Repository navigation
Releases: presmihaylov/shard
Releases · presmihaylov/shard
Release list
shard v0.1.4
Built by the release workflow from a06155a.
Changes since v0.1.3
New
- CLI:
shard shell SANDBOXopens an interactive shell in a sandbox:bash, orshwhen the image has nobash. It takes--workdirand--user, and exits with the shell's exit code. When the image has no shell at all, it says so. #590 - CLI:
shard stop,shard remove,shard pauseandshard resumetake several sandboxes. A failure does not stop the others: the command prints each failure and exits non-zero. #598 - CLI:
shard list -q(--quiet) prints only the ids. It does not go with--format. #598 - CLI:
shard pruneremoves every stopped sandbox, and asks first. With no terminal, it needs--force. #598 - Setup:
shard setupcan set up the HTTP API (shard serve) as a background service. A first install asks, and a new "Set up the HTTP API" row adds it to an existing install. The flags are--http-api,--listen(default127.0.0.1:7850) and--replace-api-key. Setup creates an API key and saves it in/etc/shard/api-key, which only root can read, or in/var/lib/shard/auth/api-keyon a Mac. It never prints the key. A repeated setup keeps the key, and--replace-api-keyreplaces it. With no terminal,--http-apidefaults tofalse. #603 - Setup:
shard setup --storage-size <size>andshard daemon --storage-size <size>set how much space shard reserves for its data. They apply only to Firecracker on a filesystem that cannot clone files, such as ext4. Elsewhere the flag fails and says why. The default is half of the free space, at most 100 GiB. The minimum is 10 GiB, and 10 GiB always stays free for the host. Setup shows the size of an existing image and never resizes it. With no terminal and no flag, setup takes the default and prints it. #587 - Firecracker and vz: a sandbox created with no
--memory, or with--memory 0, gets 512 MiB. Before, the create failed. A fork keeps the memory of its source, and a create from a snapshot keeps the memory of the snapshot. Under 128 MiB still fails, with--memory is 100 MiB, under the 128 MiB provider firecracker needs; set it to 128 MiB or more. #600 - CLI:
shard inspectshowsforked_from, the id of the sandbox that a fork came from. #607 - API: the sandbox record has a new
forked_fromfield: the id of the sandbox a fork came from. #607 - SDKs: useshards 0.1.2 names the sandbox a fork came from, as
forkedFromin TypeScript andforked_fromin Python. #607
Fixes
- Setup (Linux): when the daemon fails at start, setup and repair stop after about 6 seconds, not 2 minutes. They print
The daemon failed to start:with the daemon's error, thenRead its log with: sudo journalctl -u shard.service. #586 - Setup: when a daemon task keeps failing (3 or more restarts), setup stops its wait after about 3 seconds. It prints
The daemon started, but these tasks keep failing:, then each task with its last error. #602 - Setup: when the GitHub API rate limit for your IP address is spent, setup says so and gives the local time when it resets, or says to try again within an hour. The installer prints the reset time too. Setup now downloads its files from the release download URLs, which have no rate limit, so only the check for a newer release uses the API. #605
- Setup:
shard setupon an installation that setup did not make still changes nothing, and now exits 1, so a script can tell that refusal from a successful setup. Before, it exited 0. #611 - Uninstall: uninstall removes the
shard-serveunit that setup wrote. Ashard-serveunit that you installed yourself stays. Uninstall says that a new setup does not start it, and printssudo systemctl start shard-serveand the commands that remove it. Before, the next setup after an uninstall could delete it. #597 #603 - Uninstall (Linux): uninstall also removes the iptables rules and the firewalld zone that shard added for its bridge. #589
- Network (Linux): on a host with ufw or firewalld, sandboxes got no DNS, no proxy and no routed traffic, because the host firewall dropped them first. shard now opens its bridge as Docker does: iptables rules with the comment
managed-by-shard, and a firewalld zoneshard. The daemon checks them every 5 seconds, so it repairs them after aufw reload. The docs no longer tell you to runufw allow. If firewalld already has a zoneshardor a policyshard-forwardingthat shard did not make, shard leaves that zone or policy unchanged and refuses to start a sandbox. Rename yours, or remove it if nothing uses it. #589 - API: when a firewalld zone
shardor policyshard-forwardingthat shard did not make refuses a create, the failed reason of the sandbox names that zone or policy, so a client of the HTTP API sees the cause. #615 - Daemon: a second daemon on another root no longer removes the network rules of the first daemon's sandboxes. It refuses to start:
shard: another shard daemon, over the root /var/lib/shard, already serves this host's sandbox bridge and nft table: a host runs one daemon, so stop that one or use its root. #599 - CLI: errors name a sandbox by its name, or by its id when it has no name. #607
- CLI: when a file is missing,
shard cpnames the path and the sandbox:"/missing" in sandbox sb: no such file or directory. #608 - CLI:
sudo shard cpfrom a sandbox leaves the copied files owned by the user who ransudo, not by root. A directory that is already there keeps its owner and mode. #608 - CLI: a disk that the provider refuses names
--diskand the fix. A fork cannot set its disk, so its refusal says to remove a sandbox. #585 - CLI:
shard exec --workdirwith a directory that does not exist exits 126 on every provider. On every provider but gVisor, the error saysthe work directory "/missing" does not exist. #588 #594 - API: a resume keeps
started_at, so the uptime counts from the first start. #607 - API: errors and the
in_useholder lists name a sandbox by its name, or by its id when it has none. #607 - API: a failed create names its network cause, such as
set up the sandbox network on the host: nft failed: No such file or directory. Host paths and addresses stay in the daemon log. When no address is free, the error saysno free address left: every sandbox holds one until it is removed, run shard list --all and remove the ones you no longer need. #607 - API: a disk that the provider refuses at create, fork or pause is a
400 invalid_requestthat names the fix, not a500 internal. #585 - API: an exec with a work directory that does not exist is a
422. runc and Sysbox answered500before. #588 - API: a sandbox with a secret or a policy needs an image with a CA bundle. Without one, create,
secret grantandpolicy attachanswer400 invalid_request, not500:image index.docker.io/library/node:22-bookworm-slim has no CA bundle, which a sandbox with a secret or a policy needs: use an image with ca-certificates. #592 - API: when the host does not trust the certificate of an upstream, the
502from the proxy hashostandreasonin its body, such asthe upstream's certificate is signed by an authority the host does not trust.shard policy logsshows it as a deny of the rulecertificate. To trust an internal CA, add it to the host's certificate store and restart the daemon. #596 - API: in
shard policy logs, a drop by a host rule hasrule_text, as long as the rule has not changed since. #596 - SDKs: every client and SDK gets the new text of the
cpfile errors. #608 - Sandboxes: under the
UMask=0077that setup gives the daemon,/etcand the work directory of a sandbox were0700, so users other than root and apt failed. Directories that shard makes in a sandbox are0755now, and every exec runs with umask0022. Mount points that Sysbox makes itself still take the daemon's umask. #592 - Firecracker and vz: after a resume or a fork, the guest clock matches the host clock. Before, it was behind by the length of the pause, so TLS checks failed. This also holds for Firecracker on arm64, so the limits page no longer lists it. #595
- Firecracker and vz: a fork whose disk copy cannot fit fails before shard captures the source. The source no longer freezes and pauses for it, which took 12 to 14 seconds on Firecracker. #606
- Firecracker and vz: a sandbox makes its work directory at start, so `shard c...
shard v0.1.3
Built by the release workflow from a8e1da0.
Changes since v0.1.2
New
- Docs: https://useshards.com/docs covers install and setup, a server and a client quickstart, the concepts, the security model, guides, the TypeScript and Python SDKs, a reference and help. The repository's
docs/guides moved there, and the README points at the site. #541 - Docs: the CLI reference pages are generated from
cli/help.go(make cli-docs), and a unit test fails while they differ. #550 - Docs: the REST API reference pages are generated from the public route spec with
docs/openapi.json(make openapi), and a unit test fails while either differs. #552 - Firecracker and vz: the
kernelfield of a sandbox record holds the tag of the guest kernel it booted, such askernel-6.12.110-3, orlocal-<12 hex of its sha256>for aSHARD_KERNELdev kernel. Create and start record it, resume keeps it, and a fork copies its source's. gVisor, runc and Sysbox leave it out. #539 - CLI:
create,forkandrun --detachprintcreated sandbox <name>on stderr when the sandbox has a name. Stdout keeps the id alone. #553
Fixes
- Setup: with a saved remote connection, the first screen is that connection's menu (check, replace, remove, run sandboxes on this machine, exit).
--local,--provideror--start-at-bootpicks the local item, and--remote <url>still picks replace. #535 - Setup: the save prompt states that the connection stores the API key as plain text before it asks, and the note no longer follows the save. #535 #540
- Setup: a question with no terminal names the flag that answers it in plain words. A local setup with no terminal lists every missing flag in one error before any check, and exits 1. #535
- Setup: the review lists the removal of a saved connection, and the result for the saved connection prints before the next steps. #535
- Setup (Linux): the data check finds a Firecracker disk image in
/var/lib/shardwith no sandbox records. A refusal over another provider's data names the provider that keeps it and the commands that delete it. The delete steps first remove the sandboxes throughshard daemon --provider <owner>,shard list --allandshard remove --force, so their netns, veth and cgroup go too. Then they runrm -r /var/lib/shard. With a disk image they first free it with the uninstall note's commands:umount, thesedof its/etc/fstabline andsystemctl daemon-reloadwhen there is one, andrmof the image. When/usr/local/bin/shardis missing, the steps first choose the owner's provider so setup installs shard and starts its daemon, then remove the sandboxes, uninstall withshard setup, and delete the data. Repair and upgrade stop with the same advice before any change, and exit 1. #540 - Setup (Linux): when only root can read the sandbox records, setup asks for administrator access before the checks and reads them with sudo. A record it cannot read is skipped, as the daemon does. #540
- Setup: the retry hint after a failed step names
shard setup, or the full path of the running binary whenshardis not on PATH. With no terminal, it repeats the run's flags. #540 - Setup: a menu or the step list that redraws shorter clears the rows the taller one left. #540
- Setup: a new local setup and a repair show download progress for
runsc,firecrackerandsysbox. A download that gets no data for 30 s fails with "no data for 30s". #540 - Setup: a local setup ends with "shard is set up." and a repair with "shard is repaired.". When the service starts at boot, both end with ", and the daemon is running." instead of the period. #537 #543
- Setup: host commands drop
sudofor a root login, and hints for shard commands never showsudoon a Mac. #543 - Uninstall (Linux): the note ends with
rm -r /var/lib/shard(withsudounless root), plus the image's lock file when it exists, and addssystemctl daemon-reloadafter thesedof the/etc/fstabline. #553 - Uninstall (Linux): when the disk image is gone but its
/etc/fstabline stays, the note names the line and gives thesed, the reload and therm -r, withumount /var/lib/shardfirst while the data directory is still mounted. #553 - Uninstall (macOS): the note prints the command that deletes the saved data. #543
- CLI: with the daemon down on a host where setup installed a service that starts at boot, the error says "is the background service running? shard setup repairs it". A service installed by hand keeps its
systemctl statusorlaunchctl printhint. #537 - CLI: errors name the fix as a command or a flag. Errors and
--helptext say "API key" instead of "token", and write shard in lowercase. A command in a hint starts withsudowhen the CLI runs under sudo against the local socket. #543 - API: a sandbox or snapshot name with the shape of a generated id gets 400
invalid_requeston create, fork and snapshot create, not 500internal. #537 - API:
snapshot createon a sandbox whose image is gone namesshard pull <image>, notshard image pull. #537 - API: error messages,
failed_reasonandstopped_reasonuse plain words. No code, status, field or route changes. #543 - SDKs: the TypeScript and Python errors use the same words and drop server internals. A patch changeset carries them to the next
useshardsrelease. #543 - vz: when the daemon loses its guest connection and cannot read the VM state from a shim that still runs, the sandbox no longer reads as
stopped. The daemon retries within the grace period, then keeps the error. #533 - vz: a guest connection that times out after 5 s leaks no goroutine, handle or connection, and an answer that arrives at the timeout is used. #533
- vz: a status of a VM whose shim pid is gone waits for the follower to record the end, up to killGrace (10 s), then reads
stopped, neverrunning, both while the follower redials after a SIGTERM and after it lost the shim. A process in its exit counts as gone. #581 #582 - gVisor, runc, Sysbox: the restart count,
endedandgave_upride the exit record on fd 0, which the host holds, so a process in the sandbox cannot change them through/.shard/restarts.json. #529 - gVisor, runc, Sysbox: a link, a fifo or a large file in
/.shardno longer failsstop, and a directory, a link or a link loop at the ready file no longer fails the nextstart. #529 - Remove:
shard rmno longer fails when the egress log writes into the sandbox directory during the remove. #527 - Daemon: two log lines stop reading like faults: the socket line ends "for its owner only, as this host has no shard group", and a finished task logs "task completed and needs no restart". #553
- Site: the landing page has a new design, and the docs take its palette, fonts and logo. The installer's banner and the README show the new logo. #538 #577 #534 #576
VM proof, per docs/release.md:
- Mac: Mac mini (Mac14,3, Apple M2)
- macOS: 26.6 (25G72)
- head that passed: a8e1da0
useshards (TypeScript) 0.1.2
Patch Changes
- 03bcd2b: A sandbox record names the sandbox it was forked from, as forkedFrom in TypeScript and forked_from in Python.
useshards (TypeScript) 0.1.1
Patch Changes
- 2939f8d: Clearer wording in the README, the docstrings and the error messages.
useshards (Python) 0.1.2
Patch Changes
- 03bcd2b: A sandbox record names the sandbox it was forked from, as forkedFrom in TypeScript and forked_from in Python.
useshards (Python) 0.1.1
Patch Changes
- 2939f8d: Clearer wording in the README, the docstrings and the error messages.
shard v0.1.2
Built by the release workflow from b6da7f9.
Changes since v0.1.1
New
- One-line install:
curl -fsSL https://useshards.com/install | shdownloads the newest release, checks it against that release'sSHA256SUMS, installs it to~/.local/bin/shardand offers to runshard setup. A failed or cut install keeps the old binary. The landing page and the Install docs page show the command. #514
Fixes
- Install: the PATH hint also prints the
exportline for the current shell, soshardworks without a new shell. #520 - Setup:
shard setup --helpand the Install page list the setup exit codes. #520 - Setup: the administrator check now fails at once for a user that sudo does not allow, and names the reason. A user whose sudo needs a password passes only when setup can ask at a terminal. The apply step names the same cause. #520
- Setup (macOS): a Mac where no local provider runs now defaults to a remote connection, and the local choice says why vz is not available. #520
- Setup (macOS): the provider menu marks vz as Recommended. #518
- Setup: a local setup ends with next steps (list, create, exec and remove), with
sudowhere the socket needs it, and the foreground daemon command when the daemon does not start at boot. #519 - Setup: "Check or repair" finds a deleted provider file, and restarts a running daemon so it restores its own files. #519
- Setup: an upgrade checks that the restarted daemon answers before it reports the upgrade done, and ends with a closing line. #522
- Setup: a manual install (files setup did not make) now shows its version, the provider its sandboxes use, whether they keep running when its service stops, and the commands that move it to setup. Setup still changes none of its files. #522
- Setup: a failed download names its cause in plain words (timed out, refused, no such host), not a socket address. #521
- Setup: a progress line wider than the terminal no longer leaves pieces of old text on screen. #521
- Setup: a download that stalls for 30 s (no connection, no TLS handshake, no headers, or no new bytes) fails with "connection timed out", instead of a spinner for about 17 minutes. A slow download that still moves completes. #523
- Setup: with
SHARD_REMOTEset beside a saved connection, local setup names theSHARD_REMOTEserver as the one that commands use, and the unset hint names the saved connection that they use after it. #523 - Uninstall: a setup without a background service no longer lists a step to remove one. #518
- Uninstall: no longer says that a binary it just removed remains. #518
- Uninstall: removes the bridge and the nft tables when no sandbox and no proxy still use them, and says how to turn
ip_forwardoff. It never changesip_forwarditself. #518 - Uninstall (Linux): the refusal that asks you to remove your sandboxes first now prints its commands with
sudo. #521 - Uninstall (Linux): names the data disk image
/var/lib/shard.xfs, its size, its/etc/fstabline, and the commands that free the disk. The data stays unless you run them. #522 - Uninstall (macOS): names the daemon logs in
/var/log/shard, which it leaves, and the command that removes them. #522 - Remote: a refused API key names where the key came from (
SHARD_API_KEYor the saved config file) and how to fix it. It never prints the key. #521 - Remote: a failed connection names its cause, such as no answer, a self-signed certificate, or a socket that needs
sudo, instead of a local-daemon hint or a raw x509 error. #521 - Remote: setup prints one line per check, and the plain-text key warning shows only when the key is saved. #521
- Remote: Exit after a failed remote check prints a line. Edit prefills the saved URL, and Enter at the key prompt keeps the current key. #518
- Remote: removing a saved remote on a machine with no local setup points to
shard setup. #519 - CLI: an error that says the daemon log has the cause now names that log on this host:
/var/log/shard/daemon.logon macOS,journalctl -u shardwith systemd, or the daemon's terminal. #519 - CLI: a create refusal names the flag you type (
--memory,--vcpus,--disk), not the API field. #519 - CLI:
shard listsays on stderr how many stopped sandboxes it hides (1 stopped sandbox; shard list --all). #521 - CLI:
shard execon a stopped sandbox names it by the name you gave it, not its id. #521
VM proof, per docs/release.md:
- Mac: Mac mini (Mac14,3, Apple M2)
- macOS: 26.6 (25G72)
- head that passed: b6da7f9
shard v0.1.1
Built by the release workflow from 5ae8584.
Changes since v0.1.0
New
shard setupsets up this host for local sandboxes (provider, tools, data directory, and a systemd or launchd service), or saves a connection to a remote daemon. Seedocs/setup.md. #516
Fixes
- Firecracker: a create, start, fork or restore that is cut after its VM came up now ends that VM, so the daemon no longer holds it. #511
- macOS and Firecracker: a tag that another provider already pulled now gets its missing disk format built offline, from its own layers, with no registry call. A pull streams
buildingthenpulled. A held image with missing blobs no longer heals from the registry: remove it and pull it again. #511 - macOS:
stopcuts a reconnect to the guest that is in flight, so it no longer fails after 10 s with "the last events of sandbox ... still land". #515 - Sysbox: after a daemon restart,
stop,rm -fand the liveness check no longer fail on a sandbox whose PID 1 has fd 0 on a file the daemon cannot open. #509 - Sysbox:
stopno longer fails when the guest removes one of its own cgroups during the stop. #511 - runc, Sysbox and gVisor: a cgroup memory count that cannot be read now fails
status, and is no longer read as "no OOM kill". #509 - Egress: each sandbox logs its dropped packets under its own rate limit, so one sandbox can no longer use up the shared limit and silence the drop records of the others. #507
- Egress: a request the proxy cannot judge gets a 502 with fixed text. It no longer shows the guest the host's nameserver. The daemon log keeps the cause. #507
- Images: the image cache refuses a cached manifest or config that no longer matches its digest, and
shard image lslists such an image asunreadable. #510 - Images (macOS): the VM disk now drops a whited-out link target and keeps the directory of an opaque marker, the same as the directory unpack does. #510
SDKs and release tooling
- The
useshardsSDKs 0.1.0 are on npm and PyPI. They have their own versions and their own GitHub releases. #513 - One
Release SDKspull request now releases the SDKs to npm and PyPI when it merges. #512 - Guest kernel releases are titled
guest-kernel-<version>. The tags and the files stay the same. #517 - Tests: a killed test run no longer leaves fake guests and Firecracker VMs running. #515
VM proof, per docs/release.md:
- Mac: Mac mini (Mac14,3, Apple M2)
- macOS: 26.6 (25G72)
- head that passed: 5ae8584
shard v0.1.0
useshards (TypeScript) 0.1.0
Built by sdk-release.yml from 9e68bfa. Install from these assets: the SDK is on neither npm nor PyPI.