Skip to content

0.5.1 — 2026-09-23

Latest

Choose a tag to compare

@github-actions github-actions released this 23 Sep 12:27

Release Notes

Added

  • ags auth token prints the current access token to stdout and nothing else, so a
    script can reuse the CLI's session instead of running its own login, for example by
    passing $(ags auth token) as the bearer value of the Authorization header. Until now
    there was no way to get the bearer out of the CLI — ags auth status --format json reports
    "access_token": "valid", and --dry-run/--verbose print only a redacted header.
    The token is resolved exactly as an API call resolves it (AGS_ACCESS_TOKEN, then the
    stored token, refreshed when expired), so the printed token is the one the next request
    would send. With no token available it exits 2 (authentication failure) or 4
    (identity service unreachable), leaving stdout empty. --format json adds
    expires_at (Unix epoch seconds) and source (env / stored / refreshed /
    client_credentials). The token is printed only on stdout and never reaches stderr,
    including under --verbose, or telemetry. --dry-run is refused with a usage error
    because the command's only output would be a live credential.

  • ags update checks GitHub for a newer release and prints the upgrade command for the
    detected install method (installer script, Homebrew, or manual). It does not modify the
    installation. Use --format json for scripts.

  • ags update --install downloads the newest release's installer script and runs it for
    this copy after confirmation (--yes for scripts). Refuses a copy installed with
    Homebrew when an update is available. Keeps the previous binary as .old and restores it
    on failure. The first Ctrl-C restores the previous binary and exits 2; a second Ctrl-C is
    a force quit that exits at once and does not guarantee lock release or installer
    termination. Exit codes: 0 (installed or already current), 1 (usage or Homebrew refusal),
    2 (declined or interrupted), 4 (download failure), 5 (installer failure, verification
    failure, or restore failure). --dry-run prints what it would do and sends no request.
    The CLI never updates itself unasked.

  • ags extend security-assessment request starts a pen-testing engagement for an Extend
    app's endpoints, and ags extend security-assessment result downloads a completed
    engagement's report. Endpoints that accept PUT, PATCH or DELETE are listed and
    confirmed before the request is sent, because the assessment may generate test cases that
    modify or delete data through them. --yes confirms in non-interactive mode. --wait polls
    every 10 seconds until the engagement reaches COMPLETED or FAILED, bounded by
    --wait-limit (default 1800s). A downloaded report is written with 0600 permissions on
    Unix.

  • ags extend create-app, deploy-app, start-app, stop-app and delete-app accept
    --wait to block until the operation finishes, with --wait-interval (default 10s) and
    --wait-limit (default 600s), matching extend-helper-cli. This was listed under 0.5.0 by
    mistake. It merged after that release and ships here.

  • When a command exists at more than one API version, the output names the version it used.
    The label goes to stderr, so --format json output a script parses is unchanged.

Fixed

  • ags extend <shortcut> --help now shows the shortcut's own help page, instead of a usage
    line for a command you did not type.
  • The DO_NOT_TRACK opt-out link now points at https://donottrack.sh. The previous domain
    serves unrelated content.
  • ags ams upload error messages now quote the --executable value as you typed it
    instead of the resolved path. A 403 while finalizing or completing the upload now says
    the identity is missing the Update action of AMS:UPLOAD, instead of implying the
    whole permission is missing.
  • The competitive-multiplayer workflow briefing no longer tells you to upload the image with
    the retired AMS CLI. The workflow archives and uploads the build itself.
  • ags ams upload --dry-run now validates and normalises --upload-url the same way a
    live upload does. An invalid override now fails the dry run instead of being echoed back
    unvalidated, and a trailing slash is stripped from the reported upload_base_url.
  • ags extend deploy-app --wait and start-app --wait no longer poll for the full
    --wait-limit when a deployment comes up and then crashes (bad image, failed readiness,
    CrashLoopBackOff). The app's deployment-down status is now treated as a failed rollout,
    so the command exits promptly with deployment failed: deployment-down (exit 3) instead
    of a misleading timeout (exit 6).

Changed

  • ags ams upload human output no longer swaps its streams. The result block — Image ID,
    architecture, entrypoint, archive size and upload host, or the --dry-run plan rows — now
    goes to stdout, and the Image "<name>" uploaded banner, along with the dry-run tip,
    goes to stderr. Until now it was the reverse, so ags ams upload ... > result.txt and
    --output result.txt saved the banner and lost the Image ID. Scripts that read the old
    streams will see a change: read the Image ID from stdout, not stderr. The banner still
    prints before the block on a terminal, and --format json is unchanged.
  • ags ams upload writes its first progress line, Validating <dir>, as a normal stderr
    line like the lines after it. It was sent as a transient status update, so the next line
    overwrote it on a terminal and it was absent entirely from a captured run.
  • ags extend deploy-app --wait now confirms the app is reporting the deployment this
    command created before trusting any terminal state. Previously the wait evaluated
    appStatus alone, so its correctness depended on CSM setting deployment-in-progress in
    the same transaction as the deployment insert — an ordering the CLI cannot enforce and had
    no test against. Confirming OUR deployment id first means a later change to CSM's write
    ordering, or a concurrent deploy by another actor, cannot produce a false success. This is
    hardening of the (unreleased) --wait feature, not a fix for shipped behaviour.
  • A --wait timeout exits with code 6, distinct from an API error (3), on both the Extend
    app lifecycle commands and security-assessment request, so a CI
    caller can tell "the wait timed out, the operation may still land" from "the rollout
    failed, do not retry" without matching message text.
  • The CSM spec now bundles the v5 operations for the Extend app lifecycle —
    create-deployment, delete-app, get-app, start-app, stop-app, and list-images. As v5 is the
    highest bundled version it becomes the default, so ags extend deploy-app, delete-app,
    get-app-info, start-app, stop-app, and list-images now target their /csm/v5/...
    endpoints. Together with create-app (already v5), every Extend app-lifecycle command now
    uses the CSM v5 API. Verified end to end against the development cluster.
  • ags extend update-secret and ags extend update-var also move from the CSM v2 to the
    v5 secrets/variables endpoints. These are existing commands, so this is a behaviour change;
    the request and response shapes are unchanged from v2.
  • The v5 endpoints use the same IAM permission resources as their v2 counterparts
    (ADMIN:NAMESPACE:{namespace}:EXTEND:APP / :DEPLOYMENT / :IMAGE / :VARIABLE /
    :SECRET, actions unchanged), so moving these commands to v5 does not change what a caller
    must be granted — no role that worked on v2 will start getting 403 after upgrading.

Security

  • Updated rustls from 0.23.43 to 0.23.45 for a published advisory.

Install accelbyte-ags-cli 0.5.1

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://github.com/AccelByte/accelbyte-ags-cli/releases/download/v0.5.1/accelbyte-ags-cli-installer.sh | sh

Install prebuilt binaries via powershell script

powershell -ExecutionPolicy Bypass -c "irm https://github.com/AccelByte/accelbyte-ags-cli/releases/download/v0.5.1/accelbyte-ags-cli-installer.ps1 | iex"

Install prebuilt binaries via Homebrew

brew install AccelByte/tap/ags-cli

Download accelbyte-ags-cli 0.5.1

File Platform Checksum
accelbyte-ags-cli-aarch64-apple-darwin.tar.xz Apple Silicon macOS checksum
accelbyte-ags-cli-x86_64-apple-darwin.tar.xz Intel macOS checksum
accelbyte-ags-cli-x86_64-pc-windows-msvc.zip x64 Windows checksum
accelbyte-ags-cli-aarch64-unknown-linux-gnu.tar.xz ARM64 Linux checksum
accelbyte-ags-cli-x86_64-unknown-linux-gnu.tar.xz x64 Linux checksum
accelbyte-ags-cli-aarch64-unknown-linux-musl.tar.xz ARM64 MUSL Linux checksum
accelbyte-ags-cli-x86_64-unknown-linux-musl.tar.xz x64 MUSL Linux checksum