Repository navigation
Releases: Bonnary/pier
Releases · Bonnary/pier
Release list
v0.0.11
Added
deploy.<env>.port— SSH port for the deploy host (default 22)deploy.<env>.builder.build_port— SSH port for the build server (default 22)
Security
- SSH host keys verified trust-on-first-use against
~/.ssh/known_hosts; a known host whose key changed is rejected - SFTP writes reject symlinked parent directories on the remote side
.env.productionwritten with mode0600
v0.0.10
v0.0.10 (2026-08-30)
Fixed
- The
s3container ran SeaweedFS asweed mini, but the
chrislusf/seaweedfsimage'sENTRYPOINTalready execsweed, so
the container actually ranweed weed miniand exited with "unknown
subcommand" — the S3 gateway never came up. The command is nowmini
(the ENTRYPOINT supplies theweedprefix), which starts the S3
gateway on:8333and pre-creates the bucket again.
Changed
- Bumped version constant to
0.0.10(reflected inpier --version,
cmd/pier/main_test.go, and the README status line).
v0.0.9
v0.0.9 (2026-08-30)
Added
- The
s3sidecar (SeaweedFS) now runs inweed minimode, which
starts the S3 gateway on port 8333 and pre-creates a bucket on
startup. The bucket takes its name fromS3_BUCKET, which pier
interpolates fromAWS_BUCKET(defaultapp) so it stays in sync
with the app. pier initnow writes the full S3 configuration to.env(dev) and
.env.production(prod) whens3is in the services list:
AWS_ENDPOINT=http://s3:8333,AWS_ACCESS_KEY_ID=somekey,
AWS_SECRET_ACCESS_KEY=somesecret,AWS_DEFAULT_REGION=us-east-1,
AWS_BUCKET=app,AWS_USE_PATH_STYLE_ENDPOINT=yes. Dev previously
needed to add theAWS_*keys by hand.- The prod compose now interpolates those
AWS_*values
(${AWS_ENDPOINT},${AWS_ACCESS_KEY_ID}, ...) into the app,
queue, and scheduler containers, so they reach the app even though
prod has no bind-mounted.env.
Fixed
- The
s3container ran SeaweedFS's defaultweed server, which does
not start the S3 gateway unless-s3is passed — so port 8333 never
actually served S3 and the healthcheck could not pass. It now runs
weed mini, which starts the S3 API on 8333.
Changed
- Bumped version constant to
0.0.9(reflected inpier --version,
cmd/pier/main_test.go, and the README status line).
v0.0.7-beta
v0.0.7-beta (2026-08-18)
Added
- Custom domains + HTTPS: the production webserver is now Caddy
(caddy:2-alpine) with a pier-rendereddocker/caddy/Caddyfile.
A non-empty[deploy.<env>].domainenables HTTPS with automatic
Let's Encrypt certificates;[deploy.<env>].redirect_domains
(e.g.www) are served and redirected to the env's domain. Empty
domain = plain HTTP by IP. - Deploy DNS preflight: when a domain is set,
pier deployverifies
it resolves to the deploy host before syncing and fails fast with
an A-record hint otherwise; the health probe then checks
https://<domain>/upend to end. pier initprompts for the production domain, written to
[deploy.production].domain(blank = plain HTTP by IP).
Changed
- The deploy render phase re-writes
docker/caddy/Caddyfilefrom
pier.tomlbefore syncing. Setting (or removing) a domain in
[deploy.<env>]now takes effect on the nextpier deploy; the
file is pier-rendered, so manual edits are overwritten. - The webserver service in the merged prod compose is now fully
pier-managed: its ports followpier.toml, so adding a domain
publishes443:443(and removing one drops it) instead of keeping
a stale[80:80]list that leaves Caddy unable to answer HTTPS. MergeEnvFileupdates pier-derived.env.productionkeys (e.g.
APP_URLfrom the env's domain) when the render changes, instead of
preserving every existing line verbatim. User-owned keys are still
never touched: secrets (APP_KEY,DB_PASSWORD, AWS credentials)
and the${...}-interpolated overrides (TRUSTED_PROXIES,
CACHE_STORE,QUEUE_CONNECTION).- Domains are per deploy env:
[project].domainis removed and the
old per-env extra-domains key is renamed to
[deploy.<env>].redirect_domains. Existing configs keep loading
(unknown keys are ignored), but envs no longer inherit a
project-wide domain — setdomainin each[deploy.<env>]
section. - Bumped version constant to
0.0.7-beta(reflected in
pier --version,cmd/pier/main_test.go, and the README status
line).
Removed
[deploy.<env>].tls— HTTPS is now implied by domain presence.
Existing configs keep loading (the key is ignored); delete it and
set the domain instead.
v0.0.6-beta
v0.0.6-beta (2026-08-15)
Added
queue_workersconfig ([stack]default 1,[deploy.<env>]
override, max 32) runs that manyqueue:workprocesses in the
queue container via supervisordnumprocs, in dev and prod.
pier initwrites the explicit default.
Changed
- Bumped version constant to
0.0.6-beta(reflected in
pier --version,cmd/pier/main_test.go, and the README status
line).
v0.0.5-beta
Added
pier initasks the full deploy setup — deploy host/user/path
(branch defaulting to main) and the build machine (host_server /
local_machine / build_server, with build host/user/path when
build_server);--builder/--host/--user/--path/
--build-host/--build-user/--build-pathflags skip the
prompts.[deploy.<env>].builder/build_host/build_user/build_path
configuration for build server modes;pier bootstrap <env>
provisions both machines whenbuild_serveris set.- Real git SHA image tags (timestamp fallback) replace the hardcoded
gitshaplaceholder;docker tagwiring fixespier rollbackin
every builder mode. - Per-env sidecar services:
[deploy.<env>].servicesoverrides
[stack].servicesfor that env (absent = inherit,[]= none).
pier initscaffolds[deploy.production]with the chosen
services;pier service [env]replacesadd/removewith a
single init-style picker that edits dev or per-env lists. pier deploy <env>now re-rendersdocker-compose.prod.ymland
.env.productionfrom pier.toml before syncing (preserving
hand-written compose edits and existing env values), so per-env
services and[deploy.<env>].portsoverrides take effect.- Remote teardown:
docker compose upruns with--remove-orphans,
so sidecars removed from an env are stopped and removed on the
server (named volumes are kept).
Removed
pier buildmode <env>— the init flow now asks the build-machine
question; change it later by editingpier.toml.
Changed
- The
pier initdeploy-host prompt now reads "Deploy host (SSH target
Domain name or IP address, enter to skip)" so the expected input is
clear.
Fixed
- The
queue/schedulerapp-image sidecars in image modes
(local_machine,build_server) now reference the image tag the
transfer phase actually ships (:current) instead of:latest:
compose would otherwise try to pull:latestfrom the registry, and
a first deploy failed withpull access denied. - App-image sidecars now receive the same connection environment as the
app (DB_*,REDIS_*,APP_KEYinterpolated from
.env.production): without it the worker authenticated with the dev
.envbaked into the image and crash-looped withpassword authentication failed. - With redis in the stack, the rendered env files now default
CACHE_STORE=redisandQUEUE_CONNECTION=redis(interpolated via
${CACHE_STORE}/${QUEUE_CONNECTION}in the prod compose so the
values can be overridden in.env.production; dev compose gets the
same defaults). The database-driver defaults made queue/scheduler
workers boot-check thecache/jobstables — which only exist after
after_deploymigrations — so a first deploy'sup --waitcould
never pass, and a refused boot-time connection madequeue:workexit
0, which supervisord's defaultautorestart=unexpectednever
restarted, leaving the queue container unhealthy forever. - The prod runtime's supervisord now always restarts the php program
(autorestart=true), so a Laravel worker that exits 0 (queue: restart, a lost-connection stop in newer Laravel) comes back instead
of staying dead. - Bumped version constant to
0.0.5-beta(reflected in
pier --version,cmd/pier/main_test.go, and the README status
line).