Skip to content

[Ruby on Rails] Bump Docker from 29.7.2 to 29.8.0 - #281

Merged
hayat01sh1da merged 1 commit into
masterfrom
hayat01sh1da/no-issue-number/ruby-on-rails/bump-docker-from-29.7.2-to-29.8.0
Sep 15, 2026
Merged

hayat01sh1da merged 1 commit into
masterfrom
hayat01sh1da/no-issue-number/ruby-on-rails/bump-docker-from-29.7.2-to-29.8.0

Conversation

@hayat01sh1da

Copy link
Copy Markdown
Owner

1. Overview

This Pull Request bumps the documented Docker Engine version for the Ruby on Rails track from 29.7.2 to 29.8.0.

Unlike the previous bump, this is a single upstream release: 29.8.0 (2026-09-03) follows 29.7.2 (2026-08-05) with no patch releases in between, so the whole delta is one minor release.
Where 29.7.x was dominated by repairing image-pull regressions, 29.8.0 is a genuine feature release — it adds --umask for containers, two hardening measures (a configurable default AppArmor profile template and an AF_VSOCK escape via 32-bit socketcall(2) closed off), a large batch of Swarm service-discovery and gossip fixes, and it moves every bundled component forward, including a runc minor bump from v1.4.3 to v1.5.1.
No CVE is fixed by this release; the security entries are hardening rather than advisories.

Docker Engine is a host-side tool here, used through docker-compose build / docker-compose up; the change is confined to the environment documentation and nothing in the image definitions or the application moves.

2. Key Changes & Differences

2-1. Docker Engine — 29.7.2 → 29.8.0

Component Before (29.7.2, 2026-08-05) After (29.8.0, 2026-09-03) Changes & Differences
Docker Engine 29.7.2 29.8.0 A single upstream minor release — no 29.7.3+ exists, so the whole delta is 29.8.0 rather than a fold of several patches.
New features — 2 additions HostConfig.Umask with a --umask <octal> flag on docker create / docker run, applied to the container process, execs and healthchecks (moby/moby#53463, docker/cli#7108); the awslogs driver can now attach service names, environments and custom CloudWatch entity attributes to log entries (moby/moby#52632).
Security (hardening, no CVE) — 2 hardening changes The daemon can now be configured with a default container AppArmor profile template instead of the built-in one (moby/moby#52771); containers are blocked from reaching host VMs by creating AF_VSOCK sockets through the 32-bit socketcall(2) multiplexer, via new AppArmor and SELinux policy rules (moby/moby#53551). Also: checkpoint IDs containing path separators are now rejected, so a checkpoint can no longer address a path outside the container checkpoint directory (moby/moby#53377).
Networking — Swarm service discovery 4 latent resolution bugs Fixed A node gossiping a superseded value for a service-discovery entry after concurrent updates to the same key (moby/moby#53479); service names failing to resolve indefinitely on a node that missed a network membership announcement (moby/moby#53437); service names failing to resolve on healthy nodes after a transient node failure (moby/moby#53142); docker network inspect failing to find a healthy Swarm network when a different Swarm network could not be allocated (moby/moby#53325).
Networking — resource usage Recurring bursts; possible hang Smoothed out Periodic Swarm overlay gossip and synchronisation is now spread over time instead of firing in recurring CPU/network bursts (moby/moby#53475); gossip traffic from a node that repeatedly disconnects and rejoins is reduced (moby/moby#53479); dockerd no longer hangs when the nft command emits enough stderr to fill its pipe (moby/moby#53517).
Networking — other — 3 changes Swarm service-mesh published ports now use the same infrastructure as published ports for local containers (moby/moby#53118); remote network-driver plugins can set the container-side interface name via DstName in their Join response (moby/moby#52866); the names container and container: are now reserved, so they can no longer be used to create unusable networks (moby/moby#51973).
containerd image store 4 defects Fixed docker image inspect reported a smaller size than docker image ls, because GET /images/{name}/json omitted unpacked snapshot usage from Size (moby/moby#53426); pulls were slowed by repeated registry authentication within a single pull (moby/moby#53497); expected image-signature identity misses were logged as errors (moby/moby#53495).
Embedded containerd Experimental, opt-in only Used as a fallback dockerd now falls back to the embedded containerd when no system containerd service is configured and containerd is not installed (moby/moby#53388) — the feature introduced experimentally in 29.7.0 now has an automatic path. containerd's v2 CRI plugins are also prevented from loading when CRI is disabled (moby/moby#53564).
Build / runtime fixes — 5 fixes Classic-builder cache repaired for Dockerfile stages selecting a non-host platform with FROM --platform (moby/moby#53503); health checks no longer delayed excessively when the start interval is longer than the start period (moby/moby#52317); the container root directory / is no longer world-writable under the btrfs storage driver (moby/moby#53500); mount ordering in docker inspect and container listings is now consistent (moby/moby#53534); NRI container metadata now includes the resolved executable as argv[0] in Container.Args (moby/moby#53423).
CLI fixes — 4 fixes No more panic when DOCKER_HOST or -H names an invalid host (docker/cli#7280); docker ps sorts published ports numerically instead of lexicographically (docker/cli#7144); service mount order is preserved during forced updates, avoiding a spurious rollout on the next stack deploy (docker/cli#7227); plugin hook output such as the "What's next:" hint now prints after the command's error message rather than before it (docker/cli#6976).
API — container listing No annotation filter annotation filter added docker ps / GET /containers/json accept an annotation filter to select containers by their annotations (moby/moby#53538).
Rootless RootlessKit v3.0.x RootlessKit v3.1.0 Adds the pesto port driver (DOCKERD_ROOTLESS_ROOTLESSKIT_PORT_DRIVER=pesto; requires the pasta network driver, IPv4 only), and fixes --disable-host-loopback not being enforced for the pasta driver in rootless mode (moby/moby#53358).
BuildKit v0.32.2 v0.33.0 Minor bump (moby/moby#53554); this is what backs docker-compose build.
containerd (static binaries) v2.3.3 v2.3.4 Patch bump (moby/moby#53409).
runc (static binaries) v1.4.3 v1.5.1 Minor bump (moby/moby#52306) — the largest component move in this release; runc is the OCI runtime that actually starts every container.
Go runtime 1.26.5 1.26.8 Three patch releases of the Go toolchain for both daemon and CLI (moby/moby#53550, docker/cli#7274).
Go SDK Go >= 1.25 Go >= 1.26 Minimum supported Go version for consumers of the Docker Go SDK raised to 1.26 (docker/cli#7258) — affects code importing docker/cli, not this repository.

2-2. Files Updated in This Repository

Files Before After Changes & Differences
ruby-on-rails/README.md Docker 29.7.2 Docker 29.8.0 Updated the documented Docker Engine version in the environment section — the only file changed on this branch; Rails 8.1.3.1 / Ruby 4.0.6 / Gemfile 4.1.0.beta1 / Bundler 4.1.0.beta1 unchanged.

3. Summary

  • Bumped the documented Docker Engine version from 29.7.2 to 29.8.0 in ruby-on-rails/README.md (1 file changed, +1 / -1).
  • One upstream release, not a fold: 29.8.0 (2026-09-03) directly succeeds 29.7.2 (2026-08-05), and it is a feature release rather than a regression-repair release like 29.7.1 / 29.7.2 were.
  • Headline additions are --umask / HostConfig.Umask for containers, an annotation filter on container listings, and CloudWatch entity attributes for the awslogs driver; the security entries are hardening (configurable default AppArmor profile template, AF_VSOCK-via-32-bit-socketcall(2) blocked, checkpoint IDs with path separators rejected) with no CVE attached.
  • The bulk of the fixes are Swarm/overlay networking — four separate service-name resolution failures, smoothed-out gossip and synchronisation, and a dockerd hang when nft fills its stderr pipe — none of which this single-host application exercises, alongside containerd-image-store fixes that do affect everyday pulls and docker image inspect sizes.
  • Bundled components all move: BuildKit v0.32.2 → v0.33.0, containerd v2.3.3 → v2.3.4, runc v1.4.3 → v1.5.1 (a minor bump of the OCI runtime — the item most worth smoke-testing locally), Go 1.26.5 → 1.26.8, RootlessKit → v3.1.0.
  • Documentation-only change: no Dockerfile, Dockerfile.production, docker-compose.yml or application code is touched.

4. References

🤖 Generated with Claude Code

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@hayat01sh1da hayat01sh1da self-assigned this Sep 14, 2026

@hayat01sh1da hayat01sh1da left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@hayat01sh1da
hayat01sh1da merged commit 096ed0a into master Sep 15, 2026
5 checks passed
@hayat01sh1da
hayat01sh1da deleted the hayat01sh1da/no-issue-number/ruby-on-rails/bump-docker-from-29.7.2-to-29.8.0 branch September 15, 2026 00:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant