Commit Graph

19 Commits

Author SHA1 Message Date
KellyMichels
a71084738e chore(release): v1.0.0.0.26
Build stamp catch-up for 1 merged PR(s) since v1.0.0.0.25:
  f2e6302 fix(zdeploy): build docker stacks that come from a Dockerfile, instead of restarting the old image (#81)
2026-09-14 13:12:03 -05:00
0e7b80b4ae
chore(release): v1.0.0.0.25 (#80)
Some checks failed
tests / test (push) Has been cancelled
Build stamp catch-up for 6 merged PR(s) since v1.0.0.0.24:
  732a448 feat: add zmerge and zpull — fleet-wide PR merging and checkout sync (#79)
  573e010 docs(security): security notes, and a twin for every root .md (#78)
  3b0194a perf(tests): run each child-process invocation once (#77)
  f27f9dc fix(deploy): read the string build stamp, and never compare two unreadable labels (#76)
  16c56dc fix(ci): push trigger names master, this repo's default branch, so the workflow runs after a merge (#75)
  32e8d74 chore(ci): add a GitHub Actions workflow that lints with PSScriptAnalyzer and runs the Pester suite on Windows (#74)
2026-09-12 16:05:20 -05:00
fc52501999
chore(release): v1.0.0.0.24 (#73)
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-08 13:44:23 -05:00
f1b1fd6264
chore(release): v1.0.0.0.23 (#69)
Build stamp catch-up for 1 merged PR(s) since v1.0.0.0.22:
  135c585 docs(changelog): give every shipped release its own section, and generate the twin (#68)
2026-08-31 18:39:46 -05:00
560a2064a2
chore(release): v1.0.0.0.22 (#67)
Build stamp catch-up for 1 merged PR(s) since v1.0.0.0.21:
  40fa250 refactor(tests): move the sanitization denylist to a data file both sides can read (#66)
2026-08-31 17:56:24 -05:00
af929f73ba
chore(release): v1.0.0.0.21 (#65)
Build stamp catch-up for 1 merged PR(s) since v1.0.0.0.20:
  ac95c47 chore(sync): bring zdeploy/ZHelpers up to the private tree, sanitized (#64)
2026-08-31 15:01:27 -05:00
471789f530
chore(release): v1.0.0.0.20 (#62)
Build stamp catch-up for 1 merged PR(s) since v1.0.0.0.19:
  e4c563d fix(zversion): help text says one bump per release, not one per PR (#61)
2026-08-30 21:06:11 -05:00
c32fa8537b
chore(release): v1.0.0.0.19 (#60)
Build stamp catch-up for 1 merged PR(s) since v1.0.0.0.18:
  e738b62 feat(version): read a live build from inside the docker network, not the public proxy (#59)
2026-08-30 15:48:25 -05:00
e738b62cdf
feat(version): read a live build from inside the docker network, not the public proxy (#59)
zdeploy, zec2 and zec2online now prefer

    docker exec <viaProxy> curl http://<upstream>/api/build-version

when a project sets verify.viaProxy and verify.upstream.

Two problems it closes. A build stamp is something many sites deliberately
do not serve publicly, and a checker that reads it over the public URL stops
working the moment that endpoint is blocked -- reporting "unknown", which is
indistinguishable from "could not reach it". And the proxy answers from
whichever vhost matches the Host header, so a container with no public route
was getting another site's version back and failing deploys that had worked.

Reading it from a container on the shared network also exercises the real
HTTP path, so it proves the app is serving rather than that its database
knows a version. Purely additive: a project without those two keys behaves
exactly as before.

zec2 gains $PemKey and $SshTarget, which it had no need of until now -- the
read is inside a try/catch, so without them it would throw, be swallowed,
and fall through silently.

CHECKSUMS.txt regenerated (zchecksums -Update), zconfig.example.json
documents both shapes of the verify block, and CHANGELOG.md carries its
plain-text twin.

Pester: 231 passed, 0 failed -- including the sanitization suite.
2026-08-30 15:44:42 -05:00
58c888aa56
chore(release): v1.0.0.0.18 (#58)
Build stamp catch-up for 4 merged PR(s) since v1.0.0.0.14:
  4230566 feat: two blank lines after every z-script run (#57)
  432f210 fix(zdeploy): the pre-zip line states the label verification will require (#56)
  fcbad44 feat(zdeploy): add the static deploy kind, and a test that keeps this repo sanitized (#55)
  7b32bfa fix(zdeploy): docker kind now ships config subdirectories (#54)
2026-08-25 15:51:58 -05:00
KellyMichels
77d7c2f1f5 chore(release): v1.0.0.0.14
Build stamp catch-up for 3 merged PR(s) since v1.0.0.0.11:
  6c30f40 feat(zdeploy): sync deploy hardening from the private toolkit (#53)
  8959d9f fix(zdeploy): stop passing ssh -n to scp, which rejects it (#52)
  d99f8a1 fix(zdeploy): stop mirroring the build stamp into the local checkout (#51)
2026-08-20 11:45:19 -05:00
KellyMichels
91bbaca0e7 chore(release): v1.0.0.0.11
Build stamp catch-up for 1 merged PR(s) since v1.0.0.0.10:
  a1dd642 chore(changelog): drop the product name from the versioning entry; add the plain-text twin (#50)
2026-08-14 12:47:12 -05:00
KellyMichels
bc86162170 chore(release): v1.0.0.0.10
Build stamp catch-up for 1 merged PR(s) since v1.0.0.0.9:
  eedb95b fix(zdeploy): sync via explicit fetch + ff-only merge, not git pull (#49)
2026-08-13 19:53:00 -05:00
KellyMichels
a2fafcc6d0 chore(release): v1.0.0.0.9
Reconcile to the version build-version.json already committed. No increment.
2026-08-13 18:36:09 -05:00
KellyMichels
5701dff60a chore(release): v1.0.0.0.8
Build stamp catch-up for 8 merged PR(s) since v1.0.0.0.0:
  6c03138 fix(zdeploy): deploy edge first for any project list, not just 'all' (#46)
  976eb6d chore: point repo URLs at evomedia-net/evo.* (#44)
  0e4d9c3 fix(zdeploy): ship edge asset subdirectories, stop deploys hanging on ssh prompts, keep vendored archives (#43)
  c8fcfee fix(zdeploy): verify Next.js deploys on the server instead of probing the public IP (stops the bogus security-group warning) (#41)
  b84d24b fix(zdeploy): report where a domain-less project deployed to (#40)
  4668404 fix(zdeploy): re-land the two blank lines after the timestamp (#38)
  a868973 fix(zdeploy): verify against the committed build stamp, and read 5-segment versions (#37)
  0ddffc1 feat(zdeploy): print 'Last deployed at' timestamp as the last line of a run (#36)
2026-08-12 16:29:36 -05:00
kellymichels
976eb6d95e
chore: point repo URLs at evomedia-net/evo.* (#44)
All 16 repos moved to the evomedia-net org and were renamed into the evo.*
namespace, so every github.com/kellymichels/<old-name> reference in source
headers, CI badges, security links and docs pointed at a redirect.

Mechanical URL-only rewrite, applied longest-name-first so smartplantehs-docs
could not be clobbered by the smartplantehs rule. Nothing else changes: no
code, no product names, no behaviour. smartplantehs -> evo.ehs here is the
REPO url only; the product rename is separate and still pending.
2026-08-09 11:31:43 -05:00
kellymichels
91b638ac31
feat: checksums, toolkit versioning (v{major}.{rc}.{beta}.{alpha}.{build}), and downloadable release zips (#35)
* feat(zchecksums): SHA-256 manifest so a download can be verified before it's run

CHECKSUMS.txt lists a SHA-256 for every top-level .ps1 and .cmd - the files a
user actually executes. zchecksums verifies them; zchecksums -Update
regenerates after an intentional edit.

The manifest is sha256sum format, so 'sha256sum -c CHECKSUMS.txt' works on
Linux/macOS/WSL as well as the PowerShell path on Windows. Hashes are identical
on every platform because .gitattributes pins .ps1/.cmd to CRLF everywhere -
that pin is now load-bearing, so it is commented as such.

Beyond changed and missing files it also reports a script that is on disk but
NOT in the manifest, so something added outside a commit still gets noticed.
Exits non-zero on any of the three.

Honest about its limits, in the header and the README: the manifest lives in
the same repo as the code, so it is an integrity check rather than a signature.
It catches a truncated clone, a forgotten local edit, or an unlisted file - not
a compromised repo.

CHECKSUMS.txt is pinned to LF: sha256sum treats a trailing CR as part of the
filename and would report every entry as missing on Linux.

tests/Checksums.Tests.ps1 keeps it from rotting - a stale manifest is worse
than none, since it either cries wolf until people ignore it or quietly stops
covering a new script. The tests assert the format, LF endings, sort order,
full coverage of on-disk scripts, current hashes, and that zchecksums itself
exits 1 on a tampered file (proved by appending a byte and restoring it).

* feat(zversion, zrelease): toolkit versioning + downloadable release zips

Implements the versioning rule (SmartPlant's 5-segment scheme, now the global
standard; currently only sp and zscripts are on it at v1.x):

    v{major}.{rc}.{beta}.{alpha}.{build}

zversion: get / bump / bump-stage / set. A stage bump zeroes every lower
segment including build. 'bump' is one per PR and one per defect fix, not per
file. Any write rewrites three things together, because they are only useful
when they agree: build-version.json (source of truth), a '# Version:' line in
all 42 script headers (a lone copied script still says which release it came
from), and CHECKSUMS.txt (stamping changes every file).

zrelease: packages the current version as releases/zscripts-<version>.zip with
a sibling .sha256, for people who want the toolkit without cloning. One hash
verifies the download; the bundled CHECKSUMS.txt verifies the extracted
contents. Refuses to overwrite an existing version's zip (released = immutable;
bump instead), and refuses to package when zchecksums fails. tests/ excluded
from the zip; releases/ never packages itself.

First release included: releases/zscripts-v1.0.0.0.0.zip (42 scripts + 7
support files) and its .sha256.

.gitattributes: releases/*.sha256 pinned LF (sha256sum treats a trailing CR as
part of the filename), releases/*.zip marked binary.

Verified end-to-end as a downloader would experience it, in WSL: sha256sum -c
on the zip passes, unzip, sha256sum -c CHECKSUMS.txt inside gives 42 OK / 0
FAILED, and the extracted zdeploy.ps1 header and build-version.json both read
v1.0.0.0.0. Double-release guard and -Verify mode exercised. Full Pester suite
219/219 (the checksum tests absorb the new files automatically).
2026-07-28 13:47:25 -05:00
kellymichels
b370a46d79
fix: zbackup_ec2/zec2/zec2online require an explicit target (all), matching zbackup (#11)
These three defaulted to "every project" when run with no arguments -
inconsistent with zbackup/zdeploy/zstart/etc. (which show usage), and a
surprising amount of work to kick off by accident: zbackup_ec2 pulls a
server backup of every project, and zec2online deep-checks everything AND
auto-starts any downed stacks. Now a bare invocation prints usage and
lists the projects; 'all' does what bare used to. Applied to both the
bash and PowerShell versions.
2026-07-25 15:21:18 -05:00
KellyMichels
3546a12564 Evomedia.net Token Savers - initial public release
Config-driven PowerShell scripts to run infrastructure tasks (deploy, restart, backup, diagnostics) yourself instead of having an AI agent orchestrate them, to save agent tokens. Environment specifics live in zconfig.json (gitignored).
2026-07-15 21:33:22 -05:00