# Changelog

## 2026-08-18 - 27.3.1

### Fixes

- require production authority to postdate scratch receipt (cloudlylegacydeploymentsettlement)
  - Reject equal authority issuance/request and scratch completion timestamps in direct and stdio production authorization validation.
  - Wipe temporary canonical stdio frame buffers after encoding and decoding private settlement artifacts.

## 2026-08-18 - 27.3.0

### Features

- add Corestore database backup/restore and settlement recovery contracts (runtime)
  - Adds exact canonical JSON normalizers, encoders, SHA-256 helpers, and runtime limits for Corestore database backup allocation, receipt, restore request, and restore response contracts.
  - Adds fenced legacy deployment settlement attempt, recovery attestation, receipt v2, authority-aware validation, and LF-framed stdio contracts.
  - Preserves legacy Corestore restore request bytes and digests when optional allocation and restore-attempt fences are omitted.
  - Bumps the package manager metadata to pnpm 11.22.0.

## 2026-08-11 - 27.2.0

### Features

- add byte-safe control credential plaintext creation (corestore)
  - Export control token validation and a byte-based plaintext builder for Corestore control credentials
  - Validate UTF-8 token bytes without JSON whitespace and escape canonical JSON plaintext directly from bytes
  - Increase the sealed control credential size limit to accommodate maximum escaped tokens

## 2026-08-11 - 27.1.1

### Fixes

- accept production exact replay with original applied scratch receipt (cloudlylegacydeploymentsettlement)
  - Treat exact-replay production receipts as compatible with preserved applied scratch receipts when the request hash matches.
  - Keep no-op and fresh production execution bound to matching rehearsal dispositions.
  - Add runtime coverage for production exact replay receipt normalization.

## 2026-08-10 - 27.1.0

### Features

- allow platform binding status updates to report object storage bucket names (requests.platform)
  - Add optional objectstorageBucketName to platform binding status update requests.
  - Document cluster runtime reporting of provider-returned object storage bucket names.

## 2026-08-10 - 27.0.0

### Breaking Changes

- require durable bucket authority for object storage retention (corestore)
  - Add schema-v2 Corestore credential binding requests with canonical object-storage bucketName support and digest helpers.
  - Export canonical platform object-storage bucket name validation and limits.
  - Require platform retention bindings to carry a canonical objectstorageBucketName matching the trusted bucket authority.
  - Require retention evidence when validating Corestore object-storage credential material against a trusted retention expectation.

## 2026-08-10 - 26.0.0

### Breaking Changes

- align credential binding digests and objectstorage secret aliases (corestore)
  - Add canonical Corestore credential binding request validation and SHA-256 digest helpers for publication grants.
  - Split objectstorage plaintext credential keys from published Secret alias keys.
  - Expand logical objectstorage credentials into canonical S3 and AWS Secret aliases.
  - Require objectstorage publication receipts to cover the exact Secret alias set.

## 2026-08-10 - 25.3.0

### Features

- add dedicated WorkloadInit runtime subpath export (runtime/workloadinit)
  - Expose ./runtime/workloadinit with dedicated declaration and runtime entry points.
  - Narrow the WorkloadInit runtime dependency graph to immutable image digest validation.
  - Add tests and documentation for the WorkloadInit subpath export.

## 2026-08-10 - 25.2.0

### Features

- add corestore credentials, retention, and settlement contracts (runtime-platform)
  - Add /runtime Corestore control credential retrieval and credential publication grant/receipt contracts.
  - Add value-free objectstorage retention intents, evidence receipts, canonical digest helpers, and platform binding validators.
  - Add Cloudly legacy deployment settlement codecs, authenticated HMAC framing, golden vectors, and Node contract tests.
  - Extend cluster config DTOs with optional corestoreCredentialPublicationGrants.

## 2026-08-09 - 25.1.1

### Fixes

- accept canonical identifiers in managed secret scopes (secret)
  - Validate the management scope source prefix separately before applying shared secret identifier rules to the scope identifier.
  - Allow managed secret scope identifiers containing canonical colon-delimited segments while preserving prefix mismatch and canonical-format validation errors.
  - Update @types/node to ^26.2.0 and packageManager to pnpm@11.20.0.

## 2026-08-07 - 25.1.0

### Features

- add shared hosted-app authorization RPC contracts (hostedapp)
  - Export Cloudly's access configuration, role assignment, platform OIDC enablement, and authorization completion contracts with full `IIdentity` context.

### Maintenance

- refresh release and test tooling
  - Update tstest to 4.0.0; retain mature pnpm and Node.js type versions under the configured minimum-release-age policy.

## 2026-08-01 - 25.0.0

### Breaking Changes

- require canonical organization authority for service creation (service)
  - Add a required top-level `organizationId` to the `createService` request.
  - Keep organization ownership excluded from caller-writable service data.
  - Export canonical organization identifier validation and contract coverage.

## 2026-08-01 - 24.2.0

### Features

- add Spark Swarm observation v2 transport contract (spark-observation)
  - Add authenticated request and immutable acceptance/rejection receipt interfaces for Spark Swarm observation v2.
  - Add canonical digest helpers and validators for v2 transport request and response binding.
  - Document replay, sequencing, receipt persistence, and validation responsibilities for the v2 endpoint.

## 2026-08-01 - 24.1.0

### Features

- Add Spark Swarm observation v2 so workers can report local membership without
  inventing a manager-only Docker cluster ID while manager snapshots are
  digest-verified whenever supplied.

## 2026-07-31 - 24.0.0

### Breaking Changes

- replace pre-cutover secret lifecycle and runtime authority contracts (secrets-runtime)
  - Replace caller-timestamp envelope opening and retiring ingress recipients with active-only recipient metadata and reproducible admission bindings.
  - Add version-specific purge preflight and purgeSecretVersion contracts with revision fences, retention blockers, and durable purge operation metadata.
  - Replace runtime registration v1 self-attested node and WorkloadInit evidence with v2 Cloudly target authority, Spark Swarm observations, and WorkloadInit approval authority contracts.

## 2026-07-31 - 23.2.0

### Features

- add registration expectation contract (secret-runtime)
  - Adds getCoreflowSecretRuntimeRegistrationExpectation for JWT-derived secret runtime registration expectations.
  - Exposes a dedicated coreflowSecretRuntimeRegistrationTagId and validation that only accepts identity.jwt in expectation requests.

## 2026-07-31 - 23.1.0

### Features

- add live secret runtime registration and replay-safe deployment reports (secrets)
  - Add JWT-scoped recipient enrollment state, exact target-node and WorkloadInit artifact attestation, and mandatory report capability validation.
  - Add digest-bound, sequence- and plan-revision-fenced secret deployment report contracts with trusted cluster and live-session validation.
  - Reject WorkloadInit environment maps for manifests without launcher deliveries.

## 2026-07-31 - 23.0.4

### Fixes

- distinguish unowned CoreMail recipients from SMTP rejection (coremail)
  - Add the strict `unhandled` gateway resolution outcome for recipients not owned by an active binding.
  - Validate each response against the exact requested recipient set before gateway routing continues.

## 2026-07-30 - 23.0.3

### Fixes

- reject oversized App Store environment keys (appstore)
  - Limit public and secret environment key validation to 253 characters.
  - Add contract coverage for oversized keys in declarations and install requests.

## 2026-07-30 - 23.0.2

### Fixes

- allow mixed-case public environment keys (appstore)
  - Accept public env var declarations and install publicEnvironment keys using public-key casing rules.
  - Keep OIDC environment variables and secret inputs restricted to canonical secret keys.
  - Add contract coverage for public key casing and secret key rejection.

## 2026-07-30 - 23.0.1

### Fixes

- expose stable CoreMail contract error codes and classify oversized message
  parts as `PAYLOAD_LIMIT_EXCEEDED` (coremail)

## 2026-07-30 - 23.0.0

### Breaking Changes

- replace grouped/plaintext secret delivery with the sealed v23 contract (secrets)
  - Remove SecretGroup and SecretBundle data/request exports, bundled service and preflight fields, flattening RPCs, compatibility validators, and aggregate runtime-file design.
  - Require context-bound X25519 ingress envelopes, schema-v2 immutable manifests, request-and-scope-bound sealed runtime verification, active-recipient issuance, and two-step Coreflow recipient enrollment.
  - Add stable Docker resource names, WorkloadInit map/wrapper contracts, immutable per-platform container invocation evidence, and required Coreflow capabilities.
  - Split App Store public and secret inputs, remove serialized platform/settings/storage credentials, and require JWT-derived hosted-app machine identity with value-free revision-fenced bootstrap actions.
  - Bump storage migration normalization and golden vectors to schema 2 with service-owned credential management scopes.
  - This pre-cutover release does not complete or claim clean-v2 backup verification, historical erasure, or destructive cleanup; those remain separately gated.

## 2026-07-30 - 22.0.0

### Breaking Changes

- define the complete CoreMail v22 authority and lifecycle contract (coremail)
  - Add draining bindings, composite credential-session reporting, rotating cursor-key references, authenticated workload transfer origins, and schema-v2 canonical desired state.
  - Replace caller-constructed inbound delivery pagination with opaque cursors bounded by item and serialized-byte budgets, and require finite authoritative per-binding quotas.
  - Define fixed 30-day terminal retention, non-expiring pending inbound delivery, strict terminal status fields, and canonical one-time HTTP transfer grants.
  - Export strict runtime normalizers for messages, envelopes, transfers, submissions, gateway status, inbound delivery pages, and reconciliation status.
  - Publish exact active/draining workload operation authority and require canonical 256-bit, fixed-lifetime transfer capabilities.

## 2026-07-29 - 21.1.0

### Features

- bind reconciliation reports to immutable image rollouts (status)
  - Adds a both-or-neither `rolloutId` and `rolloutGeneration` pair to
    `reportReconciliationStatus` requests.
  - Enables Cloudly to ignore delayed immutable-image reports from superseded
    rollouts instead of mutating the current rollout state.

## 2026-07-29 - 21.0.0

### Breaking Changes

- harden runtime contracts with canonical digests and transfer-origin binding (coremail)
  - Add strict CoreMail runtime normalization, canonicalization, desired-state digest creation, and digest verification helpers.
  - Require versioned argon2id-v1 verifier format on CoreMail credential DTOs and expose the verifier policy/runtime keys.
  - Add control bootstrap and gateway peer desired-state contracts for verifier metadata and authoritative transfer origins.
  - Return dcrouter-bound CoreMail transfer origin from gateway authentication responses.

## 2026-07-29 - 20.2.0

### Features

- add CoreMail data and request contracts (coremail)
  - Export CoreMail shared data models, transfer grants, desired-state structures, reconciliation status, and limits
  - Add CoreMail TypedRequest interfaces for workload authentication, outbound submissions, inbound delivery handling, reconciliation, and gateway handoffs
  - Document CoreMail authority, transfer, and desired-state constraints with contract coverage
  - Bump @api.global/typedrequest-interfaces to ^4.0.0

## 2026-07-29 - 20.1.0

### Features

- add fenced object-storage migration control contracts (platform.storagemigration)
  - Export platform.storagemigration with versioned migration intent, status, and consumer acknowledgement contracts.
  - Add strict normalizers, mutation fences, canonical SHA-256 digest helpers, and portable golden vectors for migration payloads.
  - Introduce shared strict canonical JSON utilities and reuse them for isolated restore digests.

### Fixes

- deduplicate storage migration changelog entry (changelog)
  - Consolidates the pending fenced object-storage migration notes under the platform.storagemigration entry.

## 2026-07-29 - 20.0.0

### Breaking Changes

- introduce versioned secret contracts and runtime material API (secrets)
  - Add value-free secret metadata, SecretSet attachment, resolved manifest, validation, digest, and rollout state contracts.
  - Add secret TypedRequest contracts and a node-only runtime material verification subpath.
  - Make the legacy service secretBundleId optional and deprecate SecretBundle and SecretGroup compatibility models.

### Fixes

- downgrade @types/node to ^26.1.1 (deps)
  - Downgrades the @types/node dev dependency from ^26.1.2 to ^26.1.1.

## 2026-07-29 - 19.8.0

### Features

- add an authenticated gateway-client mail-domain count contract (gateway)
  - Expose getGatewayClientMailDomainCount with a count-only response for distinct configured mail domains.
  - Derive ownership from the authenticating gateway credential instead of caller-selected owner fields.
  - Document the new request and extend gateway contract tests.

## 2026-07-29 - 19.7.0

### Features

- add first-class Reply-To support to service mail contracts (mail)
  - Add optional replyTo support for outbound message payloads as a single bare ASCII mailbox address.
  - Expose stable mail submission error codes for invalid Reply-To values and typed-field/header conflicts.
  - Add service-mail type coverage and documentation for Reply-To handling.

### Chores

- update active Git Zone runtime tooling (dev-deps)
  - Update `@git.zone/tsrun` from 2.0.5 to 2.0.6.

## 2026-07-28 - 19.6.1

### Fixes

- validate canonical immutable rollout identities and statuses (immutableimage)
  - Require immutable deployment plans to use the immutable-digest policy and canonical rollout, release, and operation identifiers
  - Validate rollout status identity, expected digest, supported status values, and positive updatedAt timestamps

## 2026-07-27 - 19.6.0

### Features

- add explicit DNS proxy intent to deployment routes
  - Deployment callers can persist an explicit provider proxy choice per hostname.
  - Omitting the field remains valid for historical operations and existing callers.

## 2026-07-26 - 19.5.0

### Features

- add replica-starting mismatch reason (immutableimage)
  - Adds a replica-starting reason for replicas whose health is still undetermined during startup grace.
  - Clarifies that replica-starting maps to a live status until grace exhaustion reports replica-unhealthy.

## 2026-07-26 - 19.4.0

### Features

- add recovery redeploy warnings to preflight reports (deployment-preflight)
  - Add RECOVERY_REDEPLOY_OVER_FAILED_RUNTIME as an auditable non-blocking preflight warning code.
  - Expose optional warnings on deployment preflight reports without changing blocker behavior.
  - Clarify deployment operation failure retention semantics through cleanup states.

## 2026-07-24 - 19.3.1

### Fixes

- align immutable placement repair with Cloudly's authenticated admin identity guard

## 2026-07-24 - 19.3.0

### Features

- add a fenced immutable-service placement repair contract (service)
  - Require callers to fence the active rollout and rollout-status revision.
  - Keep placement repair separate from generic immutable service updates.

## 2026-07-24 - 19.2.0

### Features

- add explicit gateway DNS proxy intent (gateway)
  - Let service-domain desired state declare whether provider DNS records should be proxied.
  - Carry the optional proxy choice through gateway route synchronization while preserving backward compatibility when omitted.

## 2026-07-24 - 19.1.0

### Features

- add explicit ingress trust policy to gateway routes (gateway)
  - Adds optional directHub and smartVpn ingress flags to gateway route contracts.
  - Updates gateway contract coverage to assert explicit ingress settings for managed routes.

## 2026-07-24 - 19.0.0

### Breaking Changes

- add versioned corestore inventory reports with per-node probes (corestore-inventory)
  - Change getCorestoreInventory response to return an ICorestoreInventoryReport with inventories and per-node probes.
  - Require protocolVersion and checkedAt on corestore node inventories and add structured error codes.
  - Add coreflow capability and registration interfaces for versioned inventory probing.

## 2026-07-23 - 18.1.0

### Features

- add host-neutral platform OIDC and app-scoped role contracts for hosted apps
  - Declare App Store OIDC capabilities without enabling them automatically.
  - Bind client identity, token audience, and role assignments to an immutable app instance.
  - Validate canonical same-origin callbacks, secret environment mappings, registrations, and audience-scoped claims.
  - Document the shared per-instance enablement contract for Onebox and Cloudly.

## 2026-07-23 - 18.0.0

### Breaking Changes

- require durable controller mutation fences for Web Push binding synchronization and exact-owner deletion
- replace ID-only Web Push deletion requests with owner-scoped, fenced deletion requests

## 2026-07-23 - 17.5.0

### Features

- add portable named filesystem and object-storage App Store request contracts
- add backend-neutral storage capability advertisements and resolved binding lifecycle contracts
- keep physical backend configuration and credential values outside portable and resolved public storage DTOs

## 2026-07-23 - 17.4.0

### Features

- add Web Push contracts and deployment capability (webpush)
  - Add Web Push data models and credential-scoped request contracts for binding management, delivery, cancellation, status, and VAPID key rotation
  - Expose service-level webPush configuration and gateway Web Push capability flags
  - Allow deployment declarations and preflight bindings to require the pushnotification platform capability
  - Document Web Push contracts and mark legacy device-token push RPCs as deprecated

## 2026-07-23 - 17.3.0

### Features

- add service image retention count option (data-service)
  - Adds optional imageRetentionCount to service data definitions for configuring pushed image version retention.
  - Documents the platform default retention count of 3 and protection for active desired or immutable deployments.

## 2026-07-22 - 17.2.1

### Fixes

- persist exact original placement and target confirmation in service migration contracts

## 2026-07-22 - 17.2.0

### Features

- add deployment-scoped Coreflow routing proof contracts for exact route promotion and compensation acknowledgement

## 2026-07-21 - 17.1.0

### Features

- expose the server-authoritative candidate, active, or manual lifecycle state in gateway-client auth contexts

## 2026-07-21 - 17.0.0

### Breaking Changes

- make gateway-client credential handover explicitly two-phase (gateway)
  - Provisioning now returns an unfinalized candidate credential without revoking existing credentials.
  - Add candidate-authenticated finalization to activate credentials and revoke superseded client-bound credentials.
  - Remove caller-selected gateway client finalization and provisioning-time revocation counts from the gateway API contract.

## 2026-07-21 - 16.8.0

### Features

- add explicit gateway-route DNS modes, reconciliation outcomes, replaced-record evidence, and deployment verification retry metadata
- add canonical gateway-client policy, provisioning credential, and mail-overview contracts
- remove the legacy dedicated dcrouter ops-token setting from the Cloudly settings contract

## 2026-07-21 - 16.7.0

### Features

- add an explicit immutable-deployment blocker for required platform capabilities that are missing, disabled, degraded, or unprovisioned

## 2026-07-21 - 16.6.0

### Security

- mark App Store inputs for server-side random generation and service-owned secret-bundle persistence, with optional file-only Docker secret delivery

## 2026-07-21 - 16.5.0

### Features

- add OCI container arguments to App Store runtime contracts
- add an explicit null sentinel for removing container arguments through generic service updates

## 2026-07-21 - 16.4.1

### Fixes

- reject explicit empty container argument arrays because Docker omits them on service inspection; callers must omit the field for stable default-image command behavior

## 2026-07-21 - 16.4.0

### Features

- add bounded container argument vectors to workload desired state and immutable deployment declarations

### Security

- add credential-scoped idempotency keys to service-mail enqueue requests

## 2026-07-20 - 16.3.0

### Features

- add file-only workload secret delivery contracts (secrets)
  - Declare bounded secret-bundle key mappings to read-only Docker secret files.
  - Reject non-canonical paths, volume collisions, duplicate mappings, unsafe ownership, and writable modes.
  - Carry file-only mappings through immutable deployment preflight configuration.

## 2026-07-20 - 16.2.0

### Security

- add least-privilege adoption image tag bootstrap (deployment)
  - Promote only the exact healthy live service digest from its server-derived mutable registry target to a canonical bare semantic-version tag.
  - Return complete OCI index, platform, release, and digest-pinned evidence without granting general registry manifest writes.
  - Add an explicit rollout-adoption bootstrap for legacy services whose immutable target differs from the retained runtime, with a generation-one digest-pinned plan and pollable rollout status.

## 2026-07-20 - 16.1.0

### Security

- require acknowledged Coreflow retention before completing adoption (deployment)
  - Add a two-phase, session-bound retention-attestation contract with exact operation, configuration, runtime, and reporter evidence.

## 2026-07-20 - 16.0.1

### Security

- bind existing-service adoption to configuration and no-replacement runtime semantics (deployment)
  - Add an explicit generation-one adoption rollout mode with a complete service configuration digest.
  - Require adoption consumers to retain and attest the exact verified runtime instead of treating adoption as a promotion.

## 2026-07-20 - 16.0.0

### Breaking Changes

- add attested existing-service adoption contracts (deployment)
  - Add a mutation-free adoption preflight and a digest-fenced, idempotent adoption request.
  - Require explicit service-scoped deployment:adopt-existing authority.
  - Bind registry, release, target-scope, and healthy runtime digest evidence before switching a mutable service to immutable rollout state.

## 2026-07-20 - 15.0.0

### Breaking Changes

- add scoped immutable deployment operation contracts (deployment)
  - Replace machine deployment grant fields with an exact organization/service or organization/service-slot grant and use JWT-only credentials on scoped deployment RPCs.
  - Add revisioned reserve, status, route promotion, retry, and cleanup contracts with complete configuration, rollout, wildcard-route, readiness, and TLS evidence validation.
  - Require authenticated registry evidence bound to the operation, actor, service, image, registry host, repository, exact tag, root digest, and OCI index media type.
  - Require promotion and rollback requests to carry exact operation/repository/tag/digest fences and immutable plans and verified runtime tasks to expose exact rollout and digest evidence.

## 2026-07-19 - 14.0.0

### Breaking Changes

- distinguish read-only observed runtime digests from verified immutable rollout digests (deployment)
  - Report explicit observed-digest replica counts without promoting mutable workloads to verified status.

## 2026-07-19 - 13.0.1

### Fixes

- classify non-string preflight fence fields as invalid transport input (deployment)

## 2026-07-19 - 13.0.0

### Breaking Changes

- bind greenfield preflight to a sanitized candidate configuration (deployment)
  - Derive namespace and storage resource names in Cloudly instead of accepting caller-selected cluster names.
  - Require an explicit completeness marker and secret-reference identifiers without secret values.
  - Reject malformed transport digests, release tags, and log-unsafe request identifiers deterministically.

## 2026-07-19 - 12.0.0

### Fixes

- make greenfield deployment preflight evidence fail closed (deployment)
  - Distinguish the client intent digest from Cloudly's server-computed configuration digest.
  - Report dirty source, registry host, complete replica counts, explicit proposed storage resources, and unknown namespace safety.
  - Define an admin-only, idempotent machine-user grant normalization request without returning token material.

## 2026-07-19 - 11.4.0

### Features

- define least-privilege greenfield deployment preflight contracts (deployment)
  - Add server-persisted, service-scoped machine capabilities without broad cluster authority.
  - Define sanitized GO/NO-GO inventory for OCI indexes, runtime digests, Corestore bindings, and namespace collisions.
  - Bind release evidence and future durable operations to source, version, image, configuration, and namespace digests.

### Maintenance

- replace the broken pnpm 11.13.0 executable pin with pnpm 11.15.0.

## 2026-07-18 - 11.3.0

### Features

- define fail-closed immutable image deployment and runtime evidence contracts (deployment)
  - Separate observed registry releases, accepted digest rollouts, and exact-digest rollback plans.
  - Require task-derived Docker runtime evidence and complete healthy replica reports before rollout success.
  - Add idempotent promotion, compare-and-swap rollback, capability, ordering, and mismatch contracts.

## 2026-07-15 - 11.2.0

### Features

- Support priority and managed-kind metadata on gateway routes.
  - Allow combined `hostname` plus `routeRef` ownership so multiple managed routes for one hostname reconcile independently.
  - Define the canonical `letsencrypt-http01-forward` managed route kind.

### Maintenance

- Update the release toolchain to pnpm 11.13.0 and Node.js types 26.1.1.

## 2026-07-13 - 11.1.1

### Fixes

- reject provider-reserved database names at isolated-restore prepare ingress
  - Reject MongoDB system database names for both source and target mappings before a new restore reservation can be committed.
  - Preserve structural decoding of historical mappings so cleanup and status remain available across the contract upgrade.

## 2026-07-13 - 11.1.0

### Features

- define the hardened isolated-restore control contract (backup)
  - Bind short-lived, single-operation restore grants to a canonical, versioned authority and immutable restore plan.
  - Enforce JWT-only public authority, bounded chunk uploads, strict archive/resource normalization, and cross-runtime digest rules.
  - Add bearer-free durable chunk receipts, completed-object proofs, and golden vectors for independent implementations.

## 2026-07-13 - 11.0.0

### Breaking Changes

- require JWT-only credentials for public isolated restore requests (backup)
  - Replace caller-visible identity claims with `IIdentityCredential` on create, list, get, and cleanup requests.
  - Require Cloudly handlers to verify the JWT and derive actor, role, and tenant authority server-side.

## 2026-07-13 - 10.1.0

### Features

- define isolated restore orchestration contracts (backup)
  - Add non-runnable scratch namespaces with backup-derived cluster and source authority.
  - Add idempotency keys, revision compare-and-swap, exact cluster/node routing, verification, cursor pagination, durable backup holds, and retryable per-resource cleanup progress.

### Maintenance

- Remove the legacy implicit-any build suppression and refresh the age-eligible TypeScript toolchain.

## 2026-07-10 - 10.0.0

### Breaking Changes

- accept JWT-only credentials for cluster config requests (config)
  - Add IIdentityCredential as a JWT-only authentication contract.
  - Make IIdentity extend IIdentityCredential so full identities remain compatible where credentials are accepted.
  - Update getClusterConfig request identity to require only the JWT needed for server-side resolution.

## 2026-07-10 - 9.0.0

### Breaking Changes

- require identity for baremetal request contracts (baremetal)
  - Require identity on getBaremetalServers and controlBaremetal requests.
  - Add typedrequest contract conformance to baremetal request interfaces.
  - Update package manager metadata to pnpm 11.11.0.

## 2026-07-07 - 8.1.1

### Fixes

- allow submission auth for mail delivery status requests (mail)
  - Change IReq_GetMailDeliveryStatus.request.auth to IMailSubmissionRequestAuth so service-mail credentials can query status by spoolItemId.
  - Document getMailDeliveryStatus auth and response behavior in the README.

## 2026-07-06 - 8.1.0

### Features

- add gateway client route listing contract (gateway)
  - Add IGatewayClientRoute for client-owned route reconciliation views
  - Add getGatewayClientRoutes typed request returning gateway client routes

### Fixes

- document gateway client route contracts (docs)
  - Add README references for IGatewayClientRoute, getGatewayClientRoutes, and syncGatewayClientRoute.
  - Update the dcrouter gateway settings example to use generic placeholder values.

## 2026-07-06 - 8.0.1

### Fixes

- treat null optional port fields as absent (serviceports)
  - Normalize null optional target port range, domain port, and public port range fields consistently with undefined.
  - Add test coverage for persisted null optional service port fields.
  - Update Node.js type definitions and pnpm package manager version.

## 2026-07-04 - 8.0.0

### Breaking Changes

- introduce canonical service port routing contracts (service-ports)
  - Add shared service target port, domain route, public port mapping, and normalization helper contracts.
  - Update service and App Store interfaces to support targetPorts, domain target references, and publicPortMappings.
  - Extend gateway and Coretraffic routing contracts with transport-aware port routes, routeRef ownership, and remoteIngress intent.
  - Breaking change: legacy SSH domain routing is no longer represented through domain protocol values; public TCP/UDP exposure now uses publicPortMappings.

## 2026-06-24 - 7.28.0

### Features

- add service mail endpoint registration interfaces (mail)
  - Add inbound mail configuration fields for typed endpoints and SMTP forwarding targets
  - Add registerServiceMailEndpoint TypedRequest contract for registering inbound delivery addresses

## 2026-06-22 - 7.27.0

### Features

- add service-level mail configuration contracts (mail)
  - Expose public outbound credential metadata on mail address bindings and service mail config
  - Add service data mail configuration for per-address inbound and outbound mail settings
  - Add dcrouter gateway, SMTP submission, and inbound mail forward settings to Cloudly settings
  - Add outboundEnabled to mail address binding sync requests

## 2026-06-17 - 7.26.0

### Features

- add node service reconciliation and runtime update interfaces (node)
  - Add serveZoneServiceUpdate as a supported node action and expose serve.zone service runtime status on node runtime data.
  - Add typed request contracts for reconciling node base services and pushing node runtime updates.

## 2026-06-16 - 7.25.0

### Features

- add Cloudly base service reconciliation request contracts (requests)
  - Add reconciliation result and TypedRequest interfaces for triggering and reporting base service reconciliation.
  - Use a type-only import for identity interfaces in admin request contracts.
  - Bump @git.zone/tsdoc to ^2.1.1 and @types/node to ^25.9.2.

## 2026-06-12 - 7.24.0

### Features

- add live health status to node resource usage entries (node)
  - INodeDeploymentResourceUsage gains an optional healthStatus reported by coreflow's in-process health prober.

## 2026-06-12 - 7.23.0

### Features

- add live node resource usage request contracts (node)
  - getNodeResourceUsage lets the admin UI fetch live per-deployment CPU/memory for one node via Cloudly; coreflowGetNodeResourceUsage is the relayed coreflow request.
  - INodeDeploymentResourceUsage is keyed by the swarm task id (= IDeployment.id) and reports CPU as percent of the whole node (0-100).

## 2026-06-12 - 7.22.1

### Fixes

- document the unit of deployment CPU usage (deployment)
  - resourceUsage.cpuUsagePercent is percent of the whole node's CPU capacity (0-100), not the per-core docker stats convention; pins the scale that node-level metrics already use so producers and views stay consistent.

## 2026-06-11 - 7.22.0

### Features

- add source profile references to route interfaces (gateway)
  - Expose optional sourceProfileRef on service domain entries
  - Expose optional sourceProfileRef on gateway route sync requests

## 2026-06-11 - 7.21.0

### Features

- add Cloudly mail overview request interfaces (mail)
  - Adds interfaces for mail overview domains and recent email queue entries.
  - Defines the getMailOverview typed request contract with configuration status, gateway URL, domains, emails, and error text.

## 2026-06-11 - 7.20.0

### Features

- add live proxy traffic stats request interfaces (requests)
  - Add per-host traffic stats shape with byte rates, request rate, and active connections
  - Add Cloudly, coreflow, and coretraffic request contracts for retrieving live traffic stats

## 2026-06-11 - 7.19.0

### Features

- add per-node dcrouter target host mapping (settings)
  - Adds optional dcrouterTargetHostsByNode setting for mapping swarm node hostnames to gateway-reachable targets.

## 2026-06-11 - 7.18.0

### Features

- add getCurrentRouting request contract (requests/routing)
  - Adds a Coretraffic/Coreflow request interface for retrieving the current routing table
  - Defines reverseConfigs response payload for reverse proxy configuration hydration

## 2026-06-10 - 7.17.0

### Features

- add nfs backup replication target type (backup)
  - Extend backup replication target types to include nfs.

## 2026-06-10 - 7.16.0

### Features

- add archive pruning and external backup tier interfaces (backup)
  - Add backup record metadata for cache/external tiers and offload timestamps
  - Define archive retention/prune result interfaces and coreflowPruneNodeArchive typed request
  - Add settings for external backup targets and node cache retention

## 2026-06-10 - 7.15.0

### Features

- add service migration interfaces and requests (migration)
  - Add service migration data models and export them from the data index
  - Add TypedRequest contracts for starting, listing, and pushing service migration updates
  - Add service placement metadata for pinned, replicated, and held services

## 2026-06-10 - 7.14.0

### Features

- add corestore inventory request interfaces (corestore)
  - Add typed request contracts for retrieving corestore inventory from Cloudly and Coreflow.
  - Define corestore resource, service, and node inventory interfaces.
  - Export corestore request interfaces from the requests index.

## 2026-06-10 - 7.13.0

### Features

- add deployment log streaming request interfaces (deployment)
  - Add start and stop typed request contracts for deployment log streams between clients, Cloudly, and Coreflow.
  - Add typed contracts for reporting, pushing, and ending streamed deployment log lines.

## 2026-06-10 - 7.12.0

### Features

- add interactive deployment shell request interfaces (deployment)
  - Define deployment shell command and process request contracts for Cloudly and Coreflow.
  - Add output and exit reporting/push interfaces for streaming shell process updates.

## 2026-06-10 - 7.11.0

### Features

- add rolling deployment capability flag (service)
  - Add optional rollingCapable property to service data contracts to indicate support for overlapping rolling deployments during updates.
  - Document default behavior as stopping and archiving the previous deployment before starting a replacement.

## 2026-06-10 - 7.10.0

### Features

- add deployment archive retention setting (settings)
  - Adds optional deploymentArchiveRetentionDays to ICloudlySettings for configuring archived deployment record retention.
  - Documents the default retention period as 90 days.

## 2026-06-10 - 7.9.0

### Features

- add archived deployment metadata and query support (deployment)
  - Add optional archivedAt timestamp to deployment data for retained archived records.
  - Add optional includeArchived flag to getDeployments requests.

## 2026-06-10 - 7.8.0

### Features

- add live node metrics and action interfaces (node)
  - Add high-frequency node metrics sample types for Spark-to-Cloudly reporting and admin UI relay.
  - Add node action types and TypedRequest contracts for creating, listing, and pushing action updates.
  - Add Spark action result request and response interfaces.

## 2026-06-10 - 7.7.0

### Features

- add reporter node scoping to deployment snapshots (deployment)
  - Adds optional reporterNodeNames to deployment snapshot requests to identify the node hostnames a report is authoritative for.
  - Preserves existing full-service replacement behavior when reporterNodeNames is omitted.

## 2026-06-10 - 7.6.0

### Features

- add deployment snapshot and reconciliation request contracts (requests/deployment)
  - Add typed request contract for reporting deployment snapshots with service metadata and deployment data.
  - Add push request contracts for deployment updates and service reconciliation status.

## 2026-06-09 - 7.5.0

### Features

- add certificate domain reprovision request contract (gateway)
  - Expose IReq_ReprovisionCertificateDomain for the reprovisionCertificateDomain typed request.
  - Include optional identity, apiToken, and forceRenew request fields with success/message response metadata.

## 2026-06-09 - 7.4.0

### Features

- add gateway-specific identity contract for gateway requests (gateway)
  - Introduces IGatewayIdentity with open gateway role and type fields.
  - Updates gateway request identity payloads to use IGatewayIdentity while remaining structurally compatible with platform identities.

## 2026-06-09 - 7.3.0

### Features

- add gateway client data models and request contracts (gateway)
  - Add gateway capability, domain, DNS record, route, and token context interfaces
  - Add TypedRequest contracts for gateway capabilities, client context, domains, DNS records, route sync, and certificate import/export
  - Export gateway data and request modules through existing barrels

## 2026-06-09 - 7.2.0

### Features

- add node management typed request contracts (node-requests)
  - Adds getNodes, getNodeById, getNodeDeletionImpact, and deleteNodeById request interfaces.
  - Includes deletion impact response data for related cluster, deployments, bare metal hosts, blockers, and deletion eligibility.

## 2026-06-09 - 7.1.0

### Features

- add service reconciliation status contracts (service-status)
  - Add reconciliation status types and an optional reconciliationStatus field to service data
  - Add typed request contract for reporting reconciliation status updates
  - Align the cloudlyStatus request contract with typedrequest interfaces
- add optional identity context to settings requests (settings)
  - Adds optional identity to get, update, clear, provider connection test, and internal get setting request payloads.

## 2026-06-08 - 7.0.0

### Breaking Changes

- rename Cloudly config public URL and port fields (cloudlyconfig)
  - Replaces `publicUrl` and `publicPort` with `publicOrigin` and `listenPort` on `ICloudlyConfig`.

## 2026-06-05 - 6.3.0

### Features

- add mail interfaces and request contracts (mail)
  - Define mail data models for resource owners, address patterns, domain authorities, bindings, credentials, spool items, delivery status, journal events, and message payloads.
  - Add typed request contracts for mail authority and binding management, credential rotation, recipient resolution, inbound delivery, spool inspection, delivery journals, and outbound enqueueing.
  - Export mail data and request modules and validate the mail request namespace in tests.

### Fixes

- update public API documentation for appstore and mail contracts (readme)
  - Document the appstore root namespace and request group.
  - List hostedapp and mail request groups plus mail gateway data contracts.

## 2026-05-28 - 6.2.1

- replace Redis platform contract identifiers with Valkey
  - Updates App Store platform requirements and platform database engine contracts to use Valkey naming.

## 2026-05-26 - 6.2.0

- add hosted app parent upgrade admin contracts (hostedapp)
  - Adds admin-facing TypedRequest contracts for hosted apps to inspect and start parent-managed upgrades without exposing app-control tokens to browsers.

### Features

- add hosted app parent upgrade admin contracts (hostedapp)
  - Adds getHostedAppParentUpgradeStatus and startHostedAppParentUpgrade TypedRequest interfaces.
  - Includes identity-based requests, optional targetVersion support, hosted availability metadata, and upgrade state responses.
  - Updates @types/node to ^25.9.1.

## 2026-05-26 - 6.1.0

- add generic hosted app lifecycle contracts (hostedapp)
  - Adds service-scoped runtime identity, lifecycle reporting, bootstrap action, and managed upgrade request interfaces.
  - Adds optional hosted app lifecycle state to service data for host runtimes such as Onebox and Cloudly.

### Features

- add hosted app lifecycle contracts (hostedapp)
  - Add hosted app runtime identity, lifecycle state, bootstrap action, and managed upgrade data contracts
  - Expose typed request interfaces for lifecycle reporting, bootstrap actions, and managed upgrade operations
  - Allow services to include optional hosted app lifecycle state

## 2026-05-26 - 6.0.1

- add App Store service upgrade contracts (appstore)
  - Adds App Store upgrade preview, operation tracking, start/apply, and progress push request contracts
  - Adds service-level App Store upgrade policy, published ports, and service IDs to related service types

## 2026-05-25 - 6.0.0

### Breaking Changes

- rename app catalog contracts to appstore contracts
  - Replaces the `appcatalog` namespace with `appstore`
  - Renames app catalog DTOs and TypedRequest methods to AppStore naming
  - Adds source manifest, digest tracking, and resolved provenance fields under the new appstore contract

## 2026-05-24 - 5.10.0

### Features

- add Spark node telemetry contracts
  - Adds Spark runtime status fields to cluster node data
  - Adds a typed Spark-to-Cloudly heartbeat request contract

### Maintenance

- refresh release tooling dependencies

## 2026-05-23 - 5.9.0

### Features

- add Cloudly deployment runtime and app catalog contracts
  - Adds live deployment task metadata and workspace operation request contracts
  - Adds app catalog metadata, installation, and upgrade detection interfaces
  - Adds node jump command and external image reference contract fields

## 2026-05-14 - 5.8.0

### Features

- enable npm publishing in smartconfig (smartconfig)
  - Turns on the npm configuration by setting its enabled flag to true
  - Keeps the existing registry configuration for Verdaccio and npmjs

## 2026-05-14 - 5.7.0

### Features

- update SmartConfig release targets to schema version 2 (smartconfig)
  - adds schemaVersion 2 to the @git.zone/cli configuration
  - replaces the flat release registry settings with explicit git, npm, and docker targets
  - disables npm and docker release targets while keeping git releases enabled
  - adds an empty @ship.zone/szci configuration block

## 2026-05-08 - 5.6.0 - feat(interfaces)
add desired state, backup replication, and cluster update request fields

- add optional desiredState to base OS registration results
- add optional replicate flag to backup creation requests
- require clusterId in updateCluster requests
- bump tsclass and development tooling dependencies

## 2026-04-25 - 5.4.3 - fix(repo)
no changes to commit


## 2026-04-25 - 5.4.2 - fix(repository)
no changes to commit


## 2026-04-25 - 5.4.1 - fix(project)
no changes to commit


## 2026-04-25 - 5.4.0 - feat(package)
initialize standalone @serve.zone/interfaces package with shared TypeScript contracts

- add exported data, request, and platformservice interface namespaces for the serve.zone ecosystem
- set up package metadata, build and test scripts, and release configuration for publishing
- add a basic test to verify the package's public namespace exports

## 2026-04-25 - 5.3.1 - refactor(package)
extract serve.zone interfaces into dedicated package repository

- initialize the standalone `@serve.zone/interfaces` repository from Cloudly's current interface source tree
- add package metadata, build/test scripts, and `.smartconfig.json` release configuration
