infra: pull wireguard from ghcr.io so Renovate can look it up #391

Merged
mysticalsoap merged 3 commits from infra/wireguard-ghcr into trunk 2026-10-07 20:56:27 -04:00
Owner

Problem

Renovate reports lscr.io/linuxserver/wireguard as no-result on the dependency dashboard (#3) and skips it, so the image gets no tag or digest PRs. The image scan's finding on it (unbound-libs, two CRITICAL RCEs fixed in 1.25.2-r2, plus a HIGH in pcre2) therefore has no path to clear. Renovate's own digest PR for it (#368) was autoclosed in today's run for the same reason.

lscr.io is LinuxServer's vanity front for GHCR, but it answers the tag list itself instead of redirecting, so every lscr.io user shares GHCR's anonymous rate limit on lscr.io's address. Every ghcr.io image in this repo resolves without trouble.

Fix

  • infra/compose.yml: reference the image as ghcr.io/linuxserver/wireguard. Same tag (1.0.20260223, the floating tag LinuxServer moves onto each rebuild) and the pinned digest exists there too, so the first commit changes nothing about what runs.
  • Second commit bumps the digest to the current 1.0.20260223 build (ls124, alpine 3.24.2), which is the PR Renovate would open next. One relay bounce instead of two.
  • Maintenance.md § Renovate: the lscr.io rule, with a one-line pointer from the compose file.
  • Third commit: _helper/renovate/run.sh forwards every RENOVATE_* variable, so RENOVATE_BASE_BRANCH_PATTERNS=<branch> just renovate tests a pushed branch; documented next to just renovate in Maintenance.md.

Verification

  • ghcr.io carries the pinned digest (manifest fetch by digest returns 200), the same 1.0.YYYYMMDD tag shape, and 1308 tags in two pages, so the tag shape survives the move and pagination is not a concern.
  • just up infra on the branch: wireguard and haproxy recreated, all infra containers healthy. The container runs the new digest, wg show handshake age 34 s, unbound-libs 1.25.2-r2 and pcre2 10.49-r0 installed.
  • Public relay works through the VPS address (--resolve onto the public A record): git.mysticalsoap.com 303, mysticalsoap.com 200.
  • Trivy on the running image id (--image-src docker, fixable HIGH+CRITICAL): 0, down from 3 on the previous digest.
  • RENOVATE_BASE_BRANCH_PATTERNS=infra/wireguard-ghcr just renovate (dry run, via the new run.sh): no "Package lookup failures" warning, where today's scheduled run printed one on every branch.

After merge: just deploy --dry-run should be empty for infra, since live already runs the branch. The next scheduled run (08:00) should clear the warning from #3.

Closes #390

🤖 Generated with Claude Code

## Problem Renovate reports `lscr.io/linuxserver/wireguard` as `no-result` on the dependency dashboard (#3) and skips it, so the image gets no tag or digest PRs. The image scan's finding on it (unbound-libs, two CRITICAL RCEs fixed in 1.25.2-r2, plus a HIGH in pcre2) therefore has no path to clear. Renovate's own digest PR for it (#368) was autoclosed in today's run for the same reason. lscr.io is LinuxServer's vanity front for GHCR, but it answers the tag list itself instead of redirecting, so every lscr.io user shares GHCR's anonymous rate limit on lscr.io's address. Every `ghcr.io` image in this repo resolves without trouble. ## Fix - `infra/compose.yml`: reference the image as `ghcr.io/linuxserver/wireguard`. Same tag (`1.0.20260223`, the floating tag LinuxServer moves onto each rebuild) and the pinned digest exists there too, so the first commit changes nothing about what runs. - Second commit bumps the digest to the current `1.0.20260223` build (ls124, alpine 3.24.2), which is the PR Renovate would open next. One relay bounce instead of two. - `Maintenance.md § Renovate`: the lscr.io rule, with a one-line pointer from the compose file. - Third commit: `_helper/renovate/run.sh` forwards every `RENOVATE_*` variable, so `RENOVATE_BASE_BRANCH_PATTERNS=<branch> just renovate` tests a pushed branch; documented next to `just renovate` in Maintenance.md. ## Verification - `ghcr.io` carries the pinned digest (manifest fetch by digest returns 200), the same `1.0.YYYYMMDD` tag shape, and 1308 tags in two pages, so the tag shape survives the move and pagination is not a concern. - `just up infra` on the branch: wireguard and haproxy recreated, all infra containers healthy. The container runs the new digest, `wg show` handshake age 34 s, unbound-libs 1.25.2-r2 and pcre2 10.49-r0 installed. - Public relay works through the VPS address (`--resolve` onto the public A record): git.mysticalsoap.com 303, mysticalsoap.com 200. - Trivy on the running image id (`--image-src docker`, fixable HIGH+CRITICAL): 0, down from 3 on the previous digest. - `RENOVATE_BASE_BRANCH_PATTERNS=infra/wireguard-ghcr just renovate` (dry run, via the new run.sh): no "Package lookup failures" warning, where today's scheduled run printed one on every branch. After merge: `just deploy --dry-run` should be empty for infra, since live already runs the branch. The next scheduled run (08:00) should clear the warning from #3. Closes #390 🤖 Generated with [Claude Code](https://claude.com/claude-code)
Renovate reports lscr.io/linuxserver/wireguard as no-result and skips it,
so the image gets no tag or digest PRs and its open image-scan finding has
no path to clear (#390). lscr.io is LinuxServer's vanity front for GHCR,
but it answers the tag list itself rather than redirecting, which puts
every lscr.io user behind GHCR's anonymous rate limit on one address.
Every ghcr.io image in this repo resolves, and the same tags and digests
exist there, so the reference moves and nothing else changes: the pinned
digest is the one already running.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
infra: bump wireguard digest to 216ca1c
All checks were successful
validate / validate (pull_request) Successful in 25s
99697b3602
LinuxServer's 1.0.20260223 tag floats onto each rebuild; this is the
current one (build ls124, alpine 3.24.2). It carries unbound-libs
1.25.2-r2 and pcre2 10.49-r0, closing CVE-2026-81642, CVE-2026-82717
and CVE-2026-103111 that the image scan reports on the running digest.
Renovate would open this same bump once the lookup works; doing it here
saves a second relay bounce.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
renovate: run.sh forwards every RENOVATE_* variable
All checks were successful
validate / validate (pull_request) Successful in 22s
9d38c1ef49
The wrapper passed only the two tokens into the container, so scoping a
dry run to a branch meant rebuilding the docker run by hand. Any
RENOVATE_* in the caller's environment now goes through, which makes
RENOVATE_BASE_BRANCH_PATTERNS=<branch> just renovate the way to test a
pushed branch against the real lookups.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
mysticalsoap deleted branch infra/wireguard-ghcr 2026-10-07 20:56:27 -04:00
Sign in to join this conversation.
No description provided.