Skip to content
Permalink

Comparing changes

Choose two branches to see what’s changed or to start a new pull request. If you need to, you can also or learn more about diff comparisons.

Open a pull request

Create a new pull request by comparing changes across two branches. If you need to, you can also . Learn more about diff comparisons here.
base repository: Basekick-Labs/arc
Failed to load repositories. Confirm that selected base ref is valid, then try again.
Loading
base: v26.03.2
Choose a base ref
...
head repository: Basekick-Labs/arc
Failed to load repositories. Confirm that selected head ref is valid, then try again.
Loading
compare: v26.04.1
Choose a head ref
  • 14 commits
  • 8 files changed
  • 3 contributors

Commits on Apr 1, 2026

  1. feat(auth): add ARC_AUTH_BOOTSTRAP_TOKEN and ARC_AUTH_FORCE_BOOTSTRAP…

    … env vars
    
    Resolves painful auth bootstrap UX where the admin token was only shown
    once on first start with no recovery path short of deleting the auth DB.
    
    - ARC_AUTH_BOOTSTRAP_TOKEN: use a known token value on first run instead
      of generating a random one — enables reproducible/automated deployments
    - ARC_AUTH_FORCE_BOOTSTRAP: wipe all tokens and recreate admin with the
      provided value — recovery path when admin token has been lost
    - Both values require minimum 32 characters; stored as bcrypt hash
    
    Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
    Ignacio Van Droogenbroeck and claude committed Apr 1, 2026
    Configuration menu
    Copy the full SHA
    dc69a49 View commit details
    Browse the repository at this point in the history
  2. fix(auth): preserve existing tokens on force bootstrap (don't delete …

    …all)
    
    Deleting all tokens on ARC_AUTH_FORCE_BOOTSTRAP was dangerous — a bad
    actor with env var access could lock out all legitimate admins. Changed
    to additive recovery: a new 'arc-recovery' admin token is added without
    touching existing tokens. Legitimate admins retain access and can revoke
    the recovery token if it was injected maliciously.
    
    Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
    Ignacio Van Droogenbroeck and claude committed Apr 1, 2026
    Configuration menu
    Copy the full SHA
    56ede54 View commit details
    Browse the repository at this point in the history
  3. refactor(auth): fix TOCTOU race, remove duplication, add tests for bo…

    …otstrap methods
    
    - Fix TOCTOU race in EnsureInitialToken/EnsureInitialTokenWithValue: replace
      COUNT→INSERT two-step with a single atomic INSERT...WHERE NOT EXISTS, so
      concurrent node startups can never produce duplicate admin tokens
    - Extract insertToken private helper: CreateToken and CreateTokenWithValue
      shared ~90% identical DB insertion code; now both delegate to one place
    - Fix stale ForceBootstrap config comment (previously said "delete all tokens",
      now correctly says "add recovery token without removing existing ones")
    - Fix misleading comment in ForceAddRecoveryToken ("rotate it to new value"
      was not implemented; comment now reflects the actual no-op behavior)
    - Add 13 test cases covering CreateTokenWithValue, EnsureInitialTokenWithValue,
      and ForceAddRecoveryToken including concurrent safety and idempotency
    
    Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
    Ignacio Van Droogenbroeck and claude committed Apr 1, 2026
    Configuration menu
    Copy the full SHA
    743d193 View commit details
    Browse the repository at this point in the history
  4. docs: add auth bootstrap and TOCTOU race fix to 26.04.1 release notes

    Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
    Ignacio Van Droogenbroeck and claude committed Apr 1, 2026
    Configuration menu
    Copy the full SHA
    d8c59f1 View commit details
    Browse the repository at this point in the history
  5. fix(auth): remove unused tokenValue param from insertToken, fix stale…

    … progress doc
    
    - insertToken signature had tokenValue as first arg but never used it;
      removed per Gemini review
    - docs/progress file still described ForceBootstrap as deleting all tokens;
      updated to reflect actual additive behavior
    
    Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
    Ignacio Van Droogenbroeck and claude committed Apr 1, 2026
    Configuration menu
    Copy the full SHA
    08ceea4 View commit details
    Browse the repository at this point in the history
  6. Merge pull request #360 from Basekick-Labs/feat/auth-bootstrap-token

    feat(auth): add ARC_AUTH_BOOTSTRAP_TOKEN and ARC_AUTH_FORCE_BOOTSTRAP for predictable deployments and recovery
    xe-nvdk authored Apr 1, 2026
    Configuration menu
    Copy the full SHA
    b128e93 View commit details
    Browse the repository at this point in the history
  7. fix(helm): default deployment strategy to Recreate for RWO volume com…

    …patibility
    
    RollingUpdate deadlocks with a single replica and a ReadWriteOnce PVC: the
    new pod can't attach the volume until the old pod terminates, but RollingUpdate
    waits for the new pod to be healthy first. Recreate terminates the old pod
    first, then starts the new one.
    
    Configurable via updateStrategy.type (default: Recreate). Override to
    RollingUpdate when using shared object storage with Arc Enterprise clustering.
    
    Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
    Ignacio Van Droogenbroeck and claude committed Apr 1, 2026
    Configuration menu
    Copy the full SHA
    14fb604 View commit details
    Browse the repository at this point in the history
  8. fix(helm): use toYaml for strategy to support rollingUpdate params

    Allows users who switch to RollingUpdate to also configure maxSurge and
    maxUnavailable via values, per Gemini review suggestion.
    
    Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
    Ignacio Van Droogenbroeck and claude committed Apr 1, 2026
    Configuration menu
    Copy the full SHA
    473d720 View commit details
    Browse the repository at this point in the history
  9. docs: add Helm Recreate strategy fix to 26.04.1 release notes

    Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
    Ignacio Van Droogenbroeck and claude committed Apr 1, 2026
    Configuration menu
    Copy the full SHA
    c06d799 View commit details
    Browse the repository at this point in the history
  10. Merge pull request #361 from Basekick-Labs/fix/helm-recreate-strategy

    fix(helm): default deployment strategy to Recreate for RWO volume compatibility
    xe-nvdk authored Apr 1, 2026
    Configuration menu
    Copy the full SHA
    3dfac9d View commit details
    Browse the repository at this point in the history
  11. fix(security): restrict temp file permissions and validate memory_limit

    - chmod 0600 on CreateTemp files in restore, delete, and duckdb profiling
      to prevent world-readable parquet data and profile output (closes #362)
    - validate memory_limit with regex before SQL interpolation in compaction
      subprocess to prevent injection via config (closes #363)
    
    Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
    Ignacio Van Droogenbroeck and claude committed Apr 1, 2026
    Configuration menu
    Copy the full SHA
    d39807e View commit details
    Browse the repository at this point in the history
  12. fix(security): validate memory_limit at config load time

    Centralize memory_limit validation in config.Load() with a regex guard
    instead of at each call site. os.CreateTemp already creates 0600 files
    so chmod calls were redundant and have been removed.
    
    Addresses Gemini review feedback on #368.
    
    Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
    Ignacio Van Droogenbroeck and claude committed Apr 1, 2026
    Configuration menu
    Copy the full SHA
    f774d89 View commit details
    Browse the repository at this point in the history
  13. docs: add memory_limit validation to 26.04.1 release notes

    Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
    Ignacio Van Droogenbroeck and claude committed Apr 1, 2026
    Configuration menu
    Copy the full SHA
    d677629 View commit details
    Browse the repository at this point in the history
  14. Merge pull request #368 from Basekick-Labs/release/26.04.1

    fix(security): restrict temp file permissions and validate memory_limit
    xe-nvdk authored Apr 1, 2026
    Configuration menu
    Copy the full SHA
    e6fe712 View commit details
    Browse the repository at this point in the history
Loading