Skip to content

docs: stop advertising the read-only image variants - #468

Merged
fzipi merged 5 commits into
mainfrom
docs/read-only-variants-unavailable
Sep 24, 2026
Merged

fzipi merged 5 commits into
mainfrom
docs/read-only-variants-unavailable

Conversation

@fzipi

@fzipi fzipi commented Aug 18, 2026 •

Copy link
Copy Markdown
Member

Refs #172.

The README promises images that are not published. docker-bake.hcl has the read-only matrix entry commented out:

    read-only-fs = [
        {
            name = "writable"
            read-only = "false"
        },
        # {
        #     name = "read-only"
        #     read-only = "true"
        # }
    ]

so no read-only target is ever built or pushed. Confirmed against both registries:

ghcr:nginx-read-only          not found
hub:nginx-read-only           not found
ghcr:nginx-alpine-read-only   not found
hub:nginx-alpine-read-only    not found

The section now says so and points at #172, while noting that the machinery is still in the tree — the READ_ONLY_FS build argument in nginx/Dockerfile and nginx/docker-entrypoint.d/0-move-writables.sh — so re-enabling it later is a bake change rather than a rewrite.

The tag format sections had the same problem from the other direction: they document a [-<writable>] component, but the writable variant adds no suffix and the read-only one is not built, so no published tag has ever carried it. owasp/modsecurity-crs:nginx-writable does not resolve either. Removed from both the stable and rolling tag descriptions.

This documents the current state; whether the variants come back is the decision still open in #172.

Summary by CodeRabbit

  • Documentation
    • Updated stable and rolling tag documentation to remove the optional writable suffix.
    • Clarified that read-only filesystem variants are unpublished, while nginx support remains available but its build targets are disabled and no tags are pushed.
    • Updated the documented nginx base-image version to 1.30.5.
    • Added documentation for HSTS_MAX_AGE, X_FRAME_OPTIONS, and SKIP_RESPONSE_ANALYSIS.
    • Updated documented defaults and descriptions for SERVER_TOKENS and SSL_HONOR_CIPHER_ORDER.

The read-only build targets are commented out in docker-bake.hcl, so
nginx-read-only and nginx-alpine-read-only have never been pushed, and neither
registry serves them. The tag format sections had the same problem: no
published tag carries a writable or read-only marker, because the writable
variant adds no suffix.

Refs #172
@coderabbitai

coderabbitai Bot commented Aug 18, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Central YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Advanced

Run ID: 4c628cf6-9d40-4d93-9eb8-975e3e8220bf

📥 Commits

Reviewing files that changed from the base of the PR and between a2d51ca and af6faf1.

📒 Files selected for processing (1)
  • README.md
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

  • coreruleset/coreruleset (manual)
  • coreruleset/go-ftw (manual)
  • coreruleset/crs-toolchain (manual)
  • coreruleset/crs-linter (manual)
  • coreruleset/documentation (manual)

Included review availability: Your plan provides up to 2 included reviews per hour; 1 remains after this review.


📝 Walkthrough

Walkthrough

README.md updates image tag and nginx base-image documentation. It also adds or revises Apache and CRS environment-variable details.

Changes

README documentation

Layer / File(s) Summary
Stable and rolling tag formats
README.md
Stable and rolling tag compositions no longer include the optional writable component.
Read-only tag publication status
README.md
The documentation states that read-only tags are not published, read-only support remains in nginx builds, and read-only build targets are disabled. It updates the documented nginx base-image version from 1.30.4 to 1.30.5.
Apache environment-variable documentation
README.md
The documentation adds HSTS_MAX_AGE and X_FRAME_OPTIONS and updates the documented defaults or description for SERVER_TOKENS and SSL_HONOR_CIPHER_ORDER.
CRS environment-variable documentation
README.md
The documentation adds SKIP_RESPONSE_ANALYSIS, its default of 0, and the documented effect of setting it to 1.

Priority: ⚪ Not assessed

Estimated code review effort: 1 (Trivial) | ~5 minutes

Change: Other

Suggested labels: release:ignore, :book: documentation

Merge Risk: ⚪ Minimal · up to af6fa

The README’s image and environment-variable details match the repository configuration; no actionable merge-blocking issue remains.

🚥 Pre-merge checks | ✅ 17 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Ai Contribution Disclosure ⚠️ Warning The PR body has no ## ai disclosure section and omits the required lowercase ## what, ## why, and ## refs sections. Commit 997aa016854b62ba810126ae8b7d471db9c18763 contains `Co-Authored-By: … Add the required lowercase ## what, ## why, and ## refs sections. Add ## ai disclosure with concrete **tools used** (model and version), **assisted with** (the actual generated work), and **review performed** (specific verific…
✅ Passed checks (17 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: the README no longer advertises read-only image variants.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Regex Assembly Is The Source Of Truth ✅ Passed Passed — not applicable. The pull request changes only README.md. It does not modify an @rx pattern in rules/*.conf and does not add or modify regex-assembly/.
Rule Change Requires Go-Ftw Test Coverage ✅ Passed Not applicable. The reviewed diff changes only README.md; it does not add or modify SecRule directives in rules/*.conf or plugins/*.conf, and it does not change regex-assembly/ patterns.
Redos Risk & Re2 Compatibility ✅ Passed Not applicable. The authoritative pull-request diff changes only README.md. It does not add or modify rules/.conf, regex-assembly/.ra, or tooling code containing regexp.MustCompile or re.compile, so…
False Positive Risk & Existing Coverage ✅ Passed Not applicable. The pull request changes only README.md. It adds no detection pattern, widens no pattern, and adds no rule under rules/.conf, plugins/.conf, or regex-assembly/.
Crs Rule Metadata & Id Conventions ✅ Passed Passed — not applicable. The pull request changes only README.md. It adds or modifies no SecRule in rules/.conf, plugins/.conf, or crs-setup.conf.example.
Rule & Config Breaking Changes ✅ Passed PASS — the authoritative PR diff changes only README.md. It removes documentation for unpublished Docker image variants and corrects tag-format documentation; it does not remove or renumber CRS rules,…
Owasp Security (Web, Api & Llm) ✅ Passed No OWASP security defect is introduced. The authoritative PR diff changes only README.md: it removes unpublished read-only tag examples and suffix notation, and documents that the read-only bake matri…
Unpinned Dependencies & Actions ✅ Passed Passed: not applicable. The pull request changes only README.md. It does not change a manifest, lockfile, Dockerfile, workflow, or pipeline file covered by this check.
Secrets, Payloads & Pii In Logs ✅ Passed PASS — The pull request changes only README.md (8 additions, 10 deletions). The changed lines document image tags and build support; they add no logging, telemetry, stack trace, fixture, request, resp…
New Dependency Scrutiny ✅ Passed PASS — the authoritative PR diff changes only README.md. It adds no package, module, plugin, GitHub Action uses: step, or other dependency entry covered by New Dependency Scrutiny. The dependency ch…
Install & Build-Time Code Execution ✅ Passed No install or build-time execution risk was introduced. The authoritative diff changes only README.md (8 additions, 10 deletions). Added lines contain tag and read-only documentation only; they add no…
Renovate: Config Present And Valid ✅ Passed PASS: The PR changes only README.md. It does not touch any Renovate config path. The repository contains renovate.json at the root in both the base and head revisions, so the no-config trigger doe…
Full details: Ai Contribution Disclosure

Explanation

The PR body has no ## ai disclosure section and omits the required lowercase ## what, ## why, and ## refs sections. Commit 997aa016854b62ba810126ae8b7d471db9c18763 contains Co-Authored-By: Claude Opus 5 (1M context) &lt;noreply@anthropic.com&gt;, which the check explicitly forbids. The change is an 8-line documentation correction, not an exempt typo, version bump, or automated update.

Resolution

Add the required lowercase ## what, ## why, and ## refs sections. Add ## ai disclosure with concrete **tools used** (model and version), **assisted with** (the actual generated work), and **review performed** (specific verification). Rewrite or squash the commit history to remove the Co-Authored-By trailer and any other AI-tool signature line.

  • Fix all pre-merge checks with AI

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@fzipi
fzipi requested a review from theseion August 18, 2026 15:31
@fzipi
fzipi enabled auto-merge (squash) August 18, 2026 15:31
Comment thread README.md Outdated
fzipi and others added 2 commits August 23, 2026 09:51
@fzipi
fzipi merged commit b09f6e6 into main Sep 24, 2026
38 checks passed
@fzipi
fzipi deleted the docs/read-only-variants-unavailable branch September 24, 2026 05:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants