Repository navigation
v0.63.0
·
324 commits
to main
since this release
Immutable
release. Only release title and notes can be modified.
0.63.0 - 2026-09-20
Highlights
- Tenki works with the current CLI and rotating gateway certificates. Sandbox creation uses supported lifetime flags, and SSH verifies the gateway's certificate authority instead of pinning individual gateway keys.
- More reliable macOS VM startup. Prepared Parallels macOS images can bootstrap without guest Tools, and Apple VM builds cloud-init seed disks without mounting them on the host.
- Boat works after the ASCII Box rename. Updated CLI discovery, response parsing, SSH keys, and cleanup preserve existing Crabbox lease identities.
- Safer cancellation and cleanup recovery. Canceled operations stop waiting for lease locks, while failed deletion or local SSH cleanup retains the state needed for a safe retry.
Upgrade notes
- Tenki host-authority discovery requires a workspace API key from
tenki onboardorTENKI_API_KEYwhen the CLI does not report an authoritative trust file. Kept leases use sticky mode with no maximum duration;warmupdefaults to keeping the lease. Use--keep=false --ttl 15mfor a bounded test, and explicitly stop the lease afterward: Tenki's maximum duration pauses the sandbox rather than destroying it, and idle-timeout metadata does not enforce native expiry. PR 2341.
Fixes
- Verify Tenki gateway certificates using authoritative CLI trust or authenticated CA and session-scoped gateway discovery. Reject missing or invalid trust without enrolling leaf keys, preserve native Tenki credentials, and restore sandbox creation with supported, mutually exclusive sticky and maximum-duration flags. PR 2341. Thanks @francoluxor.
- Support the ASCII Box to Boat rename across CLI discovery, mixed response envelopes, SSH key selection, deletion operations, and secret redaction while preserving existing provider and lease identities. PR 2303. Thanks @zozo123.
- Let prepared Parallels macOS clones bootstrap through an explicitly trusted host-side SSH key when Tools cannot report or prepare the guest. Match the exact clone's DHCP identity, preserve its SSH port, reuse configured Screen Sharing only on an exactly owned clone, and wait for authenticated RFB readiness before typing. PR 1745, PR 2362. Thanks @saariuslystoned.
- Build Apple VM cloud-init seed disks directly with the shared FAT16 writer, removing the host MS-DOS mount requirement while preserving Firecracker and XCP-ng image formats. PR 2343. Thanks @steipete.
- Honor cancellation while terminal cleanup waits for exact lease-claim locks across GCP, Lume, Tart, Coder, Modal, Namespace, and related adapters. Release operation or capacity locks promptly, preserve state before deletion, and retain independent acquisition rollback and durable finalization after confirmed deletion. Apply the same cancellation boundary to explicit forget-missing cleanup in OpenSandbox, Vercel Sandbox, Crownest, and SuperServe. PR 2361, PR 2363, PR 2364, PR 2365. Thanks @steipete.
- Remove generated GCP and Linode SSH credentials and host-trust files before retiring successfully deleted or absent leases. Keep the exact recovery claim if local cleanup fails. Complete local SSH cleanup after successful failed-acquisition rollback for GCP, Azure, and Linode; retain credentials when remote cleanup fails, report local cleanup errors, and stop fresh allocation retries when recovery is incomplete. Linode terminal cleanup also honors cancellation while waiting for the claim lock. PR 2357, PR 2358, PR 2359. Thanks @steipete.
- Bound GCP public-IP discovery to two minutes, including in-flight observations and caller cancellation. Give failed-acquisition rollback up to three minutes to confirm remote deletion, including after caller cancellation, so slower deletion operations can finish cleanup. PR 2357, PR 2359. Thanks @steipete.
- Preserve generated Tart SSH credentials when failed-acquisition rollback cannot confirm ownership, delete the VM, or retire its claim, and report local artifact-cleanup errors alongside the original failure. PR 2360. Thanks @steipete.
- Preserve Lume's last successfully published claim when acquisition metadata updates fail, retaining the exact recovery state instead of falling back to unguarded rollback. PR 2366. Thanks @steipete.
Maintenance
- Consolidate Pond process and artifact preparation, retained sandbox activity updates, and remote sandbox ownership metadata checks while preserving provider-specific policy and existing behavior. PR 2356, PR 2367, PR 2368. Thanks @steipete.
- Share GCP and Hetzner implicit machine candidate selection in the coordinator while preserving explicit overrides, stored types, profile applicability, and stable ordering. PR 2369. Thanks @steipete.
- Keep Windows staged-launcher test helpers alive until final observation and confirm bounded teardown, removing timing-dependent failures without changing production transport behavior. PR 2354, Issue 2226. Thanks @steipete.