Skip to content

Prepare release 1.22.0-rc.0 - #7838

Merged
CharlieTLe merged 5 commits into
release-1.22from
prepare-release-1.22
Sep 12, 2026
Merged

Prepare release 1.22.0-rc.0#7838
CharlieTLe merged 5 commits into
release-1.22from
prepare-release-1.22

Conversation

@CharlieTLe

Copy link
Copy Markdown
Member

Prepares v1.22.0-rc.0. release-1.22 was cut from master at 4061a3d.

Per RELEASE.md, the release branch is not committed to directly.

Commits

Commit What
Pull minio from quay.io instead of Docker Hub Backport of #7837
Authenticate the integration job's remaining Docker Hub pulls Backport of #7837
Resolve the latest release image to a published version Backport of #7786
Mark release 1.22.0 in progress Backport of #7836
Update version to 1.22.0-rc.0 The actual VERSION bump

The first four are backports of PRs that are open and green against master but still awaiting maintainer review. They are here because the tag build cannot publish without them:

  • minio from quay.iodocker.io/minio/minio is no longer pullable, so all 24 integration legs fail at Preload Images. integration gates deploy, so without this the tag build never pushes any image.
  • Latest release imageintegration/util.go derived the query fuzz comparison image from VERSION. With VERSION=1.22.0-rc.0 it would try to pull quay.io/cortexproject/cortex:v1.22.0-rc.0, which only exists after deploy runs, which needs integration to pass first. This asks quay.io which GA tags are actually published instead.

They will land on master through #7837, #7786 and #7836; release-1.22 gets merged back into master at GA, per RELEASE.md.

What is not bumped

  • docs/getting-started/.env stays at v1.21.1 — RELEASE.md defers it to the stable release.
  • CHANGELOG.md keeps the ## 1.22.0 in progress heading; it becomes ## 1.22.0 <date> at GA.
  • integration/backward_compatibility_test.go does not get v1.22.0 until GA.

Verification

This PR's integration (…, integration_query_fuzz) job is the real test of the release-image resolution against an unpublished VERSION. It should log:

VERSION is 1.22.0-rc.0; the latest release published at or below 1.22.0 is v1.21.1.

Reproduced locally against the live quay.io API before pushing.

Every integration leg is failing at Preload Images:

  Error response from daemon: pull access denied for minio/minio,
  repository does not exist or may require 'docker login':
  denied: requested access to the resource is denied

minio/minio is the first Docker Hub pull in the step, so no leg gets past
it and all 24 fail in about 30 seconds. A CHANGELOG-only pull request
reproduces it, so this is not specific to any change under test. master
was last green at 4061a3d.

This is not a rate limit: the same pull fails right after a successful
'docker login' with the repository credentials. The docker.io/minio/minio
repository is simply no longer accessible.

MinIO still publishes the identical image to quay.io. quay.io/minio/minio
:RELEASE.2024-05-28T17-19-04Z is public and is a manifest list with 8
children, so it covers both the amd64 and arm64 runners.

Point the integration tests, the CI preload list, and the three
development docker-compose stacks at quay.io. The tag is unchanged, so no
behaviour changes.

Signed-off-by: Charlie Le <charlie_le@apple.com>
Preload Images still pulls consul, memcached, redis and postgres from
Docker Hub. #7464 removed the Install Docker Client step from this job,
and that script is where 'docker login' runs, so those pulls have been
anonymous since and are subject to the anonymous rate limit.

Log in explicitly, matching what the build job does. Pull requests from
forks have no secrets, so skip the login there and leave those pulls
anonymous instead of failing the step.

This is hardening, not the fix for the current breakage: minio failed
even when authenticated.

Signed-off-by: Charlie Le <charlie_le@apple.com>
Backport of #7786 onto release-1.22.

integration/util.go derived the query fuzz comparison image straight from
VERSION. The moment VERSION becomes 1.22.0-rc.0 on this branch,
integration_query_fuzz tries to pull
quay.io/cortexproject/cortex:v1.22.0-rc.0, which does not exist: that
image is pushed by the tag build's deploy job, and deploy is gated on
integration passing first.

Ask quay.io which GA tags are actually published instead, and take the
highest one at or below VERSION. The CI step mirrors the same resolution
and exports CORTEX_LATEST_RELEASE_IMAGE for the preload step.

Set the CORTEX_LATEST_RELEASE_IMAGE repository variable to bypass the
lookup.

Signed-off-by: Charlie Le <charlie_le@apple.com>
Add a '## 1.22.0 in progress' section below an empty
'## master / unreleased', move the existing unreleased entries into it,
and order them [CHANGE] -> [FEATURE] -> [ENHANCEMENT] -> [BUGFIX] per
RELEASE.md.

Also fill the gaps reported by
./tools/release/check-changelog.sh v1.21.1...master:

- new entries for #7513, #7514 and #7559
- fold #7323, #7434, #7458, #7463, #7487, #7505, #7687, #7691, #7716,
  #7726, #7775 and #7807 into the entries they belong to

Signed-off-by: Charlie Le <charlie_le@apple.com>
Signed-off-by: Charlie Le <charlie_le@apple.com>
@CharlieTLe
CharlieTLe requested a review from a team as a code owner September 12, 2026 20:57
@CharlieTLe
CharlieTLe requested review from danielblando and removed request for a team September 12, 2026 20:57
@CharlieTLe
CharlieTLe merged commit 9acae44 into release-1.22 Sep 12, 2026
74 of 75 checks passed
@CharlieTLe
CharlieTLe deleted the prepare-release-1.22 branch September 12, 2026 21:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant