1"use strict";(self.webpackChunkwoodpecker=self.webpackChunkwoodpecker||[]).push([["3500"],{89305(e,n,i){i.r(n),i.d(n,{metadata:()=>s,default:()=>a,frontMatter:()=>l,contentTitle:()=>c,toc:()=>t,assets:()=>o});var s=JSON.parse('{"type":"mdx","permalink":"/migrations","source":"@site/src/pages/migrations.md","description":"To enhance the usability of Woodpecker and meet evolving security standards, occasional migrations are necessary. While we aim to minimize these changes, some are unavoidable. If you experience significant issues during a migration to a new version, please let us know so maintainers can reassess the updates.","frontMatter":{},"unlisted":false}'),r=i(94686),d=i(23191);let l={},c="Migrations",o={},t=[{value:"<code>next</code>",id:"next",level:2},{value:"User-facing migrations",id:"user-facing-migrations",level:3},{value:"API changes",id:"api-changes",level:3},{value:"Admin-facing migrations",id:"admin-facing-migrations",level:3},{value:"Extensions",id:"extensions",level:4},{value:"API changes",id:"api-changes-1",level:3},{value:"Internal changes",id:"internal-changes",level:3},{value:"3.0.0",id:"300",level:2},{value:"User-facing migrations",id:"user-facing-migrations-1",level:3},{value:"Workflow syntax changes",id:"workflow-syntax-changes",level:4},{value:"Environment variables",id:"environment-variables",level:4},{value:"Security",id:"security",level:4},{value:"Former deprecations",id:"former-deprecations",level:4},{value:"CLI changes",id:"cli-changes",level:4},{value:"API changes",id:"api-changes-2",level:4},{value:"Miscellaneous",id:"miscellaneous",level:4},{value:"Admin-facing migrations",id:"admin-facing-migrations-1",level:3},{value:"Updated tokens",id:"updated-tokens",level:4},{value:"Image tags",id:"image-tags",level:4},{value:"Rootless images",id:"rootless-images",level:4},{value:"2.7.2",id:"272",level:2},{value:"2.0.0",id:"200",level:2},{value:"1.0.0",id:"100",level:2},{value:"0.15.0",id:"0150",level:2},{value:"0.14.0",id:"0140",level:2},{value:"From Drone",id:"from-drone",level:2}];function h(e){let n={a:"a",admonition:"admonition",code:"code",h1:"h1",h2:"h2",h3:"h3",h4:"h4",header:"header",li:"li",ol:"ol",p:"p",pre:"pre",table:"table",tbody:"tbody",td:"td",th:"th",thead:"thead",tr:"tr",ul:"ul",...(0,d.R)(),...e.components};return(0,r.jsxs)(r.Fragment,{children:["\n",(0,r.jsx)(n.header,{children:(0,r.jsx)(n.h1,{id:"migrations",children:"Migrations"})}),"\n",(0,r.jsx)(n.p,{children:"To enhance the usability of Woodpecker and meet evolving security standards, occasional migrations are necessary. While we aim to minimize these changes, some are unavoidable. If you experience significant issues during a migration to a new version, please let us know so maintainers can reassess the updates."}),"\n",(0,r.jsx)(n.h2,{id:"next",children:(0,r.jsx)(n.code,{children:"next"})}),"\n",(0,r.jsx)(n.h3,{id:"user-facing-migrations",children:"User-facing migrations"}),"\n",(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsxs)(n.li,{children:["(Kubernetes) Deprecated ",(0,r.jsx)(n.code,{children:"step"})," label on pod in favor of new namespaced label ",(0,r.jsx)(n.code,{children:"woodpecker-ci.org/step"}),". The ",(0,r.jsx)(n.code,{children:"step"})," label will be removed in a future update."]}),"\n",(0,r.jsxs)(n.li,{children:["deprecated ",(0,r.jsx)(n.code,{children:"CI_COMMIT_AUTHOR_AVATAR"})," and ",(0,r.jsx)(n.code,{children:"CI_PREV_COMMIT_AUTHOR_AVATAR"})," env vars in favor of ",(0,r.jsx)(n.code,{children:"CI_PIPELINE_AVATAR"})," and ",(0,r.jsx)(n.code,{children:"CI_PREV_PIPELINE_AVATAR"})]}),"\n",(0,r.jsxs)(n.li,{children:["deprecated ",(0,r.jsx)(n.code,{children:"CI_COMMIT_PRERELEASE"})," env var in favor of ",(0,r.jsx)(n.code,{children:"CI_PIPELINE_RELEASE_PRE"})]}),"\n",(0,r.jsxs)(n.li,{children:["deprecated ",(0,r.jsx)(n.code,{children:"runs_on"})," workflow property in favor of ",(0,r.jsx)(n.code,{children:"when.status"}),"."]}),"\n"]}),"\n",(0,r.jsx)(n.h3,{id:"api-changes",children:"API changes"}),"\n",(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsxs)(n.li,{children:["The pipeline model is currently being changed to use nested objects grouped based on the event.\nFollowing properties are deprecated and should be replaced by the their new counterparts:\n",(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsxs)(n.li,{children:[(0,r.jsx)(n.code,{children:"title"})," =>\n",(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsxs)(n.li,{children:[(0,r.jsx)(n.code,{children:"release.title"}),": for release events"]}),"\n"]}),"\n"]}),"\n",(0,r.jsxs)(n.li,{children:[(0,r.jsx)(n.code,{children:"message"})," =>\n",(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsxs)(n.li,{children:[(0,r.jsx)(n.code,{children:"tag_title"})," for tag events"]}),"\n"]}),"\n"]}),"\n",(0,r.jsxs)(n.li,{children:[(0,r.jsx)(n.code,{children:"is_prerelease"})," => ",(0,r.jsx)(n.code,{children:"release.is_prerelease"})]}),"\n",(0,r.jsxs)(n.li,{children:["extraction from ",(0,r.jsx)(n.code,{children:"ref"})," => ",(0,r.jsx)(n.code,{children:"tag_title"})]}),"\n"]}),"\n"]}),"\n"]}),"\n",(0,r.jsx)(n.h3,{id:"admin-facing-migrations",children:"Admin-facing migrations"}),"\n",(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsxs)(n.li,{children:["changed env var ",(0,r.jsx)(n.code,{children:"WOODPECKER_CONFIG_SERVICE_ENDPOINT"})," to ",(0,r.jsx)(n.code,{children:"WOODPECKER_CONFIG_EXTENSION_ENDPOINT"})]}),"\n",(0,r.jsxs)(n.li,{children:["changed env var ",(0,r.jsx)(n.code,{children:"WOODPECKER_GRPC_VERIFY"})," to ",(0,r.jsx)(n.code,{children:"WOODPECKER_GRPC_SKIP_VERIFY"}),". \u26A0\uFE0F The env var was inverted before, the naming was fixed. Setting to ",(0,r.jsx)(n.code,{children:"true"})," disables verification."]}),"\n"]}),"\n",(0,r.jsx)(n.h4,{id:"extensions",children:"Extensions"}),"\n",(0,r.jsxs)(n.p,{children:["Extension HTTP calls (as of now the configuration extension) will by default only be allowed to contact external hosts. Set ",(0,r.jsx)(n.code,{children:"WOODPECKER_EXTENSIONS_ALLOWED_HOSTS"})," accordingly to allow additional hosts as needed."]}),"\n",(0,r.jsx)(n.h3,{id:"api-changes-1",children:"API changes"}),"\n",(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsxs)(n.li,{children:["The pipeline model has been changed to use nested objects grouped based on the event (e.g. instead of a generic ",(0,r.jsx)(n.code,{children:"title"})," it now uses ",(0,r.jsx)(n.code,{children:"pr.title"}),"). Following properties are deprecated and should be replaced by the their new counterparts:\n",(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsxs)(n.li,{children:[(0,r.jsx)(n.code,{children:"sender"})," =>\n",(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsxs)(n.li,{children:[(0,r.jsx)(n.code,{children:"cron"})," for cron events"]}),"\n"]}),"\n"]}),"\n"]}),"\n"]}),"\n"]}),"\n",(0,r.jsx)(n.h3,{id:"internal-changes",children:"Internal
1changes"}),"\n",(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsxs)(n.li,{children:["Renamed the server flag ",(0,r.jsx)(n.code,{children:"config-service-endpoint"})," to ",(0,r.jsx)(n.code,{children:"config-extension-endpoint"})]}),"\n"]}),"\n",(0,r.jsx)(n.h2,{id:"300",children:"3.0.0"}),"\n",(0,r.jsx)(n.h3,{id:"user-facing-migrations-1",children:"User-facing migrations"}),"\n",(0,r.jsx)(n.h4,{id:"workflow-syntax-changes",children:"Workflow syntax changes"}),"\n",(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsxs)(n.li,{children:["\n",(0,r.jsxs)(n.p,{children:[(0,r.jsx)(n.code,{children:"secrets"})," have been entirely removed in favor of ",(0,r.jsx)(n.code,{children:"environment"})," combined with the ",(0,r.jsx)(n.code,{children:"from_secret"})," syntax (",(0,r.jsx)(n.a,{href:"https://github.com/woodpecker-ci/woodpecker/pull/4363",children:"#4363"}),").\nAs ",(0,r.jsx)(n.code,{children:"secrets"})," are just normal env vars which are masked, the goal was to allow them to be declared next to normal env vars and at the same time reduce the keyword syntax count.\nAdditionally, the ",(0,r.jsx)(n.code,{children:"from_secret"})," syntax gives more flexibility in naming.\nWhereas beforehand ",(0,r.jsx)(n.code,{children:"secrets"})," where always named after their initial secret name, the ",(0,r.jsx)(n.code,{children:"from_secret"})," reference can now be different.\nLast, one can inject multiple different env vars from the same secret reference."]}),"\n",(0,r.jsx)(n.p,{children:"2.x:"}),"\n",(0,r.jsx)(n.pre,{children:(0,r.jsx)(n.code,{className:"language-yaml",children:"secrets: [my_token]\n"})}),"\n",(0,r.jsx)(n.p,{children:"3.x:"}),"\n",(0,r.jsx)(n.pre,{children:(0,r.jsx)(n.code,{className:"language-yaml",children:"environment:\n MY_TOKEN:\n from_secret: my_token\n"})}),"\n",(0,r.jsxs)(n.p,{children:["Learn more about using ",(0,r.jsx)(n.a,{href:"https://woodpecker-ci.org/docs/next/usage/secrets#usage",children:"secrets"})]}),"\n"]}),"\n",(0,r.jsxs)(n.li,{children:["\n",(0,r.jsxs)(n.p,{children:["The ",(0,r.jsx)(n.code,{children:"includes"})," and ",(0,r.jsx)(n.code,{children:"excludes"})," event filter options have been removed"]}),"\n"]}),"\n",(0,r.jsxs)(n.li,{children:["\n",(0,r.jsxs)(n.p,{children:["Previously, env vars have been automatically sanitized to uppercase.\nAs this has been confusing, the type-case of the secret definition is now respected (",(0,r.jsx)(n.a,{href:"https://github.com/woodpecker-ci/woodpecker/pull/3375",children:"#3375"}),")."]}),"\n"]}),"\n",(0,r.jsxs)(n.li,{children:["\n",(0,r.jsxs)(n.p,{children:["The ",(0,r.jsx)(n.code,{children:"environment"})," filter option has been removed in favor of ",(0,r.jsx)(n.code,{children:"when.evaluate"})]}),"\n"]}),"\n",(0,r.jsxs)(n.li,{children:["\n",(0,r.jsxs)(n.p,{children:["Grouping of steps via ",(0,r.jsx)(n.code,{children:"steps.[name].group"})," should now be done using ",(0,r.jsx)(n.code,{children:"steps.[name].depends_on"})]}),"\n"]}),"\n"]}),"\n",(0,r.jsx)(n.h4,{id:"environment-variables",children:"Environment variables"}),"\n",(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsxs)(n.li,{children:["\n",(0,r.jsxs)(n.p,{children:["Environment variables must now be defined as maps. List definitions are disallowed. (",(0,r.jsx)(n.a,{href:"https://github.com/woodpecker-ci/woodpecker/pull/4016",children:"#4016"}),")"]}),"\n",(0,r.jsx)(n.p,{children:"2.x:"}),"\n",(0,r.jsx)(n.pre,{children:(0,r.jsx)(n.code,{className:"language-yaml",children:"environment:\n - ENV1=value1\n"})}),"\n",(0,r.jsx)(n.p,{children:"3.x:"}),"\n",(0,r.jsx)(n.pre,{children:(0,r.jsx)(n.code,{className:"language-yaml",children:"environment:\n ENV1: value1\n"})}),"\n"]}),"\n"]}),"\n",(0,r.jsx)(n.p,{children:"The following built-in environment variables have been removed/replaced:"}),"\n",(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsxs)(n.li,{children:[(0,r.jsx)(n.code,{children:"CI_COMMIT_URL"})," has been deprecated in favor of ",(0,r.jsx)(n.code,{children:"CI_PIPELINE_FORGE_URL"})]}),"\n",(0,r.jsxs)(n.li,{children:[(0,r.jsx)(n.code,{children:"CI_STEP_FINISHED"})," as it was empty during execution"]}),"\n",(0,r.jsxs)(n.li,{children:[(0,r.jsx)(n.code,{children:"CI_PIPELINE_FINISHED"})," as it was empty during execution"]}),"\n",(0,r.jsxs)(n.li,{children:[(0,r.jsx)(n.code,{children:"CI_PIPELINE_STATUS"})," due to always being set to ",(0,r.jsx)(n.code,{children:"success"})]}),"\n",(0,r.jsxs)(n.li,{children:[(0,r.jsx)(n.code,{children:"CI_STEP_STATUS"})," due to always being set to ",(0,r.jsx)(n.code,{children:"success"})]}),"\n",(0,r.jsxs)(n.li,{children:[(0,r.jsx)(n.code,{children:"WOODPECKER_WEBHOOK_HOST"})," in favor of ",(0,r.jsx)(n.code,{children:"WOODPECKER_EXPERT_WEBHOOK_HOST"})]}),"\n"]}),"\n",(0,r.jsxs)(n.p,{children:["Environment variables which are empty after workflow parsing are not being injected into the build but filtered out beforehand (",(0,r.jsx)(n.a,{href:"https://github.com/woodpecker-ci/woodpecker/pull/4193",children:"#4193"}),")"]}),"\n",(0,r.jsx)(n.h4,{id:"security",children:"Security"}),"\n",(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsxs)(n.li,{children:['The "gated" option, which restricted which pipelines can start right away without requiring approval, has been replaced by "require-approval" option. Even though this feature (',(0,r.jsx)(n.a,{href:"https://github.com/woodpecker-ci/woodpecker/pull/3348",children:"#3348"}),") was backported to 2.8, no default is explicitly set.\nThe new default in 3.0 is to require approval only for forked repositories.\nThis allows easier management of dependency bots and other trusted entities having write access to the repository."]}),"\n"]}),"\n",(0,r.jsx)(n.h4,{id:"former-deprecations",children:"Former deprecations"}),"\n",(0,r.jsx)(n.p,{children:"The following syntax deprecations will now result in an error:"}),"\n",(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsxs)(n.li,{children:[(0,r.jsx)(n.code,{children:"pipeline:"})," (",(0,r.jsx)(n.a,{href:"https://github.com/woodpecker-ci/woodpecker/pull/3916",children:"#3916"}),")"]}),"\n",(0,r.jsxs)(n.li,{children:[(0,r.jsx)(n.code,{children:"platform:"})," (",(0,r.jsx)(n.a,{href:"https://github.com/woodpecker-ci/woodpecker/pull/3916",children:"#3916"}),")"]}),"\n",(0,r.jsxs)(n.li,{children:[(0,r.jsx)(n.code,{children:"branches:"})," (",(0,r.jsx)(n.a,{href:"https://github.com/woodpecker-ci/woodpecker/pull/3916",children:"#3916"}),")"]}),"\n"]}),"\n",(0,r.jsx)(n.h4,{id:"cli-changes",children:"CLI changes"}),"\n",(0,r.jsx)(n.p,{children:"The following restructuring was done to achieve a more consistent grouping:"}),"\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n",(0,r.jsxs)(n.table,{children:[(0,r.jsx)(n.thead,{children:(0,r.jsxs)(n.tr,{children:[(0,r.jsx)(n.th,{children:"Old Command"}),(0,r.jsx)(n.th,{children:"New Command"})]})}),(0,r.jsxs)(n.tbody,{children:[(0,r.jsxs)(n.tr,{children:[(0,r.jsx)(n.td,{children:(0,r.jsx)(n.code,{children:"woodpecker-cli registry"})}),(0,r.jsx)(n.td,{children:(0,r.jsx)(n.code,{children:"woodpecker-cli repo registry"})})]}),(0,r.jsxs)(n.tr,{children:[(0,r.jsx)(n.td,{children:(0,r.jsx)(n.code,{children:"woodpecker-cli secret --global"})}),(0,r.jsx)(n.td,{children:(0,r.jsx)(n.code,{children:"woodpecker-cli admin secret"})})]}),(0,r.jsxs)(n.tr,{children:[(0,r.jsx)(n.td,{children:(0,r.jsx)(n.code,{children:"woodpecker-cli user"})}),(0,r.jsx)(n.td,{children:(0,r.jsx)(n.code,{children:"woodpecker-cli admin user"})})]}),(0,r.jsxs)(n.tr,{children:[(0,r.jsx)(n.td,{children:(0,r.jsx)(n.code,{children:"woodpecker-cli log-level"})}),(0,r.jsx)(n.td,{children:(0,r.jsx)(n.code,{children:"woodpecker-cli admin log-level"})})]}),(0,r.jsxs)(n.tr,{children:[(0,r.jsx)(n.td,{children:(0,r.jsx)(n.code,{children:"woodpecker-cli secret --organization"})}),(0,r.jsx)(n.td,{children:(0,r.jsx)(n.code,{children:"woodpecker-cli org secret"})})]}),(0,r.jsxs)(n.tr,{children:[(0,r.jsx)(n.td,{children:(0,r.jsx)(n.code,{children:"woodpecker-cli deploy"})}),(0,r.jsx)(n.td,{children:(0,r.jsx)(n.code,{children:"woodpecker-cli pipeline deploy"})})]}),(0,r.jsxs)(n.tr,{children:[(0,r.jsx)(n.td,{children:(0,r.jsx)(n.code,{children:"woodpecker-cli log"})}),(0,r.jsx)(n.td,{children:(0,r.jsx)(n.code,{children:"woodpecker-cli pipeline log"})})]}),(0,r.jsxs)(n.tr,{children:[(0,r.jsx)(n.td,{children:(0,r.jsx)(n.code,{children:"woodpecker-cli cron"})}),(0,r.jsx)(n.td,{children:(0,r.jsx)(n.code,{children:"woodpecker-cli repo cron"})})]}),(0,r.jsxs)(n.tr,{children:[(0,r.jsx)(n.td,{children:(0,r.jsx)(n.code,{children:"woodpecker-cli secret --repository"})}),(0,r.jsx)(n.td,{children:(0,r.jsx)(n.code,{children:"woodpecker-cli repo secret"})})]}),(0,r.jsxs)(n.tr,{children:[(0,r.jsx)(n.td,{children:(0,r.jsx)(n.code,{children:"woodpecker-cli pipeline logs"})}),(0,r.jsx)(n.td,{children:(0,r.jsx)(n.code,{children:"woodpecker-cli pipeline log show"})})]}),(0,r.jsxs)(n.tr,{children:[(0,r.jsx)(n.td,{children:(0,r.jsx)(n.code,{children:"woodpecker-cli (registry,secret,...) info"})}),(0,r.jsx)(n.td,{children:(0,r.jsx)(n.code,{children:"woodpecker-cli (registry,secret,...) show"})})]})]})]}),"\n",(0,r.jsxs)(n.p,{children:["(",(0,r.jsx)(n.a,{href:"https://github.com/woodpecker-ci/woodpecker/pull/4467",children:"#4467"})," and ",(0,r.jsx)(n.a,{href:"https://github.com/woodpecker-ci/woodpecker/pull/4481",children:"#4481"}),")"]}),"\n",(0,r.jsx)(n.h4,{id:"api-changes-2",children:"API changes"}),"\n",(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsxs)(n.li,{children:["Removed deprecated ",(0,r.jsx)(n.code,{children:"registry/"})," endpoint. Use ",(0,r.jsx)(n.code,{children:"registries"}),", ",(0,r.jsx)(n.code,{children:"/authorize/token"})]}),"\n"]}),"\n",(0,r.jsx)(n.h4,{id:"miscellaneous",children:"Miscellaneous"}),"\n",(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsxs)(n.li,{children:["\n",(0,r.jsxs)(n.p,{children:["For ",(0,r.jsx)(n.code,{children:"woodpecker-cli"})," containers, ",(0,r.jsx)(n.code,{children:"/woodpecker"})," has been set as the default ",(0,r.jsx)(n.code,{children:"workdir"})]}),"\n"]}),"\n",(0,r.jsxs)(n.li,{children:["\n",(0,r.jsxs)(n.p,{children:['Plugin filters for secrets (in the "secrets" repo settings) can now validate against tags.\nAdditionally, the description has been updated to reflect that these filters only apply to plugins (',(0,r.jsx)(n.a,{href:"https://github.com/woodpecker-ci/woodpecker/pull/4069",children:"#4069"}),")."]}),"\n"]}),"\n",(0,r.jsxs)(n.li,{children:["\n",(0,r.jsx)(n.p,{children:"SDK changes:"}),"\n",(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsxs)(n.li,{children:["The SDK fields ",(0,r.jsx)(n.code,{children:"start_time"}),", ",(0,r.jsx)(n.code,{children:"end_time"}),", ",(0,r.jsx)(n.code,{children:"created_at"}),", ",(0,r.jsx)(n.code,{children:"started_at"}),", ",(0,r.jsx)(n.code,{children:"finished_at"})," and ",(0,r.jsx)(n.code,{children:"reviewed_at"})," have been renamed to ",(0,r.jsx)(n.code,{children:"started"}),", ",(0,r.jsx)(n.code,{children:"finished"}),", ",(0,r.jsx)(n.code,{children:"created"}),", ",(0,r.jsx)(n.code,{children:"started"}),", ",(0,r.jsx)(n.code,{children:"finished"}),", ",(0,r.jsx)(n.code,{children:"reviewed"})," (",(0,r.jsx)(n.a,{href:"https://github.com/woodpecker-ci/woodpecker/pull/3968",children:"#3968"}),")"]}),"\n",(0,r.jsxs)(n.li,{children:["The ",(0,r.jsx)(n.code,{children:"trusted"})," field of the repo model was changed from ",(0,r.jsx)(n.code,{children:"boolean"})," to ",(0,r.jsx)(n.code,{children:"object"})," (",(0,r.jsx)(n.a,{href:"https://github.com/woodpecker-ci/woodpecker/pull/4025",children:"#4025"}),")"]}),"\n"]}),"\n"]}),"\n",(0,r.jsxs)(n.li,{children:["\n",(0,r.jsx)(n.p,{children:"CRON definitions now follow standard Linux syntax without seconds. An automatic migration will attempt to update your\nsett
1ings - ensure the update completes successfully."}),"\n",(0,r.jsx)(n.p,{children:"Example definition for a CRON job running at 8 am daily:"}),"\n",(0,r.jsx)(n.p,{children:"2.x:"}),"\n",(0,r.jsx)(n.pre,{children:(0,r.jsx)(n.code,{className:"language-sh",children:"0 0 8 * * *\n"})}),"\n",(0,r.jsx)(n.p,{children:"3.x:"}),"\n",(0,r.jsx)(n.pre,{children:(0,r.jsx)(n.code,{className:"language-sh",children:"0 8 * * *\n"})}),"\n"]}),"\n",(0,r.jsxs)(n.li,{children:["\n",(0,r.jsxs)(n.p,{children:["Native Let's Encrypt certificate support has been dropped as it was almost unused and causing frequent issues.\nLet's Encrypt needs to be set up standalone now. The SSL key pair can still be used in ",(0,r.jsx)(n.code,{children:"WOODPECKER_SERVER_CERT"})," and ",(0,r.jsx)(n.code,{children:"WOODPECKER_SERVER_KEY"})," as an alternative to using a reverse proxy for TLS termination. (",(0,r.jsx)(n.a,{href:"https://github.com/woodpecker-ci/woodpecker/pull/4541",children:"#4541"}),")"]}),"\n"]}),"\n",(0,r.jsxs)(n.li,{children:["\n",(0,r.jsxs)(n.p,{children:["The filename of the CLI binary changed for DEB and RPM packages, it is now called ",(0,r.jsx)(n.code,{children:"woodpecker-cli"})," instead of ",(0,r.jsx)(n.code,{children:"woodpecker"}),"."]}),"\n"]}),"\n"]}),"\n",(0,r.jsx)(n.h3,{id:"admin-facing-migrations-1",children:"Admin-facing migrations"}),"\n",(0,r.jsx)(n.h4,{id:"updated-tokens",children:"Updated tokens"}),"\n",(0,r.jsxs)(n.p,{children:["The Webhook tokens have been changed for enhanced security and therefore existing repositories need to be updated using the ",(0,r.jsx)(n.code,{children:"Repair all"})," button in the admin settings (",(0,r.jsx)(n.a,{href:"https://github.com/woodpecker-ci/woodpecker/pull/4013",children:"#4013"}),")."]}),"\n",(0,r.jsx)(n.h4,{id:"image-tags",children:"Image tags"}),"\n",(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsxs)(n.li,{children:["\n",(0,r.jsxs)(n.p,{children:["The ",(0,r.jsx)(n.code,{children:"latest"})," tag has been dropped to avoid accidental major version upgrades.\nA dedicated semver tag specification must be used, i.e., either a fixed version (like ",(0,r.jsx)(n.code,{children:"v3.0.0"}),") or a rolling tag (e.g. ",(0,r.jsx)(n.code,{children:"v3.0"})," or ",(0,r.jsx)(n.code,{children:"v3"}),")."]}),"\n"]}),"\n",(0,r.jsxs)(n.li,{children:["\n",(0,r.jsxs)(n.p,{children:["Previously, some (official) plugins were granted the ",(0,r.jsx)(n.code,{children:"privileged"})," option by default to allow simplified usage.\nTo streamline this process and enhance security transparency, no plugin is granted the ",(0,r.jsx)(n.code,{children:"privileged"})," options by default anymore.\nTo allow the use of these plugins in >= 3.0, they must be set explicitly through ",(0,r.jsx)(n.code,{children:"WOODPECKER_PLUGINS_PRIVILEGED"})," on the admin side.\nThis change mainly impacts the use of the ",(0,r.jsx)(n.code,{children:"woodpeckerci/plugin-docker-buildx"})," plugin, which now will not work anymore unless explicitly listed through this env var (",(0,r.jsx)(n.a,{href:"https://github.com/woodpecker-ci/woodpecker/pull/4053",children:"#4053"}),")"]}),"\n"]}),"\n",(0,r.jsxs)(n.li,{children:["\n",(0,r.jsx)(n.p,{children:"Environment variable deprecations:"}),"\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n",(0,r.jsxs)(n.table,{children:[(0,r.jsx)(n.thead,{children:(0,r.jsxs)(n.tr,{children:[(0,r.jsx)(n.th,{children:"Deprecated Variable"}),(0,r.jsx)(n.th,{children:"New Variable"})]})}),(0,r.jsxs)(n.tbody,{children:[(0,r.jsxs)(n.tr,{children:[(0,r.jsx)(n.td,{children:(0,r.jsx)(n.code,{children:"WOODPECKER_LOG_XORM"})}),(0,r.jsx)(n.td,{children:(0,r.jsx)(n.code,{children:"WOODPECKER_DATABASE_LOG"})})]}),(0,r.jsxs)(n.tr,{children:[(0,r.jsx)(n.td,{children:(0,r.jsx)(n.code,{children:"WOODPECKER_LOG_XORM_SQL"})}),(0,r.jsx)(n.td,{children:(0,r.jsx)(n.code,{children:"WOODPECKER_DATABASE_LOG_SQL"})})]}),(0,r.jsxs)(n.tr,{children:[(0,r.jsx)(n.td,{children:(0,r.jsx)(n.code,{children:"WOODPECKER_FILTER_LABELS"})}),(0,r.jsx)(n.td,{children:(0,r.jsx)(n.code,{children:"WOODPECKER_AGENT_LABELS"})})]}),(0,r.jsxs)(n.tr,{children:[(0,r.jsx)(n.td,{children:(0,r.jsx)(n.code,{children:"WOODPECKER_ESCALATE"})}),(0,r.jsx)(n.td,{children:(0,r.jsx)(n.code,{children:"WOODPECKER_PLUGINS_PRIVILEGED"})})]}),(0,r.jsxs)(n.tr,{children:[(0,r.jsx)(n.td,{children:(0,r.jsx)(n.code,{children:"WOODPECKER_DEFAULT_CLONE_IMAGE"})}),(0,r.jsx)(n.td,{children:(0,r.jsx)(n.code,{children:"WOODPECKER_DEFAULT_CLONE_PLUGIN"})})]}),(0,r.jsxs)(n.tr,{children:[(0,r.jsx)(n.td,{children:(0,r.jsx)(n.code,{children:"WOODPECKER_DEV_OAUTH_HOST"})}),(0,r.jsx)(n.td,{children:(0,r.jsx)(n.code,{children:"WOODPECKER_EXPERT_FORGE_OAUTH_HOST"})})]}),(0,r.jsxs)(n.tr,{children:[(0,r.jsx)(n.td,{children:(0,r.jsx)(n.code,{children:"WOODPECKER_DEV_GITEA_OAUTH_URL"})}),(0,r.jsx)(n.td,{children:(0,r.jsx)(n.code,{children:"WOODPECKER_EXPERT_FORGE_OAUTH_HOST"})})]}),(0,r.jsxs)(n.tr,{children:[(0,r.jsx)(n.td,{children:(0,r.jsx)(n.code,{children:"WOODPECKER_ROOT_PATH"})}),(0,r.jsx)(n.td,{children:(0,r.jsx)(n.code,{children:"WOODPECKER_HOST"})})]}),(0,r.jsxs)(n.tr,{children:[(0,r.jsx)(n.td,{children:(0,r.jsx)(n.code,{children:"WOODPECKER_ROOT_URL"})}),(0,r.jsx)(n.td,{children:(0,r.jsx)(n.code,{children:"WOODPECKER_HOST"})})]})]})]}),"\n"]}),"\n",(0,r.jsxs)(n.li,{children:["\n",(0,r.jsxs)(n.p,{children:['The resource limit settings for the "docker" backend were moved from the server into agent configuration.\nThis allows setting limits on an agent-level which allows greater resource definition granularity (',(0,r.jsx)(n.a,{href:"https://github.com/woodpecker-ci/woodpecker/pull/3174",children:"#3174"}),")"]}),"\n"]}),"\n",(0,r.jsxs)(n.li,{children:["\n",(0,r.jsxs)(n.p,{children:['"Kubernetes" backend: previously the image pull secret name was hard-coded to ',(0,r.jsx)(n.code,{children:"regcred"}),".\nTo allow more flexibility and specifying multiple pull secrets, the default has been removed.\nImage pull secrets must now be set explicitly via env var ",(0,r.jsx)(n.code,{children:"WOODPECKER_BACKEND_K8S_PULL_SECRET_NAMES"})," (",(0,r.jsx)(n.a,{href:"https://github.com/woodpecker-ci/woodpecker/pull/4005",children:"#4005"}),")"]}),"\n"]}),"\n",(0,r.jsxs)(n.li,{children:["\n",(0,r.jsxs)(n.p,{children:["Webhook signatures now use the ",(0,r.jsx)(n.code,{children:"rfc9421"})," protocol"]}),"\n"]}),"\n",(0,r.jsxs)(n.li,{children:["\n",(0,r.jsxs)(n.p,{children:["Git is now the only officially supported SCM.\nNo others were supported previously, but the existence of the env var ",(0,r.jsx)(n.code,{children:"CI_REPO_SCM"})," indicated that others might be.\nThe env var has now been removed including unused code associated with it. (",(0,r.jsx)(n.a,{href:"https://github.com/woodpecker-ci/woodpecker/pull/4346",children:"#4346"}),")"]}),"\n"]}),"\n"]}),"\n",(0,r.jsx)(n.h4,{id:"rootless-images",children:"Rootless images"}),"\n",(0,r.jsx)(n.p,{children:"Woodpecker now supports running rootless images by adjusting the entrypoints and directory permissions in the containers in a way that allows non-privileged users to execute tasks."}),"\n",(0,r.jsxs)(n.p,{children:["In addition, all images published by Woodpecker (Server, Agent, CLI) now use a non-privileged user (",(0,r.jsx)(n.code,{children:"woodpecker"})," with UID and GID ",(0,r.jsx)(n.code,{children:"1000"}),") by default. If you have volumes attached to the containers, you may
1need to change the ownership of these directories from ",(0,r.jsx)(n.code,{children:"root"})," to ",(0,r.jsx)(n.code,{children:"woodpecker"})," by executing ",(0,r.jsx)(n.code,{children:"chown -R 1000:1000 <mount dir>"}),"."]}),"\n",(0,r.jsx)(n.admonition,{type:"info",children:(0,r.jsxs)(n.p,{children:["The agent image must remain rootful by default to be able to mount the Docker socket when Woodpecker is used with the ",(0,r.jsx)(n.code,{children:"docker"})," backend.\nThe helm chart will start to use a non-privileged user by utilizing ",(0,r.jsx)(n.code,{children:"securityContext"}),".\nRunning a completely rootless agent with the ",(0,r.jsx)(n.code,{children:"docker"})," backend may be possible by using a rootless docker daemon.\nHowever, this requires more work and is currently not supported."]})}),"\n",(0,r.jsx)(n.h2,{id:"272",children:"2.7.2"}),"\n",(0,r.jsxs)(n.p,{children:["To secure your instance, set ",(0,r.jsx)(n.code,{children:"WOODPECKER_PLUGINS_PRIVILEGED"})," to only allow specific versions of the ",(0,r.jsx)(n.code,{children:"woodpeckerci/plugin-docker-buildx"})," plugin, use version 5.0.0 or above. This prevents older, potentially unstable versions from being privileged."]}),"\n",(0,r.jsx)(n.p,{children:"For example, to allow only version 5.0.0, use:"}),"\n",(0,r.jsx)(n.pre,{children:(0,r.jsx)(n.code,{className:"language-bash",children:"WOODPECKER_PLUGINS_PRIVILEGED=woodpeckerci/plugin-docker-buildx:5.0.0\n"})}),"\n",(0,r.jsx)(n.p,{children:"To allow multiple versions, you can separate them with commas:"}),"\n",(0,r.jsx)(n.pre,{children:(0,r.jsx)(n.code,{className:"language-bash",children:"WOODPECKER_PLUGINS_PRIVILEGED=woodpeckerci/plugin-docker-buildx:5.0.0,woodpeckerci/plugin-docker-buildx:5.1.0\n"})}),"\n",(0,r.jsx)(n.p,{children:"This setup ensures only specified, stable plugin versions are given privileged access."}),"\n",(0,r.jsxs)(n.p,{children:["Read more about it in ",(0,r.jsx)(n.a,{href:"https://github.com/woodpecker-ci/woodpecker/pull/4213",children:"#4213"})]}),"\n",(0,r.jsx)(n.h2,{id:"200",children:"2.0.0"}),"\n",(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsxs)(n.li,{children:["Dropped deprecated ",(0,r.jsx)(n.code,{children:"CI_BUILD_*"}),", ",(0,r.jsx)(n.code,{children:"CI_PREV_BUILD_*"}),", ",(0,r.jsx)(n.code,{children:"CI_JOB_*"}),", ",(0,r.jsx)(n.code,{children:"*_LINK"}),", ",(0,r.jsx)(n.code,{children:"CI_SYSTEM_ARCH"}),", ",(0,r.jsx)(n.code,{children:"CI_REPO_REMOTE"})," built-in environment variables"]}),"\n",(0,r.jsxs)(n.li,{children:["Deprecated ",(0,r.jsx)(n.code,{children:"platform:"})," filter in favor of ",(0,r.jsx)(n.code,{children:"labels:"}),", ",(0,r.jsx)(n.a,{href:"/docs/usage/workflow-syntax#filter-by-platform",children:"read more"})]}),"\n",(0,r.jsxs)(n.li,{children:["Secrets ",(0,r.jsx)(n.code,{children:"event"})," property was renamed to ",(0,r.jsx)(n.code,{children:"events"})," and ",(0,r.jsx)(n.code,{children:"image"})," to ",(0,r.jsx)(n.code,{children:"images"})," as both are lists. The new property ",(0,r.jsx)(n.code,{children:"events"})," / ",(0,r.jsx)(n.code,{children:"images"})," has to be used in the api. The old properties ",(0,r.jsx)(n.code,{children:"event"})," and ",(0,r.jsx)(n.code,{children:"image"})," were removed."]}),"\n",(0,r.jsxs)(n.li,{children:["The secrets ",(0,r.jsx)(n.code,{children:"plugin_only"})," option was removed. Secrets with images are now always only available for plugins using listed by the ",(0,r.jsx)(n.code,{children:"images"})," property. Existing secrets with a list of ",(0,r.jsx)(n.code,{children:"images"})," will now only be available to the listed images if they are used as a plugin."]}),"\n",(0,r.jsxs)(n.li,{children:["Removed ",(0,r.jsx)(n.code,{children:"build"})," alias for ",(0,r.jsx)(n.code,{children:"pipeline"})," command in CLI"]}),"\n",(0,r.jsxs)(n.li,{children:["Removed ",(0,r.jsx)(n.code,{children:"ssh"})," backend. Use an agent directly on the SSH machine using the ",(0,r.jsx)(n.code,{children:"local"})," backend."]}),"\n",(0,r.jsxs)(n.li,{children:["Removed ",(0,r.jsx)(n.code,{children:"/hook"})," and ",(0,r.jsx)(n.code,{children:"/stream"})," API paths in favor of ",(0,r.jsx)(n.code,{children:"/api/(hook|stream)"}),'. You may need to use the "Repair repository" button in the repo settings or "Repair all" in the admin settings to recreate the forge hook.']}),"\n",(0,r.jsxs)(n.li,{children:["Removed ",(0,r.jsx)(n.code,{children:"WOODPECKER_DOCS"})," config variable"]}),"\n",(0,r.jsxs)(n.li,{children:["Renamed ",(0,r.jsx)(n.code,{children:"link"})," to ",(0,r.jsx)(n.code,{children:"url"})," (including all API fields)"]}),"\n",(0,r.jsxs)(n.li,{children:["Deprecated ",(0,r.jsx)(n.code,{children:"CI_COMMIT_URL"})," env var, use ",(0,r.jsx)(n.code,{children:"CI_PIPELINE_FORGE_URL"})]}),"\n"]}),"\n",(0,r.jsx)(n.h2,{id:"100",children:"1.0.0"}),"\n",(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsxs)(n.li,{children:["The signature used to verify extension calls (like those used for the ",(0,r.jsx)(n.a,{href:"/docs/next/usage/extensions/configuration-extension",children:"config-extension"}),") done by the Woodpecker server switched from using a shared-secret HMac to an ed25519 key-pair. Read more about it at the ",(0,r.jsx)(n.a,{href:"/docs/next/usage/extensions/configuration-extension",children:"config-extensions"})," documentation."]}),"\n",(0,r.jsxs)(n.li,{children:["Refactored support for old agent filter labels and expressions. Learn how to use the new ",(0,r.jsx)(n.a,{href:"/docs/usage/workflow-syntax#labels",children:"filter"})]}),"\n",(0,r.jsxs)(n.li,{children:["Renamed step environment variable ",(0,r.jsx)(n.code,{children:"CI_SYSTEM_ARCH"}
1)," to ",(0,r.jsx)(n.code,{children:"CI_SYSTEM_PLATFORM"}),". Same applies for the cli exec variable."]}),"\n",(0,r.jsxs)(n.li,{children:["Renamed environment variables ",(0,r.jsx)(n.code,{children:"CI_BUILD_*"})," and ",(0,r.jsx)(n.code,{children:"CI_PREV_BUILD_*"})," to ",(0,r.jsx)(n.code,{children:"CI_PIPELINE_*"})," and ",(0,r.jsx)(n.code,{children:"CI_PREV_PIPELINE_*"}),", old ones are still available but deprecated"]}),"\n",(0,r.jsxs)(n.li,{children:["Renamed environment variables ",(0,r.jsx)(n.code,{children:"CI_JOB_*"})," to ",(0,r.jsx)(n.code,{children:"CI_STEP_*"}),", old ones are still available but deprecated"]}),"\n",(0,r.jsxs)(n.li,{children:["Renamed environment variable ",(0,r.jsx)(n.code,{children:"CI_REPO_REMOTE"})," to ",(0,r.jsx)(n.code,{children:"CI_REPO_CLONE_URL"}),", old is still available but deprecated"]}),"\n",(0,r.jsxs)(n.li,{children:["Renamed environment variable ",(0,r.jsx)(n.code,{children:"*_LINK"})," to ",(0,r.jsx)(n.code,{children:"*_URL"}),", old ones are still available but deprecated"]}),"\n",(0,r.jsxs)(n.li,{children:["Renamed API endpoints for pipelines (",(0,r.jsx)(n.code,{children:"<owner>/<repo>/builds/<buildId>"})," -> ",(0,r.jsx)(n.code,{children:"<owner>/<repo>/pipelines/<pipelineId>"}),"), old ones are still available but deprecated"]}),"\n",(0,r.jsxs)(n.li,{children:["Updated Prometheus gauge ",(0,r.jsx)(n.code,{children:"build_*"})," to ",(0,r.jsx)(n.code,{children:"pipeline_*"})]}),"\n",(0,r.jsxs)(n.li,{children:["Updated Prometheus gauge ",(0,r.jsx)(n.code,{children:"*_job_*"})," to ",(0,r.jsx)(n.code,{children:"*_step_*"})]}),"\n",(0,r.jsxs)(n.li,{children:["Renamed config env ",(0,r.jsx)(n.code,{children:"WOODPECKER_MAX_PROCS"})," to ",(0,r.jsx)(n.code,{children:"WOODPECKER_MAX_WORKFLOWS"})," (still available as fallback) "]}),"\n",(0,r.jsxs)(n.li,{children:["The pipelines are now also read from ",(0,r.jsx)(n.code,{children:".yaml"})," files, the new default order is ",(0,r.jsx)(n.code,{children:".woodpecker/*.yml"})," and ",(0,r.jsx)(n.code,{children:".woodpecker/*.yaml"})," (without any prioritization) -> ",(0,r.jsx)(n.code,{children:".woodpecker.yml"})," -> ",(0,r.jsx)(n.code,{children:".woodpecker.yaml"})]}),"\n",(0,r.jsxs)(n.li,{children:["Dropped support for ",(0,r.jsx)(n.a,{href:"https://coding.net/",children:"Coding"}),", ",(0,r.jsx)(n.a,{href:"https://gogs.io",children:"Gogs"})," and Bitbucket Server (Stash)."]}),"\n",(0,r.jsxs)(n.li,{children:[(0,r.jsx)(n.code,{children:"/api/queue/resume"})," & ",(0,r.jsx)(n.code,{children:"/api/queue/pause"})," endpoint methods were changed from ",(0,r.jsx)(n.code,{children:"GET"})," to ",(0,r.jsx)(n.code,{children:"POST"})]}),"\n",(0,r.jsxs)(n.li,{children:["rename ",(0,r.jsx)(n.code,{children:"pipeline:"})," key in your workflow config to ",(0,r.jsx)(n.code,{children:"steps:"})]}),"\n",(0,r.jsxs)(n.li,{children:["If you want to migrate old logs to the new format, watch the error messages on start. If there are none we are good to go, else you have to plan a migration that can take hours. Set ",(0,r.jsx)(n.code,{children:"WOODPECKER_MIGRATIONS_ALLOW_LONG"})," to true and let it run."]}),"\n",(0,r.jsxs)(n.li,{children:["Using ",(0,r.jsx)(n.code,{children:"repo-id"})," in favor of ",(0,r.jsx)(n.code,{children:"owner/repo"})," combination\n",(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsxs)(n.li,{children:["\u26A0\uFE0F The api endpoints ",(0,r.jsx)(n.code,{children:"/api/repos/{owner}/{repo}/..."})," were replaced by new endpoints using the repos id ",(0,r.jsx)(n.code,{children:"/api/repos/{repo-id}"})]}),"\n",(0,r.jsxs)(n.li,{children:["To find the id of a repo use the ",(0,r.jsx)(n.code,{children:"/api/repos/lookup/{repo-full-name-with-slashes}"})," endpoint."]}),"\n",(0,r.jsxs)(n.li,{children:["The existing badge endpoint ",(0,r.jsx)(n.code,{children:"/api/badges/{owner}/{repo}"})," will still work, but whenever possible try to use the new endpoint using the ",(0,r.jsx)(n.code,{children:"repo-id"}),": ",(0,r.jsx)(n.code,{children:"/api/badges/{repo-id}"}),"."]}),"\n",(0,r.jsxs)(n.li,{children:["The UI urls for a repository changed from ",(0,r.jsx)(n.code,{children:"/repos/{owner}/{repo}/..."})," to ",(0,r.jsx)(n.code,{children:"/repos/{repo-id}/..."}),". You will be redirected automatically when using the old url."]}),"\n",(0,r.jsxs)(n.li,{children:["The woodpecker-go api-client is now using the ",(0,r.jsx)(n.code,{children:"repo-id"})," instead of ",(0,r.jsx)(n.code,{children:"owner/repo"})," for all functions"]}),"\n"]}),"\n"]}),"\n",(0,r.jsxs)(n.li,{children:["Using ",(0,r.jsx)(n.code,{children:"org
1-id"})," in favour of ",(0,r.jsx)(n.code,{children:"owner"})," name\n",(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsxs)(n.li,{children:["\u26A0\uFE0F The api endpoints ",(0,r.jsx)(n.code,{children:"/api/orgs/{owner}/..."})," were replaced by new endpoints using the orgs id ",(0,r.jsx)(n.code,{children:"/api/repos/{org-id}"})]}),"\n",(0,r.jsxs)(n.li,{children:["To find the id of orgs use the ",(0,r.jsx)(n.code,{children:"/api/orgs/lookup/{org_full_name}"})," endpoint."]}),"\n",(0,r.jsxs)(n.li,{children:["The UI urls for a organization changed from ",(0,r.jsx)(n.code,{children:"/org/{owner}/..."})," to ",(0,r.jsx)(n.code,{children:"/orgs/{org-id}/..."}),". You will be redirected automatically when using the old url."]}),"\n",(0,r.jsxs)(n.li,{children:["The woodpecker-go api-client is now using the ",(0,r.jsx)(n.code,{children:"org-id"})," instead of ",(0,r.jsx)(n.code,{children:"org name"})," for all functions"]}),"\n"]}),"\n"]}),"\n",(0,r.jsxs)(n.li,{children:["The ",(0,r.jsx)(n.code,{children:"command:"})," field has been removed from steps. If you were using it, please check if the entrypoint of the image you used is a shell.\n",(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsxs)(n.li,{children:["If it is a shell, simply rename ",(0,r.jsx)(n.code,{children:"command:"})," to ",(0,r.jsx)(n.code,{children:"commands:"}),"."]}),"\n",(0,r.jsxs)(n.li,{children:["If it's not, you need to prepend the entrypoint before and also rename it (e.g., ",(0,r.jsx)(n.code,{children:"commands: <entrypoint> <cmd>"}),")."]}),"\n"]}),"\n"]}),"\n"]}),"\n",(0,r.jsx)(n.h2,{id:"0150",children:"0.15.0"}),"\n",(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsxs)(n.li,{children:["\n",(0,r.jsx)(n.p,{children:"Default value for custom pipeline path is now empty / un-set which results in following resolution:"}),"\n",(0,r.jsxs)(n.p,{children:[(0,r.jsx)(n.code,{children:".woodpecker/*.yml"})," -> ",(0,r.jsx)(n.code,{children:".woodpecker.yml"})," -> ",(0,r.jsx)(n.code,{children:".drone.yml"})]}),"\n",(0,r.jsxs)(n.p,{children:["Only projects created after updating will have an empty value by default. Existing projects will stick to the current pipeline path which is ",(0,r.jsx)(n.code,{children:".drone.yml"})," in most cases."]}),"\n",(0,r.jsxs)(n.p,{children:["Read more about it at the ",(0,r.jsx)(n.a,{href:"/docs/usage/project-settings#pipeline-path",children:"Project Settings"})]}),"\n"]}),"\n",(0,r.jsxs)(n.li,{children:["\n",(0,r.jsxs)(n.p,{children:["From version ",(0,r.jsx)(n.code,{children:"0.15.0"})," ongoing there will be three types of docker images: ",(0,r.jsx)(n.code,{children:"latest"}),", ",(0,r.jsx)(n.code,{children:"next"})," and ",(0,r.jsx)(n.code,{children:"x.x.x"})," with an alpine variant for each type like ",(0,r.jsx)(n.code,{children:"latest-alpine"}),".\nIf you used ",(0,r.jsx)(n.code,{children:"latest"})," before to try pre-release features you should switch to ",(0,r.jsx)(n.code,{children:"next"})," after this release."]}),"\n"]}),"\n",(0,r.jsxs)(n.li,{children:["\n",(0,r.jsxs)(n.p,{children:["Dropped support for ",(0,r.jsx)(n.code,{children:"DRONE_*"})," environment variables. The according ",(0,r.jsx)(n.code,{children:"WOODPECKER_*"})," variables must be used instead.\nAdditionally some alternative namings have been removed to simplify maintenance:"]}),"\n",(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsxs)(n.li,{children:[(0,r.jsx)(n.code,{children:"WOODPECKER_AGENT_SECRET"})," replaces ",(0,r.jsx)(n.code,{children:"WOODPECKER_SECRET"}),", ",(0,r.jsx)(n.code,{children:"DRONE_SECRET"}),", ",(0,r.jsx)(n.code,{children:"WOODPECKER_PASSWORD"}),", ",(0,r.jsx)(n.code,{children:"DRONE_PASSWORD"})," and ",(0,r.jsx)(n.code,{children:"DRONE_AGENT_SECRET"}),"."]}),"\n",(0,r.jsxs)(n.li,{children:[(0,r.jsx)(n.code,{children:"WOODPECKER_HOST"})," replaces ",(0,r.jsx)(n.code,{children:"DRONE_HOST"})," and ",(0,r.jsx)(n.code,{children:"DRONE_SERVER_HOST"}),"."]}),"\n",(0,r.jsxs)(n.li,{children:[(0,r.jsx)(n.code,{children:"WOODPECKER_DATABASE_DRIVER"})," replaces ",(0,r.jsx)(n.code,{children:"DRONE_DATABASE_DRIVER"})," and ",(0,r.jsx)(n.code,{children:"DATABASE_DRIVER"}),"."]}),"\n",(0,r.jsxs)(n.li,{children:[(0,r.jsx)(n.code,{children:"WOODPECKER_DATABASE_DATASOURCE"})," replaces ",(0,r.jsx)(n.code,{children:"DRONE_DATABASE_DATASOURCE"})," and ",(0,r.jsx)(n.code,{children:"DATABASE_CONFIG"}),"."]}),"\n"]}),"\n"]}),"\n",(0,r.jsxs)(n.li,{children:["\n",(0,r.jsxs)(n.p,{children:["Dropped supp
1ort for ",(0,r.jsx)(n.code,{children:"DRONE_*"})," environment variables in pipeline steps. Pipeline meta-data can be accessed with ",(0,r.jsx)(n.code,{children:"CI_*"})," variables."]}),"\n",(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsxs)(n.li,{children:[(0,r.jsx)(n.code,{children:"CI_*"})," prefix replaces ",(0,r.jsx)(n.code,{children:"DRONE_*"})]}),"\n",(0,r.jsxs)(n.li,{children:[(0,r.jsx)(n.code,{children:"CI"})," value is now ",(0,r.jsx)(n.code,{children:"woodpecker"})]}),"\n",(0,r.jsxs)(n.li,{children:[(0,r.jsx)(n.code,{children:"DRONE=true"})," has been removed"]}),"\n",(0,r.jsxs)(n.li,{children:["Some variables got deprecated and will be removed in future versions. Please migrate to the new names. Same applies for ",(0,r.jsx)(n.code,{children:"DRONE_"})," of them.\n",(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsx)(n.li,{children:"CI_ARCH => use CI_SYSTEM_ARCH"}),"\n",(0,r.jsx)(n.li,{children:"CI_COMMIT => CI_COMMIT_SHA"}),"\n",(0,r.jsx)(n.li,{children:"CI_TAG => CI_COMMIT_TAG"}),"\n",(0,r.jsx)(n.li,{children:"CI_PULL_REQUEST => CI_COMMIT_PULL_REQUEST"}),"\n",(0,r.jsx)(n.li,{children:"CI_REMOTE_URL => use CI_REPO_REMOTE"}),"\n",(0,r.jsx)(n.li,{children:"CI_REPO_BRANCH => use CI_REPO_DEFAULT_BRANCH"}),"\n",(0,r.jsx)(n.li,{children:"CI_PARENT_BUILD_NUMBER => use CI_BUILD_PARENT"}),"\n",(0,r.jsx)(n.li,{children:"CI_BUILD_TARGET => use CI_BUILD_DEPLOY_TARGET"}),"\n",(0,r.jsx)(n.li,{children:"CI_DEPLOY_TO => use CI_BUILD_DEPLOY_TARGET"}),"\n",(0,r.jsx)(n.li,{children:"CI_COMMIT_AUTHOR_NAME => use CI_COMMIT_AUTHOR"}),"\n",(0,r.jsx)(n.li,{children:"CI_PREV_COMMIT_AUTHOR_NAME => use CI_PREV_COMMIT_AUTHOR"}),"\n",(0,r.jsx)(n.li,{children:"CI_SYSTEM => use CI_SYSTEM_NAME"}),"\n",(0,r.jsx)(n.li,{children:"CI_BRANCH => use CI_COMMIT_BRANCH"}),"\n",(0,r.jsx)(n.li,{children:"CI_SOURCE_BRANCH => use CI_COMMIT_SOURCE_BRANCH"}),"\n",(0,r.jsx)(n.li,{children:"CI_TARGET_BRANCH => use CI_COMMIT_TARGET_BRANCH"}),"\n"]}),"\n"]}),"\n"]}),"\n",(0,r.jsxs)(n.p,{children:["For all available variables and their descriptions have a look at ",(0,r.jsx)(n.a,{href:"/docs/usage/environment#built-in-environment-variables",children:"built-in-environment-variables"}),"."]}),"\n"]}),"\n",(0,r.jsxs)(n.li,{children:["\n",(0,r.jsxs)(n.p,{children:["Prometheus metrics have been changed from ",(0,r.jsx)(n.code,{children:"drone_*"})," to ",(0,r.jsx)(n.code,{children:"woodpecker_*"})]}),"\n"]}),"\n",(0,r.jsxs)(n.li,{children:["\n",(0,r.jsxs)(n.p,{children:["Base path has moved from ",(0,r.jsx)(n.code,{children:"/var/lib/drone"})," to ",(0,r.jsx)(n.code,{children:"/var/lib/woodpecker"})]}),"\n"]}),"\n",(0,r.jsxs)(n.li,{children:["\n",(0,r.jsxs)(n.p,{children:["Default workspace base path has moved from ",(0,r.jsx)(n.code,{children:"/drone"})," to ",(0,r.jsx)(n.code,{children:"/woodpecker"})]}),"\n"]}),"\n",(0,r.jsxs)(n.li,{children:["\n",(0,r.jsx)(n.p,{children:"Default SQLite database location has changed:"}),"\n",(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsxs)(n.li,{children:[(0,r.jsx)(n.code,{children:"/var/lib/drone/drone.sqlite"})," -> ",(0,r.jsx)(n.code,{children:"/var/lib/woodpecker/woodpecker.sqlite"})]}),"\n",(0,r.jsxs)(n.li,{children:[(0,r.jsx)(n.code,{children:"drone.sqlite"})," -> ",(0,r.jsx)(n.code,{children:"woodpecker.sqlite"})]}),"\n"]}),"\n"]}),"\n",(0,r.jsxs)(n.li,{children:["\n",(0,r.jsxs)(n.p,{children:["Plugin Settings moved into ",(0,r.jsx)(n.code,{children:"settings"})," section:"]}),"\n",(0,r.jsx)(n.pre,{children:(0,r.jsx)(n.code,{className:"language-diff",children:" steps:\n something:\n image: my/plugin\n- setting1: foo\n- setting2: bar\n+ settings:\n+ setting1: foo\n+ setting2: bar\n"})}),"\n"]}),"\n",(0,r.jsxs)(n.li,{children:["\n",(0,r.jsxs)(n.p,{children:[(0,r.jsx)(n.code,{children:"WOODPECKER_DEBUG"})," option for server and agent got removed in favor of ",(0,r.jsx)(n.code,{children:"WOODPECKER_LOG_LEVEL=debug"})]}),"\n"]}),"\n",(0,r.jsxs)(n.li,{children:["\n",(0,r.jsxs)(n.p,{children:["Remove unused server flags which can safely be removed from your server config: ",(0,r.jsx)(n.code,{children:"WOODPECKER_QUIC"}),", ",(0,r.jsx)(n.code,{children:"WOODPECKER_GITHUB_SCOPE"}),", ",(0,r.jsx)(n.code,{children:"WOODPECKER_GITHUB_GIT_USERNAME"}),", ",(0,r.jsx)(n.code,{children:"WOODPECKER_GITHUB_GIT_PASSWORD"}),", ",(0,r.jsx)(n.code,{children:"WOODPECKER_GITHUB_PRIVATE_MODE"}),", ",(0,r.jsx)(n.code,{children:"WOODPECKER_GITEA_GIT_USERNAME"}),", ",(0,r.jsx)(n.code,{children:"WOODPECKER_GITEA_GIT_PASSWORD"}),", ",(0,r.jsx)(n.code,{children:"WOODPECKER_GITEA_PRIVATE_MODE"}),", ",(0,r.jsx)(n.code,{children:"WOODPECKER_GITLAB_GIT_USERNAME"}),", ",(0,r.jsx)(n.code,{children:"WOODPECKER_GITLAB_GIT_PASSWORD"}),", ",(0,r.jsx)(n.code,{children:"WOODPECKER_GITLAB_PRIVATE_MODE"})]}),"\n"]}),"\n",(0,r.jsxs)(n.li,{children:["\n",(0,r.jsxs)(n.p,{children:["Dropped supp
1ort for manually setting the agents platform with ",(0,r.jsx)(n.code,{children:"WOODPECKER_PLATFORM"}),". The platform is now automatically detected."]}),"\n"]}),"\n",(0,r.jsxs)(n.li,{children:["\n",(0,r.jsxs)(n.p,{children:["Use ",(0,r.jsx)(n.code,{children:"WOODPECKER_STATUS_CONTEXT"})," instead of the deprecated options ",(0,r.jsx)(n.code,{children:"WOODPECKER_GITHUB_CONTEXT"})," and ",(0,r.jsx)(n.code,{children:"WOODPECKER_GITEA_CONTEXT"}),"."]}),"\n"]}),"\n"]}),"\n",(0,r.jsx)(n.h2,{id:"0140",children:"0.14.0"}),"\n",(0,r.jsx)(n.p,{children:"No breaking changes"}),"\n",(0,r.jsx)(n.h2,{id:"from-drone",children:"From Drone"}),"\n",(0,r.jsx)(n.admonition,{type:"warning",children:(0,r.jsx)(n.p,{children:"Migration from Drone is only possible if you were running Drone <= v0.8."})}),"\n",(0,r.jsxs)(n.ol,{children:["\n",(0,r.jsx)(n.li,{children:"Make sure you are already running Drone v0.8"}),"\n",(0,r.jsx)(n.li,{children:"Upgrade to Woodpecker v0.14.4, migration will be done during startup"}),"\n",(0,r.jsx)(n.li,{children:"Upgrade to the latest Woodpecker version. Pay attention to the breaking changes listed above."}),"\n"]})]})}function a(e={}){let{wrapper:n}={...(0,d.R)(),...e.components};return n?(0,r.jsx)(n,{...e,children:(0,r.jsx)(h,{...e})}):h(e)}},23191(e,n,i){i.d(n,{R:()=>l,x:()=>c});var s=i(92990);let r={},d=s.createContext(r);function l(e){let n=s.useContext(d);return s.useMemo(function(){return"function"==typeof e?e(n):{...n,...e}},[n,e])}function c(e){let n;return n=e.disableParentContext?"function"==typeof e.components?e.components(r):e.components||r:l(e.components),s.createElement(d.Provider,{value:n},e.children)}}}]);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.