From 4ce7a06abee374b4f8aec2f70421f02887c273c2 Mon Sep 17 00:00:00 2001 From: Josh Patterson Date: Tue, 29 Sep 2026 17:39:05 -0400 Subject: [PATCH] upgrade docker to 29.8.1 and containerd.io to 2.3.6 Latest upstream stable for el9. All four NVRs are already carried by the SO prod repo, so no repo change is needed -- a so-repo-sync refresh is enough. Tested on a managersearch and a heavynode (OL 9.8, 3.4.0), upgrading from 29.2.1/2.2.1 both by hand and through the state itself: - The 29.8.1 RPM ships a byte-identical docker.service, so the full ExecStart override in files/iptables-disabled.conf still resolves correctly and the hand-written DOCKER/DOCKER-ISOLATION/DOCKER-USER chains came back byte-identical on both nodes across upgrade, restart and reboot. - update_holds re-pinned the versionlock from the old NVRs to the new ones without intervention, so soup's path needs no change. - docker-py 7.1.0 still creates sobridge and soauth (forced by removing both); bridges keep their configured kernel names rather than br-. - 29.6 changed how dynamic port allocation treats net.ipv4.ip_local_reserved_ports; Strelka's 57314 is both published and reserved, and docker-proxy still owns it with no bind errors. - docker ps --format json gained a HealthStatus key. Additive, so so-status, so-log-check and so-docker-prune all still parse it. - containerd 2.3.6 ships the same config.toml, and it is %config(noreplace) and unmodified on disk, so no .rpmnew and disabled_plugins=["cri"] survives. - Zeek/Suricata/Strelka pipeline verified end-to-end with so-test: 111k packets replayed, 0 capture loss, file extraction and ES ingest all landed. The manifest unknown exclusion in so-log-check still fires on 29.8.1 -- it comes from a tag lookup during the registry-to-registry image copy, not from the 29.2.1 upgrade the old comment blamed -- so only the comment changes. --- salt/common/tools/sbin/so-log-check | 2 +- salt/docker/init.sls | 8 ++++---- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/salt/common/tools/sbin/so-log-check b/salt/common/tools/sbin/so-log-check index 211a3f58d..852592a10 100755 --- a/salt/common/tools/sbin/so-log-check +++ b/salt/common/tools/sbin/so-log-check @@ -241,7 +241,7 @@ if [[ $EXCLUDE_KNOWN_ERRORS == 'Y' ]]; then EXCLUDED_ERRORS="$EXCLUDED_ERRORS|marked for removal" # docker container getting recycled EXCLUDED_ERRORS="$EXCLUDED_ERRORS|tcp 127.0.0.1:6791: bind: address already in use" # so-elastic-fleet agent restarting. Seen starting w/ 8.18.8 https://github.com/elastic/kibana/issues/201459 EXCLUDED_ERRORS="$EXCLUDED_ERRORS|TransformTask\] \[logs-.*user so_kibana lacks the required permissions" # Known issue with integrations starting transform jobs that are explicitly not allowed to start as a system user - EXCLUDED_ERRORS="$EXCLUDED_ERRORS|manifest unknown" # appears in so-dockerregistry log for so-tcpreplay following docker upgrade to 29.2.1-1 + EXCLUDED_ERRORS="$EXCLUDED_ERRORS|manifest unknown" # so-dockerregistry logs a tag lookup miss during image copy; not tied to one docker version EXCLUDED_ERRORS="$EXCLUDED_ERRORS|Could not index event to Elasticsearch.*\"version\" => \"9.0.8\"" # Expected during Elastic upgrade temporarily, as policies referencing older pipelines are updated fi diff --git a/salt/docker/init.sls b/salt/docker/init.sls index 9945a8096..4917cc163 100644 --- a/salt/docker/init.sls +++ b/salt/docker/init.sls @@ -18,10 +18,10 @@ dockergroup: dockerheldpackages: pkg.installed: - pkgs: - - containerd.io: 2.2.1-1.el9 - - docker-ce: 3:29.2.1-1.el9 - - docker-ce-cli: 1:29.2.1-1.el9 - - docker-ce-rootless-extras: 29.2.1-1.el9 + - containerd.io: 2.3.6-1.el9 + - docker-ce: 3:29.8.1-1.el9 + - docker-ce-cli: 1:29.8.1-1.el9 + - docker-ce-rootless-extras: 29.8.1-1.el9 - hold: True - update_holds: True