Skip to content

v1.1.0 — Pleasant to operate

Choose a tag to compare

@skydeval skydeval released this 26 Apr 01:33
· 87 commits to main since this release
9589e4d

v1.1 "Pleasant to operate" focuses on operational comfort for
self-hosters. The release adds orchestrator-friendly health
probes, supply-chain security scanning in CI, the full admin
CLI surface (moderator / report / audit / retention), startup-
time service-record drift detection, and a 41% trim of the
published crates.io tarball. The housekeeping pass deflakes
three timing-sensitive cache tests, validates contrib/
deployment configs in CI, and ships a quickstart rot-check
that exercises the README's operator workflow against a mock
PDS — silent doc drift now fails CI.

Also: this release reconciled a tracker numbering migration
mid-development (chainlink replaced an earlier crosslink
instance), and removed a stale auto-generated hook system that
was emitting misleading reminders. See
docs/tracker-history.md for the
migration record.

Added

  • /health and /ready orchestrator probe endpoints (unauthenticated, per-check rationale in §F14) (#23)
  • CI security scanning: cargo-audit + cargo-deny on push/PR plus a scheduled daily audit that opens an issue on new advisories; hard-fail posture with a dated-review-comment escape hatch in deny.toml (policy in §F15) (#13)
  • cairn moderator {add, remove, list} CLI subcommands for managing the moderators table directly; one-shot, no lease conflict with running cairn serve (contract in §F16) (#24)
  • cairn report {list, view, resolve, flag, unflag} admin CLI subcommands wrapping the tools.cairn.admin.* HTTP endpoints; audit attribution preserved via JWT iss (contract in §F17) (#7)
  • cairn audit list admin-only CLI subcommand wrapping tools.cairn.admin.listAuditLog with actor / action / outcome / time-window filters and --cursor pagination (contract in §F18) (#6)
  • cairn serve startup verify-only check against the published service record on the operator's PDS; drift / absent / unreachable each fail-start with a distinct exit code (12/13/14); reconciliation via cairn publish-service-record (contract in §F19) (#8)
  • subscribeLabels retention sweep — daily writer-task batched DELETEs against labels older than [subscribe].retention_days (default 180); operator-initiated runs via tools.cairn.admin.retentionSweep (admin-only, audited per call) and cairn retention sweep; new [retention] config block. Full contract in §F4 (#12)
  • E2E quickstart rot-check: new tests/e2e/quickstart.sh walks the README's operator workflow end-to-end (signing-key generation → config → publish-service-record → serve → curl /.well-known/did.json) against a mock PDS binary. New e2e-quickstart CI job — silent README drift now fails CI (#10)
  • contrib syntax smoke check: prototype contrib-smoke CI job was developed during v1.1 but removed before release after four CI iterations surfaced a fundamental fragility — the validators (caddy validate / caddy adapt, nginx -t, systemd-analyze verify) are version- and environment-sensitive runtime tools rather than pure syntax checkers, making the job test "does CI's specific environment accept this template" rather than "is the template syntactically valid for operators." A cleaner replacement (likely pure syntax validation, not invoking runtime tools) is tracked as chainlink #33; the docker-compose end-to-end alternative tracks as chainlink #32. Side-effect of the removal: contrib/nginx/cairn.conf ships with rate-limiting as operator-add (matches the Caddyfile pattern) — the inline rate=10r/h was one of the four failures that drove this deferral and stays out as the v1.2 design conversation hasn't picked an approach (#9)

Changed

  • crates.io tarball trimmed from 287 files to 168 via Cargo.toml [package].exclude rules — drops .chainlink/, .claude/, .github/, internal docs (cairn-design.md, RETROSPECTIVE.md, MAINTAINERS.md, CODE_OF_CONDUCT.md, docs/), and tests/ (which alone account for ~70 files including the ~40-file signature corpus). The .sqlx/ offline cache (~95 entries) is a hard floor required for downstream SQLX_OFFLINE=true builds without sqlx-cli; further reduction would require splitting the cache into lib-only vs all-targets variants and is deferred (#22)
  • §20.4 of cairn-design.md replaced its three-paragraph "named handoff target TBD" narrative (stale post-v1.0) with a brief two-sentence pointer to MAINTAINERS.md as the durable source of truth for the archive-on-silence policy. Single-source-of-truth — no policy duplication (#17)

Fixed

  • Three timing-sensitive auth-cache tests (doc_cache_returns_cached_then_expires, doc_cache_negative_has_shorter_ttl, jti_cache_expiry_permits_reuse) deflaked by routing wall-clock reads through a new Clock trait. Production wires SystemClock; tests substitute MockClock with explicit advance(Duration) calls. Zero thread::sleep in cache tests; deterministic regardless of CI scheduler jitter. Verified correctness power before commit by intentionally breaking DidDocCache::get and JtiCache::check_and_record and confirming the relevant tests panic (#21)

Removed

Security