Fuzzball v4.0.1 release notes
Fuzzball v4.0.1 stabilizes the v4.0.0 release with fixes across federation, storage, cloud deployments, and the CLI. It also enhances the object cache with implicit name inference, reworks the fuzzball run --volume flag to express the full v4 volume model, and adds a CLI download page to the web UI.
fuzzball object put and fuzzball object get now infer the destination name from the source when the target is a directory-style path.
- Implicit object names on
put. A destination URI ending in a trailing slash is filled in from the source basename:fuzzball object put data.csv fb://group/uploads tofb://group/data.csv, andfuzzball object put -R mydir fb://group/uploads the tree underfb://group/mydir/. - Implicit file names on
get. A local path that names a directory (trailing slash,., or..) is filled in from the object name:fuzzball object get fb://group/data.csv ./writes./data.csv.
fuzzball run --volumereworked for the v4 volume model. The volume spec now accepts the form[KEY=][REF:]MOUNT[,size=SIZE][,ANNOTATION=VALUE...]. A bare mount path creates an ephemeral volume with optional size and provisioner-selection annotations; a bare name references a persistent volume; and aprovisioner/volumeform selects a specific provisioner. Thesizeand annotation parameters are rejected on named persistent volumes with a clear error. Legacyvolume://references and the 3-segmentscope/class/volumeform continue to be accepted.
- CLI binary download page. A new Download CLI page, accessible from the Links menu, lets logged-in users download the Fuzzball CLI for macOS (Apple Silicon and Intel), Linux (x86_64 and ARM64), and Windows (x86_64), with platform-specific install instructions. The page preselects a likely build from the browser’s platform and matches the deployed Fuzzball version.
- Workflow stage events panel. The workflow detail page now includes a panel showing stage events for each workflow phase.
- Additional fields in workflow defaults. The workflow editor exposes more fields in the defaults section.
- Additional trusted issuers in the CRD. The FuzzballOrchestrate and FuzzballFederate CRDs accept an
additionalTrustedIssuerslist underspec.fuzzball.config, naming extra JWT issuer URLs to trust alongside the cluster’s own Keycloak, so endpoints can be trusted using tokens generated from a separate Keycloak instance. Each entry must be an absolutehttp(s)URL. - Default cluster names derived from deployment domain. Clusters deployed without an explicit name now default to the deployment’s domain (e.g.
example.com) instead ofunset-clusteror a timestamped stack name (e.g.fuzzball-20260618-170356). Federate clusters are prefixed withfederate.(e.g.federate.example.com). Existing clusters withunset-clusteror stack-derived names are renamed on the next reconcile. - Certificates issued before ingress resources. TLS certificates are now issued before the corresponding ingress resources are created, preventing a window where Kong could serve a default or expired certificate.
- GCP cluster commands.
fuzzball cluster gcp deployandupdatenow fail when the Pulumi runner job fails instead of reporting success.destroytears down provisioned resources (GKE, network, service accounts, SQL) before removing the deployment record and cleans up the deployment’s DNS records. - Docker compose deployment fixes. Docker compose deployments now support endpoints subdomains, set the cluster domain for endpoints correctly, and fix a “no space left on device” error in job containers.
- GPU cost in cloud provisioner price estimates. Cloud provisioner cost estimates now include GPU costs, producing more accurate per-node pricing.
object listauto-paginates.fuzzball object listnow walks every page automatically instead of stopping at the first response.--page-sizestill controls the per-request batch size; a new--max-pages/-mflag caps total pages fetched.volume listreturns the full result set. Previously, the volume list silently stopped at the first 25 results. The server now paginates across all accessible provisioners in a stable order and the CLI walks every page.- Object browser shows effective TTL. Objects that inherit their expiry from a group, organization, or cluster default now show the effective TTL instead of “No expiry”. The TTL status filter classifies these objects accordingly.
- Ephemeral volumes hidden from volume list.
fuzzball volume listno longer shows system-generated ephemeral volumes (e.g.ephemeral/<workflow_id>/scratch) alongside persistent volumes. - Legacy
referencefield removed. The v3-shapevolume://URI in volume info and list responses was incompatible with the v4 provisioner-based model. The--volumeflag help text now shows the correct format. - Stale instances no longer block provisioner removal. Removing or renaming a provisioner definition no longer fails with “currently used by N active instance(s)” when no instances are actually running.
node deprovisionresolves node IDs. Previously, passing the node ID (theip:portvalue shown infuzzball node list) reported success but the node kept running – only the hostname form actually terminated the instance. Both forms now work.- Bare ephemeral volumes preserved in the editor. Bare ephemeral volumes are no longer stripped when re-opening a workflow in the editor or rerunning from a previous run.
- Service-scoped secrets materialized on score. Federate now materializes service-scoped secret references when forwarding score requests to downstream clusters, so secrets referenced by workflow services resolve correctly.
- Cached cluster list on refresh failure. When a Federate cluster list refresh fails, the cached list is now served instead of returning an error.
- Signing key preserved in JWKS refresh. A cluster’s own signing key is now kept in the JWKS on refresh, preventing token validation failures after a key rotation cycle.
- Cluster record upserted on registration. Cluster registration now upserts the record, preventing failures when re-registering a previously removed cluster.
- Duplicate storage provisioner transaction handling. Rolling back an aborted transaction when skipping a duplicate storage provisioner during federation sync no longer causes a secondary error.
- v1 mount syntax in catalogs. Workflow catalogs with deprecated v1 mount syntax are now parsed server-side and upgraded to v4 format, instead of being rejected by the gateway.
- Phantom running jobs in node list. Fixed
fuzzball node listshowing jobs as running after they had completed.
- Silent data loss on non-AWS S3 endpoints. When copying data to S3-compatible object stores (e.g. Oracle Cloud), failed egress uploads now surface as errors instead of reporting success. Non-AWS S3 endpoints no longer receive the default AWS request checksum encoding that they reject.
- Malformed cluster references backfilled. Malformed
cluster_refsrows are now repaired before the owner CHECK constraint is applied, preventing migration failures on clusters with data from older versions.