Skip to content

Update ghcr.io/calibrain/shelfmark Docker tag to v1.4.0 - #3124

Merged
claytono merged 1 commit into
mainfrom
renovate/ghcr.io-calibrain-shelfmark-v1.4.0
Oct 7, 2026
Merged

claytono merged 1 commit into
mainfrom
renovate/ghcr.io-calibrain-shelfmark-v1.4.0

Conversation

@renovate

@renovate renovate Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change
ghcr.io/calibrain/shelfmark minor v1.3.15 → v1.4.0

Release Notes

calibrain/shelfmark (ghcr.io/calibrain/shelfmark)

v1.4.0

Compare Source

What's Changed
New Contributors

Full Changelog: calibrain/shelfmark@v1.3.15...v1.4.0


Configuration

📅 Schedule: (in timezone America/New_York)

  • Branch creation
    • Between 12:00 AM and 03:59 AM, on day 1 through 7 and 15 through 21 of the month, and on Monday (* 0-3 1-7,15-21 * 1)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from claytono as a code owner October 5, 2026 05:36
@renovate renovate Bot added the renovate label Oct 5, 2026
@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

ghcr.io/calibrain/shelfmark (docker) v1.3.15 -> v1.4.0

Risk: 🔴 Risk

The Deep Dive

Update Scope

Both Shelfmark deployments, kubernetes/shelfmark/deploy.yaml (books/audiobooks) and kubernetes/shelfmark-comics/deploy.yaml, move from v1.3.15@sha256:9602… to v1.4.0@sha256:4ef7…. The digest matches the multi-arch manifest currently published for the v1.4.0 tag. This minor release contains 69 commits (compare). Nothing else changes: env vars, OIDC ExternalSecrets, ingress, PVCs, NFS mounts, and the Recreate strategy stay the same. The image still uses Python 3.14.7. Only the base-image digest, uv (0.12.5 → 0.12.19), and the layer ordering change (#1379).

Performance & Stability

  • Streaming completed books (#1378): /api/localdownload used to read the whole file into RAM, keeping two copies during the transfer. The PR reports a 493 MB audiobook peaking near 963 MB. It now streams from disk. This matters here because the main instance writes audiobooks to /audiobooks, and neither deployment sets resource limits.
  • Shared log handlers (#1316): Each log file now uses one shared handler, which drops open file descriptors from about 78 to 1. This applies automatically.
  • Anna's Archive bypass (#1305, #1325): Stored clearance cookies are replayed again, so each search no longer needs a new browser solve. Countdown pages no longer restart, and the waiting room has a 300-second cap. This only matters if Anna's Archive is enabled as a source. Sources are set in the UI and stored on the /config PVC, which the repo doesn't show.

Features & UX

These are all opt-in. Source, client, and naming settings live in the /config PVC, which the repo doesn't show, so whether any of them is in use is unknown.

  • Libgen as a direct search source (#1326): Libgen joins the catalogue sources, and direct download is now driven by providers (#1337). It has to be enabled in Settings.
  • New download handoffs: TorBox (#1342) and Blackhole torrent handoff (#1312): Both are new client options and need configuration.
  • Static API key (#1366, renamed to SHELFMARK_API_KEY in #1374): Sending the key as a Bearer or X-Api-Key header authenticates the request as the first admin. Neither deploy.yaml sets it, so it stays off.
  • Calibre-library marking (#1377) and download counts or AA result stats (#1336, #1362): These add result-list indicators. Library marking needs a Calibre library to be configured.
  • Search UX: A configurable default tab via DEFAULT_CONTENT_TYPE (#1371) is useful for the audiobook-heavy main instance. Search-mode deep links (#1311) and MyAnonamouse narrator/series/bitrate columns (#1390) are also new.
  • Naming: Adds a {FirstAuthor} token (#1322) and NAMING_WORD_SEPARATOR (#1333). Both are empty or unused by default, so existing paths don't change.
  • AA "Most downloads" sort (#1351): This changes a default. The documented AA_DEFAULT_SORT default moved from relevance to empty, which means "Most downloads". Neither deploy.yaml sets AA_DEFAULT_SORT. Any sort saved in the UI is stored on the /config PVC, which the repo doesn't contain, so it's unknown whether a saved value overrides this. If nothing is saved, Anna's Archive results open in "Most downloads" order. Only the result order changes, and no files or settings are affected.

Security

No GHSA or CVE advisories are published for calibrain/shelfmark (advisories), and this release introduces none. It also contains several auth hardening fixes that apply to this OIDC deployment:

  • OIDC fail-closed (#1397): This changes how login is enforced. It is analyzed under Hazards & Risks.
  • OIDC return_to open redirect (#1359): Backslash paths are now rejected. Both instances use OIDC, so this applies.
  • Download ownership (#1357) and is_admin default (#1358): Users can no longer download queued files that belong to another user. This matters because there are several Authentik users.
  • Proxy-auth non-admin provisioning (#1356): This doesn't apply, because both instances set AUTH_METHOD=oidc, not proxy.

Overall, the update closes security holes and opens none.

Key Fixes

  • Archive extraction now runs (#1343): The default audiobook formats include zip/rar, so archives were imported unchanged. When extraction is allowed, they are now extracted. This can change what lands in /audiobooks for archived audiobook releases.
  • English default when no language is selected (#1396).
  • Torrent and Prowlarr fixes: Queued Real-Debrid torrents keep being polled (#1303). Indexers are skipped during Prowlarr failure back-off (#1324). Deluge gets correct seed-ratio keys (#1367). AudioBookBay reuses the magnet on retry (#1398). The MAM session is kept and the exact Prowlarr search reruns (#1399). The main instance mounts the shared /downloads tree. The commit that deployed it (089efa8f) describes this as the "qBittorrent downloads directory mounted for torrent sources", so torrent sources are part of the intended setup. Which indexers and clients are enabled is stored in the UI settings on the /config PVC, which the repo doesn't contain.
  • Chaptered audio grouping (#1309): Unmatched chapter files are now attached to the existing book group.
  • Cancelled-download guard (#1361): A finished download is no longer overwritten with CANCELLED.

Newer Versions

v1.4.0 (2026-09-26) is the latest release. There are 18 commits on main after it that haven't been released (compare):

  • qBittorrent over HTTPS and non-admin data leaks (#1422): This fixes qBittorrent over https:// (#1417, already present in v1.3.5) and release sources or paths leaking to non-admins (#1418). Both problems predate v1.4.0, so they aren't regressions.
  • Pre-existing download-handling problems: A queued torrent cancelled as stalled (#1420), restart-interrupted downloads stuck as active (#1409), and the SABnzbd API key on cross-host redirects (#1424). None of these was introduced in v1.4.0.
  • TorBox first-poll error (#1403): The bug is in the TorBox client added in v1.4.0. It only affects TorBox, which would be a newly configured client.

No security advisory was introduced in v1.4.0 and fixed later.

Hazards & Risks

OIDC is always enforced, even without a local password admin

v1.3.15 resolved AUTH_METHOD=oidc to none (anonymous full admin) whenever users.db had no local admin with a password (#1387). From v1.4.0, oidc is always enforced (#1397).

  • Applies to this config: Both deploy.yaml files set AUTH_METHOD=oidc, OIDC_AUTO_REDIRECT=true, OIDC_AUTO_PROVISION=true, and OIDC_ADMIN_GROUP=authentik Admins. Neither sets DISABLE_LOCAL_AUTH, so the changed code path runs on both instances.
  • Unknown exposure: It isn't known whether either users.db currently holds a local admin with a password. Upstream docs require one as a fallback (users docs). The repo can't see an admin created in the UI, because it would exist only in the PVC's users.db, so finding no admin record in the repo shows nothing either way. The behaviour change is conditional on this state:
    • If a local admin exists, v1.3.15 already enforces OIDC and login doesn't change.
    • If none exists, v1.3.15 is serving anonymous admin and v1.4.0 will start redirecting every visitor to Authentik.
  • Verified OIDC wiring for that redirect:
    • The Authentik providers allow exactly https://shelfmark.k.oneill.net/api/auth/oidc/callback and https://shelfmark-comics.k.oneill.net/api/auth/oidc/callback (opentofu/modules/authentik/generated-shelfmark*.tf).
    • The client IDs shelfmark and shelfmark-comics and the app slugs match each deploy's OIDC_DISCOVERY_URL.
    • The client secrets come from the same 1Password items via ExternalSecrets.
    • Authentik's built-in profile scope sends a groups claim (blueprint), which OIDC_ADMIN_GROUP relies on.
    • The v1.4.0 OIDC callback does not require a local admin.
  • Compatibility gap: If OIDC has never been enforced on these instances, no end-to-end Authentik login has been proven. The wiring above is all that supports it.
  • Recovery if locked out: start once with AUTH_METHOD=none, create a local admin, then revert (docs).

Other behaviour changes

  • The Anna's Archive default sort change is covered in Features & UX.
  • Archive extraction (#1343) is covered in Key Fixes.

Further Follow-up

  • Does each instance's users.db hold a local password admin?
    • Why it matters: The repo can't show which login state is live. If no local admin exists, merging moves a site from anonymous admin access to Authentik login, and that OIDC login path would be used for the first time. This unknown is why the label is risk.
    • What was checked and why it isn't decided:
      • Manifests, Authentik provider TF, the 1Password/ExternalSecret wiring, the Authentik profile scope blueprint, and the v1.4.0 auth and OIDC code (see Hazards).
      • This evaluation ran in CI mode. The repo context limits kubectl to local mode, so the PVC, pod logs, and live app couldn't be inspected.
      • *.k.oneill.net is homelab ingress, and CI mode forbids contacting private systems, so the login page wasn't probed.
    • Follow-up, before merging, from a machine on the homelab network:
      1. Run curl -s https://shelfmark.k.oneill.net/api/auth/check and curl -s https://shelfmark-comics.k.oneill.net/api/auth/check. In v1.3.15 this endpoint returns "auth_mode": "none" when the fail-open fallback is active and "oidc" otherwise (shelfmark/main.py at v1.3.15). That result decides the question on its own.
      2. As a cross-check, run kubectl -n shelfmark exec deploy/shelfmark -- /app/.venv/bin/python -c "import sqlite3;print(sqlite3.connect('/config/users.db').execute(\"select username from users where role='admin' and password_hash is not null and password_hash!=''\").fetchall())". Then run the same with -n shelfmark-comics exec deploy/shelfmark-comics. The namespaces come from each kustomization.yaml, the /app/.venv interpreter from the upstream Dockerfile (PATH=/app/.venv/bin), and /config from the PVC mount.
    • How each probe result changes the label (all conditional on running the probe):
      • Both report oidc, or both have a local password admin: OIDC is already enforced, so login behaviour doesn't change. The label becomes renovate:safe.
      • Either reports none, and an OIDC login on it then succeeds in a pre-merge kubectl apply -k test, with authentik Admins getting admin: The label becomes renovate:caution. Authentik login is now required, and the update closes an anonymous-admin exposure.
      • Either reports none, and that OIDC login test fails: The label becomes renovate:breaking. Fix the Authentik/OIDC config, or create a local admin through the documented AUTH_METHOD=none recovery, before merging.

Sources


🔴 Verdict: Risk

This minor release hardens security and has no known regressions. It is rated risk because the auth change (#1397) runs on this AUTH_METHOD=oidc config, and CI couldn't tell whether either site is currently fail-open, so it's unknown whether merging changes login behaviour. Run the /api/auth/check probe from the Further Follow-up before merging: oidc makes this safe, and none means testing OIDC login first.

@renovate
renovate Bot force-pushed the renovate/ghcr.io-calibrain-shelfmark-v1.4.0 branch 14 times, most recently from 6dc22d0 to facca46 Compare October 6, 2026 21:59
@renovate
renovate Bot force-pushed the renovate/ghcr.io-calibrain-shelfmark-v1.4.0 branch from facca46 to 1a8e8c2 Compare October 7, 2026 00:11
@claytono
claytono merged commit b9b453d into main Oct 7, 2026
18 checks passed
@claytono
claytono deleted the renovate/ghcr.io-calibrain-shelfmark-v1.4.0 branch October 7, 2026 02:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant