Skip to content

v2609.1

Choose a tag to compare

@github-actions github-actions released this 30 Sep 06:51

Changes since v2609.0.

Fixed

  • Keep unaffected VIPs bound when a renewed consensus proof revokes a
    different VIP. This avoids unnecessary failover and duplicate notify
    events. Loss of consensus proof or local health, or absence of a known
    leader, still withdraws every locally held VIP.
  • Keep an already activated VIP bound when its predecessor's release
    acknowledgement arrives. An interrupted first ARP announcement remains
    pending so reconciliation can complete the announcement and MASTER
    notification.
  • Export all 35 documented real-cluster scenarios with their required
    runners, helpers, sanitized configuration example and local
    self-tests. The v2609.0 public export included only the D26 scenario
    and omitted required harness files. Private configurations,
    credentials and generated campaign evidence remain excluded.
  • Reject false passes in real-cluster tests caused by failed SSH
    commands, unreadable evidence, stale process logs or incomplete
    restoration. Check failure-delay lower bounds and snapshot/purge
    progress explicitly. Restoration attempts all nodes and permits a
    safe retry after partial completion without treating a missing backup
    as proof of success.
  • Wait for complete five-node convergence in the Docker rebalance test
    and use OS-assigned ports for single-node Raft fixtures to avoid port
    races.

Release checks and regression coverage

  • Check the documented scenario inventory and harness dependencies in
    the exported tree and packaged source archive. Local harness
    self-tests do not contact a live cluster.
  • Build the exact version-stamped vendored source archive offline and
    run its harness checks before uploading it. Container publication
    waits for source validation; GitHub also waits for both binary
    architectures and DEB/RPM builds. Publication is not atomic across
    registries and release APIs: a later upload failure can still leave
    partial artifacts.
  • Exercise health-proof rejection through running daemons and real
    notify hooks. The regression checks BACKUP on proof loss, recovery
    to MASTER and FAULT on an actual local health-check failure, with
    dry-run VIP operations.
  • Check health-probe termination without treating zombie process
    entries as still-running descendants. The regressions still detect
    a live descendant left behind after cancellation or a successful
    probe; delayed reaping no longer causes a false failure.

Upgrade and configuration notes

  • Upgrades from versions older than v2609.0 still require a
    coordinated stop of all voters before replacing binaries. Plan an
    interruption of VIP service; mixed-version tests do not establish
    rolling compatibility for that upgrade. Follow the
    coordinated upgrade procedure.
  • The campaign below does not establish rolling-upgrade compatibility
    from v2609.0 to this release. Verify the exact version pair before
    scheduling a rolling upgrade.
  • Changing cluster-wide settings, including the VIP list, requires a
    coordinated procedure. The
    operations guide
    now distinguishes this from restarting one node with unchanged
    configuration.
  • OpenRaft remains at 0.10.0-alpha.32; this update does not change the
    dependency lockfile or the configuration format. Package metadata
    uses 2609.1.0 for the v2609.1 release tag.

Pre-release validation and limits

On 2026-09-29, the candidate completed all 35 documented scenarios on a
dedicated Ceph VM cluster: 35 passed, none failed or were skipped, and
none were retried. The final cleanup audit passed. This is evidence for
the tested candidate, not certification of later version-stamped
release artifacts or every deployment environment.

The archive-publication gates and additional health regression tests
described above were added after this campaign and checked separately.
The live campaign was not rerun for those changes.

  • C2 checks two snapshot/purge cycles per node with sampled VIP
    ownership; it is not a three-hour soak or continuous observation of
    ownership.
  • D26 uses real daemon processes and the kernel network stack, but its
    VIP operations are dry-run. Other scenarios include real kernel VIP
    failover.
  • D15/D16 use a legacy fixture identified by hash and BuildID, not a
    verified historical release tag.
  • D19 observed VIP withdrawal before fatal configuration fencing; this
    does not by itself prove that shutdown cleanup caused the withdrawal.
  • Native ARM execution and final published-artifact checks are not
    covered by this campaign.

Downloads

This release provides static Linux binaries for amd64 and arm64 and a
vendored source archive. The GitHub release also provides DEB/RPM
packages for both architectures, SHA256SUMS and build-provenance
attestations.

Container image:

docker pull ghcr.io/croit/keepafloatd:v2609.1

Verify downloaded GitHub assets against the accompanying checksum file:

sha256sum --check SHA256SUMS --ignore-missing