Prepare v1.9.0 release - #570
Merged
Merged
Conversation
…t-site-issue fix: only set the Cluster scope_type if the site_name is not None
fix: handle object and multi-object custom fields correctly
…cope_type is being set
Clusters without sites or scopes support
… group ip address overriding
check_redfish: stop syncing the live fan reading
Signed-off-by: Ricardo Bartels <ricardo.bartels@telekom.de>
Signed-off-by: Ricardo Bartels <ricardo.bartels@telekom.de>
Modules were only added to dependent_netbox_objects when model_components_as_modules was on. On a run with the option off, interfaces and power ports created by an earlier modules-on run still reference a module, and NetBox reports that relation as an object the run never loaded, so every such object logged 'Problems resolving relation module'. Reproduced on a live NetBox 4.4.5: turning the option off logged the error for every interface and power port of a host previously synced with modules. Read the module objects back on every run instead; the option keeps gating whether components are *created* as modules, not whether existing ones can be resolved. A second modules-on run stays a no-op and the option-off run resolves cleanly (it then models the components as inventory items and orphans the old modules, as before).
CI: fix docker hub push
fix: assign addresses with a non-unique role to every interface
check_redfish: model components as NetBox modules
vmware: create cables from ESXi CDP/LLDP neighbours, behind sync_host_cables
Signed-off-by: Ricardo Bartels <ricardo.bartels@telekom.de>
Signed-off-by: Ricardo Bartels <ricardo.bartels@telekom.de>
The image workflow has been publishing to ghcr.io/bb-ricardo/netbox-sync next to Docker Hub for every development build and tag. Make the GHCR address the documented one in the README and in the Kubernetes CronJob example, and say that v1.9.0 is the last release pushed to Docker Hub so current users get one release cycle to switch. The workflow keeps pushing to both registries for this release; the Docker Hub steps go away after it.
The tag sync option group and the import failure warning still named vsphere-automation-sdk. That package is archived and its runtime imports pkg_resources unconditionally, which no longer exists on Python 3.12+ with setuptools >= 82, so following the old name ends with "Tag syncing will be disabled" (#569). The README and the Dockerfile already use vcf-sdk, whose runtime (9.1.1.0) imports without pkg_resources. Name it in the option description and in the warning, and tell the user what to install.
vcf-sdk is a meta package that pulls every VMware Cloud Foundation binding (NSX, SDDC Manager, Operations, Fleet LCM, Installer, vSAN data protection). netbox-sync only needs create_vsphere_client and the tagging client, which come from vmware-vcenter and the vapi runtime and common client it depends on. Install vmware-vcenter pinned to the version vcf-sdk resolves to today, so a rebuild of the same tag gets the same SDK, and drop the apt-get line that installed nothing. Built from the same development commit: 339 MB -> 248 MB uncompressed, 58 MB -> 52 MB gzipped. All 552 Python files under vmware/ and com/ in the new image are byte-identical to the current one; the 155 files that are no longer installed belong to SDDC Manager, the VCF installer and snapservice. pyvmomi, vmware-vapi-runtime, vmware-vapi-common-client and vmware-vcenter stay at 9.1.1.0, --help works and the process still runs as uid 1000.
The application files were copied with the service user as owner, so the running process could rewrite its own code, while /app itself stayed owned by root, so the default cache directory (/app/cache) could not be created and every container run logged "NetBox caching DISABLED" and fetched all objects from NetBox again. Copy the code as root, read-only for the service user, and create /app/cache owned by the service user and group 0 with mode 0770, which also covers platforms that run the image with an arbitrary uid in group 0. Checked with --read-only --cap-drop ALL --security-opt no-new-privileges and a volume on /app/cache: the cache is writable, the code is not, --help works, and an arbitrary uid in group 0 can write the cache. Before this change the same checks failed on the cache and succeeded on writing the code.
Signed-off-by: Ricardo Bartels <ricardo.bartels@telekom.de>
docker: fix the cache directory, install security updates and only the vCenter bindings
Signed-off-by: Ricardo Bartels <ricardo.bartels@telekom.de>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Merges v1.9.0 Release