Skip to content

feat: upgrade Hub and Lab to JupyterHub 6.0.1 - #35

Draft
Delemangi wants to merge 3 commits into
mainfrom
jupyterhub-6-lean
Draft

Delemangi wants to merge 3 commits into
mainfrom
jupyterhub-6-lean

Conversation

@Delemangi

@Delemangi Delemangi commented Oct 6, 2026 •

Copy link
Copy Markdown
Member

Scope

Coordinated Hub/Lab JupyterHub 6.0.1 upgrade, matching package/version labels, immutable-image/startup safeguards, migration-disabled defaults, conservative updater, and focused regressions.

18 files, +1875/-82 against synchronized main 16eb336. Most added lines are dependency locks, focused tests and the manual runbook. Maintenance controller and large integration infrastructure remain outside this PR. PR #17 is preserved as the original tested reference.

Current lean head: 4f0dc370e3b2fb06b371b0387a7c1470f9b1c507.

Validation

  • All 25 completed PR checks passed; two optional checks skipped. Includes Hub/Lab/Web tests, lint/typechecks, configured image builds, Linux updater contracts and CodeQL.
  • The updater review fix checks container-inspection status before parsing JSON. Linux contracts cover failed inspection with empty/partial JSON refusing activation, complete matching inventory permitting activation, and existing version/ownership/interlock refusals.
  • Fresh disposable validation run 37687597130 passed at validation head c8bd63a8204bb84f6323b5e9354ac0d5343face4.
  • Exact Git-object binding passed in all three jobs against the current lean head and immutable 5.5.1 baseline 6f682ee17c8affa988deffa44c56f2e39e28e462.
  • 215 native checks passed, including Linux process-group cancellation, inherited-pipe and private-log permissions contracts; Ruff and five-file mypy passed.
  • XFS preflight and cleanup gates passed. Full integration passed 19 reported cases across 27 stages and both migration cycles: upgrade/cold restore/old acceptance, followed by upgrade/candidate acceptance.
  • Runtime coverage includes upstream ORM migration, explicit upgrade-db followed by migration-disabled Hub6 restarts, API/OAuth/cookies/scoped tokens, isolation, files, terminal/WebSocket backend, XFS quotas, matched old-pair restore, updater refusal and web loopback acceptance.
  • Owned cleanup verified: 45/45 recorded containers and 23/23 recorded images removed. One network recorded; no separate removed-network count was emitted. No unresolved build intents or retained private directory. No daemon-wide emptiness claim.

Earlier attempt and evidence limits

An earlier run timed out during baseline Lab image building before any migration cases. Test-only bounded private build diagnostics were added without changing application inputs, frozen baseline Dockerfiles or the 1,200-second build deadline. The new run passed; it does not establish the cause of the earlier stall. Raw build logs were not exposed or uploaded.

Runtime uses preserved external test-only controller orchestration and disclosed Hub ownership wrappers. Raw image package/label checks are not unwrapped shipping-Hub startup evidence. Image-only Lab fixture networking supports the controller and is not a shipping Compose change. Terminal/WebSocket backend checks are not visual xterm GUI testing.

The manual README procedure was not rehearsed. Production ingress/external-provider routing, installed updater/timer reconciliation, durable activation and manual operator rehearsal remain separate gates.

Keep draft/unmerged pending final review and production gates. No merge or production rollout is authorized. Do not publish default-branch latest before installed-updater and maintenance gates are resolved. Nothing has been merged or deployed.

@Delemangi Delemangi self-assigned this Oct 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant