📦 Other Changes
fix(toolchain): keep the 'v' prefix in cosign certificate-github-workflow-ref @aknysh (#3210)
- Bug Fixes
- Fixed signature verification for releases whose version tags include a
vprefix. Cosign workflow references now match the actual release tag, while version-like segments in unrelated key paths remain unchanged.
- Fixed signature verification for releases whose version tags include a
- Documentation
- Added a note describing the signature-verification issue and its resolution, including reproduction details, validation coverage, and related follow-up considerations.
fix(ci): allow Go toolchain download in website preview deploy @aknysh (#3191)
- Chores
- Website preview deployments can now access required release assets over HTTPS.
✨ Features
feat(scaffold): add type: computed derived fields @jorrite (#3222)
- New Features
- Added computed scaffold fields that derive values from answers or use literal values. Results are evaluated in declaration order and can be used in generated configuration, files, and matrix axes.
- Bug Fixes
- Scaffold loading now reports specific errors for configured templates that fail to load while continuing to load other templates.
- Documentation
- Documented computed-field rules, including that fields are not prompted for or settable with
--set, and cannot be referenced bywhen:conditions oroptions:.
- Documented computed-field rules, including that fields are not prompted for or settable with
feat: report CLI exceptions to Atmos Pro with metadata and Pact @osterman (#3220)
- New Features
- Added automatic CLI exception reporting to Atmos Pro for eligible GitHub Actions runs when Pro is enabled. Reports include execution and component context, with sensitive values masked.
- Added
settings.pro.errors.enabledand theATMOS_PRO_ERRORS_ENABLEDenvironment variable to control reporting independently. Reporting can be disabled without changing command exit codes or existing Sentry destinations.
- Documentation
- Added setup, eligibility, configuration, GitHub OIDC requirements, and opt-out guidance for Atmos Pro exception reporting.
Resolve toolchains from project configuration without changing pins @osterman (#3215)
- New Features
- Added frozen lockfile mode, which requires complete URL and checksum entries for the requested tool and platform, including cached tools, and prevents lockfile updates.
- Added environment settings for toolchain install paths and frozen lockfile mode.
- Improvements
- Relative toolchain paths now resolve from the project directory, even when commands run elsewhere.
- Automatic installs preserve declared tool versions and existing matching lockfile entries, recording missing entries after successful installation.
- Atmos version bootstrapping uses active project settings, or an XDG cache location when run outside a project.
- Documentation
- Updated toolchain configuration and installation guidance for path resolution and frozen installs.
feat(ai): add opencode CLI provider @aknysh (#3189)
- New Features
- Added OpenCode as an AI CLI provider for
atmos ai, with automatic detection and optional model selection. - Supports conversation history, system prompts, explicit full-auto mode, and MCP server pass-through.
- Reuses OpenCode authentication and configuration without modifying user files.
- Applies MCP settings through a temporary configuration file and reports configuration or execution errors clearly.
- Added OpenCode as an AI CLI provider for
- Documentation
- Added OpenCode setup, usage, troubleshooting, and roadmap guidance.
- Documented OpenRouter, DeepSeek, and Z.AI providers.
- Tests
- Added coverage for provider detection, command execution, response handling, and MCP integration.
feat(scaffold): support glob patterns in spec.files[].path @jorrite (#3187)
- New Features
- Scaffold file paths support glob patterns, recursive directory matching, and normalized separators.
- Apply conditions to directory trees and duplicate matched files across matrix values.
- Use file path template variables to preserve relative locations and avoid output collisions.
- Overlapping matches follow last-declared-entry precedence.
- Bug Fixes
- Invalid patterns and ambiguous matrix targets fail before files are written.
- Updates recover merge history when rendered paths change and warn when unavailable.
- Invalid file-context references are no longer misidentified as valid.
- Documentation
- Added usage guidance and a directory-matrix scaffold example.
feat(ai): add OpenRouter, DeepSeek, and Z.AI providers @aknysh (#3188)
- New Features
- Added support for OpenRouter, DeepSeek, and Z.AI providers across Atmos AI commands.
- Added configurable models, endpoints, token limits, request timeouts, conversation history, system prompts, and tool usage.
- Added secure base URL validation when API keys are configured, while allowing local loopback endpoints.
- Documentation
- Added provider configuration guidance and updated the roadmap with the new integrations.
- Bug Fixes
- Improved handling of API failures, empty responses, and insecure endpoint configurations.
feat(scaffold): --update-strategy=tracked|rendered for atmos init/scaffold generate @jorrite (#3119)
- New Features
- Added
--update-strategyto initialization and scaffold updates. - The default
trackedstrategy uses target Git history. - The
renderedstrategy reconstructs prior template state from recorded configuration, supporting updates without target Git history. - Rendered updates reuse the exact template revision and support dry-run previews.
- Added
- Bug Fixes
- Added validation for invalid strategies, incompatible
--base-refcombinations, missing configuration, and strategy switches.
- Added validation for invalid strategies, incompatible
- Documentation
- Updated CLI guides, product documentation, roadmap, and blog content.
🐛 Bug Fixes
fix(terraform): invalidate output cache after component execution @djal (#3217)
- Bug Fixes
- Terraform commands now refresh cached component outputs after successful execution, so dependent components use up-to-date values during bulk operations.
fix(store): support stack and global Vault secret scopes @djal (#3214)
- New Features
- Vault secrets can now be stored, retrieved, checked, and deleted when stack or component coordinates are empty, supporting stack-scoped and global secrets.
- Bug Fixes
- Secret availability checks now report missing, soft-deleted, or destroyed secrets as unavailable. Secrets scheduled for deletion in the future remain available until that time.
- Checking secret availability continues to use metadata without reading secret values.
fix(describe): surface native Helm chart and values in describe component @aknysh (#3228)
- Bug Fixes
atmos describe componentnow preserves Helmchart,values, andvalues_filesconfiguration in its default schema-filtered output.- Computed fields such as
atmos_componentanddepscontinue to be excluded.
- Documentation
- Added documentation describing the Helm configuration filtering fix and its validation.
fix: restore TUI startup and defer list/describe authentication @osterman (#3212)
- New Features
- Running
atmoswithout a subcommand opens the interactive picker when stack configuration is available and both input and output are interactive; otherwise, help is shown. - List and describe commands evaluate requested values on demand. Unused fields and columns no longer trigger authentication or evaluate unrelated values.
- Unavailable implicit credentials can be handled according to the command’s error mode: show computed values with a warning, omit the warning, or fail.
- Running
- Bug Fixes
- Explicit identity selection, including through
ATMOS_IDENTITY, is validated before processing; authentication failures are no longer silently skipped. - AWS access-denied responses remain authorization errors rather than being reported as unavailable credentials.
- Authentication and authorization errors during deferred store lookups are no longer replaced by configured defaults.
- Cached Terraform outputs are isolated by authentication context to prevent values from being reused across identities.
- Explicit identity selection, including through
fix(describe-affected): cover all component types (deleted helm/kubernetes + ansible/container/emulator) @aknysh (#3204)
- New Features
describe affecteddetects added, modified, and deleted Ansible, container, and emulator components, alongside existing component types, including native Helm and Kubernetes deletions.- Ansible and container source-file changes are matched to their components. Emulator components are evaluated without requiring a source directory.
- Changes within nested component paths can be reported for each matching component.
- File and folder dependencies are checked even when a component has no settings section.
- Added, modified, emptied, and removed settings sections are detected as changes.
fix(terraform): wrap and pretty-print --ui attribute values @osterman (#3216)
- Improvements
- Terraform dependency-tree output formats attribute changes with aligned values and readable diffs for structured or multiline content.
- Long values wrap without losing content, and column alignment accounts for Unicode characters.
- Sensitive and not-yet-known values are clearly labeled.
- Structured JSON and YAML values can be syntax-highlighted when enabled.
- Terraform dependency-tree output respects the active terminal width and formatting settings.
fix(scaffold): default hook working directory to the scaffold target path @jorrite (#3206)
- Bug Fixes
- Non-
type: atmosscaffold hook steps now default to the generated project’s target directory. Bare-relative working directories resolve under that target, whileworking_directory: "."retains launch-directory behavior.type: atmossteps use the launch directory when no working directory is set; explicit values are honored.
- Non-
- New Features
- Hook templates can reference the scaffold target directory with
{{ .TargetPath }}.
- Hook templates can reference the scaffold target directory with
- Documentation
- Updated scaffold and initialization guides to explain working-directory defaults and the
type: atmosexception.
- Updated scaffold and initialization guides to explain working-directory defaults and the
fix(provision): global workdir default lives in stack config, not settings @aknysh (#3200)
- Configuration
- Configure workdir provisioning defaults at the toolchain level in stack manifests.
- Component-level settings, including
enabled: false, override inherited stack defaults. - Global
settings.provision.workdirconfiguration is no longer supported.
- Documentation
- Updated provisioning guidance for configuration scope and backend defaults.
- Documented workdir
ttlsettings and expired workdir cleanup eligibility.
- Validation
- Added coverage for stack-level defaults and component-level overrides.
fix(vendor): add vendor clean --prune-lock to forget lock entries @aknysh (#3201)
- New Features
- Added a
--prune-lockoption toatmos vendor cleanfor permanently removing selected vendored components and their lock-file entries. - Added dry-run support to preview files and lock entries that would be removed.
- Lock-file entries remain preserved by default when cleaning.
- Added a
- Documentation
- Updated command documentation with usage examples, selector behavior, pruning details, and dry-run guidance.
- Added troubleshooting guidance for permanently removing vendored components.
fix(terraform): provision local-component workdir before backend/varfile generation @aknysh (#3198)
- Bug Fixes
- Fixed concurrent Terraform runs for local components using isolated work directories.
- Generated backend configuration and variable files are now placed in the appropriate per-run directory, preventing source-tree changes and read/write errors during parallel planning.
- Ensured local component files are available in the isolated work directory before Terraform execution.
- Preserved existing source-directory behavior for local non-Terraform components.
- Documentation
- Added documentation covering the work-directory race fix and a remaining limitation with the global work-directory setting.
fix(schema): allow ':' in auth/secret provider and identity names @aknysh (#3186)
- New Features
- Manifest names for authentication identities, authentication providers, and secret providers can now include colons (
:), including namespaced formats. - Authentication identities and providers support optional tags for categorization and filtering.
- Authentication identities can be marked as required for automatic authentication.
- Authentication identity definitions no longer require a
kindvalue.
- Manifest names for authentication identities, authentication providers, and secret providers can now include colons (
- Documentation
- Added guidance covering the updated manifest schema and validation behavior.
fix: make website deploys reproducible @osterman (#3181)
- New Features
- Website builds now use a consistent timestamp, producing reproducible pages and generated downloads.
- Copyright years and build-related metadata consistently reflect the build timestamp.
- Added validation for invalid build timestamp values.
- Bug Fixes
- Prevented unchanged preview builds from producing unnecessary page snapshot changes.
- Tests
- Added automated coverage for valid, missing, malformed, and out-of-range build timestamps.
fix(ci): improve legacy action migration guidance and docs release labels @osterman (#3177)
- Bug Fixes
- Corrected deprecated GitHub Action detection, including plan-storage and component-updater actions.
- Added migration warnings with Native CI links and GitHub Actions annotations.
- Documentation
- Expanded Native CI guidance for workflows, permissions, caching, SBOMs, validation, and production environment gating.
- Added migration guidance and native Atmos replacements for deprecated GitHub Actions.
- Documented multiline-safe settings output, built-in planfile storage, and
vendor update --pull-requestalternatives. - Improved release labeling for updates to existing documentation.
fix(ci): annotate terraform plan/apply warnings with file and line @osterman (#3178)
- New Features
- Added inline CI annotations for Terraform warnings from plan, apply, and deploy operations.
- Added inline error annotations for failing Terraform test assertions.
- Warning annotations include source file and line details when available.
- Bug Fixes
- Improved source-location detection for Terraform diagnostics, including warnings and varied diagnostic formats.
- Annotation failures no longer interrupt CI processing.
ci: use free GitHub-hosted runners @osterman (#3175)
- Chores
- Updated CI/CD workflows to use standard GitHub-hosted Ubuntu runners instead of custom self-hosted runners.
- Applied security hardening consistently across build matrix jobs.
- Preserved existing formatting, testing, release, and deployment workflow behavior.
ci: move content-aware S3 deploy to Mage @osterman (#3176)
- New Features
- Website deployments now use content-aware synchronization, updating only added or changed files and removing obsolete managed files.
- Deployments preserve protected demo images and versioned schema assets.
- Uploaded files receive detected content types with UTF-8 metadata where applicable.
- Deployment manifests support faster, more efficient repeat deployments.
- Bug Fixes
- Improved handling of deployment errors, missing manifests, partial deletions, and invalid upload metadata.
- Documentation
- Added guidance on deployment behavior, protected content, performance, validation, and rollback procedures.
🤖 Automatic Updates
build(deps): bump golang.org/x/tools from 0.49.0 to 0.50.0 in /tools/lintroller @dependabot[bot] (#3225)
- Bumps golang.org/x/tools from 0.49.0 to 0.50.0.
Commits
265dd1ago.mod: update golang.org/x dependencies2af88d6gopls/internal/cache: handle multiple legacy build constraints in standalone ...9e18529gopls/internal/test/integration/fake: don't poll after a workspace edit2543006go/gcexportdata: update package docs + minor tweaks7c2cac4gopls/internal/golang/completion: handle new(expr)28649eago/analysis/passes/modernize: elide red…
build(deps): bump charmbracelet/vhs from
b1afb4ftoea49a6ain /demo/screenshots @dependabot[bot] (#3224)-
[!WARNING] > Cooldown could not be applied because no publication date was available from the registry. >
- Bumps charmbracelet/vhs from
b1afb4ftoea49a6a.Commits
- See full diff in compare view
- Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase. - [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end)
-
Dependabot commands and options
- You can trigger Dependabot actions by commenting on this PR: -
@dependabot rebasewill rebase this PR -@dependabot recreatewill recreate this PR, overwriting any edits that have…
build(deps): bump the cicd group across 1 directory with 11 updates @dependabot[bot] (#3226)
- Bumps the cicd group with 11 updates in the / directory:
- | Package | From | To | | --- | --- | --- | | cloudposse/.github/.github/workflows/shared-release-branches.yml |
0.168.0|0.171.0| | github/codeql-action/upload-sarif |4.37.9|4.38.0| | github/codeql-action/init |4.37.9|4.38.0| | github/codeql-action/autobuild |4.37.9|4.38.0| | github/codeql-action/analyze |4.37.9|4.38.0| | actions/cache |5.0.5|5.1.0| | cloudposse/.github/.github/workflows/shared-go-auto-release.yml |0.170.0|0.171.0| | actions/cache/save |5.0.5|5.1.0| | hadolint/hadolint-action |3.4.0|3.5.0| | trufflesecurity/trufflehog |3.97.0|3.97.4| | [aws-actions/configure-aws-credentials](https://github.com/aws-actions/configure-a…