rackpatch v0.3.0
Pre-release
Pre-release
rackpatch v0.3.0
rackpatch v0.3.0 is a trust-focused release centered on least-privilege host maintenance, clearer operator UX, and repo cleanup.
Highlights
- Added a limited host-maintenance helper for package operations.
- Agents now advertise explicit helper-backed capabilities such as
host-package-checkandhost-package-patch. - Package maintenance is now agent-only and helper-gated.
- Multi-host package requests fan out into per-host agent jobs.
- The web UI now shows helper requirements, greys out ineligible hosts, and explains why a host is blocked.
- Added backup metadata and delete support in the UI.
- Improved agent install/update command generation and release visibility in the UI.
- Removed lingering Semaphore assets and cleaned up older trust signals.
Breaking / Behavior Changes
package_checkandpackage_patchno longer fall back to the worker or SSH path.- Hosts must have the limited host-maintenance helper enabled before package jobs can run.
- Some hosts may be intentionally blocked for live helper patching when policy requires features not yet modeled in the helper flow, such as snapshot-before-patch behavior.
Upgrade Notes
- Existing agents should be updated to the latest agent code.
- Enable the host-maintenance helper explicitly on hosts that should allow package maintenance.
- Test helper-backed package operations on one low-risk host first, such as
vault, before wider rollout.
Operator Notes
- UI package actions now reflect helper and policy eligibility directly.
- GitHub release tracking remains available for the control plane and enrolled agents.
make validateandmake release-checkare the recommended pre-release checks.