feat(container)!: Update image ghcr.io/kimdre/doco-cd (0.119.0 ➔ 0.120.1) #2187

Merged
GiorgioAresu merged 1 commit from renovate/major-ghcr.io-kimdre-doco-cd-0.x into main 2026-09-21 21:34:40 +02:00
Collaborator

This PR contains the following updates:

Package Update Change
ghcr.io/kimdre/doco-cd minor 0.119.0 → 0.120.1

⚠️ Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

kimdre/doco-cd (ghcr.io/kimdre/doco-cd)

v0.120.1

Compare Source

What's Changed

Fixed a crash that could occur when concurrent webhook deployments fetched updates into the same Git repository mirror. Git reads now use fresh, lock-scoped repository handles, keeping parallel deployments safe and ensuring each deployment reports the revision it actually deployed.

🌟 Improvements
🐛 Bug Fixes

Full Changelog: https://github.com/kimdre/doco-cd/compare/v0.120.0...v0.120.1

v0.120.0

Compare Source

What's Changed

This update improves deployment safety, concurrency, and performance, especially for repositories with multiple auto-discovered stacks.

Git repositories and OCI sources are now prepared as immutable, content-addressed artifacts. Deployments use a dedicated artifact for each revision instead of a shared mutable working tree. This allows independent stacks to deploy concurrently, while deployments for the same stack remain serialized. Older webhook events are also prevented from overwriting newer deployments.

Source preparation and Git checks are more efficient:

  • Repository artifacts are reused when the repository, reference, and compatible git_depth match.
  • Git change detection and ancestry checks are cached across stacks that use the same revisions.
  • Changed files are detected using Git tree comparisons instead of generating full patches.
  • Compose discovery, SOPS decryption, and reload handling are performed atomically.
  • Legacy repository layouts are migrated automatically during startup.

Read-only pre-deployment work, such as source initialization and change detection, is now handled separately from Docker-mutating deployment work. This allows more preparation tasks to run concurrently without consuming deployment slots.

You can find more information in the artifact storage documentation.

New configuration options
Variable Default Purpose
MAX_CONCURRENT_PREDEPLOYMENTS 8 Maximum number of concurrent read-only pre-deployment operations, including initialization and change detection.
ARTIFACT_GC_ENABLED true Enables cleanup of unreferenced Git revision and OCI digest artifacts.
ARTIFACT_GC_RETENTION_RECORDS 2 Number of recent unreferenced artifacts to keep per repository or artifact.
ARTIFACT_GC_RETENTION_TTL 1m Minimum time older unreferenced artifacts are retained before removal.
ARTIFACT_GC_INTERVAL 10m How often artifact cleanup runs. A sweep also runs at startup.

MAX_CONCURRENT_DEPLOYMENTS continues to control the number of deployments that may perform Docker mutations. MAX_CONCURRENT_PREDEPLOYMENTS controls preparation separately and can be adjusted according to available CPU, network, and storage capacity.

Updating considerations
  • Existing legacy repository data is migrated automatically during startup, no action is required. Allow this migration to finish before triggering new deployments.
  • Do not run multiple doco-cd versions against the same data directory during migration.
  • Artifact garbage collection may remove unreferenced source artifacts and decrypted SOPS material once the retention rules allow it. Increase the retention settings or disable ARTIFACT_GC_ENABLED if older artifacts must remain available.
  • In-flight deployments and artifacts still referenced by running stacks are protected from cleanup, but unreferenced artifacts should not be assumed to remain indefinitely.

[!CAUTION]
Services that write inside the cloned repository with relative bind mounts (inside the doco-cd data directory/volume) will lose their data when the service is re-/deployed from a new artifact revision.
Each artifact revision/version is like a clean, new Git worktree: When doco-cd deploys from a new Git commit or OCI artifact version, it first creates a new artifacts/<revision> worktree directory to deploy from.
If you use Pre- / Post-Deployment Scripts to generate configuration or data, it might be recommended to use named volumes or absolute host paths depending on your use case.

✨ Features
  • feat(source): enable safe parallel deployments with immutable artifacts by @​kimdre in #​1886
🌟 Improvements
  • perf(deploy): optimize deployment preparation and auto-discovered stacks by @​kimdre in #​1887
📦 Dependencies
📚 Miscellaneous
  • docs(wiki): restructure pages and add artifact storage documentation by @​kimdre in #​1890

Full Changelog: https://github.com/kimdre/doco-cd/compare/v0.119.0...v0.120.0


Configuration

📅 Schedule: (in timezone Europe/Rome)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

This PR contains the following updates: | Package | Update | Change | |---|---|---| | [ghcr.io/kimdre/doco-cd](https://github.com/kimdre/doco-cd) | minor | `0.119.0` → `0.120.1` | --- > ⚠️ **Warning** > > Some dependencies could not be looked up. Check the [Dependency Dashboard](issues/6) for more information. --- ### Release Notes <details> <summary>kimdre/doco-cd (ghcr.io/kimdre/doco-cd)</summary> ### [`v0.120.1`](https://github.com/kimdre/doco-cd/releases/tag/v0.120.1) [Compare Source](https://github.com/kimdre/doco-cd/compare/v0.120.0...v0.120.1) <!-- Release notes generated using configuration in .github/release.yml at main --> ##### What's Changed Fixed a crash that could occur when concurrent webhook deployments fetched updates into the same Git repository mirror. Git reads now use fresh, lock-scoped repository handles, keeping parallel deployments safe and ensuring each deployment reports the revision it actually deployed. ##### 🌟 Improvements - fix(git): scope mirror reads to fresh handles by [@&#8203;kimdre](https://github.com/kimdre) in [#&#8203;1892](https://github.com/kimdre/doco-cd/pull/1892) ##### 🐛 Bug Fixes - fix(reconciliation): recover panics in background deployments by [@&#8203;kimdre](https://github.com/kimdre) in [#&#8203;1891](https://github.com/kimdre/doco-cd/pull/1891) **Full Changelog**: <https://github.com/kimdre/doco-cd/compare/v0.120.0...v0.120.1> ### [`v0.120.0`](https://github.com/kimdre/doco-cd/releases/tag/v0.120.0) [Compare Source](https://github.com/kimdre/doco-cd/compare/v0.119.0...v0.120.0) <!-- Release notes generated using configuration in .github/release.yml at main --> ##### What's Changed This update improves deployment safety, concurrency, and performance, especially for repositories with multiple auto-discovered stacks. Git repositories and OCI sources are now prepared as immutable, content-addressed artifacts. Deployments use a dedicated artifact for each revision instead of a shared mutable working tree. This allows independent stacks to deploy concurrently, while deployments for the same stack remain serialized. Older webhook events are also prevented from overwriting newer deployments. Source preparation and Git checks are more efficient: - Repository artifacts are reused when the repository, reference, and compatible `git_depth` match. - Git change detection and ancestry checks are cached across stacks that use the same revisions. - Changed files are detected using Git tree comparisons instead of generating full patches. - Compose discovery, SOPS decryption, and reload handling are performed atomically. - Legacy repository layouts are migrated automatically during startup. Read-only pre-deployment work, such as source initialization and change detection, is now handled separately from Docker-mutating deployment work. This allows more preparation tasks to run concurrently without consuming deployment slots. You can find more information in the [artifact storage documentation](https://doco.cd/latest/Reference/Artifact-Storage/). ##### New configuration options | Variable | Default | Purpose | | ------------------------------- | ------: | ---------------------------------------------------------------------------------------------------------------- | | `MAX_CONCURRENT_PREDEPLOYMENTS` | `8` | Maximum number of concurrent read-only pre-deployment operations, including initialization and change detection. | | `ARTIFACT_GC_ENABLED` | `true` | Enables cleanup of unreferenced Git revision and OCI digest artifacts. | | `ARTIFACT_GC_RETENTION_RECORDS` | `2` | Number of recent unreferenced artifacts to keep per repository or artifact. | | `ARTIFACT_GC_RETENTION_TTL` | `1m` | Minimum time older unreferenced artifacts are retained before removal. | | `ARTIFACT_GC_INTERVAL` | `10m` | How often artifact cleanup runs. A sweep also runs at startup. | `MAX_CONCURRENT_DEPLOYMENTS` continues to control the number of deployments that may perform Docker mutations. `MAX_CONCURRENT_PREDEPLOYMENTS` controls preparation separately and can be adjusted according to available CPU, network, and storage capacity. ##### Updating considerations - Existing legacy repository data is migrated automatically during startup, no action is required. Allow this migration to finish before triggering new deployments. - Do not run multiple doco-cd versions against the same data directory during migration. - Artifact garbage collection may remove unreferenced source artifacts and decrypted SOPS material once the retention rules allow it. Increase the retention settings or disable `ARTIFACT_GC_ENABLED` if older artifacts must remain available. - In-flight deployments and artifacts still referenced by running stacks are protected from cleanup, but unreferenced artifacts should not be assumed to remain indefinitely. > \[!CAUTION] > Services that write inside the cloned repository with relative bind mounts (inside the doco-cd data directory/volume) **will lose their data** when the service is re-/deployed from a new artifact revision. > Each artifact revision/version is like a clean, new [Git worktree](https://git-scm.com/docs/git-worktree/2.31.0#_description): When doco-cd deploys from a *new* Git commit or OCI artifact version, it first creates a new `artifacts/<revision>` worktree directory to deploy from. > If you use [Pre- / Post-Deployment Scripts](https://doco.cd/latest/Advanced/Pre-Post-Deployment-Scripts/) to generate configuration or data, it might be recommended to use named volumes or absolute host paths depending on your use case. ##### ✨ Features - feat(source): enable safe parallel deployments with immutable artifacts by [@&#8203;kimdre](https://github.com/kimdre) in [#&#8203;1886](https://github.com/kimdre/doco-cd/pull/1886) ##### 🌟 Improvements - perf(deploy): optimize deployment preparation and auto-discovered stacks by [@&#8203;kimdre](https://github.com/kimdre) in [#&#8203;1887](https://github.com/kimdre/doco-cd/pull/1887) ##### 📦 Dependencies - chore(deps): update docker:29-dind docker digest to [`3f3c01a`](https://github.com/kimdre/doco-cd/commit/3f3c01a) by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;1877](https://github.com/kimdre/doco-cd/pull/1877) - chore(deps): update codecov/codecov-action action to v7.1.1 by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;1878](https://github.com/kimdre/doco-cd/pull/1878) - chore(deps): update github/codeql-action digest to [`1c5b675`](https://github.com/kimdre/doco-cd/commit/1c5b675) by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;1882](https://github.com/kimdre/doco-cd/pull/1882) - chore(deps): update debian:trixie-slim docker digest to [`e27e3db`](https://github.com/kimdre/doco-cd/commit/e27e3db) by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;1884](https://github.com/kimdre/doco-cd/pull/1884) - fix(deps): update module github.com/modelcontextprotocol/go-sdk to v1.8.0 by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;1885](https://github.com/kimdre/doco-cd/pull/1885) - fix(deps): update module github.com/aws/aws-sdk-go-v2/service/secretsmanager to v1.50.0 by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;1883](https://github.com/kimdre/doco-cd/pull/1883) - chore(deps): update debian:trixie-slim docker digest to [`a99cfc5`](https://github.com/kimdre/doco-cd/commit/a99cfc5) by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;1888](https://github.com/kimdre/doco-cd/pull/1888) - chore(deps): update golang:1.27.1 docker digest to [`3680233`](https://github.com/kimdre/doco-cd/commit/3680233) by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;1889](https://github.com/kimdre/doco-cd/pull/1889) ##### 📚 Miscellaneous - docs(wiki): restructure pages and add artifact storage documentation by [@&#8203;kimdre](https://github.com/kimdre) in [#&#8203;1890](https://github.com/kimdre/doco-cd/pull/1890) **Full Changelog**: <https://github.com/kimdre/doco-cd/compare/v0.119.0...v0.120.0> </details> --- ### Configuration 📅 **Schedule**: (in timezone Europe/Rome) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMDQuMiIsInVwZGF0ZWRJblZlciI6IjQ0LjEwNC4yIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL21pbm9yIl19-->
feat(container)!: Update image ghcr.io/kimdre/doco-cd (0.119.0 ➔ 0.120.0)
All checks were successful
Labeler / Labeler (pull_request) Successful in 3s
Lint / actionlint (pull_request) Successful in 6s
Lint / yamllint (pull_request) Successful in 12s
AI PR Review / AI PR Review (pull_request) Successful in 30s
Konflate 0 resources changed
7bda42b23e
Collaborator

✅ Automated recommendation: APPROVE

Analysis engine: minimax/MiniMax-M2-7-anthropic@http://litellm.ai.svc.cluster.local:4000/v1 (anthropic)

Recommendation: Approve

Container image update for doco-cd (0.119.0 → 0.120.1) applied consistently across 4 Docker host deployments.

Changes

  • 4 files updated: docker-compose.app.yaml in odroidhc4, truenas, vps-pangolin, and zimablade
  • Each updates the image tag and SHA256 digest from 0.119.0 to 0.120.1

Review Notes

  • Konflate: No rendered changes (configuration files not processed through Helm/Kustomize rendering)
  • Consistency: All 4 instances updated identically
  • Repository convention: Images pinned by tag + SHA256 digest ✓
  • No migration or API changes detected in this codebase

Release Notes Summary

  • v0.120.0: Major improvements to deployment safety, concurrency, and performance; immutable artifact preparation; concurrent deployments now safe
  • v0.120.1: Bug fix for crashes during concurrent webhook deployments (Git read handle scoping)

Both releases include stability and concurrency fixes beneficial to the Git mirror deployments running across these hosts.

<!-- ai-pr-reviewer --> <!-- ai-pr-reviewer:{"version":1,"head_sha":"225bb34abe33ceb017ce0a1bf537f09e09f7c4d2","base_sha":"dbedf26422bb8d0799ec40be34e8309171babb77","review_scope":"full","review_result":"clean"} --> <!-- ai-pr-review-sha:225bb34abe33ceb017ce0a1bf537f09e09f7c4d2 --> <!-- ai-pr-review-fingerprint:a77bc23fca47bc242a01d02826272abd448ed2f2309288b343d480ba91384731|cfg:7a30ceb5ce2b3ccbdfc6c40c9687c34755f4b5f05d11c520f006c633015e856a --> ✅ **Automated recommendation: APPROVE** _Analysis engine: minimax/MiniMax-M2-7-anthropic@http://litellm.ai.svc.cluster.local:4000/v1 (anthropic)_ ## Recommendation: Approve Container image update for `doco-cd` (0.119.0 → 0.120.1) applied consistently across 4 Docker host deployments. ## Changes - **4 files updated**: `docker-compose.app.yaml` in odroidhc4, truenas, vps-pangolin, and zimablade - Each updates the image tag and SHA256 digest from `0.119.0` to `0.120.1` ## Review Notes - **Konflate**: No rendered changes (configuration files not processed through Helm/Kustomize rendering) - **Consistency**: All 4 instances updated identically - **Repository convention**: Images pinned by tag + SHA256 digest ✓ - **No migration or API changes** detected in this codebase ## Release Notes Summary - **v0.120.0**: Major improvements to deployment safety, concurrency, and performance; immutable artifact preparation; concurrent deployments now safe - **v0.120.1**: Bug fix for crashes during concurrent webhook deployments (Git read handle scoping) Both releases include stability and concurrency fixes beneficial to the Git mirror deployments running across these hosts.
Collaborator

No rendered changes.

konflate 0.6.4 · rendered 225bb34 · full diff →

<!-- konflate:pr-2187 --> No rendered changes. <sub>konflate 0.6.4 · rendered `225bb34` · [full diff →](https://konflate.aresu.eu/#/pr/2187)</sub>
renovate-bot force-pushed renovate/major-ghcr.io-kimdre-doco-cd-0.x from 7bda42b23e
All checks were successful
Labeler / Labeler (pull_request) Successful in 3s
Lint / actionlint (pull_request) Successful in 6s
Lint / yamllint (pull_request) Successful in 12s
AI PR Review / AI PR Review (pull_request) Successful in 30s
Konflate 0 resources changed
to 225bb34abe
All checks were successful
Konflate 0 resources changed
Labeler / Labeler (pull_request) Successful in 3s
Lint / actionlint (pull_request) Successful in 5s
Lint / yamllint (pull_request) Successful in 12s
AI PR Review / AI PR Review (pull_request) Successful in 37s
2026-09-21 19:02:19 +02:00
Compare
renovate-bot changed title from feat(container)!: Update image ghcr.io/kimdre/doco-cd (0.119.0 ➔ 0.120.0) to feat(container)!: Update image ghcr.io/kimdre/doco-cd (0.119.0 ➔ 0.120.1) 2026-09-21 19:02:25 +02:00
GiorgioAresu deleted branch renovate/major-ghcr.io-kimdre-doco-cd-0.x 2026-09-21 21:34:40 +02:00
Sign in to join this conversation.
No description provided.