[bitnami/scylladb] Release 2026.1.5-debian-12-r0 (#94437)

Signed-off-by: Bitnami Bot <bitnami.bot@broadcom.com>
This commit is contained in:
Bitnami Bot
2026-06-08 16:14:28 +02:00
committed by GitHub
parent b475adf6c6
commit 215602ff4e
15 changed files with 181 additions and 51 deletions
+9 -9
View File
@@ -8,13 +8,13 @@ ARG JAVA_EXTRA_SECURITY_DIR="/bitnami/java/extra-security"
ARG TARGETARCH
LABEL org.opencontainers.image.base.name="docker.io/bitnami/minideb:bookworm" \
org.opencontainers.image.created="2026-05-25T13:00:54Z" \
org.opencontainers.image.created="2026-06-08T13:53:04Z" \
org.opencontainers.image.description="Application packaged by Broadcom, Inc." \
org.opencontainers.image.documentation="https://github.com/bitnami/containers/tree/main/bitnami/scylladb/README.md" \
org.opencontainers.image.source="https://github.com/bitnami/containers/tree/main/bitnami/scylladb" \
org.opencontainers.image.title="scylladb" \
org.opencontainers.image.vendor="Broadcom, Inc." \
org.opencontainers.image.version="2026.1.4"
org.opencontainers.image.version="2026.1.5"
ENV HOME="/" \
OS_ARCH="${TARGETARCH:-amd64}" \
@@ -29,19 +29,19 @@ RUN --mount=type=secret,id=downloads_url,env=SECRET_DOWNLOADS_URL \
DOWNLOADS_URL=${SECRET_DOWNLOADS_URL:-${DOWNLOADS_URL}} ; \
mkdir -p /tmp/bitnami/pkg/cache/ ; cd /tmp/bitnami/pkg/cache/ || exit 1 ; \
COMPONENTS=( \
"python-3.12.13-11-linux-${OS_ARCH}-debian-12" \
"python-3.12.13-12-linux-${OS_ARCH}-debian-12" \
"jre-11.0.31-11-1-linux-${OS_ARCH}-debian-12" \
"scylladb-2026.1.4-0-linux-${OS_ARCH}-debian-12" \
"scylladb-2026.1.5-0-linux-${OS_ARCH}-debian-12" \
) ; \
for COMPONENT in "${COMPONENTS[@]}"; do \
if [ ! -f "${COMPONENT}.tar.gz" ]; then \
curl -SsLf "https://${DOWNLOADS_URL}/${COMPONENT}.tar.gz" -O ; \
curl -SsLf "https://${DOWNLOADS_URL}/${COMPONENT}.tar.gz.sha256" -O ; \
fi ; \
sha256sum -c "${COMPONENT}.tar.gz.sha256" ; \
sha256sum -c "/opt/bitnami/checksums/${COMPONENT}.tar.gz.sha256" ; \
tar -zxf "${COMPONENT}.tar.gz" -C /opt/bitnami --strip-components=2 --no-same-owner ; \
rm -rf "${COMPONENT}".tar.gz{,.sha256} ; \
done
rm -rf "${COMPONENT}".tar.gz ; \
done ; \
rm -rf /opt/bitnami/checksums ;
RUN apt-get update && apt-get upgrade -y && \
apt-get clean && rm -rf /var/lib/apt/lists /var/cache/apt/archives
RUN chmod g+rwX /opt/bitnami
@@ -51,7 +51,7 @@ RUN uninstall_packages curl
COPY rootfs /
RUN /opt/bitnami/scripts/scylladb/postunpack.sh
RUN /opt/bitnami/scripts/java/postunpack.sh
ENV APP_VERSION="2026.1.4" \
ENV APP_VERSION="2026.1.5" \
BITNAMI_APP_NAME="scylladb" \
IMAGE_REVISION="0" \
JAVA_HOME="/opt/bitnami/java" \
@@ -0,0 +1 @@
f57e392ddf7e3026a3fe3df1f7b790b815c161f8a024b8c1e0f90d2b0519f0d2 jre-11.0.31-11-1-linux-amd64-debian-12.tar.gz
@@ -0,0 +1 @@
9c3f321524f50f03055d9406bd72d60e31e31b5ae9a910272e525ec9dcf1f0d1 jre-11.0.31-11-1-linux-arm64-debian-12.tar.gz
@@ -0,0 +1 @@
d750a115785a56002ab62b67f1cd27148f29d7640993606a50331c42908cedb9 python-3.12.13-12-linux-amd64-debian-12.tar.gz
@@ -0,0 +1 @@
167870501660cdb2d9075f029431ffd97b83fae928d0f3cc476faa5c96d490fe python-3.12.13-12-linux-arm64-debian-12.tar.gz
@@ -0,0 +1 @@
d2407ed7ead0f4ffacdd3a45fb551c99ed391eada65a9045ed9a524135f70a66 scylladb-2026.1.5-0-linux-amd64-debian-12.tar.gz
@@ -0,0 +1 @@
592f7be6e1beff41020a86a7db6dedb1116f7d4f4c5a456a5a0e620bd84be015 scylladb-2026.1.5-0-linux-arm64-debian-12.tar.gz
@@ -139,3 +139,40 @@ wait_for_log_entry() {
return 1
fi
}
########################
# Creates a secure temporary file containing the provided secret
# Arguments:
# $1 - secret to write to the temporary file
# Returns:
# String
#########################
credential_to_temp_file() {
local secret="$1"
local tmp_file
# Use mktemp with a specific prefix for easier debugging if something lingers
if ! tmp_file=$(mktemp "${TMPDIR:-/tmp}/at.cred.XXXXXXXX"); then
echo "Error: Failed to create temp file" >&2
return 1
fi
# Restrict permissions before writing the secret
chmod 0600 "$tmp_file"
# Write secret and ensure it's flushed to disk
printf "%s" "$secret" > "$tmp_file"
# Output the filename so the caller can capture it
echo "$tmp_file"
}
########################
# Cleans up temporary files created by credential_to_temp_file
# Arguments:
# None
# Returns:
# None
#########################
cleanup_credentials() {
debug "Cleaning up temporary files containing credentials"
rm -rf "${TMPDIR:-/tmp}"/at.cred.*
}
@@ -131,6 +131,7 @@ relativize() {
# -d|--dir-mode - mode for files.
# -u|--user - user
# -g|--group - group
# -n|--no-dereference - do not follow symlinks (use for runtime root chown of daemon-writable dirs)
# Returns:
# None
#########################
@@ -140,6 +141,7 @@ configure_permissions_ownership() {
local file_mode=""
local user=""
local group=""
local follow_symlinks="yes"
# Validate arguments
shift 1
@@ -161,6 +163,9 @@ configure_permissions_ownership() {
shift
group="${1:?missing group}"
;;
-n | --no-dereference)
follow_symlinks="no"
;;
*)
echo "Invalid command line flag $1" >&2
return 1
@@ -169,22 +174,29 @@ configure_permissions_ownership() {
shift
done
# -L: follow symlinks and emits the target path
# This is dangerous at runtime, given a co-located lower-privileged process with write access
# to the target path can redirect the chown/chmod to arbitrary paths. Example:
# Lower-privileged process run: ln -s /etc /tmp/etc
# Then, setup.sh runs: configure_permissions_ownership --dir-mode 775 /tmp
local find_L_flag=(); [[ "$follow_symlinks" == "yes" ]] && find_L_flag=("-L")
# -h: changes symlink inode ownership without touching the target.
local chown_flags=(); [[ "$follow_symlinks" == "no" ]] && chown_flags=("-h")
read -r -a filepaths <<<"$paths"
for p in "${filepaths[@]}"; do
if [[ -e "$p" ]]; then
find -L "$p" -printf ""
if [[ -n $dir_mode ]]; then
find -L "$p" -type d ! -perm "$dir_mode" -print0 | xargs -r -0 chmod "$dir_mode"
find "${find_L_flag[@]}" "$p" -not -type l -type d ! -perm "$dir_mode" -print0 | xargs -r -0 chmod "$dir_mode"
fi
if [[ -n $file_mode ]]; then
find -L "$p" -type f ! -perm "$file_mode" -print0 | xargs -r -0 chmod "$file_mode"
find "${find_L_flag[@]}" "$p" -not -type l -type f ! -perm "$file_mode" -print0 | xargs -r -0 chmod "$file_mode"
fi
if [[ -n $user ]] && [[ -n $group ]]; then
find -L "$p" -print0 | xargs -r -0 chown "${user}:${group}"
find "${find_L_flag[@]}" "$p" -print0 | xargs -r -0 chown "${chown_flags[@]}" "${user}:${group}"
elif [[ -n $user ]] && [[ -z $group ]]; then
find -L "$p" -print0 | xargs -r -0 chown "${user}"
find "${find_L_flag[@]}" "$p" -print0 | xargs -r -0 chown "${chown_flags[@]}" "${user}"
elif [[ -z $user ]] && [[ -n $group ]]; then
find -L "$p" -print0 | xargs -r -0 chgrp "${group}"
find "${find_L_flag[@]}" "$p" -print0 | xargs -r -0 chgrp "${chown_flags[@]}" "${group}"
fi
else
stderr_print "$p does not exist"
@@ -170,7 +170,7 @@ ensure_user_exists() {
if [[ -n "$home" ]]; then
mkdir -p "$home"
usermod -d "$home" "$user" >/dev/null 2>&1
configure_permissions_ownership "$home" -d "775" -f "664" -u "$user" -g "$group"
configure_permissions_ownership "$home" -d "775" -f "664" -u "$user" -g "$group" -n
fi
}
@@ -20,7 +20,7 @@
#########################
is_int() {
local -r int="${1:?missing value}"
if [[ "$int" =~ ^-?[0-9]+ ]]; then
if [[ "$int" =~ ^-?[0-9]+$ ]]; then
true
else
false
@@ -49,3 +49,36 @@ get_sematic_version () {
fi
fi
}
########################
# Compares two semantic versions
# Arguments:
# $1 - version1: first version to compare
# $2 - version2: second version to compare
# Returns:
# -1 if version1 is less than version2
# 0 if version1 is equal to version2
# 1 if version1 is greater than version2
#########################
compare_semantic_versions() {
local version1="${1:?version1 is required}"
local version2="${2:?version2 is required}"
local major1 major2 minor1 minor2 patch1 patch2
major1="$(get_sematic_version "$version1" 1)"
major2="$(get_sematic_version "$version2" 1)"
minor1="$(get_sematic_version "$version1" 2)"
minor2="$(get_sematic_version "$version2" 2)"
patch1="$(get_sematic_version "$version1" 3)"
patch2="$(get_sematic_version "$version2" 3)"
if [[ "$major1" -eq "$major2" ]] && [[ "$minor1" -eq "$minor2" ]] && [[ "$patch1" -eq "$patch2" ]]; then
echo "0"
elif [[ "$major1" -lt "$major2" ]] ||
{ [[ "$major1" -eq "$major2" ]] && [[ "$minor1" -lt "$minor2" ]]; } ||
{ [[ "$major1" -eq "$major2" ]] && [[ "$minor1" -eq "$minor2" ]] && [[ "$patch1" -lt "$patch2" ]]; }; then
echo "-1"
else
echo "1"
fi
}
@@ -14,17 +14,6 @@ cassandra_validate_tls() {
error_code=1
}
check_empty_value() {
if is_empty_value "${!1}"; then
print_validation_error "The $1 environment variable is empty or not set."
fi
}
check_default_password() {
if [[ "${!1}" = "cassandra" ]]; then
warn "You set the environment variable $1=cassandra. This is the default value when bootstrapping ScyllaDB and should not be used in production environments."
fi
}
if is_boolean_yes "$DB_CLIENT_ENCRYPTION" || is_boolean_yes "$DB_INTERNODE_ENCRYPTION"; then
! [[ -f "$DB_SSL_CERT_FILE" ]] && print_validation_error "Certificate file $DB_SSL_CERT_FILE does not exist. Please mount a certificate file in that location"
! [[ -f "$DB_SSL_KEY_FILE" ]] && print_validation_error "Certificate key file $DB_SSL_KEY_FILE does not exist. Please mount a certificate file in that location"
@@ -792,11 +781,10 @@ cassandra_change_cassandra_password() {
if (echo "ALTER USER cassandra WITH PASSWORD \$\$${escaped_password}\$\$;" | cassandra_execute_with_retries "$retries" "$sleep_time" "$user" "$old_password"); then
debug "ALTER USER command executed. Trying to log in"
# ScyllaDB uses 127.0.0.1 explicitly to keep cqlsh on the loopback interface
# and avoid the topology-aware reconnect to the pod IP during first-boot init.
local cql_host=""
[[ "$DB_FLAVOR" = "scylladb" ]] && cql_host="127.0.0.1"
wait_for_cql_access "$user" "$new_password" "$cql_host" "$retries" "$sleep_time"
# The CQL port is bound to loopback during first-boot credential seeding, so
# verify the new password over 127.0.0.1. This also keeps cqlsh on the loopback
# interface and avoids the topology-aware reconnect to the pod IP.
wait_for_cql_access "$user" "$new_password" "127.0.0.1" "$retries" "$sleep_time"
info "Password updated successfully"
fi
}
@@ -927,15 +915,13 @@ cassandra_initialize() {
am_i_root && chown -R "$DB_DAEMON_USER:$DB_DAEMON_GROUP" "$dir"
done
if ! is_dir_empty "$DB_DATA_DIR"; then
info "Deploying $DB_FLAVOR with persisted data"
else
info "Deploying $DB_FLAVOR from scratch"
__credential_seeding() {
if [[ "$DB_FLAVOR" = "scylladb" ]]; then
# ScyllaDB 2025.4.5+ (PR #22532): keep cqlsh on loopback during first-boot init.
# Otherwise, cqlsh reconnects to the pod IP (via system.local), blocked by the ensure_superuser_is_created gate.
cassandra_start_bg "$DB_FIRST_BOOT_LOG_FILE" "" "" "--broadcast-rpc-address 127.0.0.1"
else
cassandra_yaml_set "rpc_address" "127.0.0.1"
cassandra_start_bg "$DB_FIRST_BOOT_LOG_FILE"
fi
if is_boolean_yes "$DB_PASSWORD_SEEDER"; then
@@ -947,10 +933,10 @@ cassandra_initialize() {
wait_for_superuser_log_entry "$DB_FIRST_BOOT_LOG_FILE" "$DB_PEER_CQL_MAX_RETRIES" "$DB_PEER_CQL_SLEEP_TIME"
wait_for_cql_access "cassandra" "cassandra" "127.0.0.1" "$DB_PEER_CQL_MAX_RETRIES" "$DB_PEER_CQL_SLEEP_TIME"
else
# Check that all peers are ready
for peer in ${DB_PEERS//,/ }; do
wait_for_cql_access "cassandra" "cassandra" "$peer" "$DB_PEER_CQL_MAX_RETRIES" "$DB_PEER_CQL_SLEEP_TIME"
done
# Wait for all peers to be ready before changing the password
wait_for_peers_ready "$DB_PEERS" "$DB_PEER_CQL_MAX_RETRIES" "$DB_PEER_CQL_SLEEP_TIME"
# Ensure the local auth subsystem is ready (over loopback) before altering it.
wait_for_cql_access "cassandra" "cassandra" "127.0.0.1" "$DB_PEER_CQL_MAX_RETRIES" "$DB_PEER_CQL_SLEEP_TIME"
fi
# Setup user
if [[ "$DB_USER" = "cassandra" ]]; then
@@ -960,19 +946,23 @@ cassandra_initialize() {
fi
cassandra_execute_startup_cql
touch "$CASSANDRA_INIT_SEMAPHORE"
else
info "Non-seeder node. Waiting for synchronization"
# ScyllaDB uses 127.0.0.1 explicitly to keep cqlsh on the loopback interface
# and avoid the topology-aware reconnect to the pod IP during first-boot init.
local cql_host=""
[[ "$DB_FLAVOR" = "scylladb" ]] && cql_host="127.0.0.1"
wait_for_cql_access "$DB_USER" "$DB_PASSWORD" "$cql_host" "$DB_PEER_CQL_MAX_RETRIES" "$DB_PEER_CQL_SLEEP_TIME"
fi
# ScyllaDB is started with '--broadcast-rpc-address 127.0.0.1' for init only;
# stop it so the entrypoint can start it cleanly with the real address.
if [[ "$DB_FLAVOR" = "scylladb" ]]; then
cassandra_stop
wait_for_cql_access "$DB_USER" "$DB_PASSWORD" "127.0.0.1" "$DB_PEER_CQL_MAX_RETRIES" "$DB_PEER_CQL_SLEEP_TIME"
fi
cassandra_stop
[[ "$DB_FLAVOR" = "cassandra" && "$DB_ENABLE_REMOTE_CONNECTIONS" = "true" ]] && cassandra_yaml_set "rpc_address" "0.0.0.0"
}
if is_dir_empty "$DB_DATA_DIR"; then
info "Deploying $DB_FLAVOR from scratch"
__credential_seeding
elif [[ ! -f "$CASSANDRA_INIT_SEMAPHORE" ]] && is_boolean_yes "$DB_PASSWORD_SEEDER"; then
warn "The init semaphore is absent: the seed pod was interrupted between start and credential seeding. Re-running seeding against the persisted data."
__credential_seeding
else
info "Deploying $DB_FLAVOR with persisted data"
fi
}
@@ -1295,6 +1285,55 @@ wait_for_cql_access() {
fi
}
########################
# Wait until all cluster peers report Up/Normal (UN) via gossip (nodetool status)
# This is used during first-boot credential seeding instead of connecting to each
# peer over CQL with the default credentials, which would require exposing the
# default superuser on the network.
# Globals:
# BITNAMI_DEBUG
# DB_*
# Arguments:
# 1 - Comma/space separated list of peers (default: $DB_PEERS)
# 2 - Maximum number of retries (default: $DB_PEER_CQL_MAX_RETRIES)
# 3 - Sleep time between retries (default: $DB_PEER_CQL_SLEEP_TIME)
# Returns:
# None
#########################
wait_for_peers_ready() {
local -r peers="${1:-$DB_PEERS}"
local -r retries="${2:-$DB_PEER_CQL_MAX_RETRIES}"
local -r sleep_time="${3:-$DB_PEER_CQL_SLEEP_TIME}"
local peer peer_ip
for peer in ${peers//,/ }; do
peer_ip="$(dns_lookup "$peer" "v4")"
[[ -z "$peer_ip" ]] && peer_ip="$peer"
info "Waiting for peer $peer to reach Up/Normal (UN) status"
check_peer_un() {
# Using legacy RMI URL parsing to avoid URISyntaxException: 'Malformed IPv6 address at index 7: rmi://[127.0.0.1]:7199' error
# https://community.datastax.com/questions/13764/java-version-for-cassandra-3113.html
local -r check_cmd=("nodetool" "-Dcom.sun.jndi.rmiURLParsing=legacy")
local -r check_args=("status" "--port" "$DB_JMX_PORT_NUMBER")
local -r check_regex="UN\s*(${peer}|${peer_ip})"
local output="/dev/null"
if [[ "$BITNAMI_DEBUG" = "true" ]]; then
output="/dev/stdout"
fi
"${check_cmd[@]}" "${check_args[@]}" | grep -E "${check_regex}" >"${output}"
}
if ! retry_while check_peer_un "$retries" "$sleep_time"; then
error "Peer $peer did not reach Up/Normal (UN) status"
exit 1
fi
done
info "All peers reached Up/Normal (UN) status"
}
########################
# Check if Cassandra is running
# Globals:
@@ -120,6 +120,8 @@ export SCYLLADB_INITSCRIPTS_BOOT_LOG_FILE="${DB_LOG_DIR}/scylladb_init_scripts_b
export DB_INITSCRIPTS_BOOT_LOG_FILE="$SCYLLADB_INITSCRIPTS_BOOT_LOG_FILE"
export SCYLLADB_PID_FILE="${DB_TMP_DIR}/scylladb.pid"
export DB_PID_FILE="$SCYLLADB_PID_FILE"
export SCYLLADB_INIT_SEMAPHORE="${DB_VOLUME_DIR}/.scylladb-init"
export DB_INIT_SEMAPHORE="$SCYLLADB_INIT_SEMAPHORE"
export PATH="${DB_BIN_DIR}:${BITNAMI_ROOT_DIR}/common/bin:${BITNAMI_ROOT_DIR}/python/bin:${BITNAMI_ROOT_DIR}/java/bin:$PATH"
# System users (when running with a privileged user)
+1
View File
@@ -155,6 +155,7 @@ The following tables list the main variables you can set.
| `SCYLLADB_FIRST_BOOT_LOG_FILE` | Path to the ScyllaDB first boot log file | `${DB_LOG_DIR}/scylladb_first_boot.log` |
| `SCYLLADB_INITSCRIPTS_BOOT_LOG_FILE` | Path to the ScyllaDB init scripts log file | `${DB_LOG_DIR}/scylladb_init_scripts_boot.log` |
| `SCYLLADB_PID_FILE` | Path to the ScyllaDB pid file | `${DB_TMP_DIR}/scylladb.pid` |
| `SCYLLADB_INIT_SEMAPHORE` | Path to the ScyllaDB init semaphore file | `${DB_VOLUME_DIR}/.scylladb-init` |
| `SCYLLADB_DAEMON_USER` | ScyllaDB system user | `scylladb` |
| `SCYLLADB_DAEMON_GROUP` | ScyllaDB system group | `scylladb` |
| `SCYLLADB_CONF_DIR` | ScyllaDB configuration directory | `${DB_BASE_DIR}/etc` |