Summary
- Recover stalled remote operations after a configurable deadline or agent revocation/re-enrollment, release unused relay capacity without replaying work, and preserve remote cleanup fences. An offline-agent alert is enabled by default.
- Enforce job-scoped count and day retention after successful backups. New archives use per-job namespaces; older unscoped archives and other jobs' files are preserved.
- Isolate agent TLS transport: port
8080serves the web interface and public API but rejects/agent/v1; port8443serves only/agent/v1/*. - Fix container image builds by registering supervised services in the updated S6 user bundle. The queue workers, scheduler and agent TLS service start correctly with the current base image.
Upgrade Notes
- Database migrations are included and run through the normal startup process. Preserve existing storage and
APP_KEYwhen recreating the container. - Update remote agents to use count retention. Destination credentials must allow listing and deletion. Legacy unscoped archives require manual cleanup.
- Keep web and HTTP health checks on port
8080. Agent traffic must reach port8443directly or through TCP passthrough; restrict access to Docker host IPs or networks. - Agent recovery defaults to 15 minutes through
VOLUMEVAULT_AGENT_RECOVERY_MINUTES. Failed remote operations may retain cleanup fences; confirm remote helpers have stopped before manually clearing them. Configure offline-agent alerts in Alerts > Settings.
Verification
- Release changelog validation and targeted tests passed: 17 tests, 81 assertions. Pint and diff checks passed.
- Local application and agent image builds passed. An isolated application container started both queue workers, the scheduler and agent TLS service; HTTP health and agent listener isolation checks passed.
- GitHub Actions built and published both versioned images for
linux/amd64andlinux/arm64and verified their multi-platform manifests.
Full Changelog: v2.0.2...v2.0.3