Changelog
All notable changes to Odysseus, organized by release date.
August 20, 2026
The Marketing Site and Documentation Ship in Three Languages
Feature
- Full English, French, and Chinese translation of the marketing site and product documentation, generated and gated automatically on every release
- Locale-aware navigation and hreflang tags, with each translated page carrying its own JavaScript and images instead of loading none
- A round-trip translation gate that checks every registered language, not just one
August 20, 2026
Audit Hash Chain Verified End-to-End
Security
Fix
- Fixed a timestamp-precision mismatch that had silently broken hash verification for every chain-bearing audit row since the chain was enabled
- The standalone offline verifier now ships in the image, so the audit trail's tamper-evidence can be checked independently of the control plane
August 3, 2026
CronJobs: Scheduled Workloads as a First-Class Kind
Feature
- CronJob primitive with tick-driven scheduling, a missed-firing grace window, and per-status run-history limits
- Named suspend/resume actions for taking a schedule out of service without losing its run history
- Athena AI and the dashboard both gained CronJob support
July 23, 2026
Typed Ingress Surface, Live in Production
Feature
- Deployment routing and eight kinds of Traefik middleware — basicAuth, ipAllowList, stripPrefix, compress, forwardAuth, headers, redirects, and canary weighting — generated from typed specs instead of hand-written labels
- Byte-parity migration gate ensured the switch to typed generation changed nothing about what was already running
July 20, 2026
Automatic Node-Failure Detection and Evacuation
Feature
Security
- Nodes that stop responding are marked Suspect, then their workloads are evacuated automatically — nothing new is scheduled onto a node the platform cannot reach
- Evacuation is a gated, approved action, not a silent takeover
July 19, 2026
Jobs: Run-to-Completion Workloads as a First-Class Kind
Feature
- Job primitive for run-to-completion workloads, distinct from a long-running Deployment
- Dispatched through the same single container-creation path as every other workload kind
July 17, 2026
Single-Path Container Dispatch (WireSpec v2)
Feature
- Every container create now goes through one code path end to end: the control plane resolves placement and builds a versioned spec, and the node agent converts it to Docker configuration
- Retired the legacy direct-Docker path and the partial creation paths that had grown up alongside it
June 15, 2026
Distributed Volumes: Tiered Storage With Automatic, Health-Monitored Failover
Feature
- Block-level replicated volumes over a WireGuard mesh between nodes, with automatic failover when a node goes down
- Object and shared storage tiers consolidated onto a single SeaweedFS cluster serving both FUSE and S3 access
- Promoted to production
February 20, 2026
Canary Deployment Pipeline
Feature
Fix
- Full canary deployment pipeline with gateway integration and Traefik weighted routing
- Resolved 4 post-deploy issues found during live canary testing
- Image pull timeout fix with false-success detection in agent
- Agent-to-Docker container conversion for timestamps and metadata
February 19, 2026
End-to-End Canary System & Container Management
Feature
Fix
- End-to-end canary deployment system with traffic split UI and AI-assisted canary start
- Container cleanup on deployment deletion with container removal API, UI, and AI integration
- Tenant-scoped scheduler with node selection UI
- Canary state persistence via Consul for all operations
- Dashboard guard against invalid uptime for zero/missing timestamps
February 18, 2026
Documentation Suite & Scanner Improvements
Docs
Fix
- Complete documentation suite with architecture diagrams and sequence diagrams
- Documentation reorganized into subfolders with deployment runbook
- Embedded architecture images and sequence diagrams inline
- Automatic Grype scanner cache cleanup to prevent disk exhaustion
February 17, 2026
Agent Upgrade Pipeline & Network Fixes
Fix
Security
- Agent upgrade pipeline with image retagging for Compose and cascading blocker fixes
- WireGuard peer persistence and cross-tenant node resolution
- Volume usage data and network tenant inference
- Tenant metrics access control and WebSocket hijacker fix
February 16, 2026
Multi-Node API Migration & AI Model Selection
Feature
Fix
- Gateway migration Phases 0–5: complete multi-node API migration with tenant node resolver
- Unified AI model selection with single source of truth for chat provider/model
- AI Assistant tab restricted to platform admin only
- Notification settings fixes: Slack field mismatch, tenant isolation, save button UX
February 15, 2026
Billing Integration & Dashboard Upgrades
Feature
Fix
- Vault-backed billing configuration with hot-swap capability
- Dashboard upgraded to React 19 for widget compatibility
- Widget library published (@delta/musa-widgets v1.0.0)
- Billing integration stabilization: SPA routing, API paths, widget null safety
February 14, 2026
Billing Platform Integration
Feature
- Full Musa billing integration: backend, proxy, webhooks, and dashboard
- ACME-style certificate enrollment system
February 12, 2026
Tenant Isolation & Audit Improvements
Security
Fix
- Enforced tenant isolation in backup and archive APIs
- Audit attribution fixes and dashboard status improvements
- Gateway auto-pull and volume listing fixes
- CSRF token added to self-signed JWTs
February 11, 2026
Audit Logging & Agent Security
Feature
Security
- Audit logging wired to PostgreSQL with query visibility
- Bind mount allowlist made configurable for agent security
- RabbitMQ queue race condition resolved
February 10, 2026
Security Hardening Wave 5 Complete
Security
Performance
- All 184 security findings remediated across 6 waves
- 9 comprehensive security test suites covering isolation, escalation, auth bypass, compliance
- Performance testing under concurrent load
- SOC 2 and GDPR compliance verification