feat(container)!: Update image ghcr.io/kimdre/doco-cd (0.122.1 ➔ 0.123.0) #2242

Merged
GiorgioAresu merged 1 commit from renovate/major-ghcr.io-kimdre-doco-cd-0.x into main 2026-09-30 00:07:57 +02:00
Collaborator

This PR contains the following updates:

Package Update Change
ghcr.io/kimdre/doco-cd minor 0.122.1 → 0.123.0

⚠️ Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

kimdre/doco-cd (ghcr.io/kimdre/doco-cd)

v0.123.0

Compare Source

What's Changed
  • Added Sync Windows to control when doco-cd is allowed to change your stacks. For example, you can deploy only during business hours, freeze deployments over the weekend, or restrict production to a nightly maintenance window.
  • OpenBao PKI references now always expose the full certificate chain as an companion environment (CERT_FULL) similar to CERT_KEY, see the wiki.
  • In Swarm environments, the doco-cd logs now show the service name and service id.
  • Some transient errors were never retried. This is fixed now.
  • Improved documentation for SOPS usage with cloud key services and added doco-cd setup examples.
✨ Features
  • feat(config): add timezone-aware sync windows and cron schedules for polling by @​kimdre in #​1920
  • feat(openbao): expose full certificate chain as a _FULL companion variable by @​zyojv in #​1819
🌟 Improvements
📦 Dependencies
📚 Miscellaneous

Full Changelog: https://github.com/kimdre/doco-cd/compare/v0.122.1...v0.123.0


Configuration

📅 Schedule: (in timezone Europe/Rome)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

This PR contains the following updates: | Package | Update | Change | |---|---|---| | [ghcr.io/kimdre/doco-cd](https://github.com/kimdre/doco-cd) | minor | `0.122.1` → `0.123.0` | --- > ⚠️ **Warning** > > Some dependencies could not be looked up. Check the [Dependency Dashboard](issues/6) for more information. --- ### Release Notes <details> <summary>kimdre/doco-cd (ghcr.io/kimdre/doco-cd)</summary> ### [`v0.123.0`](https://github.com/kimdre/doco-cd/releases/tag/v0.123.0) [Compare Source](https://github.com/kimdre/doco-cd/compare/v0.122.1...v0.123.0) <!-- Release notes generated using configuration in .github/release.yml at main --> ##### What's Changed - Added [Sync Windows](https://doco.cd/v0.123/Advanced/Sync-Windows/) to control *when* doco-cd is allowed to change your stacks. For example, you can deploy only during business hours, freeze deployments over the weekend, or restrict production to a nightly maintenance window. - OpenBao PKI references now always expose the full certificate chain as an companion environment (`CERT_FULL`) similar to `CERT_KEY`, see the [wiki](https://doco.cd/v0.123/External-Secrets/Openbao/#full-certificate-chain). - In Swarm environments, the doco-cd logs now show the service name and service id. - Some transient errors were never retried. This is fixed now. - Improved documentation for [SOPS usage with cloud key services](https://doco.cd/v0.123/Advanced/Encryption/#usage-with-sops-and-cloud-key-services) and added doco-cd [setup examples](https://github.com/kimdre/doco-cd/tree/v0.123.0/examples). ##### ✨ Features - feat(config): add timezone-aware sync windows and cron schedules for polling by [@&#8203;kimdre](https://github.com/kimdre) in [#&#8203;1920](https://github.com/kimdre/doco-cd/pull/1920) - feat(openbao): expose full certificate chain as a \_FULL companion variable by [@&#8203;zyojv](https://github.com/zyojv) in [#&#8203;1819](https://github.com/kimdre/doco-cd/pull/1819) ##### 🌟 Improvements - fix(swarm): include service names and IDs in logs by [@&#8203;kimdre](https://github.com/kimdre) in [#&#8203;1928](https://github.com/kimdre/doco-cd/pull/1928) - fix(retry): retry HTTP 5xx and network timeouts on git and secret provider calls by [@&#8203;denisolnce](https://github.com/denisolnce) in [#&#8203;1924](https://github.com/kimdre/doco-cd/pull/1924) - fix(git): fetch pinned commit by sha when no branch or tag reaches it by [@&#8203;denisolnce](https://github.com/denisolnce) in [#&#8203;1929](https://github.com/kimdre/doco-cd/pull/1929) ##### 📦 Dependencies - chore(deps): update dependency zensical to v0.0.66 by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;1930](https://github.com/kimdre/doco-cd/pull/1930) - fix(deps): update module github.com/azure/azure-sdk-for-go/sdk/azcore to v1.23.2 by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;1931](https://github.com/kimdre/doco-cd/pull/1931) ##### 📚 Miscellaneous - docs(examples): env-first layout, shared/, and the CI bump job by [@&#8203;denisolnce](https://github.com/denisolnce) in [#&#8203;1879](https://github.com/kimdre/doco-cd/pull/1879) - docs(wiki): document SOPS with AWS KMS and other cloud key services by [@&#8203;denisolnce](https://github.com/denisolnce) in [#&#8203;1932](https://github.com/kimdre/doco-cd/pull/1932) **Full Changelog**: <https://github.com/kimdre/doco-cd/compare/v0.122.1...v0.123.0> </details> --- ### Configuration 📅 **Schedule**: (in timezone Europe/Rome) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTUuMTMiLCJ1cGRhdGVkSW5WZXIiOiI0NC4xMTUuMTMiLCJ0YXJnZXRCcmFuY2giOiJtYWluIiwibGFiZWxzIjpbInJlbm92YXRlL2NvbnRhaW5lciIsInR5cGUvbWlub3IiXX0=-->
feat(container)!: Update image ghcr.io/kimdre/doco-cd (0.122.1 ➔ 0.123.0)
All checks were successful
Labeler / Labeler (pull_request) Successful in 4s
Lint / actionlint (pull_request) Successful in 6s
Lint / yamllint (pull_request) Successful in 11s
AI PR Review / AI PR Review (pull_request) Successful in 49s
Konflate 0 resources changed
7c291cfed2
Collaborator

✅ Automated recommendation: APPROVE

Analysis engine: minimax/MiniMax-M2-7-anthropic@http://litellm.ai.svc.cluster.local:4000/v1 (anthropic)

Recommendation: Approve

This is a straightforward Renovate-driven minor version bump of the ghcr.io/kimdre/doco-cd container image from 0.122.1 → 0.123.0, applied consistently across 4 docker-compose.app.yaml files. Konflate reports zero blast-radius or lint cautions. No blockers identified.

Change summary

File Δ lines
docker/odroidhc4/.doco-cd/docker-compose.app.yaml +1/−1
docker/truenas/.doco-cd/docker-compose.app.yaml +1/−1
docker/vps-pangolin/.doco-cd/docker-compose.app.yaml +1/−1
docker/zimablade/.doco-cd/docker-compose.app.yaml +1/−1

Each change is a single-line image reference update: tag 0.123.0 + new @sha256: digest replacing the prior version/digest pair. Image digests are already present in the diff.

Non-blocking caveats

  • Automerge disabled: Renovate config has automerge off; manual merge required per PR body. This is intentional governance, not an issue.
  • OCI artifact pinning convention: Images in these files pin by @sha256: digest in addition to the tag. Per AGENTS.md, OCI artifacts (Helm charts) use tag/version pins; container images like this one correctly carry a digest, which is consistent with the existing pattern in the repo. No concern.
  • Upstream release notes could not be enriched (GitHub API fetch failures for compare/release metadata); the PR body release notes are captured inline and provide adequate change context.

No additional sections warranted

  • No linked issues → no Linked Issue Fit section.
  • No must_check items triggered.
  • Konflate rendered-diff shows no cautions or failures → no findings to surface.
  • No repository standards file present in this corpus.
<!-- ai-pr-reviewer --> <!-- ai-pr-reviewer:{"version":1,"head_sha":"7c291cfed2b9a525ae7c9c616f2ca9c09f58add0","base_sha":"99d361ab30fa22ff3914f4e9db25eec2a50a0b8e","review_scope":"full","review_result":"clean"} --> <!-- ai-pr-review-sha:7c291cfed2b9a525ae7c9c616f2ca9c09f58add0 --> <!-- ai-pr-review-fingerprint:b0e6130822065c74e78cdc80b591fd6af0c638faaac8473fb32312cfacbe9c8c|cfg:d27ea58bdbdafc403f62b1b84c70d905cc97c77c6d72d767872b88951af9ea8d --> ✅ **Automated recommendation: APPROVE** _Analysis engine: minimax/MiniMax-M2-7-anthropic@http://litellm.ai.svc.cluster.local:4000/v1 (anthropic)_ ## Recommendation: Approve This is a straightforward Renovate-driven minor version bump of the `ghcr.io/kimdre/doco-cd` container image from `0.122.1` → `0.123.0`, applied consistently across 4 docker-compose.app.yaml files. Konflate reports zero blast-radius or lint cautions. No blockers identified. ### Change summary | File | Δ lines | |---|---| | `docker/odroidhc4/.doco-cd/docker-compose.app.yaml` | +1/−1 | | `docker/truenas/.doco-cd/docker-compose.app.yaml` | +1/−1 | | `docker/vps-pangolin/.doco-cd/docker-compose.app.yaml` | +1/−1 | | `docker/zimablade/.doco-cd/docker-compose.app.yaml` | +1/−1 | Each change is a single-line image reference update: tag `0.123.0` + new `@sha256:` digest replacing the prior version/digest pair. Image digests are already present in the diff. ### Non-blocking caveats - **Automerge disabled**: Renovate config has automerge off; manual merge required per PR body. This is intentional governance, not an issue. - **OCI artifact pinning convention**: Images in these files pin by `@sha256:` digest in addition to the tag. Per AGENTS.md, OCI artifacts (Helm charts) use tag/version pins; container images like this one correctly carry a digest, which is consistent with the existing pattern in the repo. No concern. - **Upstream release notes could not be enriched** (GitHub API fetch failures for compare/release metadata); the PR body release notes are captured inline and provide adequate change context. ### No additional sections warranted - No linked issues → no Linked Issue Fit section. - No must_check items triggered. - Konflate rendered-diff shows no cautions or failures → no findings to surface. - No repository standards file present in this corpus.
Collaborator

No rendered changes.

konflate 0.6.4 · rendered 7c291cf · full diff →

<!-- konflate:pr-2242 --> No rendered changes. <sub>konflate 0.6.4 · rendered `7c291cf` · [full diff →](https://konflate.aresu.eu/#/pr/2242)</sub>
Sign in to join this conversation.
No description provided.