Skip to content

v1.1.0 — Enforced Limits & Durable Sessions

Choose a tag to compare

@Tarcroi Tarcroi released this 12 Sep 22:49
· 2 commits to main since this release

Highlights

  • The published limits now apply. POST /run (60/min) and POST /push (10/min, per client address) were documented since 1.0.0 but never counted — the limiter was mounted on a pattern that matched neither route. Both now answer 429 RATE_LIMITED past the window, with X-RateLimit-* headers on every response, and a push above SKRUN_PUSH_MAX_BODY_MB (50 MB) is refused with 413 before it is read.
  • Dashboard sessions survive a restart and last seven days. Sessions moved from process memory to a sessions table shared by every instance: a redeploy no longer signs everyone out. Session ids are stored hashed and expired rows are swept hourly.
  • Login keys expire. A key minted by skrun login lasts SKRUN_API_KEY_TTL_DAYS (default 90). Keys created through the API get no default lifetime; expires_at is now returned for every key and the dashboard proposes a duration.
  • A delegated key cannot widen the sandbox it was scoped to. Overriding an agent's environment per run now requires an account-wide credential; the cloud sandbox also verifies the bundle SHA-256 before extracting it, and a forwarded client address is only trusted from a gateway that writes it (SKRUN_TRUST_PROXY_HEADER).
  • The self-host stack pulls MinIO again. Docker Hub removed the MinIO images; the compose stack and the pipeline now pull the same pinned releases from ghcr.io/skrun-dev/minio and ghcr.io/skrun-dev/mc.

Breaking

  • POST /run and POST /push can answer 429; POST /push can answer 413. The limits did not change — they now apply.
  • Keys minted by skrun login expire after 90 days by default. Existing keys are not expired retroactively.
  • Overriding environment on a run with a delegated key answers 403 ENV_OVERRIDE_FORBIDDEN.

Migration

  • Nothing to configure. Migration 017_sessions.sql applies at startup on Postgres; the SQLite schema includes the table.
  • The deployment carrying this release loses the sessions still held in memory — one last sign-out.
  • If your gateway appends to X-Forwarded-For instead of overwriting it, set SKRUN_TRUST_PROXY_HEADER to the header it writes itself.
  • model.base_url must be the final URL: a redirect to another origin drops the Authorization header and the provider answers 401.

Stats

  • 1907 unit + integration tests pass (was 1836 at v1.0.0)
  • 140 E2E in-memory, plus the live multi-provider suite
  • Four dependency advisories closed, no major bump
  • OpenAPI 3.1 spec at 1.1.0

Install

npx @skrun-dev/cli@1.1.0 --version
# or
npm i -g @skrun-dev/cli@1.1.0

Full changelog: CHANGELOG.md