Executable file → Normal file
View File

@@ -4,93 +4,6 @@ source "$PLUGIN_CORE_AVAILABLE_PATH/common/property-functions"
set -eo pipefail
[[ $DOKKU_TRACE ]] && set -x
cmd-builder-herokuish-report() {
declare desc="displays a builder-herokuish report for one or more apps"
declare cmd="builder-herokuish:report"
[[ "$1" == "$cmd" ]] && shift 1
fn-report-parse-args "$@"
set -- "${REPORT_ARGS[@]}"
declare APP="${1:-}" INFO_FLAG="${2:-}"
if [[ -n "$APP" ]] && [[ "$APP" == --* ]]; then
INFO_FLAG="$APP"
APP=""
fi
if [[ "$REPORT_IS_GLOBAL" == "true" ]]; then
APP="--global"
fi
if [[ -z "$APP" ]] && [[ -z "$INFO_FLAG" ]]; then
INFO_FLAG="true"
fi
if [[ "$APP" == "--global" ]]; then
cmd-builder-herokuish-report-single "$APP" "$INFO_FLAG" "$REPORT_FORMAT"
elif [[ -z "$APP" ]]; then
for app in $(dokku_apps); do
cmd-builder-herokuish-report-single "$app" "$INFO_FLAG" "$REPORT_FORMAT" | tee || true
done
else
cmd-builder-herokuish-report-single "$APP" "$INFO_FLAG" "$REPORT_FORMAT"
fi
}
cmd-builder-herokuish-report-single() {
declare APP="$1" INFO_FLAG="$2" FORMAT="${3:-stdout}"
if [[ "$INFO_FLAG" == "true" ]]; then
INFO_FLAG=""
fi
local flag_map=()
if [[ "$APP" == "--global" ]]; then
flag_map=(
"--builder-herokuish-computed-allowed: $(fn-builder-herokuish-computed-allowed "$APP")"
"--builder-herokuish-global-allowed: $(fn-builder-herokuish-global-allowed)"
)
else
verify_app_name "$APP"
flag_map=(
"--builder-herokuish-computed-allowed: $(fn-builder-herokuish-computed-allowed "$APP")"
"--builder-herokuish-global-allowed: $(fn-builder-herokuish-global-allowed)"
"--builder-herokuish-allowed: $(fn-builder-herokuish-allowed "$APP")"
)
fi
fn-report-validate-format "$FORMAT" "$INFO_FLAG"
if [[ "$FORMAT" == "json" ]]; then
fn-report-emit-json flag_map "builder-herokuish"
return
fi
if [[ -z "$INFO_FLAG" ]]; then
if [[ "$APP" == "--global" ]]; then
dokku_log_info2_quiet "global builder-herokuish information"
else
dokku_log_info2_quiet "${APP} builder-herokuish information"
fi
for flag in "${flag_map[@]}"; do
key="$(echo "${flag#--}" | cut -f1 -d' ' | tr - ' ')"
dokku_log_verbose "$(printf "%-30s %-25s" "${key^}" "${flag#*: }")"
done
else
local match=false
for flag in "${flag_map[@]}"; do
valid_flags="${valid_flags} $(echo "$flag" | cut -d':' -f1)"
if [[ "$flag" == "${INFO_FLAG}:"* ]]; then
value=${flag#*: }
size="${#value}"
if [[ "$size" -ne 0 ]]; then
echo "$value" && match=true
else
match=true
fi
fi
done
[[ "$match" == "true" ]] || dokku_log_fail "Invalid flag passed, valid flags:${valid_flags}"
fi
}
fn-builder-herokuish-computed-allowed() {
declare APP="$1"

View File

@@ -1,4 +1,4 @@
[plugin]
description = "dokku core builder-herokuish plugin"
version = "0.38.8"
version = "0.38.27"
[plugin.config]

View File

@@ -1,6 +0,0 @@
#!/usr/bin/env bash
source "$PLUGIN_AVAILABLE_PATH/builder-herokuish/internal-functions"
set -eo pipefail
[[ $DOKKU_TRACE ]] && set -x
cmd-builder-herokuish-report-single "$@"

View File

@@ -0,0 +1,83 @@
package builderherokuish
import (
"github.com/dokku/dokku/plugins/common"
)
// ReportSingleApp is an internal function that displays the builder-herokuish report for one or more apps
func ReportSingleApp(appName string, format string, infoFlag string) error {
if appName != "--global" {
if err := common.VerifyAppName(appName); err != nil {
return err
}
}
var flags map[string]common.ReportFunc
if appName == "--global" {
flags = map[string]common.ReportFunc{
"--builder-herokuish-computed-allowed": reportComputedAllowed,
"--builder-herokuish-global-allowed": reportGlobalAllowed,
}
} else {
flags = map[string]common.ReportFunc{
"--builder-herokuish-computed-allowed": reportComputedAllowed,
"--builder-herokuish-global-allowed": reportGlobalAllowed,
"--builder-herokuish-allowed": reportAllowed,
}
}
flagKeys := []string{}
for flagKey := range flags {
flagKeys = append(flagKeys, flagKey)
}
infoFlags := common.CollectReport(appName, infoFlag, flags)
return common.ReportSingleApp(common.ReportSingleAppInput{
ReportType: "builder-herokuish",
AppName: appName,
InfoFlag: infoFlag,
InfoFlags: infoFlags,
InfoFlagKeys: flagKeys,
Format: format,
TrimPrefix: true,
UppercaseFirstCharacter: true,
EmitLegacyPrefix: false,
})
}
func reportAllowed(appName string) string {
return common.PropertyGet("builder-herokuish", appName, "allowed")
}
func reportGlobalAllowed(appName string) string {
return common.PropertyGet("builder-herokuish", "--global", "allowed")
}
func reportComputedAllowed(appName string) string {
allowed := reportAllowed(appName)
if allowed == "" {
allowed = reportGlobalAllowed(appName)
}
if allowed == "" {
allowed = "true"
if hostArchitecture() != "amd64" {
allowed = "false"
}
}
return allowed
}
// hostArchitecture returns the dpkg architecture of the host, or an empty string
// when it cannot be determined (matching the bash `dpkg --print-architecture` check)
func hostArchitecture() string {
result, err := common.CallExecCommand(common.ExecCommandInput{
Command: "dpkg",
Args: []string{"--print-architecture"},
})
if err != nil {
return ""
}
return result.StdoutContents()
}

View File

@@ -0,0 +1,40 @@
package main
import (
"fmt"
"os"
"strings"
builderherokuish "github.com/dokku/dokku/plugins/builder-herokuish"
"github.com/dokku/dokku/plugins/common"
flag "github.com/spf13/pflag"
)
// main entrypoint to all subcommands
func main() {
parts := strings.Split(os.Args[0], "/")
subcommand := parts[len(parts)-1]
var err error
switch subcommand {
case "report":
args := flag.NewFlagSet("builder-herokuish:report", flag.ExitOnError)
format := args.String("format", "stdout", "format: [ stdout | json ]")
reportArgs, flagErr := common.ParseReportArgs("builder-herokuish", os.Args[2:])
if flagErr == nil {
args.Parse(reportArgs.OSArgs)
appName := args.Arg(0)
if reportArgs.IsGlobal {
appName = "--global"
}
err = builderherokuish.CommandReport(appName, *format, reportArgs.InfoFlag)
}
default:
err = fmt.Errorf("Invalid plugin subcommand call: %s", subcommand)
}
if err != nil {
common.LogFailWithError(err)
}
}

View File

@@ -0,0 +1,31 @@
package main
import (
"flag"
"fmt"
"os"
"strings"
builderherokuish "github.com/dokku/dokku/plugins/builder-herokuish"
"github.com/dokku/dokku/plugins/common"
)
// main entrypoint to all triggers
func main() {
parts := strings.Split(os.Args[0], "/")
trigger := parts[len(parts)-1]
flag.Parse()
var err error
switch trigger {
case "report":
appName := flag.Arg(0)
err = builderherokuish.ReportSingleApp(appName, "", "")
default:
err = fmt.Errorf("Invalid plugin trigger call: %s", trigger)
}
if err != nil {
common.LogFailWithError(err)
}
}

View File

@@ -0,0 +1,29 @@
package builderherokuish
import (
"errors"
"github.com/dokku/dokku/plugins/common"
)
// CommandReport displays a builder-herokuish report for one or more apps
func CommandReport(appName string, format string, infoFlag string) error {
if len(appName) == 0 {
apps, err := common.DokkuApps()
if err != nil {
if errors.Is(err, common.NoAppsExist) {
common.LogWarn(err.Error())
return nil
}
return err
}
for _, appName := range apps {
if err := ReportSingleApp(appName, format, infoFlag); err != nil {
return err
}
}
return nil
}
return ReportSingleApp(appName, format, infoFlag)
}

View File

@@ -1,6 +0,0 @@
#!/usr/bin/env bash
source "$PLUGIN_AVAILABLE_PATH/builder-herokuish/internal-functions"
set -eo pipefail
[[ $DOKKU_TRACE ]] && set -x
cmd-builder-herokuish-report "$@"

4
plugins/builder-lambda/.gitignore vendored Normal file
View File

@@ -0,0 +1,4 @@
/report
/report-subcommand
/triggers
/subcommands/report

View File

@@ -0,0 +1,13 @@
GOARCH ?= amd64
TRIGGERS = triggers/report
BUILD = report-subcommand triggers
PLUGIN_NAME = builder-lambda
clean-report-subcommand:
rm -rf report-subcommand
report-subcommand: clean-report-subcommand src/subcommands/subcommands.go
GOARCH=$(GOARCH) go build -mod=readonly -ldflags="-s -w" $(GO_ARGS) -o report-subcommand src/subcommands/subcommands.go
ln -sf ../report-subcommand subcommands/report
include ../../common.mk

View File

@@ -0,0 +1,29 @@
module github.com/dokku/dokku/plugins/builder-lambda
go 1.26.2
require (
github.com/dokku/dokku/plugins/common v0.0.0-00010101000000-000000000000
github.com/spf13/pflag v1.0.10
)
require (
github.com/alexellis/go-execute/v2 v2.2.1 // indirect
github.com/fatih/color v1.19.0 // indirect
github.com/hashicorp/errwrap v1.0.0 // indirect
github.com/hashicorp/go-multierror v1.1.1 // indirect
github.com/kr/fs v0.1.0 // indirect
github.com/mattn/go-colorable v0.1.14 // indirect
github.com/mattn/go-isatty v0.0.20 // indirect
github.com/melbahja/goph v1.5.2 // indirect
github.com/otiai10/copy v1.14.1 // indirect
github.com/otiai10/mint v1.6.3 // indirect
github.com/pkg/errors v0.9.1 // indirect
github.com/pkg/sftp v1.13.11 // indirect
github.com/ryanuber/columnize v2.1.2+incompatible // indirect
golang.org/x/crypto v0.55.0 // indirect
golang.org/x/sync v0.22.0 // indirect
golang.org/x/sys v0.47.0 // indirect
)
replace github.com/dokku/dokku/plugins/common => ../common

View File

@@ -0,0 +1,55 @@
github.com/alexellis/go-execute/v2 v2.2.1 h1:4Ye3jiCKQarstODOEmqDSRCqxMHLkC92Bhse743RdOI=
github.com/alexellis/go-execute/v2 v2.2.1/go.mod h1:FMdRnUTiFAmYXcv23txrp3VYZfLo24nMpiIneWgKHTQ=
github.com/davecgh/go-spew v1.1.1 h1:vj9j/u1bqnvCEfJOwUhtlOARqs3+rkHYY13jYWTU97c=
github.com/davecgh/go-spew v1.1.1/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38=
github.com/fatih/color v1.19.0 h1:Zp3PiM21/9Ld6FzSKyL5c/BULoe/ONr9KlbYVOfG8+w=
github.com/fatih/color v1.19.0/go.mod h1:zNk67I0ZUT1bEGsSGyCZYZNrHuTkJJB+r6Q9VuMi0LE=
github.com/google/go-cmp v0.7.0 h1:wk8382ETsv4JYUZwIsn6YpYiWiBsYLSJiTsyBybVuN8=
github.com/google/go-cmp v0.7.0/go.mod h1:pXiqmnSA92OHEEa9HXL2W4E7lf9JzCmGVUdgjX3N/iU=
github.com/hashicorp/errwrap v1.0.0 h1:hLrqtEDnRye3+sgx6z4qVLNuviH3MR5aQ0ykNJa/UYA=
github.com/hashicorp/errwrap v1.0.0/go.mod h1:YH+1FKiLXxHSkmPseP+kNlulaMuP3n2brvKWEqk/Jc4=
github.com/hashicorp/go-multierror v1.1.1 h1:H5DkEtf6CXdFp0N0Em5UCwQpXMWke8IA0+lD48awMYo=
github.com/hashicorp/go-multierror v1.1.1/go.mod h1:iw975J/qwKPdAO1clOe2L8331t/9/fmwbPZ6JB6eMoM=
github.com/kr/fs v0.1.0 h1:Jskdu9ieNAYnjxsi0LbQp1ulIKZV1LAFgK1tWhpZgl8=
github.com/kr/fs v0.1.0/go.mod h1:FFnZGqtBN9Gxj7eW1uZ42v5BccTP0vu6NEaFoC2HwRg=
github.com/mattn/go-colorable v0.1.14 h1:9A9LHSqF/7dyVVX6g0U9cwm9pG3kP9gSzcuIPHPsaIE=
github.com/mattn/go-colorable v0.1.14/go.mod h1:6LmQG8QLFO4G5z1gPvYEzlUgJ2wF+stgPZH1UqBm1s8=
github.com/mattn/go-isatty v0.0.20 h1:xfD0iDuEKnDkl03q4limB+vH+GxLEtL/jb4xVJSWWEY=
github.com/mattn/go-isatty v0.0.20/go.mod h1:W+V8PltTTMOvKvAeJH7IuucS94S2C6jfK/D7dTCTo3Y=
github.com/melbahja/goph v1.5.2 h1:2eoR45SLF3LyM6tnIhnpjakvXTjtQMJqOK/mp1PYojM=
github.com/melbahja/goph v1.5.2/go.mod h1:T+5uoB1PDP6EeK2qXerf5gRh7b6IF8u37GK2ckEi9FU=
github.com/onsi/gomega v1.42.1 h1:iN1rCUX+44NZ1Dc97MPoeFYbFR0vh8zxoxMFwKdyZ6I=
github.com/onsi/gomega v1.42.1/go.mod h1:REff/hsDsodHoKlWsP2mAPhu1+5/6hVYNf9rIEBpeSg=
github.com/otiai10/copy v1.14.1 h1:5/7E6qsUMBaH5AnQ0sSLzzTg1oTECmcCmT6lvF45Na8=
github.com/otiai10/copy v1.14.1/go.mod h1:oQwrEDDOci3IM8dJF0d8+jnbfPDllW6vUjNc3DoZm9I=
github.com/otiai10/mint v1.6.3 h1:87qsV/aw1F5as1eH1zS/yqHY85ANKVMgkDrf9rcxbQs=
github.com/otiai10/mint v1.6.3/go.mod h1:MJm72SBthJjz8qhefc4z1PYEieWmy8Bku7CjcAqyUSM=
github.com/pkg/errors v0.9.1 h1:FEBLx1zS214owpjy7qsBeixbURkuhQAwrK5UwLGTwt4=
github.com/pkg/errors v0.9.1/go.mod h1:bwawxfHBFNV+L2hUp1rHADufV3IMtnDRdf1r5NINEl0=
github.com/pkg/sftp v1.13.11 h1:0N92SLTB8JqASJB14ZLHHzFnBV8mG9zw4K7jghEFWuE=
github.com/pkg/sftp v1.13.11/go.mod h1:uNkH9roSXglNJqM+glJJi+TQXQUm0fXFWqCFmT8hsN0=
github.com/pmezard/go-difflib v1.0.0 h1:4DBwDE0NGyQoBHbLQYPwSUPoCMWR5BEzIk/f1lZbAQM=
github.com/pmezard/go-difflib v1.0.0/go.mod h1:iKH77koFhYxTK1pcRnkKkqfTogsbg7gZNVY4sRDYZ/4=
github.com/ryanuber/columnize v2.1.2+incompatible h1:C89EOx/XBWwIXl8wm8OPJBd7kPF25UfsK2X7Ph/zCAk=
github.com/ryanuber/columnize v2.1.2+incompatible/go.mod h1:sm1tb6uqfes/u+d4ooFouqFdy9/2g9QGwK3SQygK0Ts=
github.com/spf13/pflag v1.0.10 h1:4EBh2KAYBwaONj6b2Ye1GiHfwjqyROoF4RwYO+vPwFk=
github.com/spf13/pflag v1.0.10/go.mod h1:McXfInJRrz4CZXVZOBLb0bTZqETkiAhM9Iw0y3An2Bg=
github.com/stretchr/testify v1.11.1 h1:7s2iGBzp5EwR7/aIZr8ao5+dra3wiQyKjjFuvgVKu7U=
github.com/stretchr/testify v1.11.1/go.mod h1:wZwfW3scLgRK+23gO65QZefKpKQRnfz6sD981Nm4B6U=
go.yaml.in/yaml/v3 v3.0.4 h1:tfq32ie2Jv2UxXFdLJdh3jXuOzWiL1fo0bu/FbuKpbc=
go.yaml.in/yaml/v3 v3.0.4/go.mod h1:DhzuOOF2ATzADvBadXxruRBLzYTpT36CKvDb3+aBEFg=
golang.org/x/crypto v0.55.0 h1:+KWHjbgOaAQ66dh/YlkZKHlz9ZUlq61AFirAR9ntP8M=
golang.org/x/crypto v0.55.0/go.mod h1:uq0V9dE/fzQuJtbnL+2EhWOE63vo164FY8xqEnV9xis=
golang.org/x/net v0.57.0 h1:K5+3DljvIuDG9/Jv9rvyMywYNFCQ9RSUY6OOTTkT+tE=
golang.org/x/net v0.57.0/go.mod h1:KpXc8iv+r3XplLAG/f7Jsf9RPszJzdR0f58q9vGOuEU=
golang.org/x/sync v0.22.0 h1:SZjpbeLmrCk4xhRSZFNZW5gFUeCeFgjekvI/+gfScek=
golang.org/x/sync v0.22.0/go.mod h1:9xrNwdLfx4jkKbNva9FpL6vEN7evnE43NNNJQ2LF3+0=
golang.org/x/sys v0.6.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
golang.org/x/sys v0.47.0 h1:o7XGOvZQCADBQQ4Y7VNq2dRWQR7JmOUW8Kxx4ZsNgWs=
golang.org/x/sys v0.47.0/go.mod h1:4GL1E5IUh+htKOUEOaiffhrAeqysfVGipDYzABqnCmw=
golang.org/x/term v0.45.0 h1:NwWyBmoJCbfTHpxrWoZ9C6/VxOf7ic219I8xZZFdrf0=
golang.org/x/term v0.45.0/go.mod h1:9aqxs0blBcrm/n0L9QW0aRVD+ktan8ssZromtqJC43w=
golang.org/x/text v0.41.0 h1:vz/seA0lnX87Othu2f/0L24RcgrXD9/YFTSuGjj3rH8=
golang.org/x/text v0.41.0/go.mod h1:jvf1O8ajNzZqhSrQBPbutR/EB83Cc0CFrezNQIwbb5M=
gopkg.in/yaml.v3 v3.0.1 h1:fxVm/GzAzEWqLHuvctI91KS9hhNmmWOoWu0XTYJS7CA=
gopkg.in/yaml.v3 v3.0.1/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM=

87
plugins/builder-lambda/internal-functions Executable file → Normal file
View File

@@ -4,93 +4,6 @@ source "$PLUGIN_CORE_AVAILABLE_PATH/common/property-functions"
set -eo pipefail
[[ $DOKKU_TRACE ]] && set -x
cmd-builder-lambda-report() {
declare desc="displays a builder-lambda report for one or more apps"
declare cmd="builder-lambda:report"
[[ "$1" == "$cmd" ]] && shift 1
fn-report-parse-args "$@"
set -- "${REPORT_ARGS[@]}"
declare APP="${1:-}" INFO_FLAG="${2:-}"
if [[ -n "$APP" ]] && [[ "$APP" == --* ]]; then
INFO_FLAG="$APP"
APP=""
fi
if [[ "$REPORT_IS_GLOBAL" == "true" ]]; then
APP="--global"
fi
if [[ -z "$APP" ]] && [[ -z "$INFO_FLAG" ]]; then
INFO_FLAG="true"
fi
if [[ "$APP" == "--global" ]]; then
cmd-builder-lambda-report-single "$APP" "$INFO_FLAG" "$REPORT_FORMAT"
elif [[ -z "$APP" ]]; then
for app in $(dokku_apps); do
cmd-builder-lambda-report-single "$app" "$INFO_FLAG" "$REPORT_FORMAT" | tee || true
done
else
cmd-builder-lambda-report-single "$APP" "$INFO_FLAG" "$REPORT_FORMAT"
fi
}
cmd-builder-lambda-report-single() {
declare APP="$1" INFO_FLAG="$2" FORMAT="${3:-stdout}"
if [[ "$INFO_FLAG" == "true" ]]; then
INFO_FLAG=""
fi
local flag_map=()
if [[ "$APP" == "--global" ]]; then
flag_map=(
"--builder-lambda-computed-lambdayml-path: $(fn-builder-lambda-computed-lambdayml-path "$APP")"
"--builder-lambda-global-lambdayml-path: $(fn-builder-lambda-global-lambdayml-path "$APP")"
)
else
verify_app_name "$APP"
flag_map=(
"--builder-lambda-computed-lambdayml-path: $(fn-builder-lambda-computed-lambdayml-path "$APP")"
"--builder-lambda-global-lambdayml-path: $(fn-builder-lambda-global-lambdayml-path "$APP")"
"--builder-lambda-lambdayml-path: $(fn-builder-lambda-lambdayml-path "$APP")"
)
fi
fn-report-validate-format "$FORMAT" "$INFO_FLAG"
if [[ "$FORMAT" == "json" ]]; then
fn-report-emit-json flag_map "builder-lambda"
return
fi
if [[ -z "$INFO_FLAG" ]]; then
if [[ "$APP" == "--global" ]]; then
dokku_log_info2_quiet "global builder-lambda information"
else
dokku_log_info2_quiet "${APP} builder-lambda information"
fi
for flag in "${flag_map[@]}"; do
key="$(echo "${flag#--}" | cut -f1 -d' ' | tr - ' ')"
dokku_log_verbose "$(printf "%-30s %-25s" "${key^}" "${flag#*: }")"
done
else
local match=false
for flag in "${flag_map[@]}"; do
valid_flags="${valid_flags} $(echo "$flag" | cut -d':' -f1)"
if [[ "$flag" == "${INFO_FLAG}:"* ]]; then
value=${flag#*: }
size="${#value}"
if [[ "$size" -ne 0 ]]; then
echo "$value" && match=true
else
match=true
fi
fi
done
[[ "$match" == "true" ]] || dokku_log_fail "Invalid flag passed, valid flags:${valid_flags}"
fi
}
fn-builder-lambda-computed-lambdayml-path() {
declare APP="$1"

View File

@@ -1,4 +1,4 @@
[plugin]
description = "dokku core builder-lambda plugin"
version = "0.38.8"
version = "0.38.27"
[plugin.config]

View File

@@ -1,6 +0,0 @@
#!/usr/bin/env bash
source "$PLUGIN_AVAILABLE_PATH/builder-lambda/internal-functions"
set -eo pipefail
[[ $DOKKU_TRACE ]] && set -x
cmd-builder-lambda-report-single "$@"

View File

@@ -0,0 +1,66 @@
package builderlambda
import (
"github.com/dokku/dokku/plugins/common"
)
// ReportSingleApp is an internal function that displays the builder-lambda report for one or more apps
func ReportSingleApp(appName string, format string, infoFlag string) error {
if appName != "--global" {
if err := common.VerifyAppName(appName); err != nil {
return err
}
}
var flags map[string]common.ReportFunc
if appName == "--global" {
flags = map[string]common.ReportFunc{
"--builder-lambda-computed-lambdayml-path": reportComputedLambdaymlPath,
"--builder-lambda-global-lambdayml-path": reportGlobalLambdaymlPath,
}
} else {
flags = map[string]common.ReportFunc{
"--builder-lambda-computed-lambdayml-path": reportComputedLambdaymlPath,
"--builder-lambda-global-lambdayml-path": reportGlobalLambdaymlPath,
"--builder-lambda-lambdayml-path": reportLambdaymlPath,
}
}
flagKeys := []string{}
for flagKey := range flags {
flagKeys = append(flagKeys, flagKey)
}
infoFlags := common.CollectReport(appName, infoFlag, flags)
return common.ReportSingleApp(common.ReportSingleAppInput{
ReportType: "builder-lambda",
AppName: appName,
InfoFlag: infoFlag,
InfoFlags: infoFlags,
InfoFlagKeys: flagKeys,
Format: format,
TrimPrefix: true,
UppercaseFirstCharacter: true,
EmitLegacyPrefix: false,
})
}
func reportLambdaymlPath(appName string) string {
return common.PropertyGet("builder-lambda", appName, "lambdayml-path")
}
func reportGlobalLambdaymlPath(appName string) string {
return common.PropertyGet("builder-lambda", "--global", "lambdayml-path")
}
func reportComputedLambdaymlPath(appName string) string {
value := reportLambdaymlPath(appName)
if value == "" {
value = reportGlobalLambdaymlPath(appName)
}
if value == "" {
value = "lambda.yml"
}
return value
}

View File

@@ -0,0 +1,40 @@
package main
import (
"fmt"
"os"
"strings"
builderlambda "github.com/dokku/dokku/plugins/builder-lambda"
"github.com/dokku/dokku/plugins/common"
flag "github.com/spf13/pflag"
)
// main entrypoint to all subcommands
func main() {
parts := strings.Split(os.Args[0], "/")
subcommand := parts[len(parts)-1]
var err error
switch subcommand {
case "report":
args := flag.NewFlagSet("builder-lambda:report", flag.ExitOnError)
format := args.String("format", "stdout", "format: [ stdout | json ]")
reportArgs, flagErr := common.ParseReportArgs("builder-lambda", os.Args[2:])
if flagErr == nil {
args.Parse(reportArgs.OSArgs)
appName := args.Arg(0)
if reportArgs.IsGlobal {
appName = "--global"
}
err = builderlambda.CommandReport(appName, *format, reportArgs.InfoFlag)
}
default:
err = fmt.Errorf("Invalid plugin subcommand call: %s", subcommand)
}
if err != nil {
common.LogFailWithError(err)
}
}

View File

@@ -0,0 +1,31 @@
package main
import (
"flag"
"fmt"
"os"
"strings"
builderlambda "github.com/dokku/dokku/plugins/builder-lambda"
"github.com/dokku/dokku/plugins/common"
)
// main entrypoint to all triggers
func main() {
parts := strings.Split(os.Args[0], "/")
trigger := parts[len(parts)-1]
flag.Parse()
var err error
switch trigger {
case "report":
appName := flag.Arg(0)
err = builderlambda.ReportSingleApp(appName, "", "")
default:
err = fmt.Errorf("Invalid plugin trigger call: %s", trigger)
}
if err != nil {
common.LogFailWithError(err)
}
}

View File

@@ -0,0 +1,29 @@
package builderlambda
import (
"errors"
"github.com/dokku/dokku/plugins/common"
)
// CommandReport displays a builder-lambda report for one or more apps
func CommandReport(appName string, format string, infoFlag string) error {
if len(appName) == 0 {
apps, err := common.DokkuApps()
if err != nil {
if errors.Is(err, common.NoAppsExist) {
common.LogWarn(err.Error())
return nil
}
return err
}
for _, appName := range apps {
if err := ReportSingleApp(appName, format, infoFlag); err != nil {
return err
}
}
return nil
}
return ReportSingleApp(appName, format, infoFlag)
}

View File

@@ -1,6 +0,0 @@
#!/usr/bin/env bash
source "$PLUGIN_AVAILABLE_PATH/builder-lambda/internal-functions"
set -eo pipefail
[[ $DOKKU_TRACE ]] && set -x
cmd-builder-lambda-report "$@"

4
plugins/builder-nixpacks/.gitignore vendored Normal file
View File

@@ -0,0 +1,4 @@
/report
/report-subcommand
/triggers
/subcommands/report

Some files were not shown because too many files have changed in this diff Show More