Skip to content

charts/authentik: move bundled PostgreSQL to the Debian 13 base - #523

Merged
BeryJu merged 1 commit into
goauthentik:mainfrom
JanWelker:postgres-trixie
Sep 18, 2026
Merged

BeryJu merged 1 commit into
goauthentik:mainfrom
JanWelker:postgres-trixie

Conversation

@JanWelker

Copy link
Copy Markdown
Contributor

What

Changes the bundled PostgreSQL image default from 17.11-bookworm (Debian 12) to 17.11-trixie (Debian 13). Same PostgreSQL version, same Docker Official image — only the base changes.

Why

postgres:17.11-bookworm currently scans with 30 critical CVEs, and 28 of them are Debian 12 OS packages that Debian has marked wont-fix or not-fixed — they will not be patched in bookworm:

Package Version in bookworm CVEs
perl, perl-base, perl-modules-5.36 5.36.0-7+deb12u3 CVE-2026-8376, CVE-2026-42496 (wont-fix); CVE-2026-57433, CVE-2026-13221, CVE-2026-12087 (not-fixed)
libc6, locales 2.36-9+deb12u14 CVE-2026-5450 (wont-fix)
openssl, libssl3 3.0.20-1~deb12u2 CVE-2026-75803 (not-fixed)
libsqlite3-0 3.40.1-2+deb12u2 CVE-2025-7458 (wont-fix)

Trixie ships substantially newer versions of each: perl 5.40.1, glibc 2.41, openssl 3.5.7, sqlite3 3.46.1.

One caveat in the interest of accuracy: libxml2 in trixie is 2.12.7+dfsg+really2.9.14, i.e. the same 2.9.14 upstream content, so CVE-2026-6653 is not addressed by this change.

Consistency: this chart already ships Debian 13 in the same values.yaml — volumePermissions.image is debian:13-slim since #434. The database container is the last Debian 12 image in the chart.

Renovate cannot propose this. docker versioning treats -bookworm as a compatibility suffix and only offers versions carrying the same suffix — the dependency dashboard (#357) lists the only available update for 17.11-bookworm as 18.6-bookworm. The base will stay on Debian 12 indefinitely unless changed by hand.

Upgrade note — worth weighing

Moving bookworm to trixie changes glibc 2.36 to 2.41. PostgreSQL records the collation version of the libc it was initialised against, so existing clusters may log a collation version mismatch warning, and indexes on text columns should be REINDEXed to be strictly correct.

That makes this more than a cosmetic swap for existing deployments, and you may prefer to do it at a major-version boundary instead. Happy to redo this as 18.x-trixie alongside #402, or to add an upgrade note to the README — your call.

I considered 17.11-alpine, which has a much smaller CVE surface, but rejected it: musl changes collation behaviour more than a glibc version bump does, which is a bigger ask of existing users.

Testing

Only the default value changes; ct install exercises a fresh install on the new base.


Disclosure: this change was prepared with the help of an LLM (Claude Code). The CVE data comes from a Kubescape scan of a running cluster; the Debian package versions were verified against sources.debian.org. I reviewed and vetted the change before raising it.

@JanWelker
JanWelker requested a review from a team as a code owner September 18, 2026 11:28
@BeryJu
BeryJu merged commit ac385a0 into goauthentik:main Sep 18, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants