v0.4-beta
Pre-release
Pre-release
v0.4-beta
This release refocuses the project on productionizing the backend — the
stale frontend was removed, and the bulk of the work since v0.3-beta is about
making a node secure, operable, and reliable to run in a cluster.
Project direction
- Removed the frontend. It was significantly out of date; effort is now on
the backend (consensus log, sync/ingest, operations).
Security
- Peer mTLS (
COMMITTED_TLS_*) and client-facing API TLS
(COMMITTED_HTTP_TLS_*). - HTTP security headers on API responses.
- Hardening pass for
gosecfindings.
Operability & deployment
- Env-var node configuration —
COMMITTED_NODE_ID,COMMITTED_API_ADDR,
COMMITTED_DATA_DIR,COMMITTED_PEER_URL,COMMITTED_PEERS— so the same
image can be templated per-node by an orchestrator (Docker/Nomad/k8s). - Multi-node bootstrap —
COMMITTED_PEERS="1=http://n1:9022,..."forms a
static Raft group on first boot; membership is then restored from the WAL on
restart. (Replaces the never-wired--id/--clusterflags.) - Graceful shutdown — bounded HTTP drain + clean WAL/raft close on
SIGINT/SIGTERM, tunable viaCOMMITTED_SHUTDOWN_TIMEOUT. - Server limits — HTTP read/write/idle timeouts and a Raft proposal
body-size cap, all env-configurable. committed --version/ build-time version stamping (version, commit,
build date).
Ingest reliability
- Ingest-worker supervisor with backoff/restart.
- Durable ingestable position (
saveIngestablePosition) so ingest resumes
where it left off. - Per-commit standby ack.
- Adversarial + e2e test coverage for ingestables, including error handling.
Build, CI & housekeeping
- Multi-arch release binaries — native darwin/linux for both arm64 and
amd64, plus windows/amd64. (windows/arm64 is not built due to an upstream
dependency limitation; Windows-on-ARM runs the amd64 binary under x64
emulation.) - CI migrated from Codeship to GitHub Actions; added a build badge.
- Fixed a race condition; substantial linting cleanup.
- Dependency bumps:
go-chi/chi→ v5.2.2,filippo.io/edwards25519→ v1.1.1.