DreamLake

Release notes

2026-10-01 — Shareable view layouts

Notes and artifact views encode their panel arrangement, sidebar and list display state in the address. Updates coalesce and encode during idle time. Unavailable auxiliary notes leave empty regions; sharing a layout does not grant access. Behavior and illustration. App PR #656 is merged and published; live split/sidebar/reading-position and list search/order reload checks passed on build 2a5135e. Validation and limits.

2026-10-01 — Audio utilities beside playback controls

Volume and cursor/follow buttons sit immediately left of playback controls, with a 12 px spacer between them. When Back to audio appears, the spacer moves before the speaker icon. Pin stays at the far left and Play stays centered. Wide and narrow browser checks, audio tests, TypeScript and production build validate the change. No public task-skill or API contract changes.

2026-10-01 — Notes speaker control grouping

The speaker/volume icon joins cursor and follow controls on the left of centered Play, separated from Pin by a 12 px spacer. Speed, remaining time and voice/model options stay right. Utility controls wrap in the narrowest panels to avoid overlapping Play. Local tests, TypeScript, build, and wide/narrow browser checks pass. This is browser UI grouping only; no public task-skill or API changes.

2026-10-01 — Notes playback layout and Share icons

Voice/model selectors are wider by default and shrink in narrow panels. Pin has an extra spacer. Volume, speed, and speed-adjusted remaining paragraph time sit right of centered Play. Share shows person-plus without presence avatars and plus alongside avatars. Local audio tests, TypeScript, production build, and wide/narrow browser fixture checks pass. UI PR #651. No SDK, CLI, API, or distributed public task-skill contract changes.

2026-10-01 — Notes audio controls and iPad sessions

Notes speech requests a playback audio session on supported browsers to address iPadOS Silent Mode behavior. Play is centered, utility buttons sit left, and voice/model selectors are compact. The volume button opens a slider with mute/unmute that restores the previous nonzero level. Desktop local tests and production build pass; audible playback on a physical iPad remains unverified. UI PR #647.

2026-09-30 — Permanent speech cache

Notes audio saves completed ElevenLabs audio and timing responses privately in S3. Identical requests for the same note reuse the saved response permanently, with current note access checked on every replay. Cache keys account for text, voice, model, output format, and supported surrounding context. Storage outages fall back to synthesis; failed and interrupted streams are never saved. Existing playback limits continue to apply.

2026-09-30 — Native editor prefixes and Backspace

The experimental native rich editor reserves a fixed gutter for heading, list, and quote prefixes, with stable nested-list indents and task checkbox slots. Activating a line preserves body position and wrapping. Backspace at the start of visible text removes a #-style (ATX) heading or root-list format, outdents a nested list subtree, or removes one quote level; Undo restores the edit as one action. Raw Markdown retains literal deletion. These changes apply only to the native experiment; CodeMirror behavior is unchanged.

2026-09-28 — Rich editor stability

Opening-title positioning runs once instead of retucking the title after typing or scrolling. Markdown preview reuses decorations for same-line caret movement and caches list-prefix measurements while retaining rich formatting. Rich tokens, references, and list controls avoid reparsing unchanged source on caret movement. Remote insertions above the viewport preserve the visible passage, yielding to user input. Vim visual selections remain visible in rich and raw views.

UI change. Repeated iPad browser crashes remain under investigation; this release does not claim an iOS memory-leak fix.

Agent Markdown source view

Notes HTML-like reads can preserve literal Markdown inside structural wrappers, including <, &, comment directives, checkboxes and Unicode. One source range matches the enclosed Markdown; no inner/outer split or display-offset conversion. CLI 0.34.4 handles the text transport and trusted address metadata. Skills explain literal source edits and generated unified diffs.

Unreleased — Notes incremental reads

Line diffs no longer fail on substantial rewrites because of merge-patch character alignment limits. Invalid references, missing baselines, generation limits and service failures are reported separately. Merge editing remains the default. Diagnosis and validation.

Unreleased — Shared Notes list ordering

HTML snapshots address ul/ol containers and all li items using their parent paths and the same reading-order sequence as paragraphs (p): s1.p1 → s1.ul2 → s1.ul2.li3 → s1.ul2.li4 → s1.p5. Checklist state is explicit, nested list reads preserve exact source, and the Notes skill follows the same contract. Design and validation.

2026-09-28 — List routes and note context

Projects, Bindrs and Notes paths control the list pane; ?note= controls the active note independently. A contextual button in the note header hides and restores the list. Compact search controls include ordering without default category chips. Project and Bindr results sort before pagination. Release details.

2026-09-27 — Organization and team Vault saving

The Vault dashboard can select a personal, organization, or team scope. Shared entries require current membership and remain isolated from personal and other shared vaults. Access keys and remote setup remain personal-only. Scope guide.

2026-09-27 — Addressed Notes snapshots and action-focused skills

Snapshot reads add --at, --toc, section views and --tag element lookup. Nested semantic sections and paragraphs carry revision-local IDs, code-point ranges and line ranges. --since defaults to line diffs; linger retains its source/SSE contract. List items have section-local IDs; --view markdown adds address comments without changing canonical source. Public skills now route through focused action guides with separate CLI and SDK workflows.

2026-09-26 — Agent selection by text

notes select --text "passage" --note NOTE resolves literal source and publishes an agent selection through RTC. Ambiguous matches require --section or --occurrence (-o); negative values count from the end (-o -1 selects the last match). Stale hashes fail without guessing. CSS lookup remains compatible. Section reads add a source hash and global code-point range. Staging and production, CLI 0.32.0 native/npm publication, docs and public skills are verified. Release receipts.

2026-09-26 — Highlight hover and public handles

Inline highlights show a small hover/focus popover with just the handle and comment, without an extra icon. Clicking still opens the source; sidebar mode keeps the existing comment cards. Highlight attribution uses canonical public handles, with exact personal-profile resolution and unresolved legacy names. Attribution remains self-declared. Details.

2026-09-26 — Notes highlight metadata

Highlights accept optional user and comment strings. The existing comments toggle selects uikit popovers or sidebar cards, with keyboard access and source editing. Existing highlights and colors remain compatible. Author labels are user-supplied. Details and verification.

2026-09-26 — Event-driven Notes selections and CLI 0.31.0

  • Stream live browser selections to CLI linger using the existing RTC awareness channel.
  • Recommend default text output for people and coding agents; JSON remains an explicit programmatic option.
  • Complete CLI 0.31.0 session commands: presence <note> reads the roster, visit registers once, and read --linger manages the session. Remove the old action arguments.
  • Coalesce events server-side at 250ms and honor CLI output throttling with trailing selection/clear delivery.
  • Resolve relative anchors to source-hash-bound Unicode offsets and selected text; remove idle body/roster polling.
  • Recheck collaborator access and close on gaps or slow consumers. Server and UI passed staging and production verification; CLI 0.31.0 is published on native and npm channels.
  • Verified live highlighted text, source offsets, two-second throttling, blur clears and clean session removal. Fresh native/npm skill installs match all 44 bundled files. Verification details.

Unreleased — Notes comments

  • Add embedded and saved comments, a current-view Inline / Sidebar setting, live mirrored drafts, dashed anchor connectors, and shared tag completion.
  • Save without replacing active typing; retry creation idempotently and reject stale object edits. Replies remain in chats.
  • Server rollout adds the NoteComment collection and its (noteId, createdAt) index. Apply the additive index only; do not use a blanket schema reset. UI and server must ship together. Source implementation is not evidence of deployment or a CLI release.

0.1.27 — Declarative layout control

  • Documented the shared UIKit layout controller and DreamLake's source-associated, pin-aware artifact previews.
  • Added agent inspection, resolution and application guidance, linking the canonical UIKit scenario catalog and CLI connection recipes.
  • Notes documentation now links to native panel behavior without duplicating the generic request schema.

Unreleased — Scoped Notes reads for agents

The Notes guide now makes section/passage reads the default for targeted work, reuses cached v2 baselines, and verifies edits with revision-checked deltas. It distinguishes legacy scoped reads from v2 snapshots and explains how read scope affects visible presence. The generated Notes skill carries the same procedure; no CLI or API behavior changes.

Unreleased — Artifact panels beside Notes

Artifact references such as :artifact[geyang/landing-pages#slide-3] open the shared artifact viewer to the right of a Note in Notes and project views. Another reference to that artifact reuses the panel and changes its local hash route without reloading the iframe or navigating away from the Note. The viewer retains versions, zoom, and authorized management controls. The frame protocol is unchanged. This entry records source behavior; merge and app deployment are separate release steps.

Unreleased — Agent instruction review follow-up

Propose partial reverts of the September 25 instruction cleanup pending Tom and Marvin's review. Retain history-backed CLI publishing and Lakeshore docs ownership corrections; restore operational detail and withdraw broader policy wording. History evidence and review scope. The original summary was published in docs 0.1.26; this follow-up is not deployed.

2026-09-25 — Inline text color released

Notes accept :color[text]{color="#ef4444"} in live preview, table cells and the app’s read-only Markdown. The saved source is preserved; invalid attributes remain literal. See the Markdown authoring guide and implementation record. App PR #451 is merged; commit 74c9b788 is verified on staging and production with a deployed browser rendering check. The guide and public Notes skill are published and fresh downloads match their committed source.

Released Notes inline color: red text and a green table status.

Light and dark screenshots with authoring examples.

2026-09-25 — SSR browser model packaging

Browser-only model runtimes are excluded from compiled SSR imports, reducing the local Netlify function from 285.9 MB to 35.3 MB unpacked. Build checks prevent the dependency leak from returning; browser loading policy remains unchanged. Comparison and upload evidence.

2026-09-25 — Explicit Notes AI activity

Opt-in agent read observations and recent inserted-text highlights use separate labels, expire automatically, and never alter canonical note text. Precise ranges disappear when source changes. Cases and verification.

2026-09-25 — Notes history text transitions

Time travel highlights appearing text in green and shows disappearing text as fading red ghosts. Reverse steps, seeks, pause, faster playback and reduced motion are handled without changing saved content or the live editor. Behavior and verification.

2026-09-25 — Localized Notes unified diffs

Incremental v2 reads with --format diff emit localized hunks with three lines of context instead of deleting and re-adding the whole note. Exact source and revision semantics remain unchanged. The Notes/CLI docs and generated skills recommend default inline diffs for compact agent checks. Cause and release verification. The API is verified on staging and production; the original headline diff shrank from 231 lines / 5,992 bytes to 11 lines / 201 bytes with identical source and revision.

Unreleased — Notes context and matching passages

Project and bindr association edits preserve the open note and browsing context. Notes search adds two matching passages, multi-paragraph previews, compact repeated excerpts and exact occurrence selection with stale-source recovery. Files, folders and ML-Dash inspectors use native draggable subview tabs. Behavior and verification scope. The owning Notes guide and generated public dreamlake-notes reference are updated together. Application deployment and live acceptance are tracked separately from docs and skill publication.

2026-09-25 — Notes search highlights deployed

Notes list search now highlights case-insensitive, literal matches in note titles and body snippets, including the narrow side-panel list. Body snippets show the first matching passage with surrounding context, so a body-only match is visible without opening the note. Clearing search removes the highlights.

App PR #441 is merged and commit a4579805 is deployed to staging and production. Production published on September 25 at 11:53 UTC. Both environments returned HTTP 200 for the homepage, Notes, artifact catalog and artifact detail. Local visual verification and all 2,330 local tests passed (5 skipped); live browser visual verification and a release screenshot remain pending because browser policy verification was unavailable. No production note content was changed.

Behavior and verification details.

2026-09-24 — Layout-owned view tabs and editor fixes

Implement local page-owned note/artifact/web-preview tabs and plain single resource panels. Only multiple views show tab chrome; a single editor or preview retains its plain header with no extra row. Reuse the eyebrow name and copyable ID in the tab, on the same horizontal row as Share and sync-status controls, without a View actions + button. Titles stay on one line, use available width without a fixed cap, and clip before the controls. Prevent long read-only/loading note titles from painting over the editor body. Check real CodeMirror sizing, scrolling and selection retention with a local transport stub. Dedupe CodeMirror language/view modules across the app and live UIKit worktree, fixing raw Markdown while live preview is selected. Unrelated resource-add buttons remain. Note-detail catalog, project-folder and bindr-list clicks open/reuse tabs without replacing existing note subjects; edge dragging splits a tab into another panel. Selection, reordering and docking preserve connected editor and iframe instances. Guard unsent note disposal and scope artifact read grants per view. Add pure API, component and mocked-browser acceptance tests. Reference/fragment navigation remains deferred. UI PR #439 is merged at 92f236e0; UIKit PR #216 is merged at c34c934. The owner requested release without waiting for CI. Local combined tests and production build passed; CI completion is not claimed. The bindr-to-body gap is 20px tighter. Delayed bindr hydration preserves the selected note tab. Local development note-body reads use a fixed-origin, read-only Vite proxy for API-authorized signed URLs, avoiding the production bucket's localhost CORS restriction without changing bucket permissions or saved content. Implementation and acceptance boundary.

2026-09-24 — Artifact paths and local routing deployed

Artifact frames now use https://artifacts.dreamlake.ai/<namespace>/<artifact-id> with ordinary query/fragment route state, without internal instance IDs in the URL. The viewer authorizes content and supplies it through the validated frame handshake; a frame path alone grants no access. Authors use dreamlake.route for state-preserving navigation. Viewer links use art.* query parameters and an ordinary fragment. Author contract.

UI PR #437 merged at 8e331dda after full CI passed, including both browser shards and the dedicated routing suite. Frame deploy 6ab5e4115d2864000890b49d was verified before app promotion; staging deploy 6ab5e46228d3cc00088d8a01 and production deploy 6ab5e5ac81f5e90008053ffa use that app revision. Production published at 2026-09-25 03:10 UTC (September 24 Pacific).

Live browser checks passed for clean URLs, Unicode query values, back/forward state preservation, iframe reload, cross-origin isolation, anonymous denial of private content, and public copy links preserving routes while excluding unrelated host fields. The new frame also rendered a legacy host embed before app promotion. Staging has separate auth/data, so its artifact acceptance used browser-only forwarding of authorized production read requests; production acceptance used the unmodified live service. No artifact content was changed.

Docs PR #738 and public skills PR #33 are merged. Live docs were browser-verified; a fresh download at skills de6d06a passed all 39 generated-file checks, with seven generator tests and source freshness checked against combined docs 8611b414. Existing installed skills in active sessions were preserved. No server API or CLI deployment was required. This records automated acceptance, not a claim of owner manual review. The release-record/pointer update changes no public procedure and requires no additional skill generation beyond the owning guide already synchronized.

2026-09-24 — Rich reference directive notation

UI PR #436 and API/docs PR #737 are merged and deployed; public skills PRs #32 and #33 are published, with installed Notes/artifact/reference skills verified.

New note insertions, extraction and reference-copy buttons prefer :note[id]; artifacts use :artifact[namespace/id]. Bindr, asset, placeholder and unresolved ChatGPT rich components also accept bracket primary content, retaining named secondary attributes in braces and all supported saved forms. Fragment targets are parsed and preserved; target navigation remains deferred. Static API HTML preserves complete atomic source mappings. No saved notes are bulk-rewritten.

2026-09-24 — Notes automated release acceptance verified

Production API/RTC, CLI 0.26.2 and Python 0.20.0 are released. Fresh public installs, package integrity, hosted docs/skills, core/HTML acceptance and four paired client MERGE/EXACT examples passed. The frozen live pilot completed 100/100 edits (50 per format, ten private fixtures), with one upload per edit and verified source/native identities. The manifest records automated success and leaves the user's browser/UI review explicitly pending. The separate recorded-evidence validator does not perform live checks; its input is the actual completed pilot. Dated evidence.

This internal acceptance closure updates evidence and dependency provenance; it changes no RTC runtime behavior or public procedure. Earlier implementation and pending-state records are retained in the dated development note.

2026-09-24 — Notes merge/exact API and client release

V2 patches carry the original baseRevision and use ordinary RTC operations by default, preserving concurrent edits through original character identities. mode: "exact" opts into a revision guard for that request; If-Match remains a compatibility alias. Retained native baselines, source validation and reconnect reuse of message IDs prevent fresh-token substitution; uncertain HTTP results require readback before resubmission. The release pairs CLI 0.26.2 and Python SDK 0.20.0 with RTC server 0.5.1; the API pins SDK 0.9.1, whose JavaScript runtime is unchanged from 0.9.0. Browser editor improvements remain intact. Source-mapped HTML reads, static rich tokens and heading numbering are available. Runnable guide.

The guide labels captured CLI/Python transcripts as isolated-fixture evidence; they are not production transcripts. Production automation and the user's manual acceptance remain distinct in the release record.

Historical development — Notes HTML heading numbering, 2026-09-23

Markdown front matter controls display-only hierarchical heading numbers with the shared editor/outline policy. Generated numbers have no editable source range; body ranges still include all front matter. Invalid options produce diagnostics and defaults without changing source. Tests and draft source changes do not establish deployed client/server parity.

Historical development — Notes static rich components, 2026-09-23

Source-mapped HTML previews render strict rich tokens and existing blue bracket placeholders, preserving atomic token ranges and literal code. ChatGPT citations remain unresolved broken-link tags; resources have inert source-only labels without metadata lookup or capability URLs. Browser behavior and releases remain separate in master #706.

Historical development — Notes patch foundation, 2026-09-23

  • Notes v2 preview: explicit source hash/RTC baseline reads, selectable strict patches, retained source observation lookup, and native RTC-only programmatic writes. Requires coordinated server/client release.

  • Notes PR 2 consumer now pins published RTC SDK 0.9.0; hosted authority compatibility remains a separate rollout gate.

  • Notes PR 2 foundation: conditional RTC bridge and targeted native operation compilation; requires the upstream conditional server release and API integration.

  • Notes patch foundation: support long sparse edits with bounded frontier alignment, preserving unchanged character runs.

An internal parser/serializer foundation supports exact inline and unified line patches through one character-edit representation, with owned application, Unicode/newline preservation and bounded validation. This PR does not expose new CLI/API commands or change document persistence. Atomic RTC commits and ordered client/rich-content milestones remain separately tracked. Development status. Merge, package release, deployment and live verification remain separate gates.

Available — Notes browser links, 2026-09-24

The Notes guide and generated dreamlake-notes skill now distinguish browser URLs (owner namespace plus full note ID) from CLI lookup (ID, slug or title), and from native #note: references. This prevents broken links made from note slugs. Documentation correction only; no routing behavior changes.

Available — Notes legacy revision diffs, 2026-09-24

Notes read/edit ETags now identify retained, note-scoped content snapshots. The namespace-scoped diff endpoint and Python note.diff(since=etag) compare a saved reference with the current body. Existing conditional patch writes use the same reference. Local drafts also support applying unified diffs and inspecting the last local edit. CLI 0.26.2 selects this ETag interface with --legacy; Python SDK 0.20.0 remote patches select it with legacy=True. Notes guide.

Deployed — Notes history and sync recovery, 2026-09-19

Notes adds view-only time travel with playback, individual edit steps and a resizable viewer. The sync indicator now checks a server-generated revision and checksum; normal concurrent edits and delayed checks do not pause sending. Replacement and composition handling preserve selection, reconnect replays only compatible pending operations, and an Out of sync ▾ dropdown lets you download a held draft, download edit data as JSON, or use the server version. Blockquotes now have consistent top and bottom spacing. Lossless RTC checkpoints preserve character identities across refresh. Usage and recovery; implementation and release status. Frontend PR #353 is merged; production includes the edit-data followup at a8f4e05 (Netlify deployment 6aaf1e954e62a90008e9f01c). Followup PR #354 CI and merge are tracked separately from that verified deployment. See the development note for the API, RTC, CLI and documentation release receipt.

Unreleased — Notes placeholders, 2026-09-18

Bracketed prose such as [ xxxxx ] and [ owner name ] appears as a blue highlighted [ text ] box with placeholder on hover in the Notes editor, tables and read-only view. Markdown references, links, task markers, code, and note references keep their existing behavior. Source text is unchanged. The Notes guide and distributed Notes skills document the convention.

Unreleased — docs-first skills and installation consistency

Notes examples now establish the revision before using $REV, distinguish the Python SDK from the standalone CLI, and retain the addressing guidance previously maintained only in the skill. The docs-to-skills procedure defines committed-source synchronization, provenance and separate publication checks. AGENTS.md and CLAUDE.md require docs-first maintenance; a docs CI job checks generated references and code-tab exports. Public skill source synchronization and hosted publication remain separate delivery steps.

Artifact installation now includes its authoring companion. Artifact and env instructions use the existing Git/symlink update path, workflow instructions use the standalone CLI and auth env list, and the Tasks guide/skills point to the dated delivery receipt instead of claiming delivery-branch-only status.

v0.1.22 — billing guide, 2026-09-18

Added billing and credits, covering the pricing preview, included usage, GPU bundles, bring-your-own-compute estimates, and planned billing controls. Paid checkout remains unavailable.

Unreleased — a real 404 on the docs site

Unknown URLs on docs.dreamlake.ai now serve a proper not-found page with an actual HTTP 404 status. The old /* -> /index.html 200 SPA catch-all in netlify.toml answered every broken link with the homepage; the site is fully prerendered, so the catch-all now rewrites to the prerendered 404.html instead. The error page renders inside the normal docs shell with the requested path echoed back, a search hint, links to the main sections, and a distinct "something went wrong" variant for render errors (Vike's is404). The page is excluded from the Pagefind index. Verified locally with netlify dev status-code checks and light/dark screenshots; live verification follows the next docs deploy. Development note.

Deployed — sim playback in sources (MuJoCo & URDF), 2026-09-17

Recorded simulator trajectories now play back kinematically in the dashboard. New mujoco and urdf dataset-viz views scrub a shared timeline in 3D with a Ctrl/⌘+wheel zoom gate (dreamlake-ai #327/#328, viz-workspace #121/#122/#123). hand_teleop records parquet datasets directly under a named-channel contract with one model snapshot per dataset, and converts its legacy npz recordings (hand_teleop #1); a generic conversion contract covers any MuJoCo/URDF trajectory, documented in the sources guide and the skill (dreamlake-skills #10). hand_teleop passed 368 tests including bit-for-bit scatter-back; dreamlake-ai passed 1745 unit tests and the production build; the eight-item local E2E checklist and Playwright smokes on deployed staging and production passed for both views. dreamlake-ai staging and production run 932cdac; production demos are fortyfive/sources/sharpa-teleop and fortyfive/sources/g1-dance (kept private — CC BY-NC-ND 4.0 retarget data). The pre-existing host-runs.spec.ts e2e failure on dreamlake-ai main is unrelated and unfixed; the viz.dreamlake.ai option-level reference for the two views remains unwritten. Ge review/testing remains separate. Development note.

Unreleased — Vault environment-file guide

Added a guide for uploading and restoring development and production .env files using the existing CLI. No Vault runtime behavior changed.

0.1.19 — Compute replaces the standalone Hosts view

Frontend PR #310 consolidates host inspection under /:namespace/compute, using the Sources layout, pattern search and a prefix eyebrow. Old host list/detail links redirect on production. Enrollment instructions and tracked-run lookup remain available; host APIs and CLI commands are unchanged. Inventory loads all API pages and polls visible tabs every ten seconds. Migration and validation. Frontend PR #310 is merged and deployed to production; signed-in browser verification confirmed the inventory and updated sidebar. Developer-only entries appear with [ dev ] badges via Cmd+Shift+D. The resize handle follows the theme. Staging rollout remains separate.

Unreleased — shared code tabs across the guides

  • Linked-note extraction preview: raw #note:<id> references, inline ID/title badges and full-height right panels. Guide. Frontend production deployment remains pending.

Twenty-two pages now use Dockit 0.2.25 code tabs for alternative examples, including host enrollment and credentials, Notes, providers, installation and developer plans. The obsolete local tab component is removed. Markdown exports retain tab labels and preserve fenced placeholders, whitespace and links. Audit, task list and validation.

0.1.18 — code tab hover edge

The first tab aligns with the code block. The panel’s upper-left corner joins it squarely when selected and rounds when another tab is selected. Inactive tabs keep their top and side hover outline without a bottom border. The toolbar aligns with the right edge, with an 8px gap between the line-number and Copy buttons.

0.1.17 — code tab surface and hover

The active tab matches the code area. Both upper panel corners are rounded, and inactive tabs gain a subtle border and color on hover.

Unreleased — Vault writer fleet audit

Read-only fleet audit traces both deployed Main writers and the other 11 ECS services to their runtime sources. Staging172 and production122 use epoch-aware1058 with migration disabled; archived retired-task stop evidence is preserved. The proposed hosted staging migration procedure remains review-only, with no flag or cloud changes.

Unreleased — affected-entry policy preview

KMS preview optionally returns bounded retained-entry metadata with current/proposed policy comparison and context-bound cursors. Ordinary preview is unchanged. The page and summary share one Mongo snapshot; later pages are separate observations. No values or provider calls are involved. Scope and validation.

0.1.16 — Vault policy tree and acceptance guides

The credentials guide adds paired CLI/Python owner-only policy-tree examples. Updated development notes distinguish published Python 0.17.0, incomplete CLI 0.22.0 publication, API acceptance, and remaining retention and host lifecycle work. Raised code tabs from 0.1.15 are preserved. This is a documentation release; it does not publish clients or change service configuration.

0.1.15 — folder-style code tabs

Code tabs match the raised chat-tab style: rounded active-tab corners, a faint outline and a baseline that opens into the code panel. The row stays compact and page-colored.

0.1.14 — compact UIKit code tabs

Code tabs use UIKit’s standard controls, reduced vertical padding and the page background. Usage stays the same.

Unreleased — native SSH control-plane sessions and relay

Control-plane PR #53 merged durable sessions, signed capability advertisements, one-use tickets, authorization leases and a WebSocket relay with bounded queues and directional FIN. Local timers close sockets on expiry, including while database reads stall; durable ownership fences replaced relay processes. Local and Linux CI checks passed: 41 real-Mongo HTTP/WSS tests and 720 unit tests (14 skipped), including a 32 MiB paused-receiver transfer. Nymph publication/dispatch/lease handling, native CLI integration and end-to-end SSH remain open. The relay is disabled by default; no runtime or schema rollout has occurred. Validation and remaining work.

Unreleased — native SSH grants

Control-plane PR #52 merged authenticated admin-only grants for an exact namespace and worker, with transactional duplicate/capacity checks and revoke/regrant semantics. Ten real-Mongo HTTP checks passed, covering authorization, restart persistence and revocation races; the existing suite passed 717 tests with 14 skipped. Linux CI passed the same suites, and complete-server startup/denial checks passed. Sessions, relay and native CLI integration remain open; no SSH access is released or deployed. Scope and validation.

Unreleased — native SSH backend proof

The isolated same-user OpenSSH backend passed eight native SSH/SFTP checks on bos14, including binary half-close, PTY, identity/host-key rejection and forwarding denial. Strict ownership checks remained enabled; temporary keys and files were removed. The SSH draft also incorporates current Nymph ownership and claim admission: 422 all-features tests passed, followed by 283 focused tests after a formatting-only correction. Both current-head Linux CI workflows passed, including 428 all-features tests with 12 ignored. This is a backend prerequisite, not a released Nymph SSH service or NAT relay. Evidence and remaining work.

Unreleased — current Vault examples and acceptance boundaries

The credentials guide adds paired candidate policy tree commands and corrects superseded enrollment/cleanup status. The runtime note links scoped key-failure, browser recovery and retention evidence without claiming all host or backup obligations complete. The terminal metadata note preserves the failed timeout and successful repeat, and requires old API processes to stop before acceptance. No package, docs-site or production completion is inferred.

Unreleased — Lakeshore host guides

Host enrollment, credentials, remote agent setup and run monitoring now live under Lakeshore. The live UI walkthrough is part of testing; Vault-backed runs sit with Run Configs, and registration/resource setup with Providers. Old host-guide URLs redirect to their new locations.

0.1.13 — integrated guide code tabs

The host testing guide uses Dockit’s shared tabbed code block for CLI/Python examples, keeping keyboard navigation, code controls and both Markdown examples. Uses published Dockit 0.2.21; desktop/mobile/dark screenshots and a read-only browser check are included in the development note.

Unreleased — enforce AWS Vault request timeouts

A candidate fix makes the SDK request deadline throw instead of merely logging a warning. The real TLS regression covers three stalled attempts, sanitized errors and recovery; the preceding real-AWS test failed at its 65-second safety guard and cleaned up all temporary resources. A second owned real-AWS test passed bounded read/resume failures, unchanged entry/checkpoint and same-process recovery, with complete permission cleanup. Runtime deployment remains pending. Evidence and runnable test.

0.1.12 — Published host recovery clients

Nymph 0.1.8 is published with exact public artifact verification. The owned production host passed one-launch crash/restart uncertainty checks through CLI 0.21.2, Python 0.16.2 and browser reload, with cleanup verified. Hosted terminal-result clearing is not claimed. Host examples retain historical receipt versions. Release verification and manual checks.

Unreleased — bos14 GPU configuration diagnostic

A bounded job reproduced zero allocated GPUs despite requesting one. The worker has local Slurm/GRES files and no configless cache; controller configless enablement alone does not establish worker configuration delivery. The job completed and its fixture was removed. A follow-up confirmed worker/controller configuration drift, but did not prove it causes zero allocation; merged-GRES inspection failed during protected cgroup initialization. Both diagnostic fixtures were removed. No cluster changes, GPU readiness or device isolation are claimed. Diagnostic evidence.

Unreleased — Current-source Slurm acceptance

The reconciled API, control plane and worker passed bos14 CPU probe/workload checks with published CLI 0.21.1 and Python 0.16.2. Delayed delivery and a lost response recovered the original timeout without dispatching the expired request. Owned cleanup passed. Host identity was seeded; production rollout, GPU/browser acceptance, missing-history policy and claim-v1 Slurm remain open. Dated results.

Unreleased — Slurm protocol integration

Draft Nymph #31 and control-plane #29 preserve private-run authorization while reconciling Slurm with current main. Real Mongo/HTTP and paired process checks passed, including one submission/result across lost responses and restart; scheduler commands were fixtures. Unsupported claim-v1 Slurm requests are rejected before staging or result delivery; envelope-free requests retain the sink capability check. Paired admission/recovery, release and live acceptance remain open. Development note.

Unreleased — owner-only Vault policy tree

A backend candidate adds paginated metadata-only prefix/entry rows with inherited policy, configured key identifiers and current-epoch migration state. Seven real HTTP/Mongo tests include concurrent cutovers, large history/prefix inventories and tenant denial; no KMS payload reads occur. CLI 0.22.0/Python 0.17.0 candidates now provide paired tree views, with local real HTTP/Mongo/PTY and staged live pagination checks. Python 0.17.0 is now published and both frozen archives were byte-verified; fresh no-cache PyPI installation and production metadata-only tree verification passed. The initial unexplained install failure remains in the receipt. CLI 0.22.0 publication is incomplete. Production API task 122 passed tree pagination after the retired-process stop gate; both synthetic entries were retired/read404 through recorded reconciliation. Production UI export/disabled-retry checks passed. These scoped results do not claim physical purge or production private-run activation. Development note.

0.1.11 — Recovery testing guide

Added paired CLI/Python inspection commands and the real API/CP/Nymph/browser recovery acceptance procedure. It distinguishes an uncertain running receipt from cancellation and terminal results. Isolated tests passed; hosted recovery and Nymph release acceptance remain pending. Evidence and manual test.

Unreleased — partial private materialization acceptance

An isolated actual main/CP/Nymph test now proves first-mapping cleanup when the second file materialization fails: no permit or task launch, both saved entries preserved, and a fresh intentional retry succeeds. Independent full rerun and three real process-cleanup tests passed. This uses an older CP pin, synthetic local encryption and a test-only CA; hosted UI recovery remains open. Dated scope and runnable evidence.

Deployed and verified — Queue mount action scope

UI #291 deployed staging source 5f18ef6; #293 deployed production source 9c739b3. Both passed CI and real hosted checks for mount-only exclusion of daemon enrollment, retained editor/resource controls, legacy launch availability and fixture cleanup. Separate readbacks confirmed the mounts and Vault copies absent and the original legacy connections healthy. Ge acceptance and new-connection creation remain separate. Evidence.

Unreleased — Queue mount action scope

UI PR #280 merged after all four remote CI jobs passed. Queue mounts hide unsupported daemon enrollment controls; legacy connections retain them, and mounts retain token editing and resource tabs. Staging PR #291 preserves the published Notes preview and includes formatting corrections verified by 13 affected component tests. Deployment and hosted acceptance remain pending. Scope and status.

Deployed and verified — Existing mount token editor

UI PR #277 is deployed to staging and production at 38cd75e. Real Chromium checks passed without API mocks: read-only identity, hidden required token, rejected-write recovery, token-only keyboard retry and clearing the token on reopen. Independent checks confirmed temporary mounts and Vault copies removed. Both runs used the development Lakeshore endpoint; new connection creation and Ge review/testing remain open. Deployment evidence and scope.

Verified — production queue mount API and CLI

Production task119/source95ba146d passed mount lifecycle, empty-queue controls, monitoring, denied enrollment proxying, token replacement and released CLI0.21.1 reads through the existing development Lakeshore namespace. The running image matched ECR after rollout completion. Independent cleanup confirmed the temporary mount/queue absent, both new Vault copies retired and the original development mount healthy. No jobs or workers were created. Production worker execution, browser acceptance and Ge review/testing remain separate. Receipt and scope.

Released and verified — CLI 0.21.1 queue mounts and Vault transport

CLI 0.21.1 combines queue-mount operations with the native Vault uncertain-write fix from 0.20.2. All eight native/npm binaries and the wrapper verify against the reviewed artifacts; a fresh npm installation passed version/hash, 34 SSH/import checks and HTTP mount/list checks. Public native development-mount reads also passed without mutations. Native and npm latest both resolve to 0.21.1. CLI docs and the version snapshot are published with 48 served files verified per deployment. Production mount/browser acceptance and Ge review/testing remain separate. Release, evidence and limits.

Released and verified — Nymph 0.1.7 owned Linux upgrade

Nymph 0.1.7 publication bytes verified across the versioned CDN, GitHub assets and latest installer objects. The public Linux x86_64 binary passed version/help execution on bos14, then replaced only the owned acceptance daemon binary with a retained rollback copy. Configuration, key and unit text stayed unchanged; the running executable hash and fresh signed readiness verified the valid git/uv startup preflight. No standalone broken-tool test or broader hosted timeout acceptance is claimed. Dated receipt and limits.

Unreleased — Private run terminal metadata

Private reconciliation preserves the first owner/deadline cancellation cause and reports confirmed deadline cancellations as timed out. Valid worker claim/setup timestamps are retained as startedAt; this is not proof of user-process spawn. Grant states remain separate from input cleanup. Scope and validation. Source only; hosted verification remains open.

Released — CLI 0.20.2 transport patch

CLI 0.20.2 fixes hidden native PUT/DELETE retries after dropped pooled connections. All eight public native binaries/manifest and source tag verify; a fresh public macOS binary passed 34 HTTP/PTY checks. At the 0.20.2 publication checkpoint, native latest resolved to 0.20.2; the combined 0.21.1 release above now carries the same fix. The patch is based on 0.20.1, excluding later queue/Notes work. All eight npm platform tarballs and the wrapper also verify, and a fresh npm installation passed the same 34 checks. Concurrent npm latest 0.21.0 was preserved; next read back as 0.20.2. Use the exact package version to select this patch. Release and bounded evidence.

Verified — production host process execution and isolated reboot

Released Python 0.16.2/CLI 0.20.1/nymph 0.1.6 passed production no-save enrollment, process success/logs, cancellation and signed reconnect on a dedicated bos14 enrollment; existing daemons were preserved. The host and SDK/cancellation receipts were verified in the production UI. A separate disposable EC2 machine passed actual reboot recovery. SDK main now includes the SSH fix and Notes baseline dependency correction (948 tests passed/60 skipped); no new package release. The combined API queue-mount guard rollout remains separately tracked. Host Dev Note · Production review.

Verified — browser cancellation and saved-entry preservation

One browser-requested cancellation reached terminal cancelled after the task-ready marker appeared; API/UI and independent SSH inspection verified both materialized inputs cleaned. Metadata-only Python0.16.1 readbacks confirmed the two saved entries remain at revision1 with no retirement or expiry. Automatic timeout, partial transfer, authentication and uncertain-write coverage remain separate. Dated cancellation receipt.

Verified — staging170 browser-submitted Vault task

One authenticated browser submission completed the pinned remote task with the selected synthetic environment value and file bytes. UI/API showed success and both mappings cleaned; SSH confirmed the ready marker and credential-stage cleanup. API source95ba146d, signed capability and UI source4da4f98d are recorded; 13 original-tab assets match the current public and immutable deployment bytes. PR545 is not deployed and timeout classification remains open. Dated receipt and scope.

Verified — staging169 hosted Vault execution

Published CLI 0.20.2 and Python 0.16.1 succeeded on the owned bos14 enrollment through staging169; owner cancellation also reached its terminal state. Independent ready markers, absent input stages and cleanup journals corroborate the API's two cleaned inputs per case. Automatic timeout cleaned both inputs but incorrectly returned cancelled/-3 instead of timed_out. The null startedAt is a CP claim/setup reconciliation gap; permit_reserved intentionally tracks grant reservation and is not a terminal-process defect. Browser/expiry/recovery acceptance and the broader issue remain separate. Dated evidence and frozen receipts.

Verified — mixed-provider KMS example

Examples #40 merged with seven live phases through owned local Vault HTTP/Mongo and actual AWS/Google KMS, using published CLI 0.20.1/Python 0.16.1. Forward/reverse migration, retained replay, provider denial/recovery and cleanup passed. All five temporary permission resources were removed; existing keys and grants were retained. This is local real-service/cloud acceptance, not hosted deployment, customer onboarding or a second live AWS region. Dated evidence and limits.

Unreleased — Vault reference and native transport audit

Correct the credential guide to show published CLI 0.20.1/Python 0.16.1 HOTP import, explicit activation and durable issuance recovery with paired examples. Real native HTTP/PTY checks exposed a pooled-connection PUT/DELETE retry; candidate CLI #83 fixes it (34 native import checks,9 compiled transport checks and 1,251 source tests pass). Installed Python 0.16.1 passed 69 bounded parity tests. This is a guide correction and unreleased candidate, not hosted acceptance or broad checklist completion. Dated coverage and limits.

Released — Python 0.16.2 noninteractive SSH

Published Python 0.16.2 fixes password prompts from ProxyJump by detaching SSH and disabling askpass; key/agent access remains supported and CLI password behavior is unchanged. The isolated patch excludes unrelated Notes changes. Reviewed artifact hashes, fresh PyPI installation, 20 installed host tests and the actual OpenSSH matrix passed; the source suite passed 669 tests with 60 skips. A separate published-SDK process succeeded on the retained staging demo host. This is not re-enrollment, reboot recovery or production acceptance. Release · Host development note · Manual checks.

Staging deployed — Vault-backed queue mounts

Staging task 168 runs source 24215a76. Queue mounts store namespace access tokens in Vault and expose scoped queue/job/worker reads, queue controls, statistics and JSON events. Connection responses distinguish mounts from legacy registrations without returning credential references. Unsupported execution connections are rejected before host or ordinary tracked-run admission.

Real staging mount, owned queue controls, monitoring, token replacement and denial checks passed, followed by independent queue/mount/credential cleanup. No jobs or workers were launched. Bulk queued cancellation and invalid-upstream health handling have source regressions; those scenarios were not part of this live check. Production, CLI publication and dashboard acceptance remain separate. Dev Note.

Released — CLI 0.20.1 and Python 0.16.1 persistent host enrollment

Published patch clients explicitly configure enrolled Nymph services to remain available when idle. Native/npm CLI 0.20.1 and PyPI Python 0.16.1 artifacts passed public byte verification and fresh installed checks; patches exclude unrelated Notes changes. Re-enrollment regenerates configuration, so restore custom private settings afterward. The same owned bos14 enrollment passed actual idle intervals beyond 300 seconds with each published client, unchanged process IDs and zero restarts. This does not establish reboot recovery or hosted Vault execution. Validation and release receipts.

Staging verified — private-run connection identity

PR524 canonicalizes frozen Mongo connection references while preserving the original pin; malformed, missing or changed identities remain denied before control-plane transport. Real-Mongo regressions and full CI passed. Staging167 settled at09:17:07UTC on narrow source 1553a62a, with exact image provenance, health200, alarmOK and unchanged non-target task/deployment settings. Personal capability and fresh owned-worker signed readiness passed at that checkpoint; KMS migration remained disabled. A later external task168 rollout reset private-run configuration and is in progress. The second hosted launch ended dependency_failed before execution, with both inputs and the worker stage cleaned. An owned standalone uv fix is configured, but fresh readiness and a third launch remain pending. No hosted execution success or production change is claimed. Development note and receipts.

Unreleased — personal namespace private-run capability

Corrects the capability lookup for personal namespaces whose Mongo organization/deletion fields are absent. Ownership and organization exclusions remain enforced. The narrow patch is deployed and verified on staging task165: authenticated capability is enabled and fresh signed owned-daemon readiness passed. No production rollout or hosted execution acceptance is claimed. Development note.

Unreleased — Vault cleanup configuration

Forwards existing entry cleanup settings through deployment without changing defaults. No current deployment or retention change is claimed. Development note.

Unreleased — CLI package release validation

CLI #29 merged, preparing version 0.2.1 with test/build/pack gates, clean-install HTTP checks and fail-closed publication. Local and Linux package validation passed; all three native builds passed, with runtime HTTP checks on Linux x64 and macOS arm64. Release credential setup remains pending. No package publication is claimed. Development note.

Unreleased — CLI cancellation intent

Lakeshore CLI #27 merged: jobs kill distinguishes accepted cancellation from a terminal result; list/show display intent separately and JSON output is preserved. Local TypeScript/Node checks passed (653 tests, one skipped). Package release and installed-client acceptance remain pending. Development note.

Unreleased — code block controls

The docs adopt Dockit 0.2.20, which adds a soft, blurred background behind floating copy and wrap controls so code underneath does not distract from the buttons.

Unreleased — Vault KMS provider and region routing

Adds routing for canonical allowlisted AWS regions and Google KMS keys while preserving existing managed defaults. Prefix references can select their provider; recorded envelopes remain readable across migrations while old routes stay configured. No schema backfill, deployment or customer IAM onboarding is claimed. Contract and rollout note.

Unreleased — Vault delivery checkpoint and task dashboard

Staging backend task 163/source cb73cee is healthy with 232 index contracts verified; private execution and KMS migration remain disabled. UI269 is deployed to staging with authenticated disabled-state review, not enabled remote-run acceptance. Isolated EKS retention/cleanup examples #38 merged 8e4ba61c; its route-injection/synthetic-host scope excludes published-client/SSH/natural-production acceptance. Nymph 0.1.6 is published and verified: 14 GitHub assets, 15 latest/installer object readbacks and a fresh default installation. Sanitized receipt. Shared-host rollout and enabled hosted execution remain open. Retention deployment configuration #500 merged after full CI with existing defaults preserved; no additional deployment is claimed. Dated note.

Project tasks and private Waterfall 23 are published: 113 records, 72 original source requirements (54 checked), plus separately counted delivery/retention checks. Exact payload bytes and task readback were verified. Unknown times remain blank.

Unreleased — production-daemon private acceptance

Actual production Nymph enrollment/poll/claim, success/cancel/expiry and normal shutdown passed on owned bos14 using published CLI 0.20/Python 0.16. Exact candidate provenance and cleanup are recorded; no shared daemon rollout is claimed. Development note.

CLI 0.20.0 and Python 0.16.0 published; staging index migration verified

Python 0.16.0 is published to PyPI with both public artifact hashes verified. Native CLI 0.20.0 is published after release76, with all eight binaries and manifest hash/size verified. npm 0.20.0 is also published: all eight platform tarballs and wrapper source bytes are verified, a fresh installed client passed binary SHA/version/capability-help checks, and public latest/next both read 0.20.0. Nymph32/45 are merged and the fresh bos14 pipeline evidence489 passes with the termination-fixed source runtime. The remote pipeline receipt uses source clients; it does not establish a full private run with installed packages or hosted activation.

Staging 162's explicitly approved Bindr index migration created/verified two canonical indexes and dropped only the reviewed legacy constraint. Fresh read-only inventory passes 232 contracts / 87 collections with no remaining additions/blockers/duplicates/parallel arrays; the application task/source/digest did not change. Index-safety note and immutable migration receipt. Backend application deployment499 later verified staging 163; enabled hosted Vault acceptance remains pending.

Staging UI deployment: UI #269 is merged and deployed to staging; authenticated disabled-capability review passed, while enabled remote-run acceptance remains open. It submits only reviewed/pinned mappings with consent, offers complete metadata-only recovery exports and paired CLI/Python recipes, guards unresolved close, and shows entry/output labels with mapping status. Read the command guide and version/hash/acceptance note. Main/CP configuration and a fresh compatible fixed worker remain required; no obsolete unfixed-bug gate is used as a substitute for checking actual deployed capability.

Unreleased — attempt-scoped cancellation API

Control-plane #44 is merged. Running cancellation records intent without claiming termination, and requires support in the worker's current signed poll. Replacement workers cannot inherit a stale cancellation advertisement. Unsupported workers retain 409. No control-plane deployment or worker capability activation. Development note.

Unreleased — retain ordinary invocations during termination refusal

Nymph #44 is merged. Cancellation keeps the original child, task and capacity until ownership checks permit verified termination. Body/setup and daemon accounting regressions passed on Linux. Persistent refusal keeps shutdown pending; recovery after losing the child handle remains open. No package release or worker deployment; existing 0.1.6 artifacts are unchanged. Development note.

Unreleased — Linux streaming cancellation acceptance

Draft Nymph #38 passed eight paired Linux scenarios, including termination refusal without premature acknowledgement. The saved evidence records a collector parsing failure and its reconciliation. Recovery cancellation and uncertainty resolution remain open. No runtime release or deployment. Development note.

Unreleased — retain executions with unknown completion

Draft Nymph #38 retains reserved capacity when recovery lacks terminal evidence. The new actual-daemon regression passed across two replacements without rerunning or acknowledging the job. Resolution and cancellation of uncertain executions remain open; cancellation capability is disabled. No runtime release or deployment. Development note.

Unreleased — fresh private termination pipeline acceptance

Owned bos14 success/cancel/expiry passed with the new Nymph termination fix and current CLI/Python sources over actual main/CP HTTP. Inputs, processes, tunnels and owned fixtures were cleaned. This does not establish installed-client or hosted activation. Development note.

Unreleased — full-worker streaming heartbeats

Draft Nymph #38 keeps full workers polling and consumes cancellation while frame delivery is blocked. Six paired daemon/Python cases and 403 local tests passed. Recovery and Linux streaming-refusal acceptance remain open; cancellation capability is disabled. No runtime release or deployment. Development note.

Unreleased — termination refusal candidate

Draft Nymph #44 retains the original child while cancellation cannot verify termination. Linux reproduced the premature failure result; the candidate adds runner and daemon acknowledgement regressions. Streaming/recovery acceptance remains open. No runtime release or deployment. Development note.

Unreleased — explicit private run configuration and discovery

Adds validated operator opt-in for private setup delivery and account-authenticated server capability metadata, with CLI/Python discovery parity. Defaults remain disabled; discovery does not claim a worker is ready. Operator setup.

Unreleased — active streaming cancellation

Draft Nymph #38 consumes signed cancellation intent for fresh executions with a known attempt. Five paired daemon/Python cases and 403 local tests passed. Recovery, blocked-frame cancellation and ownership-refusal accounting remain open; no cancellation capability or runtime deployment is enabled. Development note.

Unreleased — process-group cancellation fix merged

Nymph #42 merged after both Linux CI jobs and isolated shared-host container checks passed. Ten ownership tests and five cancellation-test repetitions passed while a separate supervisor process continued running; cleanup was verified. Package release, worker rollout and queue cancellation integration remain open. Development note.

Unreleased — owner private setup issuance and dispatch

Connects gated owner run submission to revision-pinned credential delivery and private CP execution intent, with original-key capability checks and lost-reply/cancellation recovery. Signed CP/main/Nymph transport passed on disposable HTTP/Mongo/verified-TLS fixtures; repository execution and deployment remain pending. Evidence.

Unreleased — private execution authorization binding

Permit creation now serializes namespace/host/enrollment/capability changes and rechecks expiry around persistence. The permit also cannot outlive its verified authority window.

Adds shared TypeScript/Rust execution hashes, signed selected-input delivery with checks around KMS, immutable five-second attempt permits and metadata-only cleanup receipts. The runtime adapter is disabled by default with no environment enable flag; hosted capability issuance and remote execution remain disabled. Development evidence.

Private execution API472 merged at 6bbbf8f after full CI on e216b58; no backend deployment or private-submission enablement is claimed. The permit-expiry and enrollment-key race fixes landed in 6a26580 with 146 focused tests and typecheck passed.

A real bos14 attempt failed because the workload could not locate its credential file. Nymph candidate 2a33ea1 now uses an owned sibling credential directory and task-only DREAMLAKE_SECRETS_DIR; 15 focused tests passed. The corrected binary passed actual bos14 success and owner Python cancellation, each with two materialized and two cleaned mappings; both fixtures stopped. Permit-expiry refusal also passed with no task spawn and both mappings cleaned. Receipts record all three cases and owned cleanup; the fixture uses synthetic KMS and a test-only CA.

Shell/Python examples now show explicit file consumption. CLI74/Python55 are merged after review and actual success/cancel acceptance; packages remain unpublished. Reconciliation481's staging storage/index assertions pass, while the 276-test member-authorization fix passed review and awaits integration/final CI; combined deployment acceptance remains open. Remote delivery note.

Unreleased — shared staging Bindr reconciliation

A separate deployment-index candidate replaces unconditional schema push with hash-pinned additive reconciliation. Settled staging 162 read-only inventory found two missing canonical Bindr indexes and the older unique constraint; a separately reviewed, target-pinned Bindr migration creates and verifies replacements before the sole explicit drop. Failure-only CI artifacts preserve sanitized refusal plans. Private-run configuration is forwarded with default-off behavior and unset origins omitted. Forty focused tests and typecheck passed at review; the later authorized staging index migration is recorded above, while application deployment remains pending. Index safety note.

The PR481 review fix independently authorizes filed resources on writes, display and search. Foreign or unavailable legacy references reveal no resource identifiers or metadata; legitimate grants remain supported. No shared database or deployment changes. Development note.

Read-only staging inventory confirms canonical storage/indexes and zero legacy arrays or duplicate tuples. One empty Bindr under a retired project is preserved for lifecycle review; no shared data or index changes were performed. The repeatable inventory includes real Mongo and credential-safe failure tests.

The isolated #387 candidate preserves deployed Bindr trees and membership while restoring transactional Source-reference cleanup and legacy delete compatibility. Schema/data/index and fleet checks remain rollout gates; no shared database or deployment is changed. Runtime note.

Unreleased — GCP refresh, denial and cleanup acceptance

Examples37 merged at 33690f3 with receipts pinned to 8196b60. It adds actual same-process ADC refresh across both token expiries, KMS denial after permission revocation, fresh-process federation denial and owned Kubernetes/IAM cleanup receipts. The pool is disabled and soft-deleted; its service account, key and STS API remain. This is isolated acceptance evidence, not hosted production or physical-erasure proof. Prefix KMS note.

Unreleased — Unix cancellation exit windows

Draft Nymph #42 extends bounded ownership rechecks to the macOS exit window and uses normal stdin closure for the non-group refusal fixture. Final local suite: 372 passed, eight ignored. Linux CI and shared-machine acceptance remain pending. Development note.

Unreleased — completion race and Linux ownership retry

Draft Nymph #42 preserves completed success/failure when cancellation is also ready. The candidate bounds ownership retries after Linux CI exposed escalation failures; a persistent-denial test checks that failed verification never permits signaling. 372 local tests passed, eight ignored; Linux CI and shared-machine acceptance remain pending. Development note.

Unreleased — Vault private execution and GCP acceptance checkpoint

Private setup validation 379 merged after full CI. CP30 merged at 65b8aca after CI; execution-hash API472 and Nymph32 remain review candidates; complete private delivery is not enabled. Remote delivery note.

The GCP default-ADC fixture examples36 merged. Follow-up examples37 passed actual ADC exchange, required KMS denial and isolated HTTP/Mongo core/two-owner, pagination and HOTP groups with published CLI0.18/Python0.15; refresh, revocation and cleanup acceptance remain open. This is test infrastructure and evidence, not a product deployment. Prefix KMS note.

Unreleased — retained process-group termination

Draft Nymph #42 now passes the TERM-ignoring descendant regression by retaining child ownership through the final group signal. 371 local tests passed, eight ignored. Linux CI, completion-race coverage and shared-machine acceptance remain pending; queue cancellation is not enabled. Development note.

Unreleased — process-tree cancellation regression

A new regression shows that Nymph can return killed while a SIGTERM-ignoring descendant continues executing. Nymph #41 and draft #42 track the unfixed case. Queue cancellation activation remains blocked; no runtime fix or release is included. Development note.

Unreleased — private setup contract validation

Adds pure repository/commit/mapping/consent validation and a distinct internal execution kind. Current run submission explicitly rejects setup before persistence or CP dispatch; no fallback to logged execution. CLI/Python private runs and credential delivery remain unavailable. Pipeline plan.

Tasks — shared layout and controls, 2026-09-14

Uses Notes' page layout and shared action/search components, with UIKit sliding folder/waterfall controls. Removes the separate Tasks hero and custom toggle; keeps the toolbar compact on narrow screens. UI264 · Development note.

Unreleased — signed cancellation-control read

Draft Nymph #38 reads cancellation intent for a known accepted attempt with an enrolled worker signature. Matching running intent returns true; terminal intent returns false; mismatches and errors do not authorize cancellation. Real Rust/CP signature checks and cleanup passed; the full worker suite passed 399 tests. Automatic consumption, owned termination and deployment remain pending.

Unreleased — cancellation attempt identity

Draft CP #44 dispatches and cancels a specific attempt, with compatible ownership checks for ObjectId and legacy string worker assignments. 709 tests and actual signed dispatch/cancellation checks passed. Draft Nymph #38 retains the dispatched attempt across journal reopening; 397 tests passed. Legacy records remain readable with an unknown attempt. Worker cancellation integration and rollout remain open. See the Dev Note for the initial predicate failure and recovery compatibility limits.

Unreleased — signed frame worker identity

Nymph #39 includes the enrolled worker ID in signed frame bodies, as required by real control-plane authentication. The regression failed against the old encoder and passed with the fix. Integration rerun: 395 tests and three daemon/Python cases passed; the initial unrelated Slurm test failure is retained in the Dev Note. The fix merged at af8a065 after CI. Actual Rust-to-CP signature/Mongo acceptance and cleanup passed; runtime release and hosted streaming remain pending.

Unreleased — running invocation cancellation intent

Draft CP #44 adds durable cancellation intent for capable workers without marking a running job stopped. Signed control reads are scoped to the assigned worker and namespace. 708 tests and a real HTTP/Mongo check passed. Worker integration, client/UI display, paired acceptance and rollout remain pending; this is not deployed.

Unreleased — worker capacity and daemon streaming recovery

Merged control-plane #43 keeps queued invocation and exec work pending while a worker reports full capacity, without blocking heartbeats or control messages. Signed full-route/Mongo checks, 695 tests and CI passed. Development 7d8504f passed signed public HTTPS checks; both original workers reconnected and fixture cleanup passed. Production remains pending.

Draft Nymph #38 adds opt-in daemon startup recovery and capacity accounting for surviving Python producers. Three actual-daemon/Python checks passed, including daemon replacement without another producer execution. Hosted streaming, running API cancellation and runtime release remain pending. See the development note.

Unreleased — streaming execution recovery

Nymph #38 can recover reserved Python streaming executions without rerunning the producer. Recorded outcomes survive pending-record removal, acknowledged results stay delivered, and invalid or conflicting evidence is retained. Worker-scoped reservation discovery is implemented. Full tests passed at b5b5399; focused and paired checks passed at d49331c. Daemon startup integration, hosted acceptance and runtime release remain pending. See the development note.

Unreleased — worker-side producer fencing

Nymph can fence a stopped producer under the SDK's lock. Busy producers remain untouched; legacy handoffs cannot use fencing. The SDK validates the advertised capability. Its 279 unit tests and four paired checks passed; the combined Rust suite passed 385 tests, eleven ignored. Recovery-result classification remains pending. No release or deployment.

Unreleased — producer recovery fence

SDK #23 prevents another producer from starting before the first frame by recording startup under its lock and honoring a recovery fence. Refused handoff setup preserves prior output files. The SDK suite passed 273 tests, seven skipped; paired Rust checks passed. Worker recovery integration and release remain pending.

Unreleased — streaming terminal-result journal

The explicit streaming process API rejects path-like invocation IDs before staging. Its regression, integrated handoff checks and paired SDK/Rust checks passed.

The actual daemon restart check passed for seeded pending-frame and terminal-result replay: identical frame bytes were delivered before terminal acknowledgment after replacement. This does not establish recovery of an interrupted workload.

Nymph #38 journals completed streaming outcomes and delivers pending frames before the terminal invocation acknowledgment. Focused and paired SDK/Rust tests passed, including frame-response loss and replay ordering after client reopening. The combined suite passed 382 tests, ten ignored. Daemon activation and execution recovery remain unfinished; no runtime release/deployment.

Unreleased — explicit process streaming execution

Nymph #36 connects explicit process execution to private handoff provisioning and concurrent frame delivery. It reserves execution before spawn, refuses prior attempts and retains output for durable result handling. Three paired SDK/Rust checks passed; the full suite passed 372 tests, ten ignored. Daemon polling activation and restart recovery remain unfinished; no runtime release or deployment.

Unreleased — runner output retention

Nymph #37 adds an explicit retain-and-cleanup path for successful runner output, shared by pending artifact and streaming integration. The Rust suite passed 368 tests, seven ignored. Existing callers keep their cleanup behavior; the new path is not activated or released.

Unreleased — explicit Python generator streaming

SDK #23 connects generator yields to an explicitly configured worker handoff and persists result/error files before terminal frames. Its unit suite passed 268 tests, seven skipped. The paired Python entrypoint/Rust consumer fixture passed both success and generator failure after a yield, including terminal-file ordering. The real Nymph process runner also passed success, failure and cancellation while awaiting frame acknowledgment; pending bytes and diagnostics were retained. Nymph runner enabling, API-driven cancellation, deployed CP and worker-process restart remain unfinished; the drafts are not released or deployed.

Unreleased — Python/Rust handoff acceptance

The explicit paired-checkout test passed with a real Python producer and Rust consumer: response loss preserved pending bytes, reopening retried the same frame, and acknowledgment allowed the producer to advance. Terminal state and owned cleanup were verified. The CP endpoint was simulated; runner and deployed-runtime acceptance remain open. SDK #23 and Nymph #36 remain inactive drafts.

Unreleased — frame handoff consumer draft

Nymph #36 adds inactive durable frame consumption, paired with SDK #23. It checkpoints a matching acknowledgment before removing pending bytes. Local tests cover lost responses and reopening after failed cleanup: Nymph 368 passed/seven ignored; Python 266 passed/seven skipped. Real cross-process integration and runner activation remain open.

Unreleased — Python frame handoff draft

SDK #23 adds an inactive writer that keeps one durable frame pending until its worker acknowledges it. Producer-side tests cover retained bytes and acknowledgment checks; 266 unit tests passed, seven skipped. Worker integration and restart acceptance remain open. No package release or streaming activation is claimed.

Unreleased — result stream transport and truncated reads

Nymph #35 merged with signed frame uploads, encoded-request size checks and matching acknowledgment validation. Both CI jobs and 366 local tests passed (seven ignored). Python SDK #22 merged with an error for HTTP EOF inside an unfinished frame; 260 tests passed (seven skipped), including two regressions reproduced before the fix. Neither change is released or deployed. Child-to-Nymph streaming remains unwired.

2026-09-14 — Python SDK 0.4.0

0.4.0 is published on PyPI. It includes run declarations, lifecycle helpers, namespace authentication and verified downloads of artifact-backed invocation results.

RunConfig() now defaults to runner="process". To retain Docker execution, set runner="docker" and your image explicitly. See the migration note. A fresh PyPI installation and both published distribution hashes were verified. A remote PyPI installation also passed Python exception delivery and same-ID retry checks through two temporary workers on the development control plane; one execution and fixture cleanup were verified. Server/worker artifact support is not deployed by this package release.

Unreleased — large invocation results

Python SDK #20 is released in Python SDK 0.4.0 with verified artifact downloads. Worker and control-plane artifact support remain drafts and are not deployed. Real S3 and local actual-daemon restart checks passed with one fixture execution, unchanged accepted results and verified cleanup. Retention, storage configuration and hosted/provider acceptance remain open. Development note.

Unreleased — invocation result retries

CP #41 preserves results and completion timestamps when a worker repeats an acknowledgment. Conflicting outcomes return 409. Local signed Mongo/HTTP retry and race checks passed. CI passed and development runs 50d68bb; public signed retry/race checks, fixture cleanup, fresh original-worker polls and public health passed. Worker result persistence, running cancellation and Ge acceptance remain pending. Development note.

Unreleased — queue filters and demand counts

CP #40 fixes Mongo errors in queue-filtered job listing and bulk cancellation. Stats and scaling count queued work in the database instead of loading every queued payload in the namespace. Typecheck, 690 tests (12 skipped) and real-Mongo checks passed. CI passed and development runs f5b5f15. Hosted filter/count/bulk-cancellation checks passed, fixtures were removed, and original-worker reconnection and public health were verified. Running cancellation and Ge acceptance remain pending. Development note.

Unreleased — queued cancellation race fix

CP #39 prevents queued cancellation from overwriting a concurrent worker claim or completed result. The caller receives 409 when the invocation is no longer queued and unassigned. Typecheck, 690 tests (12 skipped) and local real-Mongo checks passed. CI passed and the fix is development deployed at 70c2438. Public HTTPS cancellation/claim checks passed; fixtures were removed, original workers reconnected and public health passed. Running cancellation and Ge acceptance remain pending. Development note.

Unreleased — queue failure acceptance

A real Python exception reached the producer through development Nymph and the public queue API. With two workers enrolled, eight concurrent submissions and eight retries after failure executed the function once and preserved the error. Fixtures were removed and existing workers remained active. Cancellation, restart, streaming, job UI and package release remain pending. Development note.

Unreleased — real queue execution acceptance

Development Nymph/Python execution returned 42 through the public queue API. With two workers enrolled, eight concurrent submissions and eight post-completion retries produced one invocation and one recorded execution. Test resources were removed and existing workers preserved. This is acceptance evidence, not a package release. Streaming, remaining lifecycle checks and Ge acceptance are pending. Development note.

Unreleased — signed result frames and Python producer adoption

CP #38 is deployed to development at 963c341. Frame uploads require the assigned worker signature; conflicting retries return 409. Redis notification waits are bounded, with Mongo catch-up for readers. Typecheck, 684 tests (12 skipped), Redis checks and hosted HTTPS acceptance passed. Development ingress #419 exposes the signed upload route.

Python PR #19 is merged with 238 tests passed (seven skipped) and public HTTPS producer verification. Package release, worker integration, actual execution, production deployment and Ge acceptance remain pending. Development note.

Unreleased — namespaced producer API

Control-plane PR #37 adds authenticated namespace-scoped producer submission, await and result streaming, with namespace-local worker queue/pool lookup. Typecheck, 679 tests (12 skipped) and local signed Mongo/API plus legacy probes passed. CI passed; merged as bd6a32e. Development deployment and public HTTPS authorization, retry and result-read checks passed. Later Python producer adoption and public frame uploads are recorded above. Actual worker execution, production deployment and Ge acceptance remain pending. Development note.

Unreleased — invocation worker ownership

Control-plane PR #36 binds signed invocation callbacks to the assigned worker and namespace, and limits claims to the worker namespace. Typecheck, 674 tests (12 skipped), and local signed API/Mongo checks passed. CI passed; merged as 4d1cc71. Development deployment and hosted callback-ownership checks passed. Production deployment and Ge acceptance remain pending. Development note.

Unreleased — producer submission retries

Control-plane PR #35 returns the original invocation receipt for identical retries and HTTP 409 for conflicting reuse of an invocation ID. Running/completed state and results are preserved. Local tests and an isolated Mongo/API restart and concurrency probe passed. CI passed and the fix merged as 9ff0a0d. Development deployment and hosted retry/conflict checks passed; production rollout and Ge acceptance remain pending. Development note.

Development deployed — queue corrections

Control-plane aba4a1e deploys CP #31–#34 to development. Image typecheck and 668 tests passed, 12 skipped. Hosted queue-state/manifest rejection, fixture cleanup, TLS health and fresh polls from both existing workers passed. Production and full scaling/provider lifecycle remain open. Development note.

Deployed — queue drain confirmation

Staging #251 (ba90c59) and production #252 (7bc9962) now clarify that draining leaves running jobs active and requires separate machine shutdown. Both passed CI; published-site pointers and served confirmation text were verified. Production changes only this wording. Staging also includes the Notes/hover browser repairs. Live queue-action testing and Ge acceptance remain open. Development note.

Unreleased — inactive queue exec admission

Control-plane PR #34 rejects queue-routed exec against draining or archived queues with HTTP 409 before writing a job or worker FIFO entry. Reactivation allows new work. Four regressions and typecheck/668 tests passed, 12 skipped; CI and deployment are pending. Concurrent drain coordination and provider shutdown remain open. Development note.

Unreleased — Kubernetes pod ownership foundation

Draft Nymph PR #33 adds saved pod-UID verification and UID-preconditioned deletion options. Formatting and 363 Rust tests passed, seven ignored. The development k3s API rejected a stale UID; the replacement was preserved and all test resources were removed. The helper is not connected to dispatch; full Kubernetes execution and runtime deployment remain pending. Development note.

Unreleased — tracked request rejection on legacy queue exec

Control-plane PR #33 returns HTTP 400 for explicit tracked manifests on the legacy namespace exec endpoint, preventing silent shell-command dispatch. Four route regressions and the full typecheck/664-test suite passed, 12 skipped. CI passed; merged as 06c9001, not deployed. Durable tracked queue admission remains open. Development note.

Unreleased — queue scale-down exec ownership

Control-plane PR #32 excludes workers with pending or running exec jobs from standalone and shared-pool scale-down candidates. Typecheck and 660 tests passed, 12 skipped; CI passed and the fix merged as e6ba5bf, not deployed. Atomic draining, provider termination and compose ownership remain open. Development note.

Unreleased — elastic queue launch expiry

Control-plane PR #31 fixes expired launch holds remaining counted for namespace-scoped queues and shared pools; merged as 5b0735c, not deployed. A deterministic regression reproduced the failure; typecheck and 648 tests passed, 12 skipped. Durable launch accounting, provider-safe scale-down and live queue acceptance remain open. Development note.

Deployed — Tasks folders, progress and waterfall, 2026-09-14

Adds dedicated project Tasks with ordered subtasks, actual timing, discrete or floating progress, transactional events and role-based links to existing Notes. Includes CLI commands, folder/waterfall UI and an agent skill. Existing Notes remain unchanged. Staging/production lifecycle and browser checks passed; synthetic fixtures were retired. The redesigned UI, guide and skill are live. CLI0.19.0 is published on npm and native latest/stable channels. Development note.

Deployed — environment collections (MuJoCo & URDF envs), 2026-09-17

Namespace-scoped simulation environments: dreamlake env push/pull with content-addressed per-env dedup (unchanged files are never re-uploaded) and hash-verified round-trips; a REST read path handing out presigned file URLs so env bytes never transit the API server; and an interactive web viewer at /:ns/envs/:name — live MuJoCo simulation with actuator/joint sliders, Alt-drag forces and browser-captured thumbnails, plus a poseable URDF viewer with auto-detected *.urdf entries. Shipping this renamed the former login-environment switcher to dreamlake auth env. Server (workspace #483/#509/#625), UI (dreamlake-ai #274/#312) and CLI (dreamlake-cli #80/#106/#107) are merged and deployed: dreamlake-ai staging and production run 932cdac, CLI v0.24.2 is published on the native R2 latest/stable channels, and the envs guide is live with a public demo at marvin/envs/g1. The CLI npm channel still resolves 0.21.2; republishing there remains open. Ge review/testing remains separate. Development note.

Unreleased — user-scoped Slurm discovery

The draft worker avoids cluster-wide scheduler history during discovery while retaining identity checks and bounded responses. Live bos14 acceptance passed signed observation reads, successful completion and capped log capture, with owned cleanup. Missing-history recovery and runtime rollout remain open. Development note.

Unreleased — signed scheduler observation read-path acceptance

Real worker/control-plane/DreamLake checks passed authenticated reads across worker restart and terminal completion, with outsider denial and owned cleanup. The fixture seeds a run receipt and uses scheduler command fixtures; public Slurm submission, placement and hosted deployment remain open. Development note.

Unreleased — scheduler observations in DreamLake run responses

The API candidate preserves bounded scheduler facts and their timestamp in owner-scoped run responses, independently of execution status. Real HTTP/Mongo checks passed stale/concurrent reports, restart/outage and terminal precedence. Public Slurm dispatch, job UI and hosted deployment remain open. Development note.

Unreleased — retained Slurm submission diagnostic

The draft worker retains a bounded original submission error for later monitors. A signed worker/control-plane/Mongo check passed process restart, diagnostic API reads, one submission/result and cleanup using scheduler fixtures. Missing-history resolution, public job integration and runtime rollout remain open. Development note.

Unreleased — Slurm scheduler observations

Draft worker/control-plane changes report timestamped scheduler facts separately from worker claim status. Signed transport, persistence, stale-report protection and restart passed local integration checks. Public job projection, submission diagnostic recovery and resolution of missing scheduler history remain open. Development note · Acceptance record.

Unreleased — durable remote delivery metadata

Adds an unmounted Mongo grant/nonce adapter with owner-scoped create/status/revoke, exact entry revisions, explicit selections and a server-owned capability gate. Revocation preserves unknown-outcome metadata and cancellation intent; no remote stopping or delivery is claimed. No routes, capability issuer or decryption are enabled. Development note.

Deployed — metadata-only setup review, 2026-09-13

Frontend f182b7f is deployed to staging and production. Real WebKit phone/desktop checks passed with zero browser secret reads or remote submissions; all four synthetic entries were retired/read404. This reviews selected metadata and CLI/Python handoff, not remote execution. Runner and evidence · Dated status.

CLI 0.18.0 — published key rotation, 2026-09-13

SSH key rotation is published to npm and native downloads with artifact hashes and fresh installations verified, paired with published Python 0.15.0. Frozen releases exclude the later password probes and reservation APIs. Published-client hosted target/jump rotation, lost-response recovery and independent cleanup now pass; human runner and exact evidence. Release · Development evidence.

Unreleased — remote delivery authentication scaffold

Adds an unregistered worker signature verifier and explicit whole/selected-value projection, with bounded raw-body capture, strict media/header checks and full-window nonce retention requirements. Tests exercise real HTTP bytes and UUID-backed Vault entries in isolated Mongo. No remote delivery route or decryption capability is enabled. Development note.

Unreleased design — complete remote Vault delivery

Proposes pinned repository checkout and selected file/env delivery through existing tracked runs, with CLI/Python parity, signed worker authorization, durable outcomes and owned cleanup. Secret-enabled execution suppresses output at its source; uncertain spawn outcomes are reconciled, never blindly rerun. This is a design, not an available API or remote acceptance. Contract · Dev note.

Verified on staging — owned AWS prefix migration, 2026-09-13

Published native CLI 0.17.0 and Python 0.14.0 passed forward/reverse migration of nine dependencies, lost committed-response recovery and an isolated runtime-grant outage against real AWS KMS. The outage returned503 without checkpoint progress; restoring the grant recovered access. Four synthetic entries were retired/read404; the historical key is retained. Actual AWS context rejection and dedicated GCP SDK/adapter checks subsequently passed; production, GCP hosted/workload-identity, second-tenant and remaining dependency gates stay open. Provider evidence. Dated evidence.

Python 0.15.0 — key rotation, 2026-09-13

The published wheel and source release include reviewed SSH key rotation. Registry hashes, fresh installation and 55 rotation tests were verified. Four real target/jump pairings passed on the implementation candidate with cleanup; release-specific hosted rotation remains separate. Password-only probe work is not part of this frozen release.

Deployed — explicit Vault file export, 2026-09-13

Frontend bdff988 is deployed to staging and production. Actual WebKit downloads matched exact string/JSON bytes without extra secret reads; both origins passed synthetic retirement/read404 and browser cleanup. Native Chrome save/cancel/overwrite passed on the reviewed local candidate. Guide and deployment evidence. Remote setup delivery remains unfinished.

Unreleased — password verification and reservation candidate

Paired password-only probes are merged with real disposable-host authentication evidence. A backend reservation candidate retains encrypted revisions, freezes a dedicated replacement, and adds owner-only recovery and exact confirmation, with 30-day terminal snapshot collection. Pre-start cancellation survives shared source changes and host removal. Snapshot-bearing KMS migrations require schema-2 acknowledgment; rollout must disable migration on all old writers before introducing reservation-capable writers. It does not change remote passwords; privileged mutation and explicit rollback resolution remain required. Plan, dated evidence and limitations.

Unreleased — staging migration rollout check

Adds a read-only operator check for the expected source revision, running ECS tasks, image digest, migration flag and authenticated API capability. Five tests cover invalid rollout states. Staging task154/source 5c82000e passed with migration disabled, then task155/source 433c4cdd passed with migration enabled. Owned distinct-key AWS migration/outage acceptance now passed; production and broader acceptance remain separate. Development note.

Native CLI 0.17.0 / Python 0.14.0 — populated-prefix KMS migration

Explicit migration/resume operations re-encrypt retained entry and write/HOTP recovery envelopes in bounded batches. Encryption epochs and exact-envelope CAS preserve logical credential revisions and counters; retirement metadata cannot restore stale ciphertext. CLI/Python share metadata-only status and immutable operation IDs. The owned staging AWS flow is verified above. Key retirement, production promotion and GCP acceptance remain separate. Development plan.

Unreleased — explicit host credential cleanup confirmation

Owner-only cleanup attestation and binding lookup support resumable client-owned key rotation. Exact proof retries are idempotent; stale or changed bindings reject confirmation. Confirmed historical references may be collected after their existing retirement deadline, while the active binding retains the current credential. This is client-attested metadata, not backend SSH verification. See the rotation plan and development note.

Web Vault — selected credential files, 2026-09-13

Save one selected UTF-8 credential file after reviewing its destination; manual input is masked by default with explicit reveal. Invalid UTF-8/control bytes, unsafe basenames and oversized values are rejected. Canceled or stale reads cannot populate another session. Saving preserves BOM/CRLF bytes and uses existing write recovery without automatic retries.

Staging and production desktop/mobile acceptance passed on UI 9cc0c3d; all four synthetic entries were retired. Existing account tokens were used separately per environment. Export/download subsequently passed the deployed acceptance above; full remote setup UI and fresh OAuth remain open. Guide with CLI/Python examples.

Unreleased — prefix KMS policies

Personal owners can inspect operator-approved key references, preview a prefix, and explicitly activate an empty prefix with an immutable operation receipt. Entry creation and activation share a Mongo transaction guard. Retained entries and write/HOTP receipts require explicit migration, now implemented and verified in the owned staging AWS flow above. Broader customer/GCP setup and production promotion remain open. See the development plan.

CLI 0.16.0 / Python 0.13.0 — hosted npm saving, 2026-09-13

Fresh npm-wrapper/PyPI clients passed real enrollment, separate target/jump key/password saving, exact replay, independent saving failure, signed reconnect, restored two-hop SSH and tracked execution on staging c49dc1d / task 152. The npm password-descriptor forwarding fix is now verified through the published wrapper. Both disposable accounts and all four credential bindings/entries were cleaned up. Evidence and limits. Remote password authentication, rotation and production host saving remain open.

Unreleased — Slurm signed recovery draft

A deliberately held Slurm job reached its accepted deadline while still queued and returned one signed timeout result. No workload allocation or output was observed, and owned cleanup was verified. Natural queue contention, rejected placement and public provider status remain open. Queue evidence.

The Slurm worker captures at most 2 MiB per output stream without cancelling a workload when the limit is reached. Results preserve the scheduler exit status and include a truncation notice. Full staged logs remain intact; durable artifact upload is separate. Log capture.

A live CPU workload reached its accepted deadline without an API cancellation request. Slurm confirmed cancellation and the worker delivered one signed timeout result. Owned runtime and database cleanup was verified. Queue-only expiry and public provider placement remain open. Deadline evidence.

The draft worker now retains bounded, escaped scheduler stderr and exit status for failed commands. It still preserves uncertain submissions for reconciliation. User-facing recovery remains open. Review findings.

Nymph #31 and control-plane #29 now pass paired signed recovery after a lost claimed response and worker restart. The check uses scheduler fixtures: one submission, one signed result, unchanged accepted timestamps and verified runtime cleanup. The worker advertises protocol support and accepts the control plane's MessagePack timestamps. Reproduction instructions and a nonzero failure-exit check are included.

The bos14 controller's submission filesystem passed independent-process lock contention and reacquisition after the owned holder exited. Cross-host migration and other filesystems are outside this check.

A real CPU workload also completed on bos14 after the disposable signed worker was killed and restarted without its enrollment token. Job 146649 retained its accepted parameters and returned the expected arguments, selected input and output. Owned processes, temporary database and runtime directories were removed. This verifies direct worker dispatch with a local control plane.

Live checks also preserved a workload's nonzero exit code, confirmed cancellation after the workload started, and recovered from a short callback-tunnel outage without restarting the worker or creating another scheduler job. All owned test runtime and database cleanup was verified.

Both PRs remain draft. Lifecycle review, provider placement, unresolved-outcome UI, queue/resource rejection and deadline cases remain open. No runtime release, deployment or worker rollout occurred. Provider Dev Note.

Unreleased — explicit tracked-run request fields

Control-plane #28 rejects unsupported placement and execution fields before queuing tracked work, preventing options from being silently ignored. Valid tracked requests and the legacy exec route remain supported. Typecheck and 647 local tests passed; hosted deployment remains separate. Provider note.

Development deployment at 93c295a passed public HTTPS rejection and cancelled receipt replay checks. Both existing workers reconnected; disposable records and uploaded build files were removed. Production rollout remains open. Hosted evidence.

Unreleased — Slurm GPU request compatibility

Nymph #29 uses --gres=gpu:N for single-node GPU requests on both supported Slurm selection plugins. The candidate passed 358 local tests (seven ignored) and live CUDA computation, but bos14 reported zero allocated GPU GRES while the job was running. GPU allocation/isolation acceptance remains open; no worker upgrade or runtime release occurred. Provider note.

Unreleased — host credential replacement metadata

Conditional host-binding replacement and operation recovery are merged and unreleased with paired CLI/Python interfaces. Both immutable entry references remain retained through pending remote cleanup. This does not install or revoke SSH keys. Development plan; password rotation and cleanup confirmation remain open.

EKS acceptance — published clients and scheduled GC, 2026-09-13

A fresh isolated EKS fixture passed source regressions, npm CLI 0.16.0 / PyPI Python 0.13.0 pagination and HOTP, and actual runtime-timer cleanup with real AWS KMS. One eligible entry was purged with a redacted audit; four controls survived. Owned processes, temporary Mongo, namespace, three test IAM resources and SSM tunnel were cleaned up. Shared cluster/KMS remain. This is not production physical-GC or backup-erasure proof. Evidence and procedure.

CLI 0.16.0 / Python 0.13.0 — hosted pagination and HOTP, 2026-09-13

Fresh npm/PyPI clients passed staged 207-entry traversal, cross-client cursors, selected GPG HOTP imports, explicit ownership and replay after committed response losses. Hosted desktop/mobile UI pagination passed with no secret reads. Synthetic entries were retired. Existing-token authentication was used; fresh OAuth, second owner and production backend acceptance are not claimed. Evidence and procedures.

CLI 0.15.0 / Python 0.12.0 — hosted saving acceptance, 2026-09-13

Published native CLI 0.15.0 and PyPI Python 0.12.0 passed ten checks against staging a11e815: real Nymph enrollment, selected target/jump saving, password byte parity, independent save failure, signed reconnect, restored two-hop SSH and tracked execution. Both accounts, signing keys, four bindings and four entries were cleaned up. Evidence and limitations.

The npm 0.15.0 launcher drops password descriptors above 2. Its separate fix passed as an unreleased candidate, not the published npm launcher. Remote password authentication and production host saving were not tested.

CLI 0.16.0 / Python 0.13.0 — vault metadata pagination

Released client support for bounded HTTP pages and paired CLI/Python page controls preserve complete list output through automatic continuation. Account/prefix/scoped identity filters run before the page limit; retired inclusion remains owner-only. Legacy unpaged HTTP remains compatible and unbounded pending migration. See the pagination guide.

CLI 0.16.0 / Python 0.13.0 — host reference release

Released CLI/Python unbind releases a personal host-credential retention reference without claiming remote SSH revocation. Exact metadata protects cleanup retries; retired secrets still honor their purge deadline. See the runtime note.

Unreleased — host credential-saving SSH snapshot

A candidate Python wheel passed real two-hop SSH on bos14 with synthetic restored target/jump keys. Owned fixtures and tunnel were cleaned; 16 entries were retired across attempts. The runtime note links exact hashes, procedure and limitations. This is source-snapshot evidence, not a release, hosted deployment, real Nymph enrollment or AWS KMS acceptance.

CLI 0.16.0 / Python 0.13.0 — HOTP authority and recovery

Selected HOTP import, explicit counter ownership, encrypted counter advancement and 24-hour issuance recovery are released with paired CLI/Python request files. Hosted staging acceptance passed; production backend acceptance remains separate. See the HOTP development guide for examples and limitations.

Unreleased — Vault entry identity protection

Delayed replacement and restore operations cannot overwrite a new entry that reuses a purged name and revision. Ordinary and receipt-backed writes both require the original immutable entry ID. Production 5e4dfa6, task 111, passed exact image/health verification and seven published CLI/Python compatibility groups; synthetic credentials were retired or revoked. See the Vault runtime note for tests and remaining retention work.

Scheduled Vault entry cleanup — isolated EKS verified

Retired entry ciphertext becomes eligible for bounded, transactional cleanup after its recorded retention deadline. Active host bindings block purge; concurrent restores and bindings are rechecked. Configurable retention, redacted audit records and an operator pause setting are included. The real runtime scheduler passed isolated EKS physical purge at backend c49dc1d; production physical purge remains a separate gate. The runtime note links the operator guide and describes backup and remote-copy limitations.

CLI 0.14.0 and Python 0.11.0 — 2026-09-13

Provider registration, owned Slurm associations, retirement and request-ID receipt recovery are released. CLI 0.14.0 is published on npm and native downloads (including latest); Python 0.11.0 is published on PyPI and GitHub. Package hashes match the release builds.

Fresh npm/PyPI installations passed staging and production metadata checks at 73cd00f, with verified fixture retirement and temporary-install cleanup. Owned association checks passed on staging only. Readiness, scheduler dispatch, Kubernetes associations and Ge review/testing remain open.

See the paired CLI/Python guide and Provider Dev Note for evidence and limitations.

Published host-installer acceptance — 2026-09-13

CLI 0.13.0 and Python 0.10.0 each installed nymph 0.1.5 into a separate fresh Linux account and reached verified online status. Replay preserved identity; token-free service restart produced a fresh signed heartbeat. Both workers completed tracked uv runs with the expected output and Unix account.

Installed binary hashes matched the release manifest. Test accounts, homes and SSH keys were removed and their signing keys revoked; the original worker stayed online. uv was supplied separately. Production, existing-host rollout, machine reboot recovery and Ge review/testing remain open. See the Host Dev Note and testing guide.

Published host-client acceptance — 2026-09-13

Fresh CLI 0.13.0 and Python 0.10.0 installations passed tracked execution on an existing staging process worker: explicit file selection, argument vectors, replay/conflict handling, durable logs, failure exit 7, timeout and cancellation. All eight runs reached terminal states; no host service or pre-existing job was changed. This is acceptance of already released clients, not a new package release.

The worker advertises nymph 0.1.4. Current-installer enrollment, production host execution, Slurm/GPU/Kubernetes and Ge review/testing remain open. See the host development note and testing guide.

Vault entry write recovery — 2026-09-13

Pending entry-write request IDs survive browser reloads. Check committed receipt metadata and open current entry metadata separately; checking never retries a write or reads a secret. Storage failure blocks submission, and forgetting an ID requires confirmation.

Frontend PR #238 is merged. Local validation passed 82 tests, five browser tests, typecheck and production build. All CI checks passed. Staging and production deploy ec0a24e; both passed response-loss/reload recovery with a historical receipt at revision 2 and fresh current metadata at revision 3. Test entries were retired at revision 4/read 404. Ge review/testing is unconfirmed. See the runtime note for evidence, fault-injection details and acceptance limits.

Vault entry expiry controls — 2026-09-13

The personal Vault editor supports explicit UTC expiry on creation and keep/set/remove choices on replacement. Keeping expiry preserves the exact stored timestamp, including an already-expired date. Replacing a value alone does not reactivate it. Revealed values clear at entry expiry or after 30 seconds, whichever comes first.

Frontend PR #236 is merged. Staging and production deploy source 25a1a2d; both passed hosted UTC creation, expiry preservation/removal, reveal clearing and expired-read denial. Explicit expiry removal restored reads. Fixtures were retired at revision 7/read 404. Ge review/testing remains unconfirmed. See the runtime note for evidence, test steps and acceptance limits.

Vault scoped access-key UI — 2026-09-13

The personal Vault tab now supports explicit entry/field selection, initial token delivery, key metadata, renewal and confirmed revocation. Lost-response handling retains the issuance request ID and requires reconciliation before replacement.

Frontend PR #234 is merged. Staging and production deploy source 5e174d6; both passed real-browser selected-field issuance, reveal/clear, renewal and revocation. Excluded fields returned 404 and revoked keys returned 401. Fixture keys were revoked and entries retired afterward. Ge review/testing remains unconfirmed. See the runtime note for evidence, test steps and acceptance limits.

Vault access-key metadata cleanup — 2026-09-13

Production task 109 and staging task 147, source 3b1ad31, run bounded cleanup of terminal access-key metadata after retention. Each environment passed two scheduled-pass checks, active-key reads and retained issuance replay. Test keys were revoked and entries retired afterward. Live passes deleted zero records; aged deletion and retention boundaries passed isolated Mongo tests.

Entry ciphertext, host access and tenant guard cleanup remain separate work. See #312 and the runtime note for evidence and the test procedure.

Vault browser conditional writes — 2026-09-13

Production API dfee12b, task 108, allows If-Match through CORS. Browser replacement, retirement and restore now reach the API. Hosted browser create, reveal/hide and conditional mutations passed with a synthetic entry; cleanup retired it and independent API reads returned 404. See #308 and the runtime note for deployment and test evidence.

CLI 0.13.0 and Python 0.10.0 — 2026-09-13

CLI 0.13.0 is published on npm and native downloads; Python 0.10.0 is on PyPI. They include selected TOTP import, owner code retrieval and entry-write recovery. Fresh npm/PyPI installations passed seven production acceptance groups. All published package and native artifact checksums were verified.

The native latest channel is 0.13.0. A fresh Linux pod completed the official installer and verified the installed binary's version, checksum and command help; a fresh macOS ARM64 download passed checksum and command checks. Test resources and the dedicated tunnel were removed. Python's matching GitHub release is also published with verified asset hashes. The CLI docs and version snapshot are published at ea83d7. Ge review/testing remain unconfirmed. See the Vault runtime note.

Nymph v0.1.5 — 2026-09-13

Published Linux x86_64/arm64 and macOS arm64 binaries include supervisor identity, verified workload cancellation, signed reconnect/logging and tracked uv execution. Public versioned and latest binaries/tarballs passed SHA-256 checks; a clean macOS install reports nymph 0.1.5 and exposes --supervisor-id. Linux default and all-features CI passed; local all-features tests passed 336 with seven ignored. The supervisor Dev Note and test instructions are published on this docs site.

Release · How to test and acceptance limits. Existing hosts were not upgraded. CLI adoption/backoff and real shared scheduler/ container acceptance remain follow-ups; descendants may survive leader exit.

Unreleased

Tracked result delivery

Nymph #30 is merged and journals completed tracked results in their original server/worker scope and replays them until explicitly acknowledged. Local daemon restart and hosted signed callback acceptance passed with disposable fixtures. Delivery retries a failed directory sync before sending a saved result; force-drain cancellation stops retry backoff. Both Linux CI jobs passed. Runtime release, worker rollout and Ge review/testing remain pending. See the Provider Dev Note.

Slurm checkpoint simplification

Slurm draft #29 keeps one immutable terminal checkpoint and removes unused per-poll history. Live CPU completion, queued/running cancellation and recovery after controller expiry passed on bos14. Runtime integration, GPU acceptance and new-head CI remain pending. See the Provider Dev Note.

Tracked result acknowledgment

The control-plane callback acknowledges only an exact committed terminal result. Conflicting or unclaimed callbacks return 409, and racing progress cannot be erased by a stale final write. Local tests and real MongoDB/HTTP acceptance passed. Development 826e976 passed signed callback acceptance and both existing workers reconnected; fixtures were removed. Production rollout and durable worker result delivery remain pending. See the Provider Dev Note.

Vault backend reference status

Backend README/TOTP references now link released runtime evidence and preserve reproducible synthetic tests. They distinguish general entry-write recovery from OTP imports, which do not expose durable write IDs. No runtime release is implied.

Vault credential documentation

The credential guide now covers released selected TOTP upload/generation in CLI and Python and links current hosted UI/runtime evidence. Outdated package/activation warnings and duplicate migration paragraphs were removed. Host saving, HOTP and entry/remote cleanup gaps remain explicit. This is a documentation correction, not a new runtime release.

Tracked Slurm integration draft

The draft now fingerprints CPU, memory, GPU and time limits. A regression test catches the prior omission. Shared stage/intent validation replaces duplicate checks, and the review guide separates the adapter guarantees from unfinished dispatch, output delivery and journal retention. The runtime PR remains draft.

Nymph draft #29 now includes scheduler submission, ownership-checked recovery, durable observations and pending cancellation. Recorded terminal checkpoints can now be recovered after restart without controller access; unobserved terminal states remain unresolved. Local and Linux CI recovery tests passed at 5058c7d; upstream acknowledgment and output delivery remain open. A direct Linux adapter run on bos14 completed with matching source/input/arguments and output; owned staging and test assets were removed. Local and Linux CI tests passed. Public run API/daemon dispatch, live fault injection and GPU execution remain open; this is not a runtime release. See the Provider Dev Note for evidence and bos14's short controller-retention limit.

Provider execution contract

A proposed contract connects existing provider declarations to explicit host/runner associations and tracked-run placement. It covers client parity, legacy edit guards, scheduler recovery and real Slurm/Kubernetes acceptance. The contract is not frozen; no provider runtime or API has shipped in this change. A bos14 prerequisite probe completed an inline CPU job but found the tested controller staging path absent and no uv on the compute node PATH. Both probe jobs are terminal and their owned staging directory was removed. A follow-up uv batch job passed with controller /export/work/geyang mapped to node /work/geyang. Source/input hashes, arguments and output matched after SSH submission exited. The private uv binary and test files were removed; DreamLake provider integration remains unimplemented.

2026-09-13 — vault recovery and TOTP in production

Production API 1fe1cb2, task 107, completed the staging-first rollout with its existing managed KMS key. Seven new-client release-build check groups and nine previous-client compatibility checks passed. Fresh npm CLI 0.13.0 and PyPI Python 0.10.0 installations also passed all seven production groups; synthetic entries were retired and keys revoked. All npm/R2 artifacts are verified, and native downloads default to 0.13.0. The matching Python GitHub release is also published with verified asset hashes. Browser entry operations are verified above; second-owner receipt isolation remains open. See the runtime note.

2026-09-13 — Supervisor review and current-main integration

Ge reviewed the supervisor workstream and authorized merge. Integration preserves signed reconnect/logging and extends verified cancellation to tracked uv runs. Cached group IDs are not signalled after the leader is reaped; capture held open by descendants fails after two seconds rather than hanging or killing an unverified group. Descendants may remain running. The integrated library suite passed 201 macOS library tests and 334 total tests (six ignored). Linux default and all-features checks passed. Implementation merged as 6079ef7; evidence is in nymph PR #21.

The supervisor note now includes How to test with exact runtime/docs commands, expected results and live-acceptance limits. Review, merge, release and deployment remain separate; no release or production rollout is asserted by this entry.

2026-09-13 — vault recovery and TOTP on staging

Recovery and TOTP are merged with the reviewed Python security fixes. Staging API 1fe1cb2, task 145, passed seven hosted check groups using merged CLI and Python source clients. Tests covered dropped responses, receipts/replay, selected GPG imports, independent code generation checks, access denial, redaction and entry lifecycle. Synthetic entries were retired and the scoped key revoked. Evidence PR #303 records exact revisions and limits. New packages, production rollout, hosted UI and second-owner receipt isolation remain unverified. See the runtime note.

2026-09-13 — vault entry write recovery

Merged server, CLI and Python changes add request-ID lookup and safe replay for uncertain entry creates/replacements. Replays return the original receipt without overwriting later values. Receipts last 30 days; missing status does not prove a write failed. Server/client integration tests passed. This change is verified on staging with source clients; package release and production rollout remain pending. Updated clients require the new server. See the runtime note.

2026-09-13 — vault production acceptance

Production API b85854c now serves Vault with its own managed KMS key. Published CLI 0.12.0 and the Python 0.9.0 GitHub wheel passed selected-only SSH imports, revision checks, scoped-key isolation, one-time retrieval, raw metadata and retire/restore checks. Synthetic test credentials were retired and the scoped key revoked. The production rollout completed successfully. Remaining Vault work and release limits are listed in the runtime note.

2026-09-12 — vault production key readiness

A separate production KMS key and scoped runtime-role policy are provisioned. An isolated production-role task passed encryption/decryption and rejected an altered encryption context. Production Vault is still disabled; deployment and hosted acceptance remain. See the runtime note.

2026-09-12 — Nymph supervisor identity

Development only: open nymph PR #21 adds stable local supervisor identity, private discovery records and live ownership introspection. Child, process-group, Slurm and Docker/gVisor cancellation checks refuse missing or mismatched ownership; workload markers cannot substitute for live verification.

The implementation revision passed macOS and Linux formatting, Clippy and default tests. Existing Clippy warnings and opt-in test skips remain. Review/merge, CLI discovery and restart integration, per-slot backoff, and real shared-host acceptance are pending. Kubernetes remote deletion semantics are unchanged. No release or deployment is verified. This dated reporting update changes docs only; it does not ship the implementation or publish the docs.

See the supervisor development note for revision-specific evidence and remaining work.

2026-09-12 — vault staging acceptance

Staging API 91047c7 passed hosted Vault checks with published CLI 0.12.0 and Python 0.9.0: selected-only SSH imports, client parity, revision conflicts, scoped-key isolation, one-time retrieval and retirement cleanup. Startup index names and login-created account records are handled by merged PRs #284 and #287. Production Vault remains disabled. See the runtime note.

2026-09-12 — compose capacity

Merged lakeshore PR #24 makes count converge by terminating confirmed surplus while protecting pending replacements. Shared local up/down locks and operation journals block unsafe retries after ambiguous provider results or process death. Namespace mismatch, provider failure and startup timeout now fail explicitly.

The tested PR head passed 44 compose regressions and a clean-source full suite (641 passed, one skipped). Merge commit: eec3335. Package release, deployment, real-provider acceptance and this note's live publication remain unverified. Distributed locking and automatic crash/wedge recovery still need follow-up. Host capacity remains separate from user-space job lifecycle. See the compose development note for evidence and recovery limits.

2026-09-12 — vault import interface

The canonical CLI interface is vault import --ssh and vault import --pass-otp; Python adds vault.import_entries. SSH uploads only explicitly selected profiles and keys. Pass OTP remains a local dry-run preview; uploads are unsupported. Existing CLI aliases remain compatible. Package publication and production vault activation are pending. See the vault import note for PRs, validation and remaining work.

2026-09-12 — host enrollment callbacks

Merged control-plane and nymph updates authenticate job results and log chunks with the assigned worker key. Development ingress requires live authentication checks before opening these callback paths. Staging-to-bos14 enrollment, retry, token-free reconnect and command stdout passed. Signed raw logs were accepted; unsigned, altered and replayed chunks were rejected. Production rollout, package compatibility and host UI remain.

See the host enrollment note for revisions and tests.

2026-09-12 — SSH through nymph

Development only: draft nymph PR #22 adds SSH request admission checks, Ed25519 public-key normalization and binary DATA/FIN framing. 222 local tests passed, including 10 new SSH tests. Design PR #23 is merged.

Not available as live SSH access: backend startup, relay connections, control-plane session authorization and CLI integration are still pending. No package release, version tag or production deployment was made for this change.

See the SSH development note for exact scope, validation and remaining work.

Development reporting

Added a Dev Notes category and a standing task for each active master-plan workstream to maintain a dated note, update these release notes and DM Ge after each note update. Source links are used until each deployment is verified.

Unreleased — Vault rollout alarm preflight

The read-only ECS migration verifier now checks configured rollback alarms before and after fleet/API verification. Non-OK, missing or disabled alarms fail closed. Eleven tests cover alarm transitions and evidence redaction; no cloud changes or new deployment are implied. Fault-test cleanup and deployment sequencing are documented separately.