Changelog

All notable changes to Odysseus, organized by release date.

August 20, 2026
The Marketing Site and Documentation Ship in Three Languages
Feature
  • Full English, French, and Chinese translation of the marketing site and product documentation, generated and gated automatically on every release
  • Locale-aware navigation and hreflang tags, with each translated page carrying its own JavaScript and images instead of loading none
  • A round-trip translation gate that checks every registered language, not just one
August 20, 2026
Audit Hash Chain Verified End-to-End
Security Fix
  • Fixed a timestamp-precision mismatch that had silently broken hash verification for every chain-bearing audit row since the chain was enabled
  • The standalone offline verifier now ships in the image, so the audit trail's tamper-evidence can be checked independently of the control plane
August 3, 2026
CronJobs: Scheduled Workloads as a First-Class Kind
Feature
  • CronJob primitive with tick-driven scheduling, a missed-firing grace window, and per-status run-history limits
  • Named suspend/resume actions for taking a schedule out of service without losing its run history
  • Athena AI and the dashboard both gained CronJob support
July 23, 2026
Typed Ingress Surface, Live in Production
Feature
  • Deployment routing and eight kinds of Traefik middleware — basicAuth, ipAllowList, stripPrefix, compress, forwardAuth, headers, redirects, and canary weighting — generated from typed specs instead of hand-written labels
  • Byte-parity migration gate ensured the switch to typed generation changed nothing about what was already running
July 20, 2026
Automatic Node-Failure Detection and Evacuation
Feature Security
  • Nodes that stop responding are marked Suspect, then their workloads are evacuated automatically — nothing new is scheduled onto a node the platform cannot reach
  • Evacuation is a gated, approved action, not a silent takeover
July 19, 2026
Jobs: Run-to-Completion Workloads as a First-Class Kind
Feature
  • Job primitive for run-to-completion workloads, distinct from a long-running Deployment
  • Dispatched through the same single container-creation path as every other workload kind
July 17, 2026
Single-Path Container Dispatch (WireSpec v2)
Feature
  • Every container create now goes through one code path end to end: the control plane resolves placement and builds a versioned spec, and the node agent converts it to Docker configuration
  • Retired the legacy direct-Docker path and the partial creation paths that had grown up alongside it
June 15, 2026
Distributed Volumes: Tiered Storage With Automatic, Health-Monitored Failover
Feature
  • Block-level replicated volumes over a WireGuard mesh between nodes, with automatic failover when a node goes down
  • Object and shared storage tiers consolidated onto a single SeaweedFS cluster serving both FUSE and S3 access
  • Promoted to production
February 20, 2026
Canary Deployment Pipeline
Feature Fix
  • Full canary deployment pipeline with gateway integration and Traefik weighted routing
  • Resolved 4 post-deploy issues found during live canary testing
  • Image pull timeout fix with false-success detection in agent
  • Agent-to-Docker container conversion for timestamps and metadata
February 19, 2026
End-to-End Canary System & Container Management
Feature Fix
  • End-to-end canary deployment system with traffic split UI and AI-assisted canary start
  • Container cleanup on deployment deletion with container removal API, UI, and AI integration
  • Tenant-scoped scheduler with node selection UI
  • Canary state persistence via Consul for all operations
  • Dashboard guard against invalid uptime for zero/missing timestamps
February 18, 2026
Documentation Suite & Scanner Improvements
Docs Fix
  • Complete documentation suite with architecture diagrams and sequence diagrams
  • Documentation reorganized into subfolders with deployment runbook
  • Embedded architecture images and sequence diagrams inline
  • Automatic Grype scanner cache cleanup to prevent disk exhaustion
February 17, 2026
Agent Upgrade Pipeline & Network Fixes
Fix Security
  • Agent upgrade pipeline with image retagging for Compose and cascading blocker fixes
  • WireGuard peer persistence and cross-tenant node resolution
  • Volume usage data and network tenant inference
  • Tenant metrics access control and WebSocket hijacker fix
February 16, 2026
Multi-Node API Migration & AI Model Selection
Feature Fix
  • Gateway migration Phases 0–5: complete multi-node API migration with tenant node resolver
  • Unified AI model selection with single source of truth for chat provider/model
  • AI Assistant tab restricted to platform admin only
  • Notification settings fixes: Slack field mismatch, tenant isolation, save button UX
February 15, 2026
Billing Integration & Dashboard Upgrades
Feature Fix
  • Vault-backed billing configuration with hot-swap capability
  • Dashboard upgraded to React 19 for widget compatibility
  • Widget library published (@delta/musa-widgets v1.0.0)
  • Billing integration stabilization: SPA routing, API paths, widget null safety
February 14, 2026
Billing Platform Integration
Feature
  • Full Musa billing integration: backend, proxy, webhooks, and dashboard
  • ACME-style certificate enrollment system
February 12, 2026
Tenant Isolation & Audit Improvements
Security Fix
  • Enforced tenant isolation in backup and archive APIs
  • Audit attribution fixes and dashboard status improvements
  • Gateway auto-pull and volume listing fixes
  • CSRF token added to self-signed JWTs
February 11, 2026
Audit Logging & Agent Security
Feature Security
  • Audit logging wired to PostgreSQL with query visibility
  • Bind mount allowlist made configurable for agent security
  • RabbitMQ queue race condition resolved
February 10, 2026
Security Hardening Wave 5 Complete
Security Performance
  • All 184 security findings remediated across 6 waves
  • 9 comprehensive security test suites covering isolation, escalation, auth bypass, compliance
  • Performance testing under concurrent load
  • SOC 2 and GDPR compliance verification