Repository navigation
Abada 0.11.0-alpha
Pre-releaseAbada Engine 0.11.0-alpha Release Notes
Release date: 2026-07-19
Abada 0.11.0-alpha is the stable-contracts and security prerelease. It freezes
the /api/v1 REST surface and external-worker protocol v1, completes backend
RBAC, ships a Java worker client, and aligns Tenda and Orun with durable API
records.
Highlights
- Stable typed DTOs and machine-readable error codes across API failures.
- Executable generated-OpenAPI compatibility checking in CI.
- Bounded database pagination and filters for definitions, instances, tasks,
incidents and history. - Explicit deployment, process-control, task, operations and worker
permissions for OIDC and trusted-proxy modes. - Negative tests for invalid/expired JWTs, forged proxy headers, role
boundaries, CORS, logging and cross-user task access. - Worker protocol v1 with bounded fetch-and-lock, heartbeat, lock extension,
completion, BPMN error, technical failure/retry, idempotency and trace
propagation. - Standalone Java 21 worker SDK under
sdk/java. - Orun now consumes durable audit history and correctly maps incident IDs;
Tenda types match the frozen engine DTOs.
Database upgrade
Back up PostgreSQL, start one 0.11.0-alpha engine, and allow Flyway to apply
V9. V9 adds nullable BPMN-error and trace-context columns to external_tasks
plus an acquisition/ownership index. No existing row is deleted or rewritten.
Confirm schema version 9 before starting remaining replicas. Downgrade is not
supported; restore the backup to roll back.
Worker migration
Secured deployments now require completion bodies shaped as
{"workerId":"...","variables":{...}}. Raw variable-map completion remains
accepted only in disabled local/test mode. Use the Java worker client or update
existing workers before enabling 0.11 in production.
Boundary BPMN error events remain unsupported. A worker BPMN error is therefore
recorded as an unhandled business error and fails the process instance.
Verification evidence
The release candidate was verified on 2026-07-19 with Java 21, Node.js 24 and
Docker Desktop:
(cd engine && ./mvnw clean package): passed, 151 tests with no failures,
errors or skips. PostgreSQL 16 Testcontainers covered fresh Flyway V9 installation,
upgrades from schemas V1 through V8, restart recovery and multi-replica
persistence/concurrency behavior.engine/mvnw -q -f sdk/java/pom.xml verify: passed for the standalone
Java worker SDK.(cd tenda && npm run lint)and(cd tenda && npm run build): passed.
ESLint reported nine
existing React Fast Refresh warnings and no errors; Vite reported a large
chunk warning.(cd orun && npm run build): passed with a large chunk warning. Orun does
not yet define lint or test scripts.npm auditin both Tenda and Orun: passed with zero vulnerabilities.- The Java SDK uses Jackson 2.21.5, resolving the high- and medium-severity
advisories GitHub identified during publication. - Production and release Compose configuration validation: passed. Production
validation emitted expected warnings for unset local Keycloak/OAuth
environment variables. - Production image build: passed for
abada-engine:0.11.0-alphaon
linux/arm64, image ID
sha256:419060f06f42361c124569d1333705955d299cbe7e35c3d3cd5d4eee6f7a6448. - Executable JAR:
engine/target/abada-engine-0.11.0-alpha.jar, SHA-256
fd8b769027bff379c1316733c9e4864eec571932b921f0ab9212fe276bbe1444.
Non-blocking backend warnings were limited to the existing H2 dialect,
Open-EntityManager-in-View, optional Bean Validation provider, Mockito dynamic
agent attachment and Prometheus meter-tag warnings. These do not invalidate
the PostgreSQL-backed correctness evidence, but should be removed before the
1.0 RC where practical.
Known limitations
- Boundary BPMN error events are not part of the supported BPMN subset.
- Worker effects outside the engine remain at-least-once and must be made
idempotent by workers. - The 1.0 RC still requires published conformance, rolling-upgrade, security
review, benchmark and operational-runbook evidence.