NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #4442 most downloaded on PyPI
Python client for Taskcluster
Last release 13 days ago
21 Sep 2026
Ships on a steady schedule
a new release about every 2 weeks
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
12 years old
491 releases · first in 2014
▶ [patch] Refactor web-server middleware
▶ [patch] Refactor web-server middleware
▶ [patch] UI: Improves login window after redirect
▶ [patch] Fix 3rd party login header issue
One column per quarter.
▶ [patch] #7643 Upgrades to rust 1.86.0.
▶ [patch] #7643 Upgrades to rust 1.86.0.
▶ [patch] Generic Worker now handles artifact upload inside a task feature rather than the main processing loop of the task execution. This refactor improves code modularity.
<details> <summary>5 Dependabot updates</summary>
</details>
▶ [patch] Generic Worker: adds additional worker logs around the artifact upload process to help debug artifact upload performance.
▶ [patch] Generic Worker: adds additional worker logs around the artifact upload process to help debug artifact upload performance.
▶ [patch] #7625 Generic Worker now supports running Taskcluster Proxy on the docker bridge network outside of D2G.
▶ [patch] #7611 Fixes worker-manager events that didn't include launchConfigId in pulse messages.
▶ [patch] #7611
Fixes worker-manager events that didn't include launchConfigId in pulse messages.
▶ [patch] Upgrades to go1.23.8 (SECURITY) and yarn 4.8.1
▶ [minor] #6783 Docs: adds Generic Worker Configuration help page to the reference docs.
▶ [patch] #7606 UI displays paginated quarantine history on the worker page.
▶ [minor] #7543 Fixes broken local development UI container.
<details> <summary>4 Dependabot updates</summary>
</details>
▶ [patch] Upgrades to go1.23.7, Node.js 22.14.0, and yarn 4.7.0
▶ [patch] Upgrades to go1.23.7, Node.js 22.14.0, and yarn 4.7.0
▶ [patch] Improves worker manager launch configurations documentation
▶ [minor] #6464 Generic Worker: adds memory usage monitoring during tasks and reports average and peak memory used, in addition to the system's total available memory.
If the total percentage of memory used exceeds 90% for 5 consecutive measurements at 0.5s intervals, the worker will abort the task to prevent OOM crashes and errors. If disableOOMProtection (default false) is set to true in the worker configuration, the worker will continue to monitor and report on memory usage, but will not abort the task if memory consumption is high.
Resource monitoring can be disabled with worker config enableResourceMonitor (default true) or per task via payload.features.resourceMonitor (default true).
▶ [patch]
Generic Worker: only warn about missing audio/video os groups for non-d2g tasks.
▶ [minor] #7594
Docker Worker (D2G): adds volume type for artifacts. This is strictly used for D2G purposes only. Use this type to have D2G volume mount your artifact path instead of docker cp'ing the artifact at the end of the task run. This can be useful under spot termination instances where the docker cp command doesn't get a chance to run, instead a volume mount will have the files on the host ready for upload as soon as the spot termination requests comes in.
▶ [patch] #7603 UI shows all dates in UTC.
<details> <summary>5 Dependabot updates</summary>
</details>
▶ [patch] Upgrades goreleaser to v2.7.0 for building client-shell binaries during releases.
▶ [patch]
Upgrades goreleaser to v2.7.0 for building client-shell binaries during releases.
▶ [patch] #7581
D2G: add audio/video os-groups and scopes needed when the Docker Worker task payload requests these loopback devices.
▶ [minor] UI shows launch configs for worker pool with details and runtime worker/error statistics. Improved navigation between pages.
▶ [minor] Worker-Manager introduces new endpoints:
listWorkerPoolLaunchConfigs(workerPoolId) to fetch all active and archived launch configs for worker pool.workerPoolStats(workerPoolId) to return workers capacity and counts grouped by launch config▶ [patch] Generic Worker: fix panic when the taskcluster proxy task feature tries to terminate the taskcluster proxy PID.
▶ [patch]
Generic Worker: fix panic when the taskcluster proxy task feature tries to terminate the taskcluster proxy PID.
▶ [patch] Generic Worker: fix detection of docker bridge gateway address in the presence of ipv6
<details> <summary>1 Dependabot updates</summary>
</details>
▶ [patch] Fixes worker-manager provisioner behaviour for worker pools with capacityPerInstance > 1
▶ [patch] Fixes worker-manager provisioner behaviour for worker pools with capacityPerInstance > 1
▶ [patch] #7427 Generic Worker now writes file-caches.json and directory-caches.json after each task that uses mounts feature.
<details> <summary>1 Dependabot updates</summary>
</details>
▶ [patch] #7568 Generic Worker: fixes panic while trying to refresh taskcluster-proxy credentials.
▶ [patch] #7568
Generic Worker: fixes panic while trying to refresh taskcluster-proxy credentials.
▶ [patch] #7541 Added missing primary keys for several db tables.
▶ [patch] #7541 Added missing primary keys for several db tables.
▶ [minor] #7552 D2G: use the default docker bridge network instead of the host network.
▶ [minor] Generic Worker: when running a task through d2g, the taskcluster proxy now listens on the docker bridge instead of localhost.
<details> <summary>1 Dependabot updates</summary>
</details>
▶ [minor] #7545 D2G: sets each payload artifact as optional so tasks won't resolve as failed/failed if the artifact doesn't exist, like Docker Worker
▶ [minor] #7545
D2G: sets each payload artifact as optional so tasks won't resolve as failed/failed if the artifact doesn't exist, like Docker Worker does.
▶ [minor] #7545
Generic Worker: adds optional field to payload artifacts to ignore any artifact upload errors, for example, if the artifact isn't known to exist at the end of a task but you don't want the task to resolve as failed/failed. This makes the transition from Docker Worker --> Generic Worker (through d2g) more seamless, as Docker Worker does not resolve tasks as failed/failed if the artifact doesn't exist.
▶ [patch] #7411
Generic Worker: no longer chown loopback video/audio devices to the task user. Explicitly change group of the devices to video/audio, respectively, so that users in those groups may still access them.
<details> <summary>4 Dependabot updates</summary>
</details>
▶ [patch] #5438 Fixes hook id in audit history table. Changes worker_pool to worker-pool for consistency as entity type.
▶ [patch] #5438
Fixes hook id in audit history table.
Changes worker_pool to worker-pool for consistency as entity type.
▶ [MAJOR] #5438 Added audit history tracking for clients, roles, secrets, and hooks. History can be queried using auth.getEntityHistory(type, entityId
▶ [MAJOR] #5438
Added audit history tracking for clients, roles, secrets, and hooks.
History can be queried using auth.getEntityHistory(type, entityId) and is retained for 30 days.
▶ [minor] Worker manager introduces listWorkerPoolsStats() endpoint to return worker stats for all worker pools. Fixes UI not showing capacity for wor
▶ [minor]
Worker manager introduces listWorkerPoolsStats() endpoint to return worker stats for all worker pools.
Fixes UI not showing capacity for worker pools.
▶ [patch] Fixes an error in worker manager's provisioner when no launch configs are defined.
▶ [patch] Fixes an error in worker manager's provisioner when no launch configs are defined.
capacityPerInstance - specify worker capacity per instance (old top-level propert is supported but is deprecated)
▶ [MAJOR] #7086
Worker Manager introduces launchConfigId and schema changes:
workerManager configuration object in launch configs that includes:
launchConfigId - unique identifier for tracking and error attributioncapacityPerInstance - specify worker capacity per instance (old top-level propert is supported but is deprecated)initialWeight - control provisioning probability (0-1)maxCapacity - hard limit on number of instances per configThe provisioner distributes load across configs by:
▶ [patch] #7532 Generic Worker (windows): fix cache ownership issues. Clean up ACLs so prior task users aren't referenced anymore.
▶ [patch] #7532 Generic Worker (windows): fix cache ownership issues. Clean up ACLs so prior task users aren't referenced anymore.
▶ [patch] #7527
Fixes an issue introduced in Generic Worker 81.0.0 where the Chain of Trust
certificate would not contain all of the additional data specified in the
task-provided chain-of-trust-additional-data.json file.
Generic Worker 81.0.0 enhanced the Chain of Trust task payload feature to
support adding arbitrary additional data to the public/chain-of-trust.json
artifact. This was implemented in PR
#7507 by allowing the
task to write additional data to the file chain-of-trust-additional-data.json
in the task directory. The feature was meant to merge the content of this file
with the generated chain-of-trust.json file before publishing it as an
artifact. However, the merge of the two json objects was broken if they
contained common ancestors. For example, the generated chain-of-trust.json
file contains a top level object property environment. If the task-provided
chain-of-trust-additional-data.json file also contained a top level object
property environment containing further properties, they would be omitted
from the resulting environment property in the published Chain of Trust
certificate.
▶ [patch] #7014
Generic Worker now adds environment.imageHash (always), and
environment.imageArtifactHash (when present) to public/chain-of-trust.json
when running Docker Worker Chain of Trust tasks, to match Docker Worker
behaviour.
▶ [patch] #7479
Add a way to update d2g test expectations by setting the
D2G_UPDATE_TEST_EXPECTATIONS environment variable while running tests
▶ [patch] #7521 Generic Worker: fixes an issue introduced in v81.0.0 where TASK_USER_CREDENTIALS env var wasn't written to the task's environment if t
▶ [patch] #7521
Generic Worker: fixes an issue introduced in v81.0.0 where TASK_USER_CREDENTIALS env var wasn't written to the task's environment if task.payload.features.runTaskAsCurrentUser was enabled.
<details> <summary>2 Dependabot updates</summary>
</details>
▶ [patch] #7517 Generic Worker: fixes fork/exec issue on headless, multiuser engine introduced in v81.0.0.
▶ [patch] #7517
Generic Worker: fixes fork/exec issue on headless, multiuser engine introduced in v81.0.0.
▶ [patch] Upgrades to go1.23.6 and golangci-lint 1.63.4
▶ [patch] Upgrades to go1.23.6 and golangci-lint 1.63.4
▶ [minor] #7508 Removes Cloud Armor specific policy config from deployment templates as it was applied incorrectly.
▶ [MAJOR]
Generic Worker: feature runTaskAsCurrentUser (note: Task not Tasks) has been added to replace the previous global task config setting runTasksAsCurrentUser (which is no longer supported). Worker pools can elect to enable or disable the feature with boolean config setting enableRunTaskAsCurrentUser. Tasks with the feature enabled (task.payload.features.runTaskAsCurrentUser = true) require scope generic-worker:run-task-as-current-user:<provisionerID>/<workerType>.
This change was introduced in order that access to this privileged feature are guarded not only by worker config settings, but also by task scopes, and furthermore the feature must be explicitly requested, in order that tasks do not unintentionally inherit the feature by virtue of overgenerous scopes or unintentionally running on a pool with the feature enabled.
▶ [patch] #7462 Generic Worker (D2G): prune docker images during garbage collection, if needed.
▶ [MAJOR] The interactive feature will now drop users in the task container instead of the host
▶ [minor] #7506
Generic Worker Chain Of Trust feature now allows tasks to inject additional
data into public/chain-of-trust.json. Tasks wishing to add additional fields
should write them as json to the file chain-of-trust-additional-data.json in
the task directory. In this initial release, there are no provisions to
customise the name or path of the file. The file contents will be merged with
the default chain of trust certificate, with the default field values taking
precedence over any provided in chain-of-trust-additional-data.json. If the
file is not created by the task, no merging will take place, and the feature
will operate as before.
▶ [minor] Set TASK_WORKDIR environment variable for generic-worker tasks.
▶ [patch]
Fixed the --completed flag for taskcluster group list so it actually works instead of returning an empty list all the time
▶ [MAJOR] D2G: Drop support for podman. Docker worker payload.capabilities.containerEngine is removed. Generic Worker config d2gConfig.containerEngine
▶ [MAJOR]
D2G: Drop support for podman. Docker worker payload.capabilities.containerEngine is removed. Generic Worker config d2gConfig.containerEngine is removed.
<details> <summary>6 Dependabot updates</summary>
</details>
▶ [MAJOR] #7464 Static workers always receive workerPool's workerConfig. Previously workerConfig was stored in the worker.providerData, which made it
▶ [MAJOR] #7464 Static workers always receive workerPool's workerConfig. Previously workerConfig was stored in the worker.providerData, which made it impossible to update config without creating new worker
▶ [minor] #7465
WorkerManager.createWorker() API call handles non-unique errors and responds with 409
if worker with same workerId already exists in the pool
▶ [patch] #7463 D2G: Pull docker image as initial command to ensure latest image version is used during task execution.
▶ [patch] #7218 Generic Worker: Unset cached interactive username when we unexpectedly receive a non-task username.
▶ [patch] #7218 Generic Worker: Unset cached interactive username when we unexpectedly receive a non-task username.
This will fix errors like: interactive username gdm does not match task user task_173764785573833.
▶ [minor] Generic Worker: Stop leaking anonymous volumes created by docker containers when using d2g with tasks that have artifacts declared in the task
▶ [patch] Upgrades to Node.js v22.13.1 (SECURITY).
▶ [patch] Upgrades to Node.js v22.13.1 (SECURITY).
▶ [minor] Worker-manager scanner and provisioner logs cloud api call times and statistics. New metric will be logged with 'cloud-api-metrics' type at the end of each scan and provision loop.
▶ [patch] Upgrades to Node.js v22.13.0, rust v1.84.0, and yarn v4.6.0.
▶ [patch] Upgrades to Node.js v22.13.0, rust v1.84.0, and yarn v4.6.0.
▶ [patch] Upgrades to go1.23.5 (SECURITY).
▶ [MAJOR] #7443
Worker-pool's lifecycle queueInactivityTimeout minimum allowed value is increased
to 1200 (20min) to avoid having workers being incorrectly considered idling
while they were working on a task.
▶ [minor] Generic Worker: Improve cache mounting speed on linux, especially when they contain a lot of tiny files
▶ [patch] Generic Worker: fixes permissions issues with ReadOnlyDirectory mounts.
▶ [patch] Generic Worker: fixes permissions issues with ReadOnlyDirectory mounts.
▶ [minor] The notify service includes rootUrl in the json-e context when rendering the link included in emails.
▶ [minor]
The notify service includes rootUrl in the json-e context when rendering the link included in emails.
▶ [minor] Allows the ability to attach a Cloud Armor policy to a BackendConfig and to use that BackendConfig in the ingress configuration. (OPST-1755)
▶ [minor] Allows the ability to attach a Cloud Armor policy to a BackendConfig and to use that BackendConfig in the ingress configuration. (OPST-1755)
▶ [patch] Web-Server: fixes missing callback function in passport req.logout.
▶ [minor] #7404 Re-apply the patch to fix docker cache issues and fix the issues when using podman as the container engine.
▶ [minor] #7404 Re-apply the patch to fix docker cache issues and fix the issues when using podman as the container engine.
▶ [minor] Adding type checks with jsdoc and typescript.
<details> <summary>5 Dependabot updates</summary>
</details>
▶ [MAJOR] Generic Worker: adds worker config feature toggles to quickly/easily enable/disable features across entire worker pools. All features are en
▶ [MAJOR] Generic Worker: adds worker config feature toggles to quickly/easily enable/disable features across entire worker pools. All features are enabled, by default.
Generic Worker: adds d2gConfig worker config to configure D2G translations. enableD2G and containerEngine config settings have been moved into this new config. The following is the new structure (with default values shown):
{
...
"d2gConfig": {
"enableD2G": false,
"allowChainOfTrust": true,
"allowDisableSeccomp": true,
"allowHostSharedMemory": true,
"allowInteractive": true,
"allowKVM": true,
"allowLoopbackAudio": true,
"allowLoopbackVideo": true,
"allowPrivileged": true,
"allowPtrace": true,
"allowTaskclusterProxy": true,
"containerEngine": "docker"
},
...
}
Tasks using disabled features will be resolved as exception/malformed-payload.
▶ [minor] #7390
Generic Worker: adds d2gConfig.allowGPUs (default: false) and d2gConfig.gpus (default: all) worker config to provide NVIDIA GPU access to the running container for d2g-translated task payloads.
The translation will add the gpus flag: --gpus <d2gConfig.gpus> to the docker run ... command. Read more about the usage here.
▶ [minor]
Generic Worker: adds disableNativePayloads (default: false) worker config option (linux only) to require all task payloads to be Docker Worker payloads. If this option is set to true, the task log will no longer contain the translated task definition and the warning about using Docker Worker payloads.
Tasks submitted with native payloads will be resolved as exception/malformed-payload.
Generic Worker: adds d2gConfig.logTranslation (default: true) worker config to control whether the D2G-translated task definition is logged to the task logs.
<details> <summary>2 Dependabot updates</summary>
</details>
▶ [patch] Upgrades to Node.js v22.12.0, go v1.23.4, and yarn v4.5.3.
▶ [patch] Upgrades to Node.js v22.12.0, go v1.23.4, and yarn v4.5.3.
▶ [MAJOR] #3823 Add authentication to websockets at the time of subscribing to pulse messages
This introduces new scope web:read-pulse that needs to be added to the existing anonymous role
in order to keep Pulse subscriptions public.
▶ [patch] #4086
queue.getArtifact() checks if artifact is expired and returns ResourceExpired - 410 in such cases
<details> <summary>1 Dependabot updates</summary>
</details>
▶ [patch] #7404 Generic Worker: Reverting 61b985dd009210a204da3bb354eab2037d132bef due to issue #7404 with cache permissions.
▶ [patch] #7404 Generic Worker: Reverting 61b985dd009210a204da3bb354eab2037d132bef due to issue #7404 with cache permissions.
<details> <summary>6 Dependabot updates</summary>
</details>
▶ [MAJOR] #7128 Generic Worker now only changes file ownership of files inside caches, if the file was owned by the previous task user. Previously Gen
▶ [MAJOR] #7128 Generic Worker now only changes file ownership of files inside caches, if the file was owned by the previous task user. Previously Generic Worker changed the ownership of all files inside a cache to be the new task user, which caused problems if files were modified inside containers using different subuids.
▶ [patch] #7386 Fixes UI issue where "No WorkerPool exists" error was shown in pending/claimed tasks list.
<details> <summary>6 Dependabot updates</summary>
</details>
▶ [patch] D2G: ConvertScopes() additionally checks scopes for loopbackAudio and loopbackVideo.
▶ [patch]
D2G: ConvertScopes() additionally checks scopes for loopbackAudio and loopbackVideo.
▶ [patch]
D2G: ConvertScopes() checks all scopes at once so users would see all missing scopes in one run.
▶ [patch] Upgrades to go1.23.3.
▶ [patch] Upgrades to the new Node.js LTS version 22.11.0
▶ [patch] #7246 Add linting rule for spaces before and after keywords Add linting rule to remove spaces inside round parenthesis
<details> <summary>8 Dependabot updates</summary>
</details>
▶ [patch] Upgrades to Node.js 20.18.0 and yarn 4.5.1
▶ [patch] Upgrades to Node.js 20.18.0 and yarn 4.5.1
▶ [MAJOR]
D2G: Renamed methods Convert() --> ConvertPayload() and Scopes() --> ConvertScopes().
D2G: ConvertScopes() checks that the provided docker worker payload is valid with the supplied scopes. Generic Worker will now resolve a docker worker task as exception/malformed-payload if any required docker worker scopes are missing for its payload.
▶ [MAJOR] #7320 Reverts PR #7324. Taskcluster Proxy will now only listen on 127.0.0.1.
▶ [patch] #7340 D2G: Use unique task container names to avoid container naming conflicts.
▶ [patch]
Fixed the rust library for uploading artifact when the object service returned
a content-length header. It will now avoid duping the header which was
resulting in 400s from upstream object storages.
▶ [patch] The rust client will now properly fail when the PUT url call returns an error while uploading an artifact.
<details> <summary>3 Dependabot updates</summary>
</details>
▶ [patch] #7322 Worker Manager: AWS and GCP workers now transition into stopping state on call to removeWorker.
▶ [patch] #7322
Worker Manager: AWS and GCP workers now transition into stopping state on call to removeWorker.
▶ [MAJOR] #7320 D2G: containers no longer use the host's network namespace
▶ [patch] #7327
D2G: Don't provide --privileged flag for dind and host shared memory use. Only using now as a one-to-one mapping to Docker Worker's privileged payload flag.
▶ Additional change not described here: #7286.
▶ [patch] #7309 D2G: No longer pass --init to the docker run ... command. This was breaking docker image build tasks that Taskgraph creates. To kill t
▶ [patch] #7309
D2G: No longer pass --init to the docker run ... command. This was breaking docker image build tasks that Taskgraph creates. To kill the running docker container, we now pass -s KILL to the timeout command.
▶ [patch] #6858
D2G: Translated payload or task definition will no longer contain the default expires string for artifacts, "0001-01-01T00:00:00.000Z".
▶ [patch] #7307 Generic Worker (D2G): Pass devices through to the docker run ... command using --device instead of a volume mount.
▶ [patch] #7307
Generic Worker (D2G): Pass devices through to the docker run ... command using --device instead of a volume mount.
▶ [patch] Upgrades to go1.23.2 and yarn 4.5.0
▶ [minor]
The notify service includes rootUrl in the json-e context when rendering slack/matrix/email messages.
▶ [patch]
D2G: No longer specify file mount format on image if compressed with gzip, bzip2, xz, or zstd when using docker. Generic Worker will now no longer decompress these files before running docker load. Docs here.
▶ [patch] #7305
Generic Worker multiuser engine task log headers now include generic-worker
config properties runTasksAsCurrentUser and headlessTasks in order to help
troubleshoot unexpected behaviour. These properties fundamentally affect how
the task runs, so it is useful to log them together with the other worker
environment information.
Sentry reports also now include this information.
▶ Additional change not described here: #6923.
<details> <summary>5 Dependabot updates</summary>
</details>
▶ [patch] #7052 Fixes edge-case in estimation that was introduced in #7283 where claimed count might be greater than the existing capacity.
▶ [patch] #7052 Fixes edge-case in estimation that was introduced in #7283 where claimed count might be greater than the existing capacity.
…many idling workers. queue.pendingTasks is being deprecated in favour of queue.taskQueueCounts which includes both pending and claimed tasks counts.
▶ [minor] #7052
Worker-manager now uses number of claimed tasks during estimation process to avoid having too many idling workers.
queue.pendingTasks is being deprecated in favour of queue.taskQueueCounts which includes both pending and claimed tasks counts.
▶ [patch] #7222
Worker Runner: Replaces deprecated /proc/<pid>/oom_adj with /proc/<pid>/oom_score_adj.
▶ [MAJOR] #7174
Queue service now emits pulse messages to the exchange/taskcluster-queue/v1/task-exception exchange when a task has an exception that is automatically retried.
▶ [patch] #7151 Fixes Task dependencies not being reloaded in the UI when switching between tasks.
▶ [patch] Fixes continuation token error handling
▶ [MAJOR] #7235 Generic Worker (windows): Removes calls to wmic (being deprecated) and net in favor of a more modern approach using PowerShell cmdlets…
▶ [patch] #7278
Adds containerEngine docs in Capabilities section of Docker Worker docs.
▶ [MAJOR] #7235
Generic Worker (windows): Removes calls to wmic (being deprecated) and net in favor of a more modern approach using PowerShell cmdlets.
The powershell executable is required to be in the path.
▶ [MAJOR] Generic Worker: Adds containerEngine worker config option to select between docker and podman to be used during D2G payload translations.
▶ [MAJOR]
Generic Worker: Adds containerEngine worker config option to select between docker and podman to be used during D2G payload translations.
Default is docker and this value will be overridden by task.payload.capabilities.containerEngine, if specified.
▶ [MAJOR]
Generic Worker: Adds enableD2G worker config option to internally process Docker Worker payloads using D2G. Defaults to false and will return a malformed-payload if a Docker Worker payload is detected and this config isn't set to true.
▶ [minor]
D2G: Adds capabilities.containerEngine to the Docker Worker payload schema strictly to use as a docker/podman toggle for the d2g-translated payload.
▶ [minor] #4595
Generic Worker can now be run in headless mode, meaning tasks do not have a
dedicated graphical user environment. To do this, the Generic Worker config
setting headlessTasks should be set to true. This can only be enabled or
disabled at the Worker level, tasks cannot choose if they run in a headless
environment or not, it depends on the worker settings (i.e. the Worker Pool
configuration).
There are no reboots in headless mode, and multiple worker instances can
be run concurrently on the same host (e.g. Worker Pool definitions may have
capacity greater than one).
Furthermore, on Linux, Gnome Desktop is no longer required.
▶ [patch] #7151 Fixes a bug in UI where task dependencies were not having colours.
▶ [patch] #7255
D2G now passes --init to the podman run/docker run command it generates,
in order that signals are properly received and processed by the container.
▶ Additional change not described here: #7269.
<details> <summary>1 Dependabot updates</summary>
</details>
▶ [patch] #7263 Improve github checks output - handle 404 cases for empty artifact list. Adds artifact redirect page in UI to redirect user to the act
▶ [patch] #7263 Improve github checks output - handle 404 cases for empty artifact list. Adds artifact redirect page in UI to redirect user to the actual artifact.
▶ [patch] Upgrades to Node.js v20.17.0 and go1.23.1 (security release).
▶ [patch] Upgrades to Node.js v20.17.0 and go1.23.1 (security release).
▶ [minor] #7257
Worker-manager provides an option to request public IP for generic-worker in Azure that is skipped by default.
Passing publicIp = true in the launch configuration will enable the public IP request.
{
"workerManager": {
"publicIp": true
}
}
▶ [minor] #7151 Queue service supports up to 10.000 dependencies for a single task.
▶ [MAJOR] Update dependencies in the rust client
▶ [patch] #5669 Enhanced github integration with information: task runtime, head of logs, status information, link of task group, list of 50 artifacts.
▶ [patch] #5669 Fix incorrect artifact url generation Fix artifact fetch with listArtifact due to permission issues
▶ Additional change not described here: #5669.
<details> <summary>4 Dependabot updates</summary>
</details>
▶ [patch] #7233 getArtifact now encodes artifact names to return valid URLs even when the name contains unsafe characters.
▶ [patch] #7233 getArtifact now encodes artifact names to return valid URLs even when the name contains unsafe characters.
<details> <summary>3 Dependabot updates</summary>
</details>
▶ [patch] #7218 Generic Worker Multiuser engine on Linux, macOS and FreeBSD now waits for the required task user to be logged in to the console sessio
▶ [patch] #7218 Generic Worker Multiuser engine on Linux, macOS and FreeBSD now waits for the required task user to be logged in to the console session, rather than waiting for any user to be logged in, and then checking whether it is the anticipated user. This subtle change in behaviour means that temporarily a different user may be (or appear to be) logged into the console session without causing Generic Worker to panic. It is hoped that this will reduce intermittent issues where a different user appears to be logged in (such as gdm user on Linux) since it is suspected that this might just be a fleeting login that passes due to some race condition in the start up of the Gnome Desktop.
If this doesn't resolve the issue, and under certain circumstances, the gdm user instead remains logged in, i.e. it is not a fleeting login, we may need to restore the previous behaviour, since otherwise when the issue does occur, it would take a full 5 minutes before timing out, adding to costs unnecessarily. However, we hope that that will not be the case.
▶ [patch] #7012 Generic Worker retains the interactive username it determines inside WaitForLoginCompletion (by returning it) to avoid needing to re-d
▶ [patch] #7012 Generic Worker retains the interactive username it determines inside WaitForLoginCompletion (by returning it) to avoid needing to re-determine it later. The intention is to reduce intermittent errors caused by the underlying method to determine the interactive username itself intermittently failing. So long as the interactive username can be determined just once during the specidied timeout period, the value can be retained and used when required.
▶ [patch] #7172 Fixes UI js error on dashboard on some deployments
▶ [patch] #7172 Fixes UI js error on dashboard on some deployments
▶ [patch] #6304 GitHub service no longer skips CI based on PR description. It will only skip CI based on the PR title or the commit message, as GitHub does.
<details> <summary>7 Dependabot updates</summary>
</details>
▶ [patch] #7202 Fixes github.renderTaskclusterYml rendering error for the payloads including invalid params
▶ [patch] #7202
Fixes github.renderTaskclusterYml rendering error for the payloads including invalid params
▶ [patch] #7195 Fixes worker-manager intermittent test failure
▶ [patch] bug 1907075 Web server graphql endpoints return 413 instead of 500 error.
▶ [patch] Upgrades to Node.js v20.16.0, go v1.23.0, and yarn v4.4.0.
▶ [MAJOR] #7036 Secrets are being introduced in services configuration. All sensitive values that are marked as secrets would be deployed in kubernetes as Secrets (as they used to be). All non-sensitive values would be stored inside ConfigMap resources. Deployments and CronJobs would fetch values from both secrets and configuration maps.
▶ [patch] #7167 Change the polling period for EC2 spot instance interruption notices to 5 seconds, as recommended by AWS documentation.
▶ [MAJOR] #7073 Generic Worker now logs to standard error instead of standard out. This is a bug fix, it seems it has always been logging to standard out.
▶ [minor]
Change adduser usage to useradd
adduser is a debian specific wrapper around useradd and friends. By
changing to useradd, we allow workers to be deployed on non debian
derivative distributions.
Generic Worker multiuser engine on Linux/FreeBSD now depends on:
and no longer depends on:
▶ [minor] #7145
Fixes inconsistency in the internal queue implementation that could lead to tasks being visible as pending in the UI
after they were resolved with deadline-exceeded.
▶ [patch] #7128 Generic Worker / D2G partial bug fix: support has been improved for running Docker Worker tasks with caches under Generic Worker. Previously, caches from a Docker Worker task running under Generic Worker containing files owned by a user other than root would not be owned by the same (container) user when the cache was mounted in a future task. D2G now consistently maps container uids and gids to host subuids and subgids (when caches are used) in order that cache file ownership, as seen from inside the container, is maintained across task runs. However, this fix does not apply when the privileged capability is enabled in the Docker Worker payload, since privileged tasks are executed under docker rather than podman. This fix only applies when podman is used.
▶ [patch] #7128
Generic Worker multiuser engine on Linux now uses /usr/sbin/deluser --remove-home instead of /usr/sbin/deluser --remove-all-files when deleting previous task users. This ensures that caches that may still be owned (in whole or in part) by the task user are not deleted.
<details> <summary>5 Dependabot updates</summary>
</details>
▶ [patch] #7073 CLI tools and generic-worker now returns short-version string if executed with --short-version argument:
▶ [patch] #7073
CLI tools and generic-worker now returns short-version string if executed with --short-version argument:
generic-worker --short-versionlivelog --short-versionwebsocktunnel --short-versionstart-worker --short-versiontaskcluster version --short-version▶ [patch] #7129 Worker-manager would avoid sending emails with duplicate error messages, as long as error message and information are the same.
▶ [minor] #7139
Generic Worker now sets environment variable TASK_GROUP_ID to the taskGroupId of the currently running task.
▶ [patch] #7132
Bug fix: Generic Worker multiuser on Linux/macOS was previously executing task
commands as processes that did not include the supplementary groups of the task
user, only its primary group. Until upgrading from Ubuntu 22.04 to Ubuntu 24.04
task users did not have supplementary groups, so this had no negative
consequences. However, /usr/sbin/adduser on Ubuntu 24.04 by default gives
newly generated users the supplementary group users, which introduced a
discrepency between the groups that the task command process was in, and the
groups that the user was in. Generic Worker multiuser on Linux and macOS now
ensures that the launched processes of task commands are given not only the
primary group of the task user, but also any supplementary groups that it has.
<details> <summary>3 Dependabot updates</summary>
</details>
▶ [patch] #7085 Adds timestamp to the worker related pulse events that were added in #7085.
▶ [patch] #7085
Adds timestamp to the worker related pulse events that were added in #7085.
▶ [patch] Switch CI to use Ubuntu 24.04
▶ [MAJOR] #7126 d2g no longer includes --privileged in all generated podman run commands. This was previously introduced as a breaking change in relea…
▶ [MAJOR] #7126
d2g no longer includes --privileged in all generated podman run commands. This was previously introduced as a breaking change in release 61.0.0 (PR #6891) but has broken some tasks. The original reason for adding it (#6890) seems to no longer apply, as the original bug report is no longer reproducible. This therefore reverts the d2g treatment of the --privileged flag to how it was before release 61.0.0.
▶ [minor] #7085 Worker-manager publishes more events to new exchanges in Pulse:
worker-pool-errorworker-requestedworker-runningworker-stopped▶ [patch] #7120 Removed memory, pid, and ulimits for d2g payloads.
▶ [patch] Updated azure test certificates.
▶ Additional change not described here: #7095.
<details> <summary>20 Dependabot updates</summary>
</details>
▶ [MAJOR] #7082 This change comprises three elements:
▶ [MAJOR] #7082 This change comprises three elements:
docker rather than podman if the Docker
Worker task has the privileged capability enabled. This should result in
fewer tasks failing due to differences in default behaviour between docker
and podman privileged containers.▶ [patch] #7083 Fixes query validation in pagination queries that were throwing 500 InternalServerError instead of 400 InputError
▶ [patch] #7083
Fixes query validation in pagination queries that were throwing 500 InternalServerError instead of 400 InputError
▶ [minor] #7089 Fixes an issue when cancelling a task didn't remove it from the pending queue. This made worker-manager think there are more pending tasks than there actually were, and create more workers.
▶ [patch] Upgrades to node v20.14.0 and go1.22.4 (SECURITY release).
▶ [patch] Upgrades to node v20.14.0 and go1.22.4 (SECURITY release).
▶ [minor] #7035 Helm chart allows conditional deployment of several resource types:
This might be useful in the deployments that use custom Ingress or manage secrets and configs externally.
Example usage: helm template --values .. --set "skipResourceTypes[0]"=ingress --set "skipResourceTypes[0]"=secert .
▶ [minor] #7076 Worker Runner now uses IMDSv2 instead of IMDSv1 in EC2. IMDSv1 is being phased out by Amazon.
▶ [patch] #7080 Fixes github service issue during cancellation of the previous runs that were not created. Response code was not checked properly which resulted in sending same error for each new build.
▶ [patch] #6668 Fixes an issue to support yarn run for dev:start and dev:stop scripts
▶ [minor] #7070 Generic Worker now sets the environment variable TASKCLUSTER_INSTANCE_TYPE in task commands to the instance type of the worker, if con
▶ [minor] #7070 Generic Worker now sets the environment variable TASKCLUSTER_INSTANCE_TYPE in task commands to the instance type of the worker, if configured. This matches the (undocumented) behaviour of Docker Worker. D2G also passes this environment variable through to podman, to emulate Docker Worker's behaviour.
▶ [patch] Fixes UI issue in worker view where error was shown despite worker being found.
▶ [patch] #7059
D2G now includes libvirt OS group in generated Generic Worker task payloads that use Docker Worker KVM device.
▶ [patch] #6954 Fixes an issue with github badges that timed out on non-existing branches.
▶ [patch]
Tasks using notify.pulse.<topic>.on-<event> routes now send out messages
using the specified topic. This means it's now possible to subscribe to
specific topics.
▶ [minor] #5073
Github service supports issue_comment events to trigger jobs through /tasckluster param comments in open Pull Requests.
.taskcluster.yml in default branch should allow this with policy.allowComments: collaborators value.
Tasks would be rendered with tasks_for = "github-issue-comment" and event.taskcluster_comment = param
This is an implementation of RFC 168
▶ [patch] #6567
yarn generate commands will attempt to run pg_dump inside the docker container if local binary is missing or its version is different from the server version.
<details> <summary>2 Dependabot updates</summary>
</details>
▶ [minor] #5967 Allows Docker Worker payloads to be used on the insecure Generic Worker engine, translated by d2g.
▶ [minor] #5967
Allows Docker Worker payloads to be used on the insecure Generic Worker engine, translated by d2g.
▶ [patch] #7025 Fixes JavaScript error in "Create Worker Pool" page that was introduced in the last release. Adds link to "Errors" in workers navigati
▶ [patch] #7025 Fixes JavaScript error in "Create Worker Pool" page that was introduced in the last release. Adds link to "Errors" in workers navigation bar.
<details> <summary>2 Dependabot updates</summary>
</details>
▶ [patch] Upgrades to go1.22.3 (SECURITY release). Was supposed to be handled in PR #7006, but was accidentally left out.
▶ [patch] Upgrades to go1.22.3 (SECURITY release). Was supposed to be handled in PR #7006, but was accidentally left out.
Your coding agent can read these notes before it upgrades. Set up the MCP server →