NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #4675 most downloaded on PyPI
Python client for Taskcluster
Last release 5 days ago
21 Sep 2026
Ships on a steady schedule
a new release about every 2 weeks
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
12 years old
491 releases · first in 2014
▶ [patch] This fixes the default worker state of a worker not known by worker manager to be standalone as opposed to unmanaged to be consistent with t
▶ [patch]
This fixes the default worker state of a worker not known by worker manager to be standalone as opposed to unmanaged to be consistent with the rest of the project. This issue was first brought up in v44.16.0
▶ [patch]
Fix this error (Function listWorkers takes options: continuationToken, limit, quarantined, workerState but was given isQuarantined) while filtering workers based on quaratine status.
▶ [patch] Don't allow additional properties in worker-response.yml schema. Updated descriptions in worker-response.yml and list-workers-response.yml s
▶ [patch]
Don't allow additional properties in worker-response.yml schema. Updated descriptions in worker-response.yml and list-workers-response.yml schemas to explain some default values that may occur in the case where the queue knows about the worker, but worker manager does not. Also, updated the GraphQL queries to extract additional needed data.
▶ [patch] Fix schema validation issues.
▶ [patch]
Upgrade node to the latest LTS release, v16.15.1. Also upgrade golangci-lint to 1.46.2.
▶ [patch]
Upgrade to go1.18.3 from go1.18.2.
▶ [patch] #5042 Add a configuration option to disable CORS configuration for the queue's S3 client. This is a step forward for supporting minio as a S3 backend.
▶ [patch] #5043
Add a configuration option to enable s3ForcePathStyle for the queue's S3 client
▶ [minor] #5085 Allow Taskcluster to rerun single task from github interface.
▶ [patch] Replace rust-crypto by hmac-sha256 in the rust client to help with dependency deduplication
▶ [patch] Update a few rust dependencies in the client crate to help reducing duplicates
One column per quarter.
▶ [patch] Handle some null checks with optional chaining. Also, ensure all data is extracted out during workerManager.listWorkers() calls.
▶ [patch]
Handle some null checks with optional chaining. Also, ensure all data is extracted out during workerManager.listWorkers() calls.
▶ [patch] Fix arguments for get_task_queue_wm_2 (get_task_queue_wm is now deprecated).
▶ [patch]
Fix arguments for get_task_queue_wm_2 (get_task_queue_wm is now deprecated).
▶ [patch] Remove unneeded read access to workers table from queue service. Add read access to task_queues table to worker_manager service for workerMa
▶ [patch]
Remove unneeded read access to workers table from queue service. Add read access to task_queues table to worker_manager service for workerManager.getWorker() method to prevent 500 permission denied SQL error.
▶ [patch] Fix GRAPHQL_VALIDATION_FAILED error on ViewWorker query.
▶ [patch]
Fix GRAPHQL_VALIDATION_FAILED error on ViewWorker query.
▶ [patch] Fix output schema validation error when calling workerManager.listWorkers() and workerManager.getWorker() methods by not requiring additiona
▶ [patch]
Fix output schema validation error when calling workerManager.listWorkers() and workerManager.getWorker() methods by not requiring additional worker manager fields.
▶ [patch] Updated k8s ingress API from deprecated extensions/v1beta1 to networking.k8s.io/v1 allowing usage of k8s 1.22+
▶ [patch] #5459
Add exponential backoff retries to the dockerPush function to help alleviate intermittent failures in the release-publish task.
▶ [patch]
Updated k8s ingress API from deprecated extensions/v1beta1 to networking.k8s.io/v1 allowing usage of k8s 1.22+
▶ [minor] #5440 Add functionality to terminate workers via a Terminate Worker button in the Worker views.
▶ [minor] #3060 Mix queue and worker info to provide worker manager worker data in Worker views. This additional data also enabled us to provide a Terminate Worker button in the Worker views.
Deprecated: queue.listWorkers() and queue.getWorker()
Use instead: workerManager.listWorkers() and workerManager.getWorker()
▶ [patch] #5446 Don't require user to hover over speed dial actions button to reach Raw Log button. Show by default.
▶ [patch] #5361 Link Worker State Buttons on Worker Pool Details View to a filtered view of workers in that state.
▶ [patch] Update some rust dependencies to get rid of duplicated versions of base64
▶ [minor] #5152 Fix default config value and improve prompt message.
▶ [minor] #5179 Lazy rendering of big tables. Improves Roles page rendering
▶ [patch] Deprecate old Azure endpoints that are no longer use:
▶ [patch] Deprecate old Azure endpoints that are no longer use:
azureCredentials (Can be migrated to secrets service)azureTablesazureTablesSASazureContainersazureContainersSASRemove test dependency on AZURE_ACCOUNT
▶ [patch] #5287
fix: remove temporary dependency.
▶ [patch] #5363 The generic-worker no longer resolves tasks as exception that mount a file/directory that has disappeared from the file system. Instead it invalidates the cache entry.
▶ [patch] #5433 Show workers from last recently active. Also, removed the deprecated prop onChangePage and replaced with onPageChange.
▶ [patch] #4999 Introduce queue timeout to avoid some cloud calls to be stuck and fail whole scan process.
▶ [patch] #4366 Display last date active in the worker detail view.
▶ [patch] #5412 Docker-worker no longer accepts and ignores arbitrary properties in task payloads. It now only accepts properties defined in its payload schema.
▶ [patch] #2776
Show worker tasks from most recent to least recent. Also, link the taskId field to the task page.
▶ [patch] #5433
Show workers from last recently active. Also, removed the deprecated prop onChangePage and replaced with onPageChange.
▶ [patch] Add null check to lastDateActive in queue workers serialize() func.
▶ [patch]
Add null check to lastDateActive in queue workers serialize() func.
No changes
No changes
▶ [patch] bug 1767244 Upgrade hawk to v9.0.1 to fix a vuln.
▶ [patch] bug 1767244
Upgrade hawk to v9.0.1 to fix a vuln.
### DEVELOPERS ▶ [patch] Fix build.sh
▶ [patch] Fix build.sh
▶ [patch] Upgrades some vulnerable rust deps and rust toolchain from 1.49.0 to 1.60.0.
▶ [patch] #5373
Allow local UI to run against existing taskcluster installation using TASKCLUSTER_ROOT_URL.
▶ [patch] #5362 Display task artifacts sorted by importance
▶ [patch] #5348 Fix artifact copy functionality.
▶ [patch] Fix null check error from #5380
▶ [patch] Upgrades some vulnerable rust deps and rust toolchain from 1.49.0 to 1.60.0.
▶ [minor] #4999 Trigger immediate resource provisioning for Azure.
Since operations are already async, this shouldn't slow down provisioning loop.
It is done in attempt to prevent azure workers stay in 'Requested' state until the next workerScannerAzure loop picks it up.
▶ [patch] bug 1613593 Adding extra information about failed worker provisioning
▶ [patch] #5364
The github/v1/repository/<owner>/<repo>/<branch>/latest endpoint now supports projects using checks-v2 reporting.
<details> <summary>1 Renovate updates</summary>
</details>
▶ [patch] Return lastDateActive from queue.listWorkers().
▶ [patch]
Return lastDateActive from queue.listWorkers().
<details> <summary>1 Renovate updates</summary>
</details>
▶ [patch] Update ViewWorkers query to get lastDateActive. Update some schemas too.
▶ [patch]
Update ViewWorkers query to get lastDateActive. Update some schemas too.
<details> <summary>1 Renovate updates</summary>
</details>
▶ [patch] go get no longer builds or installs packages in module-aware mode, so replacing with go install.
▶ [patch]
go get no longer builds or installs packages in module-aware mode, so replacing with go install.
Nothing published for this version
▶ [patch] Add new counts/capacities to graphql schema.
▶ [patch] Add new counts/capacities to graphql schema.
▶ [minor] #4987 Worker manager scanner split in two: non-azure providers and azure.
Deprecates get_worker_pool_with_capacity, get_worker_pools_with_capacity, and update_worker_pool_with_capacity.
▶ [minor] #4942
Addresses #4942. Add get_worker_pool_with_capacity_and_counts_by_state, get_worker_pools_with_capacity_and_counts_by_state, and update_worker_pool_with_capacity_and_counts_by_state functions to get worker counts and capacity by state for worker pools.
Deprecates get_worker_pool_with_capacity, get_worker_pools_with_capacity, and update_worker_pool_with_capacity.
▶ [patch] Change azure nic payload.
▶ [patch] Change azure nic payload.
▶ [patch] #4987 Azure cannot create VMs without with Network interface. We create network interface always, but skip provisioning of public IP when it
▶ [patch] #4987 Azure cannot create VMs without with Network interface. We create network interface always, but skip provisioning of public IP when it's not needed. There might be a case where public IP is needed for RDP though.
▶ [patch] The existing pulse messages for worker-manager are now documented.
▶ [patch] The existing pulse messages for worker-manager are now documented.
▶ [minor] #4987 Skip public network creation for Azure workers that only have generic worker config.
▶ Additional change not described here: #5323.
<details> <summary>1 Renovate updates</summary>
</details>
▶ [patch] Upgrade Node.js version from v16.14.0 to v16.14.2 for OpenSSL security patch.
▶ [patch] Upgrade Node.js version from v16.14.0 to v16.14.2 for OpenSSL security patch.
▶ [patch]
Upgrade to latest minimist version to address https://github.com/taskcluster/taskcluster/security/dependabot/73.
▶ [patch]
Upgrade to latest mocha version to address https://github.com/taskcluster/taskcluster/security/dependabot/70, https://github.com/taskcluster/taskcluster/security/dependabot/71, and https://github.com/taskcluster/taskcluster/security/dependabot/72.
▶ [patch] #5282 Fix issue with unicode characters in user profile.
Using Github as oauth provider encodes user profile using base64 encoding,
which, if contains unicode characters, is not decoded properly by atob().
▶ [patch] #5003 Allow provisioner to exit instead of being stuck in delayed loop.
▶ [patch] #5235 Added __version__, __lbheartbeat__, and __heartbeat__ endpoints to web-server service. Can be reached at /api/ /v1/{__version__, __lbh
▶ [patch] #5235
Added __version__, __lbheartbeat__, and __heartbeat__ endpoints to web-server service. Can be reached at /api/<service name>/v1/{__version__, __lbheartbeat__, __heartbeat__}. __heartbeat__ is simply returning a 200 empty JSON object for now - implementation to follow in individual PRs per service.
▶ [patch] #5269 Worker-runner now renews worker credentials at an appropriate time, even if the host hibernates before the credentials expire.
▶ [patch] #5277 Fix "can't access property length of undefined" that prevented showing missing permissions error.
▶ [patch] #5274
fix: Follow Log enabled by default to automatically load to bottom of log file.
▶ [patch] #5271 Added missing badge statuses, changed badge colors to be more distinctive.
▶ [patch] bug 1651965 Update get_queue_artifacts_paginated query to use index and speed up query. Details: https://bugzilla.mozilla.org/show_bug.cgi?id=1651965
▶ [patch] #5284 Updated azure test signature due to expiration of existing one.
▶ [patch]
Fix usage of temporary.writeFile in uploadToS3 for docker-worker
▶ [patch] Go patch update from 1.17.7 to 1.17.8. Also upgrade golangci-lint from 1.39.0 to 1.44.2.
▶ [patch] Go patch update from 1.17.7 to 1.17.8. Also upgrade golangci-lint from 1.39.0 to 1.44.2.
▶ [patch] #5234
Added initial /__heartbeat__ endpoint to all service APIs. Simply returning a 200 empty JSON object for now - implementation to follow in individual PRs per service.
Addresses issues 5234, 5236, 5237, 5238, 5239, 5240, 5241, 5242
<details> <summary>1 Renovate updates</summary>
</details>
▶ [patch] #5235 Added ingress to the web-server service to access the __version__ and __lbheartbeat__ endpoints. Can be reached at /api/web-server/v1/
▶ [patch] #5235
Added ingress to the web-server service to access the __version__ and __lbheartbeat__ endpoints. Can be reached at /api/web-server/v1/{__version__, __lbheartbeat__}.
These were added to comply with the Dockerflow standard.
▶ [patch] #5247 Pagination and filters shown conditionally
▶ [patch] Fix the badge generation when using the badge API. It now works when deployed through helm too
▶ [patch]
Introduces dev:ensure:db and dev:ensure:rabbit commands to ensure postgres and rabbit have necessary user accounts and permissions.
Updated dev-deployment.md with instructions how to set up own rabbitmq/posgres for testing/dev puropses.
▶ Additional change not described here: #5150.
▶ [patch] Added __version__ and __lbheartbeat__ endpoints to all services. Can be reached at /api/ /v1/{__version__, __lbheartbeat__}. These were adde
▶ [patch]
Added __version__ and __lbheartbeat__ endpoints to all services. Can be reached at /api/<service name>/v1/{__version__, __lbheartbeat__}.
These were added to comply with the Dockerflow standard.
▶ [minor] #5139
Added support for reporting: checks-v1 in generated github badges
▶ [patch] #5181 Added "Copy URL" to the artifacts table.
▶ [patch] #5181 Added "Copy URL" to the artifacts table.
Added filter row functionality for big tables.
▶ [patch] #5027 Clicking on a secret row now works outside of the text part as well
<details> <summary>1 Renovate updates</summary>
</details>
▶ [patch] Remove unneeded nginx config, tcp_nopush as it's already set in the default config by nginx.
▶ [patch]
Remove unneeded nginx config, tcp_nopush as it's already set in the default config by nginx.
▶ [patch] #4983 Improved snapshot testing with react-testing-library (instead of Enzyme). Fixes UI menu for the task actions: correct icon for tasks n
▶ [patch] #4983
Improved snapshot testing with react-testing-library (instead of Enzyme).
Fixes UI menu for the task actions: correct icon for tasks named ^(rerun|retrigger).
Improves ViewTask page: show all details without "Show more/show less".
Shows artifacts by default, if there's less than 10 of them.
▶ [patch]
Updated nginx user config location due to node LTS upgrade changing paths from /etc/nginx/conf.d/default.conf to /etc/nginx/http.d/default.conf.
Also, added __heartbeat__ config back to nginx.conf to continue to serve 200s until work in https://github.com/taskcluster/taskcluster/issues/4597 is complete.
▶ [minor] #3540
generic-worker tasks can now use tar.xz and tar.zst formatted mounts.
▶ [patch] #5193 Fix webpack loader to properly handle .mjs modules.
▶ [patch] #5193
Fix webpack loader to properly handle .mjs modules.
Include yarn build in testing pipeline to avoid inconsistent dependencies.
▶ [patch] #5082 Updated go from 1.16.7 to 1.17.6. This fixes an issue where the generic worker failed to build on M1 MacBooks (arm64).
▶ [patch] #5082 Updated go from 1.16.7 to 1.17.6. This fixes an issue where the generic worker failed to build on M1 MacBooks (arm64).
▶ [minor] Fixed artifacts pagination
▶ Additional change not described here: #5070.
<details> <summary>7 Renovate updates</summary>
</details>
▶ [patch] #5039 The new queue.aws_endpoint Helm configuration value allows setting the endpoint used to access S3 buckets. This configuration enables
▶ [patch] #5039
The new queue.aws_endpoint Helm configuration value allows setting the endpoint used to access S3 buckets. This configuration enables use of non-AWS S3-compatible backends.
▶ [minor] #4614 This version drops support for Python-2.7 in the Python client. Python-2.7's support window ended over one year ago.
▶ Additional change not described here: #4594.
▶ [patch] No changes. Deployment failed for 44.2.1 as well.
▶ [patch] No changes. Deployment failed for 44.2.1 as well.
▶ [minor] bug 1131975 taskcluster command line tool to validate json against a schema. having syntax taskcluster validate-json https://some_schema.jso
▶ [minor] bug 1131975
taskcluster command line tool to validate json against a schema. having syntax taskcluster validate-json https://some_schema.json https://example.son
▶ [patch] #4896
The queue no longer returns 500 errors when calling queue.getArtifact for an object artifact.
▶ [patch] #4934
When running yarn dev:init, store the RabbitMQ cluster management API
origin at meta.rabbitAdminManagementOrigin rather than the root key
rabbitAdminManagementOrigin. This avoids a schema validation error when
running yarn dev:apply. If you've already run yarn dev:init, then you
can manually move rabbitAdminManagementOrigin in dev-config.yml.
▶ [patch] #2749 updated the hook component to be using ListView from material-ui
▶ Additional change not described here: #4920.
<details> <summary>4 Renovate updates</summary>
</details>
▶ [patch] bug 1712924 Resolves an issue with github logins
▶ [patch] bug 1712924 Resolves an issue with github logins
▶ [patch] #4882
Taskcluster-lib-pulse now supports connections to servers that use SNI, such as up-to-date CloudAMQP clusters using a custom certificate. It does so by passing an explicit servername socket option.
▶ [patch] #4606 Generic-worker now supports downloading object artifacts as well as the older s3 artifacts.
▶ [MAJOR] #4895 The upload helper functions included with each client now take an uploadId parameter. For Go and Rust, these parameters are required.
▶ [patch] bug 1711612
Retried calls to queue.createArtifact will now work correctly, allowing both retries and the documented updates.
▶ [patch] #4764 The JS, Rust, Go (in a previous release) and Python clients now have artifact download functions which will download an artifact regardless of its storage type, applying retries and other best practices.
▶ [patch] #4714 The client libraries' object-upload functions now calculate and send hashes for the uploaded objects.
▶ [patch] #4890 This version fixes a bug in the rust client where API methods with method POST but without a request payload would result in 411 errors due to a missing Content-Length header.
▶ [patch] bug 1711921
When a docker-worker's payload specifies an artifact name ending with /, it has historically produced an artifact containing //. That is now normalized to a single /.
▶ Additional changes not described here: #4757, #4807, #4889.
<details> <summary>40 Renovate updates</summary>
</details>
▶ [minor] #4746 The object service is now ready for use. The queue supports an object storage type which will be stored in the object service. As of t
▶ [minor] #4746
The object service is now ready for use.
The queue supports an object storage type which will be stored in the object service.
As of this version, we recommended setting procs: 1 for the object service if it had previously been set to 0, and configuring at least one backend for artifacts.
▶ [patch] #4648
All services now have a <service>.pulse_amqps Helm configuration that controls whether to use amqps (with TLS) to communicate with the Pulse server. The value defaults to true, matching current behavior, but can be set to false in cases where the AMQP server is local and encryption is unnecessary.
▶ [patch] The object service now defaults to 1 replica, not 0. The service will not start if it is not properly configured, and we recommend setting the service up at this time, as in the next major release workers will begin uploading objects to the queue.
▶ [minor] bug 1631824 The Azure provider of the worker-manager service now assigns unique names to all data disks attached to a VM, allowing those disks to be removed when the worker is removed.
▶ [patch] #4765 Native "Apple silicon" binaries of taskcluster-proxy, livelog, start-worker and generic-worker are provided (darwin-arm64). The darwin amd64 executables no longer need to be run through Rosetta 2 binary translation on darwin/arm64 workers.
▶ [patch] #3925 The worker-manager service now ships with the latest CA certs, avoiding the need to download these at runtime. These certificates are good until October 8, 2024.
▶ Additional changes not described here: #4707, #4779, #4795.
<details> <summary>36 Renovate updates</summary>
</details>
▶ [patch] #4696 The github.com/taskcluster/taskcluster/vNN/workers/generic-worker/mocktc library is no longer publicly exposed.
▶ [patch] #4696
The github.com/taskcluster/taskcluster/vNN/workers/generic-worker/mocktc library is no longer publicly exposed.
▶ [patch] Upgrade from node 14.16.0 to 14.16.1 across services and docker-worker.
▶ [patch] bug 1442024
The object service now serves text/html content with Content-Disposition: attachment to avoid security issues inherent in serving arbitrary HTML documents.
▶ [patch] Go major version upgrade for generic-worker and worker-runner (go 1.15.6 -> go 1.16.3). Prerequisite step for providing native darwin/arm64 binaries for both (native Apple Silicon builds).
▶ [minor] #4548
The queue now additionally supports artifacts with the storageType object, stored via the object service.
▶ [patch] #4576 The shell client now has two new commands to download data from Taskcluster:
taskcluster download object <name> <filename> -- download directly from the object servicetaskcluster download artifact <taskId> [<runId>] <name> <filename> -- download the content of an artifact
These commands follow current best practices, including retries with backoff. When supported by the object service, they will also verify download integrity.▶ [patch] #4698 Uploading functions in the Python client have been renamed to use camel-case instead of underscores.
▶ Additional changes not described here: #4623, #4631, #4739, #4741, #4744.
<details> <summary>20 Renovate updates</summary>
</details>
…relative to the working directory. This is a breaking change from previous behaviour.
▶ [patch] #4655 Since #4586 landed, the built-in-workers service has failed to resolve tasks due to using the wrong credentials. This issue has been fixed, and no released version of Taskcluster had this bug.
▶ [patch] #4561
The GitHub service now allows collaborators to test out a .taskcluster.yml in a PR, when there is no such file in the default branch initialized yet.
▶ [patch] #4556
The auth.azure_accounts Helm value is no longer required.
▶ [patch] #3981
The new queue.task_claim_timeout Helm configuration parameter controls the duration of the task claim that queue.claimWork returns. The default is 20 minutes, matching the previous hard-coded setting.
▶ [MAJOR] #3779
Generic-worker simple/docker engine now have a default tasks directory of tasks, relative to the working directory. This is a breaking change from previous behaviour.
▶ [patch] #4691
Added a generic-worker config parameter (livelogPortBase) to allow configuring which ports are used for live logging.
▶ [patch] #4715
The worker-manager service now deprovisions workers when removeWorker is called and when the workers terminate themselves. Previously it would wait forever for such workers to be deleted, without attempting that deletion.
▶ [MAJOR] #4586 The following queue API endpoints no longer support their legacy scopes. In most of these cases, the legacy scopes are shorter than the still-supported fully-qualified scopes.
queue.claimTask no longer accepts queue:claim-task.queue.reclaimTask no longer accepts queue:reclaim-task.queue.reportCompleted and queue.reportException no longer accept queue:resolve-task.queue.createArtifact no longer accepts queue:create-artifact:<name>.Investigations detailed in the linked issue suggest that none of these scopes are actively used.
▶ [minor] #4516
The index service has a new index.deleteTask method that can be used to delete indexed tasks.
▶ [minor] #4547
This version adds new queue methods artifact, latestArtifact, artifactInfo, and latestArtifactInfo, all of which provide more flexible access to information about artifacts.
▶ [patch] #4502
The GitHub service now correctly handles tasks that depend on other tasks not defined in .taskcluster.yml.
▶ [patch] #3794 The worker manager no longer considers quarantined users in its definition of existing capacity. If necessary, it will provision new workers for any pending tasks as if the quarantined worker did not exist.
▶ [patch] #2393 On the Secrets and Roles pages, a delete button now appears on each row.
▶ [patch] The client libraries (Go, Python, Rust, and JS) now provide convenience methods for uploading/downloading objects to/from the Object Service.
▶ [patch] #3964
The styleguidist support in ui/ was outdated and has been removed.
▶ Additional changes not described here: bug 1419577, bug 1701255, #3948, #3993, #4133, #4420, #4422, #4423, #4424, #4453, #4523, #4587, #4592, #4608, #4610, #4631, #4631, #4646, #4649, #4705, #4722, #4537.
<details> <summary>87 Renovate updates</summary>
</details>
▶ [patch] #4519 Tasks with priority or requires can once again be created via the UI. (This includes creating interactive tasks.)
▶ [patch] #4519
Tasks with priority or requires can once again be created via the UI. (This includes creating interactive tasks.)
<details> <summary>4 Renovate updates</summary>
</details>
▶ [minor] #4470 The task-creator and retrigger function now treat task definitions as a JSON object, accepting new properties such as taskQueueId and
▶ [minor] #4470
The task-creator and retrigger function now treat task definitions as a JSON object, accepting new properties such as taskQueueId and projectId.
▶ [patch] #4502 A case where an invalid .taskcluster.yml would not result in a user-visible error has been fixed
▶ [patch] #2393 On the page where all clients are listed, added Delete icon beside each client. This helps to delete client faster without going to the Client page.
▶ Additional change not described here: #4458.
<details> <summary>20 Renovate updates</summary>
</details>
▶ [minor] #4050 Docker-worker and generic-worker now use link artifacts to connect live.log to live_backing.log. This functionality requires Taskclust
▶ [minor] #4050
Docker-worker and generic-worker now use link artifacts to connect live.log to live_backing.log. This functionality requires Taskcluster services running at least Taskcluster-40.0.0.
▶ [minor] #4455 As of this version, the Javascript client library now uses got instead of superagent to make its HTTP requests. There is no intentional user-visible impact.
▶ Additional changes not described here: #4386, #4444.
<details> <summary>20 Renovate updates</summary>
</details>
▶ [patch] #4417 In a followup to a bug partially fixed in v41.0.1, the hooks.triggerHook function no longer crashes due to the projectId property from
▶ [patch] #4417
In a followup to a bug partially fixed in v41.0.1, the hooks.triggerHook function no longer crashes due to the projectId property from queue.createTask.
▶ Additional change not described here: #4405.
<details> <summary>1 Renovate updates</summary>
</details>
▶ [patch] #4417 The hooks.triggerHook method no longer fails with a 500 error, and now correctly includes the taskQueueId property.
▶ [patch] #4417
The hooks.triggerHook method no longer fails with a 500 error, and now correctly includes the taskQueueId property.
▶ [patch] #4411
The queue.createArtifact method now allows specifying a contentType for "link" artifacts, which is necessary to indicate to the UI that a link can be viewed as a logfile.
▶ [patch] #4304 The queue now better tracks workers. In particular, it will not "lose track of" a worker which resumes claiming work a short time after it expires, and workers will not immediately expire after being un-quarantined.
▶ Additional changes not described here: #4273, #4274, #4340, #4346, #4380, #4388.
<details> <summary>21 Renovate updates</summary>
</details>
The object service remains entirely experimental and further breaking changes will be made without major version bumps.
▶ [patch] #4272
The experimental object.uploadObject endpoint has been removed and replaced with object.createUpload. The object service remains entirely experimental and further breaking changes will be made without major version bumps.
▶ [patch] #4276 The worker-manager service will now start up even if one of its providers is down or misconfigured. Worker pools using that provider will not be provisioned, but other pools will continue to operate normally.
▶ [patch] #4336
Worker-Runner now correctly includes the workerGroup and workerId properties in error reports.
▶ [MAJOR] #4262
Tasks now have a projectId property that can be used to distinguish tasks for different purposes run in the same Taskcluster deployment. The queue.createTask method now requires scope queue:create-task:project:<projectId>, permitting administrative control over which clients can create tasks for which projects.
The default projectId is none. To avoid permissions errors on upgrade, we recommend that queue:create-task:project:none be added to the anonymous role before upgrading to this version. Once the upgrade is complete, callers may be modified to create tasks with non-default projectId and given appropriate scopes.
▶ [minor] #4270
Task manipulation (rerun, cancel, schedule) is now controlled by scopes related to the task's projectId, completing implementation of RFC#163. With this change, and with the inclusion of projectId in task definitions, administrators can control task manipulation by granting queue:<verb>-task-in-project:<projectId> scopes to the appropriate entities.
▶ [patch]
Upgrade to Sentry v6, but disable the new
session tracking feature
with autoSessionTracking: false, to avoid collecting more data than is
needed.
▶ [MAJOR] #3581
Client methods that took two separate provisionerId and taskQueueId parameters take now a
single parameter (workerPoolId or taskQueueId depending on the service involved).
Affected methods are queue.claimWork, queue.pendingTasks, purgeCache.purgeCache and purgeCache.purgeRequests.
The API maintains compatibility at the URL level.
▶ [MAJOR] #4058
The queue.getArtifact and queue.getLatestArtifact methods now also return a JSON body containing the URL from which the artifact can be downlodaed, in addition to the existing behavior, returning a 303 redirect.
This is a major change only because it changes the function signatures in the Go client.
▶ [minor] #3580 The queue service API responses will now include the taskQueueId, which will match provisionerId/workerType, which are also returned. Also, it is now possible to create tasks supplying a taskQueueId instead of the separate provisionerId and workerType identifiers.
▶ [minor] #4247
Updating an artifact from a reference type to link type now correctly updates the artifact type.
▶ [patch] #4248 Fixed an issue where listing tasks with link artifacts would cause errors.
▶ [patch] #4269
The task properties projectId and taskQueueId are now displayed in the Taskcluster UI, and referenced appropriately in the documentation.
▶ [patch] bug 1562993 generic-worker now only reports the first error it encounters when a task fails or hits an exception.
▶ [minor] #4058
Client libraries no longer treat redirects as errors. The methods that return redirects are those which involve fetching artifacts, and typically these have required generating signed URLs. With this change, these methods can be called directly and will return a JSON payload containing a url property from which the artifact can be downloaded. The fetch API does not support reading bodies from redirects, so this functionality is not available in taskcluster-client-web, which treats redirects as errors.
▶ [minor] #2393 On the page where all roles are listed, added Delete icon beside each role. This helps to delete role faster without going to the Role page.
▶ [minor] Taskcluster now sports a Rust client!
▶ [patch] #3789 Fixed an issue where when there's no more data, the continuationToken property was not being omitted, but being returned as just an empty string. Depending on implementation, that could cause a caller to loop endlessly calling the purge cache endpoint.
▶ Additional changes not described here: #3868, #4250, #4275, #4279, #4281, #4295, #4296, #4298, #4256.
<details> <summary>72 Renovate updates</summary>
</details>
No changes
No changes
▶ [minor] This version removes the unused deployment configuration variable queue.use_cloud_mirror and queue.public_artifact_ec2_proxies. Neither serv
▶ [minor]
This version removes the unused deployment configuration variable queue.use_cloud_mirror and queue.public_artifact_ec2_proxies. Neither served any useful purpose, and it is unlikely that either value appears in any deployment configuration.
▶ [patch] #4125
Workerpools now correctly understand the reregistrationTimeout option.
▶ [MAJOR] #3773
Support for superseding has been removed. See the linked issue for the detailed reasoning. While workers still allow supersederUrl in payloads, it has no effect. Older workers running with newer services that try to supersede tasks will encounter errors. No known instances of superseding exist.
▶ [MAJOR] #4123
The taskcluster-client-web library no longer implements OIDCCredentialAgent. This agent interfaced with a login.taskclutser.net service that no longer exists.
▶ [MAJOR] #3604 The notify service no longer supports irc notifications. IRC is declining in popularity and no known deployments of Taskcluster support this functionality, but it is nonetheless considered a breaking API change.
▶ [minor] #4050
The queue has a new artifact type, link, allowing links between artifacts on the same task.
▶ [patch] #4057 All clients (JS, Python, Go, Web, Shell) now fail when an API method results in a redirect, rather than following that redirect. The API methods that return redirects are those related to Taskcluster artifacts, and these methods must be accessed by building and fetching a signed URL.
▶ [patch] #2721
Taskcluster-proxy now correctly proxies "non-canonical" URLs, such as those containing // or urlencoded values.
▶ [patch] #3878 The Taskcluster UI now handles artifacts better, avoiding huge URLs that expire quickly.
▶ [patch] #3983 The UI will no longer fail when viewing a task with dependencies that have expired.
▶ [patch] #4199
The sift dependency has been updated again, to a version that does not cause #4061.
▶ [patch] #1064
The taskcluster command now parses errors from the API, and does not show the command usage when an error occurs.
▶ [patch] #3758
The taskcluster command will now display a warning after a short delay if it is expecting a request payload on stdin.
▶ [minor] #3578
The queue service now uses taskQueueId internally instead of the pair provisionerId/workerType for tasks.
▶ [patch] #3894 Postgres errors now include a Sentry fingerprint to help distinguish them in error reports.
▶ Additional changes not described here: #2398, #2875, #3466, #3665, #3739, #3751, #3888, #4072, #4125, #4209, #3718.
<details> <summary>57 Renovate updates</summary>
</details>
▶ [patch] This version fixes an error where a worker pool with an invalid providerId would cause all worker provisioning to cease.
▶ [patch] This version fixes an error where a worker pool with an invalid providerId would cause all worker provisioning to cease.
▶ [minor] #3542 Docker-worker no longer supports VNC access to interactive tasks. This support has been broken for ages and unused.
▶ [patch]
The taskcluster-client-web library client classes now have a buildSignedUrlSync method.
▶ [patch] #4056 The taskcluster-proxy no longer follows redirects. In practice, this is only an issue when calling the artifact-related API methods that return a redirect to the artifact content. The proxy will now return the redirect response unchanged.
▶ [minor] #3578
The tasks table uses task_queue_id instead of separate provisioner_id/worker_type to identify task queues.
This change is applied through an online migration process.
▶ Additional change not described here: #3940.
<details> <summary>5 Renovate updates</summary>
</details>
▶ [patch] The octokit throttling plugin has been removed in this release. We did not appear to understand its assumptions. It will probably come back
▶ [patch] The octokit throttling plugin has been removed in this release. We did not appear to understand its assumptions. It will probably come back later once we understand it better.
▶ Additional changes not described here: #3892, #4012.
<details> <summary>1 Renovate updates</summary>
</details>
▶ [patch] #4034 The queue's artifact expiration crontask now uses a much more efficient query and should be able to keep up with the load.
▶ [patch] #4034 The queue's artifact expiration crontask now uses a much more efficient query and should be able to keep up with the load.
▶ [patch] #3797 A race condition in github checks updates has been resolved
▶ [patch] #4064 Taskcluster services and docker-worker now use Node 14, the current LTS version.
▶ [patch] #4059 Fixed an issue fetching GitHub metadata when using a Taskcluster instance without the anonymous role.
▶ [patch] #4059 Fixed an issue fetching GitHub metadata when using a Taskcluster instance without the anonymous role.
This presented as unexpected 'Failed to get your artifact.' errors.
▶ [minor] #4006
The takscluster-client-web library is no longer installable from a <script> tag.
Instead, it should be incorporated into the build process of the consuming application, like any other library.
▶ [patch] Improved error messages related to fetching artifacts for GitHub checks.
▶ [patch] #4061 This version fixes an issue with the "actions" button not appearing for task groups.
▶ [patch] #3939
The object service now supports uploadId in the upload process.
▶ [patch] #4074 We now use github's library for generating app jwt tokens instead of making our own tokens
▶ Additional changes not described here: #3951, #3999, #4036.
▶ [patch] #3901 Fixed a bug where signing public S3 artifacts would result in Forbidden errors on the task and task group views.
▶ [patch] #3901 Fixed a bug where signing public S3 artifacts would result in Forbidden errors on the task and task group views.
▶ [patch] #3867
Taskcluster-Github should now function correctly in a deployment with no scopes in the anonymous role.
If you have a locked-down deployment without allowing public artifacts fetching in your anonymous role, you must add
queue:get-artifact:public/github/customCheckRunText.md and queue:get-artifact:public/github/customCheckRunAnnotations.json
to the scopes of your task to avoid an error comment being added to your
commits. Note that this will change if you choose a custom artifact name (see custom artifact docs for more)
▶ [MAJOR] #3713
This version introduces a new, in-development object service. It is currently configured for a default replica count of 0, meaning that it will not run, and this is the recommended configuration. However, it will nonetheless require configuration of a new database user (<prefix>_object).
▶ [minor] #3669 The Azure worker-manager takes additional steps to verify the identity proof during worker registration. The identify proof is the output of the attested data API, which includes details about the worker and is signed by the Azure platform.
Previously, the worker-manager checked that the message signer was issued by one of four published intermediate certificates issued by a single root CA. Azure is planning to expand to five more root CAs (see Azure TLS certificate changes for details). The worker-manager now downloads an unknown intermediate certificate, verifies that it was issued by a known root CAs, and adds it to the list of trusted certificates. The 4 legacy intermediate certificates, still in use in Azure as of November 2020, are pre-loaded as trusted certificates.
The worker manager now verifies that the message signer is for
metadata.azure.com or a subdomain. This is true for any workers in the
Azure public cloud, but not the sovereign clouds like azure.us.
One of the new root CAs uses Elliptic Curve Cryptography (ECC) instead of RSA. The Azure worker-manager doesn't support this or other ECC certificates. This is tracked in issue #3923.
There is no performance change expected until Azure ships the TLS certificate
changes, planned by February 15, 2021. When new intermediate certificates are
used, there will be up to a 5 second delay on worker registration while the new
certificate is downloaded for the first time. A new manager log entry,
registration-new-intermediate-certificate, is emitted after a successful
download and verification, and includes the certificate details.
▶ [patch] #3899 Docker-worker now decompresses downloaded images when they have a compressed content-encoding, as artifacts produced by docker-worker now have.
▶ [patch] #3637 Taskcluster-Github should now avoid spamming an identical comment many times in certain situations.
▶ [patch] #3982 The quickstart now correctly shows whether the GitHub integration is enabled for a repository.
▶ [patch] #3578
There are two new API methods for the queue service: listTaskQueues and getTaskQueue
▶ [minor] #3578
The queue service now uses taskQueueId internally, instead of provisionerId/workerType, for worker info
purposes (provisioners, worker types and workers).
The queue_provisioners table is dropped and the queue_worker_types table is renamed to task_queues.
▶ [patch] #3832 Octokit now uses github's own retry/rate-limit plugins instead of our own.
▶ Additional changes not described here: #3712, #3715, #3717, #3719, #3808, #3881, #3898, #3917, #3935, #3937, #3954, #3986, #4009.
▶ [patch] #3906 Creating comments on github is fixed in this release
▶ [patch] #3906 Creating comments on github is fixed in this release
▶ [patch] #3903
Scopes are now expanded in between using a certificate's scopes and checking authorizedScopes
as well.
▶ [patch] #3908 E-mail and Slack notifications should now correctly link to the group when the group ID does not match the task ID.
▶ [patch] #3874 The notify service now has enough scopes to handle notifications on Taskcluster instances without the anonymous role.
▶ [patch] #3874 The notify service now has enough scopes to handle notifications on Taskcluster instances without the anonymous role.
▶ [patch] #3884
Clients created with third-party sign-in (e.g., taskcluster signin) will no longer be disabled if they contain assume:anonymous or scopes in that role.
▶ [patch] #3899
Docker-worker now skips gzipping artifacts with an .lz4 extension, in addition to the existing list of extensions.
▶ [patch] #3873
The /provisioners/<worker-type> view now works correctly, fixing the error about reading property replace of null.
▶ Additional change not described here: #3837.
▶ [patch] Setting a node DEBUG env var via the debug field of service configs is supported again. If left unset it will default to ''. Example:
▶ [patch]
Setting a node DEBUG env var via the debug field of service configs is supported again.
If left unset it will default to ''. Example:
auth:
debug: '*'
▶ [patch] #3865 Livelog TLS support is now functional.
▶ [patch] #3851
The GitHub quickstart tool now generates correct .taskcluster.yml files, among other bugfixes.
▶ [patch] #3836 The web UI no longer fails with "ext.certificate.expiry < now".
▶ [patch] #3831 This version fixes an issue introduced in v38.0.0 which would cause the log viewer to display 401 errors.
▶ [patch]
Config types of env:list now generate the correct type in helm schemas.
Your coding agent can read these notes before it upgrades. Set up the MCP server →