Skip to content

Releases: dexadata/leoflow

v0.4.8

Choose a tag to compare

@github-actions github-actions released this 21 Sep 02:53
c45e901

Leoflow v0.4.8

A 0.x (pre-1.0) build — SemVer carries the maturity, there is no separate
alpha/beta, and the pre-alpha series ended at v0.0.1 (ADR 0037). APIs and
on-disk shape may still evolve between minor versions; -rc.N tags are release
candidates gated by the E2E suite. Install this exact release with:

curl -fsSL https://raw.githubusercontent.com/neochaotic/leoflow/v0.4.8/install.sh | LEOFLOW_VERSION=v0.4.8 sh

A bare curl … | sh installs the latest stable release (/releases/latest
excludes pre-releases), so on a pre-release page it would NOT give you v0.4.8.
LEOFLOW_VERSION must sit on the sh side of the pipe (not curl) — a
VAR=x curl … | sh prefix sets the var for curl only, so install.sh would
not see it and would fall back to latest-stable.


Added

  • The UI refresh interval is settable from the chart
    (ui.autoRefreshIntervalSeconds).
    It was reported that the Pro UI feels far
    slower to update than Lite, and it does: Pro polls every 30s and Lite every 1s,
    a thirty-fold difference. The setting to change it already existed and was
    documented, and the chart modelled nothing, so a Helm operator could reach it
    only through extraEnv, which hides the behavior from anyone reading the
    chart.

    The chart omits the variable entirely when unset rather than rendering an empty
    one, so the server's default stays in charge and nobody goes looking in the
    chart for a number the chart did not choose.

    This exposes the choice; it does not change the default. Copying Lite's 1s
    would multiply request and query load by thirty per open tab, and Lite can
    afford that only because it is one person against a local database. Choosing a
    better default needs the cost of one refresh cycle measured, which is tracked
    in #1196 along with the
    question of whether polling is the right mechanism at all.

  • A long-running resilience soak battery (test/soak/). The gates we had
    answer a different question: test/e2e/ proves a path works once, test/load/
    measures one cost at one instant, and chaos-runtime.sh injects a fault and
    checks the recovery. None told us whether a control plane that has been
    dispatching since Friday is still dispatching on Monday, or whether the cost of
    a tick had started tracking the size of the history table rather than the
    active set.

    make soak runs a realistic scheduled workload (six DAG projects spanning the
    python, bash and airflow_operator task types, with DuckDB generating the
    data volume) against a dedicated local Postgres and asserts ten invariants on
    every sample: wedge thresholds on queued/scheduled/running, scheduler
    health, run-creation cadence per DAG, leader churn, retry budget, archived-
    attempt state, and terminal-run consistency. (The archived-attempt check is
    cheap and holds, but it is not an at-most-once proof: see test/soak/README.md
    section 1 for exactly what it can and cannot catch.) Evidence is written
    continuously
    (samples.jsonl fsynced per record, summary.md and verdict.json rewritten
    atomically every sample), so a harness that is killed still leaves a current
    report.

    make soak-selftest proves the assertions can fail: it injects a real 300 s
    Postgres outage while declaring a 45 s window for it, and the run must exit
    exactly 1 with recorded violations (exit 2, a harness that never ran, is a
    failure of the self test, not a pass). Nothing is faked and no threshold is
    relaxed.

    Everything runs locally and costs nothing: no cloud, no cluster, no paid
    service, and no public HTTP endpoint anywhere in the workload (the operator leg
    points at a loopback fixture server, and CI enforces that). Bounded by a
    wall-clock ceiling, a disk budget with a clean stop, and a watchdog. Long runs
    are scheduled locally via test/soak/schedule/install.sh; CI runs only a
    6-minute harness smoke, for the cost reasons documented in
    test/soak/README.md.

  • auth.session_cookie_insecure (default false), the one escape hatch the
    fix above needs. Secure is now decided by the server rather than by the
    page's location.protocol, and a browser refuses a Secure cookie from a
    plain-http origin that is not loopback, so a deployment served over plain http
    to a real hostname would otherwise have been upgraded into a sign-in page that
    posts valid credentials, gets a 200, and lands back on itself. It cannot be
    derived from the request: behind a TLS-terminating ingress the server sees
    plain http while the browser sees https, so request-derived Secure would
    strip it from the deployment that most needs it. Operator-scoped, WARN at
    boot while it is on, and no Helm value on purpose.

  • auth.oidc.auto_redirect starts the flow instead of showing the sign-in
    page.
    Off by default. Where an edge proxy has already authenticated the
    session, or SSO is the only way in, that page was a screen to acknowledge for
    nothing; a comparable tool against the same identity provider lands the user
    inside with no visible login step.

    Signing out reaches the page, not the flow. logoutHandler redirected to
    the bare sign-in URL, which with auto-redirect on is itself a redirect to the
    identity provider. Our sign-out does not end the IdP session, so a user who
    signed out would be signed straight back in and the button would appear to do
    nothing, and the more reliable the SSO setup is, the more completely it fails.

    It is suppressed on a refused sign-on, and that guard is the feature. A
    denial answers a redirect back to the sign-in page, so redirecting it onward
    would bounce every refusal straight back to the identity provider: an infinite
    loop with no surface left to read the error on. It is also suppressed by
    ?local=1, so a break-glass account can reach the password form when the
    identity provider is the thing that is broken, without an operator editing
    values and rolling out to get back in.

Changed

  • Changelog entries are now one file per pull request. make changelog (a wrapper around changie) writes .changes/unreleased/<slug>.yaml, and the release cut folds every pending fragment into CHANGELOG.md under ## [Unreleased]. Before this, every open PR edited the same ## [Unreleased] lines in one file: merging any one of them made the rest dirty, each rebase cost a full CI cycle of around fifty-five checks, and resolving those conflicts by keeping both sides is how the section came to hold five headings for three kinds. Two fragments are two different files and cannot conflict. Editing CHANGELOG.md by hand still satisfies the guard. (#1200)

  • The documentation version menu says which release you are reading. The
    current release now appears as v0.4.7 (latest) rather than latest, and the
    unreleased leg as dev (main, unreleased). Before this, the current release
    was the ONE release whose number the menu never showed: an archived tag shows
    its number only after it has been superseded, so the number a reader most
    wants was the one missing. The project's own maintainer read the menu and
    concluded latest meant main.

    A new gate reconciles the menu the published site uses with the fallback a
    local hugo build uses. The two had already drifted: one listed a release the
    other did not, so a local build and the published site disagreed about which
    releases exist.

  • The session cookie is now Secure by default, decided by the server
    rather than by the page's location.protocol (see the fix below).

    Upgrading a deployment served over plain http on a name that is not
    localhost:
    set auth.session_cookie_insecure: true BEFORE you upgrade. A
    browser refuses a Secure cookie on such an origin, and it refuses the
    Secure deletion too. So with the default, a new login is silently discarded
    and sign-out stops signing anybody out: the pre-existing non-Secure
    cookie from the old build stays in the jar, stays a valid session, and cannot
    be cleared until its original lifetime runs out. Loopback is unaffected,
    because browsers treat it as potentially trustworthy, and so is anything
    behind TLS, which is every chart install.

Fixed

  • A GA release page carried none of the release. The body was generated
    from the commits since the previous tag, and a GA is cut from its own release
    candidate, so the only commit between the two is the promotion itself. The
    v0.4.7 page said one line, release: promote v0.4.7 GA, while CHANGELOG.md
    held 35 entries for that same version: everything written for a human to read
    stayed in a file, and the page most people reach from GitHub showed nothing.

    The body is now composed from the changelog section for the tag, so a release
    page says what the release did. A candidate falls back to [Unreleased],
    which is where its entries are. The commits are still one click away, as a
    compare link.

    The generated list was also keeping noise it meant to drop: the filters were
    anchored as ^docs:, ^test: and ^chore:, and every commit in this
    repository is scoped, as in docs(changelog):, so none of the three ever
    matched anything.

  • Building and deploying in separate steps could name the same image two
    different ways
    (#1227). A project that sets registry.tag_strategy: git_sha had its image pushed under the DAG version by leoflow compile --build --push, while leoflow deploy looked for it under the commit SHA,
    because the build never consulted the strategy and the deploy did.

    This only shows up when the two commands run separately, which is the normal
    CI/CD shape: build in one job, deploy in another with --skip-build. A single
    leoflow deploy, which does both, was never affected. With the default
    strategy the two rules happen to agree, so the fail...

Read more

v0.4.8-rc.1

v0.4.8-rc.1 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 21 Sep 01:41
b3fb4be

Leoflow v0.4.8-rc.1

A 0.x (pre-1.0) build — SemVer carries the maturity, there is no separate
alpha/beta, and the pre-alpha series ended at v0.0.1 (ADR 0037). APIs and
on-disk shape may still evolve between minor versions; -rc.N tags are release
candidates gated by the E2E suite. Install this exact release with:

curl -fsSL https://raw.githubusercontent.com/neochaotic/leoflow/v0.4.8-rc.1/install.sh | LEOFLOW_VERSION=v0.4.8-rc.1 sh

A bare curl … | sh installs the latest stable release (/releases/latest
excludes pre-releases), so on a pre-release page it would NOT give you v0.4.8-rc.1.
LEOFLOW_VERSION must sit on the sh side of the pipe (not curl) — a
VAR=x curl … | sh prefix sets the var for curl only, so install.sh would
not see it and would fall back to latest-stable.

Changelog


Artifacts are checksummed (SHA-256) and the checksums file is cosign-signed
(keyless). Verify with cosign verify-blob.

v0.4.7

Choose a tag to compare

@github-actions github-actions released this 19 Sep 14:54
7fa5018

Leoflow v0.4.7

A 0.x (pre-1.0) build — SemVer carries the maturity, there is no separate
alpha/beta, and the pre-alpha series ended at v0.0.1 (ADR 0037). APIs and
on-disk shape may still evolve between minor versions; -rc.N tags are release
candidates gated by the E2E suite. Install this exact release with:

curl -fsSL https://raw.githubusercontent.com/neochaotic/leoflow/v0.4.7/install.sh | LEOFLOW_VERSION=v0.4.7 sh

A bare curl … | sh installs the latest stable release (/releases/latest
excludes pre-releases), so on a pre-release page it would NOT give you v0.4.7.
LEOFLOW_VERSION must sit on the sh side of the pipe (not curl) — a
VAR=x curl … | sh prefix sets the var for curl only, so install.sh would
not see it and would fall back to latest-stable.

Changelog


Artifacts are checksummed (SHA-256) and the checksums file is cosign-signed
(keyless). Verify with cosign verify-blob.

v0.4.7-rc.2

v0.4.7-rc.2 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 18 Sep 17:11
c884c94

Leoflow v0.4.7-rc.2

A 0.x (pre-1.0) build — SemVer carries the maturity, there is no separate
alpha/beta, and the pre-alpha series ended at v0.0.1 (ADR 0037). APIs and
on-disk shape may still evolve between minor versions; -rc.N tags are release
candidates gated by the E2E suite. Install this exact release with:

curl -fsSL https://raw.githubusercontent.com/neochaotic/leoflow/v0.4.7-rc.2/install.sh | LEOFLOW_VERSION=v0.4.7-rc.2 sh

A bare curl … | sh installs the latest stable release (/releases/latest
excludes pre-releases), so on a pre-release page it would NOT give you v0.4.7-rc.2.
LEOFLOW_VERSION must sit on the sh side of the pipe (not curl) — a
VAR=x curl … | sh prefix sets the var for curl only, so install.sh would
not see it and would fall back to latest-stable.

Changelog


Artifacts are checksummed (SHA-256) and the checksums file is cosign-signed
(keyless). Verify with cosign verify-blob.

v0.4.7-rc.1

v0.4.7-rc.1 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 17 Sep 14:09
5f0200e

Leoflow v0.4.7-rc.1

A 0.x (pre-1.0) build — SemVer carries the maturity, there is no separate
alpha/beta, and the pre-alpha series ended at v0.0.1 (ADR 0037). APIs and
on-disk shape may still evolve between minor versions; -rc.N tags are release
candidates gated by the E2E suite. Install this exact release with:

curl -fsSL https://raw.githubusercontent.com/neochaotic/leoflow/v0.4.7-rc.1/install.sh | LEOFLOW_VERSION=v0.4.7-rc.1 sh

A bare curl … | sh installs the latest stable release (/releases/latest
excludes pre-releases), so on a pre-release page it would NOT give you v0.4.7-rc.1.
LEOFLOW_VERSION must sit on the sh side of the pipe (not curl) — a
VAR=x curl … | sh prefix sets the var for curl only, so install.sh would
not see it and would fall back to latest-stable.

Changelog


Artifacts are checksummed (SHA-256) and the checksums file is cosign-signed
(keyless). Verify with cosign verify-blob.

v0.4.6

Choose a tag to compare

@github-actions github-actions released this 11 Sep 02:56
68e6552

Leoflow v0.4.6

A 0.x (pre-1.0) build — SemVer carries the maturity, there is no separate
alpha/beta, and the pre-alpha series ended at v0.0.1 (ADR 0037). APIs and
on-disk shape may still evolve between minor versions; -rc.N tags are release
candidates gated by the E2E suite. Install this exact release with:

curl -fsSL https://raw.githubusercontent.com/neochaotic/leoflow/v0.4.6/install.sh | LEOFLOW_VERSION=v0.4.6 sh

A bare curl … | sh installs the latest stable release (/releases/latest
excludes pre-releases), so on a pre-release page it would NOT give you v0.4.6.
LEOFLOW_VERSION must sit on the sh side of the pipe (not curl) — a
VAR=x curl … | sh prefix sets the var for curl only, so install.sh would
not see it and would fall back to latest-stable.

Changelog


Artifacts are checksummed (SHA-256) and the checksums file is cosign-signed
(keyless). Verify with cosign verify-blob.

v0.4.6-rc.1

v0.4.6-rc.1 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 10 Sep 19:00
a2370f3

Leoflow v0.4.6-rc.1

A 0.x (pre-1.0) build — SemVer carries the maturity, there is no separate
alpha/beta, and the pre-alpha series ended at v0.0.1 (ADR 0037). APIs and
on-disk shape may still evolve between minor versions; -rc.N tags are release
candidates gated by the E2E suite. Install this exact release with:

curl -fsSL https://raw.githubusercontent.com/neochaotic/leoflow/v0.4.6-rc.1/install.sh | LEOFLOW_VERSION=v0.4.6-rc.1 sh

A bare curl … | sh installs the latest stable release (/releases/latest
excludes pre-releases), so on a pre-release page it would NOT give you v0.4.6-rc.1.
LEOFLOW_VERSION must sit on the sh side of the pipe (not curl) — a
VAR=x curl … | sh prefix sets the var for curl only, so install.sh would
not see it and would fall back to latest-stable.

Changelog


Artifacts are checksummed (SHA-256) and the checksums file is cosign-signed
(keyless). Verify with cosign verify-blob.

v0.4.5

Choose a tag to compare

@github-actions github-actions released this 09 Sep 19:39
d8a5042

Leoflow v0.4.5

A 0.x (pre-1.0) build — SemVer carries the maturity, there is no separate
alpha/beta, and the pre-alpha series ended at v0.0.1 (ADR 0037). APIs and
on-disk shape may still evolve between minor versions; -rc.N tags are release
candidates gated by the E2E suite. Install this exact release with:

curl -fsSL https://raw.githubusercontent.com/neochaotic/leoflow/v0.4.5/install.sh | LEOFLOW_VERSION=v0.4.5 sh

A bare curl … | sh installs the latest stable release (/releases/latest
excludes pre-releases), so on a pre-release page it would NOT give you v0.4.5.
LEOFLOW_VERSION must sit on the sh side of the pipe (not curl) — a
VAR=x curl … | sh prefix sets the var for curl only, so install.sh would
not see it and would fall back to latest-stable.

Changelog


Artifacts are checksummed (SHA-256) and the checksums file is cosign-signed
(keyless). Verify with cosign verify-blob.

v0.4.5-rc.3

v0.4.5-rc.3 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 09 Sep 17:38
5c3fd1c

Leoflow v0.4.5-rc.3

A 0.x (pre-1.0) build — SemVer carries the maturity, there is no separate
alpha/beta, and the pre-alpha series ended at v0.0.1 (ADR 0037). APIs and
on-disk shape may still evolve between minor versions; -rc.N tags are release
candidates gated by the E2E suite. Install this exact release with:

curl -fsSL https://raw.githubusercontent.com/neochaotic/leoflow/v0.4.5-rc.3/install.sh | LEOFLOW_VERSION=v0.4.5-rc.3 sh

A bare curl … | sh installs the latest stable release (/releases/latest
excludes pre-releases), so on a pre-release page it would NOT give you v0.4.5-rc.3.
LEOFLOW_VERSION must sit on the sh side of the pipe (not curl) — a
VAR=x curl … | sh prefix sets the var for curl only, so install.sh would
not see it and would fall back to latest-stable.

Changelog


Artifacts are checksummed (SHA-256) and the checksums file is cosign-signed
(keyless). Verify with cosign verify-blob.

v0.4.5-rc.2

v0.4.5-rc.2 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 08 Sep 16:52
2d3009c

Leoflow v0.4.5-rc.2

A 0.x (pre-1.0) build — SemVer carries the maturity, there is no separate
alpha/beta, and the pre-alpha series ended at v0.0.1 (ADR 0037). APIs and
on-disk shape may still evolve between minor versions; -rc.N tags are release
candidates gated by the E2E suite. Install this exact release with:

curl -fsSL https://raw.githubusercontent.com/neochaotic/leoflow/v0.4.5-rc.2/install.sh | LEOFLOW_VERSION=v0.4.5-rc.2 sh

A bare curl … | sh installs the latest stable release (/releases/latest
excludes pre-releases), so on a pre-release page it would NOT give you v0.4.5-rc.2.
LEOFLOW_VERSION must sit on the sh side of the pipe (not curl) — a
VAR=x curl … | sh prefix sets the var for curl only, so install.sh would
not see it and would fall back to latest-stable.

Changelog


Artifacts are checksummed (SHA-256) and the checksums file is cosign-signed
(keyless). Verify with cosign verify-blob.