Commit c3d4ae8f26

c3d4ae8f26dc0387ae87162141cb5b140f054a71

parent: ed608b4d4a

Verified · cmc ci/build: success ci/test: success ci/vuln: success

cmc <hello@cleberg.net> · 2026-09-02 02:12 UTC

CHANGELOG: v1.4.0

Layout: unified · split

CHANGELOG.org +62
@@ -4,6 +4,68 @@ Versioning follows semver from v0.1.0. Database migrations run
44automatically on daemon start; upgrade notes appear per release when
55anything beyond "replace the binary and restart" is needed.
66
7* v1.4.0 — 2026-09-01
8
9Until now the instance had one operator surface: root on the host. Every
10question about the instance itself — who is on it, what is stuck, what a
11spam repository is doing — needed a shell on port 2222. This release
12gives an instance admin the same answers over SSH, and one page on the
13web.
14
15- =admin user list= pages accounts by username with
16 =--state active|pending|disabled|admin=, each row carrying its state
17 and =last_seen=, the newest use of any of its SSH keys or API tokens.
18 =admin user show <name>= adds the keys with their last use, each
19 address with how it was verified, PGP keys, org roles, owned
20 repository count, API token names and live browser sessions. Both are
21 SSH-only and refused to non-admins, like =audit=. #69
22- =admin user promote|demote=. The only way to admin was
23 =admin user create --admin=; an existing account could not be raised
24 and an admin could not step down. Demoting the last admin is refused
25 inside the transaction that counts them. The host-local twin is the
26 recovery path when no admin key is reachable. #70
27- Repository overrides for moderation: =admin repo list= with size and
28 last push, and =admin repo archive|unarchive|visibility|delete=. Policy
29 still knows nothing about instance admin — a private repository
30 answers not-found to an admin as before — so each override skips the
31 access check explicitly and writes its own =admin repo.<action>= audit
32 row. #71
33- =gitbayd admin= dispatches into the registry. User create, disable,
34 enable and delete, email verify, invite and stats were reimplemented on
35 the host; they now live in the registry, SSH-only and admin-gated, and
36 the host binary runs them as the host — an admin context with no
37 account behind it, so its audit rows say =source: host= where a
38 session says the key fingerprint. Invite and stats gain an SSH twin by
39 the same move. =backup=, =gc= and the backfills stay host-local. #72
40- =audit= filters: =--actor <user>= or =--actor -= for actorless rows,
41 =--action <prefix>=, and =--since= as a duration (=30m=, =24h=, =7d=)
42 or a date. =gitbayd admin audit= takes the same flags and =--json=. #73
43- =dashboard= carries a =queues= block for admins: per worker —
44 webhooks, mail, mirrors, builds, dependency checks — the pending,
45 retrying and dead-lettered counts, the oldest pending age, and the
46 retrying or failed rows themselves, capped at twenty each. The mail
47 queue was readable nowhere before. =/admin= renders the block by
48 dispatching =dashboard=; non-admins get a 404 and no rail link. #74
49- =gitbayd admin config show= prints the configuration in effect as
50 TOML, defaults filled in and =smtp_pass= redacted, so a support
51 question starts from what runs rather than what was written. #81
52- Build badges are served as PNG at =badge/build.png= as well as SVG,
53 for places that will not render SVG.
54- Host monitoring writes its reading to journald on every run and exits
55 non-zero on an alert, so an unset webhook no longer looks like a
56 healthy host; it reads the ACME cache where it actually lives and
57 reports the soonest expiry. govulncheck runs as its own CI job. The
58 database is snapshotted hourly by =gitbay-db-backup.timer=, keeping 48,
59 alongside the nightly full archive; archives inherit the database's
60 mode rather than the umask default. #28
61- A runner whose log stream drops no longer fails the build it was
62 recording. #67
63- =go.yaml.in/yaml/v3= and =golang.org/x/net= bumped. #60
64
65Replace the binary and restart. No migration. The =gitbay-db-backup=
66timer and the monitor changes ship in =deploy/cloud-init.yaml= for new
67hosts; an existing host takes them from there by hand.
68
769* v1.3.0 — 2026-08-31
870
971A runner took every repository's work, which decided where you could run