2026-06-10T21:48:24Z - 2026-09-10T21:48:24Z
Overview
3 releases published by 1 user
Published
0.2.0
0.2.0
Published
0.1.1
0.1.1
Published
0.1.0
0.1.0
75 pull requests merged by 1 user
Merged
#137 release: 0.2.0
Merged
#139 refactor: one drill record per version, in drills/
Merged
#138 feat: CI refuses a release PR with no drill record
Merged
#136 docs(changelog): one line per entry, and a pass over the whole file
Merged
#135 fix: route the #124/#125 test files through tmp()
Merged
#124 feat: cast github-app create/register — run the App Manifest flow instead of transcribing it
Merged
#122 fix: floor the shellcheck sweep on bin/cast, and stop skipping newline-less files
Merged
#120 fix: reap temp dirs — a runtime clone leak in resolveCheckout, and 68 uncleaned test sites
Merged
#125 feat: an application can declare HTTP basic auth, and apply sets it
Merged
#119 fix: lint every tracked shell script, and prove the set is complete
Merged
#134 fix: assert no shipped changelog heading is deleted or duplicated
Merged
#132 fix(labels): sweep on labeled so the handoff is immediate
Merged
#130 docs(contributing): document the blocker axis and merge-next ownership
Merged
#129 refactor(labels): split PR labels into state (whose ball) and blocker (what is in the way)
Merged
#128 fix(labels): state:needs-human means a human could merge it right now
Merged
#116 release: 0.1.1
Merged
#115 chore: bump main to 0.1.1-dev
Merged
#114 fix: the ceremony re-arms the changelog, and CI notices when it doesn't (#113)
Merged
#110 release: 0.1.0
Merged
#112 feat: merging a release-labeled PR is the release
Merged
#109 fix: the release suite accepts the ceremony's own tree
Merged
#105 fix: CAST_AGE_KEY_FILE_<ENV> maps to a name a shell can set
Merged
#106 fix: a manifest with no ${…} refs applies without a store (#104)
Merged
#107 fix: resolve the GitHub App only when the manifest declares applications (#103)
Merged
#101 feat: release flow — tagged releases with a prebuilt dist asset (#96)
Merged
#100 feat: versioned installations — the box#79 layout, ported the way rig#36 ported it
Merged
#99 fix: base the human auto-request on this handoff, not review history
Merged
#93 fix(draft): read backup schedules and emit backup blocks (#75)
Merged
#95 feat(draft): capture service hostnames via per-service GET (#83)
Merged
#92 fix(draft): name is_static in UNCAPTURED.md when the live read cannot see it (#70)
Merged
#91 docs(semantics): GitHub App registration is API-doable at 4.1.2 (#84)
Merged
#94 fix(secrets): read the age identity once per process so <(...) keys survive --all
Merged
#90 fix(test): use /dev/fd instead of /proc/self/fd in fd-path regression test
Merged
#98 feat: label automation — state reconciler, path-scoped labeler, and CONTRIBUTING
Merged
#97 docs: LABELS.md — the label taxonomy (states, stale/blocked, scopes)
Merged
#88 fix(diff): Coolify's own generated vars are not orphans (#87)
Merged
#86 fix(diff): ignore preview env rows so they cannot shadow production (#85)
Merged
#82 feat(draft): resolve a repo's GitHub App by source_id, not the only-App guess (#72 item 8)
Merged
#81 feat(service): set and diff per-container service hostnames via urls (#72 item 1)
Merged
#80 docs(draft): correct stale "backup schedules not exposed by the API" claim (#72)
Merged
#79 fix(diff): compare non-secret env vars against fresh value, not stale real_value (#78)
Merged
#71 fix: restore-db.sh connects as the container's Coolify superuser, not "postgres"
Merged
#69 fix(diff): converge live projection on compose domains and is_static
Merged
#67 feat(resolve): derive base-URL env vars from manifest domains via ${domain:...} (#66)
Merged
#65 feat(resolve): derive DATABASE_URL/REDIS_URL from the database cast created (#60)
Merged
#64 fix(apply): express static-site build settings so a monorepo app is served, not run (#63)
Merged
#61 feat: diff and apply a database's backup schedule (#51)
Merged
#55 fix(apply): refuse to write the generated-secret placeholder over a live value (#47)
Merged
#56 fix: never write an env var whose name Coolify injects itself (SOURCE_COMMIT, COOLIFY_*)
Merged
#59 feat(destroy): cast destroy — a scoped, state-gated teardown verb (#43)
Merged
#58 feat(capture): --generated-only, the bootstrap's missing pass 2
Merged
#62 test(resolve): fix stale compose_file fixture that reddens main after #49+#46 merge
Merged
#57 fix(apply): pre-flight domain uniqueness, and translate Coolify's 409 (#44)
Merged
#53 fix(apply): create databases and services before the applications that need them (#45)
Merged
#54 feat(resolve): warn that apply cannot enable "Include Source Commit in Build" (#46)
Merged
#52 fix(manifest): refuse checkout paths that are not absolute (#49)
Merged
#42 fix: the first apply against a fresh multi-destination box (#40, #41)
Merged
#39 fix: apply creates the environment its resources name (#38)
Merged
#35 fix: hand the age identity to age on stdin — fd paths resolve only in cast's process
Merged
#33 inventory --emit-draft: a reviewable blueprint of a live instance (#27)
Merged
#32 fleet operations: cast diff/apply --all over the project registry (#26)
Merged
#31 smoke resolves its target inside the project it was declared under (#29)
Merged
#30 a project registry — the list of what exists (#25)
Merged
#28 place a resource on a destination — and a state file that can say which (#21)
Merged
#24 inventory sweeps the instance — and an empty environment shouts (#22)
Merged
#23 --resource: the third name a hand-built box does not share with you
Merged
#20 read-side coordinates (#17, #18) + cast inventory (#19)
Merged
#16 fix clone auth (#13); named Coolify instances (#14); cast capture (#15)
Merged
#12 fix: diff refuses an absent target instead of reporting it as empty (#11, #6)
Merged
#10 cast is team-aware: assert the token's team before mutating (fail-closed)
Merged
#8 chore: re-home the control-plane dump to rig
Merged
#4 fix: restore-db.sh takes the target database name
Merged
#3 fix(install): wire BINDIR onto PATH in the shell profile, not a warning
Merged
#2 docs: add semantics.md — the apply contract and Coolify 4.1.2 limits
Merged
#1 feat: cast — the Coolify executor, extracted from the infra state repo
63 issues closed from 1 user
Closed
#72 Audit: every manual Coolify-UI step, verified against v4.1.2 and next — two claims refuted, two gaps survive into v4.2
Closed
#126 changelog: seed ## Unreleased with all three section headings, and let the -dev bump write them
Closed
#123 A PR can delete a shipped release heading and CI stays green — port box#122's monotonicity guard
Closed
#7 cast github-app create: run the App Manifest flow instead of transcribing it by hand
Closed
#121 The shellcheck class check only covers *.sh, so bin/cast could drop out of the sweep silently
Closed
#117 The test suite leaks temp dirs: 89 mkdtempSync sites, 0 cleanups — 6731 dirs / 189MB in one day, some holding age keys
Closed
#76 Basic Auth / custom labels are API-settable on applications at 4.1.2 — cast just can't say them; rebuilt resources stay unprotected
Closed
#118 CI's shellcheck sweep never lints .github/scripts/*.sh — including release-notes.sh
Closed
#133 changelog: nothing notices a DELETED release heading — and release-notes.sh re-arms on duplicates
Closed
#131 labels: sweep on labeled so the handoff is immediate, and let the author set state:needs-human
Closed
#127 labels: state:needs-human is sticky and blind to mergeability, and nothing says which PR to merge next
Closed
#113 The ceremony disarms CHANGELOG.md: main has no Unreleased section right now, and the next merged PR lands inside shipped 0.1.0
Closed
#5 Promote scripts/register-github-app.sh to a proper subcommand: cast github-app register
Closed
#70 is_static stays create-time-only until Coolify serializes settings on a read — track the upstream fix, and make draft admit what it couldn't see
Closed
#111 Merging a release-labeled PR should BE the release — auto-tag + publish on merge (box#96 twin)
Closed
#108 release.test.ts demands the real Unreleased section — the release PR of the ceremony can never pass CI
Closed
#102 CAST_AGE_KEY_FILE_<ENV> is unsettable for env names containing a hyphen
Closed
#104 Greenfield manifest-first bootstrap is a chicken-and-egg: apply demands a store, capture refuses an absent project
Closed
#103 apply resolves a GitHub App unconditionally — a databases-only manifest cannot apply without one
Closed
#96 release flow: tagged releases with a prebuilt dist asset
Closed
#75 draft still claims backup schedules aren't API-readable (pre-#51 text) — read them and emit backup: blocks
Closed
#83 draft doesn't capture service hostnames — teach --emit-draft the per-service GET (sibling of #75)
Closed
#84 semantics.md: GitHub App REGISTRATION is API-doable at 4.1.2 — say so (#74 leftover)
Closed
#36 --all drains an injected process-substitution key after the first project
Closed
#37 fd-path regression test hardcodes /proc/self/fd — Linux-only, breaks the suite on macOS
Closed
#89 cast smoke's canary appears to live in the PREVIEW env set — the never-delete guarantee is verified against rows apply never writes
Closed
#87 Coolify's own SERVICE_*/POSTGRES_* magic vars report as orphans forever — a correct box can never read clean
Closed
#85 fetchEnv silently collapses duplicate env keys — a shadow row makes every in-place-updated var diff forever (cause of #78)
Closed
#78 cast diff re-proposes the five prod flags as change — root cause UNKNOWN (real_value-stale theory disproved)
Closed
#74 Which GitHub App clones a repo IS visible via the API — resolve source_id instead of the only-App heuristic
Closed
#73 Service hostnames ARE settable and readable on Coolify 4.1.2 (urls) — adopt it, delete the manual-UI step
Closed
#68 diff/apply never converge on a compose app's docker_compose_domains or a static app's is_static — perpetual drift + redeploy every apply
Closed
#66 Derive *_BASE_URL env vars from the manifest domains cast already parses — hand-writing them into the env template drifts from the domains it creates
Closed
#60 Derive DATABASE_URL/REDIS_URL from the database resource cast created — delete the two-pass bootstrap instead of automating it
Closed
#63 apply drops install_command / build_command / is_static — a static monorepo app gets built and RUN as its root package.json, and boots the wrong workspace
Closed
#51 Backup schedules are write-only on a premise that is false — GET /databases/{uuid}/backups exists, so a rebuilt database silently has no backups
Closed
#47 apply writes the pending-coolify-generated placeholder over a live generated secret — a routine command takes prod down
Closed
#50 cast can write an env var that silently suppresses Coolify's own injection of it (SOURCE_COMMIT, COOLIFY_*) — and it fails green
Closed
#43 cast destroy — a scoped teardown verb, because "resolve manually" is a UI deletion with no guardrails
Closed
#48 The bootstrap is two-pass and cast has no pass 2 — nothing can fill a generated secret after apply creates it
Closed
#44 Domain uniqueness is instance-wide, but cast plans project-scoped — so apply can plan a create Coolify will refuse
Closed
#45 apply creates applications before the databases they depend on — a first apply always deploys against nothing
Closed
#46 Can "Include Source Commit in Build" be set via the API? If it can, apply should set it — if it can't, apply should say so
Closed
#49 compose_file without a leading slash 422s the create — cast validates nothing, and its own docs teach the broken value
Closed
#41 The multi-destination 400 is unactionable, and arrives after apply has already mutated Coolify
Closed
#40 A cast-created project is left carrying Coolify's empty default environment
Closed
#38 First apply against a fresh project 404s — cast never creates the Coolify environment
Closed
#34 The documented prod-key recipe (CAST_AGE_KEY_FILE_PROD=<(pm read …)) cannot work: age resolves the fd path in its own process
Closed
#27 inventory --emit-draft: a reviewable blueprint of a live instance (and an honest list of what it could not capture)
Closed
#26 fleet operations: cast diff/apply --all over the project registry
Closed
#29 smoke resolves its target instance-wide: it can write to a different project's — or a different environment's — app of the same name
Closed
#25 state has no project registry — the list of what exists lives only in the operator's head
Closed
#21 cast cannot place a resource on a destination — and the state file has nowhere to say which
Closed
#22 inventory can't sweep an instance — a discovery verb that needs you to have discovered
Closed
#19 cast inventory: see the box before you adopt it — the missing first step
Closed
#17 the environment has no read-side coordinate — so a legacy box gets to name OUR environments
Closed
#18 capture: an absent RESOURCE reports as 15 missing names — the D-237 bug, one level deeper
Closed
#14 support multiple Coolify instances — select by identifier instead of editing .coolify.env
Closed
#15 cast capture: adopt a hand-built Coolify instance into the age secret store
Closed
#13 resolve: authenticate clones via gh CLI / token — never fall into git's interactive prompt
Closed
#6 github_apps bindings: key by full org/repo slug (short-name keys collide across orgs)
Closed
#11 diff cannot tell "project absent" from "project empty" — a name mismatch reports a clean diff that verified nothing
Closed
#9 cast must be team-aware: assert the token's team before mutating (fail-closed)
4 issues created by 1 user
Opened
#77 v4.2 upgrade tracker: settings as diffed fields, destinations resolver, read:sensitive token, OpenAPI re-vendor
Opened
#140 Instance B's compose file is not in the repo — the drill's only reproducible half is the pinned refs
Opened
#141 cast has a drill gate and a record format, but no instrument — nine legs against two live Coolify instances, run from memory
Opened
#142 The next release must carry a real drill record, not a waiver