Release Notes
Added
-
ags auth tokenprints the current access token to stdout and nothing else, so a
script can reuse the CLI's session instead of running its own login, for example by
passing$(ags auth token)as the bearer value of theAuthorizationheader. Until now
there was no way to get the bearer out of the CLI —ags auth status --format jsonreports
"access_token": "valid", and--dry-run/--verboseprint only a redacted header.
The token is resolved exactly as an API call resolves it (AGS_ACCESS_TOKEN, then the
stored token, refreshed when expired), so the printed token is the one the next request
would send. With no token available it exits2(authentication failure) or4
(identity service unreachable), leaving stdout empty.--format jsonadds
expires_at(Unix epoch seconds) andsource(env/stored/refreshed/
client_credentials). The token is printed only on stdout and never reaches stderr,
including under--verbose, or telemetry.--dry-runis refused with a usage error
because the command's only output would be a live credential. -
ags updatechecks GitHub for a newer release and prints the upgrade command for the
detected install method (installer script, Homebrew, or manual). It does not modify the
installation. Use--format jsonfor scripts. -
ags update --installdownloads the newest release's installer script and runs it for
this copy after confirmation (--yesfor scripts). Refuses a copy installed with
Homebrew when an update is available. Keeps the previous binary as.oldand restores it
on failure. The first Ctrl-C restores the previous binary and exits 2; a second Ctrl-C is
a force quit that exits at once and does not guarantee lock release or installer
termination. Exit codes: 0 (installed or already current), 1 (usage or Homebrew refusal),
2 (declined or interrupted), 4 (download failure), 5 (installer failure, verification
failure, or restore failure).--dry-runprints what it would do and sends no request.
The CLI never updates itself unasked. -
ags extend security-assessment requeststarts a pen-testing engagement for an Extend
app's endpoints, andags extend security-assessment resultdownloads a completed
engagement's report. Endpoints that acceptPUT,PATCHorDELETEare listed and
confirmed before the request is sent, because the assessment may generate test cases that
modify or delete data through them.--yesconfirms in non-interactive mode.--waitpolls
every 10 seconds until the engagement reachesCOMPLETEDorFAILED, bounded by
--wait-limit(default 1800s). A downloaded report is written with0600permissions on
Unix. -
ags extend create-app,deploy-app,start-app,stop-appanddelete-appaccept
--waitto block until the operation finishes, with--wait-interval(default 10s) and
--wait-limit(default 600s), matchingextend-helper-cli. This was listed under 0.5.0 by
mistake. It merged after that release and ships here. -
When a command exists at more than one API version, the output names the version it used.
The label goes to stderr, so--format jsonoutput a script parses is unchanged.
Fixed
ags extend <shortcut> --helpnow shows the shortcut's own help page, instead of a usage
line for a command you did not type.- The
DO_NOT_TRACKopt-out link now points athttps://donottrack.sh. The previous domain
serves unrelated content. ags ams uploaderror messages now quote the--executablevalue as you typed it
instead of the resolved path. A 403 while finalizing or completing the upload now says
the identity is missing theUpdateaction ofAMS:UPLOAD, instead of implying the
whole permission is missing.- The
competitive-multiplayerworkflow briefing no longer tells you to upload the image with
the retired AMS CLI. The workflow archives and uploads the build itself. ags ams upload --dry-runnow validates and normalises--upload-urlthe same way a
live upload does. An invalid override now fails the dry run instead of being echoed back
unvalidated, and a trailing slash is stripped from the reportedupload_base_url.ags extend deploy-app --waitandstart-app --waitno longer poll for the full
--wait-limitwhen a deployment comes up and then crashes (bad image, failed readiness,
CrashLoopBackOff). The app'sdeployment-downstatus is now treated as a failed rollout,
so the command exits promptly withdeployment failed: deployment-down(exit3) instead
of a misleading timeout (exit6).
Changed
ags ams uploadhuman output no longer swaps its streams. The result block — Image ID,
architecture, entrypoint, archive size and upload host, or the--dry-runplan rows — now
goes to stdout, and theImage "<name>" uploadedbanner, along with the dry-run tip,
goes to stderr. Until now it was the reverse, soags ams upload ... > result.txtand
--output result.txtsaved the banner and lost the Image ID. Scripts that read the old
streams will see a change: read the Image ID from stdout, not stderr. The banner still
prints before the block on a terminal, and--format jsonis unchanged.ags ams uploadwrites its first progress line,Validating <dir>, as a normal stderr
line like the lines after it. It was sent as a transient status update, so the next line
overwrote it on a terminal and it was absent entirely from a captured run.ags extend deploy-app --waitnow confirms the app is reporting the deployment this
command created before trusting any terminal state. Previously the wait evaluated
appStatusalone, so its correctness depended on CSM settingdeployment-in-progressin
the same transaction as the deployment insert — an ordering the CLI cannot enforce and had
no test against. Confirming OUR deployment id first means a later change to CSM's write
ordering, or a concurrent deploy by another actor, cannot produce a false success. This is
hardening of the (unreleased)--waitfeature, not a fix for shipped behaviour.- A
--waittimeout exits with code6, distinct from an API error (3), on both the Extend
app lifecycle commands andsecurity-assessment request, so a CI
caller can tell "the wait timed out, the operation may still land" from "the rollout
failed, do not retry" without matching message text. - The CSM spec now bundles the v5 operations for the Extend app lifecycle —
create-deployment, delete-app, get-app, start-app, stop-app, and list-images. As v5 is the
highest bundled version it becomes the default, soags extend deploy-app,delete-app,
get-app-info,start-app,stop-app, andlist-imagesnow target their/csm/v5/...
endpoints. Together withcreate-app(already v5), every Extend app-lifecycle command now
uses the CSM v5 API. Verified end to end against the development cluster. ags extend update-secretandags extend update-varalso move from the CSM v2 to the
v5 secrets/variables endpoints. These are existing commands, so this is a behaviour change;
the request and response shapes are unchanged from v2.- The v5 endpoints use the same IAM permission resources as their v2 counterparts
(ADMIN:NAMESPACE:{namespace}:EXTEND:APP/:DEPLOYMENT/:IMAGE/:VARIABLE/
:SECRET, actions unchanged), so moving these commands to v5 does not change what a caller
must be granted — no role that worked on v2 will start getting 403 after upgrading.
Security
- Updated
rustlsfrom 0.23.43 to 0.23.45 for a published advisory.
Install accelbyte-ags-cli 0.5.1
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/AccelByte/accelbyte-ags-cli/releases/download/v0.5.1/accelbyte-ags-cli-installer.sh | shInstall prebuilt binaries via powershell script
powershell -ExecutionPolicy Bypass -c "irm https://github.com/AccelByte/accelbyte-ags-cli/releases/download/v0.5.1/accelbyte-ags-cli-installer.ps1 | iex"Install prebuilt binaries via Homebrew
brew install AccelByte/tap/ags-cliDownload accelbyte-ags-cli 0.5.1
| File | Platform | Checksum |
|---|---|---|
| accelbyte-ags-cli-aarch64-apple-darwin.tar.xz | Apple Silicon macOS | checksum |
| accelbyte-ags-cli-x86_64-apple-darwin.tar.xz | Intel macOS | checksum |
| accelbyte-ags-cli-x86_64-pc-windows-msvc.zip | x64 Windows | checksum |
| accelbyte-ags-cli-aarch64-unknown-linux-gnu.tar.xz | ARM64 Linux | checksum |
| accelbyte-ags-cli-x86_64-unknown-linux-gnu.tar.xz | x64 Linux | checksum |
| accelbyte-ags-cli-aarch64-unknown-linux-musl.tar.xz | ARM64 MUSL Linux | checksum |
| accelbyte-ags-cli-x86_64-unknown-linux-musl.tar.xz | x64 MUSL Linux | checksum |