infra: pull wireguard from ghcr.io so Renovate can look it up #391
No reviewers
Labels
No labels
audit-work
bug
docs
general-admin
major-upgrade
needs-vps-sync
new-service
on-hold
outside-work
post-podman
renovate
upstream
vps
No milestone
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
mysticalsoap/docker!391
Loading…
Reference in a new issue
No description provided.
Delete branch "infra/wireguard-ghcr"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Problem
Renovate reports
lscr.io/linuxserver/wireguardasno-resulton the dependency dashboard (#3) and skips it, so the image gets no tag or digest PRs. The image scan's finding on it (unbound-libs, two CRITICAL RCEs fixed in 1.25.2-r2, plus a HIGH in pcre2) therefore has no path to clear. Renovate's own digest PR for it (#368) was autoclosed in today's run for the same reason.lscr.io is LinuxServer's vanity front for GHCR, but it answers the tag list itself instead of redirecting, so every lscr.io user shares GHCR's anonymous rate limit on lscr.io's address. Every
ghcr.ioimage in this repo resolves without trouble.Fix
infra/compose.yml: reference the image asghcr.io/linuxserver/wireguard. Same tag (1.0.20260223, the floating tag LinuxServer moves onto each rebuild) and the pinned digest exists there too, so the first commit changes nothing about what runs.1.0.20260223build (ls124, alpine 3.24.2), which is the PR Renovate would open next. One relay bounce instead of two.Maintenance.md § Renovate: the lscr.io rule, with a one-line pointer from the compose file._helper/renovate/run.shforwards everyRENOVATE_*variable, soRENOVATE_BASE_BRANCH_PATTERNS=<branch> just renovatetests a pushed branch; documented next tojust renovatein Maintenance.md.Verification
ghcr.iocarries the pinned digest (manifest fetch by digest returns 200), the same1.0.YYYYMMDDtag shape, and 1308 tags in two pages, so the tag shape survives the move and pagination is not a concern.just up infraon the branch: wireguard and haproxy recreated, all infra containers healthy. The container runs the new digest,wg showhandshake age 34 s, unbound-libs 1.25.2-r2 and pcre2 10.49-r0 installed.--resolveonto the public A record): git.mysticalsoap.com 303, mysticalsoap.com 200.--image-src docker, fixable HIGH+CRITICAL): 0, down from 3 on the previous digest.RENOVATE_BASE_BRANCH_PATTERNS=infra/wireguard-ghcr just renovate(dry run, via the new run.sh): no "Package lookup failures" warning, where today's scheduled run printed one on every branch.After merge:
just deploy --dry-runshould be empty for infra, since live already runs the branch. The next scheduled run (08:00) should clear the warning from #3.Closes #390
🤖 Generated with Claude Code