Release notes
0.21.1 — 2026-09-15
Combines the queue-mount commands from 0.21.0 with the Vault uncertain-write transport fix released in 0.20.2. The pinned artifact source is 96ebe5b; release preparation #84 is merged.
All eight native downloads match the manifest. npm accepted all nine uploads, and the wrapper matches the reviewed bytes. A fresh macOS registry installation passed the binary checksum, version, 34 SSH/import HTTP/PTY checks and detached HTTP queue mount/list checks. All eight npm platform binaries match the native manifest. Native and npm latest read back as 0.21.1. Release and manifest.
The public native macOS binary also passed queue, job and worker reads through the existing development mount, without mutations. Staging API acceptance is recorded in #274; production CLI/UI and Ge testing remain separate. Delivery note.
Unreleased
-
Add five runnable synthetic OTP import checks against published Python0.16.1 over real loopback HTTP: per-entry source changes, dropped-response uncertainty and conflict redaction. No runtime change or broad OTP/SSH completion claim. Evidence matrix.
-
Add synthetic OTP import regressions for a later source changing during an earlier upload. Both content replacement and symlink swaps stop dispatch while preserving completed entries. No runtime change or new deployment; audit and recovery boundaries.
-
2026-09-15: CLI 0.20.1 and Python 0.16.1 are published with
keep_alive_s = -1for enrolled user-systemd hosts. Owned bos14 acceptance passed with unchanged process IDs and zero restarts after Python 324.72s and CLI 302.83s idle windows. Existing hosts can use the paired repair commands; preserve the original request ID when reconciling an uncertain response. Publication and live evidence. Reboot survival and completed hosted private execution remain separate open acceptance checks.
0.21.0 — superseded by 0.21.1
Introduced dreamlake queues mount, mounts, inspect, list, jobs, workers, token and unmount, with explicit namespaces, hidden token input and Vault storage. Native artifacts and npm packages were uploaded, but this pinned source predates the Vault transport fix in 0.20.2. Native channel promotion was held. Use the combined 0.21.1 release to retain the Vault fix. Existing 0.21.0 artifacts remain unchanged.
Queue commands · Validation and publication history.
0.20.1 — 2026-09-15
- Keep enrolled user-systemd hosts available while idle by explicitly setting
keep_alive_s = -1. Existing hosts require re-enrollment with this fix. Paired CLI/Python bootstrap tests parse the generated TOML and verify re-enrollment repairs the old configuration. Published in v0.20.1; hosted acceptance is tracked separately.
CLI source suite: 1,019 passed; typecheck and 33-page docs build passed. All eight platform binaries built. A fresh copied macOS ARM64 binary passed real HTTP enrollment with the unchanged portable bootstrap over a synthetic SSH wrapper; parsed configuration has keep_alive_s=-1. This published patch was based on the previous tag plus the reviewed host fix; unrelated Notes changes on main were excluded.
0.20.0 — 2026-09-15
Adds private repository setup with explicit selected credential mappings and authenticated capability discovery, paired with Python 0.16.0. Published to native downloads and npm from reviewed source f34ca03. All eight native downloads and npm platform binaries match the release manifest; the public npm wrapper matches reviewed source bytes.
dreamlake run --setup setup.json --allow-vault-deliverysubmits a pinned public repository, uv-lock dependencies and explicitly selected env/file mappings to an enrolled host. The metadata file is explicitly selected and bounded; it contains no secret values. Unknown submission outcomes reuse the same request ID and payload.dreamlake runs capabilities <namespace> --jsonreports authenticated server support and limits. Host readiness is verified separately at submission.- Existing password verification/reservation and Task commands remain included. This release does not implement remote password mutation or enable backend private execution.
Paired CLI/Python examples cover submission, discovery, status and cancellation. Private production activation requires the reviewed worker termination fix and fresh acceptance. Validation: 1,019 CLI tests, typecheck and the 33-page documentation build passed. All eight platform binaries built with embedded WASM checks; the native binary reports 0.20.0 with dependencies detached. A fresh isolated registry installation passed the installed binary hash, version and capability-help checks. Public native latest and npm latest/next resolve to 0.20.0. Release and manifest.
0.19.1 — 2026-09-14
Published to native downloads. All eight platform binaries passed public
checksum and size verification. At this historical release checkpoint native latest was 0.19.1. npm accepted the
packages, but macOS arm64 was still processing, so npm latest remained
at 0.19.0. Version 0.20.0 above is now published and verified on both channels.
- Task commands accept
DREAMLAKE_NAMESPACEandDREAMLAKE_PROJECTsession defaults. Explicit flags take precedence; namespace still falls back to login, and project is required when no default is set. No shared context is persisted. - CLI docs link to the DreamLake and Lakeshore documentation tabs.
Password APIs — release status reconciliation
CLI tag 0.19.1 includes password verification and reservation source. Python 0.16.0 is published to PyPI with matching public artifact hashes and a fresh registry version/API check; matching hosted password acceptance is still required. The old CLI 0.19.0 candidate in PR #66 is superseded and must not be republished.
vault password-rotation reserve|show|read|start|cancel|confirm has paired Python methods. Private metadata inputs and strict response validation keep ordinary operation output free of passwords; selected recovery reads are explicit. Real HTTP/native Mongo cross-client target/jump metadata flows passed. Requires backend #370; remote mutation and rollback resolution remain unfinished. Guide.
Password-only verification
vault verify-password and Python verify_host_password verify one saved password with isolated SSH and private askpass IPC. Candidate native/npm/Python real target/jump password success/denial checks passed with independent cleanup. Password rotation and fresh installed-client/hosted enrollment/KMS acceptance remain separate. Guide.
0.18.0 — 2026-09-13
Adds vault rotate-key preparation, pinned API requests, isolated SSH transport and recoverable phase journals. Candidate CLI/Python target and jump rotation passed real SSH acceptance with independent cleanup. CLI 0.18.0 is published to npm and native downloads, paired with Python 0.15.0. Published CLI 0.18.0/Python 0.15.0 hosted staging acceptance passed four target/jump rotations and committed-response-loss recovery, followed by verified owned cleanup (examples #34). Production acceptance remains separate. The frozen release excludes the password-only verification changes above. Development evidence.
Quoted target and jump SSH arguments beginning with -p are preserved rather than interpreted as the vault prefix.
0.17.0 — 2026-09-13
Published to npm and native downloads. Paired Python 0.14.0 is published. All eight public native artifacts and all nine public npm tarballs match the frozen reviewed release. A fresh registry installation with scripts disabled reports 0.17.0.
- Personal owners can inspect trusted prefix KMS policies, preview retained records, activate empty prefixes, and explicitly start/resume populated-prefix migrations. Immutable request IDs recover uncertain outcomes; explicit prefixes are checked before resuming. The SDK never prompts or advances migration in the background.
- Conditional host-binding replacement and owner-only operation recovery retain both credential identities until explicit cleanup. This metadata API does not install or revoke remote SSH keys; remote rotation candidates are excluded.
Migration requires backend #359. The operator migration flag defaults to false and must remain disabled until all writers enforce policy epochs. Installing this package does not enable migration, configure customer grants, or prove hosted acceptance. Paired KMS guide.
0.16.0 — 2026-09-13
Published to npm and native downloads. Paired Python release: 0.13.0. The matching backend is required; package validation does not establish hosted deployment.
- HOTP import defaults inactive. Explicit counter ownership, encrypted atomic issuance and a private immutable request file support safe retries; source pass registrations are never modified. See Vault operations.
- Metadata listing follows bounded pages; explicit
--limit/--cursorsupports one-page consumers. Retired inclusion remains owner-only. - The npm launcher preserves explicitly selected target/jump password descriptors (private files/real pipes, maximum descriptor 1024), including its permission repair retry, while closing unrelated descriptor gaps.
vault unbindreleases an exact personal retention reference while preserving active secrets and making no claim of remote SSH revocation.
Source: HOTP #50, pagination #52, and unbind #49, plus descriptor fix #53. A separately copied candidate launcher was verified against published native 0.15 and staging, with target/jump saving and cleanup. That is not publication evidence for this 0.16 package. All eight published native artifacts match the reviewed manifest; a fresh npm installation reports 0.16.0.
0.15.0 — 2026-09-13
Selected post-enrollment SSH password/private-key saving and account-owned host bindings are included. Target and jump credentials are selected separately; interactive saving defaults to N, quiet grants no consent, and automation uses explicit selections and protected descriptors. Enrollment success survives a saving failure; uncertain writes and saved-but-unbound entries retain recovery metadata. CLI/Python examples.
Paired Python release: 0.12.0. Source implementation is merged in CLI #47, Python #34, and backend #336. CLI publication is verified on npm and native downloads; all platform binaries match the release manifest and latest points to 0.15.0. Python 0.12.0 is published on PyPI/GitHub. Hosted acceptance remains pending. Earlier bos14 checks used a synthetic source snapshot, not these release artifacts. See the Vault Dev Note.
Unreleased — populated-prefix KMS migration
vault kms migrate, bounded resume, and shared status have paired Python methods. Preview includes retained entry/write/HOTP receipt counts. Metadata output strips ciphertext/KMS identifiers and uncertainty retains the original operation ID. Source candidate only; package and hosted verification are pending.
Password reservation candidates also acknowledge retained-record schema 2 on KMS migration start/resume and preserve separate password-snapshot/total counts in metadata. Compatible backend deployment must precede these commands. Source validation: target/jump cross-client reservation and snapshot reads over real loopback HTTP/Mongo; published CLI 0.17/Python 0.14–0.15 are safely gated, new clients advance the same migration. No remote password changes are included.