Page MenuHomePhabricator

Rebuild production Stretch images with GNUTLS/OpenSSL updates for LE issue chain update
Closed, ResolvedPublic

Description

T283165 updated the production servers, but if we still run production images on Stretch we need to rebuild/redeploy them with latest Stretch:

The expected version numbers are
openssl1.0: 1.0.2u-1~deb9u5
gnutls28: 3.5.8-5+deb9u6

Event Timeline

Joe changed the task status from Open to In Progress.Sep 21 2021, 9:01 AM
Joe claimed this task.

The debmonitor query for libssl 1.0.2 tells us it's mostly images under the /releng prefix.

In addition, we have the following images:

  • graphoid Decommissioned
  • fluentd Decommissioned
  • nodejs-slim old stretch-based nodejs image, needs updating
  • ruby which is still stretch-based, should probably be bumped at least to use buster, and is apparently unused by releng or anything else.
  • wikimedia-portals just needs to have its blubberfile to be updated not to pin specific versions of the images.

The debmonitor query for | libgnutls30 tells us again it's mostly releng images, plus:

Change 722565 had a related patch set uploaded (by Giuseppe Lavagetto; author: Giuseppe Lavagetto):

[operations/docker-images/production-images@master] Update a few stretch-based images for openssl / gnutls updates

https://gerrit.wikimedia.org/r/722565

Mentioned in SAL (#wikimedia-operations) [2021-09-21T09:44:58Z] <_joe_> deleting images for graphoid, T291458

Mentioned in SAL (#wikimedia-operations) [2021-09-21T09:46:08Z] <_joe_> deneb:~# docker-registryctl delete-tags docker-registry.wikimedia.org/fluentd T291458

Change 722565 merged by Giuseppe Lavagetto:

[operations/docker-images/production-images@master] Update a few stretch-based images for openssl / gnutls updates

https://gerrit.wikimedia.org/r/722565

Mentioned in SAL (#wikimedia-operations) [2021-09-21T09:59:27Z] <_joe_> rebuilding openjdk8* image, ruby, nodejs-slim for T291458

Change 722572 had a related patch set uploaded (by Giuseppe Lavagetto; author: Giuseppe Lavagetto):

[operations/docker-images/production-images@master] Fix openjdk8 images build

https://gerrit.wikimedia.org/r/722572

Change 722572 merged by Giuseppe Lavagetto:

[operations/docker-images/production-images@master] Fix openjdk8 images build

https://gerrit.wikimedia.org/r/722572

Change 722606 had a related patch set uploaded (by Giuseppe Lavagetto; author: Giuseppe Lavagetto):

[wikimedia/portals@master] Update blubberfile to avoid specific versions of parent images

https://gerrit.wikimedia.org/r/722606

Change 722606 merged by jenkins-bot:

[wikimedia/portals@master] Update blubberfile to avoid specific versions of parent images

https://gerrit.wikimedia.org/r/722606

Change 725765 had a related patch set uploaded (by Giuseppe Lavagetto; author: Giuseppe Lavagetto):

[wikimedia/portals@master] pipeline: switch to newer, buster-based image

https://gerrit.wikimedia.org/r/725765

Change 725765 merged by jenkins-bot:

[wikimedia/portals@master] pipeline: switch to newer, buster-based image

https://gerrit.wikimedia.org/r/725765