chore(apps): bump the pins that can move without mirroring

Of the 33 apps behind upstream, these five pull straight from a public
registry, so their targets exist already and the bump is real work rather
than a promise:

  strfry          1.0.4        -> 1.1.1
  netbird (nginx) 1.27-alpine  -> 1.31.3-alpine
  pine    (nginx) 1.27-alpine  -> 1.31.3-alpine
  pine-piper      2.2.2        -> 2.4.2
  nostr-rs-relay  0.8.9        -> 0.10.0

All five targets verified present upstream with skopeo before editing, so
none of these can turn into an image-not-found on a node.

Deliberately NOT bumped here, though they are also direct-pull:
core-lightning (v23.08 -> v26.06, ~3 years of schema migrations), gitea
(four minors of DB migrations), and netbird-server/netbird-dashboard —
which have to move in lockstep and carry their own migrations. Those are
each a piece of work, not a line edit.

The other 24 are blocked on something else entirely: their images live in
our mirror and none of the upgrade targets have been mirrored yet, so a
pin bump alone would break every install. That needs registry push
credentials.

These take effect when the catalog is regenerated and re-signed — the
catalog overrides on-disk manifests, so editing here changes nothing on a
node until the signing ceremony.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
archipelago
2026-08-17 10:54:05 -04:00
co-authored by Claude Opus 5
parent 86923f05a5
commit 7d6e52537a
5 changed files with 8 additions and 8 deletions
+1 -1
View File
@@ -18,7 +18,7 @@ app:
container_name: netbird container_name: netbird
container: container:
image: docker.io/library/nginx:1.27-alpine image: docker.io/library/nginx:1.31.3-alpine
pull_policy: if-not-present pull_policy: if-not-present
network: netbird-net network: netbird-net
# Self-signed TLS cert materialised before create — the dashboard needs a # Self-signed TLS cert materialised before create — the dashboard needs a
+2 -2
View File
@@ -1,7 +1,7 @@
app: app:
id: nostr-rs-relay id: nostr-rs-relay
name: Nostr Relay (Rust) name: Nostr Relay (Rust)
version: 0.8.0 version: 0.10.0
# Where this app comes from, so scripts/check-upstream-releases.py can # Where this app comes from, so scripts/check-upstream-releases.py can
# tell us when the pin below has fallen behind. Without it nothing can: # tell us when the pin below has fallen behind. Without it nothing can:
# container.image names our mirror, not the project it was mirrored from. # container.image names our mirror, not the project it was mirrored from.
@@ -11,7 +11,7 @@ app:
description: High-performance Nostr relay written in Rust. Host your own decentralized social media relay and earn networking profits. description: High-performance Nostr relay written in Rust. Host your own decentralized social media relay and earn networking profits.
container: container:
image: scsibug/nostr-rs-relay:0.8.9 image: scsibug/nostr-rs-relay:0.10.0
image_signature: cosign://... image_signature: cosign://...
pull_policy: verify-signature pull_policy: verify-signature
data_uid: "1000:1000" data_uid: "1000:1000"
+2 -2
View File
@@ -1,7 +1,7 @@
app: app:
id: pine-piper id: pine-piper
name: Pine Piper (TTS) name: Pine Piper (TTS)
version: "2.2.2" version: "2.4.2"
# Where this app comes from, so scripts/check-upstream-releases.py can # Where this app comes from, so scripts/check-upstream-releases.py can
# tell us when the pin below has fallen behind. Without it nothing can: # tell us when the pin below has fallen behind. Without it nothing can:
# container.image names our mirror, not the project it was mirrored from. # container.image names our mirror, not the project it was mirrored from.
@@ -18,7 +18,7 @@ app:
container_name: pine-piper container_name: pine-piper
container: container:
image: docker.io/rhasspy/wyoming-piper:2.2.2 image: docker.io/rhasspy/wyoming-piper:2.4.2
pull_policy: if-not-present pull_policy: if-not-present
network: archy-net network: archy-net
network_aliases: [pine-piper] network_aliases: [pine-piper]
+1 -1
View File
@@ -19,7 +19,7 @@ app:
container_name: pine container_name: pine
container: container:
image: docker.io/library/nginx:1.27-alpine image: docker.io/library/nginx:1.31.3-alpine
pull_policy: if-not-present pull_policy: if-not-present
network: archy-net network: archy-net
network_aliases: [pine] network_aliases: [pine]
+2 -2
View File
@@ -1,7 +1,7 @@
app: app:
id: strfry id: strfry
name: Strfry Nostr Relay name: Strfry Nostr Relay
version: 0.9.0 version: 1.1.1
# Where this app comes from, so scripts/check-upstream-releases.py can # Where this app comes from, so scripts/check-upstream-releases.py can
# tell us when the pin below has fallen behind. Without it nothing can: # tell us when the pin below has fallen behind. Without it nothing can:
# container.image names our mirror, not the project it was mirrored from. # container.image names our mirror, not the project it was mirrored from.
@@ -11,7 +11,7 @@ app:
description: Lightweight Nostr relay written in C++. Alternative to nostr-rs-relay with lower resource usage. description: Lightweight Nostr relay written in C++. Alternative to nostr-rs-relay with lower resource usage.
container: container:
image: dockurr/strfry:1.0.4 image: dockurr/strfry:1.1.1
image_signature: cosign://... image_signature: cosign://...
pull_policy: verify-signature pull_policy: verify-signature