Skip to content

v0.1.9 — Google Sheets & frictionless onboarding

Choose a tag to compare

@db-tycoon-stephen db-tycoon-stephen released this 12 Jun 10:19
· 145 commits to main since this release
4f4afdd

v0.1.9 — Google Sheets & frictionless onboarding

Released: 2026-06-10

Headline: a first-class Google Sheets source, plus tycoon managing a
project-local .venv so Python setup stops blocking new users — and,
folded in alongside, the live multi-client warehouse (Quack), pipeline
notifications, and scheduled runs. The full cycle plan and the
onboarding-.venv design are in
docs/proposals/v0.1.9-scope.md.

Landed

  • Scheduled runs (#48) — tycoon schedule add/list/remove/status wraps
    the platform-native scheduler (macOS launchd, Linux systemd --user) so a
    tycoon data run-all --notify can fire every morning with no cron-wrangling
    and no daemon. Logs to ~/.local/share/tycoon/schedule/<name>/run.log;
    Windows points at Task Scheduler. Docs:
    tycoon schedule.
  • Pipeline notifications (#46) — tycoon notify <severity> <message> and
    tycoon data run-all --notify post to a Slack or generic webhook
    ($TYCOON_NOTIFY_WEBHOOK_URL) so unattended runs don't fail silently.
    Best-effort; non-secret prefs in an optional notify: block. Docs:
    tycoon notify.
  • DuckDB Quack — live multi-client warehouse (#42) — folded into
    tycoon start with no new commands. When the Quack extension is available
    (core_nightly), tycoon start serves the warehouse over Quack's local RPC
    protocol on :9494; tycoon data query then attaches to the live
    warehouse instead of fighting the single-writer file lock. Token persisted
    once in .tycoon/secrets.yml; skipped silently where the extension can't
    load. Deferred follow-up: auto-coordinating standalone dbt writes. Docs:
    tycoon start.
  • tycoon setup + tycoon doctor --fix (#57) — the managed-.venv
    payoff. tycoon setup builds a project-local .venv beside tycoon.yml
    on a supported interpreter via uv venv --python (uv auto-downloads the
    CPython if needed), pins it with .python-version, and installs tycoon's
    stack into it. doctor --fix runs the same flow when the interpreter check
    fails. With the interpreter check (also #57), this closes the Python-version
    trap behind #55. Docs: tycoon setup.
  • Google Sheets source (#52) — the headline. tycoon data sources add google_sheets registers a spreadsheet as a first-class source: tabs/ranges
    land in DuckDB with the header row as typed columns. Auth is a Google
    service-account JSON key (cron-friendly), defaulting to
    ${GOOGLE_APPLICATION_CREDENTIALS}; a blank key falls back to dlt's own
    resolution (OAuth / ADC). Config is spreadsheet_url_or_id plus an optional
    range_names list (blank = all sheets). Non-interactive via --no-prompt.
    The dlt google_sheets verified source isn't bundled — pulled on demand via
    dlt init. First cut is full-refresh replace per run. Recipe in the
    sources guide.
  • tycoon doctor Python-interpreter check (#57) — the first sub-piece
    of the managed-.venv work. doctor now verifies the running interpreter
    is in >=3.12,<3.14 as its first check and fails with an actionable hint
    (e.g. uv venv --python 3.13) otherwise. Closes the blind spot that hid
    #55: tycoon runs dbt out of its own interpreter, so a too-new Python (3.14,
    no dbt wheels) used to surface only at data transform run.

Security

A security review of the codebase produced nine findings (all filed as
issues, labelled security). The two High-severity ones are fixed in this
release; the rest are scoped for v0.1.10.

  • Fivetran credential leak (#60) — api_key/api_secret are now
    SecretStr (masked in any repr/traceback) with field docs that recommend
    ${FIVETRAN_API_SECRET} env-var indirection. Critically, save_project
    now preserves the hand-authored ingestion_metadata block verbatim: before
    this, a sources add/register write round-tripped the expanded secret
    straight back into tycoon.yml. The scaffolded .gitignore now also covers
    .env, .dlt/secrets.toml, and **/profiles.yml. tycoon.yml itself
    stays committable — it's the shareable stack template and is meant to carry
    ${ENV} references, not literal secrets.
  • SQL identifier injection (#61) — schema/table/column names from
    tycoon.yml or introspected from an untrusted DuckDB file are now quoted
    via a shared quote_identifier helper before they reach SQL. The Rill
    Parquet export (data analyze --rill) and data schema row counts were the
    affected paths; because DuckDB COPY … TO/INSTALL can write files and
    load extensions, a crafted schema: in a shared project was a path to
    arbitrary file write. Defence-in-depth identifier/path validation at the
    config layer is tracked for v0.1.10 (#65).

Deferred

  • Layer-granular backup (#31) — deferred. The issue is framed as making an
    existing backup.skip_raw mechanism layer-aware, but no cloud-bucket backup
    track ever shipped (it depended on the DuckLake path, which is itself
    deferred — see the Rill/DuckLake notes). There's nothing yet to make
    layer-aware. Revisit once a backup mechanism lands.

Carried follow-ups for #57 (core landed): uvx database-tycoon init
bootstrap that builds the .venv during scaffold, and collapsing the
3-way install menu in the onboarding docs into the one recommended path.

This file fills in as work lands; keep it in sync with CHANGELOG.md.