Files
kuber/changelogs/2.7.0.md
T
2026-10-06 15:31:51 +00:00

3.7 KiB

2.7.0-rc2

  • Simplify the cross-platform passive updater with explicit inherited environment and process.execPath, a bounded wait for the install outcome before CLI exit, and no TTY workaround or external timeout helper.
  • Show aggregate context-upload progress in an Uploading context child task, deduplicating shared blobs and accounting for resumed uploads.
  • Support build: auto:<GitHub HTTPS .cnb URI> with optional #sha256=<hex> pinning. The real kilterset/bun 1.0.0 package was fetched and validated for Linux ARM64; its architecture mismatch was correctly rejected for AMD64.
  • Live CNB Kubernetes Job execution and registry push remain unverified.

2.7.0-rc1

Added

  • Add kuber init to create compose.yml with a first app, log in when needed, and register trust for the current directory. Add kuber add app to insert another service into an existing project while preserving existing services and YAML content.
  • Support interactive and non-interactive scaffolding with app-root detection, image, Buildpacks, or Dockerfile-template sources, Postgres/S3 claims, resource limits, and replicas.
  • Bundle eight Dockerfile and .dockerignore templates: bun-service, bun-next, bun-compiled, node-pnpm, python-web, go-static, rust-static, and static-nginx.
  • Support bare build: auto through CNB Buildpacks, including subproject contexts through x-kuber-build-context. Auto builds require Git and use Git-selected worktree files with .gitignore filtering, including tracked files matched by ignore rules; .dockerignore does not control this selection.
  • Support build: auto:<URI> for an HTTPS GitHub release .cnb package, optionally pinned with #sha256=<hex>, with server-side package staging, digest verification, and target-architecture validation.

Changed

  • Begin generated Compose files with managedBy: kuber # See https://npmx.dev/@dmgnr/kuber for documentation. and accept the marker in kuber's Compose schema.
  • Show aggregate context-upload bytes and percentage as a separate task during kuber up, deduplicating shared blobs across workspaces and accounting for resumed uploads.
  • Simplify the passive updater to launch the current Bun executable with the inherited runtime environment, without Linux terminal helpers or an external timeout command. Wait for the bounded install outcome and its success or available-version notice before CLI exit; suppress automatic installs in tests and source-tree development.

Fixed

  • Validate scaffold paths and options, refuse to overwrite existing generated files, detect concurrent Compose edits, and roll back newly generated files on failures. Initialization preserves files needed to repair local trust after successful remote registration.
  • Reject potential credential files selected for auto-build snapshots and require unsafe paths to be excluded through .gitignore.
  • Reject symlinked workspace parents and unsafe snapshot symlink traversal; validate server-side symlink chains and cycles before materialization.
  • Remove malformed or expired session files, including sessions with invalid expiry timestamps.
  • Bound registry manifest reads, validate supported manifest structure, verify advertised digests against the response bytes, and avoid exposing registry error-response bodies.
  • Reject unknown top-level Compose properties while retaining supported fields and x- extensions.

Release notes

  • Auto builds always use CNB Buildpacks, even when a Dockerfile exists; there is no BuildKit fallback. Ordinary Dockerfile builds retain the BuildKit path.
  • The managedBy marker is kuber-specific; ordinary docker compose rejects generated files containing it.
  • Live CNB Kubernetes Job execution and registry push have not been verified for this release candidate.