Все проверки выполнены успешно
CI / test (push) Successful in 2m32s
Docker / Build and publish worker image (push) Successful in 18m17s
- reconnect safely after token rotation and retry leased results - reject malformed tasks and remove production cluster debug mutation - validate environment files and require immutable container images BREAKING CHANGE: Docker install, deploy, and Compose now require an immutable repository@sha256 image reference.
62 строки
3.0 KiB
Markdown
62 строки
3.0 KiB
Markdown
# Changelog
|
|
|
|
## 2026-07-19
|
|
|
|
### Standalone installation and deployment
|
|
|
|
- Added `rsmon-worker install` for installing the current binary, a mode-0600
|
|
environment file, and a root-owned systemd service.
|
|
- Added `rsmon-worker deploy` for installing workers over SSH with key or
|
|
password authentication, optional secret files, and host-key verification
|
|
through `known_hosts` or a pinned fingerprint.
|
|
- Added `--token-file`, `--url`, `--api-key`, and `--no-start` deployment
|
|
options.
|
|
- Added optional `--docker` deployment using a prebuilt image. Docker install
|
|
and deploy now require an immutable `repository@sha256:...` reference before
|
|
any Docker or remote-host mutation; the former mutable `latest` default is no
|
|
longer accepted.
|
|
- Simplified the default systemd service to `Type=simple`, `User=root`, and
|
|
`Restart=on-failure`.
|
|
- Reworked the legacy `scripts/install-systemd.sh` script as a compatibility
|
|
wrapper around the built-in installer.
|
|
|
|
### Standalone repository cleanup
|
|
|
|
- Removed the remaining certificate-bundle fallback under `/data/rsmon` and
|
|
updated its documentation.
|
|
- Changed Docker build and runtime bases to public Go and Debian images.
|
|
- Documented binary, systemd, Docker, and SSH deployment workflows.
|
|
- Added installer and SSH host-verification tests.
|
|
|
|
### Verification
|
|
|
|
- Passed `make test`, `make build`, `go vet`, and `go mod verify`.
|
|
- Validated systemd units, Compose configuration, Docker image pull and
|
|
execution, and production worker job reporting.
|
|
- Published the changes as commit `3256dcd` (`feat: add worker install and
|
|
deploy`) on `master`, triggering the Docker image workflow.
|
|
|
|
### Task protocol and local audit hardening
|
|
|
|
- Required one task-envelope branch, matching outer/inner job IDs, and a
|
|
non-empty lease token before local execution.
|
|
- Added structured terminal failures for unsupported check kinds and safely
|
|
attributable malformed envelopes.
|
|
- Recorded delegated notification outcomes in the bounded `/notifications`
|
|
view using only job ID, method, status, duration, and time.
|
|
- Added static permanent handling for invalid deadlines and recovered
|
|
notification executor panics without retaining secret-bearing text.
|
|
- Removed the critical-cluster test-config endpoint, CLI flag, environment
|
|
switch, and production helper; hardcoded config application is test-only.
|
|
- Made runner token rotation connection-scoped and in-memory: it reconnects
|
|
without stopping web, inventory, metrics, or cluster subsystems. Durable token
|
|
storage, bootstrap exchange, rotation acknowledgement, and revocation remain
|
|
unimplemented.
|
|
- Added bounded resend of dequeued check and notification result envelopes after
|
|
websocket reconnect; control-plane application remains at-least-once and must
|
|
deduplicate by leased job and lease token. Failed metric snapshots are dropped
|
|
and replaced by the next periodic tick, not replayed.
|
|
- SIGTERM stops new dispatch and waits for active work, but stale-lease
|
|
acknowledgement, bounded graceful final-result drain, and duplicate-frame
|
|
coverage remain open.
|