Releases: croit/keepAfloatD
Release list
v2609.1
Changes since v2609.0.
Fixed
- Keep unaffected VIPs bound when a renewed consensus proof revokes a
different VIP. This avoids unnecessary failover and duplicate notify
events. Loss of consensus proof or local health, or absence of a known
leader, still withdraws every locally held VIP. - Keep an already activated VIP bound when its predecessor's release
acknowledgement arrives. An interrupted first ARP announcement remains
pending so reconciliation can complete the announcement andMASTER
notification. - Export all 35 documented real-cluster scenarios with their required
runners, helpers, sanitized configuration example and local
self-tests. Thev2609.0public export included only the D26 scenario
and omitted required harness files. Private configurations,
credentials and generated campaign evidence remain excluded. - Reject false passes in real-cluster tests caused by failed SSH
commands, unreadable evidence, stale process logs or incomplete
restoration. Check failure-delay lower bounds and snapshot/purge
progress explicitly. Restoration attempts all nodes and permits a
safe retry after partial completion without treating a missing backup
as proof of success. - Wait for complete five-node convergence in the Docker rebalance test
and use OS-assigned ports for single-node Raft fixtures to avoid port
races.
Release checks and regression coverage
- Check the documented scenario inventory and harness dependencies in
the exported tree and packaged source archive. Local harness
self-tests do not contact a live cluster. - Build the exact version-stamped vendored source archive offline and
run its harness checks before uploading it. Container publication
waits for source validation; GitHub also waits for both binary
architectures and DEB/RPM builds. Publication is not atomic across
registries and release APIs: a later upload failure can still leave
partial artifacts. - Exercise health-proof rejection through running daemons and real
notify hooks. The regression checksBACKUPon proof loss, recovery
toMASTERandFAULTon an actual local health-check failure, with
dry-run VIP operations. - Check health-probe termination without treating zombie process
entries as still-running descendants. The regressions still detect
a live descendant left behind after cancellation or a successful
probe; delayed reaping no longer causes a false failure.
Upgrade and configuration notes
- Upgrades from versions older than
v2609.0still require a
coordinated stop of all voters before replacing binaries. Plan an
interruption of VIP service; mixed-version tests do not establish
rolling compatibility for that upgrade. Follow the
coordinated upgrade procedure. - The campaign below does not establish rolling-upgrade compatibility
fromv2609.0to this release. Verify the exact version pair before
scheduling a rolling upgrade. - Changing cluster-wide settings, including the VIP list, requires a
coordinated procedure. The
operations guide
now distinguishes this from restarting one node with unchanged
configuration. - OpenRaft remains at
0.10.0-alpha.32; this update does not change the
dependency lockfile or the configuration format. Package metadata
uses2609.1.0for thev2609.1release tag.
Pre-release validation and limits
On 2026-09-29, the candidate completed all 35 documented scenarios on a
dedicated Ceph VM cluster: 35 passed, none failed or were skipped, and
none were retried. The final cleanup audit passed. This is evidence for
the tested candidate, not certification of later version-stamped
release artifacts or every deployment environment.
The archive-publication gates and additional health regression tests
described above were added after this campaign and checked separately.
The live campaign was not rerun for those changes.
- C2 checks two snapshot/purge cycles per node with sampled VIP
ownership; it is not a three-hour soak or continuous observation of
ownership. - D26 uses real daemon processes and the kernel network stack, but its
VIP operations are dry-run. Other scenarios include real kernel VIP
failover. - D15/D16 use a legacy fixture identified by hash and BuildID, not a
verified historical release tag. - D19 observed VIP withdrawal before fatal configuration fencing; this
does not by itself prove that shutdown cleanup caused the withdrawal. - Native ARM execution and final published-artifact checks are not
covered by this campaign.
Downloads
This release provides static Linux binaries for amd64 and arm64 and a
vendored source archive. The GitHub release also provides DEB/RPM
packages for both architectures, SHA256SUMS and build-provenance
attestations.
Container image:
docker pull ghcr.io/croit/keepafloatd:v2609.1Verify downloaded GitHub assets against the accompanying checksum file:
sha256sum --check SHA256SUMS --ignore-missingv2609.0
Important: coordinated upgrade required
This release changes how VIP ownership is retained across an ownerless
gap. Do not perform a rolling upgrade from older versions. Mixed
versions are unsupported, even if the cluster retains quorum. Plan a
maintenance window with an interruption of VIP service.
- Stop every old daemon and prevent its supervisor from restarting it.
- Verify that all old daemons have stopped and their IPv4 and IPv6 VIPs
are absent from every node. - Install the same new version on every voter and check that
cluster-wide settings agree before starting any voter. - Start the upgraded cluster, then verify health and single-owner VIP
placement before ending the maintenance window.
See the upgrade procedure.
Changes
- Preserve VIP-holder history across ownerless gaps and require current,
applied consensus proof before takeover. - Release VIPs before a SIGHUP-triggered supervised restart.
- Harden health timing, child-process cleanup, connection admission,
transport shutdown and configuration-identity checks. - Reject the shipped secret placeholder and install packaged
configuration files root-owned with mode 0600. - Fix IPv6 VIP source-address selection and strengthen crash cleanup.
- Verify public source completeness and ship reproducible build inputs
in the vendored source archive.
The default configuration is an example, not a production-ready setup.
Configure node addresses, VIPs and a unique cluster secret before use.
Downloads
Static Linux binaries, Debian packages and RPM packages are provided for
amd64 and arm64, together with a vendored source archive and SHA256SUMS.
Package and binary versions use 2609.0.0; the release tag is v2609.0.
Verify the files you downloaded:
sha256sum --check SHA256SUMS --ignore-missingRuntime container, supporting linux/amd64 and linux/arm64:
docker pull ghcr.io/croit/keepafloatd:v2609.0v2606.2
- Initial public release of keepAfloatD (7a1d11d)
Container Images
Runtime:
docker pull ghcr.io/croit/keepafloatd:v2606.2
Dev:
docker pull ghcr.io/croit/keepafloatd/dev:v2606.2
Verify downloads
sha256sum --check SHA256SUMS --ignore-missing