v1.1.0 — Enforced Limits & Durable Sessions
Highlights
- The published limits now apply.
POST /run(60/min) andPOST /push(10/min, per client address) were documented since 1.0.0 but never counted — the limiter was mounted on a pattern that matched neither route. Both now answer429 RATE_LIMITEDpast the window, withX-RateLimit-*headers on every response, and a push aboveSKRUN_PUSH_MAX_BODY_MB(50 MB) is refused with413before it is read. - Dashboard sessions survive a restart and last seven days. Sessions moved from process memory to a
sessionstable shared by every instance: a redeploy no longer signs everyone out. Session ids are stored hashed and expired rows are swept hourly. - Login keys expire. A key minted by
skrun loginlastsSKRUN_API_KEY_TTL_DAYS(default 90). Keys created through the API get no default lifetime;expires_atis now returned for every key and the dashboard proposes a duration. - A delegated key cannot widen the sandbox it was scoped to. Overriding an agent's
environmentper run now requires an account-wide credential; the cloud sandbox also verifies the bundle SHA-256 before extracting it, and a forwarded client address is only trusted from a gateway that writes it (SKRUN_TRUST_PROXY_HEADER). - The self-host stack pulls MinIO again. Docker Hub removed the MinIO images; the compose stack and the pipeline now pull the same pinned releases from
ghcr.io/skrun-dev/minioandghcr.io/skrun-dev/mc.
Breaking
POST /runandPOST /pushcan answer429;POST /pushcan answer413. The limits did not change — they now apply.- Keys minted by
skrun loginexpire after 90 days by default. Existing keys are not expired retroactively. - Overriding
environmenton a run with a delegated key answers403 ENV_OVERRIDE_FORBIDDEN.
Migration
- Nothing to configure. Migration
017_sessions.sqlapplies at startup on Postgres; the SQLite schema includes the table. - The deployment carrying this release loses the sessions still held in memory — one last sign-out.
- If your gateway appends to
X-Forwarded-Forinstead of overwriting it, setSKRUN_TRUST_PROXY_HEADERto the header it writes itself. model.base_urlmust be the final URL: a redirect to another origin drops theAuthorizationheader and the provider answers401.
Stats
- 1907 unit + integration tests pass (was 1836 at v1.0.0)
- 140 E2E in-memory, plus the live multi-provider suite
- Four dependency advisories closed, no major bump
- OpenAPI 3.1 spec at 1.1.0
Install
npx @skrun-dev/cli@1.1.0 --version
# or
npm i -g @skrun-dev/cli@1.1.0Full changelog: CHANGELOG.md