Skip to content

NetOps 0.3.0

Choose a tag to compare

@Con-Benksl Con-Benksl released this 22 Jul 13:18
· 11 commits to main since this release

NetOps 0.3.0

Superseded by NetOps 0.3.1. Version 0.3.0 accidentally enabled shell xtrace in the remote backup transaction; use v0.3.1 instead.

This release replaces the blanket remote-write prohibition with a control-channel risk model:

  • An unrelated remote VPS can be changed directly by Codex over SSH after one explicit impact and rollback confirmation. Codex performs the backup, Linux commands, validation, verification, and rollback instead of handing commands to the user.
  • A remote node or VPS carrying the current Codex path requires a verified independent path or the exact-plan executor with automatic rollback.
  • Only local active control-plane changes that may disconnect Codex, such as TUN, system proxy, proxy process, DNS, routes, or firewall switching, remain a manual user action.

The exact-plan executor is now available for transactions that need it. Apply and rollback require strict authorization, a matching plan ID, fresh control-channel evidence, exact target coverage, verified backup integrity, and durable receipts. SQLite targets can use a stable reviewed query plus an online consistency backup so live counters do not invalidate unrelated configuration changes.

Compatibility

  • Change spec and plan schema: 3.0 (breaking; regenerate 2.0 plans)
  • Fleet and diagnostic bundle schemas: remain 2.0
  • Scheduled monitor installation and removal: still dry-run only

Release artifacts were built twice with the tag commit timestamp and passed fresh-install smoke tests. Verify downloads with SHA256SUMS.