NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #1120 by repository stars
Last release today
07 Oct 2026
Ships fairly regularly
a new release about every 8 days
Some releases are documented
notes for 26 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
2 years old
437 releases · first in 2024
Nothing published for this version
Important destroy.remove_dir is now deprecated and ignored. See destroy settings docs.
This release brings clearer deployment status reporting, optional cleanup for unused source caches, and faster Git mirror operations. Please review the upgrade notes below for changes that may affect custom health checks, GitHub App status reporting, Prometheus queries, or stack cleanup.
live/ data. Enable it in Compose:
environment:
SOURCE_GC_ENABLED: "true"The image now uses a dedicated, smaller /healthcheck binary for each health checks. A custom Compose healthcheck.test overrides the image default.
Action: If you set it to test: ["CMD", "/doco-cd", "healthcheck"], remove the override or change it to test: ["CMD", "/healthcheck"].
See the health check docs.
Destroying a stack now preserves its shared source directory so it cannot remove data used by another stack.
Important
destroy.remove_dir is now deprecated and ignored. See destroy settings docs.
Action: If you relied on that setting to reclaim unused source caches, enable source GC (disabled by default). See Destroy settings and Source GC settings
When deployment status reporting is enabled with GitHub App authentication, doco-cd now reports through GitHub Checks instead of commit statuses. Checks are separate from commit statuses in branch protection and require the App permission.
Action: Grant Checks: Read and write, approve the installation permission update, and review any required branch-protection checks. Token-based GitHub authentication continues to use commit statuses.
To reduce histogram series and scrape overhead, deployment_stage_duration_seconds no longer includes the deployment or context labels. Per-deployment timing remains available as deployment_duration_seconds.
Action: Remove deployment/context label filters or groupings from queries on the stage-duration histogram, or use the per-deployment metric.
See metrics docs.
Full Changelog: v0.123.0...v0.124.0
One column per month.
Nothing published for this version
Nothing published for this version
Added Sync Windows to control when doco-cd is allowed to change your stacks. For example, you can deploy only during business hours, freeze deployment
CERT_FULL) similar to CERT_KEY, see the wiki.Full Changelog: v0.122.1...v0.123.0
Nothing published for this version
Nothing published for this version
Nothing published for this version
This release fixes an issue with self-updating where the deploying instance posted a "Pending - In Progress" commit status and then handed over, while
This release fixes an issue with self-updating where the deploying instance posted a "Pending - In Progress" commit status and then handed over, while the instance finishing the handover never updated the commit status.
Full Changelog: v0.122.0...v0.122.1
A long requested feature is now fully supported; Doco-CD is now able to update itself, even without a secondary updater instance. See the Self-Updatin
A long requested feature is now fully supported; Doco-CD is now able to update itself, even without a secondary updater instance.
See the Self-Updating wiki page for more information and a migration guide.
This release also fixes a bunch of bugs that were introduced after the artifact storage update in v0.120.0.
Note
After upgrading, every Swarm service gets one rolling update. Services that use recreate.ignore are recreated once when they move to the new live copy. Standalone commits that only change recreate.ignore files now run a deployment instead of being skipped. Nothing is recreated, but it sends the "Deployment completed" notification if notifications are configured.
Full Changelog: v0.121.0...v0.122.0
Improved performance and reliability of the auto-discovery feature with the artifact storage (introduced in v0.120.0).
Full Changelog: v0.120.1...v0.121.0
Nothing published for this version
Fixed a crash that could occur when concurrent webhook deployments fetched updates into the same Git repository mirror. Git reads now use fresh, lock-
Fixed a crash that could occur when concurrent webhook deployments fetched updates into the same Git repository mirror. Git reads now use fresh, lock-scoped repository handles, keeping parallel deployments safe and ensuring each deployment reports the revision it actually deployed.
Full Changelog: v0.120.0...v0.120.1
Nothing published for this version
This update improves deployment safety, concurrency, and performance, especially for repositories with multiple auto-discovered stacks.
This update improves deployment safety, concurrency, and performance, especially for repositories with multiple auto-discovered stacks.
Git repositories and OCI sources are now prepared as immutable, content-addressed artifacts. Deployments use a dedicated artifact for each revision instead of a shared mutable working tree. This allows independent stacks to deploy concurrently, while deployments for the same stack remain serialized. Older webhook events are also prevented from overwriting newer deployments.
Source preparation and Git checks are more efficient:
git_depth match.Read-only pre-deployment work, such as source initialization and change detection, is now handled separately from Docker-mutating deployment work. This allows more preparation tasks to run concurrently without consuming deployment slots.
You can find more information in the artifact storage documentation.
| Variable | Default | Purpose |
|---|---|---|
MAX_CONCURRENT_PREDEPLOYMENTS |
8 |
Maximum number of concurrent read-only pre-deployment operations, including initialization and change detection. |
ARTIFACT_GC_ENABLED |
true |
Enables cleanup of unreferenced Git revision and OCI digest artifacts. |
ARTIFACT_GC_RETENTION_RECORDS |
2 |
Number of recent unreferenced artifacts to keep per repository or artifact. |
ARTIFACT_GC_RETENTION_TTL |
1m |
Minimum time older unreferenced artifacts are retained before removal. |
ARTIFACT_GC_INTERVAL |
10m |
How often artifact cleanup runs. A sweep also runs at startup. |
MAX_CONCURRENT_DEPLOYMENTS continues to control the number of deployments that may perform Docker mutations. MAX_CONCURRENT_PREDEPLOYMENTS controls preparation separately and can be adjusted according to available CPU, network, and storage capacity.
ARTIFACT_GC_ENABLED if older artifacts must remain available.Caution
Services that write inside the cloned repository with relative bind mounts (inside the doco-cd data directory/volume) will lose their data when the service is re-/deployed from a new artifact revision.
Each artifact revision/version is like a clean, new Git worktree: When doco-cd deploys from a new Git commit or OCI artifact version, it first creates a new artifacts/<revision> worktree directory to deploy from.
If you use Pre- / Post-Deployment Scripts to generate configuration or data, it might be recommended to use named volumes or absolute host paths depending on your use case.
Full Changelog: v0.119.0...v0.120.0
Nothing published for this version
Fixed a bug in the SOPS decryption logic which caused some files to stay encrypted after a deployment run.
${...} placeholder unchanged instead of returning an error. Previously, doco-cd passed that unresolved value through to the deployment. Now the Infisical provider fails fast when the returned secret still contains an Infisical reference expression.stop_services now stay stopped correctly while the scheduled job is still running.Full Changelog: v0.118.1...v0.119.0
fix(lock): implement cross-process locking to prevent concurrent write races by @kimdre in #1862
Full Changelog: v0.118.0...v0.118.1
When temporarily stopping services during a job run, doco-CD now honors stop_services grace periods correctly, see Stop timeout behavior in the wiki.
stop_services grace periods correctly, see Stop timeout behavior in the wiki.Full Changelog: v0.117.1...v0.118.0
fix(encryption): keep decrypted files from every bind-mounted directory by @chan-mai in #1837
Full Changelog: v0.117.0...v0.117.1
Added a new REST API endpoint for force-recreating an entire Docker Compose project or one selected service while preserving the deployed configuratio
--force-recreate does.restart action, which already forces service task updates through Swarm's ForceUpdate. Docker Swarm has no distinct --force-recreate operation.Full Changelog: v0.116.0...v0.117.0
ci: update image vulnerability scanning workflow by @kimdre in #1820
New in this release:
SSH_KNOWN_HOSTS_FILE env var to provide a file to doco-cd that contains trusted SSH host keys.Full Changelog: v0.115.0...v0.116.0-rc.1
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
This release mainly contains code cleanup and refactoring.
This release mainly contains code cleanup and refactoring.
Two small things have been added:
timeout deploy config setting in the wiki.Full Changelog: v0.114.0...v0.115.0-rc.1
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Added Azure Key Vault provider support.
Added a stateless Model Context Protocol server to allow AI applications/LLMs to communicate directly with doco-cd using provided MCP tools.
Doco-CD exposes the MCP server at POST /mcp using streamable HTTP transport. The endpoint uses the HTTP_PORT and follows doco-cd's TLS configuration.
Enable the server with MCP_ENABLED: true and provide an API secret using API_SECRET or API_SECRET_FILE (see REST API Authentication):
services:
app:
environment:
MCP_ENABLED: "true"
API_SECRET: your-api-keySee the wiki about how to set the correct client configuration for authentication against the MCP server.
If you are using Docker Swarm, you can now configure each deployment, whether doco-cd should deploy as a Compose project or a Swarm stack. Use the new swarm.enabled deploment configuration setting for this.
true deploys a Docker Swarm stack. false deploys a Docker Compose project. When omitted, the Docker context determines the mode (like before). An explicit true fails if the context is not a Swarm manager or DOCKER_SWARM_FEATURES=false.
name: netbird
swarm:
enabled: falseWhen the value of enabled changes for a doco-cd-managed deployment, doco-cd migrates the project or stack automatically. Its volumes are retained during this migration.
Full Changelog: v0.113.0...v0.114.0
Nothing published for this version
This release adds multi-context support and cleans up deprecated code/features.
This release adds multi-context support and cleans up deprecated code/features.
The one_shot alias for one_off is no longer supported.
Use one_off instead; one_shot values are rejected.
one_shot to one_off in job definitions.Legacy label formats are retired:
cd.doco.deployment.auto_discovercd.doco.deployment.auto_discover.deletecd.doco.deployment.auto_discovery.deleteNew deployments use cd.doco.deployment.auto_discovery and the JSON configuration label cd.doco.deployment.auto_discovery.config.
Existing deployments using legacy auto-discovery labels are migrated automatically:
ENCRYPTED PRIVATE KEYSupport is removed because it relied on the deprecated Go x509.DecryptPEMBlock() API. Use modern OpenSSH or unencrypted PEM key formats.
Docker Compose services are started automatically after they are created or updated. To let an external tool control a service's lifecycle, set the cd.doco.deployment.autostart service label to false.
services:
on-demand:
image: example/on-demand:latest
labels:
cd.doco.deployment.autostart: "false"The label defaults to true. When it is false:
More info in the wiki: https://doco.cd/latest/Deploy-Settings/#preserve-a-services-running-state
Added multi-context support for Docker contexts to all subsystems of doco-cd:
context label)Project, stack, and scheduled-job endpoints now accept one optional context query parameter. If it is omitted or set to default, the endpoint uses the default Docker context. Named contexts must exist in the Docker CLI context store available to doco-cd. More info in the wiki.
These endpoints return the selected external context name in the X-Doco-CD-Context response header. Their JSON response shapes do not change.
one_shot alias for jobs, deprecated labels, and PKCS#1 SSH support by @kimdre in #1757Full Changelog: v0.112.0...v0.113.0
This pre-release removes three deprecated features that have reached end-of-life.
This pre-release removes three deprecated features that have reached end-of-life.
Job execution mode: the one_shot alias for one_off is no longer supported.
Use one_off instead; one_shot values are rejected.
Auto-discovery labels: legacy label formats are retired:
cd.doco.deployment.auto_discovercd.doco.deployment.auto_discover.deletecd.doco.deployment.auto_discovery.deleteNew deployments use cd.doco.deployment.auto_discovery and the JSON configuration label cd.doco.deployment.auto_discovery.config.
SSH private keys: PKCS#1 ENCRYPTED PRIVATE KEY support is removed because
it relied on the deprecated Go x509.DecryptPEMBlock() API. Use modern OpenSSH
or unencrypted PEM key formats.
Existing deployments using legacy auto-discovery labels are migrated automatically:
one_shot to one_off in job definitions.Docker Compose services are started automatically after they are created or updated. To let an external tool control a service's lifecycle, set the cd.doco.deployment.autostart service label to false.
services:
on-demand:
image: example/on-demand:latest
labels:
cd.doco.deployment.autostart: "false"The label defaults to true. When it is false:
More info in the wiki: https://doco.cd/next/Deploy-Settings/#preserve-a-services-running-state
one_shot alias for jobs, deprecated labels, and PKCS#1 SSH support by @kimdre in #1757Full Changelog: v0.113.0-rc.1...v0.113.0-rc.2
This pre-release adds multi-context support for Docker contexts to all subsystems of doco-cd:
This pre-release adds multi-context support for Docker contexts to all subsystems of doco-cd:
context label)Project, stack, and scheduled-job endpoints now accept one optional context query parameter. If it is omitted or set to default, the endpoint uses the default Docker context. Named contexts must exist in the Docker CLI context store available to doco-cd. More info in the wiki.
These endpoints return the selected external context name in the X-Doco-CD-Context response header. Their JSON response shapes do not change.
Full Changelog: v0.112.0...v0.113.0-rc.1
Failed Compose Lifecycle Hooks are now detected and handled correctly.
Full Changelog: v0.111.0...v0.112.0
Some stacks cannot be deployed without a running SCM available (e.g. a self-hosted Gitea/Forgejo instance that should be deployed via doco-cd (hence a
Some stacks cannot be deployed without a running SCM available (e.g. a self-hosted Gitea/Forgejo instance that should be deployed via doco-cd (hence a chicken-and-egg problem), or a stack that is deployed from a local Git repository that is not hosted on any remote SCM). This release adds support for polling local Git repositories to solve this problem.
Mount the directory containing your local Git repo into the doco-cd container, then use a poll config with the url: value being the absolute path to the Git repo inside the container.
More info in the wiki at Polling Local Filesystem Repositories.
In addition to interval-based polling, doco-cd watches the local repository's git directory for changes and triggers a deployment check immediately when new commits land, without waiting for the next interval. This is enabled by default; set watch: false to disable it and rely on interval only. Set interval: 0 (with watch left enabled) to rely on the watcher exclusively, with no periodic fallback polling at all.
See the watch poll option in the wiki.
.env files (env_files) are now parsed with compose-go's dotenv engine (the same one Docker Compose uses) instead of godotenv. Variables set in one env_files entry are now correctly available for ${VAR} substitution in later entries.
Reference docs:
.env syntax (.env file section): https://docs.docker.com/compose/how-tos/environment-variables/variable-interpolation/#env-fileInterpolation syntax): https://docs.docker.com/reference/compose-file/interpolation/Warning
No longer supported / behavior changes:
${var} references are no longer left as literal text. Previously, godotenv only expanded UPPERCASE variable names and silently ignored ${lowercase_var}/${MixedCase}, keeping the literal string in the value. These are now interpolated like any other variable — if unset, they resolve to an empty string instead of the original literal text.If any of your .env files intentionally relied on lowercase ${...} placeholders being left untouched, rename them to avoid the $/${} pattern (e.g. escape with \$) or ensure the referenced variable is actually defined.
Note
New/added support:
.env files: ${VAR:-default}, ${VAR-default}, ${VAR:+alt}, ${VAR+alt}, ${VAR:?error}, ${VAR?error}.SOME_VAR) now inherit the value from the process environment or an earlier env_files entry.Full Changelog: v0.110.1...v0.111.0
Nothing published for this version
Nothing published for this version
Fixed a bug that caused the job API to not return the last_run_at field anymore.
Fixed a bug that caused the job API to not return the last_run_at field anymore.
Full Changelog: v0.110.0...v0.110.1
Direct TLS/SSL Support for web server
Set the new environment variables HTTP_TLS_CERT_FILE and HTTP_TLS_KEY_FILE to enable HTTPS for the API and metrics server, and healthcheck.
Added automatic OpenBao certificate rotation, see the wiki for more info.
Set these env vars for doco-cd to enable and configure the cert rotation watcher:
CERT_ROTATION_ENABLED=true
CERT_ROTATION_THRESHOLD=72h
CERT_ROTATION_CHECK_INTERVAL=1hUse pki-role:
external_secrets:
CERT: "pki-role:pki:my-role:app.example.com"pki-role:certs:myapp-role:myapp.example.com -> Issues a new certificate for the common name myapp.example.com using the myapp-role PKI role in the certs secret engine in the root namespace.pki-role:my-namespace:certs:myapp-role:myapp.example.com -> Same as above but in the my-namespace namespace.pki-role: issues a fresh certificate and matching private key on deploy. When rotation is enabled, doco-cd will watch the deployed cert’s expiry and redeploy the affected service before it expires.
Use CERT for the certificate and CERT_KEY for the private key in your compose file.
See the OpenBao Provider documentation in the PR.
Full Changelog: v0.109.2...v0.110.0
Added automatic OpenBao certificate rotation
Added automatic OpenBao certificate rotation
To test the new feature, switch your OpenBao secret reference from pki: to pki-role: and enable the rotation watcher:
external_secrets:
CERT: "pki-role:pki:my-role:app.example.com"Examples:
pki-role:certs:myapp-role:myapp.example.com -> Issues a new certificate for the common name myapp.example.com using the myapp-role PKI role in the certs secret engine in the root namespace.pki-role:my-namespace:certs:myapp-role:myapp.example.com -> Same as above but in the my-namespace namespace.Then set these env vars for doco-cd:
CERT_ROTATION_ENABLED=true
CERT_ROTATION_THRESHOLD=72h
CERT_ROTATION_CHECK_INTERVAL=1hpki-role: issues a fresh certificate and matching private key on deploy. When rotation is enabled, doco-cd will watch the deployed cert’s expiry and redeploy the affected service before it expires.
Use CERT for the certificate and CERT_KEY for the private key in your compose file.
See the OpenBao Provider documentation in the PR.
Full Changelog: v0.109.2...v0.110.0
Full Changelog: v0.109.2...v0.110.0-rc.1
Nothing published for this version
Nothing published for this version
Added TRUSTED_PROXY_NETWORKS and TRUSTED_PROXY_HEADER env vars to configure trusted proxies for real client ip logging in API logs.
Added TRUSTED_PROXY_NETWORKS and TRUSTED_PROXY_HEADER env vars to configure trusted proxies for real client ip logging in API logs.
Full Changelog: v0.109.1...v0.109.2
Your coding agent can read these notes before it upgrades. Set up the MCP server →