-
-
-
-
-
1.9.2Release: Squid Tentacle v1.9.2bbf81b71 · ·
Squid 1.9.2 Default MasterKey at-rest enforcement to Strict — an empty/weak/all-zero key now refuses to initialise the encryption service instead of silently encrypting under a recoverable key, making the at-rest encryption cluster (Account/Feed/Certificate, 1.9.1) genuinely protective. Opt-out preserved via SQUID_MASTER_KEY_ENFORCEMENT=warn|off.
-
1.9.1Release: Squid Tentacle v1.9.18c611acd · ·
Squid 1.9.1 Multi-pod concurrency correctness + at-rest secret encryption + disk self-heal completion. - Atomic one-active-deployment-per-concurrency-tag claim (#441) - Defer tentacle upgrade when a deployment script is in flight on the machine (#443) - Encrypt DeploymentAccount.Credentials / ExternalFeed.Password / Certificate.Password+Data at rest (#437/#438/#439) - Wire disk self-heal into K8s-agent local-exec mode (#440)
-
1.9.0Release: Squid Tentacle v1.9.04f09b624 · ·
Squid 1.9.0 Server-side idempotency + Tentacle disk self-heal (SOTA-audit P1 complete, P2 disk-self-heal): - Pause (resumable) on transient infra failure instead of failing (#434) - Scope the in-flight reattach store to the dispatch unit, not the machine (#433) - Wire disk-pressure self-heal into the Tentacle host lifecycle, hardened (#435) - End-to-end ProcessAsync transient-pause test (#436)
-
1.8.19Release: Squid Tentacle v1.8.19deccd860 · ·
1.8.19 — server-side StartScript idempotency (record-before-RPC), transient-target policy scoped to role-matched targets
-
1.8.18Release: Squid Tentacle v1.8.189edf0999 · ·
1.8.18 — resumable deployment timeout (pause+preserve checkpoint, manual resume), DeploymentTimedOut audit category, InFlightScriptStore read concurrency fix
-
1.8.17Release: Squid Tentacle v1.8.174097f951 · ·
1.8.17 — Deployment failure-semantics + tentacle logging and isolation-mutex hardening - #423 Make deployment kill-timeout configurable via env var - #424 Default unavailable deployment targets to fail-fast - #425 Skip PostDeploy convention when the main script fails - #426 Persist the tentacle agent log to a rotated file under the service - #427 Send the isolation mutex name on the wire's IsolationMutexName field
-
1.8.16Release: Squid Tentacle v1.8.16d51e7168 · ·
1.8.16 — Bind tentacle healthz to loopback on Windows to stop firewall prompt
-
1.8.15Release: Squid Tentacle v1.8.1539bbca4b · ·
1.8.15 — Clarify upgrade log: plain-language phases and ASCII errors
-
1.8.14Release: Squid Tentacle v1.8.14fd7be7ec · ·
1.8.14 — Fix and harden Windows tentacle upgrade download path
-
1.8.13Release: Squid Tentacle v1.8.130d3a5a8f · ·
1.8.13 — Rename cross-platform tentacle flavor: LinuxTentacle -> Tentacle The on-host tentacle flavor is OS-neutral (Windows uses it too), so it is renamed from LinuxTentacle to Tentacle (id/class/namespace/settings/logs + install snippets). Backward-compatible: LinuxTentacle stays a resolver alias and the legacy config section is still read, so deployed agents keep starting after upgrade (#419). Client-side only — no server/DB change.
-
1.8.12Release: Squid Tentacle v1.8.1299046e87 · ·
1.8.12 — Fix Windows Tentacle upgrade download (resolve $RID in the URL) upgrade-windows-tentacle.ps1 left $RID unexpanded in the single-quoted download URL, 404ing every Windows self-upgrade since the feature shipped. Resolve it before download (#418), plus cross-OS coverage for the gaps that hid it (agent-resolved==builder, no-placeholder invariant, release-workflow contract, mirror 404s unresolved tokens).
-
1.8.11Release: Squid Tentacle v1.8.116f00bbd7 · ·
1.8.11 — Preview/deploy deployment-target eligibility convergence Transient-target health policy applied in preview (#416); preview and deploy now share one machine-selection primitive and the planner honors manual action-skip on real deploys (#417).
-
1.8.10Release: Squid Tentacle v1.8.1054903605 · ·
1.8.10 — Persisted Event audit stream (deployment-lifecycle + document audit, generic two-point emission, bounded retention) + action-scoped namespace on KubernetesApi deploys
-
1.8.9Release: Squid Tentacle v1.8.94d1f0d8d · ·
Squid 1.8.9 — Windows + Linux Tentacle lifecycle PR gates - PR-gated Windows tentacle lifecycle smoke E2E (service + blue-green upgrade); required status check via the 3-job sentinel pattern (#407, #408) - Fix install-script E2E flakiness: UAC exit-code propagation + per-test ProgramData isolation; non-breaking install-tentacle.ps1 elevation-seam refactor; re-gate install-script category (#409) - PR-gated Linux blue-green versioned-upgrade smoke E2E; required status check, symmetric with Windows (#410)
-
1.8.8Release: Squid Tentacle v1.8.867d7f2d5 · ·
Squid 1.8.8 — Versioned blue-green Tentacle upgrades - Versioned install layout: versions/<v> selected by a stable `current` pointer (#402, #403) - Blue-green upgrade on both OSes: the running version is never touched; rollback is an instant pointer flip (#403) - Real-OS upgrade E2E — Linux systemd (#404), Windows SCM + junction (#405) - Version GC (keep newest N, default 3) + same-version re-upgrade no-op (#406)
-
1.8.7Release: Squid Tentacle v1.8.722eb7627 · ·
Squid 1.8.7 — Tentacle observability - Live deployment log tail (stream script output) (#396) - Durable upgrade trace, survives server restart (#397) - Real Halibut connection log per machine + endpoint (#398, #399) - Windows upgrade-events.jsonl parity with Linux (#400) - Operator-visible marker on script log truncation (#401)