upgrade forgejo 15.0.4 → 16.0.0 #73

Stängd
öppnade 2026-07-17 11:42:30 +00:00 av supernaut · 1 kommentar
Ägare

Upgrade the production Forgejo instance from 15.0.4 to 16.0.0 (released 2026-07-16).

Plan tracked internally (verified against the released v16.0.0 on 2026-07-17 — see its "Task 0 findings" block).

Scope

  • Mandatory config (BC1): [security] REVERSE_PROXY_TRUSTED_PROXIES — v16 removed the * default; Forgejo sits behind Caddy on the internal gitborg bridge (10.89.0.0/24), so without it every request appears to come from the proxy.
  • Image pin: forgejo_image_tag: 15.0.4 → 16.0.0 (+ stale :15 comment refs).
  • Pre-flight: fresh backup + green restore drill (ADR 0027) + flush-queues; consumer audit (BC4–BC7) came back clean; BC8 (OIDC "Remember me" SSO-binding, PR 12321) needs only a post-upgrade smoke test.
  • Apply: site.yml --tags forgejo; schema migration is irreversible-forward → rollback = restore-from-backup, never a tag revert.
  • Post-upgrade: doctor + functional verification (client IP, OIDC session, git SSH/HTTPS, Actions, metrics, reconciler), optional hooks/description cleanup, docs (runbook §upgrade, upgrade-cadence ADR, architecture.md).

Follow-up features (token-rotation API, Zoekt, dynamic OIDC group mappings, Actions APIs, Authorized Integrations) are deliberately out of scope — separate issues, gated on this landing.

Upgrade the production Forgejo instance from `15.0.4` to `16.0.0` (released 2026-07-16). Plan tracked internally (verified against the released v16.0.0 on 2026-07-17 — see its "Task 0 findings" block). ## Scope - **Mandatory config (BC1):** `[security] REVERSE_PROXY_TRUSTED_PROXIES` — v16 removed the `*` default; Forgejo sits behind Caddy on the internal `gitborg` bridge (`10.89.0.0/24`), so without it every request appears to come from the proxy. - **Image pin:** `forgejo_image_tag: 15.0.4 → 16.0.0` (+ stale `:15` comment refs). - **Pre-flight:** fresh backup + green restore drill (ADR 0027) + `flush-queues`; consumer audit (BC4–BC7) came back clean; BC8 (OIDC "Remember me" SSO-binding, PR 12321) needs only a post-upgrade smoke test. - **Apply:** `site.yml --tags forgejo`; schema migration is irreversible-forward → rollback = restore-from-backup, never a tag revert. - **Post-upgrade:** doctor + functional verification (client IP, OIDC session, git SSH/HTTPS, Actions, metrics, reconciler), optional hooks/`description` cleanup, docs (runbook §upgrade, upgrade-cadence ADR, architecture.md). Follow-up features (token-rotation API, Zoekt, dynamic OIDC group mappings, Actions APIs, Authorized Integrations) are deliberately **out of scope** — separate issues, gated on this landing.
supernaut refererade till detta ärende från en incheckning 2026-07-17 11:46:31 +00:00
Upphovsperson
Ägare

Upgrade completed and verified 2026-07-17 (window ~13:35–14:20 UTC).

  • Pre-flight: PR #74 (reverse-proxy trust 10.89.0.0/24 + pin 16.0.0 + runbook + local preview). Fresh backup bitborg-20260717T120602Z.tar.age + both off-site copies green + green restore drill; queues flushed before restart.
  • Apply hit the #63 gap live (restart ran on the stale generated unit → container stayed on 15.0.4); recovered with podman pull + manual restart. Root cause documented on #63.
  • Migration: v16 series completed cleanly; forgejo doctor check --all 27/27 OK (also re-run after cleanup).
  • Verification: running image/version = 16.0.0 ✓ · web + HTTPS git ✓ · SSH git ✓ · OIDC login ✓ (no "Remember me" exists in the SSO-only flow — BC8's LTA change is automatic for OIDC) · /metrics 401 w/o token, 200 for vmagent ✓ · reconciler clean against v16 admin API ✓ · Actions run on ephemeral runner: success, 18 s ✓ · no new alerts ✓.
  • BC1 note: the trusted-proxy config is proven working (controlled XFF probe resolved correctly). Real client IPs are still lost before Caddy by rootless port-forwarding — pre-existing, tracked as #81 (also blocks #48).
  • Post-upgrade cleanup (BC2/BC3) done: 5 per-repo hooks/ dirs + 5 description files deleted; doctor clean.
  • SECRET_KEY + INTERNAL_TOKEN rotated (exposure during verification): live on prod, vault change in PR #82.
  • Docs: runbook § Upgrade Forgejo expanded (merged in #74), ADR 0028 (upgrade cadence) in bitborg-docs PR #25.
  • Follow-ups filed: #75 (token rotation API), #76 (Zoekt), #77 (OIDC group-mapping spike), #78 (Actions APIs), #79 (2FA evidence), #80 (Authorized Integrations), #81 (client IPs).
  • Minor: fj pr status can't parse v16's check-run URL shape (cosmetic fj incompatibility).
**Upgrade completed and verified 2026-07-17** (window ~13:35–14:20 UTC). - Pre-flight: PR #74 (reverse-proxy trust `10.89.0.0/24` + pin `16.0.0` + runbook + local preview). Fresh backup `bitborg-20260717T120602Z.tar.age` + both off-site copies green + green restore drill; queues flushed before restart. - Apply hit the #63 gap live (restart ran on the stale generated unit → container stayed on 15.0.4); recovered with `podman pull` + manual restart. Root cause documented on #63. - Migration: v16 series completed cleanly; `forgejo doctor check --all` 27/27 OK (also re-run after cleanup). - Verification: running image/version = 16.0.0 ✓ · web + HTTPS git ✓ · SSH git ✓ · OIDC login ✓ (no "Remember me" exists in the SSO-only flow — BC8's LTA change is automatic for OIDC) · `/metrics` 401 w/o token, 200 for vmagent ✓ · reconciler clean against v16 admin API ✓ · Actions run on ephemeral runner: success, 18 s ✓ · no new alerts ✓. - BC1 note: the trusted-proxy config is proven working (controlled XFF probe resolved correctly). Real client IPs are still lost **before** Caddy by rootless port-forwarding — pre-existing, tracked as #81 (also blocks #48). - Post-upgrade cleanup (BC2/BC3) done: 5 per-repo `hooks/` dirs + 5 `description` files deleted; doctor clean. - SECRET_KEY + INTERNAL_TOKEN rotated (exposure during verification): live on prod, vault change in PR #82. - Docs: runbook § Upgrade Forgejo expanded (merged in #74), ADR 0028 (upgrade cadence) in bitborg-docs PR #25. - Follow-ups filed: #75 (token rotation API), #76 (Zoekt), #77 (OIDC group-mapping spike), #78 (Actions APIs), #79 (2FA evidence), #80 (Authorized Integrations), #81 (client IPs). - Minor: `fj pr status` can't parse v16's check-run URL shape (cosmetic fj incompatibility).
Logga in för att delta i denna konversation.
Ingen milstolpe
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra#73
Ingen beskrivning angiven.