• v32.18.0
    Release / build-and-release (push) Failing after 11m38s
    Stable

    philkunz released this 2026-09-28 04:42:49 +00:00 | 28 commits to main since this release

    2026-09-28 - 32.18.0

    Features

    • Bundle the Cloudly App Store template 1.7.0 for Cloudly 33.4.0 through @serve.zone/appstore 32.7.0, moved from 32.6.0 in package.json, pnpm-lock.yaml and the binary's deno.lock. Onebox reads the App Store from the catalog this package bundles, so onebox appstore upgrade cloudly --version 1.7.0 on a host running template 1.2.1, 1.3.0, 1.4.0, 1.5.0 or 1.6.0 needs this release. The template pins the Cloudly 33.4.0 image index code.foss.global/serve.zone/cloudly@sha256:f4f88f0c3765d1b129fa4f3ff68438958e55d4fad598393fb0c686261e46c7ed, keeps the 1.6.0 runtime contract (environment, both root-only secret files, platform OIDC, health check) and requires Onebox 32.4.0; against 1.6.0 only its image and changelog differ. It marks the upgrade breaking, migration-required, backup-before-upgrade and manual-review, because Onebox reads these flags from the target version alone: from every earlier template Cloudly 33.4.0 runs the forward-only data step runtime-session-protocol-offer from 0.21.0 to 0.22.0 at its first start, which states protocol: null on Pallet session rows recorded before Cloudly stored a node's protocol offer, and from 1.2.1 the 0.20.0 to 0.21.0 migration of Cloudly 33.0.0 runs before it; neither step has an inverse, so only the pre-upgrade backup goes back. The template changelog names the published-port ranges and symmetric same-port outbound of Cloudly 33.4.0, the SNAT band of new handoff leases, the refusals published-port-reserved, published-port-symmetric-without-egress, published-port-symmetric-inside-overlap and service-deleting, and the node-contract-behind withholding from Pallet nodes below interfaces 32.31.0; from 1.4.0 and earlier the rollout order Cloudly 33.4.0 before Coreflow 33.2.0. Onebox enforces only minOneboxVersion; the other flags and the template changelog are the operator's, as the Cloudly upgrade runbook states. The App Store upgrade test now checks that 1.7.0 is the latest catalog version and prepares its upgrade from installs of 1.2.1 (Cloudly 32.9.1 image, as central runs), 1.3.0, 1.4.0, 1.5.0 and 1.6.0 (Cloudly 33.0.0, 33.1.0, 33.2.0 and 33.3.0 images). App Store 32.7.0 still pins @serve.zone/interfaces 32.3.0, so no other runtime package moves.

    Maintenance

    • Merge the dashboard bundle's third-party notices into the release binaries' THIRD_PARTY_NOTICES.md. The binary embeds the minified dashboard bundle from dist_serve, whose packages' license texts it carried nowhere; @git.zone/tsbundle 3 writes them beside the bundle as dist_serve/bundle.js.third-party-notices.txt and .json. The release workflow's notices step now runs pnpm run notices:binary (scripts/assemble-binary-notices.ts), which writes the Onebox and @serve.zone/workloadinit licenses, the workloadinit notices, the dashboard notices verbatim in a fenced block and notices/third-party-notices.supplement.md. It refuses a build without the dashboard notices, a text file that is not tsbundle's, and a text and JSON pair that disagree on the bundled packages. test/binary-notices.node.ts covers the merge and the three refusals with fixture notices.
    • @design.estate/dees-catalog ^16.4.0 → ^16.6.0; release tooling @git.zone/tsbundle 3.0.0 (the dashboard bundle ships its third-party notices, which the binary notices now merge), @git.zone/tsdeno 1.11.0 (the committed minimumDependencyAge in deno.json stays authoritative) and @git.zone/tswatch 4.0.2 (pnpm 12.6.0 and @types/node 26.6.3 wait for the seven-day rule).
    Downloads