Repository navigation
v1.8.0
Deep runtime telemetry arrives as an opt-in native extension, and the dev tier gets git back after shipping without it.
Highlights
cboxdk/telemetry-native in every tier from slim up, off by default. telemetry-native v0.1.0 is the native half of cboxdk/laravel-telemetry: a statistical CPU profiler on a per-thread CPU timer, native timing for PDO/Redis connects and curl_exec, bounded runtime counters, and a signal-safe crash recorder that re-raises so the process still dies with its core dump. laravel-telemetry can tell you a request burned 410 ms of PHP CPU; this tells you which call stacks burned it.
Set PHP_TELEMETRY_NATIVE=true to load it, and PHP_TELEMETRY_NATIVE_AUTO=true to additionally open a unit at RINIT so profiles cover framework boot — a separate switch on purpose, because RINIT fires once per process in queue workers and Octane, where an automatic unit would span hours and mean nothing.
It is off by default because it is pre-1.0 and because its crash recorder installs fatal-signal handlers — not because it costs anything. Upstream's FPM measurements put loading it, installing the hooks and arming the recorder inside the harness's own noise floor. That is the opposite of why opentelemetry is gated, and the ini uses the same read-only-safe scan-dir mechanism. PHP 8.3+ only; the 8.2 images skip it and say so.
The dev tier shipped without git. dev-base listed git among its build deps and then purged it with --auto-remove, which also took git-man, liberror-perl and patch. So the one tier that exists for CI and local development was the only one where composer VCS installs, git status on a bind-mounted app and cweagans/composer-patches did not work — while the baked safe.directory = * sat there with no git to serve.
Confirmed against the published images, not just the source: php-base:8.4-bookworm-dev and php-cli:8.4-bookworm-dev both answered git: not found, while their chromium/standard tiers had it. php-fpm and php-fpm-nginx dev images are unaffected — they build FROM the official php-fpm image with their own apt layer. New tests/test-runtime-deps.sh fails any stage that purges a slim-base runtime package, verified to fail on the old line.
arm64 built OpenTelemetry from the Dockerfile default. The shared build workflow has two near-identical jobs and only the amd64 one read extensions.opentelemetry out of versions.json, so after any pin bump the two architectures behind the same tag could carry different otel versions. Both jobs now read and pass it.
One changelog. docs/changelog.md is gone; cbox.dk takes the changelog from the root file. The duplicate sat at 1.5.1 for two minor releases while CHANGELOG.md reached 1.7.0, because the gate meant to catch that only ever compared them in the direction that stayed green.
PHP 8.6 beta lane, all four tiers (experimental, #23) also ships in this tag — see the changelog for the full 8.6.0beta2 extension scoreboard.
Getting the fixes
The image build chain is triggered by this release's commits. The dev-tier git fix reaches the registry when the php-base and php-cli builds finish; php-fpm and php-fpm-nginx were never affected.
Full details in CHANGELOG.md.