Repository navigation
Releases: privatenpm/rustaccio
Releases · privatenpm/rustaccio
Release list
v0.13.0
[0.13.0] - 2026-09-24
Changed
RUSTACCIO_LOG_FORMATdefaults toauto:prettyon an interactive terminal,jsonotherwise (containers, log shippers). Setprettyorcompactexplicitly to keep human-readable output outside a terminal.- ANSI colours are emitted only when stdout is a terminal, and never when
NO_COLORis set. - HTTP requests log one
request completedline (status,latency_ms, inside thehttp_requestspan withmethod,path,request_id) instead of a tower-http response line plus a span-close line. /-/pinghealth probes are logged at debug level, so they no longer appear at the defaultinfolevel.
Fixed
- The
http_requestspan now carries the generated or caller-suppliedx-request-id; it was always-because the trace layer ran before the request ID was set.
v0.12.0
[0.12.0] - 2026-09-23
Changed
- Switched the S3 client's TLS provider from
aws-lc-rstoring(ringwas already in the dependency tree viareqwest):aws-smithy-http-clientnow uses itsrustls-ringfeature,aws-config/aws-sdk-s3no longer enable theirdefault-https-clientfeature, and all S3 code paths set an explicit HTTP connector. This removes the largeaws-lc-sysC build, cutting cold--features s3/--all-featurescompile times. No behavioral change is expected for S3 operations; note the S3 client no longer negotiates post-quantum hybrid TLS key exchange.
Build
- Pre-commit hooks now auto-use the
sccachecompiler cache when it is installed (brew install sccache), matching the existingjustrecipes and CI behavior. - Dev profile now uses
debug = 1(line tables only) for faster codegen/linking and smaller artifacts; breakpoints and backtraces still work, debugger variable inspection is limited. - Release profile no longer uses incremental compilation.
- Pre-commit hook drops the standalone
cargo checkstep;cargo clippy --all-targets --all-featuresis a strict superset and running both forced full rebuilds.
v0.10.0
[0.10.0] - 2026-06-19
Added
- Added versioned integration contracts in
docs/contracts/for auth request mapping, external policy decisions, npm bootstrap payloads, registry event schema, and error taxonomy. - Added machine-readable error
code(and contextualhintfor key auth/policy failures) to JSON error responses. - Added request ID propagation (
x-request-id) into external auth and policy HTTP backends. - Added best-effort registry event emission with pluggable sink (
RUSTACCIO_EVENT_SINK=none|http) and event emission for admin/package mutation operations. - Added
GET /-/npm/v1/bootstrapendpoint for npm/pnpm/yarn/bun onboarding snippets and.npmrcbootstrap guidance. - Added admin cache invalidation hook endpoint
POST /-/admin/package-cache/invalidatefor external/event-driven cache eviction. - Added opt-in startup connectivity probing via
RUSTACCIO_STARTUP_CONNECTIVITY_CHECK, logging IPv4/IPv6 TCP reachability toregistry.npmjs.organd the configured tarball S3 endpoint. - Added a
postgresstate-coordination backend (RUSTACCIO_STATE_COORDINATION_BACKEND=postgres,RUSTACCIO_STATE_COORDINATION_POSTGRES_URL) using session-scopedpg_advisory_lock; the multi-instance write lock is now abstracted behind aLockBackend/LockGuardtrait with per-backend modules (s3,redis,postgres). The managed profile acceptsredis|s3|postgresfor state coordination.
Changed
- Breaking: authentication is now limited to two modes selected by
RUSTACCIO_AUTH_BACKEND:none(anonymous, subject to ACL/policy) andhttp(external HTTP token verification). Thehttpbackend verifies incoming bearer tokens againstRUSTACCIO_AUTH_HTTP_REQUEST_AUTH_ENDPOINTand resolves identity (username/groups) from the response. Tokens are issued out of band by the external system and supplied by clients via.npmrc(//<registry>/:_authToken=<token>). - Breaking: managed mode now requires
RUSTACCIO_AUTH_BACKEND=httpplusRUSTACCIO_AUTH_HTTP_REQUEST_AUTH_ENDPOINTinstead of the removedRUSTACCIO_AUTH_EXTERNAL_MODEflag. - Breaking: removed snapshot-based package metadata persistence and shared S3
__rustaccio_meta/state.jsonpackage snapshots. Package metadata is now always sidecar-authoritative (package.json), and Rustaccio no longer writes any localstate.json(no on-disk auth/session/token records). - Breaking: runtime startup now enforces deployment profiles (
local|s3|managed) withRUSTACCIO_RUNTIME_PROFILEoverride or automatic profile inference from config, including strict backend requirements for the managed profile (redisrate limiting +postgresquotas +redis|s3|postgresstate coordination). - Breaking: backend selector parsing is now strict for auth, tarball, and policy backends (invalid backend values fail fast at startup instead of silently falling back).
- Added bounded in-memory caches with periodic pruning for package metadata and external policy decisions; added package discovery modes (
single-node|multi-node) with optional periodic shared-backend package-name refresh. - Added memory-cardinality bounds for in-memory governance backends (rate limiter/quota) to prevent unbounded key growth.
- Hardened mode config semantics:
RUSTACCIO_RUNTIME_PROFILE=managednow implies managed guardrails, managed guardrails additionally requireRUSTACCIO_AUTH_BACKEND=httpandRUSTACCIO_AUTH_HTTP_REQUEST_AUTH_ENDPOINT, and package discovery mode parsing now fails fast on invalid values. - State-coordination S3 config now falls back to
RUSTACCIO_S3_*values whenRUSTACCIO_STATE_COORDINATION_S3_*are unset to reduce duplicated configuration. - Added metadata backend abstraction scaffold via
RUSTACCIO_METADATA_BACKEND(currentlysidecaronly; transactional backend reserved/not yet available). - Added optional strict revision-concurrency guard (
RUSTACCIO_STRICT_REVISION_CHECK, defaults enabled in managed mode) for package mutation paths. - Package routes now require an explicit package-rule
proxyto consult an uplink; they no longer implicitly fall back todefaultor all configured uplinks. - Local bearer auth tokens now expire by TTL (
RUSTACCIO_AUTH_TOKEN_TTL_SECS, default 30 days), and expired auth/login-session state is pruned on startup, lookup, and background maintenance to prevent unbounded auth/session growth.
Removed
- Breaking: removed the local authentication backend (
RUSTACCIO_AUTH_BACKEND=local/auth.backend: local) and all local user/credential management. There is no local user database. - Breaking: removed
npm login/npm adduser(PUT/-/user), npm token create/list/revoke (/-/npm/v1/tokens), profile/password change (/-/npm/v1/userPOST), and the web login session flow (/-/v1/login,/-/v1/done,/-/v1/login_cli) along with the web UI login/register forms. - Breaking: removed on-disk auth/session persistence —
state.jsonand itsusers,auth_tokens,npm_tokens, andlogin_sessionsno longer exist. - Breaking: removed auth config keys and env vars:
flags.webLogin/RUSTACCIO_WEB_LOGIN,RUSTACCIO_PASSWORD_MIN,RUSTACCIO_LOGIN_SESSION_TTL_SECONDS,RUSTACCIO_AUTH_TOKEN_TTL_SECS,RUSTACCIO_AUTH_EXTERNAL_MODE, and the auth HTTP endpointsaddUserEndpoint/loginEndpoint/changePasswordEndpoint(envRUSTACCIO_AUTH_HTTP_ADDUSER_ENDPOINT,..._LOGIN_ENDPOINT,..._CHANGE_PASSWORD_ENDPOINT). The external HTTP request-auth and optionalallow*policy hooks (plusRUSTACCIO_AUTH_HTTP_TIMEOUT_MS) are retained. - Legacy Verdaccio
store.aws-s3-storageYAML compatibility path for tarball backend configuration.
Fixed
- Scoped package publishes now normalize
_attachmentskeys anddist.tarballentries to canonical tarball filenames, preventing nested tarball paths like@scope/pkg.tgzfrom causingnpm install404s. - Request tracing now records route/query context on API spans and demotes high-frequency external auth helper spans to
debug, reducing noisyINFOclose-event logs. - S3 tarball backend warnings now include endpoint, bucket, key/prefix scope, AWS request IDs, gateway headers, and SDK error kind to speed up production diagnosis of broken S3 backends and proxies.
- Authoritative S3 metadata lookup failures now surface as upstream
502/503responses instead of being collapsed into404 no such package available; transport-level S3 timeouts are classified as503.
v0.8.0
[0.8.0] - 2026-02-14
Fixed
- Package manifest
versionsobject now preserves insertion (publish) order instead of sorting lexicographically, matching Verdaccio behavior.
v0.3.0
[0.3.0] - 2026-02-14
Added
- Graceful shutdown handling for standalone runtime on
SIGTERM/Ctrl+C. - Additional runtime/config test coverage for timeout parsing,
audit.enabledroute gating,web.enableroute gating, and invalidRUSTACCIO_CONFIGhandling. - Explicit compatibility policy and documented Verdaccio behavior differences/limits in
README.md.
Changed
- CI Rust job timeout increased from 30 to 60 minutes.
Config::from_env()now returnsResultand fails fast whenRUSTACCIO_CONFIGis set but invalid/unreadable.- Security audit endpoints now return
404when audit middleware is disabled. - Search endpoint now caps
sizeto250. - Store persistence and sidecar syncing were refactored to reduce unnecessary state cloning and filter uplink-cached package snapshots during serialization.
- Docker publish workflow now builds with
CARGO_BUILD_JOBS=1for lower-memory builds. - Docker runtime image hardening updated user creation with
useradd --no-log-init. - Dependency surface cleanup:
- removed unused direct deps
bytes,futures-util, andhttp - removed unused
reqweststreamfeature - moved
flate2andtartodev-dependencies - removed unused
chronoserdefeature
- removed unused direct deps
- Repo hygiene updates for local artifacts (
.gitignore,.dockerignore).
Removed
- Deprecated file-length gate test (
tests/file_length.rs).
v0.2.0
[0.2.0] - 2026-02-14
Added
- GitHub Actions CI for formatting, check, clippy, feature-matrix tests, and docs with warnings denied.
- Multi-stage Docker build with non-root runtime defaults.
- GitHub Actions workflow to build and publish multi-arch container images to GHCR on version tags.
- GitHub Actions release job for version tags that publishes a GitHub Release using the matching version section from
CHANGELOG.md. - README deployment and embedding examples for standalone, library-owned
main, and Axum sidecar integration with a customAuthHook. - S3 TLS CA bundle controls and richer S3 error reporting.