Repository navigation
v2609.1
Changes since v2609.0.
Fixed
- Keep unaffected VIPs bound when a renewed consensus proof revokes a
different VIP. This avoids unnecessary failover and duplicate notify
events. Loss of consensus proof or local health, or absence of a known
leader, still withdraws every locally held VIP. - Keep an already activated VIP bound when its predecessor's release
acknowledgement arrives. An interrupted first ARP announcement remains
pending so reconciliation can complete the announcement andMASTER
notification. - Export all 35 documented real-cluster scenarios with their required
runners, helpers, sanitized configuration example and local
self-tests. Thev2609.0public export included only the D26 scenario
and omitted required harness files. Private configurations,
credentials and generated campaign evidence remain excluded. - Reject false passes in real-cluster tests caused by failed SSH
commands, unreadable evidence, stale process logs or incomplete
restoration. Check failure-delay lower bounds and snapshot/purge
progress explicitly. Restoration attempts all nodes and permits a
safe retry after partial completion without treating a missing backup
as proof of success. - Wait for complete five-node convergence in the Docker rebalance test
and use OS-assigned ports for single-node Raft fixtures to avoid port
races.
Release checks and regression coverage
- Check the documented scenario inventory and harness dependencies in
the exported tree and packaged source archive. Local harness
self-tests do not contact a live cluster. - Build the exact version-stamped vendored source archive offline and
run its harness checks before uploading it. Container publication
waits for source validation; GitHub also waits for both binary
architectures and DEB/RPM builds. Publication is not atomic across
registries and release APIs: a later upload failure can still leave
partial artifacts. - Exercise health-proof rejection through running daemons and real
notify hooks. The regression checksBACKUPon proof loss, recovery
toMASTERandFAULTon an actual local health-check failure, with
dry-run VIP operations. - Check health-probe termination without treating zombie process
entries as still-running descendants. The regressions still detect
a live descendant left behind after cancellation or a successful
probe; delayed reaping no longer causes a false failure.
Upgrade and configuration notes
- Upgrades from versions older than
v2609.0still require a
coordinated stop of all voters before replacing binaries. Plan an
interruption of VIP service; mixed-version tests do not establish
rolling compatibility for that upgrade. Follow the
coordinated upgrade procedure. - The campaign below does not establish rolling-upgrade compatibility
fromv2609.0to this release. Verify the exact version pair before
scheduling a rolling upgrade. - Changing cluster-wide settings, including the VIP list, requires a
coordinated procedure. The
operations guide
now distinguishes this from restarting one node with unchanged
configuration. - OpenRaft remains at
0.10.0-alpha.32; this update does not change the
dependency lockfile or the configuration format. Package metadata
uses2609.1.0for thev2609.1release tag.
Pre-release validation and limits
On 2026-09-29, the candidate completed all 35 documented scenarios on a
dedicated Ceph VM cluster: 35 passed, none failed or were skipped, and
none were retried. The final cleanup audit passed. This is evidence for
the tested candidate, not certification of later version-stamped
release artifacts or every deployment environment.
The archive-publication gates and additional health regression tests
described above were added after this campaign and checked separately.
The live campaign was not rerun for those changes.
- C2 checks two snapshot/purge cycles per node with sampled VIP
ownership; it is not a three-hour soak or continuous observation of
ownership. - D26 uses real daemon processes and the kernel network stack, but its
VIP operations are dry-run. Other scenarios include real kernel VIP
failover. - D15/D16 use a legacy fixture identified by hash and BuildID, not a
verified historical release tag. - D19 observed VIP withdrawal before fatal configuration fencing; this
does not by itself prove that shutdown cleanup caused the withdrawal. - Native ARM execution and final published-artifact checks are not
covered by this campaign.
Downloads
This release provides static Linux binaries for amd64 and arm64 and a
vendored source archive. The GitHub release also provides DEB/RPM
packages for both architectures, SHA256SUMS and build-provenance
attestations.
Container image:
docker pull ghcr.io/croit/keepafloatd:v2609.1Verify downloaded GitHub assets against the accompanying checksum file:
sha256sum --check SHA256SUMS --ignore-missing