Repository navigation
build(deploy): bump the pinned cloudflared to 2026.9.3 - #122
Merged
Merged
Conversation
2024.11.1 was two years of fixes behind. The pin stays explicit rather than moving to `latest`, so rebuilding an old commit still produces the binary it originally shipped. One change in that window touches cotel: 2026.4.0 flipped the `--edge-ip-version` default from 4 to auto, which follows whichever address family the resolver answers with first and falls back to the other only after a connection has already failed. Token mode now defaults `TUNNEL_EDGE_IP_VERSION` to 4, holding the behaviour the old version had; local-config mode is left alone, because that env var silently outranks an `edge-ip-version` in the operator's own config.yml. Startup connectivity pre-checks, also new, are kept on: they run concurrently with startup rather than gating it, and the table they log separates a blocked UDP path from a bad token — the diagnosis the deploy health gate cannot make, since it probes cotel's /healthz and not the tunnel. `--token-file` is not adopted. It keeps the token out of `ps` inside the container, but the value stays readable via `docker inspect` and /proc/1/environ, so it closes no access path in exchange for a tmpfs mount and a secret on disk. Co-Authored-By: Wayland <wayland@agents.flopbut.local> Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
|
Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 40 minutes. View limit detailsLimit details: You’ve used the included review currently available. Review configuration: ⚙️ Run configuration
📒 Files selected for processing (7)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changed
CLOUDFLARED_VERSIONgoes from 2024.11.1 (2024-11-19) to 2026.9.3 (2026-09-24), still an explicit tag rather thanlatest, so rebuilding an old commit keeps producing the binary it originally shipped. Plus the one mitigation that two years of changelog actually calls for, and docs.I read the full
CHANGES.mdfor the window. Only four entries touch anything cotel does:--edge-ip-versiondefault4→autoproxy-dnsremovedlocalhost:20241-20245when--metricsis absentThe one that matters:
--edge-ip-versionautoconnects over whichever address family the system resolver answers with first, and falls back to the other only after a connection has already failed - and then sticks with the fallback for 10 minutes (region.go,GiveBack: a V6 connectivity error swaps in the secondary set with aprimaryTimeout). A container whose resolver answersAAAAfirst but has no working IPv6 egress therefore burns its first attempts failing. I reproduced exactly that:TUNNEL_EDGE_IP_VERSION=6on this network yieldsSUMMARY: Environment has critical failures, while4andautoboth come up healthy here.Token mode now defaults
TUNNEL_EDGE_IP_VERSIONto4, which is precisely the 2024.11.1 behaviour, and an operator can still setauto/6. Local-config mode is deliberately not touched: I verified that this env var silently outranks anedge-ip-version:in the operator's ownconfig.yml(config said6, env said4, it connected over IPv4), and silently ignoring a mounted config file is worse than inheriting upstream's new default. That asymmetry is documented in both tunnel guides.Pre-checks: left on, deliberately
New since 2024.11.1, cloudflared probes DNS/QUIC/HTTP2/API at startup and logs a ~20-line
CONNECTIVITY PRE-CHECKStable. The issue flagged these as running "before the tunnel comes up" - they do not.cmd.go:428callsgo runPrechecks(...), and the source comment is explicit: "Pre-checks are diagnostic only and do not gate tunnel startup." AFAILrow does not stop anything, and the suite is capped at 10s. So--no-prechecksis not needed, and the table is worth keeping: it separates a blocked UDP path from a bad token, which is the diagnosis the deploy health gate structurally cannot make, since it probes cotel's/healthzand not the tunnel.--token-file: evaluated, not adoptedIt exists now (
$TUNNEL_TOKEN_FILE; absent in 2024.11.1) and would flip thepsrow of the visibility table to "No". That is the only row it changes. Whoever can runpsinside the container can also read/proc/1/environ, so the same person reaches the same value by a path--token-filedoes not touch - it would cost a tmpfs mount and a secret on disk to close nothing. Reasoning recorded in the doc so it is not re-litigated.Verified
Built and ran the real image on arm64 (this PR's tree, rebased onto
mainafter #120 landed):docker build .green; baked binary reportscloudflared version 2026.9.3.{"ok":true,"spans":0,...}, matching the CI smoke-test shape.docker logs: 0 hits by full value and by 24-char prefix - the fix(deploy): keep the tunnel token out of the container log #120 fix is not regressed by the bump.Environmental variables map[TUNNEL_EDGE_IP_VERSION:4]andSettings: map[token:*****]- default applied, token still redacted.ip=198.41.192.77),SUMMARY: Environment is healthy.4; token mode withTUNNEL_EDGE_IP_VERSION=auto→auto; local-config mode → unset; no tunnel → unset, no cloudflared.docsVitePress build green;sh -n scripts/entrypoint.shclean.Not verified, and it cannot be from here
https://otlp.aignite.planswering after the real deploy. The production token lives only in theCLOUDFLARE_TUNNEL_TOKENsecret and merging is the deploy, so a 2-year jump cannot be smoke-tested against the real tunnel first. The health gate does not cover this: it probes cotel's/healthz, so a healthy cotel behind a dead tunnel passes.Pre-deploy baseline captured just now, for comparison straight after the merge:
Rollback is the previous image, which is still on the host.