Files
kuber/changelogs/2.7.0.md
T
2026-10-06 15:31:51 +00:00

38 lines
3.7 KiB
Markdown

# 2.7.0-rc2
- Simplify the cross-platform passive updater with explicit inherited environment and `process.execPath`, a bounded wait for the install outcome before CLI exit, and no TTY workaround or external timeout helper.
- Show aggregate context-upload progress in an `Uploading context` child task, deduplicating shared blobs and accounting for resumed uploads.
- Support `build: auto:<GitHub HTTPS .cnb URI>` with optional `#sha256=<hex>` pinning. The real `kilterset/bun` 1.0.0 package was fetched and validated for Linux ARM64; its architecture mismatch was correctly rejected for AMD64.
- Live CNB Kubernetes Job execution and registry push remain unverified.
# 2.7.0-rc1
## Added
- Add `kuber init` to create `compose.yml` with a first app, log in when needed, and register trust for the current directory. Add `kuber add app` to insert another service into an existing project while preserving existing services and YAML content.
- Support interactive and non-interactive scaffolding with app-root detection, image, Buildpacks, or Dockerfile-template sources, Postgres/S3 claims, resource limits, and replicas.
- Bundle eight Dockerfile and `.dockerignore` templates: `bun-service`, `bun-next`, `bun-compiled`, `node-pnpm`, `python-web`, `go-static`, `rust-static`, and `static-nginx`.
- Support bare `build: auto` through CNB Buildpacks, including subproject contexts through `x-kuber-build-context`. Auto builds require Git and use Git-selected worktree files with `.gitignore` filtering, including tracked files matched by ignore rules; `.dockerignore` does not control this selection.
- Support `build: auto:<URI>` for an HTTPS GitHub release `.cnb` package, optionally pinned with `#sha256=<hex>`, with server-side package staging, digest verification, and target-architecture validation.
## Changed
- Begin generated Compose files with `managedBy: kuber # See https://npmx.dev/@dmgnr/kuber for documentation.` and accept the marker in kuber's Compose schema.
- Show aggregate context-upload bytes and percentage as a separate task during `kuber up`, deduplicating shared blobs across workspaces and accounting for resumed uploads.
- Simplify the passive updater to launch the current Bun executable with the inherited runtime environment, without Linux terminal helpers or an external `timeout` command. Wait for the bounded install outcome and its success or available-version notice before CLI exit; suppress automatic installs in tests and source-tree development.
## Fixed
- Validate scaffold paths and options, refuse to overwrite existing generated files, detect concurrent Compose edits, and roll back newly generated files on failures. Initialization preserves files needed to repair local trust after successful remote registration.
- Reject potential credential files selected for auto-build snapshots and require unsafe paths to be excluded through `.gitignore`.
- Reject symlinked workspace parents and unsafe snapshot symlink traversal; validate server-side symlink chains and cycles before materialization.
- Remove malformed or expired session files, including sessions with invalid expiry timestamps.
- Bound registry manifest reads, validate supported manifest structure, verify advertised digests against the response bytes, and avoid exposing registry error-response bodies.
- Reject unknown top-level Compose properties while retaining supported fields and `x-` extensions.
## Release notes
- Auto builds always use CNB Buildpacks, even when a Dockerfile exists; there is no BuildKit fallback. Ordinary Dockerfile builds retain the BuildKit path.
- The `managedBy` marker is kuber-specific; ordinary `docker compose` rejects generated files containing it.
- Live CNB Kubernetes Job execution and registry push have not been verified for this release candidate.