fix(container): update image quay.io/ceph/ceph (v20.2.2 ➔ v20.2.3) - #4355
Conversation
|
|
Overall Grade |
Security Reliability Complexity Hygiene |
Code Review Summary
| Analyzer | Status | Updated (UTC) | Details |
|---|---|---|---|
| JavaScript | Aug 5, 2026 9:54p.m. | Review ↗ | |
| Shell | Aug 5, 2026 9:54p.m. | Review ↗ |
Important
AI Review is run only on demand for your team. We're only showing results of static analysis review right now. To trigger AI Review, comment @deepsourcebot review on this thread.
|
Warning Review limit reached
Next review available in: 44 minutes Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (1)
📝 WalkthroughWalkthroughThe Rook Ceph HelmRelease now references Ceph image ChangesRook Ceph image
Estimated code review effort: 1 (Trivial) | ~2 minutes Possibly related PRs
Suggested reviewers: 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
@@ spec.template.spec.containers.rook-ceph-tools.image @@
# apps/v1/Deployment/rook-ceph/rook-ceph-tools
! ± value change
- quay.io/ceph/ceph:v20.2.2@sha256:6b4b5ae33acd3d736eb26d2a19238bce71a22f9cfb99cca887ba6312d0957644
+ quay.io/ceph/ceph:v20.2.3@sha256:d195020de02512030118e772cef7859e92904e91eb4cb21acb503f8b94118137
@@ spec.cephVersion.image @@
# ceph.rook.io/v1/CephCluster/rook-ceph/rook-ceph
! ± value change
- quay.io/ceph/ceph:v20.2.2@sha256:6b4b5ae33acd3d736eb26d2a19238bce71a22f9cfb99cca887ba6312d0957644
+ quay.io/ceph/ceph:v20.2.3@sha256:d195020de02512030118e772cef7859e92904e91eb4cb21acb503f8b94118137
|
@@ spec.values.cephImage.tag @@
# helm.toolkit.fluxcd.io/v2/HelmRelease/rook-ceph/rook-ceph-cluster
! ± value change
- v20.2.2@sha256:6b4b5ae33acd3d736eb26d2a19238bce71a22f9cfb99cca887ba6312d0957644
+ v20.2.3@sha256:d195020de02512030118e772cef7859e92904e91eb4cb21acb503f8b94118137
|
AI Automated ReviewAnalysis engine: omniroute@http://litellm.ai.svc.cluster.local/v1 (openai) RecommendationApprove. This is a routine Renovate patch bump of the Ceph container image ( Change-by-change findings
Must-check items
Release notesRenovate PR body lacks upstream release notes. I attempted to fetch the Ceph v20.2.3 changelog but the tool budget was exhausted before the fetch completed; the only release evidence retrieved was the Ceph v20.2.0 Tentacle release announcement (https://ceph.io/en/news/blog/2025/v20-2-0-tentacle-released/). The specific v20.2.3 changelog is not verified this run. Given the patch-level nature of the bump within the same major line and the prior successful merge of the v20.2.1 → v20.2.2 bump (PR 3304), the risk is low. Standards Compliance
Tool Harness FindingsTool harness planning is pending; no substantive harness findings were produced for this change. Unknowns or Needs Verification
|
| cephImage: | ||
| repository: quay.io/ceph/ceph | ||
| tag: v20.2.2@sha256:6b4b5ae33acd3d736eb26d2a19238bce71a22f9cfb99cca887ba6312d0957644 | ||
| tag: v20.2.3@sha256:d195020de02512030118e772cef7859e92904e91eb4cb21acb503f8b94118137 |
There was a problem hiding this comment.
Info: Ceph v20.2.3 upstream release notes could not be fetched this run (tool budget exhausted); patch-level bump within the v20 Tentacle line is low risk, but the specific changelog remains unverified.
Automated finding from AI PR review.
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@kubernetes/apps/rook-ceph/rook-ceph/cluster/helmrelease.yaml`:
- Line 42: Update the image reference in the HelmRelease to use a valid,
documented Ceph release tag and its matching Quay digest. Verify whether v20.2.3
is intended; otherwise use v20.2.2, and ensure the tag digest matches the
registry so Flux image validation succeeds.
🪄 Autofix
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro Plus
Run ID: 89d78b82-803b-44d0-939f-45b9544d9e09
📒 Files selected for processing (1)
kubernetes/apps/rook-ceph/rook-ceph/cluster/helmrelease.yaml
🔗 Linked repositories identified
CodeRabbit considers these linked repositories for cross-repo context during reviews:
Tanguille/LLMKube(auto-detected)Tanguille/pr-reviewer-action(auto-detected)Tanguille/toolhive(auto-detected)Tanguille/renovate-presets(auto-detected)Tanguille/litellm-operator(auto-detected)Tanguille/2x-R9700-RDNA4-GFX1201-sglang-inference(auto-detected)
| cephImage: | ||
| repository: quay.io/ceph/ceph | ||
| tag: v20.2.2@sha256:6b4b5ae33acd3d736eb26d2a19238bce71a22f9cfb99cca887ba6312d0957644 | ||
| tag: v20.2.3@sha256:d195020de02512030118e772cef7859e92904e91eb4cb21acb503f8b94118137 |
There was a problem hiding this comment.
🩺 Stability & Availability | 🔴 Critical | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
#!/bin/bash
set -euo pipefail
token="$(
curl -fsSL 'https://quay.io/v2/auth?service=quay.io&scope=repository:ceph/ceph:pull' |
jq -r '.token'
)"
curl -fsSI \
-H "Authorization: Bearer ${token}" \
-H 'Accept: application/vnd.oci.image.index.v1+json, application/vnd.docker.distribution.manifest.list.v2+json, application/vnd.oci.image.manifest.v1+json, application/vnd.docker.distribution.manifest.v2+json' \
'https://quay.io/v2/ceph/ceph/manifests/v20.2.3' |
grep -i '^docker-content-digest:'Repository: Tanguille/cluster
Length of output: 204
🏁 Script executed (no clone):
#!/bin/bash
set -euo pipefail
# Try public Quay.io API without authentication
echo "=== Attempting public Quay.io API call ==="
curl -fsSL 'https://quay.io/api/v1/repository/ceph/ceph/tag/v20.2.3' 2>&1 || echo "Public API call failed"
# Also try direct manifest fetch without auth headers (some public images allow this)
echo ""
echo "=== Attempting direct manifest fetch ==="
curl -fsSI -H 'Accept: application/vnd.docker.distribution.manifest.v2+json' \
'https://quay.io/v2/ceph/ceph/manifests/v20.2.3' 2>&1 || echo "Direct manifest fetch failed"
Length of output: 669
🌐 Web query:
rook-ceph v20.2.3 ceph image quay.io sha256 digest
💡 Result:
There is no "v20.2.3" release of the official Ceph container image as of August 5, 2026. The latest minor release in the Ceph "Tentacle" (v20.2.x) series supported by Rook is v20.2.2 [1][2]. Official Ceph container images are hosted on Quay.io at quay.io/ceph/ceph [1][2]. Rook documentation recommends using explicit full-version tags for production clusters (e.g., v20.2.2-20260616) rather than relying on floating major version tags like v20 or v20.2 [1][2]. Because container image digests are unique to each specific image build and vary by architecture (e.g., linux/amd64, linux/arm64), a single digest for "v20.2.3" does not exist. To find the specific sha256 digest for any Ceph image version, you should inspect the image directly from the registry using a tool like skopeo or docker: docker buildx imagetools inspect quay.io/ceph/ceph:v20.2.2-20260616 Replace the tag in the command above with the specific build tag you are using in your CephCluster CRD [1][2].
Citations:
- 1: https://rook.github.io/docs/rook/latest-release/Upgrade/ceph-upgrade/
- 2: https://rook.io/docs/rook/latest-release/Upgrade/ceph-upgrade/
🏁 Script executed:
#!/bin/bash
cat -n kubernetes/apps/rook-ceph/rook-ceph/cluster/helmrelease.yaml | head -50Repository: Tanguille/cluster
Length of output: 2370
The pinned digest does not match the Quay image for this tag.
The tag v20.2.3 on Quay resolves to sha256:14e61b63ef3577a397bb9e836f65fb13d63ecb12842cac2ff498bceee6db4b23, but the HelmRelease pins sha256:d195020de02512030118e772cef7859e92904e91eb4cb21acb503f8b94118137. Flux validates the pulled image against the pinned digest and rejects the image if they do not match. This digest mismatch prevents the HelmRelease from reconciling and blocks Ceph cluster deployment.
Verify whether v20.2.3 is the intended tag. Web search indicates the latest Ceph v20.2.x release is v20.2.2. Update the digest to match the intended tag from the Quay registry, or use a documented release tag such as v20.2.2.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@kubernetes/apps/rook-ceph/rook-ceph/cluster/helmrelease.yaml` at line 42,
Update the image reference in the HelmRelease to use a valid, documented Ceph
release tag and its matching Quay digest. Verify whether v20.2.3 is intended;
otherwise use v20.2.2, and ensure the tag digest matches the registry so Flux
image validation succeeds.
86a9299 to
8058b5c
Compare
This PR contains the following updates:
v20.2.2→v20.2.3Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Configuration
📅 Schedule: (in timezone Europe/Brussels)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about these updates again.
This PR was generated by Mend Renovate. View the repository job log.