Skip to content

[OPTMZT-89]: Update image policies for 2025 #9433

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Draft
wants to merge 1 commit into
base: old-site
Choose a base branch
from
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
27 changes: 5 additions & 22 deletions jekyll/_cci2/android-images-support-policy.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -18,11 +18,11 @@ This document outlines the CircleCI Android image release, update, and deprecati
[#release-policy]
== Release policy

Android images are released once a quarter, with patch releases potentially being made for security issues. These images are generally built on top of the latest version of our most recent stable base Ubuntu image with added packages for Android.
Android images are released once a quarter, with patch releases potentially made for security issues. These images are generally built on top of the latest version of our most recent stable base Ubuntu image with added packages for Android.

- We install the most up-to-date versions of each tool/package in newly built images.
- We aim to package 6 levels of the Android API within each image release.
- As this image is not specifically designed for the Android Gradle Plugin (AGP), some updates may come later than desired. However, we aim to follow compatibility matrices for link:https://docs.gradle.org/current/userguide/compatibility.html[AGP] and link:https://developer.android.com/build/releases/gradle-plugin#updating-gradle[Gradle].
- As this image is not specifically designed for the Android Gradle Plugin (AGP), some updates may come later than desired. We aim to follow compatibility matrices for link:https://docs.gradle.org/current/userguide/compatibility.html[AGP] and link:https://developer.android.com/build/releases/gradle-plugin#updating-gradle[Gradle].

Releases may be skipped if there are no material updates to core Android functionality, such as `sdkmanager`, `ndk` or platform versions.

Expand All @@ -37,12 +37,10 @@ For the latest major version of Docker:

- `edge`: These tags are reserved for previews of new releases, which will initially point to this tag. The `edge` tags may include incremental updates to the `current` image release, which may change without notice, and is not recommended to be used for production CI workloads. `current` will be updated with these changes after a period of stability (generally an average of a week).

- Date based tagging: Android images are generally released once every 3 months. The date-based tagging conventions take the format of `<year>.<month>.<patch>`, such as `2023.10.1`. We recommend using the `default` version and not pinning to a date version.

[#critical-cve-patches]
== Critical CVE patches

When critical CVEs are disclosed that affect the versions of the operating system or software stack in our Docker convenience images, we will investigate the impact that this has on our images being used within the CircleCI execution environment. If customers are impacted by these CVEs we will push a patch fix to the released image(s), and this image will supersede the original image.
When critical CVEs are disclosed around the operating system or software stack of this image, we will investigate the impact this has on the image within the CircleCI execution environment. If customers are impacted by these CVEs we will push a patch fix to the released image(s), and this image will supersede the original image.

[#bug-reports-issues-and-prs]
== Bug reports, issues, and PRs
Expand All @@ -52,24 +50,9 @@ File a link:https://support.circleci.com/hc/en-us/requests/new[Support Ticket wi
[#image-lifespan-eol]
== Image lifespan / EOL

We will keep a total of seven images at maximum, with a deprecation cycle happening once per year. The table below shows which images will be kept in each cycle. Generally we will aim to start EOL process within 3 months of a new version release.

Current Deprecation (Jan 2024):

[.table.table-striped]
[cols=2*, options="header", stripes=even]
|===
| Release cycle
| Image status

| Current year
| Keep all quarterly images of this year. Keep Q4 (October) image release of the last 2 years

|===

When an image is selected for deprecation and removal, we will create an announcement on our Discuss forum, along with reaching out via email to developers who have requested one of the deprecated images in their recent jobs.
When a new API Level for Android is released we will release it to edge. We will give a 3 month warning before the default image will have oldest version no longer supported. We will create an announcement on our Discuss forum and along with additional outreach where possible.

We will also plan brownouts to ensure users are aware of the approaching removal of deprecated images. Generally, we will aim to start an EOL process within 3 months of a new version release.
Generally we will aim to start EOL process within 3 months of a new version release.

[#exceptions]
== Exceptions
Expand Down
4 changes: 2 additions & 2 deletions jekyll/_cci2/android-machine-image.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -54,7 +54,7 @@ workflows:
executor:
name: android/android-machine
resource-class: large
tag: 2021.10.1
tag: default
```

[#more-complex-orb-usage]
Expand All @@ -75,7 +75,7 @@ jobs:
executor:
name: android/android-machine
resource-class: large
tag: 2021.10.1
tag: default
steps:
- checkout
# Create an AVD named "myavd"
Expand Down
8 changes: 4 additions & 4 deletions jekyll/_cci2/linux-cuda-images-support-policy.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -20,9 +20,9 @@ This document outlines the xref:using-gpu#linux-gpu[CircleCI Linux CUDA image] r
[#release-policy]
== Release policy

The CircleCI CUDA images are based on our Linux VM machine images for the purpose of providing an image that can leverage the additional processing capabilities of CircleCI’s GPU executor.
The CircleCI CUDA images are based on our Linux VM machine images. This provides an image that can leverage the additional processing capabilities of CircleCI’s GPU executor.

We aim to support the three most recent minor versions (or three most recent even numbered minor versions, if minor version >= `6`) of the two most recent and supported major CUDA releases. We closely track Nvidia’s own release cycle and aim to release our images within a week of the CUDA release.
We aim to support the two most recent and supported major CUDA releases. We closely track Nvidia’s own release cycle and aim to release our images within a week of the CUDA release.

The release policy is not an SLA (service level agreement). We can not, and do not, provide an official SLA turnaround time for new CUDA images.

Expand All @@ -42,7 +42,7 @@ The following tags are available for the CircleCI Linux CUDA images:
[#critical-cve-patches]
== Critical CVE patches

When critical CVEs are disclosed that affect the versions of the operating system or software stack in either Linux or Windows images, we will investigate the impact that this has on our images being used across CircleCI execution environments.
When critical CVEs are disclosed around the operating system or software stack of this image, we will investigate the impact this has on the image within the CircleCI execution environment.

In most cases, due to the ephemeral and isolated nature of the environment, it is not necessary to patch these images. We will always communicate our stance on these disclosures via our link:https://discuss.circleci.com/[Discuss Forum].

Expand Down Expand Up @@ -101,7 +101,7 @@ A minor version release -- CUDA 11.8:

Once a new even numbered minor version is released, that version will be added and the oldest existing version will be removed, provided that more than 3 minor versions exist.

When an image is selected for deprecation and removal, we will create an announcement on our Discuss forum, along with reaching out via email to developers who have requested one of the deprecated images in their recent jobs. We will also plan brownouts to help ensure you are aware of the approaching removal of deprecated images.
When an image is selected for deprecation and removal, we will create an announcement on our Discuss forum and along with additional outreach where possible.

[#exceptions]
== Exceptions
Expand Down
16 changes: 5 additions & 11 deletions jekyll/_cci2/linux-vm-support-policy.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -31,18 +31,14 @@ Tags we support for this image (tag is what is specified in `.circleci/config.ym

- `current` version of the image will receive updates approximately every three months.

- `previous` version of the image will receive the previous version of `current`.

- `edge` tags are reserved for previews of new releases, which will initially point to this tag. The edge tags may include incremental updates to the current quarterly (every 3 months) image release, which may change without notice, and is not recommended to be used for production CI workloads. `current` will be updated with these changes after a period of stability.

- Date based tagging: The Ubuntu LTS based images have the image slug format of: `ubuntu-<LTS version>:<year>.<month>.<patch>`, such as `ubuntu-2204:2023.10.1`. We recommend using the `default` version and not pinning to a date version.

We always aim to release a version of this image every three months.
We always aim to release a version of this image every three months. Tags will be supported on all versions we support.

[#critical-cve-patches]
== Critical CVE patches

When critical CVEs are disclosed that affect the versions of the operating system or software stack in Linux VM images, we will investigate the impact that this has on our images being used within the CircleCI execution environment. If customers are impacted by these CVEs we will push a patch fix to the released image(s). This image will supersede the original image.
When critical CVEs are disclosed around the operating system or software stack of this image, we will investigate the impact this has on the image within the CircleCI execution environment. If customers are impacted by these CVEs we will push a patch fix to the released image(s). This image will supersede the original image.

[#bug-reports-issues-and-prs]
== Bug reports, issues, and PRs
Expand All @@ -63,10 +59,8 @@ Current Deprecation (Jan 2024):
| Support

| Ubuntu 20.04 LTS
| Build quarterly images for current year and retain Q4 (October) release from the past two years.

| Ubuntu 22.04 LTS
| Quarterly images built and only Q4 image retained each year
|===


Expand All @@ -82,13 +76,13 @@ Example: When Ubuntu 24.04 LTS is released
| Deprecated and removed entirely

| Ubuntu 22.04 LTS
| Retain only Q4 (October) releases from past two years
| `current` and `edge` tags retained

| Ubuntu 24.04 LTS
| Quarterly images built and only Q4 (October) image retained from each year
| `current` and `edge` tags retained
|===

When an image is selected for deprecation and removal, we will create an announcement on our Discuss forum, along with reaching out via email to developers who have requested one of the deprecated images in their recent jobs.
When an image is selected for deprecation and removal, we will create an announcement on our Discuss forum and along with additional outreach where possible.

We will also plan brownouts to ensure users are aware of the approaching removal of deprecated images. Generally, we will aim to start an EOL process within 3 months of a new version release.

Expand Down
40 changes: 19 additions & 21 deletions jekyll/_cci2/remote-docker-images-support-policy.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -14,14 +14,14 @@ contentTags:
[#overview]
== Overview

This document outlines the xref:building-docker-images#[CircleCI remote Docker image] release, update, and deprecation policy. This policy applies to all CircleCI remote Docker images built for the remote Docker feature (setup_remote_docker).
This document outlines the xref:building-docker-images#[CircleCI remote Docker image] release, update, and deprecation policy. This policy applies to all CircleCI remote Docker images built for the remote Docker feature (`setup_remote_docker`).

[#release-policy]
== Release policy

The CircleCI remote Docker images are based on our Linux VM images with Docker installed for the purposes of providing a remote environment that can execute Docker commands within jobs on the Docker executor.

We aim to support the latest two versions of the Docker Engine that are classified as within Security Support status.
We aim to support the latest three versions of the Docker Engine that are classified as within Security Support status.

Remote Docker images will be updated when a patch version is released upstream. Tags will be redirected to the updated images automatically as described in the xref:#tagging[tagging] section of this document. We will announce these releases on our link:https://discuss.circleci.com/[Discuss Forum].

Expand All @@ -36,14 +36,12 @@ For the latest major version of Docker:

- `edge`: This tag is reserved for previews of new releases, which will initially point to this tag. The tag may include incremental updates relative to the current quarterly image release, which may change without notice, and is not recommended for production CI workloads.

- `previous`: Once an `edge` image is promoted to `default`, the previous `default` image is moved to the `previous` tag.

For the previous major version of Docker, we support a single tag following the format of `dockerXX`, for example, `docker23` for Docker 23. This tag will point to the latest patch version of the major release, and will be updated if any patch versions are issued upstream. We recommend using the default version.
For the previous major version of Docker, we support a single tag following the format of `dockerXX`, for example, `docker27` for Docker 27. This tag will point to the latest patch version of the major release, and will be updated if any patch versions are issued upstream. We recommend using the default version.

[#critical-cve-patches]
== Critical CVE patches

When critical CVEs are disclosed that affect the versions of the operating system or software stack in our remote Docker images, we will investigate the impact that this has on our images being used within the CircleCI execution environment. If customers are impacted by these CVEs we will push a patch fix to the released image(s), this image will supersede the original image.
When critical CVEs are disclosed around the operating system or software stack of this image, we will investigate the impact this has on the image within the CircleCI execution environment. If customers are impacted by these CVEs we will push a patch fix to the released image(s), this image will supersede the original image.

[#bug-reports-issues-and-prs]
== Bug reports, issues, and PRs
Expand All @@ -63,39 +61,39 @@ Current Deprecation:
| Version
| Support

| Docker 20
| We will support one version of Docker 20 with a tag of `20.10.24`
| Docker 25
| `docker25` tag is maintained for Docker 25 support

| Docker 23
| `docker23` tag is maintained for Docker 23 support
| Docker 26
| `docker26` tag is maintained for Docker 26 support

| Docker 24
| Set to `default`, `edge` and `previous` tags
| Docker 27
| Set to `default` and `edge` tags. `docker27` tag is maintained for Docker 27 as default tag as well.
|===

Example: When Docker 25 is released:
Example: When Docker 28 is released:

[.table.table-striped]
[cols=2*, options="header", stripes=even]
|===
| Version
| Support

| Docker 20
| Docker 25
| Deprecated and removed

| Docker 23
| `docker23` tag is frozen and kept until next cycle
| Docker 26
| `docker26` tag kept until next cycle

| Docker 24
| Moved from `default`, `edge` and `previous` tags to `docker24` tag
| Docker 27
| Moved from `default` and `edge` tags to `docker27` tag only

| Docker 25
| Set to `default`, `edge` and `previous` tags
| Docker 28
| Set to `default` and `edge` tags. With `docker28` tag for pinning Docker version.
|===


When an image is selected for deprecation and removal, we will create an announcement on our Discuss forum, along with reaching out via email to developers who have requested one of the deprecated images in their recent jobs.
When an image is selected for deprecation and removal, we will create an announcement on our Discuss forum and along with additional outreach where possible.

We will also plan brownouts to ensure users are aware of the approaching removal of deprecated images. Generally, we will aim to start an EOL process within 3 months of a new version release

Expand Down
Loading