v0.1.9 — Google Sheets & frictionless onboarding
v0.1.9 — Google Sheets & frictionless onboarding
Released: 2026-06-10
Headline: a first-class Google Sheets source, plus tycoon managing a
project-local .venv so Python setup stops blocking new users — and,
folded in alongside, the live multi-client warehouse (Quack), pipeline
notifications, and scheduled runs. The full cycle plan and the
onboarding-.venv design are in
docs/proposals/v0.1.9-scope.md.
Landed
- Scheduled runs (#48) —
tycoon schedule add/list/remove/statuswraps
the platform-native scheduler (macOS launchd, Linuxsystemd --user) so a
tycoon data run-all --notifycan fire every morning with no cron-wrangling
and no daemon. Logs to~/.local/share/tycoon/schedule/<name>/run.log;
Windows points at Task Scheduler. Docs:
tycoon schedule. - Pipeline notifications (#46) —
tycoon notify <severity> <message>and
tycoon data run-all --notifypost to a Slack or generic webhook
($TYCOON_NOTIFY_WEBHOOK_URL) so unattended runs don't fail silently.
Best-effort; non-secret prefs in an optionalnotify:block. Docs:
tycoon notify. - DuckDB Quack — live multi-client warehouse (#42) — folded into
tycoon startwith no new commands. When the Quack extension is available
(core_nightly),tycoon startserves the warehouse over Quack's local RPC
protocol on:9494;tycoon data querythen attaches to the live
warehouse instead of fighting the single-writer file lock. Token persisted
once in.tycoon/secrets.yml; skipped silently where the extension can't
load. Deferred follow-up: auto-coordinating standalone dbt writes. Docs:
tycoon start. tycoon setup+tycoon doctor --fix(#57) — the managed-.venv
payoff.tycoon setupbuilds a project-local.venvbesidetycoon.yml
on a supported interpreter viauv venv --python(uv auto-downloads the
CPython if needed), pins it with.python-version, and installs tycoon's
stack into it.doctor --fixruns the same flow when the interpreter check
fails. With the interpreter check (also #57), this closes the Python-version
trap behind #55. Docs:tycoon setup.- Google Sheets source (#52) — the headline.
tycoon data sources add google_sheetsregisters a spreadsheet as a first-class source: tabs/ranges
land in DuckDB with the header row as typed columns. Auth is a Google
service-account JSON key (cron-friendly), defaulting to
${GOOGLE_APPLICATION_CREDENTIALS}; a blank key falls back to dlt's own
resolution (OAuth / ADC). Config isspreadsheet_url_or_idplus an optional
range_nameslist (blank = all sheets). Non-interactive via--no-prompt.
The dltgoogle_sheetsverified source isn't bundled — pulled on demand via
dlt init. First cut is full-refresh replace per run. Recipe in the
sources guide. tycoon doctorPython-interpreter check (#57) — the first sub-piece
of the managed-.venvwork. doctor now verifies the running interpreter
is in>=3.12,<3.14as its first check and fails with an actionable hint
(e.g.uv venv --python 3.13) otherwise. Closes the blind spot that hid
#55: tycoon runs dbt out of its own interpreter, so a too-new Python (3.14,
no dbt wheels) used to surface only atdata transform run.
Security
A security review of the codebase produced nine findings (all filed as
issues, labelled security). The two High-severity ones are fixed in this
release; the rest are scoped for v0.1.10.
- Fivetran credential leak (#60) —
api_key/api_secretare now
SecretStr(masked in anyrepr/traceback) with field docs that recommend
${FIVETRAN_API_SECRET}env-var indirection. Critically,save_project
now preserves the hand-authoredingestion_metadatablock verbatim: before
this, asources add/registerwrite round-tripped the expanded secret
straight back intotycoon.yml. The scaffolded.gitignorenow also covers
.env,.dlt/secrets.toml, and**/profiles.yml.tycoon.ymlitself
stays committable — it's the shareable stack template and is meant to carry
${ENV}references, not literal secrets. - SQL identifier injection (#61) — schema/table/column names from
tycoon.ymlor introspected from an untrusted DuckDB file are now quoted
via a sharedquote_identifierhelper before they reach SQL. The Rill
Parquet export (data analyze --rill) anddata schemarow counts were the
affected paths; because DuckDBCOPY … TO/INSTALLcan write files and
load extensions, a craftedschema:in a shared project was a path to
arbitrary file write. Defence-in-depth identifier/path validation at the
config layer is tracked for v0.1.10 (#65).
Deferred
- Layer-granular backup (#31) — deferred. The issue is framed as making an
existingbackup.skip_rawmechanism layer-aware, but no cloud-bucket backup
track ever shipped (it depended on the DuckLake path, which is itself
deferred — see the Rill/DuckLake notes). There's nothing yet to make
layer-aware. Revisit once a backup mechanism lands.
Carried follow-ups for #57 (core landed): uvx database-tycoon init
bootstrap that builds the .venv during scaffold, and collapsing the
3-way install menu in the onboarding docs into the one recommended path.
This file fills in as work lands; keep it in sync with CHANGELOG.md.