Skip to content

Prepare v1.9.0 release - #570

Merged
bb-Ricardo merged 197 commits into
mainfrom
development
Oct 2, 2026
Merged

bb-Ricardo merged 197 commits into
mainfrom
development

Conversation

@bb-Ricardo

Copy link
Copy Markdown
Owner

Merges v1.9.0 Release

pto-centrica and others added 30 commits February 26, 2025 09:18
…t-site-issue

fix: only set the Cluster scope_type if the site_name is not None
fix: handle object and multi-object custom fields correctly
Sergey Sannikov and others added 14 commits September 10, 2026 13:57
check_redfish: stop syncing the live fan reading
Signed-off-by: Ricardo Bartels <ricardo.bartels@telekom.de>
Signed-off-by: Ricardo Bartels <ricardo.bartels@telekom.de>
Modules were only added to dependent_netbox_objects when
model_components_as_modules was on. On a run with the option off, interfaces
and power ports created by an earlier modules-on run still reference a module,
and NetBox reports that relation as an object the run never loaded, so every
such object logged 'Problems resolving relation module'. Reproduced on a live
NetBox 4.4.5: turning the option off logged the error for every interface and
power port of a host previously synced with modules.

Read the module objects back on every run instead; the option keeps gating
whether components are *created* as modules, not whether existing ones can be
resolved. A second modules-on run stays a no-op and the option-off run resolves
cleanly (it then models the components as inventory items and orphans the old
modules, as before).
fix: assign addresses with a non-unique role to every interface
check_redfish: model components as NetBox modules
vmware: create cables from ESXi CDP/LLDP neighbours, behind sync_host_cables
Signed-off-by: Ricardo Bartels <ricardo.bartels@telekom.de>
Signed-off-by: Ricardo Bartels <ricardo.bartels@telekom.de>
semx and others added 14 commits October 1, 2026 22:26
The image workflow has been publishing to ghcr.io/bb-ricardo/netbox-sync next
to Docker Hub for every development build and tag. Make the GHCR address the
documented one in the README and in the Kubernetes CronJob example, and say
that v1.9.0 is the last release pushed to Docker Hub so current users get one
release cycle to switch. The workflow keeps pushing to both registries for
this release; the Docker Hub steps go away after it.
The tag sync option group and the import failure warning still named
vsphere-automation-sdk. That package is archived and its runtime imports
pkg_resources unconditionally, which no longer exists on Python 3.12+ with
setuptools >= 82, so following the old name ends with "Tag syncing will be
disabled" (#569). The README and the Dockerfile already use vcf-sdk, whose
runtime (9.1.1.0) imports without pkg_resources. Name it in the option
description and in the warning, and tell the user what to install.
vcf-sdk is a meta package that pulls every VMware Cloud Foundation binding
(NSX, SDDC Manager, Operations, Fleet LCM, Installer, vSAN data protection).
netbox-sync only needs create_vsphere_client and the tagging client, which
come from vmware-vcenter and the vapi runtime and common client it depends
on. Install vmware-vcenter pinned to the version vcf-sdk resolves to today,
so a rebuild of the same tag gets the same SDK, and drop the apt-get line
that installed nothing.

Built from the same development commit: 339 MB -> 248 MB uncompressed,
58 MB -> 52 MB gzipped. All 552 Python files under vmware/ and com/ in the
new image are byte-identical to the current one; the 155 files that are no
longer installed belong to SDDC Manager, the VCF installer and snapservice.
pyvmomi, vmware-vapi-runtime, vmware-vapi-common-client and vmware-vcenter
stay at 9.1.1.0, --help works and the process still runs as uid 1000.
The application files were copied with the service user as owner, so the
running process could rewrite its own code, while /app itself stayed owned
by root, so the default cache directory (/app/cache) could not be created
and every container run logged "NetBox caching DISABLED" and fetched all
objects from NetBox again.

Copy the code as root, read-only for the service user, and create /app/cache
owned by the service user and group 0 with mode 0770, which also covers
platforms that run the image with an arbitrary uid in group 0.

Checked with --read-only --cap-drop ALL --security-opt no-new-privileges and
a volume on /app/cache: the cache is writable, the code is not, --help works,
and an arbitrary uid in group 0 can write the cache. Before this change the
same checks failed on the cache and succeeded on writing the code.
Signed-off-by: Ricardo Bartels <ricardo.bartels@telekom.de>
docker: fix the cache directory, install security updates and only the vCenter bindings
Signed-off-by: Ricardo Bartels <ricardo.bartels@telekom.de>
@bb-Ricardo
bb-Ricardo merged commit 6905c38 into main Oct 2, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.