Skip to content

Releases: Bonnary/pier

v0.0.11

Choose a tag to compare

@Bonnary Bonnary released this 02 Sep 07:49

Added

  • deploy.<env>.port — SSH port for the deploy host (default 22)
  • deploy.<env>.builder.build_port — SSH port for the build server (default 22)

Security

  • SSH host keys verified trust-on-first-use against ~/.ssh/known_hosts; a known host whose key changed is rejected
  • SFTP writes reject symlinked parent directories on the remote side
  • .env.production written with mode 0600

v0.0.10

Choose a tag to compare

@Bonnary Bonnary released this 30 Aug 05:13

v0.0.10 (2026-08-30)

Fixed

  • The s3 container ran SeaweedFS as weed mini, but the
    chrislusf/seaweedfs image's ENTRYPOINT already execs weed, so
    the container actually ran weed weed mini and exited with "unknown
    subcommand" — the S3 gateway never came up. The command is now mini
    (the ENTRYPOINT supplies the weed prefix), which starts the S3
    gateway on :8333 and pre-creates the bucket again.

Changed

  • Bumped version constant to 0.0.10 (reflected in pier --version,
    cmd/pier/main_test.go, and the README status line).

v0.0.9

Choose a tag to compare

@Bonnary Bonnary released this 30 Aug 02:34

v0.0.9 (2026-08-30)

Added

  • The s3 sidecar (SeaweedFS) now runs in weed mini mode, which
    starts the S3 gateway on port 8333 and pre-creates a bucket on
    startup. The bucket takes its name from S3_BUCKET, which pier
    interpolates from AWS_BUCKET (default app) so it stays in sync
    with the app.
  • pier init now writes the full S3 configuration to .env (dev) and
    .env.production (prod) when s3 is in the services list:
    AWS_ENDPOINT=http://s3:8333, AWS_ACCESS_KEY_ID=somekey,
    AWS_SECRET_ACCESS_KEY=somesecret, AWS_DEFAULT_REGION=us-east-1,
    AWS_BUCKET=app, AWS_USE_PATH_STYLE_ENDPOINT=yes. Dev previously
    needed to add the AWS_* keys by hand.
  • The prod compose now interpolates those AWS_* values
    (${AWS_ENDPOINT}, ${AWS_ACCESS_KEY_ID}, ...) into the app,
    queue, and scheduler containers, so they reach the app even though
    prod has no bind-mounted .env.

Fixed

  • The s3 container ran SeaweedFS's default weed server, which does
    not start the S3 gateway unless -s3 is passed — so port 8333 never
    actually served S3 and the healthcheck could not pass. It now runs
    weed mini, which starts the S3 API on 8333.

Changed

  • Bumped version constant to 0.0.9 (reflected in pier --version,
    cmd/pier/main_test.go, and the README status line).

v0.0.7-beta

Choose a tag to compare

@Bonnary Bonnary released this 18 Aug 11:49

v0.0.7-beta (2026-08-18)

Added

  • Custom domains + HTTPS: the production webserver is now Caddy
    (caddy:2-alpine) with a pier-rendered docker/caddy/Caddyfile.
    A non-empty [deploy.<env>].domain enables HTTPS with automatic
    Let's Encrypt certificates; [deploy.<env>].redirect_domains
    (e.g. www) are served and redirected to the env's domain. Empty
    domain = plain HTTP by IP.
  • Deploy DNS preflight: when a domain is set, pier deploy verifies
    it resolves to the deploy host before syncing and fails fast with
    an A-record hint otherwise; the health probe then checks
    https://<domain>/up end to end.
  • pier init prompts for the production domain, written to
    [deploy.production].domain (blank = plain HTTP by IP).

Changed

  • The deploy render phase re-writes docker/caddy/Caddyfile from
    pier.toml before syncing. Setting (or removing) a domain in
    [deploy.<env>] now takes effect on the next pier deploy; the
    file is pier-rendered, so manual edits are overwritten.
  • The webserver service in the merged prod compose is now fully
    pier-managed: its ports follow pier.toml, so adding a domain
    publishes 443:443 (and removing one drops it) instead of keeping
    a stale [80:80] list that leaves Caddy unable to answer HTTPS.
  • MergeEnvFile updates pier-derived .env.production keys (e.g.
    APP_URL from the env's domain) when the render changes, instead of
    preserving every existing line verbatim. User-owned keys are still
    never touched: secrets (APP_KEY, DB_PASSWORD, AWS credentials)
    and the ${...}-interpolated overrides (TRUSTED_PROXIES,
    CACHE_STORE, QUEUE_CONNECTION).
  • Domains are per deploy env: [project].domain is removed and the
    old per-env extra-domains key is renamed to
    [deploy.<env>].redirect_domains. Existing configs keep loading
    (unknown keys are ignored), but envs no longer inherit a
    project-wide domain — set domain in each [deploy.<env>]
    section.
  • Bumped version constant to 0.0.7-beta (reflected in
    pier --version, cmd/pier/main_test.go, and the README status
    line).

Removed

  • [deploy.<env>].tls — HTTPS is now implied by domain presence.
    Existing configs keep loading (the key is ignored); delete it and
    set the domain instead.

v0.0.6-beta

Choose a tag to compare

@Bonnary Bonnary released this 15 Aug 12:14

v0.0.6-beta (2026-08-15)

Added

  • queue_workers config ([stack] default 1, [deploy.<env>]
    override, max 32) runs that many queue:work processes in the
    queue container via supervisord numprocs, in dev and prod.
    pier init writes the explicit default.

Changed

  • Bumped version constant to 0.0.6-beta (reflected in
    pier --version, cmd/pier/main_test.go, and the README status
    line).

v0.0.5-beta

Choose a tag to compare

@Bonnary Bonnary released this 10 Aug 19:41

Added

  • pier init asks the full deploy setup — deploy host/user/path
    (branch defaulting to main) and the build machine (host_server /
    local_machine / build_server, with build host/user/path when
    build_server); --builder / --host / --user / --path /
    --build-host / --build-user / --build-path flags skip the
    prompts.
  • [deploy.<env>].builder / build_host / build_user / build_path
    configuration for build server modes; pier bootstrap <env>
    provisions both machines when build_server is set.
  • Real git SHA image tags (timestamp fallback) replace the hardcoded
    gitsha placeholder; docker tag wiring fixes pier rollback in
    every builder mode.
  • Per-env sidecar services: [deploy.<env>].services overrides
    [stack].services for that env (absent = inherit, [] = none).
    pier init scaffolds [deploy.production] with the chosen
    services; pier service [env] replaces add/remove with a
    single init-style picker that edits dev or per-env lists.
  • pier deploy <env> now re-renders docker-compose.prod.yml and
    .env.production from pier.toml before syncing (preserving
    hand-written compose edits and existing env values), so per-env
    services and [deploy.<env>].ports overrides take effect.
  • Remote teardown: docker compose up runs with --remove-orphans,
    so sidecars removed from an env are stopped and removed on the
    server (named volumes are kept).

Removed

  • pier buildmode <env> — the init flow now asks the build-machine
    question; change it later by editing pier.toml.

Changed

  • The pier init deploy-host prompt now reads "Deploy host (SSH target
    Domain name or IP address, enter to skip)" so the expected input is
    clear.

Fixed

  • The queue / scheduler app-image sidecars in image modes
    (local_machine, build_server) now reference the image tag the
    transfer phase actually ships (:current) instead of :latest:
    compose would otherwise try to pull :latest from the registry, and
    a first deploy failed with pull access denied.
  • App-image sidecars now receive the same connection environment as the
    app (DB_*, REDIS_*, APP_KEY interpolated from
    .env.production): without it the worker authenticated with the dev
    .env baked into the image and crash-looped with password authentication failed.
  • With redis in the stack, the rendered env files now default
    CACHE_STORE=redis and QUEUE_CONNECTION=redis (interpolated via
    ${CACHE_STORE} / ${QUEUE_CONNECTION} in the prod compose so the
    values can be overridden in .env.production; dev compose gets the
    same defaults). The database-driver defaults made queue/scheduler
    workers boot-check the cache/jobs tables — which only exist after
    after_deploy migrations — so a first deploy's up --wait could
    never pass, and a refused boot-time connection made queue:work exit
    0, which supervisord's default autorestart=unexpected never
    restarted, leaving the queue container unhealthy forever.
  • The prod runtime's supervisord now always restarts the php program
    (autorestart=true), so a Laravel worker that exits 0 (queue: restart, a lost-connection stop in newer Laravel) comes back instead
    of staying dead.
  • Bumped version constant to 0.0.5-beta (reflected in
    pier --version, cmd/pier/main_test.go, and the README status
    line).