From 3541c68357d2e8367714b414a9ac6d828670ba2b Mon Sep 17 00:00:00 2001
From: lilly
Date: Tue, 19 May 2026 11:01:51 +0200
Subject: [PATCH 1/2] disable dnssec for catalog zones on auth-dns
Catalog zones are not real zones in the DNS hierarchy and don't
have a parent zone. Therefore they will never have a valid DNSSEC
delegation so we should skip signing those zones.
---
roles/knot/templates/knot.conf.j2 | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
diff --git a/roles/knot/templates/knot.conf.j2 b/roles/knot/templates/knot.conf.j2
index c661e25..45a0f8d 100644
--- a/roles/knot/templates/knot.conf.j2
+++ b/roles/knot/templates/knot.conf.j2
@@ -67,8 +67,7 @@ template:
# template for automatically created special zones
- id: catalog
catalog-role: generate
- dnssec-signing: on
- dnssec-policy: default
+ dnssec-signing: off
# define zones on this server
From 20b50a03b3b8e4edba9414bf0a6f13934886a76e Mon Sep 17 00:00:00 2001
From: Renovate
Date: Tue, 19 May 2026 09:16:11 +0000
Subject: [PATCH 2/2] Update docker.io/pretalx/standalone Docker tag to v2026
---
resources/chaosknoten/pretalx/docker_compose/compose.yaml.j2 | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/resources/chaosknoten/pretalx/docker_compose/compose.yaml.j2 b/resources/chaosknoten/pretalx/docker_compose/compose.yaml.j2
index 0bbfcb8..de4c8db 100644
--- a/resources/chaosknoten/pretalx/docker_compose/compose.yaml.j2
+++ b/resources/chaosknoten/pretalx/docker_compose/compose.yaml.j2
@@ -33,7 +33,7 @@ services:
- pretalx_net
pretalx:
- image: docker.io/pretalx/standalone:v2025.1.0
+ image: docker.io/pretalx/standalone:v2026.1.2
entrypoint: gunicorn
command:
- "pretalx.wsgi"
@@ -78,7 +78,7 @@ services:
- pretalx_net
celery:
- image: docker.io/pretalx/standalone:v2025.1.0
+ image: docker.io/pretalx/standalone:v2026.1.2
command:
- taskworker
restart: unless-stopped