Skip to content

Abada 0.11.0-alpha

Pre-release
Pre-release

Choose a tag to compare

@bashizip bashizip released this 19 Jul 15:50
· 540 commits to main since this release
3e6cdbc

Abada Engine 0.11.0-alpha Release Notes

Release date: 2026-07-19

Abada 0.11.0-alpha is the stable-contracts and security prerelease. It freezes
the /api/v1 REST surface and external-worker protocol v1, completes backend
RBAC, ships a Java worker client, and aligns Tenda and Orun with durable API
records.

Highlights

  • Stable typed DTOs and machine-readable error codes across API failures.
  • Executable generated-OpenAPI compatibility checking in CI.
  • Bounded database pagination and filters for definitions, instances, tasks,
    incidents and history.
  • Explicit deployment, process-control, task, operations and worker
    permissions for OIDC and trusted-proxy modes.
  • Negative tests for invalid/expired JWTs, forged proxy headers, role
    boundaries, CORS, logging and cross-user task access.
  • Worker protocol v1 with bounded fetch-and-lock, heartbeat, lock extension,
    completion, BPMN error, technical failure/retry, idempotency and trace
    propagation.
  • Standalone Java 21 worker SDK under sdk/java.
  • Orun now consumes durable audit history and correctly maps incident IDs;
    Tenda types match the frozen engine DTOs.

Database upgrade

Back up PostgreSQL, start one 0.11.0-alpha engine, and allow Flyway to apply
V9. V9 adds nullable BPMN-error and trace-context columns to external_tasks
plus an acquisition/ownership index. No existing row is deleted or rewritten.
Confirm schema version 9 before starting remaining replicas. Downgrade is not
supported; restore the backup to roll back.

Worker migration

Secured deployments now require completion bodies shaped as
{"workerId":"...","variables":{...}}. Raw variable-map completion remains
accepted only in disabled local/test mode. Use the Java worker client or update
existing workers before enabling 0.11 in production.

Boundary BPMN error events remain unsupported. A worker BPMN error is therefore
recorded as an unhandled business error and fails the process instance.

Verification evidence

The release candidate was verified on 2026-07-19 with Java 21, Node.js 24 and
Docker Desktop:

  • (cd engine && ./mvnw clean package): passed, 151 tests with no failures,
    errors or skips. PostgreSQL 16 Testcontainers covered fresh Flyway V9 installation,
    upgrades from schemas V1 through V8, restart recovery and multi-replica
    persistence/concurrency behavior.
  • engine/mvnw -q -f sdk/java/pom.xml verify: passed for the standalone
    Java worker SDK.
  • (cd tenda && npm run lint) and (cd tenda && npm run build): passed.
    ESLint reported nine
    existing React Fast Refresh warnings and no errors; Vite reported a large
    chunk warning.
  • (cd orun && npm run build): passed with a large chunk warning. Orun does
    not yet define lint or test scripts.
  • npm audit in both Tenda and Orun: passed with zero vulnerabilities.
  • The Java SDK uses Jackson 2.21.5, resolving the high- and medium-severity
    advisories GitHub identified during publication.
  • Production and release Compose configuration validation: passed. Production
    validation emitted expected warnings for unset local Keycloak/OAuth
    environment variables.
  • Production image build: passed for abada-engine:0.11.0-alpha on
    linux/arm64, image ID
    sha256:419060f06f42361c124569d1333705955d299cbe7e35c3d3cd5d4eee6f7a6448.
  • Executable JAR:
    engine/target/abada-engine-0.11.0-alpha.jar, SHA-256
    fd8b769027bff379c1316733c9e4864eec571932b921f0ab9212fe276bbe1444.

Non-blocking backend warnings were limited to the existing H2 dialect,
Open-EntityManager-in-View, optional Bean Validation provider, Mockito dynamic
agent attachment and Prometheus meter-tag warnings. These do not invalidate
the PostgreSQL-backed correctness evidence, but should be removed before the
1.0 RC where practical.

Known limitations

  • Boundary BPMN error events are not part of the supported BPMN subset.
  • Worker effects outside the engine remain at-least-once and must be made
    idempotent by workers.
  • The 1.0 RC still requires published conformance, rolling-upgrade, security
    review, benchmark and operational-runbook evidence.