Skip to content

v0.11.0

Choose a tag to compare

@snonux snonux released this 17 Sep 05:41
· 506 commits to main since this release

Release v0.11.0

Release Notes

Overview

This release makes gonf push self-contained: when a target host runs an outdated (or missing) gonf binary, the controller now detects it and automatically syncs a current one before applying your configuration. No more manual binary juggling across your fleet, and no more push failures caused by plan-schema version drift between controller and targets.

Features

Automatic remote gonf binary sync

Before the first apply chunk of a push, gonf now probes the target's plan-schema version. If the remote binary is missing or too old to understand the plan being sent, gonf:

  • Detects the host's OS and architecture (via uname), or uses explicit overrides.
  • Cross-compiles a gonf binary for that host on the fly (cached per GOOS/GOARCH within the push, so mixed-arch fleets don't rebuild repeatedly).
  • Transfers and installs it to the host using scp and install, honoring the host's privilege mode (sudo, doas, or plain root — root logins install without elevation).
  • Verifies the installed binary via its explicit path so a stale PATH entry can't shadow it, then re-runs the remaining apply commands against that path.

This means a single controller binary can roll out config to a heterogeneous fleet even when the targets are on older releases — the tool upgrades itself where needed.

New host options for controlling sync

Three new options on Host/Fleet let you steer the sync behavior:

  • WithGOOS / WithGOARCH — pin the cross-compile target instead of probing the host (useful for exotic or cross-compiled targets).
  • WithGonfPath — choose a custom remote install path (default /usr/local/bin/gonf).

-plan-version flag

gonf -plan-version now prints the plan-schema integer the binary can emit and apply — distinct from -version, which prints the release string. This is what the sync logic uses to compare controller and remote capabilities.

Improvements

  • Privilege-aware apply commands now carry an explicit binary path, so elevated and unprivileged chunks both target the freshly installed binary consistently.
  • Cleaner remote pre-flight — privilege misconfiguration (e.g. -privilege=none with an elevated chunk) still fails fast before any SSH traffic, now also before any binary sync occurs.
  • Testability seams — the new sync path is fully testable without real SSH; existing tests were updated to stub the version probe, keeping the suite deterministic.

Migration Notes

No breaking changes. If your targets already run a current gonf binary, the version probe succeeds and the sync path is skipped entirely — behavior is unchanged.

One note for hosts where the SSH login is not root and Privileged() is not set: the sync install writes to /usr/local/bin/gonf, which requires write access there. On standard setups you'll want Privileged() (with sudo or doas) or a root login, which the install respects automatically.

Docs

The plan documentation now covers the remote-binary-sync flow end to end, including how the probe works and how to override the install path and compile target.