Fifty-eight commits since v1.0.0. No breaking change: the documented docker run command is unchanged.
Tools answer before you type
Every tool page now carries a worked answer for its first example in the static HTML. AI assistants and crawlers do not run JavaScript, so until now they saw an empty panel and a "type something here" prompt on all 39 tools. 37 of 39 now server-render a real result.
The two exceptions are deliberate. The certificate decoder needs asynchronous WebCrypto and prints expiry text that goes stale daily; the jq playground's answer needs its WebAssembly binary at build time. The UUID generator is seeded but only with the all-zero Nil UUID and a fixed inspector example — baking a minted UUID into a page would serve every visitor the same "freshly generated" value.
Two more full-length practice exams
- DOP-C02 Practice Set 3 — 75 questions, 180 minutes
- AIF-C01 Mock Exam 2 — 65 questions, 90 minutes
Both are real exam length and follow the domain weightings AWS publishes. All 140 questions are original and share no scenario with the 95 already on the site, which is enforced by a similarity check in the test suite.
Every answer key was re-derived independently from a copy with the keys and explanations removed, so agreement is evidence rather than an echo. That pass caught three services that had closed to new customers mid-2026 — Amazon Kendra, Bedrock Agents (now Agents Classic) and SageMaker A2I — and changed one answer key outright.
The existing AIF mock was also rebalanced: option B had been correct in 40 of its 54 single-answer questions, so always picking B beat studying.
Also in this release
- A design pass: three elevation tiers, dark-stable instrument panels for tool results, figure captions, and an amber tick on values that changed.
- Tool FAQs moved into one registry so
/llms-full.txtcan carry them. - Four new comparison articles and a 14-day AIF-C01 study plan that now uses both mocks.
Self-hosting fixes
Two things were wrong in v1.0.0 and are fixed here:
- The hardened run crash-looped. A tmpfs mounts root-owned and masks the image's ownership, so nginx (uid 101) could not create its scratch directories.
docker runneeds--tmpfs /var/cache/nginx:uid=101,gid=101, and Compose cannot express uid/gid, sodocker-compose.ymlnow uses long-form volumes. .dockerignoreexcludes.git, so every image build produced the same service-worker cache name and served stale pages after an upgrade. The Dockerfile now takes aBUILD_IDbuild argument, which CI supplies.
docker run -d --name opscanopy -p 8080:8080 \
--read-only \
--tmpfs /var/cache/nginx:uid=101,gid=101 \
--tmpfs /var/run:uid=101,gid=101 \
--security-opt no-new-privileges:true \
ghcr.io/opscanopy/opscanopy.com:1.1.0Verified by pulling anonymously and running with exactly that command: healthy, no restarts, and /sw.js carries this release's build id.