NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #4675 most downloaded on PyPI
Python client for Taskcluster
Last release 4 days ago
15 Sep 2026
Ships on a steady schedule
a new release about every 2 weeks
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
12 years old
490 releases · first in 2014
▶ [patch] Upgrades to node v20.13.0 and go1.22.3 (SECURITY release).
▶ [patch] Upgrades to node v20.13.0 and go1.22.3 (SECURITY release).
▶ [minor] #6979
Generic Worker multiuser engine on Linux now sets environment variableXDG_RUNTIME_DIR to /run/user/<UID> in task command processes (unless Generic Worker config setting runTasksAsCurrentUser is set to true).
▶ [patch] bug 1768667
Adds Task Group link in UI for indexed tasks.
Introduces new route to redirect to the Task Group view: /tasks/index/:namespace/:indexTask/task-group
<details> <summary>1 Dependabot updates</summary>
</details>
build(deps): bump the node-deps group across 1 directory with 17 updates
One column per quarter.
<details> <summary>8 Dependabot updates</summary>
</details>
▶ [patch] #6983 AWS provider correctly detects InvalidInstanceID.NotFound error and marks worker as stopped.
▶ [patch] #6983
AWS provider correctly detects InvalidInstanceID.NotFound error and marks worker as stopped.
▶ [patch] #6987
Generic Worker now checks if a graceful termination was requested from worker runner before calling queue.claimWork().
This helps fix a race condition where a preemption occurs right after Generic Worker starts up, but before the graceful termination handler to abort the task has been initialized.
▶ [patch] #6984 Github auto-cancel gracefully ignores missing task groups and doesn't log errors in github comments. This can happen when decision task failed on previous runs.
▶ [patch] #6761
Switching from googleapis package to a smaller @googleapis/* libraries to reduce startup time and avoid loading APIs we don't use.
▶ [patch] #6972 Generic Worker now uploads task payload artifacts in parallel to decrease graceful termination time in the event of a spot termination
▶ [patch] #6972 Generic Worker now uploads task payload artifacts in parallel to decrease graceful termination time in the event of a spot termination.
The insecure engine no longer performs a file copy command as the task user before the artifact upload process happens to help speed up the process.
Generic Worker (posix only) now tries to put an exclusive file lock on artifacts before upload to prevent the file from being written to by any other process. This is done in lieu of copying the file to a temporary location which was achieving the same thing. If putting the lock on the file fails, Generic Worker will fallback to copying the file.
▶ [patch] #6972
Don't compress .npz artifacts by default in Generic Worker.
<details> <summary>2 Dependabot updates</summary>
</details>
▶ [patch] Upgrades to Node.js v20.12.2 which is a security release.
▶ [patch] Upgrades to Node.js v20.12.2 which is a security release.
<details> <summary>6 Dependabot updates</summary>
</details>
▶ [patch] #6900 Worker Runner on Azure no longer sends a graceful-termination message if the scheduled event type is Freeze. It will continue to send
▶ [patch] #6900
Worker Runner on Azure no longer sends a graceful-termination message if the scheduled event type is Freeze. It will continue to send the message for all other event types: Reboot, Redeploy, Preempt, and Terminate.
▶ [patch] #6957
Improves performance of the findTasksAtIndex call (introduced in #6915)
that returns multiple tasks for a given list of namespaces and indexes.
▶ [patch] #6958 Worker Manager now only applies GCP disk labels to PERSISTENT disk types.
▶ [patch] #6958
Worker Manager now only applies GCP disk labels to PERSISTENT disk types.
This fixes an issue in v64.2.2 where initializeParams.labels was being set on all disk types and caused GCP to error on local SSDs (SCRATCH type disks).
▶ [patch] Upgrades to go1.22.2 and Node.js 20.12.1 which are both security releases.
▶ [patch] Upgrades rust version to 1.77.1 and ran cargo audit fix to fix insecure crates.
▶ [patch]
Upgrades rust version to 1.77.1 and ran cargo audit fix to fix insecure crates.
▶ [patch] Upgrades to Node.js v20.12.0
<details> <summary>7 Dependabot updates</summary>
</details>
▶ [patch] #6802 Worker Runner no longer polls the metadata service for the Google provider. Instead, we've added ?wait_for_change=true to the endpoint
▶ [patch] #6802
Worker Runner no longer polls the metadata service for the Google provider. Instead, we've added ?wait_for_change=true to the endpoint to perform a hanging GET request that'll return as soon as the metadata has changed and the VM has been preempted.
▶ [minor] Remove maxRunTime limitations for docker payloads in generic worker (d2g)
<details> <summary>2 Dependabot updates</summary>
</details>
▶ [patch] #6928 D2G no longer adds --cap-add=SYS_PTRACE for the docker worker allowPtrace feature since all capabilities are already added with the --
▶ [patch] #6928
D2G no longer adds --cap-add=SYS_PTRACE for the docker worker allowPtrace feature since all capabilities are already added with the --privileged flag being passed to all D2G commands as of #6890.
No changes
No changes
▶ [MAJOR] The Docker Worker binary is no longer built during releases. The most recent Docker Worker binary can be found here.
▶ [MAJOR] The Docker Worker binary is no longer built during releases. The most recent Docker Worker binary can be found here.
▶ [MAJOR] #6832 The Generic Worker simple engine has been renamed to the insecure engine.
▶ [MAJOR] #6832
The Generic Worker simple engine has been renamed to the insecure engine.
All future release binaries for this engine will also be renamed (e.g. generic-worker-simple-darwin-arm64 --> generic-worker-insecure-darwin-arm64), so please update any scripts that reference the simple engine binary.
This change was made to help make it extremely apparent that it should not be used in production environments and is only recommened for testing and development.
▶ [patch] Upgrades to go1.22.1 which is a security release.
▶ [patch]
Generic Worker now utilizes filepath.WalkDir instead of filepath.Walk.
filepath.WalkDir was introduced in go1.16 and is more performant and efficient over filepath.Walk.
This may help with race conditions during artifact uploads, where a file was initially seen, but then became unavailable at upload time.
▶ [patch] Upgrades to go1.22.1 which is a security release.
▶ [MAJOR] #6881
Google cloud workers spawned by Worker Manager now have workerGroup set to
the Google Cloud Zone (e.g. us-east1-d) rather than the Google Cloud
Region (e.g. us-east1). This makes it easier to issue api requests against
an instance, e.g. gcloud compute instances delete <workerId> --zone=<workerGroup>.
▶ [patch] #6890
D2G now always passes --privileged to the generated podman run command.
Without this option, some tasks that ran successfully under Docker Worker,
including tasks without Docker Worker capabilities, would not run correctly
under Generic Worker. Please note, this only elevates the privileges inside the
podman container, which runs as the task user on the host. The privileges
inside the container are still limited to the host privileges of the task user.
▶ [patch]
Generic Worker now correctly reports the Worker Pool ID when an interactive task is attempted on a worker pool with the interactive feature disabled. Previously the task log would report the Worker Pool ID in the exception/malformed-payload task run as <workerGroup>/<workerType>; now it correctly reports it as <provisionerId>/<workerType>. The Interactive feature is considered disabled when Generic Worker config setting enableInteractive is either absent or explicitly set to false in the Generic Worker config.
▶ [patch] Upgrades internal references library to use async fs operations to make upcoming node20 upgrade easier.
<details> <summary>7 Dependabot updates</summary>
</details>
▶ [patch] Fixes graphql validation rules for hooks groups query.
▶ [patch] Fixes graphql validation rules for hooks groups query.
▶ [patch] #6864
D2G now passes --privileged flag to the generated podman run command when
Docker Worker payload enables device capability hostSharedMemory. Without
this option, the podman container could not successfully access the shared
memory, despite the inclusion of argument --device=/dev/shm. With both
arguments present (--privileged and --device=/dev/shm), shared memory now
appears to be available inside the podman container.
<details> <summary>3 Dependabot updates</summary>
</details>
▶ [patch] Fix docker worker interactive shell UI rows/cols settings.
▶ [patch] Fix docker worker interactive shell UI rows/cols settings.
▶ [patch] #6836 Upgrades graphql server and client libraries to graphql 16.8
▶ [patch] #6836 Upgrades graphql to 16.8.1 in ui
<details> <summary>1 Dependabot updates</summary>
</details>
▶ [minor] #6845 D2G now provides support for the (discontinued) disableSeccomp capability which was removed from Docker Worker, but was still used by
▶ [minor] #6845 D2G now provides support for the (discontinued) disableSeccomp capability which was removed from Docker Worker, but was still used by the bugmon fuzzing project in the Community taskcluster environment. This was added to ease the migration path of this project from Docker Worker to Generic Worker.
▶ [patch] #6848 Fix an issue where an interactive session would close up when the shell would output invalid UTF-8.
▶ [patch] #6850 Add a proper TERM environment variable to interative sessions. This helps with some ncurses apps and tmux for example.
▶ Additional change not described here: #6852.
<details> <summary>4 Dependabot updates</summary>
</details>
▶ [patch] Upgrades to node v18.19.1, which is a security release.
▶ [patch]
Switched to use math/rand/v2 (new in go1.22), removed deprecated call to windows.OpenCurrentProcessToken(), fixed staticcheck errors, and added a staticcheck GitHub actions workflow for our repo.
▶ [patch] Upgrades to node v18.19.1, which is a security release.
▶ [patch] Kubernetes lifecycle timeouts correctly set to avoid having 502s.
▶ [patch] #6795 Fixes "Raw Log" button in UI that can point to an expired artifact.
▶ [patch] #6820 Fixes scope view in the UI. Search by scope shows roles and clients that use given scope.
▶ [patch] Upgrades to go1.22.0
▶ [patch] #6820 Fixes scope view in the UI. Search by scope shows roles and clients that use given scope.
<details> <summary>1 Dependabot updates</summary>
</details>
▶ [patch] Upgrades to yarn v4.1.0
▶ [patch] Upgrades to yarn v4.1.0
<details> <summary>5 Dependabot updates</summary>
</details>
▶ [patch] Worker Runner now checks for termination notice when starting the Google provider.
▶ [patch] Worker Runner now checks for termination notice when starting the Google provider.
When Worker Runner runs, the instance may already be scheduled to be shutdown. So on Google provider startup, we now check for this case.
This functionality mimics what's already in place for AWS.
This change also decreases the time Worker Runner checks to see if the instance is scheduled to be shutdown from 30 seconds to 15 seconds on the Google and Azure providers, as they each have a 30 second notice before a hard-shutdown Google: https://cloud.google.com/compute/docs/instances/spot#preemption-process Azure: https://learn.microsoft.com/en-us/azure/virtual-machines/spot-vms.
▶ [patch] #6801
Fixes a bug in notify service where multiple messages to the same channel were not sent.
Adds 204 status code to the email, matrix, pulse, slack endoints when message was detected to be duplicate and was not sent.
▶ [patch] #6793 D2G will now ensure that tasks whose max run time is exceeded still have the chance to publish artifacts. This means that Docker Worker tasks definitions that are run under Generic Worker and are aborted due to hitting the max run time should still publish the artifacts from the aborted docker container they ran in.
▶ [patch] #6798 Generic Worker now includes the original Docker Worker task definition in the chain of trust certificate, if the task payload is a Docker Worker task payload. Previously, it was including the internal Generic Worker representation of the task definition.
▶ [patch] The Task Creator now defaults to a task that only takes 1 minute to run instead of 10 mins, to redue resource consumption. Tutorials updated to reflect change.
<details> <summary>1 Dependabot updates</summary>
</details>
▶ [patch] #6789 Generic Worker no longer modifies task scopes passed to Taskcluster Proxy. Previously there was a bug where Taskcluster Proxy would be
▶ [patch] #6789
Generic Worker no longer modifies task scopes passed to Taskcluster Proxy.
Previously there was a bug where Taskcluster Proxy would be passed the
d2g-modified scopes by Generic Worker rather than the original task scopes from
the task definition of the queue.claimWork response body. If the task was not
also explicitly assigned the required generic-worker scopes, this would result
in HTTP 401 errors from Taskcluster Proxy calls.
This has now been fixed, so that it is sufficient for tasks with a Docker Worker payload to contain only Docker Worker scopes, not have the associated generic-worker scopes, yet still work under Generic Worker and use the Taskcluster Proxy feature without causing HTTP 401 errors.
▶ [patch] Generic Worker now copies archives to the task user's directory before unarchiving.
▶ [patch] Generic Worker now copies archives to the task user's directory before unarchiving.
▶ [minor] #6785 Generic Worker now exits with exit code 82 if the chain of trust key is missing.
▶ [patch] Go upgrade to 1.21.6.
▶ [patch] Go upgrade to 1.21.6.
go1.21.6 (released 2024-01-09) includes fixes to the compiler, the runtime, and the crypto/tls, maps, and runtime/pprof packages. See the Go 1.21.6 milestone on our issue tracker for details.
▶ [minor]
Generic Worker: adds unarchive subcommand to the generic-worker binary.
▶ [minor] #6720
The taskcluster UI now shows errors when an action's input does not match the action.schema
▶ [patch] #6235 Migrates to aws sdk v3.
▶ [patch] #6235 Migrates to aws sdk v3.
▶ [patch] #6563 Ensure livelog and interactive tasks tunnels work after a websocktunnel restart.
▶ [patch] #6563 Ensure livelog and interactive tasks tunnels work after a websocktunnel restart.
▶ [patch] #6779 Interactive feature data race fixed, whereby an error could cause a concurrent read and write of process state in different go routine
▶ [patch] #6779 Interactive feature data race fixed, whereby an error could cause a concurrent read and write of process state in different go routines.
▶ [minor] bug 1874568 Fixes token expiry issue for Auth0 login strategy that was not refetched.
▶ [patch] #6495 Improve changelog rendering in UI
▶ [patch] Added helper script to make it easier to run websocktunnel locally.
<details> <summary>1 Dependabot updates</summary>
</details>
▶ [patch] #6762 Generic Worker: Tasks internally translated by D2G will add exit code 128 to the retry exit status array for retrying on an intermitte
▶ [patch] #6762 Generic Worker: Tasks internally translated by D2G will add exit code 128 to the retry exit status array for retrying on an intermittent docker image pull issue.
<details> <summary>5 Dependabot updates</summary>
</details>
▶ [patch] Generic Worker: No longer logs out the redirect URL for the interactive shell feature since they are signed.
▶ [patch] Generic Worker: No longer logs out the redirect URL for the interactive shell feature since they are signed.
▶ [MAJOR] #6759 Kubernetes pods use liveness probe instead of unconditionally killing containers daily.
▶ [patch] #6641 Worker-manager no longer counts "stopping" instances as part of the existing capacity when estimating the number of workers to start (although they are still counted towards maxCapacity).
<details> <summary>7 Dependabot updates</summary>
</details>
▶ [minor] #6671 Several UI changes:
▶ [minor] #6671 Several UI changes:
<details> <summary>1 Dependabot updates</summary>
</details>
No changes
No changes
▶ [patch] #6733 Generic Worker: fixes file-not-readable-on-worker error while uploading artifacts with the simple engine.
▶ [patch] #6733
Generic Worker: fixes file-not-readable-on-worker error while uploading artifacts with the simple engine.
▶ [patch] Upgrades to go1.21.5 and Node 18.19.0.
▶ [minor] bug 1858424 Generic Worker: ensure task user has access to the mount location specified.
▶ [minor] bug 1858424 Generic Worker: ensure task user has access to the mount location specified.
Generic Worker: Add create-file and create-dir subcommands to generic-worker intended for internal use during task execution.
▶ [patch] #6688 The hooks list table now displays the timestamp of each hook's latest created task.
▶ [patch] #6716 Adds lifecycle preStop hook for services to allow graceful termination of pods in kubernetes without loss of connections.
▶ [MAJOR] #5514 Removes postgres v11 support.
▶ [MAJOR] #5514 Removes postgres v11 support.
▶ [minor] #6716
Services now support graceful server termination by listening to SIGTERM and letting existing connections to be served while rejecting new connections.
<details> <summary>6 Dependabot updates</summary>
</details>
▶ [patch] #6701 Generic Worker: Fixes permission denied error while checking if generic-worker binary is executable by the task user for simple engine
▶ [patch] #6701
Generic Worker: Fixes permission denied error while checking if generic-worker binary is executable by the task user for simple engine.
▶ [patch]
Upgrades rust version to 1.74.0 and ran cargo audit fix to fix insecure crates.
<details> <summary>1 Dependabot updates</summary>
</details>
▶ [patch] Generic Worker: Adds validation that the task user is able to read and execute the generic-worker binary on startup of the worker. If the ta
▶ [patch] Generic Worker: Adds validation that the task user is able to read and execute the generic-worker binary on startup of the worker. If the task user is not able to read and execute the binary, the worker will exit with exit code 69, internal error.
▶ [patch] #4998 This fixes a bug in the Python client where an exception was raised on 300 HTTP status.
▶ [MAJOR] bug 1855653 Generic Worker: The generic-worker binary _must be_ readable and executable by the task user. If it's not, artifact uploads _wil
▶ [MAJOR] bug 1855653
Generic Worker: The generic-worker binary must be readable and executable by the task user. If it's not, artifact uploads will fail.
Generic Worker: Add copy-to-temp-file subcommand to generic-worker to copy a file (--copy-file) to a temporary file.
▶ [patch] #6671
Introduces workerManager.workerPoolErrorStats() to return total number of errors for any worker pool or all worker pools.
Stats are split into totals by day, hour, kind of error and error code.
Worker Pool errors are kept in db for 7 days.
▶ [patch] Removes compatibility columns in refactored queue tables that were used during migration for backward-compatibility purposes.
▶ [patch] #6682
Tweaking server.keepAliveTimeout to fix downstream errors in reverse proxy and load balancer.
Default node's http server keepAliveTimeout is 5s which might be an issue when working behind a reverse proxy which has bigger timeouts.
To reduce number of 502 errors, application's keep alive timeout should be larger than the one of the reverse proxy,
and that in turn, should be larger than the Load Balancer's one.
▶ [patch] Upgrades to go1.21.4 and node 18.18.2.
▶ [patch] bug 1859323 Generic Worker now reports the full path of tasks-resolved-count.txt, next-task-user.json and current-task-user.json in worker logs.
<details> <summary>3 Dependabot updates</summary>
</details>
▶ [minor] #2939 Introduces queue.listPendingTasks(taskQueueId) and queue.listClaimedTasks(taskQueueId). Those endpoints return a list of tasks that ar
▶ [minor] #2939
Introduces queue.listPendingTasks(taskQueueId) and queue.listClaimedTasks(taskQueueId).
Those endpoints return a list of tasks that are currently pending or claimed by workers.
New scopes introduced for those endpoints:
queue:pending-list:<taskQueueId>queue:claimed-list:<taskQueueId>▶ [patch] #6656
D2G now shell escapes environment variable key names in case they contain spaces or special characters that would previously mess up the podman run... command.
<details> <summary>3 Dependabot updates</summary>
</details>
▶ [patch] Expired azure test certificates updated
▶ [patch] Expired azure test certificates updated
▶ [patch] Fix hooks UI page "unknown" task state error.
▶ [patch] #6636
Fix Dockerfile from PR #6646. The .yarn directory does not exist anymore, so it shouldn't be copied.
▶ [patch] #6636 Upgrades to modern Yarn version 4.
To enable on your machine:
corepack enable
yarn set version berry
▶ [patch] #6644 Fixes __version__ endpiont in web-server
▶ [patch] #6644 Fixes version endpiont in web-server
▶ [patch] #6634
Fixes queue.claimWork endpoint returning 500 in some rare conditions.
▶ [minor] #6371 D2G tool now can convert an entire Docker Worker task definition to a Generic Worker task definition.
New taskcluster d2g -h output:
Converts a docker-worker payload (JSON) to a generic-worker payload (JSON).
To convert a task definition (JSON), you must use the task definition flag (-t, --task-def).
Usage:
taskcluster d2g [flags]
Examples:
taskcluster d2g -f /path/to/input/payload.json
taskcluster d2g -t -f /path/to/input/task-definition.json
cat /path/to/input/payload.json | taskcluster d2g
cat /path/to/input/task-definition.json | taskcluster d2g -t
echo '{"image": "ubuntu", "command": ["bash", "-c", "echo hello world"], "maxRunTime": 300}' | taskcluster d2g
Flags:
-f, --file string Path to a .json file containing a docker-worker payload or task definition.
-h, --help help for d2g
-t, --task-def Must use if the input is a docker-worker task definition.
Global Flags:
-v, --verbose verbose output
▶ [patch]
Hooks last fires display unknown as task state if task is missing or not scheduled. This can happen with task was expired and removed but last run information still exist.
▶ [patch] #6472
D2G: Add the kvm OS group to the Generic Worker payload if the KVM device is enabled in the Docker Worker payload.
▶ [patch] docker-worker: fix error message when a task is missing scopes for cache volumes
▶ [MAJOR] #4260
Javascript codebase converted to use ECMAScript modules (ESM).
This includes db, libraries/*, services/* and infrastructure/tooling/* folders.
Clients remain unchanged.
▶ [patch] Introduces helper databaes utilities to create new version (migration) and renumber existing.
yarn db:new creates new db migration and test
yarn db:renumber old new renumbers existing version
▶ [patch]
Move docker compose image names to .env file to keep compose files unchanged between releases.
▶ Additional change not described here: #6621.
<details> <summary>4 Dependabot updates</summary>
</details>
▶ [patch] #6616 Github service no longer cancels builds for the same SHA for push events. Only pull_request events would cancel running builds for the
▶ [patch] #6616
Github service no longer cancels builds for the same SHA for push events.
Only pull_request events would cancel running builds for the same pull request if they exist.
This is to avoid canceling same commit pushed to different branches.
▶ [patch]
Allow specifying 0 as a value for onExitStatus.purgeCaches.
<details> <summary>2 Dependabot updates</summary>
</details>
▶ [patch] #2940 Fixes claimed task resolver db query that returned too many records. Bug introduced in migration 91
▶ [patch] #2940 Fixes claimed task resolver db query that returned too many records. Bug introduced in migration 91
▶ [patch] #2940 Patches existing migration to prevent data loss because of incorrect field values.
▶ [patch] Upgrades to go1.21.3 and node v18.18.1
<details> <summary>1 Dependabot updates</summary>
</details>
▶ [patch] #2940 Patches 91-migration script to account for non-unique pending tasks. This was a blocking exception during migration time.
▶ [patch] #2940 Patches 91-migration script to account for non-unique pending tasks. This was a blocking exception during migration time.
▶ [MAJOR] #2940 Queue service internals refactored. azure_queue_messages table and azqueue library are no longer used. Claim, resolved, deadline and p
▶ [MAJOR] #2940
Queue service internals refactored. azure_queue_messages table and azqueue library are no longer used.
Claim, resolved, deadline and pending queues now use separate tables. Existing messages are preserved during migration.
Database migration 0091 expects that previous 0090 migration was applied and there are no pending tasks that didn't migrate to the new format yet.
Make sure that v55.3.x was deployed first and data was fully migrated before deploying this version.
▶ [patch] #2940 Resolved tasks do not drop deadline messages, which was removed during queue refactoring. Messages will stay until task deadline even if task is being resolved.
▶ [patch] Upgrades to go1.21.2
▶ [patch] UI: Task Definitions and Payloads now display in YAML by default for readability.
<details> <summary>1 Dependabot updates</summary>
</details>
▶ [patch] Patches an issue in github service cancelling task groups for non-push/pull-request events
▶ [patch] Patches an issue in github service cancelling task groups for non-push/pull-request events
<details> <summary>1 Dependabot updates</summary>
</details>
▶ [patch] #6592 Generic Worker no longer allows you to specify the same group twice in the osGroups array property.
▶ [patch] #6592 Generic Worker no longer allows you to specify the same group twice in the osGroups array property.
▶ [patch] #6590 Generic Worker osGroups feature on Linux has been fixed. It never worked on this platform.
▶ [patch] #6471
Worker Runner now sets the TASKCLUSTER_WORKER_LOCATION variable for Generic Worker.
<details> <summary>5 Dependabot updates</summary>
</details>
▶ [patch] #6498 Github service auto cancels previous builds by default now. This behavior can be disabled by setting autoCancelPreviousChecks to false
▶ [patch] #2940 Prepares azure_queue_messages table for upcoming migration by adding task_queue_id, priority columns.
▶ [patch] #2940
Prepares azure_queue_messages table for upcoming migration by adding task_queue_id, priority columns.
▶ [patch] D2G now takes advantage of Generic Worker Indexed Artifacts, introduced in Generic Worker 51.0.0. D2G translates Indexed Docker Images into Generic Worker mounted Indexed Artifacts. Previously, D2G generated commands to query the taskcluster Index and fetch the docker image. With this improvement, docker images are now cached on workers, docker image dependencies between tasks are declarative (and thus inspectable), and generated Generic Worker task payloads are simpler and easier to understand.
▶ [minor] #6553
Generic Worker File Mounts now include an optional format field to specify the compression format for the content. Generic Worker will decompress the retrieved content using the format specified before writing to disk. To avoid decompression, do not include the format field.
Allowed compression formats are: bz2, gz, lz4, xz, and zst.
This change additionally adds support for the tar.lz4 format for Writable Directory Caches and Read Only Directories.
▶ [patch] Updates ubuntu image versions to jammy.
▶ [patch]
Updates ubuntu image versions to jammy.
▶ [patch] #6530 Workers deployed in GCP as spot instances or preemptible VMs now handle instance termination gracefully.
▶ [patch] #6530 Workers deployed in GCP as spot instances or preemptible VMs now handle instance termination gracefully.
▶ [minor] #6528 Github webhook handler supports recommended X-Hub-Signature-256 verification. All verification failures are being reported to the sent
▶ [minor] #6528
Github webhook handler supports recommended X-Hub-Signature-256 verification.
All verification failures are being reported to the sentry additionally.
▶ [patch] Replaces slow db query to fetch check run build status with a faster one, which is used in background status update handlers.
▶ [patch] Upgrades to go1.21.1
▶ [patch] #6521 Generic Worker now outputs a warning in the task log if a Docker Worker payload is supplied, together with the d2g-converted task defi
▶ [patch] #6521 Generic Worker now outputs a warning in the task log if a Docker Worker payload is supplied, together with the d2g-converted task definition, in order to help users migrate their tasks to native Generic Worker format.
▶ Additional change not described here: #6513.
<details> <summary>7 Dependabot updates</summary>
</details>
▶ [minor] #2942 The new queue.maxTaskDeadlineDays Helm configuration parameter controls the maximum value allowed for task deadlines. The default is 5
▶ [minor] #2942
The new queue.maxTaskDeadlineDays Helm configuration parameter controls the maximum value allowed for task deadlines. The default is 5 days, matching the previous hard-coded setting.
▶ [MAJOR] #6117
workerManager.getWorker returns worker even if it is quarantined and expired.
This is to avoid confusion in the UI when a worker is linked in UI, still exists in database, but page returns 404.
<details> <summary>1 Dependabot/Renovate updates</summary>
</details>
▶ [minor] #5995 Generic Worker: Adds task.payload.feature.loopbackAudio for loopback audio device support on Linux.
▶ [minor] #5995
Generic Worker: Adds task.payload.feature.loopbackAudio for loopback audio device support on Linux.
The snd-aloop kernel module must be installed on the host system for this feature to work, although it does not need to be loaded. Generic Worker loads the module with modprobe and generates the virtual audio device with a snd-aloop command. Under the multiuser engine, it also manages file ownership of the device with chown to ensure that only tasks with suitable scopes have read/write access to the virtual device.
For tasks that enable the feature, the virtual audio device will be found at /dev/snd. Devices inside that directory will take the form /dev/snd/controlC<DEVICE_NUMBER>, /dev/snd/pcmC<DEVICE_NUMBER>D0c, /dev/snd/pcmC<DEVICE_NUMBER>D0p, /dev/snd/pcmC<DEVICE_NUMBER>D1c, and /dev/snd/pcmC<DEVICE_NUMBER>D1p, where <DEVICE_NUMBER> is an integer between 0 and 31, inclusive. The Generic Worker config setting loopbackAudioDeviceNumber may be used to change the device number in case the default value (16) conflicts with another audio device on the worker. Future releases of Generic Worker may provide the capability of having more than one virtual audio device; currently only one virtual audio device is supported.
▶ [patch] #6481
Allow git SSH urls in metadata.source.
▶ [patch] #6476 Generic Worker now checks the Index to see if there is a new version of an Indexed Artifact available. If there isn't, it is fine to use its cached copy, but if there is, it updates its cache.
▶ [patch] Generic Worker: If a Docker Worker payload is received, the resulting, d2g-translated Generic Worker payload will be logged out to the user.
▶ [patch] #6438
dependencies are no longer removed from the task definition when you Edit or Retrigger a task.
▶ [minor] #6269
Generic Worker now provides configuration property maxTaskRunTime as an upper bound for task payload property maxRunTime. Tasks with maxRunTime exceeding this value will be resolved as exception/malformed-payload.
▶ Additional changes not described here: #6482, #6484.
<details> <summary>3 Dependabot/Renovate updates</summary>
</details>
▶ [patch] Upgrades go to 1.21.0 and node to 18.17.1
▶ [patch] Upgrades go to 1.21.0 and node to 18.17.1
▶ [patch] #6440 Generic Worker now allocates a pseudo tty when running Docker Worker tasks, to emulate Docker Worker behavior. Previously it did not allocate a tty, which could result in e.g. output not being colored.
▶ Additional changes not described here: #6400, #6414, #6442.
<details> <summary>11 Dependabot/Renovate updates</summary>
</details>
▶ [patch] Upgrade Node.js to 18.17.0.
▶ [patch] Upgrade Node.js to 18.17.0.
▶ [patch] #6405 Expire artifacts job no longer logs errors for each missing artifact. Instead it reports the number of missing artifacts at the end of the job.
▶ [patch] Adds a task log letting the user know their Docker Worker payload is being converted to a Generic Worker payload using d2g.
<details> <summary>1 Dependabot/Renovate updates</summary>
</details>
▶ [minor] #5961 Generic Worker now supports the osGroups feature on macOS, Linux and FreeBSD. Support was already added to Windows in Generic Worker 6
▶ [minor] #5961
Generic Worker now supports the osGroups feature on macOS, Linux and
FreeBSD. Support was already added to Windows in Generic Worker 6.0.0.
Example Linux/macOS task (requires docker to be installed on worker):
created: <timestamp>
deadline: <timestamp>
workerType: my-worker-type
provisionerId: mv-provisioner-id
scopes:
- generic-worker:os-group:my-provisioner-id/my-worker-type/docker
payload:
osGroups:
- docker
command:
- - docker
- run
- --rm
- ubuntu:latest
- /usr/bin/echo
- hello
maxRunTime: 60
metadata:
name: Ubuntu - docker test
owner: pmoore@mozilla.com
source: https://github.com/taskcluster/taskcluster/pull/6397
description: Test calling docker from a Generic Worker task
Removed posix generic-worker binaries due to a security vulnerability when using the interactive feature.
▶ [patch] #6420 Fixes generic worker issue where artifacts were no longer being uploaded.
Removed posix generic-worker binaries due to a security vulnerability when using the interactive feature.
Your coding agent can read these notes before it upgrades. Set up the MCP server →