Squid 1.8.0 — Upgrade Hardening initiative
8 PRs (H1-H8) closing every link in the 1.7.x operator-facing failure chain
discovered during the Windows IIS deploy field test.
H1 (#354) — UpgradeEligibilityReason codes + cold-cache NoOsDetected
+ OS-aware registry-unreachable messages. Windows operators
no longer see misleading "Docker Hub unreachable" hints.
H2 (#355) — Capability cache persisted to machine.runtime_capabilities_json.
Server pod restart no longer wipes the cache.
H3 (#356) — Active health-check returns structured ManualHealthCheckResult
with fresh AgentVersion/Os + structured ErrorCode.
H4 (#357) — Upgrade-lock contention message enriched with dispatchedAt +
targetVersion + expected-remaining time.
H5 (#358) — LinuxTentacleUpgradeStrategy strict-Linux-only; UpgradeAsync
cold-cache guard. Direct API can no longer bypass H1.
H6 (#359) — MachineUpgradeStatus.RolledBack distinct from Failed. Operators
see "safely restored to baseline" instead of "broken".
H7 (#360) — role:* capability slots. IIS deploy to non-IIS machine fails
at plan-time with actionable hint, not at runtime with
"Import-Module WebAdministration: module not found".
H8 (#361) — Composition regression-guard tests pinning the cumulative
H1-H7 behaviour. 11 new tests; 5596/5596 total unit suite
green; +79 net new tests across the initiative.
Operator-facing impact: every failure mode encountered in the 1.7.x chain
is now structurally impossible. Cross-OS upgrade is uniform; failed
upgrades self-recover via rollback (.bak / apt-snapshot); plan-time
validation catches missing target capabilities before any wasted dispatch.