Changelog
The shdctl command-line tool release history, including new features, fixes, and breaking changes.
읽는 시간 27분최근 업데이트: 9시간 전
This changelog records shdctl release notes from an operator's perspective: new commands, new flags, behavior changes, and breaking changes. This changelog doesn't include internal refactors.
[1.0.0] - 2026-10-09
Added
-
Thecommand rebuilds a secrets import file from the secrets already deployed in a cluster, for when the file you deployed with is gone. The result goes straight back into
shdctl secret export.shdctl secret generate --import- Anything the cluster has no usable value for is listed at the end. Supply those values by hand before you run , or it generates new values, and deploying them breaks whatever still uses the old ones.
secret generate - The command needs a kubeconfig with the verb on secrets in the namespace, which is more than a deployment pipeline needs. Run it as an operator rather than widening a CI role.
list - The file it writes holds your secrets in the clear (mode ): keep it in your secret store, not in Git.
0600
For the flags and the values it exports, refer to Recover the import file from a cluster. - Anything the cluster has no usable value for is listed at the end. Supply those values by hand before you run
-
is now a documented, supported manifest field: a per-chart layer of extra Helm values, applied after every layer the release ships, for when a chart needs a setting the manifest doesn't expose. The field is unchanged since 0.13.0, and nothing in your manifest needs to move; what's new is that its behavior is specified and supported.
configuration.overrides.<chart-name>.values- The key mentioned in 0.10.0 is no longer accepted.
_arrayMergestops and points at the list-patching form that replaces it.shdctl release generate - A chart name the release doesn't contain now fails generation with the release's chart names listed.
- It stays a last resort: can't catch a key you misspelled under
shdctl manifest validate, and a chart's value keys can move between releases. Read the generatedvalues:before you deploy, check your overrides again after each upgrade, and tell Unity what you had to override, so that the setting can become a manifest field of its own.values.yaml
For the merge semantics and the list-patching form, refer to Per-chart Helm value overrides. - The
-
Themanifest field selects where S3-compatible object storage comes from.
configuration.objectStoreis the default, and what every existing manifest gets: the in-cluster store, unchanged.provider: garagepoints transformation step logs, MongoDB backups, and Unity Studio publications at an endpoint you own, and stops deploying the in-cluster store.provider: s3- With ,
s3,endpoint, and the three bucket names are required, andregionnames the one you left out.shdctl manifest validateis optional: setting it moves the pgBackRest repository off its persistent volume, and requires anbuckets.postgresBackupsendpoint.https - needs a CORS rule and an
buckets.studioAssetsendpoint, and shdctl checks neither: both fail only in the browser, while the server reports success.https - prompts for the object store's access key pair instead of generating one. That pair must be able to read, write, and delete in every bucket you name.
shdctl secret generatewithout--use-defaultsleaves it at the--importplaceholder, so don't deploy that snapshot.TBD - stops mirroring the in-cluster store's images with
shdctl artifact sync images, so if you switch back, run the sync again before you deploy.s3
For the endpoint grammar, the behavior of each bucket, and the warnings that shdctl emits for a partial configuration, refer to Bringing your own object storage. - With
-
now also mirrors the Docker images that a release manifest's artifacts run, not just the artifacts themselves. There's nothing to do beyond the sync you already run, but expect more images to be copied, and
artifact sync imagesto contact the source registry.--dry-run -
Thecommand reports what a target registry holds against what your manifest requires, without writing to it. Missing images make it exit with a non-zero code, so a pipeline can gate a deployment on it. It reads release manifests from the target registry, so it works air-gapped.
shdctl artifact sync verify- A probe can't tell "not found" from "not authorized", so an expired credential looks exactly like an empty registry. When every required image comes back missing, says so, and points you at
verify: run that first.shdctl artifact sync preflight - "Present but not required" covers only the images this release defines. Tags left by earlier releases aren't reported.
For the flags, refer to Verify the target registry. - A probe can't tell "not found" from "not authorized", so an expired credential looks exactly like an empty registry. When every required image comes back missing,
-
Themanifest field sizes the volume that the pgBackRest repository sits on, independently of
configuration.infrastructure.components.postgresql.backupStorage. If you leave it out, the sizing profile's default applies (100Gi onstorage, 800Gi onsmall, 1600Gi onmedium). Whenlargeis set, no backup volume is provisioned at all, andconfiguration.objectStore.buckets.postgresBackupswarns that this field is ignored. A persistent volume can't shrink, so a value below what a deployed cluster already has is refused, and the volume stays as it was.release generate -
Themanifest field holds annotations that
configuration.kubernetes.podAnnotationsadds to every pod the release creates, for examplerelease generateon AKS with an HTTP proxy. A chart'skubernetes.azure.com/no-http-proxy-vars: "true"can change or remove one for that chart. For the field, refer to the annotated example.configuration.overrides
Changed
-
Thecommand is now
vpctl. The tool was named for "Virtual Private Cloud", which the product is no longer called: it's a Self-Hosted Deployment, so the tool isshdctl. Install it withshdctl, which also leaves ainstall-shdctl.shsymlink so that your existing scripts keep running; they print a notice that names the new command. Install the new version, and at your convenience, switch your scripts tovpctl,shdctlandSHDCTL_USERNAME, andSHDCTL_PASSWORD. Everything in the following table keeps working throughout shdctl 1.x, and stops working in shdctl 2.0.0:install-shdctl.shYou have
Still works in 1.x
Replace with
The commandvpctlYes, with a notice shdctlandVPCTL_USERNAMEVPCTL_PASSWORDYes, with a notice andSHDCTL_USERNAMESHDCTL_PASSWORDCredentials in ~/.vpctl/config.jsonYes, read in place Run to move themshdctl configure <registry>run from a checkout or a release tarballinstall-vpctl.shYes, it forwards install-shdctl.shTwo things aren't on that schedule. The old download path () is still published until Unity announces otherwise, because a vendored installer fails there with an unclear registry error that upgrading can't fix. Andreleases/cli/vpctl_<os>_<arch>keeps carryingcompatibility.yamlalongside the newminVpctlVersion, so a 0.13.0 or earlier binary pointed at this release still enforces a minimum version rather than silently accepting it.minShdctlVersion -
shdctl follows the release package's rename from "onprem" to "shd", and can still pull every previously published release. It reads the package from, falling back to
platform/shd/, andplatform/onprem/falls back to the previous release repository for a version that isn't published under the current one.release pull- Generate a release earlier than SHD 2.0.0 with the vpctl version it shipped with. shdctl stops on the key those releases use, and names it.
_arrayMerge - Pass when you pull into an extraction directory that already holds a release. Without it, extraction stops at the first file that already exists. If a directory ends up holding both package directories, the next command that reads the release (
--clean-output,release generate,secret generate, orsecret export) stops with an error that names both, instead of letting the stale one shadow the fresh one.artifact sync
- Generate a release earlier than SHD 2.0.0 with the vpctl version it shipped with. shdctl stops on the
-
Breaking:now mirrors only the images your manifest's enabled features require, where it previously mirrored every image in the release. Images that only Istio, the Prometheus stack, log collection, or database monitoring need are skipped when those features are off, and so are the in-cluster object store's images once
shdctl artifact sync imagesisconfiguration.objectStore.provider. A run that skips anything says so on stderr.s3- Turning a feature on now means running again before you deploy: on an air-gapped registry, a missing image can't be fetched at deployment time.
shdctl artifact sync imagestells you whether a registry already holds what a manifest needs.shdctl artifact sync verify - To mirror the full image set as before, pass . Use it for a registry that deployments with different feature sets share.
--allandartifact sync preflightaren't affected.oras
- Turning a feature on now means running
-
Breaking:now refuses
shdctl release generatetogether with--clean-output, before it deletes anything. Run a full--nameinstead;shdctl release generateon its own is unchanged.--name -
Breaking: a manifest whoseis
configuration.kubernetes.docker.repositorycan no longer setartifactSync.sourceRepository: every command that reads the manifest refuses it,docker.namespaceandshdctl manifest validateincluded. Removecluster checkwhen you pull straight from Unity's registry.docker.namespace -
Breaking: deleting the top-levelapplication no longer tears down the deployment. It now leaves the child applications and their workloads running, and reapplying
asset-solutionsadopts them again. To remove a deployment, delete the top-level application first, then the child applications: while it exists, it recreates any child you delete.app-of-apps-application.yaml -
now checks the release package's minimum shdctl version, like
shdctl artifact sync,release generate, andsecret generatealready did. To bypass the check, passsecret export.--skip-version-check -
The chart index thatwrites is now
shdctl release generate, previouslycharts-metadata.yaml.vpctl-metadata.yamlreads either, so a tree that an earlier version generated still deploys. If your GitOps repository has the old file committed, regenerating drops it.shdctl release deploy -
Logs now go to stderr rather than stdout, so a command's own output, such as acommand list, the
--dry-runresults, or acluster checkreport, no longer risks a warning landing in the middle of it. If you redirectedverifyto capture log output, redirect stderr instead.shdctl ... > file -
now honors
configuration.overrideson any key, not only on keys that hold a single value: setting a key whose value is a map or a list tonullnow removes it. If a manifest of yours sets a map or a list tonull, read the generatednullonce before your next deployment. Setting a key tovalues.yamlor{}is unchanged.[] -
now requires Kubernetes 1.34 or later: a cluster on 1.33 fails the version check instead of passing it. Kubernetes 1.33 is past its upstream end of life, and past Amazon EKS standard support.
shdctl cluster check -
now fails when the cluster has no default storage class, even if the manifest sets
shdctl cluster check, and warns when that class isn't the cluster default. The field applies only to Garage and the licensing server; every otherconfiguration.kubernetes.storage.defaultStorageClassvolume uses the cluster's default storage class. If the check fails, mark a storage class as the cluster default before you deploy.ReadWriteOncenow probes the cluster default, plus the manifest's class when it's different.--probe-storage -
now also generates the image pull secret named by
shdctl secret generate, into the same file as the release secrets, soconfiguration.kubernetes.imagePullSecretcreates it along with everything else, and you no longer need the separateshdctl secret deploystep. It carries the container registry credentials you already supply forkubectl create secret docker-registry, for the registry your manifest pulls images from (acr-oras-credentials, orconfiguration.kubernetes.docker.repositorywhen no mirror is configured). If anything other than shdctl creates that secret in your cluster, such as a refresher for a registry that issues short-lived credentials (ECR tokens expire after 12 hours), turn generation off in your manifest before your nextartifactSync.sourceRepository, so that the generated snapshot doesn't overwrite the live credential when you deploy:secret generateconfiguration: kubernetes: imagePullSecret: name: ecr-regcred generate: falseNothing is generated, and the reason is logged, when generation is off, the manifest names no pull secret, the name collides with another secret in the release, no registry resolves, or the registry credentials weren't supplied. -
now warns about every value in your import file that it doesn't read, naming the file and the entry: a secret name that the release's schema doesn't define, a key that the secret doesn't declare, or a key that names a field the schema derives from a default. Read the warnings before you deploy: where the schema generates a field you meant to supply, generation creates a new random value in place of yours, and nothing says so until something fails to authenticate with it. The usual cause is a value filed under the wrong secret. Generation still succeeds either way.
shdctl secret generate -
and
shdctl release deploy --format helmnow stop with a message that names the problem when the directory they're pointed at wasn't produced byshdctl release uninstall, or is missing a chart the release contains, instead of deploying a subset of the release and reporting success.shdctl release generate -
starts each wave's largest charts first, so a wave deployed with
shdctl release deployabove 1 finishes sooner. The dry run lists the charts in the order they deploy.--concurrency -
You can now list IPv6 CIDRs in, so a cluster whose traffic leaves over IPv6 can allow its own egress prefix in. The two families mix freely in one list, entries are still validated by position, and nothing in an existing manifest needs to move.
configuration.networking.allowedIngressCIDRs
Deprecated
- written as a plain string (the secret name) is deprecated in favor of the block form, which keeps the name and the new
configuration.kubernetes.imagePullSecretswitch under one key. There's nothing to do now: the string form still works, meansgenerate, and keeps working until a release announces its removal. shdctl logs a notice that names the replacement when it reads one.generate: true - is deprecated and ignored. There's nothing to do now: a manifest that still carries the key validates and deploys exactly as before, the rendered charts are identical either way, and the tool logs a notice. Delete the line at your convenience.
platform:no longer asks for it, and a future release will reject it. The value is no longer checked, so a manifest that says something other thanshdctl manifest initalso stops failing validation.onprem
Fixed
- now stops with an error when the file is missing or doesn't parse. It used to warn and carry on without a manifest, so the command then failed on something unrelated (
--manifest <path>) or, for a command that needs nothing else, ran without the manifest you named. Withoutversion is required, a--manifestfound by searching upward is still used on a best-effort basis, as before.manifest.yaml - now validates the file you name, instead of ignoring the flag and exiting with code 0 against whatever
shdctl manifest validate --manifest <path>it found by searching upward. A pipeline step that gated on this command passed regardless of the manifest: check yours again.manifest.yaml - now prints the schema to stdout, so
shdctl manifest schemacaptures it instead of writing an empty file.shdctl manifest schema > manifest.cueis unchanged.--export - now reuses the RSA key your import file carries (
shdctl secret generate'sasset-cloud-storage-abstraction), instead of creating a new one on every run and rotating it when you deploy. Astorage-key.pemfile written by an earlier version doesn't carry the key: the first run after you upgrade creates one and persists it. To keep the key a cluster already runs with, rebuild the file from that cluster with--persistbefore you generate: refer to Rebuild a secrets file that vpctl persisted.shdctl secret export - A value supplied for a field is now rejected at generation time, naming the field, unless it's a PKCS#1 key (
keyType: rsa). The PKCS#8 form previously deployed, and then made the services that read it crash-loop, with nothing pointing at the key. To convert one, run-----BEGIN RSA PRIVATE KEY-----. Keys that shdctl generates aren't affected.openssl rsa -traditional -in key.pem -out key-pkcs1.pem - now names the secret in its placeholder warning (
shdctl secret generate --use-defaults).field pixyz-license-3dds.pixyz.lic is required ...andpixyz-licenseboth have apixyz-license-3ddsfield, so the two warnings used to read identically.pixyz.lic - no longer renders the top-level
shdctl release generate --format argocdapplication as one of its own children, which could cascade-delete every application in the deployment and all their workloads on a later regeneration. Before you upgrade, check whetherasset-solutionsexists in your GitOps repository. If it does, the live top-level application is tracking itself: remove the<pathPrefix>/asset-solutions/templates/asset-solutions.yamlfinalizer from it first, then regenerate and commit. With no finalizer, the worst case is ArgoCD deleting that one application while the child applications keep running, and reapplyingresources-finalizer.argocd.argoproj.ioadopts them again.app-of-apps-application.yaml - A full now removes the application of a chart that's no longer in the release, or that your manifest disables, instead of leaving it in the deployment's desired state. Expect ArgoCD to delete such an application and its workloads on the next sync after you commit. If you disabled a chart in an earlier release and rely on its workloads still being there, enable it again before you regenerate.
shdctl release generate --format argocd - no longer drops the other charts' registry details from the generated output, which left a later
shdctl release generate --name <chart>pointing Helm at a directory that held only values. If you ranshdctl release deploy --format helmsince 0.13.0, run a fullrelease generate --namebefore your next deployment.shdctl release generate - now removes only the output file; nothing else in its directory is touched.
shdctl secret generate --clean-output - now writes only that secret. Every generated value must come from
shdctl secret generate --name <secret>or--import: a run that would create one from scratch is refused, naming it, and so is a name the release doesn't produce.--persist
[0.13.0] - 2026-08-12
Added
The command validates your manifest and then verifies that the target Kubernetes cluster meets the deployment prerequisites, before you deploy.
vpctl cluster checkFor more information, refer to cluster command.
[0.12.0] - 2026-07-10
Security
- Rebuilt with Go 1.26.5 (previously 1.26.4) to fix an Encrypted Client Hello privacy vulnerability in , reachable from vpctl through OCI registry pulls, Helm operations, and manifest parsing.
crypto/tls - Updated to version 2.6.1 to fix a registry authentication vulnerability: the client followed a
oras.land/oras-go/v2challenge'sBearerURL without validating its scheme or host, so a malicious or intercepted registry could redirect token requests to internal endpoints or downgrade them to unencrypted HTTP. This was reachable from every authenticated registry operation, such asrealmandrelease pull.artifact sync - These updates improve the toolchain and dependencies without changing behavior.
vpctl
Added
- The manifest field (
configuration.networking.ipFamilyoripv4, defaultipv6) adds support for single-stack IPv6 clusters. When you setipv4, vpctl injectsipv6into every chart's values and configures MongoDB to bind its pods' IPv6 addresses. Manifests that omit the field render identical output to previous versions.global.ipFamily: ipv6 - The manifest field (default
configuration.kubernetes.dnsService) overrides the in-cluster DNS service name that the log-collection gateway resolves against. Set it to your Kubernetes distribution's CoreDNS service name, for examplekube-dnson RKE2, if log collection crash-loops with the errorrke2-coredns-rke2-coredns.host not found in resolver - The secret schema field makes
keyType: "base64"emit the standard base64 encoding ofvpctl secret generaterandom bytes, for examplelengthfor an AES-256 key. Base64-encoded symmetric keys that previously had to be generated manually withlength: 32and pasted in are now auto-generated.openssl rand -base64 32
Changed
- and
release generatenow merge the shared baseartifact syncwith the platform overlay when they read the release package, instead of relying on a pre-merged file, and release packages now ship both files. Older release packages that contain a single pre-mergedversions.yamlcontinue to load unchanged.versions.yaml
[0.11.0] - 2026-06-03
Security
- Rebuilt with Go 1.26.4 (previously 1.26.3) to address two standard library CVEs that affect :
vpctl- Fixed a vulnerability that could include unescaped input in error messages during CUE and YAML manifest parsing.
net/textproto - Fixed a issue that could cause inefficient hostname parsing during TLS verification for Helm and OCI registry operations.
crypto/x509
- Fixed a
- Updated to version
golang.org/x/netto fix an0.55.0Punycode validation vulnerability during manifest validation.idna - These updates improve the toolchain and dependencies without changing behavior.
vpctl
Added
- The manifest field lets you select an image variant, such as
configuration.imageVariant, during chart generation. If an image doesn't support the requested variant,hardenednow fails instead of generating incorrect image tags.vpctl release generate - The manifest field lets you deploy Garage, PostgreSQL (Percona), MongoDB (Percona), Elasticsearch (ECK), and RabbitMQ as single-replica deployments. Set this Boolean value to
configuration.infrastructure.singleNodeto disable PodDisruptionBudgets and remove hard anti-affinity rules. Use this option only for test or evaluation clusters, not for production.true - The flag lets you deploy independent charts within the same deployment wave in parallel. The default value is
release deploy --concurrency, which preserves sequential deployment. You can set1in the manifest to change the default, and the command-line flag overrides the manifest value. If the concurrency value is greater thandeployment.helm.concurrency,1buffers each chart's Helm output and displays it after the chart finishes.vpctl - Per-wave and end-of-deploy summary lines, for example, are now emitted on every non-dry-run deploy, regardless of the concurrency setting.
Wave N complete: X total, Y succeeded, Z failed - The manifest field lets you assign fixed Kubernetes node ports for the
configuration.networking.ingress.traefik.nodePortsandwebTraefik entry points. Each port must be within thewebsecurerange. Omit this field to let Kubernetes assign node ports automatically.30000-32767 - The option reads the registry password from standard input. This is the recommended authentication method for automation.
vpctl configure set --password-stdin - The and
VPCTL_USERNAMEenvironment variables provide non-interactive credentials toVPCTL_PASSWORD. Credential precedence is command-line flag, environment variable, then interactive prompt.vpctl configure set - The secret schema field enforces a minimum secret length.
minLengthnow prompts for a longer value in interactive mode or exits with an error in non-interactive mode if the value is too short. You can't combinevpctl secret generatewithminLength, and generated secrets must use adefaultvalue that is at least equal tolength.minLength
Changed
- now requires a file path. The
secret generate --persistshortcut no longer defaults to--persist. To preserve the previous behavior, usesecrets.import.yaml.--persist secrets.import.yaml - now displays a warning if you use the
vpctl configure setcommand-line option because the password is visible in your shell history and the process list. The option remains available for backward compatibility. Use--passwordor--password-stdininstead. If you don't provide credentials and standard input isn't connected to a terminal, the command exits with an error instead of waiting indefinitely.VPCTL_PASSWORD
Fixed
- now applies the
vpctl artifact syncvalue when it mirrors Docker images, which matches the behavior ofconfiguration.imageVariant. Previously,vpctl release generatemirrored the base image tags while chart generation referenced variant-specific tags, such asartifact sync. This mismatch could causeasset-front-end:1.0.342-hardenederrors when you setImagePullBackOff.imageVariant: hardened - now correctly writes secrets to the specified file. Previously, the command ignored the provided file path and always wrote to
secret generate --persist <file>, which could overwrite the existing import file.secrets.import.yaml
[0.10.0] - 2026-05-12
Security
- Rebuilt with Go 1.26.3 (previously 1.25.x) to pick up four standard-library CVE fixes that were reachable from vpctl: two escaper bypasses used by CUE schema validation, a
html/templateNUL-byte panic on Windows used by OCI registry pulls, and an HTTP/2net.Dialerinfinite loop used by every outbound HTTP call. TheSETTINGS_MAX_FRAME_SIZEdependency is bumped to v0.53.0.golang.org/x/net
Added
- New optional manifest field. Reference a pre-existing Kubernetes Secret (single key
configuration.networking.trustedCaSecretName, PEM-encoded CA chain) to make the .NET workflow containers (StorageTool) trust an internally-signed ingress certificate. Required for environments where the ingress TLS isn't chained to a publicly-trusted CA. The CA bundle is also mounted into the Pixyz Argo workflow templates (ca-bundle.crt,asset-manager-glb-preview,asset-manager-metadata-extraction,asset-manager-optimize-and-convert) for defensive coverage of any future outbound HTTPS calls from those containers.asset-manager-thumbnail-generator - flag (default
release deploy --timeout): per-release timeout passed to10mwhen waiting.helm - flag (default
release deploy --retries): number of additional attempts after a failed0orhelm upgrade --install. Helps with the "CRDs not yet visible on first attempt" race that sometimes resolves on a second attempt.helm template | kubectl apply - flag (default
release deploy --retry-delay): sleep between retry attempts.5s - support in the secret schema: generates
keyType: hexhex characters (lowercaselength–a/f–0) from9for cryptographic secrets that require pure hex (for example, the Garagecrypto/rand). Therpc_secretfield is required and must be even.length
Changed
- Breaking: now defaults to
release deploy --wait(wastrue). Each Helm release is waited on before vpctl moves to the next chart, with the new default 10-minute per-release timeout. Passfalseto restore the previous fire-and-forget behavior.--wait=false - Breaking: the manifest field under
rustfs:is replaced byconfiguration.infrastructure.components, which exposesgarage:(standard CPU and memory requests and limits),resources,metaStorage,dataStorage, andreplicas(capped at 3). The on-premises release package'sreplicationFactorcompatibility.yamlis bumped tominVpctlVersionin the same release, so you must upgrade vpctl to0.10.0before you can deploy on-premises release0.10.0or later.0.13.0 - Remote Helm charts now resolve their source registry from
manifest.yaml, the same way Docker images and ORAS artifacts already do, instead of a per-chart URL.artifactSync.sourceRepository - The helper in chart values now recurses through nested map levels, so paths like
_arrayMergemerge into_arrayMerge.backups.pgbackrest.repos.0.X. Top-level array behavior is unchanged.backups.pgbackrest.repos[0].X
[0.9.0] - 2026-04-24
Added
- flag: saves generated values to a file (default:
secret generate --persist [path]) and auto-loads it on subsequent runs so values are reused without regeneration.secrets.import.yaml - support in the secret schema: auto-generates a self-signed CA certificate (RSA 4096-bit, 10-year validity period) when no value is provided, so you don't need to manually supply a CA certificate for non-interactive generation.
keyType: ca-cert - Alphanumeric-only validation for generated password fields, to prevent special characters, for example, ,
@, from breaking connection strings. This applies to both auto-generated and user-provided values. Set!in the secret schema to opt out for fields that are not used in connection strings.alphanumeric: false - manifest setting (
deployment.helmChartModeor"local", defaults to"remote"): choose between local charts from the release package or remote OCI charts. Existing manifests without this field continue using local charts."local" - subcommand to sync OCI Helm charts between registries (mirrors remote charts for air-gapped deployments).
vpctl artifact sync charts - Remote chart support across the and
release generatepaths, including multi-source ArgoCDrelease deploy --format helmgeneration (OCI chart source + Git values reference).Application - Image and chart references in rendered output are rewritten to your target registry during generation (air-gapped deployments).
Fixed
- now re-prompts on invalid input in interactive mode instead of aborting the entire session.
secret generate - export now correctly base64-encodes fields with
secret generate(e.g. licenses), so reimporting preserves the original values instead of corrupting them.encoding: "base64" - interactive input for
secret generatefields (licenses) now uses a multi-line reader, so pasted multiline base64 content works correctly.encoding: "base64"
Changed
- now writes a
secret generate --use-defaultsplaceholder for required fields with no default and no auto-generate option, instead of stopping execution. A warning is logged for each such field so you know to replace them before deploying.TBD - Sync recap now lists the specific images and artifacts that failed instead of only showing a count.
[0.8.0] - 2026-03-17
Added
- support in
oras_artifactsfor tracking OCI artifact versions alongside Docker images.versions.yaml - subcommand for syncing Docker images between registries.
vpctl artifact sync images - subcommand for syncing ORAS artifacts between registries.
vpctl artifact sync oras - subcommand: verifies registry authentication by syncing one Docker image and one ORAS artifact, and provides troubleshooting hints if the command fails
vpctl artifact sync preflight
Changed
- Breaking: renamed to
vpctl image sync/vpctl artifact sync images. Update any CI scripts that invoke the old command.vpctl artifact sync oras - Breaking: Manifest field renamed to
imageSync. Update yourartifactSync.manifest.yaml - Breaking: flag removed from
--skip-login. Authenticate to source and target registries withartifact sync imagesbefore running the sync.docker login
[0.7.0] - 2026-03-13
Added
- command to interactively create a new
vpctl manifest init(replacesmanifest.yaml).vpctl release init - command to validate an existing manifest against the embedded CUE schema.
vpctl manifest validate - command to display the CUE schema and export it for standalone
vpctl manifest schemavalidation.cue vet - Manifest validation errors are now more precise: schema constraints, defaults, and cross-field rules are defined in CUE and embedded in the binary. now validates manifests automatically during loading.
LoadManifest - manifest configuration for X509 client certificate authentication.
authentication.x509 - field on the RustFS infrastructure component to size the log volume PVC independently of data storage.
logStorage - manifest field to control the maximum number of concurrent transformation workflows in Argo Workflows (default: 20).
configuration.transformations.parallelism - field in the secret schema to enforce exact value length validation.
exactLength
Deprecated
- is deprecated; use
vpctl release initinstead.vpctl manifest init
Removed
- Breaking: manifest section (
configuration.licensingandFlexLM) removed. Parallelism is now controlled bysdkLicenses.configuration.transformations.parallelism
[0.6.0] - 2026-03-03
Added
- Version compatibility check: and
release generatenow verify that vpctl satisfies the minimum version required by the release package (secret generate). The command blocks execution and displays a clear upgrade message when vpctl is too old. Usecompatibility.yamlto bypass. Dev builds and RC versions are handled gracefully.--skip-version-check - flag: processes multiple images in parallel using a worker pool (default: 1 = sequential).
image sync --concurrency
Fixed
- no longer prints an irrelevant manifest-not-found warning.
vpctl version
[0.5.0] - 2026-02-23
Added
- manifest section with sizing profiles (
infrastructure,small,medium) and per-component resource overrides for MongoDB, PostgreSQL, RabbitMQ, object storage, and Elasticsearch.large - flag: checks if each image already exists on the target registry (via
image sync --skip-existing) and skips it, to avoid redundant pull an push cycles.docker manifest inspect - flag: removes local images (
image sync --cleanup) after each successful push, to free disk space on CI runners and local machines.docker rmi
[0.4.0]
Added
- manifest section to enable or disable Loki + Alloy log collection.
monitoring.logCollection - manifest section for ArgoCD deployment defaults (
deployment.argocd,repoURL,pathPrefix,destinationServer). CLI flags take precedence over manifest values when you provide both.targetRevision
Changed
- Breaking: Manifest field renamed to
docker.images.sourceRepository.imageSync.sourceRepository
[0.3.1]
Added
- Service mesh configuration in the manifest.
Changed
- Traefik configuration moved under the manifest section.
ingress
[0.3.0]
Added
- ArgoCD app-of-apps chart generation support ().
release generate --format argocd - command to initialize a new manifest file.
release init - command to uninstall a release.
release uninstall - RSA private key generation in the secret schema.
- flag on
--name,image sync, andrelease generateto filter to a single chart or image.release deploy - flag on
--dry-runandrelease deploy.image sync - Default storage class configuration for Kubernetes storage in the manifest.
- Network configuration in the manifest.
Changed
- now extracts to
release pullby default. Use./extracted-releaseto skip extraction; use--skip-extractto specify a custom extraction directory. Replaces the previous--extract-dirflag.--extract - Breaking: and
release deploynow execute by default. Useimage syncto preview commands. Previously they printed commands without executing.--dry-run - is now a no-op when the target registry is unset or equals the source registry (
image sync).uccmpprivatecloud.azurecr.io - Traefik configuration simplified to set up a service with annotations.
LoadBalancer
[0.2.0]
No customer-facing changes. (Internal updates to the secret-template format.)
[0.1.0]
Added
- Initial release of the vpctl CLI tool.
- Application management commands: download, generate, and deploy.
- Manifest file support with automatic discovery, searched upward from CWD.
- Secret management commands: generate.
- Configuration management commands: view, set, and delete.
- command.
version