Skip to content

chore(deps): update delivery-kit and remove legacy ELF libraries - #493

Merged
ldmonster merged 3 commits into
mainfrom
chore/deps/delivery-kit-2-79-1
Sep 24, 2026
Merged

ldmonster merged 3 commits into
mainfrom
chore/deps/delivery-kit-2-79-1

Conversation

@alexey-igrychev

@alexey-igrychev alexey-igrychev commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Update the embedded Delivery Kit to remove the ELF signer's C-library dependencies from d8 builds. The previous SDK prevents static linking on Ubuntu 26.04 with OpenSSL 3.5, reporting unresolved jent_read_entropy and uncompress symbols.

What

  • Advance the complete embedded Delivery Kit from v2.69.0-dk to v2.79.1-dk.1, including its required SDK, nelm, kubedog, logboek and copy-recurse versions.
  • Select SDK v1.4.2, whose ELF signer uses Go and elfedit instead of the former C implementation. VERIFIED: the minimal signer program links statically and runs on Ubuntu 26.04.1 where SDK v1.2.0 fails.
  • Stop installing libelf-dev, libssl-dev, libuv1-dev, libzstd-dev and zlib1g-dev in the release build, and remove the CGO_LDFLAGS=-lz workaround.
  • Retain libbtrfs-dev for Buildah and the existing static-linking flags in Taskfile; this does not remove CGO from d8 as a whole.

Why

The old SDK hardcodes a static C-library link list. Ubuntu 26.04's OpenSSL 3.5 needs additional transitive dependencies and exposes the incorrect zlib ordering in that list, so importing the SDK can break the entire d8 build even when ELF signing is not used.

Updating to the Go implementation removes that dependency on the host's OpenSSL link requirements. Maintaining another linker workaround in d8 would leave the same distribution-dependent failure mode in place; the release build's former signer packages and -lz workaround are no longer needed.

Use the current Delivery Kit 2 release and its delivery-kit-sdk v1.4.2 dependency, which implements ELF signing without the former OpenSSL static-link flags. Update the module graph and checksums.

Signed-off-by: Aleksei Igrychev <aleksei.igrychev@palark.com>
Remove the system ELF, OpenSSL, libuv, zstd and zlib development packages used by the former SDK signer, together with its static-link workaround. Keep libbtrfs development headers for the remaining Buildah CGO code.

Signed-off-by: Aleksei Igrychev <aleksei.igrychev@palark.com>
@alexey-igrychev alexey-igrychev changed the title chore(deps): update delivery-kit to v2.79.1-dk.1 chore(deps): update delivery-kit and remove legacy ELF libraries Sep 23, 2026
@alexey-igrychev

alexey-igrychev commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor Author

Verification

  • On native Ubuntu 26.04.1 with GCC 15.2, OpenSSL 3.5.5 and Go 1.26.0, built the same minimal program referencing inhouse.Sign against SDK v1.2.0 and v1.4.2, using -linkmode external -extldflags=-static. The old version fails with unresolved jent_read_entropy and uncompress; the new version produces a statically linked executable and runs. This checks the reported SDK link failure, not a complete native d8 build on Ubuntu 26.04.
  • Local task lint:dev:check reports the same nonamedreturns finding as CI at internal/mirror/dist/cli.go:125. That file has identical contents before and after this PR (Git blob 732dd940b6c856766d35b515ee728135442478e4).

Review focus

  • Review the complete Delivery Kit upgrade from 2.69 to 2.79 and the selected deployment/build dependencies in go.mod; the scope extends beyond the ELF signer.
  • Check the release-package removal in trdl.yaml against the retained Buildah requirements; libbtrfs-dev and the static-linking flags remain.

Follow-up

  • Published d8 v0.33.22, which contains this PR. Downstream version updates are unblocked.
  • In deckhouse/deckhouse, update candi/version_map.yml from d8 v0.33.19 and remove obsolete ELF C build dependencies and the libuv symlink setup from modules/007-registrypackages/images/d8/werf.inc.yaml and modules/800-deckhouse-tools/images/web/werf.inc.yaml, retaining the dependencies needed by Buildah.
  • In deckhouse/virtualization, update d8 v0.33.11 in .github/actions/install-d8/action.yml and .github/actions/setup-e2e-toolchain/action.yml, then verify the E2E toolchain with the new release.
  • In deckhouse/modules-gitlab-ci, update d8 v0.29.24 in templates/CVE_Scan.gitlab-ci.yml and verify its d8 stronghold authentication and secret-reading flow.
  • In deckhouse/deckhouse, update d8 v0.15.0 in testing/cloud_layouts/script-commander.sh and verify the module/platform mirror pull and push commands across that version jump.
  • In deckhouse/deckhouse, verify the mirror flow in testing/cloud_layouts/script.sh after it picks up the new release through releases/latest; no version-pin edit is needed there.
  • In deckhouse/lib-connection, smoke-test the d8 k proxy integration with the new release.

Rollout progress

  • DKP packaged d8, cloud mirror pin and GitLab helper: draft chore(deps): update d8 to v0.33.22 deckhouse#23341. Both release build targets pass in the exact DKP builder with the reduced package set. Synthetic authenticated/TLS registry mirror flows pass. Full CI image assembly and real cloud runs remain open.
  • CVE scan template: draft chore(deps): bump d8 CLI to v0.33.22 in CVE scan template modules-gitlab-ci#167. Old/new stronghold response handling matches against a local mock API; real GitLab identity validation remains open.
  • Virtualization GitHub actions: submitted to the GitLab source repository because GitHub is a read-only mirror. The active GitLab E2E runner toolchain is separate and still needs its installed d8 version checked.
  • Published d8 satisfies the tested proxy-side lib-connection contracts on macOS and Linux: startup parsing, impersonation forwarding and shutdown. The real SSH/tunnel/node-shim integration remains unverified.
  • Direct SDK PR chore(deps): update delivery-kit-sdk to v1.4.2 deckhouse#23274: Tests pass on rerun and changelog validation passes after restoring its required heading; milestone intentionally remains unset and private CSE build/signature validation remains open.

@ldmonster
ldmonster merged commit 80e2c67 into main Sep 24, 2026
12 of 14 checks passed
@ldmonster ldmonster added the enhancement New feature or request label Sep 24, 2026
@ldmonster
ldmonster deleted the chore/deps/delivery-kit-2-79-1 branch September 24, 2026 15:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants