0.10.1
odysseus-core
Fixed
-
odysseus could not read an SSH key from disk unless ssh-agent happened to be holding it.
net-sshneedsed25519andbcrypt_pbkdfto parse anything in the-----BEGIN OPENSSH PRIVATE KEY-----container -- which is what every modernssh-keygenwrites, RSA included, not only ed25519 -- and neither was declared, sokey_factory.rbraisedNotImplementedErrorbefore it ever looked at the algorithm. Both are runtime dependencies now. Reported by a tester whose deploys failed with a passphrase-protected key; the passphrase was not the cause, the key format was. -
A passphrase-protected SSH key is no longer reported as "Check your SSH keys." odysseus connects with
non_interactive: true-- a passphrase prompt on a deploy connection can never be answered, so prompting would hang rather than help -- and net-ssh reports the resulting key-loading failure to a logger rather than raising it, so with none configured the reason was discarded and the reader was sent to inspect keys that were entirely correct. The failure now names each locked key and gives thessh-addline for it.Odysseus::SSHKey.encrypted?answers that by reading the cipher named in the key file, so no passphrase is needed to detect one. -
docker pusshno longer hangs silently. It ran through backticks with everything folded into a captured string, which had three consequences: no output reached the terminal until the push finished, so a healthy push and a stuck one looked identical; there was no timeout; and stdin stayed attached to the parent, so a child that asked a question waited forever on an answer nobody could see it requesting. Output now streams as it arrives, stdin is closed so any prompt reaches EOF and fails promptly, and a push is bounded byPUSSH_TIMEOUT(30 minutes -- generous, since it exists to end a hang rather than to police a slow link). A push that does time out now suggests what to check, including the Tailscale stepsSSH#with_connectionalready gives for the deploy connection but whichpusshnever reached.
Changed
-
Every container odysseus starts now has a bounded log. Containers inherited the daemon's default logging, which on a stock Docker install is
json-filewith no size limit, so a long-lived container filled the disk -- most visiblyodysseus-caddy, the one container no deploy ever replaces. Everydocker runnow carries--log-driver json-file --log-opt max-size=100m --log-opt max-file=3.The driver is named rather than left to the daemon because
max-sizeandmax-filebelong tojson-fileandlocalonly: on a host defaulting tojournaldorsyslog, docker refuses the run rather than ignoring them. Naming it also makes explicit whatodysseus logsalready assumed, since it shells out todocker logs.This overrides a deliberate daemon-wide log driver on the host. Making the driver and options configurable per service is tracked in TODO.md.
odysseus-cli
Fixed
-
deploy --buildno longer dies withincompatible character encodings: UTF-8 and BINARYafter the build has already succeeded. The streamed-output reader accumulated chunks fromIO#read_nonblock, which returns ASCII-8BIT, into a UTF-8 string literal -- which silently takes the chunk's encoding on the first append. Any byte above 0x7F in the build or push output then reached the spinner's UTF-8 format string as binary and raised there. Bytes are now accumulated as binary and decoded once a line is complete, so a read boundary falling inside a multi-byte character cannot mangle it either. Reported from a real deploy that failed while pushing to a host.